Draft — pending legal review. This page is a structural template, not a finished privacy notice. Every [[PLACEHOLDER]] below must be filled in and the content approved by qualified Swiss counsel before it is relied upon.
Privacy Notice
Effective date: [[EFFECTIVE_DATE]] · Last updated: [[EFFECTIVE_DATE]]
This notice explains how PCworld Atlas (“the Service”) processes personal data under the revised Swiss Federal Act on Data Protection (nFADP) and, where applicable, the EU GDPR. It is issued by the controller identified below.
1. Controller & contact
The controller for data processed to operate the Service is:
[[COMPANY_LEGAL_NAME]][[COMPANY_ADDRESS]], Switzerland- UID/CHE number:
[[COMPANY_UID_CHE_NUMBER]] - Contact:
[[CONTACT_EMAIL]] - Data protection contact (if designated):
[[DPO_CONTACT_EMAIL]]
Where a customer organization (“tenant”) uses the Service to manage its own customers, suppliers, or employees, that organization is itself the controller for the personal data it enters about those people, and we process it on the organization’s behalf. This notice covers our own processing as controller (visitors and registered users) and, in that capacity, as processor for tenant-entered data.
2. Who this notice covers
- Visitors to our public pages.
- Registered users who log into an organization (“tenant users”).
- Business contacts (customers, suppliers) that a tenant organization enters into the Service.
- Employees whose payroll a tenant organization processes through the Service.
3. What we collect and why
The Service processes the following categories of personal data:
- Account & session data — name, email address, profile image; short-lived session metadata (IP address, user agent) kept only long enough to detect anomalous logins. Purpose: authentication, account security, fraud prevention.
- Organization (tenant) data — organization name, legal address, VAT number, bank account details. Purpose: operating the ERP service, invoicing the tenant.
- Business contacts — names, emails, phone numbers, addresses, and VAT numbers of a tenant’s own customers and suppliers, entered by the tenant. Purpose: enabling the tenant’s invoicing, quoting, and CRM activity.
- Employee & payroll data — name, date of birth, Swiss social-security (AHV) number, address, IBAN, marital status, number of children, residence-permit type, contract and salary terms. Purpose: payroll processing on behalf of the tenant employer.
- Financial & accounting records — invoices, quotes, bills, payments, journal entries, payslips. Purpose: bookkeeping and statutory accounting compliance.
- Support & diagnostics — support tickets, audit/security logs, application error reports. Purpose: customer support, security, service reliability.
- Marketing (optional) — email address, only if you opt in to newsletter communications at registration. Purpose: product updates. You can unsubscribe at any time.
4. Legal basis
- Performance of the contract between you (or your organization) and us.
- Legitimate interest — account security, fraud prevention, and service reliability monitoring.
- Legal obligation — Swiss accounting law (Art. 958f CO) and applicable social-insurance law for payroll data.
- Consent — only for the optional newsletter opt-in, withdrawable at any time.
5. Subprocessors & recipients
We share personal data with the following categories of subprocessors, strictly to operate the Service:
| Subprocessor | Role | Data involved |
|---|---|---|
| Stripe | Payment processing & subscription billing | Billing contact details, payment metadata |
SMTP relay ([[EMAIL_PROVIDER_NAME]]) | Transactional email delivery | Recipient name/email, message content (e.g. invoices, invites) |
OCR microservice ([[OCR_PROVIDER_NAME]]) | Extracts data from uploaded supplier-bill images | Supplier invoice documents (stateless processing) |
Object storage / hosting ([[HOSTING_PROVIDER_NAME]]) | Stores uploaded documents and generated PDFs | Invoices, quotes, payslips, bill attachments, export archives |
| Error monitoring (self-hosted, Sentry-compatible) | Application error & crash diagnostics | Technical error context, which may incidentally include identifiers |
A full, signed Data Processing Agreement covering these subprocessors is available on request: [[DPA_REQUEST_CONTACT]].
6. Cross-border data transfers
Personal data is primarily processed in Switzerland. Some subprocessors above (notably Stripe, our email relay, and error monitoring) may process data outside Switzerland, including in the EU/EEA or elsewhere. Where that happens, we rely on an applicable adequacy decision or on recognized safeguards such as the EU Standard Contractual Clauses as accepted under the FADP. [[TRANSFER_SAFEGUARD_DETAILS]]
7. Retention
- Accounting records — invoices, bills, payments, journal entries, and payslips are retained 10 years, as required by Swiss law (Art. 958f CO). This period cannot be shortened by an erasure request; instead, an erasure request anonymizes the identity fields on the referenced customer, supplier, or employee record while the document itself is preserved intact.
- Session security telemetry — IP address and user agent on session records are automatically cleared after a short, configurable retention window once they are no longer needed to detect anomalous logins.
- Terminated-employee HR data — cleared field-by-field on separate schedules tied to when each field’s purpose ends: bank details once payroll is fully settled (plus a short correction window); contact details, civil status, date of birth, and residence-permit type at the fiscal year-end following termination; the AHV/social-security number after an additional statutory floor beyond that. Payslip PDFs themselves remain for the full 10-year accounting period regardless, as they are themselves accounting records.
- Deleted organizations — kept in a recoverable, soft-deleted state for a grace period to allow export, then permanently purged (including the associated Stripe customer record), except for accounting records, which survive in anonymized form for the statutory period above.
- Uploaded documents never attached to a record — automatically purged after a short window.
- Audit & security logs — retained as an accountability record and are not subject to erasure, since an audit trail of who did what is itself a legal basis for retention.
8. Your rights
Subject to the retention constraints described above, you have the right to:
- Access the personal data we (or a tenant, as controller) hold about you.
- Request rectification of inaccurate data.
- Request erasure — for data outside the 10-year accounting retention, this means deletion; for data referenced by a retained accounting record, this means anonymizing your identity on that record rather than deleting the record itself.
- Request a portable export of your data.
- Object to processing based on legitimate interest.
- Withdraw consent at any time (e.g. the newsletter opt-in), without affecting processing already carried out.
- Lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC/EDÖB).
To exercise any of these rights, contact [[CONTACT_EMAIL]]. If your data was entered by an organization you are a customer, supplier, or employee of, that organization’s administrator is often the fastest route, since it is the controller for data it entered about you.
9. Cookies
The Service uses only essential, first-party cookies: your authentication session, security (CSRF) protection, and your language/theme preference. We do not use third-party advertising or tracking cookies.
10. Changes to this notice
We may update this notice from time to time. Material changes will be communicated via [[CHANGE_NOTIFICATION_METHOD]]. The “last updated” date above reflects the most recent revision.
11. Contact
Questions about this notice or how your data is processed: [[CONTACT_EMAIL]].
See also our Terms of Service.