SOTHURA SAFE
← Back to homepage
EN
DEDeutschFRFrançaisITItalianoENEnglish

Privacy Policy

The German version is binding. This translation is provided for information only.

Swiss Federal Act on Data Protection (revDSG, in force since 1 September 2023) · EU General Data Protection Regulation (GDPR) · Stand: August 2026 · Version: 2026-08-v1

1. Overview and dual role

SOTHURA SAFE GmbH, Wassergasse 5, 4573 Lohn-Ammannsegg, Switzerland (hereinafter "we", "us", "provider"), takes the protection of personal data seriously. This statement describes which personal data we process, for what purposes, on what legal basis, for how long and with whom we share it.

In the relationship with our customers (insurance intermediaries, brokers, broker pools, insurers), we act in a dual role:

  • Controller (Art. 5 lit. j revDSG / Art. 4(7) GDPR): for processing data of our registered users (user account, login, billing, support, website use).
  • Data processor (Art. 5 lit. k revDSG / Art. 4(8) GDPR): for processing data that our customers, as controllers, bring into the platform. In particular client and policy data. This processing takes place exclusively on the customer's instructions on the basis of a data processing agreement (DPA).

2. Controller and contact

SOTHURA SAFE GmbH
Wassergasse 5
4573 Lohn-Ammannsegg, Switzerland

Data protection contactdatenschutz [at] sothura [dot] com
Security incidentsecurity [at] sothura [dot] com
Postal addressSOTHURA SAFE GmbH, Wassergasse 5, 4573 Lohn-Ammannsegg

For data subjects in the EU/EEA, we accept enquiries via the address above. A representative under Art. 27 GDPR will be appointed and published here once the conditions for application are met.

3. Scope

This statement applies to the processing of personal data in connection with (i) visiting our website, (ii) using the SOTHURA SAFE platform (admin and customer portals, mobile access, APIs), (iii) initiating and performing B2B contracts, and (iv) communication via our email and appointment channels.

For data that our customers bring into the platform in their capacity as controllers, the customer's own privacy notices to its end clients apply primarily. We process such data only in accordance with the DPA.

4. Categories of personal data processed

4.1 User and contact data

  • Last name, first name, professional email address, phone number
  • Function, employer, organisational unit, role, location
  • Authentication data: password hashes (Argon2/bcrypt), 2FA secrets, session tokens
  • Consents, preferences, communication history

4.2 Client and advisory data (on behalf of our customers)

  • Master data of end clients (name, address, date of birth, contact)
  • AHV number, IBAN, tax data, professional and family situation
  • Insurance policies, pension certificates, claims history, offers
  • Consultation protocols, risk profiles, needs analyses, advisory documentation (Art. 45 ISA)
  • Uploaded documents and the content extracted from them

The data processed may include particularly sensitive personal data within the meaning of Art. 5 lit. c revDSG or special categories under Art. 9 GDPR (in particular health data for daily-allowance and life insurance policies). We process such data only on the basis of a valid DPA and with the security measures described in section 9.

4.3 Usage and technical data

  • IP address, user agent, device and browser information
  • Access and activity logs (timestamps, actions, endpoints)
  • Performance and error telemetry to stabilise the platform

4.4 Billing and contract data

  • Company, address, UID, VAT number, payment details
  • Invoices, dunning and communication history

4.5 AI processing data

  • Content of uploaded documents for analysis
  • Prompt history, model responses, error feedback for quality assurance
  • No use of identifiable customer data to train AI models

5. Purposes and legal bases

PurposeLegal basis (revDSG)Legal basis (GDPR, where applicable)
Provision and operation of the platformArt. 31(2)(a), performance of contractArt. 6(1)(b) GDPR
Authentication, access control, IT securityOverriding interest (Art. 31(2)(c))Art. 6(1)(b) and (f) GDPR
Invoicing and accountingLegal obligation (Art. 957 ff. CO)Art. 6(1)(b) and (c) GDPR
AI-supported analyses and recommendationsPerformance of contract, consentArt. 6(1)(b) or (a) GDPR
FINMA/compliance documentationLegal obligation, overriding interestArt. 6(1)(c) and (f) GDPR
Product development on an aggregated, anonymous basisOverriding interest (Art. 31(2)(c))Art. 6(1)(f) GDPR
Audit and evidence-preservation logsLegal obligation, legitimate interestArt. 6(1)(c) and (f) GDPR
Abuse prevention, fraud preventionOverriding interestArt. 6(1)(f) GDPR
B2B marketing to existing contacts (opt-out)Overriding interest, Art. 3 UCAArt. 6(1)(f) GDPR
Establishment, exercise or defence of legal claimsOverriding interestArt. 6(1)(f), Art. 9(2)(f) GDPR

6. AI processing and automated individual decisions

The platform uses artificial intelligence to extract documents, calculate policy comparisons, evaluate coverage, support advice and enable compliance checks.

No autonomous decisions with legal effect. All AI outputs are decision support for the advisors of our customers. Only the advisor takes the substantive decision vis-à-vis the end client and bears regulatory responsibility (Art. 3 VVG, Art. 45 ISA). Automated individual decision-making within the meaning of Art. 21 revDSG or Art. 22 GDPR does not take place.

Processing by AI services. To analyse documents and technical questions we use language models operated exclusively in data centres in Switzerland and the European Union. The legal basis is commissioned processing under Art. 9 revDSG. Training the models on your data is contractually excluded. For abuse prevention the provider may retain inputs and responses for a limited time and, where abuse is suspected, have its own staff review them; the data stays in the selected region and does not feed model training. The specific AI sub-processors are listed on the sub-processors page.

7. Categories of recipients and sub-processors

We disclose personal data to the following categories of recipients, in each case only to the extent necessary and on the basis of contractual safeguards:

  • Cloud and infrastructure providers for hosting, database, storage and key management. Data centres in Switzerland (Zurich) and the European Union
  • AI services for content analysis: Switzerland and the EU, no training on customer data
  • Email and transactional providers for sign-up, notification and support communication
  • Payment and accounting service providers for card payments, invoicing and dunning
  • Monitoring, logging and support tools to ensure operations
  • Integration partners, only when an integration has been activated by the customer (e.g. Microsoft 365 or comparable office and collaboration services)
  • Bearers of professional secrecy (lawyers, tax advisors, auditors, insurers) and authorities, where required by law
  • Legal successors in the event of restructuring, merger, demerger or business transaction

A current and versioned sub-processor list is maintained on the security page and updated with prior notice before any change.

No disclosure to non-contractual third parties for advertising purposes takes place.

8. Data transfer abroad

The primary data storage and customer database are located in Switzerland. Individual sub-services (in particular AI processing, email, support, monitoring) are provided in EU/EEA states or, in justified exceptional cases, in third countries such as the US.

For transfers to countries without an adequate level of protection, we ensure protection through:

  • EU Standard Contractual Clauses (SCC) in their current version, supplemented by the Swiss specifications recognised by the FDPIC;
  • additional technical measures (encryption at rest and in transit, field-level encryption of particularly sensitive data, own key sovereignty);
  • organisational measures (access controls, audit logs);
  • transfer impact assessments where indicated.

Where governmental authorities in third countries demand the disclosure of data, we examine each order for legal admissibility and inform the affected customer to the extent legally permitted.

Appointment booking on our website links out to Calendly, an external provider based in the USA; the details you enter there are subject to its own privacy terms.

9. Technical and organisational measures (TOMs)

Under the technical lead of the Head of Security and Infrastructure, the provider implements a layered security framework. The basis is the revDSG, the GDPR, the relevant FINMA circulars on operational risk and recognised standards. The underlying cloud infrastructure operates in data centres certified to ISO/IEC 27001 and SOC 2 Type II; the provider aligns with these standards as well as the NIST Cybersecurity Framework.

9.1 Cryptography

  • AES-256 encryption of data at rest
  • TLS 1.2+ encryption of data in transit, HSTS, Perfect Forward Secrecy
  • Own encryption keys with hardware-backed management; cryptographic deletion option via key revocation
  • Client-Side Field Level Encryption (CSFLE) for particularly sensitive fields (AHV number, IBAN, date of birth, policy number, claim numbers)
  • Regular key rotation; separation of data and key management

9.2 Network and infrastructure security

  • Private networking (network isolation, private endpoints), no public DB endpoints
  • Static Cloud NAT IP for outbound connections, IP allowlisting on critical interfaces
  • Separate service accounts with least privilege for app, analytics and backup
  • Web Application Firewall and rate limiting on ingress

9.3 Authentication and authorisation

  • Strict separation of admin auth and portal auth (no shared session surface)
  • Multi-factor authentication (MFA) for all provider employees
  • Role-based access control (RBAC) on the principle of least privilege
  • Session rotation, server-set HTTP-only cookies (tokens not in browser storage)
  • Signed URLs with a maximum validity of 15 minutes for file uploads

9.4 Tenant separation (multi-tenant isolation)

  • Strict logical separation of customer data at the database layer ("tenant scoping")
  • Fail-closed principle: if the tenant context is missing, no data is returned
  • Cross-tenant access is systematically prevented through integration and E2E tests

9.5 Mandatory security-gate catalogue (SG-001 to SG-009)

Every product change is verified before going live against the following catalogue of gates; evidence is documented in an audit-proof manner:

GateDescriptionMandatory evidence
SG-001Unauthenticated access to protected portal routes is deniedE2E redirect tests
SG-002Tenant fail-closed: no data access without tenant contextIntegration tests (empty results / 403)
SG-003Cross-tenant access strictly deniedIntegration and E2E negative tests (403)
SG-004Logout invalidates active session server-sideAPI test and E2E follow-up access
SG-005Tokens are not used as the primary strategy in browser storageCode review evidence
SG-006AI endpoints reachable only authenticated and tenant-scopedIntegration test 401/403
SG-007Signed-URL access is tenant-scopedIntegration test 401/403
SG-008Type check, linter and unit tests before rolloutCheck before push
SG-009Runtime smoke on the deployed revision (401/403/redirect)HTTP smokes against prod/staging

9.6 Audit, logging and monitoring

  • Audit-proof, immutable audit logs with retention of up to 10 years
  • Access, admin and AI prompt logs with timestamp and actor identity
  • 24/7 monitoring and anomaly-based alerting

9.7 Backup, recovery, resilience

  • Continuous backups with point-in-time recovery in Swiss data centres
  • Versioned storage buckets ("ransomware-resistant")
  • Documented restart and disaster recovery procedures

9.8 Secure development and deployment

  • Code review and four-eyes principle required for production-relevant changes
  • Dependency monitoring, automated vulnerability scans, patch management
  • Secret management via cloud key vault, no secrets in source code
  • Separate environments dev/staging/prod with IP-filtered prod ingress

9.9 Organisational measures

  • Data processing agreements (DPA) with all sub-processors
  • Data protection impact assessment (DPIA) for high-risk processing
  • Records of processing under Art. 12 revDSG / Art. 30 GDPR
  • Confidentiality obligation and annual training for all employees
  • Background checks for individuals with productive data access
  • Written incident response procedure, notification as quickly as possible (Art. 24 nFADP); for EU-related incidents additionally within 72 hours (GDPR Art. 33)

For further details and the changelog, see the security page at /en-ch/sicherheit.

10. Retention and deletion

Data categoryRetention
Active user accounts and contract dataDuration of the contractual relationship
Invoices and accounting records10 years (Art. 958f CO)
Advisory documentation (where stored by customers as controllers)Per the controller's instructions, typically 10 years
Audit and security logsup to 10 years (revDSG evidence, criminal prosecution)
Support communicationup to 3 years after last interaction
Marketing contacts (B2B, opt-out)until objection
Server and access logs (not security-relevant)up to 90 days

After the retention period expires, data is deleted or reliably anonymised. If statutory or contractual obligations prevent deletion, further processing is restricted.

11. Rights of data subjects

You have, in particular, the following rights:

  • Information (Art. 25 revDSG / Art. 15 GDPR), we will inform you within 30 days about the data we process about you.
  • Rectification of inaccurate data (Art. 32(1) revDSG / Art. 16 GDPR).
  • Erasure of data that is no longer required or that is processed unlawfully (Art. 32(2)(c) revDSG / Art. 17 GDPR).
  • Restriction of processing in case of dispute over accuracy or lawfulness (Art. 18 GDPR).
  • Data portability, provision in a common, machine-readable format (Art. 28 revDSG / Art. 20 GDPR).
  • Objection to processing based on overriding interest, and withdrawal of consent at any time with effect for the future.
  • Complaint to the competent supervisory authority (section 13).

To exercise your rights, please contact us at datenschutz [at] sothura [dot] com. To prevent identity misuse, we reserve the right to request appropriate proof of identity before providing information.

If your request concerns client data that a customer has brought into the platform as a controller, we will forward your request to the responsible customer or ask you to contact them directly.

12. Cookies and tracking

12.1 Technically necessary cookies

We use technically necessary session cookies for authentication, security (CSRF protection) and load balancing. These cookies do not require consent (Art. 45c TCA/analogous, Art. 25(2) TTDSG for Germany).

12.2 No consent-required cookies

We deliberately do without marketing trackers, advertising cookies and audience measurement. We therefore use no consent-required service and obtain no consent for cookies — which is why you will not see a cookie banner. The one exception to this restraint is Cloudflare Turnstile, which we use as technically necessary bot protection on our public forms (details in section 12.3). It relies on our overriding interest in the security and functionality of our services (Art. 31(1)(d) revDSG, Art. 6(1)(f) GDPR), not on your consent. Should we introduce consent-required services in future, we will inform you in advance and obtain your consent.

12.3 Cloudflare Turnstile (bot protection, technically necessary)

On public forms (e.g. the waitlist sign-up on this page), we use Cloudflare Turnstile, a captcha-free bot protection from Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA).

ProviderCloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
Data processedIP address, user agent, technical information about your browser (screen size, JavaScript environment), aggregated interaction patterns (mouse, keyboard, scroll). No cookies for recognition are set; Turnstile uses short-lived tokens (validity 5 minutes).
PurposeProtection against automated spam and abuse, and ensuring the availability of our services.
Legal basisArt. 31(1)(d) revDSG (overriding interest in security and functionality) and Art. 6(1)(f) GDPR (legitimate interest).
Data flow to the USProcessing takes place on Cloudflare edge servers worldwide, including the US. Cloudflare is certified under the EU-US Data Privacy Framework; in addition, Standard Contractual Clauses under Art. 46(2)(c) GDPR are in place.
Storage periodBot detection signals are kept on the Cloudflare edge only briefly. We ourselves do not store Turnstile data persistently.
Further informationCloudflare Privacy Policy

13. Supervisory authorities

The competent supervisory authorities for data subjects are in particular:

  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern. www.edoeb.admin.ch
  • EU/EEA: the data protection authority of your country of residence or of the place of the alleged infringement.

14. Security incidents and notification duties

We operate a written incident response procedure. We notify the FDPIC of personal data breaches likely to result in a high risk to the personality or fundamental rights of data subjects without delay under Art. 24 revDSG or within 72 hours under Art. 33 GDPR and, where required, the data subjects. We notify our customers in their capacity as controllers of incident-relevant events within 72 hours.

15. Minors

The platform is aimed exclusively at commercial users; it is not directed at minors. We do not knowingly process data of persons under 16 years of age for our own purposes.

16. Changes to this statement

We adapt this privacy policy when the legal situation, technology or processing activities change. The current version is available on this page with its version status. We additionally communicate material changes by email or through the platform.

17. Outlook add-in

For use in Microsoft Outlook we provide an Outlook add-in. In doing so, we process the following personal data:

  • The add-in runs inside Microsoft Outlook and becomes active only through a deliberate action by the user
  • On that trigger, it processes the content of the opened email and its attachments to file them in the client dossier on the platform
  • Sign-in to the add-in happens through the user's Microsoft account (Microsoft Entra ID); we receive the account details transmitted for that sign-in
  • The add-in is linked to the portal account by matching the Microsoft account's sign-in address against a portal account; where the match is unique, the link happens automatically, otherwise a one-time pairing code is required that the user generates in the portal and enters into the add-in

Storage 100 % in Switzerland; the AI analysis runs in Zurich and moves to an EU location only when Zurich is at capacity — processing therefore exclusively in Switzerland and the EU, client, contract and document data is not transferred to the US or other third countries.

The same purposes, legal bases and security measures that apply to the rest of the platform (Sect. 4–9) apply to the data processed through the add-in.

The formalities

SOTHURA SAFE GmbH, Wassergasse 5, 4573 Lohn-Ammannsegg, Canton of Solothurn. Registered in the commercial register of the Canton of Solothurn, UID CHE-429.131.582. Management is held by Silvio Siegenthaler and Michel Di Vito, joint signature by two. The full provider identification is set out in the legal notice.

  • Legal notice and provider identification
  • Security and data protection
  • General terms and conditions (B2B)
© 2026 SOTHURA SAFE GmbH. All rights reserved. Version 2026-08-v1.