SOTHURA SAFE
← Back to homepage

Privacy Policy

The German version is binding. This translation is provided for information only.

Swiss Federal Act on Data Protection (revDSG, in force since 1 September 2023) · EU General Data Protection Regulation (GDPR) · Stand: Juli 2026 · Version: 2026-04-v2

1. Overview and dual role

SOTHURA SAFE GmbH, Wassergasse 5, 4573 Lohn-Ammannsegg, Switzerland (hereinafter "we", "us", "provider"), takes the protection of personal data seriously. This statement describes which personal data we process, for what purposes, on what legal basis, for how long and with whom we share it.

In the relationship with our customers (insurance intermediaries, brokers, broker pools, insurers), we act in a dual role:

  • Controller (Art. 5 lit. j revDSG / Art. 4(7) GDPR): for processing data of our registered users (user account, login, billing, support, website use).
  • Data processor (Art. 5 lit. k revDSG / Art. 4(8) GDPR): for processing data that our customers, as controllers, bring into the platform. In particular client and policy data. This processing takes place exclusively on the customer's instructions on the basis of a data processing agreement (DPA).

2. Controller and contact

SOTHURA SAFE GmbH
Wassergasse 5
4573 Lohn-Ammannsegg, Switzerland

Data protection contactdatenschutz [at] sothura [dot] com
Security incidentsecurity [at] sothura [dot] com
Postal addressSOTHURA SAFE GmbH, Wassergasse 5, 4573 Lohn-Ammannsegg

For data subjects in the EU/EEA, we accept enquiries via the address above. A representative under Art. 27 GDPR will be appointed and published here once the conditions for application are met.

3. Scope

This statement applies to the processing of personal data in connection with (i) visiting our website, (ii) using the SOTHURA SAFE platform (admin and customer portals, mobile access, APIs), (iii) initiating and performing B2B contracts, and (iv) communication via our email and appointment channels.

For data that our customers bring into the platform in their capacity as controllers, the customer's own privacy notices to its end clients apply primarily. We process such data only in accordance with the DPA.

4. Categories of personal data processed

4.1 User and contact data

  • Last name, first name, professional email address, phone number
  • Function, employer, organisational unit, role, location
  • Authentication data: password hashes (Argon2/bcrypt), 2FA secrets, session tokens
  • Consents, preferences, communication history

4.2 Client and advisory data (on behalf of our customers)

  • Master data of end clients (name, address, date of birth, contact)
  • AHV number, IBAN, tax data, professional and family situation
  • Insurance policies, pension certificates, claims history, offers
  • Consultation protocols, risk profiles, needs analyses, advisory documentation (Art. 45 ISA)
  • Uploaded documents and the content extracted from them

The data processed may include particularly sensitive personal data within the meaning of Art. 5 lit. c revDSG or special categories under Art. 9 GDPR (in particular health data for daily-allowance and life insurance policies). We process such data only on the basis of a valid DPA and with the security measures described in section 9.

4.3 Usage and technical data

  • IP address, user agent, device and browser information
  • Access and activity logs (timestamps, actions, endpoints)
  • Performance and error telemetry to stabilise the platform

4.4 Billing and contract data

  • Company, address, UID, VAT number, payment details
  • Invoices, dunning and communication history

4.5 AI processing data

  • Content of uploaded documents for analysis
  • Prompt history, model responses, error feedback for quality assurance
  • No use of identifiable customer data to train AI models

5. Purposes and legal bases

PurposeLegal basis (revDSG)Legal basis (GDPR, where applicable)
Provision and operation of the platformArt. 31(2)(a), performance of contractArt. 6(1)(b) GDPR
Authentication, access control, IT securityOverriding interest (Art. 31(2)(c))Art. 6(1)(b) and (f) GDPR
Invoicing and accountingLegal obligation (Art. 957 ff. CO)Art. 6(1)(b) and (c) GDPR
AI-supported analyses and recommendationsPerformance of contract, consentArt. 6(1)(b) or (a) GDPR
FINMA/compliance documentationLegal obligation, overriding interestArt. 6(1)(c) and (f) GDPR
Product development on an aggregated, anonymous basisOverriding interest (Art. 31(2)(c))Art. 6(1)(f) GDPR
Audit and evidence-preservation logsLegal obligation, legitimate interestArt. 6(1)(c) and (f) GDPR
Abuse prevention, fraud preventionOverriding interestArt. 6(1)(f) GDPR
B2B marketing to existing contacts (opt-out)Overriding interest, Art. 3 UCAArt. 6(1)(f) GDPR
Establishment, exercise or defence of legal claimsOverriding interestArt. 6(1)(f), Art. 9(2)(f) GDPR

6. AI processing and automated individual decisions

The platform uses artificial intelligence to extract documents, calculate policy comparisons, evaluate coverage, support advice and enable compliance checks.

No autonomous decisions with legal effect. All AI outputs are decision support for the advisors of our customers. Only the advisor takes the substantive decision vis-à-vis the end client and bears regulatory responsibility (Art. 3 VVG, Art. 45 ISA). Automated individual decision-making within the meaning of Art. 21 revDSG or Art. 22 GDPR does not take place.

Processing by AI services. To analyse documents and technical questions we use language models operated exclusively in data centres in Switzerland and the European Union. The legal basis is commissioned processing under Art. 9 revDSG. Transmitted content is processed transiently in memory and is not stored at the provider; training the models on your data and any human review by the provider are contractually excluded. The specific AI sub-processors are listed on the sub-processors page.

7. Categories of recipients and sub-processors

We disclose personal data to the following categories of recipients, in each case only to the extent necessary and on the basis of contractual safeguards:

  • Cloud and infrastructure providers for hosting, database, storage and key management. Data centres in Switzerland (Zurich) and the European Union
  • AI services for content analysis: Switzerland and the EU, no training on customer data
  • Email and transactional providers for sign-up, notification and support communication
  • Payment and accounting service providers for card payments, invoicing and dunning
  • Monitoring, logging and support tools to ensure operations
  • Integration partners, only when an integration has been activated by the customer (e.g. Microsoft 365 or comparable office and collaboration services)
  • Bearers of professional secrecy (lawyers, tax advisors, auditors, insurers) and authorities, where required by law
  • Legal successors in the event of restructuring, merger, demerger or business transaction

A current and versioned sub-processor list is maintained on the security page and updated with prior notice before any change.

No disclosure to non-contractual third parties for advertising purposes takes place.

8. Data transfer abroad

The primary data storage and customer database are located in Switzerland. Individual sub-services (in particular AI processing, email, support, monitoring) are provided in EU/EEA states or. In justified exceptional cases, in third countries such as the US.

For transfers to countries without an adequate level of protection, we ensure protection through:

  • EU Standard Contractual Clauses (SCC) in their current version, supplemented by the Swiss specifications recognised by the FDPIC;
  • additional technical measures (encryption at rest and in transit, field-level encryption of particularly sensitive data, own key sovereignty);
  • organisational measures (access controls, audit logs);
  • transfer impact assessments where indicated.

Where governmental authorities in third countries demand the disclosure of data, we examine each order for legal admissibility and inform the affected customer to the extent legally permitted.

9. Technical and organisational measures (TOMs)

Under the technical lead of the Head of Security and Infrastructure, the provider implements a layered security framework. The basis is the revDSG, the GDPR, the relevant FINMA circulars on operational risk and recognised standards. The underlying cloud infrastructure operates in data centres certified to ISO/IEC 27001 and SOC 2 Type II; the provider aligns with these standards as well as the NIST Cybersecurity Framework.

9.1 Cryptography

  • AES-256 encryption of data at rest
  • TLS 1.2+ encryption of data in transit, HSTS, Perfect Forward Secrecy
  • Own encryption keys with hardware-backed management; cryptographic deletion option via key revocation
  • Client-Side Field Level Encryption (CSFLE) for particularly sensitive fields (AHV number, IBAN, date of birth, policy number, claim numbers)
  • Regular key rotation; separation of data and key management

9.2 Network and infrastructure security

  • Private networking (network isolation, private endpoints), no public DB endpoints
  • Static Cloud NAT IP for outbound connections, IP allowlisting on critical interfaces
  • Separate service accounts with least privilege for app, analytics and backup
  • Web Application Firewall and rate limiting on ingress

9.3 Authentication and authorisation

  • Strict separation of admin auth and portal auth (no shared session surface)
  • Multi-factor authentication (MFA) for all provider employees
  • Role-based access control (RBAC) on the principle of least privilege
  • Session rotation, server-set HTTP-only cookies (tokens not in browser storage)
  • Signed URLs with a maximum validity of 15 minutes for file uploads

9.4 Tenant separation (multi-tenant isolation)

  • Strict logical separation of customer data at the database layer ("tenant scoping")
  • Fail-closed principle: if the tenant context is missing, no data is returned
  • Cross-tenant access is systematically prevented through integration and E2E tests

9.5 Mandatory security-gate catalogue (SG-001 to SG-009)

Every product change is verified before going live against the following catalogue of gates; evidence is documented in an audit-proof manner:

GateDescriptionMandatory evidence
SG-001Unauthenticated access to protected portal routes is deniedE2E redirect tests
SG-002Tenant fail-closed: no data access without tenant contextIntegration tests (empty results / 403)
SG-003Cross-tenant access strictly deniedIntegration and E2E negative tests (403)
SG-004Logout invalidates active session server-sideAPI test and E2E follow-up access
SG-005Tokens are not used as the primary strategy in browser storageCode review evidence
SG-006AI endpoints reachable only authenticated and tenant-scopedIntegration test 401/403
SG-007Signed-URL access is tenant-scopedIntegration test 401/403
SG-008Build and test pipeline green (tsc, lint, integration tests, E2E tests)CI run
SG-009Runtime smoke on the deployed revision (401/403/redirect)HTTP smokes against prod/staging

9.6 Audit, logging and monitoring

  • Audit-proof, immutable audit logs with retention of up to 10 years
  • Access, admin and AI prompt logs with timestamp and actor identity
  • 24/7 monitoring and anomaly-based alerting

9.7 Backup, recovery, resilience

  • Continuous backups with point-in-time recovery in Swiss data centres
  • Versioned storage buckets ("ransomware-resistant")
  • Documented restart and disaster recovery procedures

9.8 Secure development and deployment

  • Code review and four-eyes principle required for production-relevant changes
  • Dependency monitoring, automated vulnerability scans, patch management
  • Secret management via cloud key vault, no secrets in source code
  • Separate environments dev/staging/prod with IP-filtered prod ingress

9.9 Organisational measures

  • Data processing agreements (DPA) with all sub-processors
  • Data protection impact assessment (DPIA) for high-risk processing
  • Records of processing under Art. 12 revDSG / Art. 30 GDPR
  • Confidentiality obligation and annual training for all employees
  • Background checks for individuals with productive data access
  • Written incident response procedure, notification as quickly as possible (Art. 24 nFADP); for EU-related incidents additionally within 72 hours (GDPR Art. 33)

For further details and the changelog, see the security page at /en-ch/sicherheit.

10. Retention and deletion

Data categoryRetention
Active user accounts and contract dataDuration of the contractual relationship
Invoices and accounting records10 years (Art. 958f CO)
Advisory documentation (where stored by customers as controllers)Per the controller's instructions, typically 10 years
Audit and security logsup to 10 years (revDSG evidence, criminal prosecution)
Support communicationup to 3 years after last interaction
Marketing contacts (B2B, opt-out)until objection
Server and access logs (not security-relevant)up to 90 days

After the retention period expires, data is deleted or reliably anonymised. If statutory or contractual obligations prevent deletion, further processing is restricted.

11. Rights of data subjects

You have, in particular, the following rights:

  • Information (Art. 25 revDSG / Art. 15 GDPR), we will inform you within 30 days about the data we process about you.
  • Rectification of inaccurate data (Art. 32(1) revDSG / Art. 16 GDPR).
  • Erasure of data that is no longer required or that is processed unlawfully (Art. 32(2)(c) revDSG / Art. 17 GDPR).
  • Restriction of processing in case of dispute over accuracy or lawfulness (Art. 18 GDPR).
  • Data portability, provision in a common, machine-readable format (Art. 28 revDSG / Art. 20 GDPR).
  • Objection to processing based on overriding interest, and withdrawal of consent at any time with effect for the future.
  • Complaint to the competent supervisory authority (section 13).

To exercise your rights, please contact us at datenschutz [at] sothura [dot] com. To prevent identity misuse, we reserve the right to request appropriate proof of identity before providing information.

If your request concerns client data that a customer has brought into the platform as a controller, we will forward your request to the responsible customer or ask you to contact them directly.

12. Cookies, tracking and website analysis

12.1 Technically necessary cookies and local storage

We use technically necessary session cookies for authentication, security (CSRF protection) and load balancing. These cookies do not require consent (Art. 45c TCA/analogous, Art. 25(2) TTDSG for Germany). In addition, we store your cookie consent and a randomly generated visitor identifier without account reference in your browser's localStorage in order to remember your choice on subsequent visits.

12.2 Usage statistics with PostHog (consent required)

With your consent, we use PostHog, a product analytics tool operated by PostHog Inc. We use the EU cloud instance (hosting in Frankfurt, Germany) and collect only anonymised page views and interactions to understand platform usage and improve the product. We do not use PostHog for advertising, cross-site tracking or profiling within the meaning of Art. 5 lit. f revDSG. Session recordings are disabled.

ProviderPostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA
HostingEU cloud (eu.i.posthog.com), Frankfurt
Data categoriesPseudonymous visitor ID (localStorage), page view URL, time spent, browser type, language setting, screen resolution, technical telemetry
Legal basisConsent (Art. 6(6) revDSG / Art. 6(1)(a) GDPR)
Storage periodup to 12 months (PostHog default), immediate termination on withdrawal
Third-country transferHosting in the EU; parent company in the US: Standard Contractual Clauses (SCC) plus supplementary measures

12.3 Your choices

On your first visit you will see a cookie banner with three options: "Accept all", "Essential only" and "Settings" (for individual selection). Without your consent, PostHog is not loaded. The platform continues to work without restriction.

You can withdraw your consent at any time. To do so, delete the entry sothura-cookie-consent from your browser's local storage settings (DevTools → Application → Local Storage), or contact us at datenschutz [at] sothura [dot] com. We are happy to help. A central withdrawal button in the footer is in preparation.

For each consent we keep an anonymised audit entry (visitor ID, choice, time, hashed IP) to fulfil our duty of evidence under Art. 12 revDSG and Art. 7(1) GDPR.

12.4 No further trackers

We deliberately do without marketing trackers and advertising cookies. One exception is Cloudflare Turnstile, which we use as technically necessary bot protection on our public forms (details in section 12.5). Should we introduce further consent-required services, we will extend the consent banner accordingly and ask you for consent again.

12.5 Cloudflare Turnstile (bot protection, technically necessary)

On public forms (e.g. the waitlist sign-up on this page), we use Cloudflare Turnstile, a captcha-free bot protection from Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA).

ProviderCloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
Data processedIP address, user agent, technical information about your browser (screen size, JavaScript environment), aggregated interaction patterns (mouse, keyboard, scroll). No cookies for recognition are set; Turnstile uses short-lived tokens (validity 5 minutes).
PurposeProtection against automated spam and abuse, and ensuring the availability of our services.
Legal basisArt. 31(1)(d) revDSG (overriding interest in security and functionality) and Art. 6(1)(f) GDPR (legitimate interest).
Data flow to the USProcessing takes place on Cloudflare edge servers worldwide, including the US. Cloudflare is certified under the EU-US Data Privacy Framework; in addition, Standard Contractual Clauses under Art. 46(2)(c) GDPR are in place.
Storage periodBot detection signals are kept on the Cloudflare edge only briefly. We ourselves do not store Turnstile data persistently.
Further informationCloudflare Privacy Policy

13. Supervisory authorities

The competent supervisory authorities for data subjects are in particular:

  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern. www.edoeb.admin.ch
  • EU/EEA: the data protection authority of your country of residence or of the place of the alleged infringement.

14. Security incidents and notification duties

We operate a written incident response procedure. We notify the FDPIC of personal data breaches likely to result in a high risk to the personality or fundamental rights of data subjects without delay under Art. 24 revDSG or within 72 hours under Art. 33 GDPR and, where required, the data subjects. We notify our customers in their capacity as controllers of incident-relevant events within 72 hours.

15. Minors

The platform is aimed exclusively at commercial users; it is not directed at minors. We do not knowingly process data of persons under 16 years of age for our own purposes.

16. Changes to this statement

We adapt this privacy policy when the legal situation, technology or processing activities change. The current version is available on this page with its version status. We additionally communicate material changes by email or through the platform.

© 2026 SOTHURA SAFE GmbH. All rights reserved. Version 2026-04-v2.