Last updated: 10 July 2026
Privacy Policy
1. Introduction
1.1 This Privacy Policy explains how Solodesk Sàrl ("Solodesk", "we", "us") collects and processes personal data when you use the Solodesk application and website at solodesk.ch (the "Service").
1.2 We process personal data in accordance with the Swiss Federal Act on Data Protection (revised FADP / revDSG, in force since 1 September 2023) and its ordinance. Because the Service is available only to Swiss-registered businesses and Swiss-resident sole traders, our processing is governed by Swiss law. Where the EU General Data Protection Regulation (GDPR) nonetheless applies to your personal data, §2.3 and §10 explain the additional rights you have.
1.3 For the personal data of your account and your business, Solodesk is the controller. For the information you upload about your own clients and suppliers, your role and ours are different — see §6.
2. Who this policy is for
2.1 This policy covers personal data relating to: (a) the individuals who register and use the Service on behalf of a business (account holders and their users); (b) visitors to our website; and (c) people who contact us (for example for support or sales).
2.2 Note on terminology: the revised FADP protects the personal data of natural persons only. Data relating solely to legal entities (companies) is not "personal data" under Swiss law.
2.3 Scope and the GDPR. The Service is offered only to businesses registered in Switzerland and self-employed persons resident in Switzerland (see the Terms of Service), and our processing is governed by Swiss law. If, in your particular case, the EU GDPR applies to your personal data, §10 explains the equivalent rights you have and how to complain.
3. What personal data we collect
We collect the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, email address, password (stored hashed), Google sign-in identifier and profile basics (if you use Google) | You / Google sign-in |
| Business profile | Your company's legal name, UID, address, canton, legal form, contact details, VAT status | You / Swiss registry lookup (Zefix, BFS UID register) |
| Subscription & billing | Plan, billing status, and payment metadata. Card payments are processed by Stripe; we do not store full card numbers | You / Stripe |
| Content you create or upload | Documents you upload and the data extracted from them, contacts, invoices, bank-statement data, ledger entries, reports. This may contain personal data — see §6 | You |
| Usage & technical | Log data, device/browser information, IP address, timestamps, request identifiers, actions in the app, and security signals (including via reCAPTCHA) | Automatically |
| Communications | Messages, support requests and their content | You |
3.2 The Service is intended for business and accounting documents and does not require special categories of sensitive personal data. Where such data nonetheless appears in a document you choose to upload, you are responsible for it as its controller (see §6).
4. Why we process personal data (purposes)
We process personal data to:
- (a) provide the Service — create and manage your account, host and process your documents and data, run AI classification and extraction, keep your books, generate invoices and reports, and enable the features of your plan;
- (b) handle billing — manage subscriptions, trials, invoicing and payment via Stripe;
- (c) communicate with you — send service, security, transactional and account messages, and respond to your requests;
- (d) secure and maintain the Service — authentication, fraud and abuse prevention (including reCAPTCHA), logging, troubleshooting, and backups;
- (e) improve the Service — using usage data and aggregated/de-identified statistics;
- (f) send marketing communications — where you have opted in (see §13.4);
- (g) comply with law and enforce our terms, establish, exercise or defend legal claims.
5. How Swiss law permits our processing
5.1 The revised FADP does not require a specific "legal basis" for each processing operation the way the EU GDPR does. Under Swiss law, a private company may process personal data provided it observes the data-processing principles of Art. 6 FADP — lawfulness, good faith, proportionality, purpose limitation, accuracy and data security — and does not unlawfully breach the data subject's personality rights (Art. 30 FADP).
5.2 A justification (Art. 31 FADP) is required only where a processing operation would otherwise breach your personality rights — for example to disclose sensitive personal data to third parties, or to process data beyond what you would reasonably expect. Where a justification is required, we rely on one of the following: your consent; an overriding private interest, in particular processing directly connected with entering into or performing our contract with you (Art. 31(2)(a) FADP); or a legal obligation.
5.3 Where we ask for your consent (for example for marketing emails or non-essential cookies), you may withdraw it at any time; withdrawal does not affect processing already carried out.
6. Data you upload about your clients and suppliers ("counterparty data")
6.1 To run your accounting, you upload documents and enter information about your business counterparties (clients and suppliers) — for example invoices, receipts, bank statements, names, addresses, UIDs and IBANs. This is predominantly commercial information about businesses.
6.2 Swiss data-protection law distinguishes legal persons from natural persons:
- Information about a legal person (for example an SA, a Sàrl/GmbH or an AG) is not personal data under the revised FADP and falls outside Swiss data-protection law.
- Information about a natural person is protected — and this includes a sole proprietor / one-person business (raison individuelle, Einzelunternehmen), who remains a natural person (personne physique) even when acting commercially, as well as any named individual connected with a business (a contact person, signatory or employee).
Because many Swiss businesses are sole proprietors, and invoices, receipts and bank statements routinely name individuals, a significant part of the counterparty information you upload is protected personal data.
6.3 For that protected personal data:
- you are the controller and determine why and how it is processed; and
- Solodesk acts on your behalf as your service provider (processor), processing it only to provide the Service and on your instructions.
6.4 As the controller of that data, you are responsible for having a lawful basis to collect and upload it, and for meeting any information or other obligations toward the individuals concerned. We make the Service available to help you store and process it securely, and we act only on your instructions. We do not use this counterparty data for our own purposes; using it for our own purposes (for example our own analytics, or to train AI models) would make us a controller for that use, which we do not do.
6.5 Where we act as your processor, this processing is governed by a data-processing agreement (available from us on request). Contact us at privacy@solodesk.ch to put one in place.
7. Artificial intelligence and document processing
7.1 To classify documents and extract data (counterparty, amounts, dates, line items, text), the Service sends the relevant documents and their contents to our AI processing provider, Google Cloud Vertex AI (Gemini models), which returns structured results. This is a core function of the Service.
7.2 AI results are probabilistic and may contain errors; the Service surfaces uncertain results for your review, and you should verify them.
7.3 No retention, no model training. Under our Vertex AI configuration (zero data retention), Google does not retain your content after returning the result to us, and — per its enterprise terms — does not use your content to train its foundation AI models. Your content is processed solely to deliver results back to you.
7.4 To perform this processing, your content is transmitted to Google Cloud Vertex AI, which may involve processing outside Switzerland (see §8 and §11).
7.5 No solely-automated decisions. We do not take decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing (Art. 21 FADP / Art. 22 GDPR). Our AI classifies and extracts information from documents for your review; it does not make decisions about you.
8. Who we share personal data with
8.1 We do not sell personal data. We share it only with service providers who process it on our behalf under contract, and only as needed to run the Service. Our main sub-processors are:
| Provider | Purpose | Notes on location |
|---|---|---|
| Google Cloud Platform (hosting, database, file storage) | Hosting the Service, storing documents and data | Primary infrastructure in Switzerland (Zurich region, europe-west6) |
| Google Cloud Vertex AI (Gemini) | AI classification and data extraction from documents (§7) | Google Cloud (see §11) |
| Stripe | Subscription and payment processing | Global payment processor (see §11) |
| SendGrid | Sending transactional and service emails | Email delivery provider (see §11) |
| Sentry | Application error monitoring and troubleshooting | International (see §11) |
| Google reCAPTCHA (Enterprise) | Bot and abuse prevention on sign-up/login | Google service |
| Zefix / BFS UID register | Swiss company-registry lookups you initiate (to fill in company details) | Swiss federal registries |
8.2 We may also disclose personal data where required by law or a lawful authority request, to enforce our terms, to protect our rights, safety and property or those of others, or in connection with a merger, acquisition or asset sale (subject to appropriate safeguards).
8.3 A current list of sub-processors is available on request at privacy@solodesk.ch.
8.4 Our public marketing website uses Plausible and Mautic, which we self-host on our own Google Cloud infrastructure in Switzerland — so the data they process stays with us and is not shared with a third party — together with Google Tag Manager, which loads Google measurement and advertising tags. These are described in §13.
9. Data hosting and retention
9.1 Hosting location. The core Service — including the database and your uploaded documents — is hosted on Google Cloud infrastructure located in Switzerland (Zurich region).
9.2 Digital copies, not your master records. Solodesk stores digital copies of the documents and data you upload, as a hosting and processing convenience. The original documents and records remain with you, and the statutory obligation to retain accounting records and business correspondence — in particular the 10-year retention duty under Art. 958f of the Swiss Code of Obligations — remains your responsibility. You should not rely on Solodesk as the sole repository of records you are legally required to keep.
9.3 Retention. We keep personal data for as long as your account is active and as needed to provide the Service, and afterwards only as necessary to comply with our own legal obligations (including our own accounting and VAT-retention duties for the business records we generate, such as billing records), resolve disputes and enforce our agreements. Server logs and security data are kept for a limited period.
9.4 Deletion and export. You can delete data within the Service, and you can request deletion of your account. On account closure, your account is deactivated and your data is retained for 30 days, during which you can export it; after that period we delete it (subject to §9.3). Before closing your account, export the data and documents you need to keep (§10(e)), because Solodesk holds only copies and you bear the statutory retention duty (§9.2).
10. Your rights
10.1 Under the revised FADP you have the right to:
- (a) information / access — obtain confirmation of whether we process your personal data and receive a copy and related information;
- (b) rectification — have inaccurate data corrected;
- (c) deletion — request deletion of your personal data, subject to our overriding legal obligations and legitimate grounds for retention;
- (d) object / restrict — object to certain processing, and object to direct marketing at any time (see §13.4);
- (e) data portability — receive personal data you provided in a common electronic format, or have it transferred, where the conditions of the FADP are met;
- (f) withdraw consent — where processing is based on consent, at any time, without affecting prior processing;
- (g) not be subject to solely-automated decisions producing legal or similarly significant effects (see §7.5).
10.2 To exercise your rights, contact privacy@solodesk.ch. We may need to verify your identity, and we will respond within the periods required by law (as a rule, 30 days).
10.3 If the EU GDPR applies to you, you have equivalent rights (including access, rectification, erasure, restriction, portability and objection), and you may lodge a complaint with your local EU/EEA data-protection supervisory authority in addition to the Swiss authority below.
10.4 Swiss supervisory authority. You may report a data-protection concern to the Federal Data Protection and Information Commissioner (FDPIC / EDÖB), Feldeggweg 1, 3003 Bern (www.edoeb.admin.ch), which supervises FADP compliance and can investigate and order corrective measures, but does not award individual remedies. You may also enforce your rights before the civil courts. We would appreciate the chance to address your concern first.
11. International transfers
11.1 Our core infrastructure — the database and your uploaded documents — is in Switzerland (§9.1). However, some of our providers (for example Stripe, SendGrid, Sentry, and Google in relation to AI processing, support or administration) are international organisations that may access or process personal data outside Switzerland. Access to personal data from abroad also counts as a disclosure abroad.
11.2 We disclose personal data abroad only where the FADP permits, relying on:
- the Federal Council's list of countries with adequate data protection (which includes the EEA and, for the United States, recipients certified under the Swiss–U.S. Data Privacy Framework); or
- where no adequacy applies, appropriate safeguards — in particular the EU Standard Contractual Clauses with the adaptations required for Swiss law by the FDPIC, together with a transfer-impact assessment; or
- a statutory exception under Art. 17 FADP (for example, a transfer necessary to perform our contract with you).
11.3 The main recipient countries are the European Union / EEA and the United States. You can request details of the safeguards we rely on at privacy@solodesk.ch.
12. How we protect personal data
12.1 We apply technical and organisational measures appropriate to the risk, including: hosting in Switzerland; encryption of personal data in transit and at rest; access controls and authentication; private document storage; session management and revocation; logging and monitoring; and restricting staff access to what is necessary.
12.2 No system is completely secure. You are responsible for keeping your credentials confidential and for the security of your own devices.
13. Cookies, tracking and marketing communications
13.1 In the Solodesk application. Within the authenticated product we use only the cookies and similar technologies needed to run the Service and keep it secure — for example authentication/session cookies and the Google reCAPTCHA mechanism used to prevent abuse (which shares limited data with Google for that purpose). We do not use advertising or cross-site tracking in the application.
13.2 On our public marketing website. Our website uses:
- Essential cookies — needed for the site to function and stay secure;
- Plausible — privacy-friendly, cookieless analytics, self-hosted on our own Swiss infrastructure; it measures site usage in aggregate and does not set tracking cookies or identify you;
- Mautic — our marketing-automation tool, self-hosted on our own Swiss infrastructure; it may set a cookie to recognise you and to measure how you engage with our website and emails (that data stays with us);
- Google Tag Manager — which loads Google measurement and advertising tags that may set cookies and share data with Google, including for conversion measurement and advertising.
13.3 Your choices (cookies). Under Swiss law (Art. 45c of the Telecommunications Act) we may use cookies where we inform you and you can refuse them. We obtain your consent, through a cookie banner, before setting non-essential cookies used for marketing or advertising (Mautic tracking and Google advertising tags); essential cookies and cookieless analytics do not require consent. If the GDPR applies to you, we obtain prior opt-in consent for non-essential cookies. You can also control cookies through your browser settings.
13.4 Marketing emails. We send marketing emails only where you have opted in — for example the marketing-emails checkbox during onboarding. You can withdraw your consent and unsubscribe at any time via the link in each marketing email or by contacting privacy@solodesk.ch. Service, security and transactional messages are part of the Service and are not marketing.
14. Children
14.1 The Service is a business tool intended for adults acting in a business capacity and is not directed to children. We do not knowingly process personal data of children in connection with the Service.
15. Changes to this Privacy Policy
15.1 We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and, for material changes, notify you by a reasonable means. Continued use of the Service after the change takes effect constitutes acknowledgement of the updated policy.
16. Contact
Solodesk Sàrl
Chemin des Coquelicots 16, 1214 Vernier, Switzerland
Data-protection contact: privacy@solodesk.ch