PCworld Atlas

Draft — pending legal review. This page is a structural template, not a finished privacy notice. Every [[PLACEHOLDER]] below must be filled in and the content approved by qualified Swiss counsel before it is relied upon.

Privacy Notice

Effective date: [[EFFECTIVE_DATE]] · Last updated: [[EFFECTIVE_DATE]]

This notice explains how PCworld Atlas (“the Service”) processes personal data under the revised Swiss Federal Act on Data Protection (nFADP) and, where applicable, the EU GDPR. It is issued by the controller identified below.

1. Controller & contact

The controller for data processed to operate the Service is:

Where a customer organization (“tenant”) uses the Service to manage its own customers, suppliers, or employees, that organization is itself the controller for the personal data it enters about those people, and we process it on the organization’s behalf. This notice covers our own processing as controller (visitors and registered users) and, in that capacity, as processor for tenant-entered data.

2. Who this notice covers

3. What we collect and why

The Service processes the following categories of personal data:

5. Subprocessors & recipients

We share personal data with the following categories of subprocessors, strictly to operate the Service:

SubprocessorRoleData involved
StripePayment processing & subscription billingBilling contact details, payment metadata
SMTP relay ([[EMAIL_PROVIDER_NAME]])Transactional email deliveryRecipient name/email, message content (e.g. invoices, invites)
OCR microservice ([[OCR_PROVIDER_NAME]])Extracts data from uploaded supplier-bill imagesSupplier invoice documents (stateless processing)
Object storage / hosting ([[HOSTING_PROVIDER_NAME]])Stores uploaded documents and generated PDFsInvoices, quotes, payslips, bill attachments, export archives
Error monitoring (self-hosted, Sentry-compatible)Application error & crash diagnosticsTechnical error context, which may incidentally include identifiers

A full, signed Data Processing Agreement covering these subprocessors is available on request: [[DPA_REQUEST_CONTACT]].

6. Cross-border data transfers

Personal data is primarily processed in Switzerland. Some subprocessors above (notably Stripe, our email relay, and error monitoring) may process data outside Switzerland, including in the EU/EEA or elsewhere. Where that happens, we rely on an applicable adequacy decision or on recognized safeguards such as the EU Standard Contractual Clauses as accepted under the FADP. [[TRANSFER_SAFEGUARD_DETAILS]]

7. Retention

8. Your rights

Subject to the retention constraints described above, you have the right to:

To exercise any of these rights, contact [[CONTACT_EMAIL]]. If your data was entered by an organization you are a customer, supplier, or employee of, that organization’s administrator is often the fastest route, since it is the controller for data it entered about you.

9. Cookies

The Service uses only essential, first-party cookies: your authentication session, security (CSRF) protection, and your language/theme preference. We do not use third-party advertising or tracking cookies.

10. Changes to this notice

We may update this notice from time to time. Material changes will be communicated via [[CHANGE_NOTIFICATION_METHOD]]. The “last updated” date above reflects the most recent revision.

11. Contact

Questions about this notice or how your data is processed: [[CONTACT_EMAIL]].


See also our Terms of Service.