Legal
Privacy policy
This privacy policy informs you about the personal data we process when you visit our website, use our contact form, open an account in the client portal or receive advice from us on insurance, tax, pension and relocation matters. It applies to the website profinio.swiss, the client portal (app.profinio.swiss) and the internal advisory software our advisers use to handle your matters.
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and the Data Protection Ordinance (DPO). Where the EU General Data Protection Regulation (GDPR) applies to individual processing operations, in particular for clients resident in Germany, France or Italy, we also comply with its requirements.
1. Controller and contact
The controller responsible for the processing described in this policy is:
[To be completed before publication: Firma gemäss Handelsregister], [To be completed before publication: Rechtsform]
[To be completed before publication: Strasse und Hausnummer], [To be completed before publication: PLZ und Ort], Switzerland
E-mail: [To be completed before publication: E-Mail-Adresse für Datenschutzanfragen]
Telephone: [To be completed before publication: Telefonnummer]
For all questions regarding data protection and the exercise of your rights (section 11), please contact the e-mail address given above. "Profinio" is [To be completed before publication: eigene Firma oder Marke der genannten Firma].
Optional section: Datenschutzberater nach Art. 10 DSG – nur falls eine Datenschutzberaterin oder ein Datenschutzberater ernannt wurde
Our data protection adviser (Art. 10 FADP) is: [To be completed before publication: Name und Kontakt des Datenschutzberaters].
Optional section: EU-Vertreter nach Art. 27 DSGVO – falls Personen mit Wohnsitz in der EU, insbesondere Grenzgängerinnen und Grenzgänger, aktiv angesprochen werden und keine Ausnahme nach Art. 27 Abs. 2 DSGVO greift; juristisch prüfen
For persons resident in the European Union, we have appointed the following representative pursuant to Art. 27 GDPR: [To be completed before publication: Name, Adresse und Kontakt des EU-Vertreters].
2. Definitions and scope
Personal data means all information relating to an identified or identifiable person. Sensitive personal data includes, among other things, information about health; such information may be contained in insurance documents (for example health insurance model, supplementary insurance, benefit statements). Processing covers any handling of personal data, such as collection, storage, use, disclosure and erasure.
This policy applies to:
- the public website profinio.swiss (also accessible via profinio.ch and profinio.it) with its contact form,
- the client portal, in which you record your profile, upload documents, record your insurance policies and exchange messages with your adviser,
- the advisory software (CRM) our staff use to handle your matters,
- e-mails and notifications sent by these systems.
This policy does not apply to third-party websites to which we link.
3. Principles and legal bases
We process personal data only lawfully, in good faith, proportionately and for the purposes stated at the time of collection or evident from the circumstances. We collect only information that is actually needed for the consultation (data minimisation), and we process your data for as long as is necessary for the purpose or required by statutory obligations (section 9).
Under the FADP, the processing of personal data by private companies does not require a specific legal basis as long as the statutory principles are observed. For the processing of sensitive personal data that we receive from you in the course of the consultation, we obtain your explicit consent (Art. 6 para. 7 FADP). Where the GDPR applies, we base our processing on the following grounds:
- Contract (Art. 6 para. 1 let. b GDPR): account, client profile, consultation, documents, messages, notifications.
- Explicit consent (Art. 6 para. 1 let. a and Art. 9 para. 2 let. a GDPR): sensitive data, in particular health information in insurance documents; disclosure to insurers or partners; marketing, where offered.
- Legitimate interest (Art. 6 para. 1 let. f GDPR): security, logging, prevention of misuse, backups, responding to contact enquiries.
- Legal obligation (Art. 6 para. 1 let. c GDPR): retention obligations, obligations under insurance supervision law, duties to provide information to authorities.
You may withdraw consent at any time with effect for the future (section 11).
4. Processing operations in detail
4.1 Visiting the website
When you access profinio.swiss, our web server processes the technically necessary connection data: IP address, time, page accessed, volume of data transferred, browser type and the previously visited page (referrer), where your browser transmits these. This information is used exclusively to deliver the pages, for security and for troubleshooting. It is not linked to other data and is not used to analyse your behaviour. Retention of server logs: [To be completed before publication: Aufbewahrungsdauer der Webserver-Logs (technisch zu bestätigen, Vorschlag höchstens 30 Tage)].
The website uses no cookies and no analytics or tracking tools. Fonts, images and all other resources are delivered from our own server; no data is transferred to third parties when you visit the website. For the language selection, your browser stores at most one local setting (section 6).
4.2 Contact form
When you send us an enquiry via the contact form, we process the information you enter: name, e-mail address, optionally telephone number and company, the topic selected (for example insurance, tax, pensions, relocation, cross-border commuters, business), your message, the language selected, as well as the time and the version of your consent to being contacted. Please do not enter any health information or information about third parties in the message field; we will discuss such details with you in a personal conversation or in the secure client portal.
Purpose: responding to your enquiry and allocating it to a responsible adviser. Access: responsible adviser, team lead and administration. Retention: enquiries that do not lead to a consultation are deleted after 6 months; if the enquiry leads to an advisory relationship, we transfer the information to your client file.
Protection against misuse: the form contains an invisible control field that detects automated entries without transferring data to third parties.
Optional section: Cloudflare Turnstile – nur falls der Spamschutz Turnstile aktiviert wird
In addition, we use the spam protection Cloudflare Turnstile from Cloudflare, Inc. (USA) on the contact page. Turnstile checks whether a request originates from a human and, for this purpose, processes technical characteristics of your browser and your IP address. Data may be transferred to the USA in the process (section 8). The basis is our legitimate interest in protecting the form against misuse. Turnstile is loaded only on the contact page. [To be completed before publication: Garantie für die Übermittlung an Cloudflare, Inc. (z. B. Data Privacy Framework oder Standardvertragsklauseln) – juristisch prüfen]
4.3 Registration and account in the client portal
To open an account, we collect your e-mail address, a password of your choice (stored only as a cryptographic hash) and your preferred language. We send you an e-mail to confirm your address; only after confirmation is your client file created and our administration informed of the new registration (without a name, only with your client number). When you log in, we process the time and technical session data to protect your account.
Purpose: access to the client portal, protection of your account. Retention: until the account is deleted; login logs 12 months.
Optional section: Login mit Google – nur falls der Google-Login beibehalten wird (Entscheid offen, Empfehlung: abschalten)
Alternatively, you can sign in with your Google account. In this case, Google LLC (USA) or Google Ireland Ltd. (Ireland) receives the information that you are signing in to our portal, and we receive from Google your e-mail address and confirmation that the account belongs to you. We do not automatically take over your name from Google; you enter it yourself in the portal. Use of Google sign-in is voluntary; you may use a password instead. Google's privacy policy applies to processing by Google. [To be completed before publication: Garantie für die Übermittlung an Google (z. B. Data Privacy Framework oder Standardvertragsklauseln) – juristisch prüfen]
4.4 Onboarding and client profile
So that we can advise you and assign you a suitable adviser, you record information about yourself and your situation in the client portal. We ask only for what is needed for the consultation:
- Identity and contact: first name, surname, date of birth, optionally gender, address, canton, country, telephone, contact e-mail, preferred language and preferred means of contact.
- Life situation: nationality, residence status (for example Swiss citizenship, permit B, C or G), marital status, number of children.
- Occupation and finances: type of employment, employer, occupation, optionally income (only where needed for tax or pension matters).
- Request: services requested, description of your request, urgency, client type (private or business).
Taken together, this information provides a picture of your personal and financial situation. We use it exclusively for your personal consultation by human advisers; no automated evaluation takes place (section 12). You may omit optional information and may correct your details in the portal at any time.
Purpose: preparing and conducting the consultation, assigning the responsible adviser. Legal basis: contract; for sensitive information, your explicit consent. Access: your responsible adviser, their deputy, the responsible team lead and the administration. Retention: duration of the advisory relationship and thereafter [To be completed before publication: gesetzliche Aufbewahrungsfrist (Vorschlag: 10 Jahre nach Ende des Mandats, Art. 958f OR)].
4.5 Advice and case handling (CRM)
Our staff maintain cases relating to your matters (for example tax return, change of insurance, pension advice, relocation), tasks with deadlines and notes. Internal notes and review remarks are not visible in the portal but form part of your personal data and are covered by the right of access, unless statutory exceptions (Art. 26 FADP) apply. Each assignment to an adviser is recorded with the time and the reason.
Your adviser sees only the clients assigned to them or for whom they act as deputy. Team leads additionally see the clients of their team. Only the administration has access to all files.
Purpose: providing the advisory service, organisation and quality assurance. Legal basis: contract. Retention: as for the client profile (section 4.4).
4.6 Documents
In the client portal you can upload documents, for example salary statements, tax documents, insurance policies, residence permits, bank and contract documents. For each document we store the category, display name, file type, size, time, status and any remarks or queries.
Sensitive data: insurance documents, in particular those of health insurance, may contain information about your health. We process such documents only with your explicit consent, which we obtain before the first upload, and only to the extent necessary for your consultation. You decide for yourself which documents you upload. Please do not upload documents of third parties without their agreement.
Security: documents are transmitted in encrypted form and stored in non-public storage. Access is via time-limited, person-specific links; every retrieval of a document by staff is logged (section 4.10). File names and document contents do not appear in e-mails or notifications.
Retention: documents that you delete yourself in the portal are removed promptly (from backups within around 6 months, section 4.11), unless a statutory retention obligation exists. Otherwise, the retention period of the client file applies (section 4.4).
4.7 Insurance overview
You may record your existing insurance policies in the portal or have us record them: category (for example health insurance, supplementary insurance, household contents, liability, life, pensions), insurer, product, policy number, premiums, term, notice period, deductible, cover and remarks. Information on the health insurance model and supplementary insurance may allow conclusions to be drawn about your health and is therefore treated as sensitive data (explicit consent, section 4.6).
Purpose: overview, comparison and optimisation of your insurance cover as part of the consultation. Retention: as for the client file.
4.8 Messages between you and your adviser
In the portal you can write messages to your adviser and send attachments. Messages are delivered to your adviser or, in their absence, to their deputy; the administration may read along where necessary (for example in case of absence or for quality assurance). Messages are stored unchanged so that the history remains traceable. No AI assistant is in use; your messages are not transmitted to providers of artificial intelligence. Where possible, please use the document function or a personal conversation for health information.
Purpose: communication within the advisory relationship. Retention: as for the client file.
4.9 Notifications and e-mails
The portal informs you and our staff about events, for example a new message, a query regarding a document, the assignment of an adviser or a reminder about open items. Notifications contain no content and no names, only the type of event, your client number and a link to the portal. We send e-mails via [To be completed before publication: Name, Firma und Land des E-Mail-Versanddienstes (Vorschlag: Infomaniak Network SA, Schweiz)]; this service receives your e-mail address and the message content (client number, event type, link).
Purpose: operation of the portal, information about the status of your matters, deadline monitoring. Retention: read notifications 90 days, unread notifications at most 12 months; sent e-mails are kept in the system only with their delivery status.
Optional section: Newsletter und Marketing – nur falls Newsletter oder Marketing-Mails geplant sind
With your separate consent, we send you information about our services and about developments in the areas of insurance, tax and pensions. You may withdraw this consent at any time, for example via the unsubscribe link in every e-mail or in the portal. [To be completed before publication: Versanddienst für Newsletter, Land und Vertrag]
4.10 Logging (security and evidence logs)
For the security of your data and for traceability, we log who made which change to your data and when (for example creation, modification, assignment, archiving) and when staff viewed your file, your documents or your messages. The log contains the time, the acting person, the type of operation and the records concerned, but no content (no names, addresses, amounts or texts). The log cannot be subsequently altered or deleted and is accessible only to the administration. Your own access to your own data is not logged.
Legal basis: statutory obligation to keep logs when processing sensitive data (Art. 4 DPO) and our legitimate interest in security. Retention: at least 12 months, [To be completed before publication: Aufbewahrungsdauer der Protokolle über 12 Monate hinaus (Vorschlag: 24 Monate)].
4.11 Backups
We create backups of the entire database and all documents several times a day. The backups are encrypted before transmission and stored with a storage provider in the Netherlands (section 7); the storage provider cannot read the contents. Backups are retained on a staggered basis and overwritten after around 6 months at the latest. Deleted data may therefore remain in backups for up to around 6 months; it is not actively processed there and is used only for restoration in an emergency. Restorability is checked regularly and automatically.
Legal basis: legitimate interest in the availability and integrity of the data; statutory obligation to ensure data security (Art. 8 FADP).
4.12 Consents
We store your consents (for example to the processing of sensitive data, to being contacted, to disclosure to insurers or partners) with the type, time, version of the underlying text and channel (portal, advisory meeting). A withdrawal is recorded as a separate entry; the original entry is retained as evidence.
Purpose: evidence of consent (accountability). Retention: as for the client file.
4.13 Data migration from the previous platform
Existing clients whose files were kept on our previous platform are transferred once to the new system. In doing so, we transfer only the data of genuine clients and only the fields that continue to be needed; information that is no longer needed is not transferred. After the migration, the data on the previous platform is deleted and the deletion is confirmed in writing by the previous provider. [To be completed before publication: Datum der Übernahme und der Löschbestätigung]
4.14 Staff and applicants
We process information about our staff (name, business contact details, function, team, qualifications, availability) to organise the consultation and show you only the details of your responsible adviser (name, function, business contact details, specialisations, languages, photograph if any). Internal personnel data is accessible only to the administration and the person concerned.
5. No processing by artificial intelligence
We use no AI service in the consultation, in the client portal or in the CRM. Your information, documents and messages are not transmitted to providers of artificial intelligence. Should we introduce an AI-supported service in future, we will inform you in advance in this policy and obtain your consent where required.
6. Cookies and local storage
Our website does not set cookies. The client portal uses your browser's local storage exclusively for technically necessary purposes: maintaining your login (session token) and your language setting. This information remains in your browser, is not used for tracking and is removed when you log out or delete your browser data. A consent banner is therefore not required.
7. Recipients and processors
Within our company, only those persons who need access to your data for their tasks receive it (section 4.5). To operate the platform, we engage service providers who process personal data on our behalf and in accordance with our instructions (processors, Art. 9 FADP / Art. 28 GDPR). Data processing agreements are in place with them.
| Service provider | Task | Data | Location |
|---|---|---|---|
| Infinity Media, [To be completed before publication: Rechtsform und Adresse von Infinity Media] | Development, operation and maintenance of the platform | all platform data (access only for operation and support) | Switzerland |
| Hetzner Online GmbH | Servers for database, documents and application | all platform data | Falkenstein, Germany |
| Backblaze Inc. (EU region) | Storage of encrypted backups | all data, exclusively encrypted; provider has no access to contents | Amsterdam, Netherlands |
| [To be completed before publication: E-Mail-Versanddienst (Vorschlag: Infomaniak Network SA)] | Sending login e-mails and notifications | e-mail address, client number, link | [To be completed before publication: Land des E-Mail-Versanddienstes] |
Optional section: Zusätzliche Dienstleister – nur falls Google-Login oder Cloudflare Turnstile aktiviert werden
| Service provider | Task | Data | Location |
|---|---|---|---|
| Google Ireland Ltd. / Google LLC | Sign-in with Google (voluntary) | e-mail address, login event | Ireland / USA |
| Cloudflare, Inc. | Turnstile spam protection on the contact page | technical browser characteristics, IP address | USA / EU |
Other recipients: in the course of your consultation, we disclose your data to third parties only with your consent or on your instruction, for example to insurance companies for quotes and applications, to tax authorities for the filing of your tax return or to [To be completed before publication: weitere Dienstleister, die Kundendaten erhalten (z. B. Partner für Steuerberatung, Buchhaltung, Telefonie) gemäss Fragebogen D]. These recipients are themselves responsible for their own processing. We disclose data to authorities or courts only where we are legally obliged to do so.
Technical services without access to personal data: Cloudflare, Inc. (name resolution for the domains), Let's Encrypt (issuance of TLS certificates for our domain names).
8. Cross-border disclosure
Your data is stored and processed on servers in Germany; encrypted backups are held in the Netherlands. Both countries provide an adequate level of data protection within the meaning of Art. 16 para. 1 FADP (Annex 1 DPO). Storage in Switzerland does not currently take place.
Disclosure to countries without an adequate level of data protection, in particular the USA, occurs only in the marked optional cases (sign-in with Google, Cloudflare Turnstile spam protection) and only with appropriate safeguards, which we specify in section 4 in each case. Our operating service provider Infinity Media is domiciled in Switzerland.
9. Retention and erasure
We retain personal data only for as long as is necessary for the respective purpose or as statutory retention obligations exist. Thereafter, the data is erased or anonymised.
| Data | Retention |
|---|---|
| Client file (profile, cases, tasks, notes, documents, insurance policies, messages, consents) | duration of the advisory relationship and thereafter [To be completed before publication: gesetzliche Aufbewahrungsfrist (Vorschlag: 10 Jahre nach Ende des Mandats, Art. 958f OR)]; then erasure |
| Documents deleted by the client in the portal | immediately, unless a retention obligation exists |
| Contact enquiries without an advisory relationship | 6 months |
| Notifications in the portal | 90 days after being read, at most 12 months |
| Login logs | 12 months |
| Security and evidence logs | at least 12 months, [To be completed before publication: Aufbewahrungsdauer der Protokolle über 12 Monate hinaus (Vorschlag: 24 Monate)] |
| Backups (encrypted) | staggered, overwritten after around 6 months at the latest |
| Web server logs | [To be completed before publication: Aufbewahrungsdauer der Webserver-Logs (technisch zu bestätigen, Vorschlag höchstens 30 Tage)] |
When an advisory relationship ends, your file is archived. Until the retention period expires, you retain read access to your own data in the portal but can no longer make changes; our advisers no longer have access to archived files. Once the period has expired, the data is erased.
10. Data security
We protect your data with technical and organisational measures appropriate to the risk, including:
- encrypted transmission of all data (TLS) between your device and our systems,
- access rules directly in the database on the principle of "no access by default": each row is visible only to those persons who need it for their tasks; the rules are verified with more than 1,000 automated tests,
- separation of internal notes and personnel data from the data you see in the portal,
- logging of changes and of read access by staff, not subsequently alterable (section 4.10),
- administrative access to the database is not publicly reachable and can be used for operations only via secured connections,
- client-side encrypted backups several times a day with a weekly automated restore test,
- data minimisation: notifications and e-mails contain no names, file names or content; fields that are not needed are not collected,
- passwords are stored only as a hash; accounts are activated only after confirmation of the e-mail address; deactivated accounts immediately lose all access,
- contractual confidentiality obligations of our staff and service providers; training of advisers in handling sensitive information.
Despite all measures, no data transmission over the internet can be fully protected against access by third parties. Please protect your password and log out after use, particularly on shared devices. We will inform you and, where required, the supervisory authority if a breach of data security is likely to result in a high risk to you (Art. 24 FADP, Art. 33 and 34 GDPR).
11. Your rights
Under the applicable data protection law, you have the following rights:
- Access (Art. 25 FADP, Art. 15 GDPR): you may find out whether and which personal data we process about you, for what purpose, for how long, where it originates and to whom we disclose it.
- Rectification (Art. 32 FADP, Art. 16 GDPR): you may have incorrect information rectified; you can adjust your profile details yourself in the portal.
- Erasure (Art. 32 FADP, Art. 17 GDPR): you may request the erasure of your data unless a statutory retention obligation prevents this. You can delete documents yourself in the portal.
- Data portability (Art. 28 FADP, Art. 20 GDPR): you may receive the data you have disclosed to us in a commonly used electronic format or have it transferred to another body.
- Withdrawal of consent: at any time with effect for the future; the lawfulness of processing carried out until then remains unaffected.
- Objection and restriction (Art. 30 para. 2 let. b FADP, Art. 18 and 21 GDPR): you may object to processing or request its restriction where the statutory requirements are met.
To exercise your rights, please contact [To be completed before publication: E-Mail-Adresse für Datenschutzanfragen]. Where available, you can also initiate a data export and a deletion request directly in the client portal under "My data". To protect your data, we must verify your identity and may request further information for this purpose. We generally respond within 30 days; exercising your rights is in principle free of charge.
Complaint: you may at any time contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch. If you are resident in an EU member state, you may additionally lodge a complaint with the data protection supervisory authority of your country of residence.
12. No automated individual decisions
We do not make decisions based solely on automated processing that would have legal effects for you or significantly affect you (Art. 21 FADP, Art. 22 GDPR). Recommendations and decisions concerning your consultation are made personally by our advisers. Reminders and deadline notices in the portal are generated automatically but have no legal consequences for you.
13. Changes to this policy
We may amend this privacy policy if our processing operations or the legal requirements change. The version published in the portal and on the website at the relevant time is authoritative. Each version bears a version date; consents you give relate to the version valid at that time and are recorded with its version date. In the event of material changes, we will inform registered clients in the portal.
| Version | Change |
|---|---|
| [To be completed before publication: Versionsdatum der freigegebenen Fassung (JJJJ-MM-TT, identisch mit text_version der Einwilligungen)] | First version (draft of 04.10.2026, legally reviewed on [To be completed before publication: Datum der juristischen Freigabe]) |