Skip to content
RechtsKI

Privacy Policy

We attach the highest importance to the protection of your personal data

Data Protection & Security

1. Introduction and Scope

We attach the highest importance to the protection of your personal data and to processing in compliance with applicable data protection laws, in particular the Swiss Federal Act on Data Protection (FADP, SR 235.1) and the Data Protection Ordinance (DPO, SR 235.11). This policy explains what data we collect, how we process it, and what rights you have as a data subject. It applies to all users of our services.

2. Data Controller / Data Protection Advisor

The controller responsible for data processing is: agentic labs GmbH, Bützenenweg 16, 4450 Sissach

3. Our Offerings and Data Hosting

We offer our SaaS solution in the following variants:

  • Standard (Cloud Service): Operation and storage on the Safe Swiss Cloud infrastructure in Switzerland (ISO 27001); AI processing by default via Microsoft Azure (region Switzerland North), or entirely via Safe Swiss Cloud per request. Storage and processing exclusively in Switzerland.
  • Enterprise Cloud (Customer Cloud): Operation in the customer's cloud infrastructure (e.g., Azure, AWS). Data location as agreed.
  • On-Premises: Operation on customer's own servers on-site. We process data exclusively according to contract and instructions.

In all models: No transfer to unauthorized third parties, conclusion of data processing agreements (Art. 9 FADP, Art. 7 DPO).

4. Categories of Personal Data

We process in particular the following data:

  • Account data: Name, email address, password (encrypted), management via Google Firebase Authentication.
  • Usage and log data: IP address, access time, browser type, device type.
  • Content data: Text inputs and uploaded documents used for AI queries.
  • Communication data: Content of support requests and correspondence.

No profiling or automated decision-making with legal effects (Art. 21 FADP).

5. Purposes and Legal Bases for Personal Data

We process personal data according to the following legal bases:

  • Contract performance (Art. 31 para. 2 lit. a FADP; Art. 6 para. 1 lit. b GDPR)
  • Legitimate interest (Art. 31 para. 1 FADP; Art. 6 para. 1 lit. f GDPR)
  • Legal obligation (Art. 31 para. 1 FADP; Art. 6 para. 1 lit. c GDPR)
  • Consent (Art. 31 para. 1 FADP; Art. 6 para. 1 lit. a GDPR)

If we need your consent for certain processing (e.g., storing chat histories, sending newsletters), we request it explicitly. Consent is documented and can be revoked at any time with effect for the future, without affecting the lawfulness of processing carried out until that point.

6. Transfer and Data Processors

We only transfer personal data if it is legally permitted, necessary for contract performance, or if you have expressly consented. Transfer occurs exclusively to carefully selected and contractually bound processors pursuant to Art. 9 FADP and Art. 28 GDPR.

Safe Swiss Cloud (Hosting, Storage and Swiss LLM Processing)

The platform runs on Safe Swiss Cloud's ISO 27001-certified infrastructure in Switzerland, where all content data is stored. Safe Swiss Cloud is a Swiss provider and is not subject to the US CLOUD Act. The selectable Swiss LLM mode as well as document comparison, document splitter, case files, timeline, text recognition (OCR) and anonymisation also run via Safe Swiss Cloud. The basis is a data processing agreement pursuant to Art. 9 FADP.

Microsoft Azure (AI Processing via Azure OpenAI)

Microsoft Azure is used in standard mode for processing AI requests. The main location is the Switzerland North region, so that personal data remains in Switzerland. For certain functions, Microsoft may use other data centers within the selected geography (Switzerland/EU). Azure OpenAI (Model Provision): Processing preferably takes place in Switzerland (Switzerland North region); if a specific model is not available regionally, processing occurs in the selected geography (CH/EU). No model training with our content; prompts/outputs may be stored for up to 30 days for abuse monitoring; zero data retention is possible upon request. We optionally use customer-managed keys (CMK) via Azure Key Vault.

  • Accountability obligation (Art. 5 para. 2 GDPR): Microsoft supports us in fulfilling our proof obligations through appropriate documentation and audit reports for the duration of the contract.
  • Use of sub-processors (Art. 28 para. 2 GDPR): Microsoft may only use sub-processors with prior authorization. In case of general authorization, Microsoft informs – to the extent permitted – of changes in advance so that we can object.
  • Adherence to instructions (Art. 28 para. 3 GDPR): Microsoft processes data exclusively according to our documented instructions. Transfer to third countries or international organizations only occurs if there is a legal basis. If Microsoft is legally obligated to disclose data, Microsoft informs – to the extent permitted.
  • Confidentiality: All persons employed by Microsoft who come into contact with personal data are bound to confidentiality.
  • Technical and organizational measures (Art. 32 GDPR; Art. 1-3 DPO): Microsoft ensures a level of protection appropriate to the risk through encryption, access controls, pseudonymization, backup and recovery procedures, and regular security audits.
  • Assistance for data subject rights and DPIA (Art. 28 para. 3 lit. e-f GDPR): Microsoft helps us, as far as possible, to respond to requests for access, deletion, or portability and to conduct data protection impact assessments.
  • Return/Deletion (Art. 28 para. 3 lit. g GDPR): Upon contract termination, all personal data is, at our choice, deleted or returned, unless a legal retention obligation precludes this.
  • Evidence and audits (Art. 28 para. 3 lit. h GDPR): Microsoft provides us with necessary information and enables audits, including independent reviews.
  • Liability for sub-processors (Art. 28 para. 4 GDPR): Microsoft ensures that engaged third parties comply with the same data protection obligations and is responsible for their compliance.
  • Data security level (Art. 32 GDPR): Microsoft and we jointly take appropriate technical and organizational measures to ensure the integrity, confidentiality, availability, and resilience of systems.
  • Data breach notification (Art. 33 GDPR; Art. 24 FADP): If Microsoft becomes aware of a personal data breach, Microsoft informs us immediately and provides all available information pursuant to Art. 33 para. 3 GDPR, so that we can fulfill our notification obligation to the FDPIC.

Google Firebase (Authentication)

For user account management (registration, login, password reset), we use Google Firebase Authentication. Google Ireland Limited (for EEA/Switzerland) or Google LLC (USA) acts as processor pursuant to Art. 9 FADP and Art. 28 GDPR.

  • Data types:: Email addresses; Passwords (encrypted, hash method); User-Agent strings and IP addresses (to increase security and detect abuse)
  • Retention:: Authentication data remains in the system until user account deletion. Thereafter, data is removed from live and backup systems within a maximum of 180 days.
  • International data transfer:: Firebase Authentication is operated in the USA. Transfer of personal data to the USA is secured by: Standard Contractual Clauses (SCCs, 2021 version) pursuant to Art. 16 FADP and Art. 46 GDPR; Swiss-U.S. Data Privacy Framework (status 2023); Supplementary technical measures such as encryption and access restrictions
  • Certifications and security standards:: Firebase Authentication is certified according to the following standards: ISO 27001 (Information Security Management); ISO 27017 (Cloud Security Controls); ISO 27018 (Data Protection in Public Clouds); SOC 1, SOC 2, SOC 3 (regular audit reports)
  • Adherence to instructions: Google processes data exclusively on documented instruction from the customer.
  • Confidentiality: Only authorized employees with corresponding confidentiality obligations have data access.
  • Technical and organizational measures: Google implements comprehensive TOMs including encryption, access controls, and regular security audits.
  • Assistance for data subject rights: Google helps us respond to requests for access, deletion, and portability under FADP/GDPR.
  • Assistance for DPIA: Google ensures that necessary information is available to conduct data protection impact assessments.
  • Sub-processors: Google may use sub-processors but informs transparently about their use. These are contractually obligated to comply with the same data protection standards.
  • Return/Deletion: After account closure, data is completely deleted or anonymized, unless a legal retention obligation precludes this.

Third-party APIs and sub-processors: are only integrated after review and contractual commitment.

7. Technical and Organizational Measures (TOMs)

We implement appropriate technical and organizational measures pursuant to Art. 1-3 DPO and data protection by design and by default (Art. 7 FADP). Additionally, we log accesses and processing pursuant to Art. 4 DPO where necessary. Measures are regularly reviewed for effectiveness and adapted to the state of the art.

Technical measures (excerpt):

  • Encryption at rest/in transit (e.g., AES-256, TLS 1.2+), key management with HSM/Key-Vault, rotation.
  • Access controls (MFA, SSO), network segmentation, least privilege, endpoint hardening.
  • Logging of security-relevant events (e.g., authentications, role changes); SIEM monitoring, alerts, evidence retention according to DPO.
  • Secure software development (code reviews, secrets management, dependency scans), vulnerability and patch management, regular penetration tests.
  • Backup/recovery strategy (regularly tested), business continuity and disaster recovery.

Organizational measures (excerpt):

  • Role and authorization concept (JML process), four-eyes principle and separation of duties in sensitive processes.
  • Data protection and security policy, employee training, confidentiality commitments.
  • Contractually regulated data processing (SCCs/DPF where necessary), sub-processor governance with change notifications.
  • Incident response process including notification system according to FADP/DPO; regular exercises.
  • Data classification, data minimization, pseudonymization/anonymization where possible; retention and deletion concept.

Process controls, evidence, and effectiveness:

  • Implementation and documentation obligation: We ensure that all described processes and measures are actually implemented and documented (TOM evidence, processor contracts, DPIA reports, action plans).
  • Effectiveness control: Regular reviews/audits (internal/external), technical controls (e.g., log analysis, access reviews, pen-test reports), management reviews, and continuous improvement.
  • Accountability artifacts: Record of processing activities, TOM inventory, training evidence, sub-processor list, risk register including CAPA measures (Corrective/Preventive Actions).
  • DPIA process: In case of high risk, we conduct a data protection impact assessment according to Art. 22 FADP: results, residual risks, and decided TOMs are documented, regularly reviewed, and updated if necessary.

Notes on logging and retention (clarification):

Security-relevant logs (accesses/processing) are kept so that it can be subsequently verified whether data was processed in accordance with its purpose; retention occurs in a risk-appropriate manner and in accordance with DPO requirements. Rationale and guidance: The above additions correspond to the FDPIC's guidance on TOMs (governance, implementation, evidence, effectiveness verification) and operationalize the DPO/FADP requirements for a SaaS environment.

8. Data Transfers to Third Countries

If transfer to third countries occurs, we ensure an adequate level of data protection pursuant to Art. 16 FADP and Art. 8-12 DPO through:

  • Use of Standard Contractual Clauses (SCCs)
  • Use of the Swiss-U.S. Data Privacy Framework (where applicable)
  • Conducting a risk assessment (Transfer Impact Assessment)
  • Supplementary technical protective measures (encryption, access restrictions)

9. Retention Period, Deletion, and Archiving

We retain personal data only as long as necessary for the respective purposes or as required by a legal obligation.

Specific timelines:

  • Security logs according to Art. 4 DPO (accesses/processing) are retained for at least 12 months.
  • Operational/application logs without personal reference: 90 days.
  • Business-relevant documents/correspondence according to CO 958f: 10 years.
  • AI content data: no permanent storage without consent; in Azure OpenAI use, abuse monitoring on the service side for up to 30 days, without model training.

Archiving:

If there is a legal obligation, personal data is kept exclusively for archiving purposes pursuant to Art. 6 para. 4 FADP. Archiving occurs exclusively in compliance with legal requirements and with appropriate technical and organizational protective measures (e.g., access restriction, encryption).

10. Data Subject Rights

Pursuant to Art. 25-29 FADP and Art. 16-22 DPO, you have the right to:

  • Information
  • Rectification
  • Deletion
  • Restriction of processing
  • Data portability
  • Objection
  • Complaint to the Federal Data Protection and Information Commissioner (FDPIC)

You also have the right to file a complaint with the Federal Data Protection and Information Commissioner (FDPIC) if you believe that the processing of your personal data violates data protection regulations: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland

www.edoeb.admin.ch

11. Data Protection Impact Assessment (DPIA)

Particularly sensitive personal data (Art. 5 lit. c FADP), in particular health data, biometric/genetic data, data on criminal/administrative proceedings/sanctions, social assistance measures. We conduct a preventive DPIA in case of high risk (Art. 22 FADP). DPIA retention: at least 2 years after end of processing (Art. 14 DPO).

12. Data Breach Notification

We notify data security breaches to the FDPIC as soon as possible if a high risk to personality or fundamental rights is likely (Art. 24 FADP). Content/documentation occurs according to Art. 16-22 DPO. Internally, we set a target of ≤72 hours to meet the notification obligation in a timely manner. We inform data subjects in case of high risk.

13. Processing Regulations

If particularly sensitive personal data is processed on a large scale or high-risk profiling is conducted, we create a record of processing activities (Art. 12 FADP).

14. Legal Disclosure Obligations

Transfer of personal data to authorities or courts only occurs if we are legally obligated. We carefully verify legality and inform the data subject to the extent permitted (Art. 19 FADP).

15. Changes to This Policy

We reserve the right to adapt this policy if legal changes or technical developments require it. The current version is always available on our website.

16. Data Protection by Design and by Default

We are committed to configuring data processing according to the 'Privacy by Design & Default' principle (Art. 7 FADP; Art. 25 GDPR). Already in planning, development, and selection of our systems and processes, we consider the principle of data minimization and implement privacy-friendly default settings. Personal data is always limited to what is necessary for the respective purpose, unless you expressly desire more extensive processing.

17. Confidentiality, Integrity, Availability, and Traceability

Our technical and organizational measures ensure:

  • Confidentiality: Access only for authorized persons,
  • Integrity: Protection against unauthorized or accidental changes,
  • Availability: Ensuring that data is available when needed,
  • Traceability: Comprehensive logging and auditing of accesses and processing.

For this purpose, we use access controls, logging pursuant to Art. 4 DPO, and regular security audits.

18. Assistance in Exercising Data Subject Rights

We ensure that you can exercise your rights as a data subject (information, rectification, deletion, restriction, objection, portability) easily and effectively. Requests are processed without delay, at the latest within 30 days (Art. 25 para. 5 FADP; Art. 12 para. 3 GDPR). If processing is not possible within this period, we inform you promptly of the reasons for the delay and the expected processing period.

19. Joint Controllership

In case of joint determination of purpose and means, we regulate responsibilities contractually (transparency, data subject rights, security measures, notifications). We inform pursuant to Art. 19 FADP about the essential content of these agreements.

Contact

For any questions about data protection, please contact us at: [email protected]