Swiss Federal Act on Data Protection (revDSG, in force since 1 September 2023) · EU General Data Protection Regulation (GDPR) · Stand: August 2026 · Version: 2026-08-v1
SOTHURA SAFE GmbH, Wassergasse 5, 4573 Lohn-Ammannsegg, Switzerland (hereinafter "we", "us", "provider"), takes the protection of personal data seriously. This statement describes which personal data we process, for what purposes, on what legal basis, for how long and with whom we share it.
In the relationship with our customers (insurance intermediaries, brokers, broker pools, insurers), we act in a dual role:
SOTHURA SAFE GmbH
Wassergasse 5
4573 Lohn-Ammannsegg, Switzerland
| Data protection contact | datenschutz [at] sothura [dot] com |
|---|---|
| Security incident | security [at] sothura [dot] com |
| Postal address | SOTHURA SAFE GmbH, Wassergasse 5, 4573 Lohn-Ammannsegg |
For data subjects in the EU/EEA, we accept enquiries via the address above. A representative under Art. 27 GDPR will be appointed and published here once the conditions for application are met.
This statement applies to the processing of personal data in connection with (i) visiting our website, (ii) using the SOTHURA SAFE platform (admin and customer portals, mobile access, APIs), (iii) initiating and performing B2B contracts, and (iv) communication via our email and appointment channels.
For data that our customers bring into the platform in their capacity as controllers, the customer's own privacy notices to its end clients apply primarily. We process such data only in accordance with the DPA.
| Purpose | Legal basis (revDSG) | Legal basis (GDPR, where applicable) |
|---|---|---|
| Provision and operation of the platform | Art. 31(2)(a), performance of contract | Art. 6(1)(b) GDPR |
| Authentication, access control, IT security | Overriding interest (Art. 31(2)(c)) | Art. 6(1)(b) and (f) GDPR |
| Invoicing and accounting | Legal obligation (Art. 957 ff. CO) | Art. 6(1)(b) and (c) GDPR |
| AI-supported analyses and recommendations | Performance of contract, consent | Art. 6(1)(b) or (a) GDPR |
| FINMA/compliance documentation | Legal obligation, overriding interest | Art. 6(1)(c) and (f) GDPR |
| Product development on an aggregated, anonymous basis | Overriding interest (Art. 31(2)(c)) | Art. 6(1)(f) GDPR |
| Audit and evidence-preservation logs | Legal obligation, legitimate interest | Art. 6(1)(c) and (f) GDPR |
| Abuse prevention, fraud prevention | Overriding interest | Art. 6(1)(f) GDPR |
| B2B marketing to existing contacts (opt-out) | Overriding interest, Art. 3 UCA | Art. 6(1)(f) GDPR |
| Establishment, exercise or defence of legal claims | Overriding interest | Art. 6(1)(f), Art. 9(2)(f) GDPR |
The platform uses artificial intelligence to extract documents, calculate policy comparisons, evaluate coverage, support advice and enable compliance checks.
No autonomous decisions with legal effect. All AI outputs are decision support for the advisors of our customers. Only the advisor takes the substantive decision vis-à-vis the end client and bears regulatory responsibility (Art. 3 VVG, Art. 45 ISA). Automated individual decision-making within the meaning of Art. 21 revDSG or Art. 22 GDPR does not take place.
Processing by AI services. To analyse documents and technical questions we use language models operated exclusively in data centres in Switzerland and the European Union. The legal basis is commissioned processing under Art. 9 revDSG. Training the models on your data is contractually excluded. For abuse prevention the provider may retain inputs and responses for a limited time and, where abuse is suspected, have its own staff review them; the data stays in the selected region and does not feed model training. The specific AI sub-processors are listed on the sub-processors page.
We disclose personal data to the following categories of recipients, in each case only to the extent necessary and on the basis of contractual safeguards:
A current and versioned sub-processor list is maintained on the security page and updated with prior notice before any change.
No disclosure to non-contractual third parties for advertising purposes takes place.
The primary data storage and customer database are located in Switzerland. Individual sub-services (in particular AI processing, email, support, monitoring) are provided in EU/EEA states or, in justified exceptional cases, in third countries such as the US.
For transfers to countries without an adequate level of protection, we ensure protection through:
Where governmental authorities in third countries demand the disclosure of data, we examine each order for legal admissibility and inform the affected customer to the extent legally permitted.
Appointment booking on our website links out to Calendly, an external provider based in the USA; the details you enter there are subject to its own privacy terms.
Under the technical lead of the Head of Security and Infrastructure, the provider implements a layered security framework. The basis is the revDSG, the GDPR, the relevant FINMA circulars on operational risk and recognised standards. The underlying cloud infrastructure operates in data centres certified to ISO/IEC 27001 and SOC 2 Type II; the provider aligns with these standards as well as the NIST Cybersecurity Framework.
Every product change is verified before going live against the following catalogue of gates; evidence is documented in an audit-proof manner:
| Gate | Description | Mandatory evidence |
|---|---|---|
| SG-001 | Unauthenticated access to protected portal routes is denied | E2E redirect tests |
| SG-002 | Tenant fail-closed: no data access without tenant context | Integration tests (empty results / 403) |
| SG-003 | Cross-tenant access strictly denied | Integration and E2E negative tests (403) |
| SG-004 | Logout invalidates active session server-side | API test and E2E follow-up access |
| SG-005 | Tokens are not used as the primary strategy in browser storage | Code review evidence |
| SG-006 | AI endpoints reachable only authenticated and tenant-scoped | Integration test 401/403 |
| SG-007 | Signed-URL access is tenant-scoped | Integration test 401/403 |
| SG-008 | Type check, linter and unit tests before rollout | Check before push |
| SG-009 | Runtime smoke on the deployed revision (401/403/redirect) | HTTP smokes against prod/staging |
For further details and the changelog, see the security page at /en-ch/sicherheit.
| Data category | Retention |
|---|---|
| Active user accounts and contract data | Duration of the contractual relationship |
| Invoices and accounting records | 10 years (Art. 958f CO) |
| Advisory documentation (where stored by customers as controllers) | Per the controller's instructions, typically 10 years |
| Audit and security logs | up to 10 years (revDSG evidence, criminal prosecution) |
| Support communication | up to 3 years after last interaction |
| Marketing contacts (B2B, opt-out) | until objection |
| Server and access logs (not security-relevant) | up to 90 days |
After the retention period expires, data is deleted or reliably anonymised. If statutory or contractual obligations prevent deletion, further processing is restricted.
You have, in particular, the following rights:
To exercise your rights, please contact us at datenschutz [at] sothura [dot] com. To prevent identity misuse, we reserve the right to request appropriate proof of identity before providing information.
If your request concerns client data that a customer has brought into the platform as a controller, we will forward your request to the responsible customer or ask you to contact them directly.
We use technically necessary session cookies for authentication, security (CSRF protection) and load balancing. These cookies do not require consent (Art. 45c TCA/analogous, Art. 25(2) TTDSG for Germany).
We deliberately do without marketing trackers, advertising cookies and audience measurement. We therefore use no consent-required service and obtain no consent for cookies — which is why you will not see a cookie banner. The one exception to this restraint is Cloudflare Turnstile, which we use as technically necessary bot protection on our public forms (details in section 12.3). It relies on our overriding interest in the security and functionality of our services (Art. 31(1)(d) revDSG, Art. 6(1)(f) GDPR), not on your consent. Should we introduce consent-required services in future, we will inform you in advance and obtain your consent.
On public forms (e.g. the waitlist sign-up on this page), we use Cloudflare Turnstile, a captcha-free bot protection from Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA).
| Provider | Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA |
|---|---|
| Data processed | IP address, user agent, technical information about your browser (screen size, JavaScript environment), aggregated interaction patterns (mouse, keyboard, scroll). No cookies for recognition are set; Turnstile uses short-lived tokens (validity 5 minutes). |
| Purpose | Protection against automated spam and abuse, and ensuring the availability of our services. |
| Legal basis | Art. 31(1)(d) revDSG (overriding interest in security and functionality) and Art. 6(1)(f) GDPR (legitimate interest). |
| Data flow to the US | Processing takes place on Cloudflare edge servers worldwide, including the US. Cloudflare is certified under the EU-US Data Privacy Framework; in addition, Standard Contractual Clauses under Art. 46(2)(c) GDPR are in place. |
| Storage period | Bot detection signals are kept on the Cloudflare edge only briefly. We ourselves do not store Turnstile data persistently. |
| Further information | Cloudflare Privacy Policy |
The competent supervisory authorities for data subjects are in particular:
We operate a written incident response procedure. We notify the FDPIC of personal data breaches likely to result in a high risk to the personality or fundamental rights of data subjects without delay under Art. 24 revDSG or within 72 hours under Art. 33 GDPR and, where required, the data subjects. We notify our customers in their capacity as controllers of incident-relevant events within 72 hours.
The platform is aimed exclusively at commercial users; it is not directed at minors. We do not knowingly process data of persons under 16 years of age for our own purposes.
We adapt this privacy policy when the legal situation, technology or processing activities change. The current version is available on this page with its version status. We additionally communicate material changes by email or through the platform.
For use in Microsoft Outlook we provide an Outlook add-in. In doing so, we process the following personal data:
Storage 100 % in Switzerland; the AI analysis runs in Zurich and moves to an EU location only when Zurich is at capacity — processing therefore exclusively in Switzerland and the EU, client, contract and document data is not transferred to the US or other third countries.
The same purposes, legal bases and security measures that apply to the rest of the platform (Sect. 4–9) apply to the data processed through the add-in.
SOTHURA SAFE GmbH, Wassergasse 5, 4573 Lohn-Ammannsegg, Canton of Solothurn. Registered in the commercial register of the Canton of Solothurn, UID CHE-429.131.582. Management is held by Silvio Siegenthaler and Michel Di Vito, joint signature by two. The full provider identification is set out in the legal notice.