Last updated: 6 August 2026

Privacy Policy

1. Controller

AI Swiss Group klg Ruhsitzstrasse 29, 9000 St. Gallen, Switzerland UID: CHE-396.352.045 Email: info@aiswissgroup.ch This policy explains how we process personal data. It is written to meet the Swiss Federal Act on Data Protection (FADP / revDSG, in force since 1 September 2023) and, where our activities fall within its scope, the EU General Data Protection Regulation (GDPR). We are not required to appoint a Data Protection Officer. All data protection enquiries go to the address above and are handled by the partners. We have not appointed a representative in the EU under Art. 27 GDPR: our processing of data relating to persons in the EU/EEA is occasional, does not involve special categories of data on a large scale, and does not include large-scale monitoring of behaviour.

2. Website visitors

When you open our website, our hosting provider automatically records technical data: IP address, date and time, browser type and version, operating system, referring page and requested files. This is technically necessary to deliver the site and to protect it against attacks and misuse. Legal basis: our overriding legitimate interest in secure and stable operation (Art. 31 para. 1 FADP; Art. 6(1)(f) GDPR). Retention: server logs are deleted as soon as they are no longer needed for security purposes, at the latest after 12 months.

3. Enquiries via contact form, email, phone, Telegram and WhatsApp

We process the data you send us: name, email address, phone number, company, and the content of your message. We use it solely to respond and, if it leads to a project, to prepare and perform the contract. Submissions from the contact form on this website are delivered to us through a Telegram bot. Please note that Telegram and WhatsApp are operated by third parties outside Switzerland and that message content is processed on their infrastructure. If you prefer that your enquiry not pass through these services, use email. Legal basis: performance of a contract or pre-contractual measures (Art. 31 para. 2 lit. a FADP; Art. 6(1)(b) GDPR). Retention: enquiries that do not lead to a contract are deleted after 12 months.

4. Clients

For client relationships we process contact and billing details, contract documents, project correspondence, access credentials you provide, and payment data. Legal basis: performance of contract, and compliance with our statutory obligations, in particular the ten-year retention duty for business records under Art. 958f CO. Retention: 10 years from the end of the financial year in which the business relationship ended.

5. Client data inside projects we build

When we develop, host, maintain or support a website, bot or automation for a client, we may access personal data belonging to that client's own users. In that constellation the client is the controller and we act as a processor on their instructions only. This is governed by a separate data processing agreement; we do not use such data for our own purposes.

6. Cookies and analytics

We run no advertising or marketing trackers on this website. For usage statistics we use Umami, which we host ourselves on our own server. Umami works without cookies, does not create cross-site profiles and does not transmit data to a third-party analytics company. Aggregated figures such as page views, referrers and approximate country are recorded. The only cookie we set is a technical one that remembers your language choice. It is strictly necessary for the site to work in the language you selected, and it therefore requires no consent. Since we set no analytics or marketing cookies, we do not operate a consent banner. Details are set out in our Cookie Policy. Legal basis: overriding legitimate interest in understanding and improving the use of our website (Art. 31 para. 1 FADP; Art. 6(1)(f) GDPR).

7. Job applications

If you send us a job application, we process the documents you provide for the purpose of the selection process and delete them within 6 months of its conclusion, unless you agree to a longer retention.

8. Recipients and subprocessors

We do not sell personal data. We disclose it only to service providers who support our operations, bound by contract to process it solely on our instructions, and to authorities where we are legally required to do so. • Hetzner Online GmbH — hosting and delivery of this website; data centre in Nuremberg, Germany (EU). • Telegram FZ-LLC — delivery of contact-form submissions and communication channel. UAE. • WhatsApp Ireland Ltd. — communication channel, where you choose it. EU / USA. • Microsoft Ireland Operations Ltd. (Microsoft 365) — business email correspondence. EU / USA. • Umami — usage statistics; self-hosted on our own server in the EU, no transfer to a third party.

9. Transfers abroad

Some of the providers above process data outside Switzerland, in particular within the EU and, for the messaging services, in third countries. We transfer personal data to such countries only where an adequate level of protection is ensured — through a Federal Council adequacy decision, the Swiss–US Data Privacy Framework, or the EU Standard Contractual Clauses with the Swiss addendum, supplemented where necessary by additional safeguards. You can request a copy of the relevant safeguards from us.

10. Data security

We apply technical and organisational measures appropriate to the risk: TLS encryption in transit, access control on a need-to-know basis, multi-factor authentication for administrative accounts, encrypted credential storage, regular backups, and separation of client environments. We develop with reference to recognised standards, including the OWASP guidance and ISO/IEC 27001 as a framework; we do not hold an ISO/IEC 27001 certificate. No transmission over the internet can be guaranteed to be fully secure, and we cannot exclude all risk.

11. Your rights

Under Swiss law, and additionally under the GDPR where it applies, you may request: • access to the personal data we hold about you; • correction of inaccurate data; • deletion, or restriction of processing; • objection to processing based on legitimate interests; • data portability, where applicable; • withdrawal of consent at any time, with effect for the future. Write to info@aiswissgroup.ch. We may ask you to identify yourself before responding, to prevent disclosure to the wrong person. We answer within 30 days. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) or, if you are in the EU/EEA, with your national supervisory authority.

12. Obligation to provide data

You are not legally required to give us personal data. However, without the data needed to conclude and perform a contract, we cannot provide our services.

13. Automated decision-making

We do not make decisions producing legal effects concerning you based solely on automated processing.

14. Changes

We may update this policy to reflect changes in our services or in the law. The version published on our website applies.

Questions about data protection?

Write to us — enquiries are handled directly by the partners.

info@aiswissgroup.ch