Privacy Policy
Protecting your privacy.
We protect your data
We, DeepCloud AG (“DeepCloud”) respect your privacy and protect your personal data according to the applicable data protection laws. This is the DeepCloud Privacy Policy. It is valid for all our websites, including:
- deepcloud.swiss
- deepcloud.ch
- deepbox.swiss
- deepbox.ch
- deepart.swiss
- deepsign.swiss
- deepsign.ch
- deepid.swiss
- deepid.ch
- deeppay.swiss
- deepmail.swiss
- deepvalidator.swiss
- deepninja.swiss
- deepo.swiss
- deepv.swiss
- deepv.ch
- support.deepcloud.swiss
- landing.deepsign.swiss
- landing.deepcloud.swiss
with the associated subpages, as well as for our corporate presence on LinkedIn, YouTube, Facebook, Instagram and Vimeo.
Access to our website is free, although some of our online services are restricted to certain users and require registration. Our online offers are not aimed at children or the general public. Our websites are structured so that you can visit them without having to disclose any
personal data. When you visit our websites, we ask you for your consent to certain data processing, which you can accept or reject. If you decide to provide us with personal data, we consider it our obligation to handle this personal data very carefully and within the framework of the legal requirements. This Privacy Policy is intended to provide you with comprehensive information about the data processing performed by us and applies to all data processing by DeepCloud, regardless of whether we receive your personal data online or offline and regardless of the communication channel (such as company website, other company websites on the Internet, by telephone, email, post, or personal contact).
Responsible position
DeepCloud AG
Abacus-Platz 1
9300 Wittenbach – St. Gallen
T +41 58 854 14 14
info@deepcloud.swiss
We have appointed a data protection officer for DeepCloud. They are available at:
Insofar as DeepCloud processes personal data and the General Data Protection Regulation (“GDPR”) applies to such processing, we have designated as our representative in the EU:
Abacus Business Solutions GmbH
Mies-van-der-Rohe-Straße 6
Tower 1 – 10. OG
80807 Munich
datenschutz@abacus.eu
If you have any questions about data protection, please feel free to contact us at any time.
What is personal data?
Personal data is any information relating to the personal or material circumstances of an identified or identifiable natural person (“data”). This includes, for example, the name, address, telephone number, or email address. This term does not include anonymous data or information whose content does not indicate or suggest the identity or factual circumstances of an identifiable individual, such as the number of visitors to a website. There are also so-called special categories of data (“sensitive data”). This includes data revealing your racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic and biometric data to uniquely identify you, health data, or data concerning your sex life or sexual orientation. We will only process such data – if at all – with your explicit consent, unless another legal basis makes such data processing necessary.
Our data processing and your data
The content and information presented on our websites serve to provide you with general information about us as a company and about our services, such as DeepServices. While using our websites, it is possible that data may be disclosed by you or collected by us for certain purposes. Furthermore, as a company, we process data that you disclose to us or transmit to us in other ways, for example by mail, email, telephone, during a business transaction, or personal contact. Our data processing includes, for example, the collection, storage, transmission, deletion, and other processing of your data. Only data that is necessary and appropriate for the intended purpose will be processed. Our data processing is carried out for the purposes stated by us or for the purposes requested by you. Data processing outside of the intended purposes will only take place if we inform you accordingly and if a change of purpose is lawful.
Where we process data as a data processor on behalf of another data controller, please contact the data controller responsible for the data processing. In such cases, we are unable to provide you with any information; instead, we will refer you to the person responsible or inform them of the matter so that they can contact you directly.
In the following, we inform you about the individual data processing, its purpose, and its legal basis for us as a company.
Your contact information
You can provide your contact information and interest in our products and services in a contact form, an inquiry, through a personal contact during an event or web demo, or contact us in other ways so that we or partners we select can contact you, inform you about DeepCloud Services, conduct a web demo with you, or fulfill other offers. Furthermore, we store and process information that you select in lists and menus on our websites. When you send us an email we save the content of the email as such, and the data that is generated when inquiries are sent to our email servers, such as sender and recipient IDs, time stamps and, if necessary, reasons for errors or rejections if the transmission of an email fails. If you wish to receive information material, you can also provide us with your email address so that we can send you the requested information by email with your consent. We use your data ourselves or provide it to the relevant companies. This is done within the framework of data protection and competition law requirements. We process your data based on legitimate interests. Processing is done both in your interest – you have contacted us – and in ours, to establish the satisfaction of all inquirers, if necessary to fulfil a contract with you, or to carry out pre-contractual measures. We will only process your data for the purpose of contacting you. Your data may be stored in our CRM system and in other technical systems. When using website forms, your data will be transmitted in encrypted form according to the current state of the art. You provide us with your data voluntarily, and only as much data as necessary is requested (mandatory data are marked with *). All other information is optional.
Transmission of data to selected partners
If we determine that we can only satisfactorily respond to your inquiry with the assistance of a selected partner, we may share your data based on legitimate interests or, if necessary, we will obtain your consent to share your data. Consent is given voluntarily and can be revoked at any time for the future.
Offers requiring registration and login
In the course of providing our DeepServices, visiting our websites or using our support, there is the possibility of using online offers that require you to register, authenticate, and log in. This applies in particular to opening a DeepCloud account, using our DeepServices, but also to arranging a web demo so that you can get a better idea of our services through an online presentation, remote access in the event of a support request, registering for events or arranging an appointment. This involves providing and transmitting to us a variety of data resulting from the respective form or our queries. When using such a form, your data will be transmitted in encrypted form according to the current state of the art. You provide us with your data voluntarily, and only as much data as necessary is requested (mandatory data are marked with *). All other information is optional. DeepCloud is free to choose their authentication methods. The data to be provided results directly from the specific procedure used. You are required to choose strong passwords when choosing login credentials. You are responsible for the security of your login data and must not pass it on to unauthorised third parties. The processing of your data within the scope of our (registration and login required) offers is carried out with your consent when registering or logging in, based on our legitimate interest in providing you with the information necessary to use our services satisfactorily, to be able to contact us, and for the proper processing of an existing contractual relationship.
Registration and DeepCloud account login
Successful registration is required to open a DeepCloud account. The link sent to the email address provided must be used for this purpose. Registration opens a DeepCloud account for the Owner that offers certain functionalities. Please complete the registration form, providing the required information. When using certain DeepServices or extended functionalities of the DeepCloud account, the unique identification of the Registrant and, if applicable, the verification of the Organization is required. After registration, it is possible to sign on to the DeepCloud account using an access-protected login and various DeepServices can be used.
We use DeepServices ourselves, but we also offer them to our clients, in which case we provide them on behalf of the client. Below, we describe the data processing operations that take place in this context.
Using the DeepCloud account and DeepServices
We offer a DeepCloud account and a range of DeepServices as cloud-based Software as a Service. These are web-based software applications and applications (Apps) with various functionalities. The focus is on the storage, organization, and sharing of information and documents or on the optimization of internal company communication, processes and accounting, with the possibility of integrating employees and other third parties. It is also possible to analyse and utilise information efficiently.
If you have taken out subscriptions to specific DeepServices as part of your DeepCloud account, these can also be used by users you have authorised, provided you grant them access via your DeepCloud account and they have logged in to a DeepCloud account.
The respective owner of the DeepCloud account is personally responsible for ensuring that data processed in connection with the DeepCloud account and DeepServices is used in accordance with data protection regulations, where personal data is collected in the process. This allows you to enter, save, amend or delete data.
For the use of the DeepCloud account and the DeepServices, all data will be stored and processed that accrue upon registration as well as all data and documents that are collected and processed in DeepBox and when using the DeepServices. This includes data related to address entry, accounting, invoices and quotations, time recording, expense receipts, payroll accounting, and all content provided by the user in the process. Furthermore, this also includes content that can be processed by a fiduciary or by additional services such as those of payment providers, when using mobile Apps, and exchanged between the respective parties involved.
The data processed in the DeepCloud account and the DeepServices include the following: Personal master data such as name, address, date of birth, employer, contact data such as telephone and/or email address, time and wage recording data such as working hours, absences (sickness or holidays), overtime and extra hours, expense receipts, product master data, contractual relationship data and contractual data including delivery, payment and invoicing data, bank account and credit card data, and all data recorded within the DeepCloud account and DeepServices. This data may come from current and former employees and job applicants, service providers, suppliers, banks and other payment providers, customers, business partners, prospective customers, and all the employees of the companies who act as contacts for these companies.
During the term of the contract, DeepCloud creates a backup of the content stored in the applications in accordance with standard backup procedures. Upon termination of use of the DeepCloud account (e.g. following the end of the contractual relationship or termination) or of DeepServices, the holder of the DeepCloud account is responsible for planning the termination of use of the DeepCloud account and DeepServices. The Customer shall, autonomously and in due time prior to termination, ensure that its data files are backed up and delete corresponding data or authorise DeepCloud to delete the data upon termination of the contractual relationship, as the data will be deleted at the latest upon expiry of the backup periods. Data which DeepCloud is obliged to retain for a limited period, as well as data required for invoicing or the collection of payments for services rendered, are exempt from deletion.
DeepService DeepSign
DeepSign enables electronic signing of digital documents for individuals (signatories) and organisations (if their authorised representatives sign) as well as the use of timestamps. The simple electronic signature (SES), advanced electronic signature (AES) and qualified electronic signature (QES) and electronic seals are available. Depending on the type of signature, different data relating to the initiator (the person who invites another person to sign) and the signatory or seal creator are processed.
Data processing carried out by DeepSign:
In order to be able to sign a document, the initiator collects the email address so that the invitation can be sent to the signatory. The initiator may additionally write and send messages for the signatory. Similarly, the choice of signature or seal is recorded, as well as the certification or trust service (in accordance with ZertES or the eIDAS Regulation) through which a signature or seal is to be created.
A SES requires the signatory’s Email address, which the signatory uses to confirm the SES. DeepCloud processes and transmits the relevant documents to the parties involved, such as signatories and observers.
To use the other types of signatures, additional data is processed. Among other things, this requires prior authentication and, where necessary, verification of the signatory’s identity. DeepCloud provides its own identification service DeepID for this purpose (information on data processing in DeepID can be found in the Privacy Policy under “Data processing when our Mobile Apps are used”). At the signatory’s option, another third-party identification service accepted for DeepSign may also be used. Their privacy policy applies in this regard.
By whom is data processed?
- Customers and their employees or other users authorised by the customer
- The signatory for the electronic signature
- Observers of the signing process
- Authorised representatives of the seal issuer’s organisation
- Persons whose data is contained in the documents to be signed
What data is processed?
For the purpose of signing and to maintain the traceability of the confirmation of a signature, DeepCloud records the following data (insofar as it is collected and transmitted by the identification service used or disclosed by the initiator or signatory him/herself within DeepSign):
- Login details for the DeepCloud account when the initiator or signatory uses DeepSign
- Master and contact data (when opening a DeepCloud account)
- Email address for signatory invitations
- Telephone number if the relevant signature provides for its processing
- Selection of the electronic signature, electronic time stamp or type of seal, as well as the certification or trust service
- Result of the prior identification and verification of the signatory (success, failure)
- Confirmation or rejection of signature
- Documents, their contents and annexes
- Certified extracts from the Commercial Register and VAT register (legal entities)
- Power of attorney
- Other evidence relating to specific attributes
- vIf the creator is not a natural person, details of the creator’s representative may be recorded, namely a copy of the relevant pages of the identity document (passport, identity card) containing the following information (e.g. gender, first name and surname, date of birth, expiry date of the identity document, nationality)
- Log files relating to the signature or authentication process (such as business partner number, transaction number, process-related data), hash values, transaction history, signature/timestamp selection, signature ID
- Diagnosis and analysis data (e.g., product interaction, usage data)
- Data on the means of authentication personally used (such as device number) and technical data on the device
- Data on acceptance of the current terms of use of DeepCloud and of third-party providers as well as confirmation of the user’s place of residence in case of AES or QES
- Any other information or documents entered or provided by the user within the service relating to a requested signature or seal, the user’s organisation, or other supporting documents concerning specific attributes for an FES or QES certificate, as well as other relevant information such as the responsible registration authority (e.g. DeepCloud for DeepID)
- Information that the user provides in inquiries regarding DeepSign (as in the case of support)
What is the purpose of the data processing?
Data and information are processed by DeepCloud in order to provide the DeepSign electronic signature service, to allow secure and smooth use of the service, to contribute to its improvement, and to comply with legal obligations such as responding to official requests.
What are the legal bases/justification for data processing?
DeepSign is used by DeepCloud itself and is provided by DeepCloud on behalf of its customers as part of a data processing agreement. For this reason, data processing is carried out in accordance with the legal bases on which DeepCloud and the DeepCloud customer responsible for this data processing rely. The legal bases for this include, for example, the data subject’s consent, overriding legitimate interests, a contract with the data subject, or legal obligations.
To which recipients is data transmitted?
Recipients in connection with the fulfilment of legal obligations: DeepCloud may disclose personal data to recipients if this appears necessary or appropriate to comply with applicable laws and regulations or to verify compliance with them and to respond to requests from competent authorities. This concerns, in particular, state-accredited conformity assessment bodies, audit officers and the approving body for certification services for the purpose of checking the proper performance of the AES and seal service.
Third-party providers as recipients of data: DeepCloud may transfer personal data to third-party providers if the user makes use of a service provided by such a third-party provider, such as if the user uses an identification service other than DeepID for the release of a QES or AES. In addition, certification services are provided from a provider of certification services recognized in Switzerland according to the Swiss Federal Act on Qualified Electronic Signatures (ZertES) and a provider of trust services recognized in the EU according to the EU Regulation on electronic identification and trust services for electronic transactions in the internal market (eIDAS Regulation) (third-party provider). These third-party providers generate electronic signatures, time stamps and seals in accordance with legal requirements and their certificate policies. Personal data of the signatory will be transferred to recipients within the EU that have an adequate level of data protection. These providers are subject to strict legal requirements when providing their services.
Data from publicly available sources, such as the Swiss Commercial Register and the cantonal commercial registers, as well as information from publicly accessible websites and information sources, and from DeepID’s own DeepService DeepInfos, is used to verify organisations within DeepID and for a DeepCloud account (information on data processing at DeepInfos can be found in the Privacy Policy under ‘DeepInfos’).
When using third-party provider services, the data protection provisions of these third-party providers will apply.
Service providers as recipients of data: DeepCloud uses external service providers to deliver DeepSign. These are hosting and service providers. They use server locations in Switzerland for this purpose.
How long is data stored?
Fundamentally, data is stored for as long as necessary for the stated purpose and as required by contract or statute. In the field of certification and trust services, there are very long statutory retention obligations, which can be as long as 39 years in order to be able to document the issue of your electronic signature(s). Where there is no longer any purpose for storing the data or any retention obligations, the data will be anonymised or deleted – once the applicable backup retention periods have expired.
DeepService DeepValidator
The DeepValidator can be used to check the validity of certain electronic signatures and seals. To this end, the documents containing the signature(s) or seal(s) to be verified can be uploaded to DeepValidator so that the certificate underlying a signature or seal, issued by the certification or trust service , can be validated.
In the web edition, it is not possible to carry out a discrete verification of a signature or seal where only the hash value would be transmitted for verification.
Users of DeepValidator receive a report on the validation results, which may also contain personal data.
In addition, DeepInfos can be used to check who has signing authority within an organisation and the respective scope of their authority to act on its behalf. To do this, the organisation can be selected from DeepService DeepInfos so that a comparison can then be made between the authorised signatories stored in DeepInfos for that organisation and the signatories listed in the signatures. In this process, personal data relating to the individuals named in the signature(s) is processed for the purposes of verification. Information on data processing at DeepInfos can be found in the privacy policy under ‘DeepInfos’.
Data processing carried out by DeepService:
When using the web version of DeepValidator, only those personal data that are necessary for validating the signature or seal are processed. If the DeepValidator is used via a DeepCloud account, details regarding data processing can be found in the section ‘Registering for and logging in to a DeepCloud account’. The documents uploaded for validation are not stored, but are deleted immediately after validation and the report has been generated. Your content, with the exception of the signature or seal to be validated, will not be processed.
By whom is data processed?
Data is processed relating to the individuals whose signatures or seals are being validated.
What data is processed?
Data relating to the certificate for the seal or signature, the validity of which is being verified, is processed. These may include:
- Details of the signatory, such as name and authorisation to sign, as well as details of the organisation affixing the seal
- Selection of the electronic signature, electronic time stamp or type of seal, as well as the certification or trust service
- Result of the prior identification of the signatory
- Any other information entered or provided by the user within the service, or other supporting documents relating to specific attributes for a certificate
To which recipients is data transmitted?
DeepCloud uses external service providers to deliver the DeepValidator. These are information services for certificates, hosting and service providers. They process data for the purposes described by DeepCloud. They use server locations in Switzerland for this purpose.
How long is the data stored?
The document uploaded for validation is deleted from DeepValidator immediately after the report is generated.
The report on the validation results is also deleted from DeepValidator 5 minutes after it is generated.
Data relating to the verification of authorised signatories in DeepInfos is deleted after 30 minutes of inactivity, once the browser session has ended.
What is the purpose of the data processing?
The data is processed in order to verify certificates and timestamps used for electronic signatures or seals.
What are the legal bases/justification for data processing?
In principle, DeepCloud processes data within the DeepValidator following consent from the person using the DeepValidator and after that person has uploaded the document containing the signatures or seals to be validated into the DeepValidator. Should this also involve data relating to other individuals, DeepCloud will process such data on the basis of overriding legitimate interests in order to be able to offer the DeepValidator.
DeepService DeepO
DeepO is a data collection AI from DeepCloud that is integrated directly into the DeepBox or into third-party systems (such as ERP systems). It captures and processes data from documents uploaded to a DeepBox or a third-party system. It thus enables data to be automatically captured from a wide range of document types – such as invoices, receipts, payslips and order confirmations – and imported into an ERP system, whilst additional information from other sources can also be integrated.
Data processing carried out by DeepO:
With DeepO, information can be extracted from documents stored in a DeepBox or in a third-party system. This can either be triggered manually or, for example, automated using DeepFlow. The decision to process documents and data using DeepO (whether automatically or manually) rests with the customer and is carried out by authorised users of DeepServices.
By whom is data processed?
- Customers of DeepCloud and their employees or other users authorised by the customer of DeepService
- Individuals whose data is contained in the content, documents or files to be processed by DeepService
What data is processed?
Among other things, DeepO can extract the following data from uploaded documents – depending on the analysis criteria and the content of the document, this may include contact details, invoice numbers, contract billing details or payment details.
What is the purpose of the data processing?
DeepO is provided by DeepCloud on behalf of the DeepCloud customer as part of a data processing contract. The purpose of the data processing is therefore determined by the DeepCloud customer who is the data controller.
The data and information are processed by DeepCloud in order to make them available to DeepO, to ensure the secure and seamless use of DeepServices, to contribute to its improvement, and to comply with existing obligations.
Where DeepCloud uses DeepO itself as the data controller, this is for the purpose of automatic data collection and analysis within its ERP system.
What are the legal bases/justification for data processing?
DeepO is provided by DeepCloud on behalf of the customer as part of a data processing contract. For this reason, data processing is carried out in accordance with the legal bases on which the customer responsible for this data processing rely. The legal bases for this include, for example, the data subject’s consent, overriding legitimate interests, a contract with the data subject, or legal obligations.
Where DeepCloud uses DeepO itself as the data controller, this is done on the basis of its legitimate interests in organising its work processes efficiently.
To which recipients is data transmitted?
DeepCloud uses external service providers to deliver DeepO and to handle support cases (which the customer authorises). These are hosting and service providers. They use server locations in Switzerland for this purpose.
How long is data stored?
Fundamentally, DeepCloud data is stored for as long as necessary for the stated purpose and as required by contract or statute. Where there is no longer any purpose for storing the data or any retention obligations, the data will be anonymised or deleted – once the applicable backup retention periods have expired.
DeepService DeepMail
With DeepMail, documents can be stored directly in the user’s Private Box using end-to-end encryption. In this private box, only the recipient has access to the document. They use the link in a DeepMail email to create a DeepCloud account or to log in to his existing DeepCloud account. DeepMail can be integrated with customers’ ERP systems, enabling documents to be sent directly via DeepMail from within those systems.
Data processing carried out by DeepService:
The recipient’s email address provided will be used to send the DeepMail. In addition, personal data may be contained in the documents that are filed and stored in the user’s Private Box.
The decision to use DeepMail and process data in the process rests with the customer, and is carried out by their authorised DeepServices users.
By whom is data processed?
Data relating to the recipient of the DeepMail and to those individuals whose data is contained in the documents is processed.
What data is processed?
DeepMail processes the recipient’s email address and, where applicable, the necessary registration details for a new DeepCloud account, as well as the data contained in the stored documents.
What is the purpose of the data processing?
DeepMail is provided by DeepCloud on behalf of the customer as part of a data processing contract. The purpose of the data processing is therefore determined by the customer who is the data controller.
The data and documents are processed by DeepCloud in order to make them available to DeepMail, to ensure the secure and seamless use of DeepServices, to contribute to its improvement, and to comply with existing obligations.
Where DeepCloud uses DeepMail itself as the data controller, this is done for the purpose of securely transmitting documents to the recipient’s Private Box.
What are the legal bases/justification for data processing?
DeepMail is provided by DeepCloud on behalf of the customer as part of a data processing contract. For this reason, data processing is carried out in accordance with the legal bases on which the customer responsible for this data processing rely. The legal bases for this include, for example, the data subject’s consent, overriding legitimate interests, a contract with the data subject, or legal obligations.
Where DeepCloud uses DeepMail itself as the data controller, this is done in accordance with the law or on the basis of the consent of the data subject – for example, an employee or job applicant – in order to send them the necessary documents, and on the basis of its legitimate interests in organising its work processes efficiently.
To which recipients is data transmitted?
DeepCloud uses external service providers to deliver DeepMail and to handle support cases (which the customer authorises). These are hosting and service providers. They only process data for the designated purposes and are contractually bound to comply with the data protection obligations under the relevant data protection laws. They have been carefully selected, are bound by instructions and are regularly monitored. They use server locations in Switzerland for this purpose.
If the customer uses DeepMail from within their ERP system, data can also be transferred to the customer’s ERP system.
How long is the data stored?
The documents remain stored provided that the recipient has an active DeepCloud account and does not delete them from the Private Box themselves. If a DeepCloud account is not created after receiving a DeepMail, this Private Box will be deleted after one year.
Fundamentally, DeepCloud data is stored for as long as necessary for the stated purpose and as required by contract or statute. If there is no longer any purpose for storage or contractual or statutory retention obligations no longer exist, anonymisation or deletion will occur after expiration of existing backup periods.
DeepService DeepV
With DeepV, dashboards and PDFs can be created and shared from reporting tools such as the Abacus Data Analyzer. This allows you to view clear visualisations on the dashboards within the Data Analyser, covering various areas. Anyone with access to them can comment on these using the comment function.
Data processing carried out by DeepService:
The data processing operations depend on the documents or data records entered for analysis. The customer, through its authorised DeepV users, decides on the data and how it is to be processed as part of the requested analysis.
By whom is data processed?
Various categories of individuals may be affected by data processing; this depends on the dataset being analysed. Possible examples include:
- Customers of DeepCloud and their employees or other users authorised by the customer of DeepService
- Our clients’ clients and their employees
- Employees and applicants
- Individuals whose data is contained in the content, documents or files to be processed by DeepService
What data is processed?
DeepV processes the following categories of data:
- Metadata
- Contact details such as an email address (if a dashboard is shared)
- Master data such as first name and surname (when comments are posted)
- Data derived from the visualisations and the underlying datasets
What is the purpose of the data processing?
DeepV is provided by DeepCloud on behalf of the customer as part of a data processing contract. The purpose of the data processing is therefore determined by the customer who is the data controller.
The data and information are processed by DeepCloud in order to make them available to DeepV, to ensure the secure and seamless use of DeepServices, to contribute to its improvement, and to comply with existing obligations.
Where DeepCloud uses DeepV itself as the data controller, this is done to improve data analysis capabilities with a view to making its workflows more efficient.
What are the legal bases/justification for data processing?
DeepV is provided by DeepCloud on behalf of the customer as part of a data processing contract. For this reason, data processing is carried out in accordance with the legal bases on which the customer responsible for this data processing rely. The legal bases for this include, for example, the data subject’s consent, overriding legitimate interests, a contract with the data subject, or legal obligations.
Where DeepCloud uses DeepV itself as the data controller, this is done on the basis of its legitimate interests in organising its work processes efficiently and in making sound decisions based on data analysis.
To which recipients is data transmitted?
The customer, through its authorised users, decides whether to grant other people access to the reports. They can invite them by email. Similarly, data is exchanged with the customer’s connected ERP system, provided that the customer has set up such a connection.
DeepCloud uses external service providers to deliver DeepV. These are hosting and service providers. They use server locations in Switzerland for this purpose.
How long is the data stored?
Once the analysis has been completed, the data is stored by DeepCloud for a defined, limited period of time and is then automatically deleted unless the customer deletes it beforehand.
Fundamentally, DeepCloud data is stored for as long as necessary for the stated purpose and as required by contract or statute. Where there is no longer any purpose for storing the data or any retention obligations, the data will be anonymised or deleted – once the applicable backup retention periods have expired.
DeepService DeepForms
DeepForms can be used to create surveys on a variety of topics. There are various question types, such as checkboxes, text input fields, drop-down menus, date fields and document uploads.
Data processing carried out by DeepService:
Depending on the content of the survey, data relating to the participants will be processed, as well as data relating to those who initiate the survey and take part in it.
By whom is data processed?
Depending on who the survey is sent to and what it contains, data from various categories of individuals may be processed; these could include, for example:
- Customers of DeepCloud and their employees or other users authorised by the customer of DeepService
- Our clients’ clients and their employees
- Business partners such as suppliers, partners
- Freelancers
- Interested parties
- Employees of the above-mentioned categories as points of contact
- Employees and applicants
- People whose data is contained in DeepForms or who are asked to complete a survey
What data is processed?
DeepForms also allows you to conduct anonymous surveys. No personal data is processed in this process.
If a survey is not designed to be anonymous, the person completing it must provide their email address and name. It is also possible to restrict the survey to people who are part of the user’s organisation. In this case, employees log in via SSO, using their work email address.
What is the purpose of the data processing?
DeepForm is provided by DeepCloud on behalf of the customer as part of a data processing contract. For this reason, data processing is carried out in accordance with the legal bases on which the customer responsible for this data processing rely. The legal bases for this include, for example, the data subject’s consent, overriding legitimate interests, a contract with the data subject, or legal obligations.
Where DeepCloud uses DeepForms itself as the data controller, this is done to clarify existing circumstances, improve data analysis capabilities with a view to making its workflows more efficient.
What are the legal bases/justification for data processing?
DeepForm is provided by DeepCloud on behalf of the customer as part of a data processing contract. For this reason, data processing is carried out in accordance with the legal bases on which the customer responsible for this data processing rely. The legal bases for this include, for example, the data subject’s consent, overriding legitimate interests, a contract with the data subject, or legal obligations.
Where DeepCloud uses DeepForms itself as the data controller, this is done on the basis of its legitimate interests in organising its work processes efficiently and in making sound decisions based on data analysis.
To which recipients is data transmitted?
The user decides to whom the survey results are sent via DeepForms. Similarly, data is exchanged between DeepCould and connected ERP system, provided that the customer has set up such a connection.
DeepCloud uses external service providers to deliver DeepForms. These are hosting and service providers. They use server locations in Switzerland for this purpose.
How long is the data stored?
The data is stored on DeepCloud until the user deletes the survey results.
DeepService DeepPortal
With DeepPortal, customers can create their own portals based on DeepServices. For example, fiduciaries can set up portals for their clients, providing them with an overview of their schedule, DeepServices, activities, etc. This can be individually configured.
Data processing carried out within DeepService
Depending on which DeepServices are integrated into DeepPortal, the data processing is determined by these DeepServices. Customers are invited by email; if personal data is contained in the email address, this data is processed in the process. The customer then logs in via a DeepCloud account or creates one. More detailed information on how data is processed in relation to the respective DeepServices and the DeepCloud account can be found in the relevant sections of this privacy policy.
By whom is data processed?
Data processing is determined by which DeepServices and content (such as contact persons and the agenda) are integrated into DeepPortal. More detailed information on which individuals’ data is processed in the respective DeepServices can be found in the relevant sections of this privacy policy.
What data is processed?
Data processing is determined by which DeepServices are integrated into DeepPortal. More detailed information on which data is processed in the respective DeepServices can be found in the relevant sections of this privacy policy.
What is the purpose of the data processing?
The aim is to provide a personalised portal solution tailored to the customer or to their own customers and staff.
What are the legal bases/justification for data processing?
DeepPortals are provided by DeepCloud on behalf of the customer as part of a data processing contract. For this reason, data processing is carried out in accordance with the legal bases on which the customer responsible for this data processing rely. The legal bases for this include, for example, the data subject’s consent, overriding legitimate interests, a contract with the data subject, or legal obligations.
Where DeepCloud uses DeepPortal itself as the data controller, this is done on the basis of its legitimate interests in organising its work processes efficiently and presenting itself in the best possible light to customers and staff.
To which recipients is data transmitted?
DeepCloud uses external service providers to deliver the DeepPortals. These are hosting and service providers. They use server locations in Switzerland for this purpose.
Otherwise, no data is generally transferred to other recipients, unless there is a connection to such a data recipient that has been set up by the customer via its authorised users.
How long is the data stored?
The retention periods depend on the DeepServices integrated in each case and can therefore be found in the relevant chapters. Portals themselves are removed when they are deleted by the customer.
DeepService DeepInfos
DeepInfos provides its users with access to company-related data aggregated from various sources. Using the query function, data can be enriched by combining information from various sources, and potential links between different organisations and individuals can be displayed.
Data processing carried out by DeepService
DeepInfos processes data relating to individuals who are associated with a company and are therefore, for example, listed publicly in the commercial register.
By whom is data processed?
Data relating to individuals listed in commercial register entries or entries in other business-related databases, such as members of the management board or authorised signatories, may be processed.
What data is processed?
The following categories of data may be processed:
- Names and addresses of individuals listed, for example, in commercial register entries
- Company names
- Addresses (street, house number, postcode, town)
- Company IDs (UID)
- VAT numbers
- NOGA codes (industry classification)
- EGID data
Addresses from an address master in an ERP system (such as Abacus Software) can be synchronised with DeepInfos, but only if they are addresses of the ‘Organisation’ type, as DeepInfos stores only business addresses and not those of private individuals.
What is the purpose of the data processing?
The purpose of data processing is to maintain up-to-date company-related personal data when entering addresses into an ERP system, and to improve DeepServices such as DeepSign, for example to determine and verify authorisation to sign an electronic signature.
What are the legal bases/justification for data processing?
DeepCloud provides DeepInfos as the data controller. This is done on the basis of their legitimate interests in organising their work processes efficiently, using up-to-date address information, and improving their DeepServices for their customers.
To which recipients is data transmitted?
DeepCloud uses external service providers to deliver DeepInfos. These are hosting and service providers. They use server locations in Switzerland for this purpose.
How long is the data stored?
The data is continuously updated and stored, provided it has not been deleted from the information sources.
Use of AI tools by us
We also use AI tools in our work that do not necessarily process personal data, but fulfil technical security requirements such as virus checks or protection against bots.
When we use an AI tool to support us in our work, we pay attention to their legally compliant use and want to ensure the necessary transparency in their use. If we use an AI tool to support us in our work, we will do so in accordance with existing regulations and our values. As a rule, they fulfil narrowly defined procedural tasks, improve our previously performed activities or only carry out a preparatory task.
We examine their use and possible negative consequences for those affected. We do not use AI tools that make decisions for us, significantly influence the results of a decision and could have a significant impact on people. We ensure that preparatory decisions on results made by them are always reviewed by a human. If an AI tool used by us is in direct dialogue with humans, we will inform you of this by means of a notice. We are and remain responsible, even if we use AI tools to support us.
DeepService DeepA
DeepA is an AI-powered assistant that helps with the analysis and processing of information within DeepServices or, provided a connection has been established to the customer’s ERP system, supports these processes. To this end, information is drawn from the customer’s ERP system, as well as from the company’s own connected AI models or those of other providers.
Data processing carried out by DeepService
Whether data processing takes place depends on the specific use case of DeepA and the data input to and output from the AI assistant.
By whom is data processed?
Various categories of individuals may be affected by data processing; this depends on the use case, the input and output, and the AI model. Possible examples include:
- Customers
- Employees
- Suppliers
- Applicants
- Individuals whose data is processed during input or output, or who are included in the AI model
What data is processed?
DeepA processes the following categories of data:
- Data derived from the inputs and outputs and the underlying data records in the AI model or the ERP system
- Image data and metadata
- Column headings (depending on the label chosen by the user)
What is the purpose of the data processing?
The purpose depends on the specific use case when using the AI assistant. This is determined by the user via their prompt.
What are the legal bases/justification for data processing?
DeepA is provided by DeepCloud on behalf of the customer as part of a data processing contract. For this reason, data processing is carried out in accordance with the legal bases on which the customer responsible for this data processing rely. The legal bases for this include, for example, the data subject’s consent, overriding legitimate interests, a contract with the data subject, or legal obligations.
Where DeepCloud uses DeepA itself as the data controller, this is done – depending on the specific use case when utilising the AI assistant – either on the basis of its legitimate interests in optimising its work processes, or following the consent of the data subject and with a view to presenting itself in the best possible light to customers and staff.
To which recipients is data transmitted?
DeepCloud uses external service providers to deliver DeepA. These are hosting and service providers. They only process data for the purposes described by DeepCloud and are contractually bound to comply with the data protection obligations under the relevant data protection laws. They have been carefully selected, are bound by DeepCloud’s instructions and are regularly monitored. They use server locations in Switzerland for this purpose.
In principle, however, no data is passed on to third parties.
How long is the data stored?
No data from DeepA is stored on DeepCloud.
DeepService DeepTranslate
What does DeepService do?
DeepService DeepTranslate can be used to translate texts into a variety of languages. In addition, other DeepServices and Abacus products can be automatically translated into the desired language using this tool.
Data processing carried out by DeepService
Depending on the content to be translated by DeepTranslate, a wide variety of data processing operations may take place.
By whom is data processed?
Different categories of individuals may be affected by data processing carried out by DeepTranslate, depending on which DeepServices or texts are being translated. Possible examples include:
- End customers and business customers
- General customers
- Employees of customers
- Users of an App, such as a person to be identified
- Signatory for an electronic signature
- Employees
- Business partner
- Subscribers
- Freelancers
- Contact persons (employees of a business partner/customer)
What data is processed?
Depending on how DeepTranslate is used, various categories of personal data may be processed. Possible applications include, for example:
- Personal master data (e.g., name, company name, address)
- Communication Data (e.g., telephone, email address)
- Identification data (e.g., user ID or identity UID)
- Data from identification documents (e.g., ID cards and passports) such as name, maiden name, date of birth, nationality, photo, data and certificate of the NFC chip, ID data, date of issue, term of validity, country of issue, metadata, optical character recognition, security features, MRZ
- Documents and their content if they contain personal data
- Multimedia data (photos, videos such as challenge response videos and voice recordings)
- Location data
- Diagnosis and analysis data (e.g., product interaction, usage data)
- Data on data subjects’ devices used as means of authentication
- Confirmations, such as acceptance of the applicable GTCs or acknowledgement of the Privacy Policy
To which recipients is data transmitted?
The data is transmitted to DeepCloud and, if connected to an ERP system, to the ERP provider. For further information on how data is processed in the customer’s ERP system, please refer to the ERP provider’s privacy policy.
How long is the data stored?
No data from DeepTranslate is stored on DeepCloud.
What is the purpose of the data processing?
The purpose of data processing is to provide DeepServices in various languages, as well as to translate linked third-party services.
What are the legal bases/justification for data processing?
The data is processed on the basis of the customer’s consent to the use of DeepTranslate. This consent may be withdrawn at any time. Data processing that has taken place up to that point remains lawful on the basis of the prior consent.
DeepService DeepLaw
DeepLaw can be used to search various legal sources (statutes, case law). This involves using the chat function to enter a query, which then searches various sources of information and provides an answer to the question asked.
Data processing carried out by DeepService
Where the information sources on which DeepLaw is based contain personal data, such data may be processed.
By whom is data processed?
Depending on the data contained in the sources, various categories of individuals may be affected. The options are:
- Case law
- Members of the judiciary (such as court clerks or public prosecutors)
- The parties or their legal representatives, as well as other parties to the proceedings, unless anonymised in the judgment
What data is processed?
Depending on the data contained in the texts, different categories of data may be processed.
What is the purpose of the data processing?
The purpose of DeepLaw is to carry out legal research by answering queries, taking into account various sources of information and utilising AI.
What are the legal bases/justification for data processing?
DeepLaw is provided by DeepCloud on behalf of the customer as part of a data processing contract. For this reason, data processing is carried out in accordance with the legal bases on which the customer responsible for this data processing rely. The legal bases for this include, for example, the data subject’s consent, overriding legitimate interests, a contract with the data subject, or legal obligations.
Where DeepCloud uses DeepLaw itself as the data controller, this is done on the basis of its legitimate interests in organising its work processes efficiently and in making sound decisions based on data analysis.
To which recipients is data transmitted?
DeepCloud uses external service providers to deliver DeepLaw. These are hosting and service providers. They use server locations in Switzerland for this purpose. DeepCloud also makes use of publicly available legal texts and case law databases.
How long is the data stored?
No data from DeepLaw is stored on DeepCloud.
DeepService DeepAnalyze
With DeepAnalyze, financial analyses can be generated quickly and dynamically customised. This involves using DeepAnalyze’s chat function to enter a query, which then generates a programme code that searches the relevant information sources and provides an answer to the question asked.
Data processing carried out by DeepService
In principle, no personal data needs to be processed when using DeepAnalyze. Where the information sources on which the analysis is based contain personal data relating to the customer , this data may be processed by DeepAnalyze.
By whom is data processed?
Depending on the data contained in the information sources, different categories of individuals may be affected.
What data is processed?
Depending on the data contained in the information sources, different categories of data may be processed.
What is the purpose of the data processing?
The purpose of DeepAnalyze is to create customised programmes for financial analysis (such as cash flow statements).
What are the legal bases/justification for data processing?
DeepAnalyze is provided by DeepCloud on behalf of the customer as part of a data processing contract. For this reason, data processing is carried out in accordance with the legal bases on which the customer responsible for this data processing rely. The legal bases for this include, for example, the data subject’s consent, overriding legitimate interests, a contract with the data subject, or legal obligations.
Where DeepCloud uses DeepAnalyze itself as the data controller, this is done on the basis of its legitimate interests in organising its work processes efficiently.
To which recipients is data transmitted?
DeepCloud uses external service providers to deliver DeepAnalyze. These are hosting and service providers. They use server locations in Switzerland for this purpose.
How long is the data stored?
No data from DeepAnalyze is stored on DeepCloud.
DeepService DeepConfidential
DeepConfidential can be used to handle a variety of requests, such as summaries, comparisons, analyses and translations. Documents uploaded via the chat function are searched as sources of information, and a response to the question asked is provided.
Data processing carried out by DeepService
Where documents uploaded to DeepConfidential contain personal data, this data may be processed.
By whom is data processed?
Depending on the data contained in the documents, different categories of individuals may be affected.
What data is processed?
Depending on the data contained in the documents, different categories of data may be processed.
What is the purpose of the data processing?
The purpose of DeepConfidential is to answer enquiries by taking into account the information sources provided, using AI.
What are the legal bases/justification for data processing
DeepConfidential is provided by DeepCloud on behalf of the customer as part of a data processing contract. For this reason, data processing is carried out in accordance with the legal bases on which the customer responsible for this data processing rely. The legal bases for this include, for example, the data subject’s consent, overriding legitimate interests, a contract with the data subject, or legal obligations.
Where DeepCloud itself acts as the data controller in relation to DeepConfidential, this is based on its legitimate interests in organising its work processes efficiently and obtaining information from the sources used.
To which recipients is data transmitted?
DeepCloud uses external service providers to deliver DeepConfidential. These are hosting and service providers. They use server locations in Switzerland for this purpose.
How long is the data stored?
For every query submitted to DeepConfidential, the input and output data are stored solely for the purposes of that query and are not used to train AI models. They will be deleted immediately after the enquiry. DeepConfidential does not keep a chat history.
AI tools from third-party providers
We use various AI tools from external providers, such as chatbots based on LLMs (Large Language Models) or translation tools, to make them available to our staff for internal use only.
No personal data should be entered. The tools are used solely to provide support and do not make any decisions that affect people. Where content has been generated using AI (such as images or text on a website), this is clearly labelled or is apparent to the viewer from the context.
CV parsing
What does the service do?
CV parsing can be used within a job portal (such as Abacus Applicant Management) to analyse applicants’ documents; this is carried out by Textkernel B.V., Netherlands (Textkernel), using a server solution based in Germany. Further information on how Textkernel processes data is available in the privacy policy on their website.
CV parsing enables data and information to be extracted from CVs so that it can be entered into the application form and subsequently stored in the correct location within the Applicant Management system. This saves time for both the applicant and the employer.
We also use CV parsing in general for our HR system to efficiently search employee documents for relevant data and record this in the HR system.
Data processing carried out as part of the service
If the applicant uploads documents via the application form and ticks the consent tickbox for CV parsing, these documents are fed into the CV parsing system and data from them is automatically populated into the application form in the next step. CV parsing does not make any decisions here, but only transfers the data transmitted to the form. In the next step, applicants can check all the data filled in by CV parsing and correct it if necessary. For existing staff, relevant data can be compiled in the HR system via a search using CV parsing.
By whom is data processed?
Data relating to applicants and, in some cases, employees is processed.
What data is processed?
Depending on the content of the application documents submitted, various categories of personal data may be processed. Possible applications include:
- Personal master data (e.g., name, recipient name, CV)
- Communication data (e.g., telephone, e-mail address)
- Documents and their content if they contain personal data
- Multimedia data (such as photos)
To which recipients is data transmitted?
When using CV parsing, data is transmitted to Textkernel.
How long is the data stored?
The data is processed by Textkernel whilst the form is being completed, then deleted there and stored in the Applicant Management system.
What is the purpose of the data processing?
The purpose of data processing is to efficiently extract data from documents such as CVs, in order to populate the relevant form with this data.
What are the legal bases/justification for data processing?
The applicant can consent to the use of CV parsing and revoke the consent at any time. Data processing that has taken place up to that point remains lawful on the basis of the prior consent.
With the applicant’s consent, we continue to use CV parsing even after an applicant has been recruited, with the process being carried out by management or HR on behalf of the newly recruited employee.
Matomo
Within the DeepCloud account and on DeepCloud websites, the web analytics service Matomo is used. Matomo enables us to analyse the use of the websites, the DeepCloud account and DeepServices, and to improve the respective functions. To do so, different data and information about the use of AbaNinja and its users is collected. Matomo uses cookies, which are stored on the end device, and which enable an analysis of the use of the websites, the DeepCloud account and DeepServices. The information collected and generated is then stored and analysed in Switzerland. Matomo is used with the extension “AnonymizeIP”. This means that IP addresses are processed in abbreviated form, which means that they cannot be directly linked to a person. The IP address transmitted by the browser via Matomo is not merged with other data collected by DeepCloud. DeepCloud automatically deletes the data in Matomo 14 months after its collection, once a month.
The storage of all cookies can be disabled by changing the corresponding setting in the browser software. If the storage of all cookies is disabled, it may not be possible to use the full functionality of all of the features of the AbaNinja website or other websites. You can also prevent the transmission of the data generated by the cookies and related to the use of websites (including the IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available under the following link. The same procedure should then be followed on all the devices used. Please note that if all cookies are deleted, you will need to perform steps outlined above again to prevent the use of Google Analytics. Matomo is an open-source project and is hosted on premise at DeepCloud. Matomo’s current Privacy Policy is available on their website.
Sending messages
We use the email provider retarus GmbH, Bahnhofplatz 65, 8500 Frauenfeld, Switzerland, to send messages from DeepCloud, such as those relating to DeepServices or the DeepCloud account (e.g. invoices, quotations, system notifications, contract amendments, etc.). This provider processes data for the purposes described by DeepCloud and is contractually bound to comply with the data protection obligations under the relevant data protection laws. They have been carefully selected, are bound by DeepCloud’s instructions and are regularly monitored. To do this, it uses server locations in Switzerland. The current Privacy Policy of retarus is available on their website.
Additional services activated by the user
If additional services are used as part of a DeepBox, the Owner agrees to their terms of use and data protection and authorises DeepCloud to enable the necessary data processing, data access, and data exchange so that these additional services can be integrated and used for deepbox. The owner of the DeepCloud account is responsible for granting, restricting or revoking access rights to these additional services, as well as for ensuring that data is processed lawfully within the DeepBox.
DeepPay
DeepPay enables ERP or accounting software to be connected via an interface to Swiss banks, Open Banking platforms (such as bLink) and other payment service providers, thereby enabling the use of their services, such as payment initiation and account information services (AIS & PSS). It is also possible to exchange data between different companies regarding the sending and receiving of invoices (such as AbaBridge). DeepCloud merely provides the interface to these third-party providers for a data exchange so that the executed transactions can be displayed or triggered by the relevant third-party provider. In order to carry out the transactions, data and, where applicable, documents are exchanged between the parties involved in the transaction. To ensure that a transaction can be clearly identified, an application-specific ID is used in conjunction with further details relating to the relevant party. This can be bank or payment-specific data such as account information, account statements, IBAN, or the credit card number. Each party involved is responsible for the data processing taking place in its spheres of activity and for the security of the data in accordance with the agreed provisions. The responsibility for the provision and processing of the additional services and the processing of data and documents when using said services (including the payment and account information processed via these services) does not lie with DeepCloud, but with these third-party providers or the customers as users of this system. The current Privacy Policy of this third-party provider is available on their website.
AbaElster
DeepCloud provides the “AbaElster” service to German Customers for the transmission of information from the Customer’s Abacus ERP to a tax office in Germany in order to use the “Online Tax Office ELSTER” offer for the tax assessment procedure. AbaElster is exclusively intended for use in connection with the electronic submission of tax returns and transmission of tax data in accordance with legal requirements. In the process, information from the Customer’s Abacus ERP is transmitted in encrypted form to DeepCloud’s server in Switzerland. This information is transmitted to the respective tax office. After successful transmission, the information is automatically deleted from DeepCloud’s server.
The information provided includes all relevant personal data required for tax purposes, such as personal identification and contact details (first name and surname, address, date and place of birth, religious affiliation, tax number, identification number, email address, telephone number; details from the advance VAT return, permanent extension application and recapitulative statement (ZM), specifically: taxable turnover, tax amount, tax period, company address, name of the administrator, turnover from customers in the EU along with their names and VAT numbers; technical information such as certificates, IP addresses, device information, MAC addresses, etc.; as well as any data that the customer transmits to the tax office as part of the data processing process. DeepCloud acts here as an order processor for the Customer, which fulfils its legal duty of tax declaration, such that requests for information are to be addressed directly to the respective customer. The respective tax authorities provide separate information on data processing around the taxation procedure and around “ELSTER”.
Commissioned data processing and commissioned service providers
The data processed via a DeepService, as well as the content stored in the DeepServices, is processed within the framework of the existing contractual relationship with the owner of the DeepCloud account. We process this data within the framework of commissioned data processing with the Owner of the DeepCloud account. A commissioned data processing agreement is entered into with us for the use of the DeepCloud account. The aim is that data processing in the context of the use of the DeepServices and DeepCloud takes place mainly in Switzerland. Where we engage service providers within the EU (for example, in Germany) to carry out certain services, the EU offers a level of data protection that is adequate for Switzerland.
If we ourselves, as the responsible party, use contracted service providers for our own purposes, we also try to ensure that data is processed in Switzerland. In special cases, we may require the services of service providers who provide their services outside Switzerland. In such cases, we try to commission service providers in a country that has a level of data protection appropriate for Switzerland. Otherwise, we ensure with suitable guarantees such as standard data protection clauses, other guarantees or upon obtaining your consent that a legally compliant data transfer can take place.
In any case, our commissioned service providers are carefully selected and commissioned. You are contractually bound to comply with data protection obligations under the relevant data protection legislation and with our instructions. They have been carefully selected and are regularly monitored.
Data processing when using our mobile applications (Apps)
This Privacy Policy applies to all DeepCloud Mobile Apps, regardless of the App store in which they are offered.
DeepCloud’s Mobile Apps include:
- DeepBox (Android and iOS)
- DeepID (Android and iOS)
- DeepSign (Android and iOS)
- DeepSign Desk App (iPadOS)
Here we provide information about the data processing performed by us when our Mobile Apps are used. Our Mobile Apps are primarily used for document management (DeepBox App), identification of persons, verification of organisations, and release of expressions of intent and actions, or for authentication and verification of a user (such as DeepID and DeepSign Apps).
The Mobile Apps are used either as a stand-alone solution or in combination with web applications. It is also possible for a Mobile App to be downloaded, and data collected via the Mobile App without any data being transferred to a web application. In this case, the data collected by you via the Mobile App does not leave your device; the same applies to the use of the Mobile Apps in “offline mode.” The collected data remains locally in the Mobile App on your device unless it is switched to “online mode” or synchronised.
As a general rule, our Mobile Apps are either downloaded and used by you on a mobile device, or your employer (or its service provider) requests that you use the Mobile App. The use for data exchange with a web application may then exist within the framework of an existing contractual relationship with you, with your employer, or with another contractual partner.
You are under no obligation to provide your data to DeepCloud. However, it is possible that certain functions of a Mobile App may not be available or only be available to a limited extent if you do not provide data.
What data is processed when using the Mobile Apps?
Various data may be collected when the Mobile Apps are used, transmitted to the corresponding web application linked to the Mobile App, and processed by it. This is done using synchronisation. Some Mobile Apps require that synchronisation with the corresponding web application is permitted. The first step is a check of whether the Mobile App is accepted by this web application or whether any DeepCloud subscriptions exist (“DeepCloud Sub” at DeepBox). User information is transmitted to DeepCloud and compared with existing DeepCloud Subs.
In order to use a confirmed DeepID identity, an exchange of data between DeepCloud and a third-party provider may occur for you as a user of DeepID. For details, please refer to the “DeepID” section.
Depending on the Mobile App, different data of different categories of data subjects may be processed depending on which DeepService is used in order to synchronize or exchange this data between the Mobile App and a web application. How the data controller for the web application (third-party provider) processes this data is within that party’s area of responsibility and DeepCloud is not informed of it.
The following categories of data may be included depending on the Mobile App:
- Personal master data (e.g., name, company name, address)
- Communication data (e.g., telephone, e-mail address)
- Identification data (e.g., user ID or identity UID)
- Data from identification documents (e.g., ID cards and passports) such as name, maiden name, date of birth, nationality, photo, data and certificate of the NFC chip, ID data, date of issue, term of validity, country of issue, metadata, optical character recognition, security features, MRZ
- Documents and their content if they contain personal data
- Multimedia data (photos, videos such as challenge response videos and voice recordings)
- Location data
- Diagnosis and analysis data (e.g., product interaction, usage data)
- Data on data subjects’ devices used as means of authentication
- Confirmations, such as acceptance of the applicable GTCs or acknowledgement of the Privacy Policy
Depending on the Mobile App, these may be the following categories of data subjects:
- End customers and business customers
- General customers
- Employees of customers
- Users of an App, such as a person to be identified
- Signatory for an electronic signature
- Employees
- Business partner
- Subscribers
- Freelancers
- Contact persons (employees of a business partner/customer)
If support is needed, users may send error reports to DeepCloud if anything abnormal occurs when using the Mobile App. The crash logs do not contain any personal data.
When a Mobile App is downloaded, the data required for this purpose will additionally be transmitted to the respective App store (e.g., username, email address, customer number, time of download, any payment information from the App and the individual device number). We have no control over such data processing and are not responsible for it. This data is processed because it is necessary in order to download the Mobile App onto your device. Further information can be found in the privacy policy of the app store in question.
Collection of diagnostic data
We integrate various services (such as Sentry, Firebase Crashlytics and Abalytics) to transmit diagnostic data, depending on the mobile app.
Abalytics is a service provided by Abacus Research AG that is designed to transmit diagnostic data from Mobile Apps to app developers. Abalytics is used, for example, in our DeepBox mobile app.
What diagnostic data is sent to Abacus Research AG?
In the privacy settings, you can choose between the required, minimal or the complete diagnostic data. We advise you to activate collection of complete diagnostic data to enable optimal resolution of malfunctions during use of the Mobile App.
As the diagnostic data required for the operation, fault diagnosis and further development of the Mobile Apps is essential, we have a legitimate interest in collecting it. The user’s consent is required for both minimal and comprehensive diagnostic data.
Crash Logs
The full logs for the applications (including the database)can be transmitted by selecting “Send error report” under “Help” à, which may be useful in cases of support. They are not sent automatically. Only crash logs are sent automatically to help identify faults.
Required diagnostic data
For the purposes of operation, fault diagnosis and improving the Mobile Apps, necessary diagnostic data—specifically information on the use of the Mobile App collected via Abalytics—is gathered.
These include general information such as:
- Actions in the Mobile App: such as tapping tiles
- Device information: Device type, operating system, operating system version (including information such as: (IP addresses or MAC addresses that could be used to identify the user are not transmitted), screen size, language, zoom level
- Use of accessibility tools such as screen readers and large font sizes
- Selection of diagnostic data (required, minimal, complete)
- Does the user have a staff photo: yes/no
- Customer permits certain functions: yes/no
- Team size (relevant for analysing app usage performance)
- A randomly generated user ID that cannot be traced back to a specific person (fake user ID)
- Session ID (provides information on the duration of the session and the average number of actions performed by users)
- Consents granted, such as camera access and push notifications
- Mobile App version
- Mobile App crashes (including stack traces)
The necessary diagnostic data does not contain any personal data and does not allow the user to be identified.
We collect this data in order to provide our products and services across different devices and operating systems and to ensure their accessibility. We also use this data to track user numbers, so that we can identify overall trends and ensure the app remains functional and stable even when user numbers are high.
In addition, we can, for example, track which customers frequently use which features, or notify our customers when a feature is reaching the end of its life cycle, so that they can adapt their processes in good time.
The functionality and stability of our Mobile Apps, as well as their further development, are in our legitimate interest.
Minimum diagnostic data
In addition to the necessary diagnostic data, the minimum diagnostic data includes a unique, traceable user ID, such as a User Identifier (GUID), so that events can be matched in crash reporting and Mobile App faults can be better traced.
Complete diagnostic data
In addition to the necessary and minimum diagnostic data, the full diagnostic data includes information such as the user’s name or email address, any other personal data provided by the user, in order to streamline the support process in the event of a fault with the Mobile App.
By whom is data processed?
Where personal data is processed varies depending on the user of the Mobile App; examples include:
- Customers that use the relevant applications and their employees
- Employees of Abacus companies
To which recipients is data transmitted?
The data is transmitted to Abacus Research AG, a contracted service provider.
How long is the data stored?
The data will be stored for as long as is necessary for the purpose for which it was collected.
What is the purpose of the data processing?
The purposes can be found in the relevant categories of diagnostic data.
What are the legal bases for data processing?
The legal basis can be found in the relevant categories of diagnostic data (overriding legitimate interests or the user’s consent).
Links between mobile apps
When links are used within our DeepID and DeepSign mobile apps between different applications on the same mobile device, we use a third-party provider, Branch Metrics Inc., 195 Page Mill Road, Suite 101, Palo Alto, CA 94306, USA. The current Privacy Policy of this third-party provider is available on their website. There is also an opt-out option:
Opt-out: https://legal.branch.io/#branchio-privacyoptout
The following data, amongst other things, is used when creating links:
- Metadata (such as IP address, time, number of links used)
- Custom data from the QR code (e.g. voucher codes) that is included in the URL to control the process
- Domains/URLs used for linking
This feature can be used to ensure a secure link from the web or from another application to the relevant app. By using this feature, the user consents to the processing of this data. However, the user can also enter this link manually. However, this may be prone to input errors. The aim is to ensure that our mobile apps work properly. This is in our legitimate interest to improve our DeepServices and make them more user-friendly.
Branch Metrics, Inc. is a US-American company, so there is the possibility that data might also be processed in the U.S. Both the EU and Switzerland issued positive adequacy decisions concerning the USA after entering the corresponding Swiss/EU-US Data Privacy Frameworks, so that a data transfer to the USA is lawful following certification of such companies. In addition, we will try wherever possible, to provide further safeguards such as entering standard data protection clauses or obtaining consent to commissioned data processing to ensure lawful data transmission.
Where is the data stored?
Data that DeepCloud stores in a DeepBox is located in a cloud solution certified in accordance with ISO 27001 by a contracted service provider who only processes your data for the purposes described by us. The contracted service provider has been carefully selected and commissioned by us, is bound by our instructions and is subject to regular review. The server locations are in Switzerland.
The DeepBox mobile app (iOS / Android)
Function of the DeepBox Mobile App:
DeepBox allows documents from different sources (via the camera, from the photo album, or from another cloud service) to be transferred to a DeepBox . These can be analysed, scanned and digitised using DeepO. For more detailed information about DeepO and how data is processed when using it, please see: ‘The DeepO service’.
In addition, bills can be paid via the DeepBox app. If you are using an ERP system that is compatible with DeepBox, payments can be initiated directly from the DeepBox app. For more detailed information on how data is processed when you pay invoices via your DeepBox, please see: “Additional services activated by the user”.
The DeepBox app offers DeepSign integration, which allows you to track your documents and the signing process via the DeepBox app.
Technical data and information that is processed and/or stored:
The App supports devices with iOS and Android (from Android version 5.0, exception: Huawei devices with their own operating system that do not support Google Services).
- (Static) URL for access to the DeepBox system
- Authentication factors (Access – & Refresh Token) for access to the DeepBox Tokens are deleted after the user logs out within the App.
- App Version
- Model of the terminal device (iPhone/Android)
- Version Operating System
- Indication of the countries/regions in which the App is used
- Android: CrashReports and StackTrace (Sentry). In the case of event logs, these are active by default (Matomo). The user can set restrictions or deactivate this via the settings.
- iOS: Logs are created by the Sentry for debugging purposes (CrashReports only).
- Documents and content captured via App
“Privacy/ Data Protection”: Display of a window with selection
- Required diagnostic data: CrashReports and StackTrace, specification of countries/regions, Sentry (by default)
- Complete diagnostic data: Event logs (Android)
Saving:
Data, information, and documents for uploading to a DeepBox are (temporarily) stored in the App (storage also possible for offline use) or made available via access authorisation. DeepCloud only stores technical or statistical data on the use of the App (such as crash reports, countries/regions) within the scope of App use, otherwise storage takes place in the user’s mobile device or after transfer of the data, information, and documents in the connected DeepBox.
Third-party services used:
iOS: Sentry, to make the app more secure and to analyse crash reports.
Android: Sentry, to analyse crash reports and Matomo to analyse the use of the App.
Including the libraries listed within the App settings “Licences”.
Access authorisation/s:
The App requires access to the camera function (to be able to scan, store, and read the documents), the photo album (where documents are stored to be used), the calendar (iOS only, so that expiry dates of the documents can be determined by means of the calendar) and the activation of the location services (where the locations are recorded by code). Furthermore, access to the Internet is required to enable a corresponding transfer connection to the connected DeepBox. The access authorisations are requested when the App is installed, and the respective function is used for the first time. They only become active when the user has agreed and can be deactivated at any time, after which certain functions of the App can no longer be used.
Android: On older devices (older than Android 6), permission is requested when the App is installed.
Access protection:
Access protection can take place via the mobile terminal, in which the possible access restrictions are activated, and the existing encryptions are used. No separate App access protection is implemented.
Network protocol:
As a network protocol, the App uses the HTTPS protocol with TLS encryption for communication.
DeepID service and DeepID Mobile App (Android / iOS)
The DeepID service and the DeepID App (DeepID) are used to digitally identify individuals, e.g., in order to be able to use DeepCloud’s digital signature service—DeepSign—to verify organisations, to approve statements of intent and actions, or to enable users to authenticate themselves using DeepID for DeepCloud web applications or for services of third-party providers.
This requires going through an online identification process using the DeepID App. This identification process has been developed and tested in accordance with the legal provisions of ZertES/VZertES in Switzerland and the eIDAS Regulation in Europe, as well as the requirements of recognised certification and trust service providers as part of an implementation plan for identification of persons for advanced and qualified electronic signatures (AES and QES). Verification of the secure online identification process using DeepID and the DeepID App is documented by KPMG and is available in the form of the corresponding documentation. The legal requirements provide for a regular review that audits and confirms the legal changes and functions of DeepID.
A user’s identification documents are checked and digitised as a DeepID. Each user can have only one confirmed DeepID. The process recognises whether the same user appears with different identification documents. Furthermore, each means of authentication must be registered in accordance with the implementation plan and assigned to the user. The user must be the authorised owner of the device and must have sole control over it so that it can be used for authentication. Identity verification and signature creation or other authorisation is linked in the same technical connection, until a new identity verification is carried out.
This ensures that the identified person is actually identical to the active user of the DeepID App and that the authenticated device is in his/her possession. The process required for this purpose is prescribed by the DeepID App. The authentication factors used also include verification of the submitted and approved identification document, the image material, and the challenge response video taken by the person him/herself.
DeepID has a wide range of applications; for instance, the confirmed identity can be used for various services for the authentication of a person in a system login, time recording, access solutions or the release of expressions of intent such as the commissioning of electronic signatures.
The user can change the overall configuration, such as the device used, at any time. However, this automatically leads to a new authentication of the device, possibly even making it necessary to go through parts of the identification process once again. The detailed procedure is described below.
What data is processed in DeepID?
DeepCloud records the following user data for identification purposes and to maintain the traceability of identification confirmation as well as for the use of the DeepID (insofar as this data is disclosed by the user in the identification process or within the DeepID App or is transmitted by a third-party provider for whom the DeepID is to be used):
- Nationality
- Place of residence (country information)
- Photos of the relevant pages (such as front and reverse) of the selected identification document (as permitted by the prescribed process) with the information contained therein (such as surname, first name, gender, date of birth, signature, date of validity and serial number of the identification document, nationality, place of origin, and any biometric data from the photo)
- Where supported: Scan of the NFC chip of an identification document with the data read from it (such as surname, first name, date of birth, address, date of validity and serial number of the identification document, nationality, place of origin, signature, and any biometric data from the photo)
- Distinguished Name: A statutory standard for the form of a name in certificates; the Subject DN includes the name of the signatory, and the Issuer DN the identification of the Trust Service Provider providing the service (in the case of DeepID, DeepCloud)
- Photos and challenge response video of the user from video identification, as specified in the process
- Email address
- Address
- Telephone number
- User ID
- Data on the means of authentication personally used (such as device number) and technical data on the device
- Result of identification and verification (success, failure)
- Information that the user provides in inquiries to DeepCloud (as in the case of support)
- Data on acceptance of DeepCloud’s and third-party providers’ current terms of use, as well as confirmation of the user’s place of residence for advanced and qualified electronic signatures (AES or QES)
- Other data, information or documents provided when using DeepID relating to a requested signature, or to organisations such as commercial register extracts, powers of attorney, shareholder contracts, or other supporting documents relating to specific attributes for a certificate for AES or QES, other relevant information such as the responsible registration office (such as DeepCloud), signature or authentication log files (such as business partner number, process number, process-related data) and hash values
Data is temporarily stored in the DeepID App so that the user can continue the identification process after closing the Mobile App, but only for a limited period of time. If this time window has expired, the data must be recorded again. Once the identification process has been completed, the following data will continue to be stored locally in the DeepID App:
- User ID, device number
- Identity information such as username, place of residence, place of origin, and date of birth
- Profile image if the user uses one for the DeepID App
The identity information is also deleted within the DeepID App and stored in DeepCloud for the use of DeepID as soon as the user has been confirmed in the DeepID App and the affected data can be accessed on a case-by-case basis.
Procedure for identification and the data processing that is carried out:
The user’s identity must be confirmed before using the functionalities of the DeepID App for the first time. To do so, the User shall follow the steps provided for in the DeepID app. In certain cases, a QR code or voucher can be used to start the identification process. He/she indicates their place of residence and nationality. The identification documents approved for identification are selected based on these choices. There are restrictions in this regard for certain third-party services and DeepCloud, as residence is only considered sufficient in certain countries, and only certain countries and their identity documents are accepted. Only those identification documents are permitted that the providers of the certification or trust services allow for this purpose. These will be indicated during the Identification process. The identification documents must be valid at the time of identification.
An identity document – in accordance with DeepCloud’s specifications – is then photographed twice, capturing both the front and the back (including the page with the signature). To make this possible, the user must allow the DeepID App to capture images and videos with their device. If a passport is used, the NFC chip contained therein is automatically read and stored with its certificate, the passport metadata and the passport photo. Data from other identification documents is collected and stored automatically using an image.
The user then performs facial recognition using a 3D selfie and Challenge Response Videos. The user’s biometric data is processed for this comparison to establish identity, which the user expressly consents to. A rating is generated by a test algorithm to determine whether the person named in the identification document is really the user. For this reason, photos and videos must be taken personally by and from the person being identified. If the test produces a positive result, the identification process can be continued. If an error report is made, the user can repeat the process and contact DeepID support if necessary.
The user then confirms his/her data (such as first name, last name, birth date, place of origin, gender), enters his/her residential address and provides his/her email address so that DeepCloud can send him/her important messages such as his/her email verification code. He/she will then receive this verification code using which he/she can confirm his/her email address. The user will receive a recovery code, which he/she must keep in a safe place.
It is necessary that the device used to identify the user can be registered as his/her means of authentication and verified in accordance with a user authentication method recognised in accordance with DIN standards. By doing so, the user confirms that he/she has sole control over the means of authentication.
An AI-based user-centric authentication suite from a third-party provider is used to authenticate the device used to ensure secure communication between the DeepID App and the releases desired by the user, such as the provision of an electronic signature. As an additional security factor, the user specifies a six-digit PIN for access to the DeepID App or activates his/her device’s access protection (such as face ID) as well as the automatic screen lock to unlock the DeepID App in order to protect it from unauthorised access and to protect it from unintentional expressions of intent. The DeepID PIN must be confirmed in order to activate the DeepID App for use.
After that, the user is registered and the identity is verified, a process that can take some time. If the data entered by the user cannot be verified automatically, DeepCloud support endeavours to complete the process, together with the user if necessary. The user can be contacted for this purpose within a reasonable time frame, or contacts DeepCloud support him/herself. After the verification is completed, the user will receive a push notification to this effect.
If the identification of the release of electronic signatures serves a certification or trust service provider in Switzerland or the EU, then once the user has submitted a request, his/her registration for such electronic signatures will only be granted if all prescribed requirements of these providers have been met.
The existence of a registration is checked before each electronic signature is approved; if necessary, the identification must be repeated. The data processing occurring thereby will be performed to the extent required by law for a signature process (identification of the signatory and authentication of the device before release of the signature).
Further data processing performed during use of the App
Within the DeepID App, the user has the option of selecting different functionalities as part of the dashboard. The user may manage his/her data in his/her profile and complete tasks such as releasing statements of intent or actions and starting the process for verification of an organisation. To this end, he/she may invite other persons to identify themselves so that they can subsequently verify an organisation. To do so, the user can use the communication tools available on his/her device, such as email or SMS, to invite the person in question for identification.
After the PIN input is incorrect three times, the user must follow the steps provided by DeepCloud in order to be able to log in to his/her DeepID App again. The following actions are required for this: The user inputs his/her date of birth, retakes a selfie and video, confirms his/her device with the PIN received by email and specifies a six-digit PIN, registers with the access protection he/she chooses.
There is no automated decision-making within the meaning of applicable data protection laws.
To which recipients is data transmitted?
Recipients in connection with the fulfilment of legal obligations: DeepCloud may disclose personal data to recipients if this appears necessary or appropriate to comply with applicable laws and regulations or to verify compliance with them and to respond to requests from competent authorities. This concerns, in particular, state-accredited conformity assessment bodies, audit officers and the approving body for certification services for the purpose of checking the proper performance of the registration service.
Third-party providers as recipients of data: DeepCloud may transfer personal data to third-party providers if the user makes use of a service provided by such a third-party provider, such as if the user wishes to authorise a declaration of intent or action, or in order to enable an authentication for such a service.
Service providers as recipients of data: DeepCloud uses external service providers to deliver DeepID. These are hosting and service providers. They only process data for the purposes described by DeepCloud and are contractually bound to comply with the data protection obligations under the relevant data protection laws. They have been carefully selected, are bound by DeepCloud’s instructions and are regularly monitored. They use server locations in Switzerland for this purpose; their registered office is in Switzerland or the EU, which offers an adequate level of data protection for Switzerland.
What diagnostic data is transmitted to DeepCloud via the DeepID App?
Minimal diagnostic data for diagnosing errors or problems within the DeepID App is collected using Sentry (iOS and Android), to which DeepCloud has access. These do not contain any personal data.
How long is data stored?
Fundamentally, data is stored for as long as necessary for the stated purpose and as required by contract or statute. In the area of identification and in the case of certification and/or trust services, there are very long statutory retention obligations—from completion of the identification process at least 17 years according to ZertES and at least 39 years according to the eIDAS Regulation—in order to be able to prove that a person was identified and that an electronic signature was granted. If there is no longer any purpose for storage or contractual or statutory retention obligations no longer exist, anonymisation or deletion will occur after expiration of existing backup periods.
Information that is necessary to enable users to log into the Mobile App, such as login data or a profile picture, remains stored for as long as the usage relationship with the user, retention obligations or any other purpose for their processing exists.
Diagnostic data is deleted as soon as it is no longer needed for its purpose.
What is the purpose of the data processing?
The data and information are processed by DeepCloud in order to provide the functionalities offered in DeepID, to allow secure and smooth use of the DeepID Service and the DeepID App, to contribute to their improvement, to provide support, and to comply with legal obligations such as responding to official requests.
What are the legal bases/justification for data processing?
DeepCloud collects and processes data and information in accordance with your express consent, based on overriding legitimate interests, a contract or legal obligations.
The DeepSign Mobile App (Android / iOS)
Function of the DeepSign Mobile App:
DeepSign enables electronic signing of digital documents for individuals (signatories) and organisations (if their authorised representatives sign) as well as the use of timestamps. The simple electronic signature (SES), advanced electronic signature (AES) and qualified electronic signature (QES) are available.
The service includes selecting from the electronic signatures provided, displaying and transmitting the documents to be signed, applying the selected electronic signature and/or (qualified) electronic time stamp, inviting other signatories, confirming this, and storing the documents in Deep-Sign.
Technical data and information that is processed and/or stored
The app supports devices (both smartphones and tablets) running iOS and Android, in accordance with the app stores’ guidelines.
- Free device memory
- User ID
- App Version
- Model of the terminal device (iPhone/iPad/Android)
- Version of the operating system
- Time
- Selected time zone
- Battery level
- Android: CrashReports and StackTrace (Sentry). In the case of event logs, these are active by default (Matomo). The user can set restrictions or deactivate this via the settings.
- iOS: Logs are created by the Sentry for debugging purposes (CrashReports only).
- Documents and content captured via App
What diagnostic data is transmitted to DeepCloud via the DeepSign App?
Necessary diagnostic data for diagnosing errors or problems within the DeepSign App is collected using Firebase Crashlytics (Android) or Sentry, to which DeepCloud has access. These do not contain any personal data. To find out how Firebase Inc. and Microsoft handle such information, see their respective privacy policies.
The user is free to choose whether only the necessary diagnostic data or the full set of diagnostic data should be sent to DeepCloud. You will be asked to confirm this the first time you run the app, and you can change it at any time afterwards under ‘Privacy Settings’.
- Required diagnostic data: CrashReports, app usage data, app and device information (such as user ID, time zone, battery level, app version) and StackTrace, Sentry (by default)
When crash reports are sent, the user ID is also sent to DeepCloud. This is so that support can identify which users are affected. Neither the device name nor the IP address is transmitted to DeepCloud.
- Complete diagnostic data: Event logs (Android)
Third-party services used:
iOS: Sentry, to make the app more secure and to analyse CrashReports.
Android: Sentry, to analyse CrashReports and Matomo to analyse the use of the App.
Including the libraries listed within the App settings “Licences”.
How long is data stored?
Fundamentally, data is stored for as long as necessary for the stated purpose and as required by contract or statute.
Data, information and documents are uploaded immediately to the DeepSign service and are stored there on DeepCloud’s servers in accordance with the settings selected in DeepSign. User data is retained until it is deleted by the support team following a deletion request. DeepCloud only stores technical or statistical analysis data on the use of the App (such as CrashReports, countries/regions) within the scope of App use, otherwise storage takes place in the user’s mobile device or after transfer of the data, information, and documents in the connected deepbox.
In the area of identification and in the case of certification and/or trust services, there are very long statutory retention obligations—from completion of the identification process at least 17 years according to ZertES and at least 39 years according to the eIDAS Regulation—in order to be able to prove that a person was identified and that an electronic signature was granted. If there is no longer any purpose for storage or contractual or statutory retention obligations no longer exist, anonymisation or deletion will occur after expiration of existing backup periods.
Information that is necessary to enable users to log into the Mobile App, such as login data, remains stored for as long as the usage relationship with the user, retention obligations or any other purpose for their processing exists.
Diagnostic data is deleted as soon as it is no longer needed for its purpose.
What is the purpose of the data processing?
The data and information are processed by DeepCloud in order to provide the functionalities offered in DeepSign, to allow secure and smooth use of the DeepSign and the DeepSign App, to contribute to their improvement, to provide support, and to comply with legal obligations such as responding to official requests.
What are the legal bases/justification for data processing?
DeepCloud collects and processes data and information in accordance with your express consent, based on overriding legitimate interests, a contract or legal obligations.
Access authorisation/s:
iOS: The photo album is accessed via the photo selection and the file system via the file selection. These functions are provided directly by iOS, so the DeepSign Desk app does not request any permissions, as it only displays the final result from the scanner and the selected photo or file. If the user uses Face ID to secure access to the DeepSign app , permission to access the camera and Face ID will be requested to ensure this feature works properly.
Android: The app requires access to the camera function (to scan and save documents) and to the photo album (where the documents to be used are stored). Access to the ‘internet’ is also required to enable a connection to the linked account on the DeepSign service for data transfer. The access authorisations are requested when the App is installed, and the respective function is used for the first time. They only become active when the user has agreed and can be deactivated at any time, after which certain functions of the App can no longer be used.
Access protection:
Access protection can take place via the mobile terminal, in which the possible access restrictions are activated, and the existing encryptions are used. In addition to these access control measures, the DeepSign Desk app supports the setting up of a PIN code and, provided the device meets the necessary hardware and software requirements, authentication using biometric data (Face ID / Touch ID) is also possible. The biometric data is verified by the operating system and is not stored in the app.
The DeepSign Desk Mobile App (iPadOS)
Function of the Mobile App DeepSign Desk:
The DeepSign Desk app allows documents to be signed on the spot (e.g. at a counter). An iPad is used for signing, which enables signatories to provide a visual signature. This allows counter staff to send the documents immediately after they have been signed via DeepSign or any other preferred application.
To do this, an employee from the organisation enters the relevant login details for the DeepCloud account, after which the signatory can sign the document as described above.
The service includes selecting from the visual signatures provided, displaying and transmitting the documents to be signed, using the visual signature element, and storing the documents in DeepSign.
The DeepSign Desk mobile app does not support signing using QES or FES.
Technical data and information that is processed and/or stored
The app supports devices running iPadOS 16.0 or later.
- Free device memory
- User ID
- App Version
- Model of the terminal device (iPhone/iPad/Android)
- Version of the operating system
- Time
- Selected time zone
- Battery level
- iPadOS: Logs are created by the Sentry for debugging purposes (CrashReports only).
- Documents and content captured via App
What diagnostic data is transmitted to DeepCloud via the DeepSign Desk App?
Necessary diagnostic data for diagnosing errors or problems within the DeepID App is collected using Sentry (iOS), to which DeepCloud has access. These do not contain any personal data. To find out how Firebase Inc. and Microsoft handle such information, see their respective privacy policies.
The user is free to choose whether only the necessary diagnostic data or the full set of diagnostic data should be sent to DeepCloud. You will be asked to confirm this the first time you run the app, and you can change it at any time afterwards under ‘Privacy Settings’.
- Required diagnostic data: CrashReports, app usage data, app and device information (such as user ID, time zone, battery level, app version) and StackTrace, Sentry (by default)
When CrashReports are sent, the user ID is also sent to DeepCloud. This is so that support can identify which users are affected. Neither the device name nor the IP address is transmitted to DeepCloud.
Third-party services used:
iPadOS: Sentry, to make the app more secure and to analyse CrashReports.
Including the libraries listed within the App settings “Licences”.
How long is data stored?
Fundamentally, data is stored for as long as necessary for the stated purpose and as required by contract or statute.
Data, information and documents are uploaded immediately to the DeepSign service and are stored there on DeepCloud’s servers in accordance with the settings selected in DeepSign. User data is retained until it is deleted by the support team following a deletion request. DeepCloud only stores technical or statistical analysis data on the use of the App (such as CrashReports, countries/regions) within the scope of App use, otherwise storage takes place in the user’s mobile device or after transfer of the data, information, and documents in the connected deepbox.
In the area of identification and in the case of certification and/or trust services, there are very long statutory retention obligations—from completion of the identification process at least 17 years according to ZertES and at least 39 years according to the eIDAS Regulation—in order to be able to prove that a person was identified and that an electronic signature was granted. If there is no longer any purpose for storage or contractual or statutory retention obligations no longer exist, anonymisation or deletion will occur after expiration of existing backup periods.
Information that is necessary to enable users to log into the Mobile App, such as login data, remains stored for as long as the usage relationship with the user, retention obligations or any other purpose for their processing exists.
Diagnostic data is deleted as soon as it is no longer needed for its purpose.
What is the purpose of the data processing?
The data and information are processed by DeepCloud in order to provide the functionalities offered in DeepSign, to allow secure and smooth use of the DeepSign Desk and the DeepSign App, to contribute to their improvement, to provide support, and to comply with legal obligations such as responding to official requests.
What are the legal bases/justification for data processing?
DeepCloud collects and processes data and information in accordance with your express consent, based on overriding legitimate interests, a contract or legal obligations.
Access authorisation/s:
iPadOS: The photo album is accessed via the photo selection and the file system via the file selection. These functions are provided directly by iOS, so the DeepSign Desk app does not request any permissions, as it only displays the final result from the scanner and the selected photo or file. If the user uses Face ID to secure access to the DeepSign app , permission to access the camera and Face ID will be requested to ensure this feature works properly.
Access protection:
Access protection can take place via the mobile terminal, in which the possible access restrictions are activated, and the existing encryptions are used. In addition to these access control measures, the DeepSign Desk app supports the setting up of a PIN code and, provided the device meets the necessary hardware and software requirements, authentication using biometric data (Face ID / Touch ID) is also possible. The biometric data is verified by the operating system and is not stored in the app.
Network protocol:
As a network protocol, the App uses the HTTPS protocol with TLS encryption for communication. This reflects the current state of the art.
Events
Registration and participation in an event
You can register for an event such as a course, workshop, forum, webinar, seminar, consultation, (online) event, training, or trade fair (“Event”) on our website. You can send your registration for an Event in writing by post or email to the contact address given in each case or book participation in the event directly on our websites on the Internet or by telephone. The data provided by you will be stored by us and processed for the planning and implementation of the Event as well as for the follow-up support of the participants and, if necessary, passed on to our commissioned service providers. If you take part in an (online) event, a webinar or a survey, certain data such as your email address, name or the company you work for are required for the implementation of the (online) Event, the webinar or for the evaluation of the survey. In some cases, a survey is also conducted anonymously. Commissioned service providers are used precisely for the implementation of such events. We are happy to provide information about our commissioned service providers upon request. When participating in an Event, the General Terms and Conditions for Events apply. We reserve the right to publish your name, company and, if applicable, photo and company logo after an event (e.g. website, flyers, reports, company appearances in social media, etc.) and to delete these posts at any time without giving reasons.
Data processing in response to specific pandemic or epidemic situations
Where necessary, in the event of a specific pandemic or epidemic situation, we may keep attendance records of those present at events so that chains of transmission can be traced. It can record the name, telephone number and – if available – the seat number (for rows of seats). The corresponding list is, depending on the specifications, kept for 14 days and then deleted. If required, it can be made available to authorities so that they can carry out contact tracing. We provide information about how we handle attendance lists before an event.
Participation in a raffle at an event
If participation in a raffle is possible at an event, we process your data so that you can participate in the raffle and a winner can be determined and notified at the end. We use your data within the scope of the sweepstakes based on your consent to participate in the sweepstakes. You can revoke this at any time with effect for the future. You can find more information on a possible revocation under “Your rights”.
Video and photo recordings when participating in an event
We reserve the right to take photos and videos during an event in which you may also be featured. These photos and videos will be used exclusively for our own purposes (e.g. use for company websites, flyers, reports or via newsletters, for company appearances in social media, information to participants via email, etc.) to report on or document the event. If you are shown as part of a larger group of people or are merely an “accessory” to a building or location where you are not the focus of the shots, we may take these photos and videos based on our legitimate interests for the purposes described above. You can object to their use at any time. If you are portrayed as an individual or are the focus of any recording, we will seek your consent for such recording. You then have a right of withdrawal in relation to your consent. If photos and videos (sound and image) are taken of you, e.g. for testimonials, for giving presentations or training, for your support in improving or developing our services, this will only be done with your consent. You can also revoke this consent at any time. Details can be found in the specific declaration of consent.
Online events and meetings
More and more events and meetings are being held online only. This requires an invitation or registration, for which you will be sent an email with a participant link. There may be live presentations, video demonstrations and active information exchange. It is possible that we record an online event with sound and video and that participants can be heard and/or seen. These recordings are used exclusively for the company’s own purposes (e.g. use within a lecture or training series, webinars, for the company’s own websites, flyers, reports, for company appearances in social media, newsletters, information to participants by email), to report on it, to document it or to replay it. When taking part in such an event, participants are set to ‘mute’; nor are participants required to turn on their cameras to show images of themselves. Sound and/or video activation is only carried out by participants after their approval. The release also constitutes consent to the making of audio and video recordings should the online event be recorded. No sound or images are edited out afterwards. If participants do not want to be recorded, they should not activate their audio and video functions throughout the event. It will still be possible to send questions to the moderator(s) via the chat function. These will be answered by the moderator(s) as far as possible during the event or in person via the chat function. For the planning and implementation of such events and meetings (including the sending invitations and confirmations of participation, the analysis of the event or surveys relating to it) we use evenito AG, Limmatquai 122, 8001 Zurich, Switzerland. This is a service provider commissioned by us which receives your data for the purposes described above and which itself uses commissioned service providers for this purpose. We also use software solutions from Zoom Video Communications (“Zoom”), Inc.,55 Almaden Blvd, Suite 600, 95113 San Jose, California/USA for meetings. These companies also process data in the U.S. Both the EU and Switzerland issued positive adequacy decisions concerning the USA after entering the corresponding Swiss/EU-US Data Privacy Frameworks, so that a data transfer to the USA is lawful following certification of such companies.
Lead generation at events
At certain events, such as trade fairs, we may collect your data using the barcode on your admission ticket, provided the trade fair organiser permits us to process such data. In doing so, personal data such as your name, address, telephone number and email address may be processed (depending on the details you provided when registering for the event).
You decide for yourself whether you wish to share your data with us by presenting your ticket with the barcode for us to scan. For this data processing, we use a service provider commissioned by us, to whom your data is passed on for the purposes described above. They were carefully selected and appointed by us. They are bound to our instructions and are regularly monitored. The data required for the lead generation is transmitted to them. This data is also processed outside Switzerland; at present, data processing takes place in the EU, which offers an appropriate level of data protection for Switzerland.
Your application
On our website under “Jobs”and our company presence on LinkedIn, as well as on various job portals, you have the opportunity to find out about current vacancies at DeepCloud and to apply for them. The privacy policy for our job portal also applies here, which can be viewed at jobs.abacus.ch/datenschutz-jobportal.
If you wish to send us an application, such as a speculative application, e.g. by email, we would like to point out that you should preferably use our careers portal and that unencrypted emails are not protected against unauthorised access whilst in transit. You can encrypt your attachments yourself should you choose to submit your application by email, for example with a ZIP solution and communicate the corresponding password separately (by telephone). If you apply for an advertised position by email, the data you provide (e.g. title, name, postal address, email address, telephone number, languages, earliest start date, your cover letter, and other data and documents you provide) will be stored to process your application. This is done to carry out pre-contractual measures with you in relation to possible employment as an employee.
Other data processing in the context of your application
If you provide references as part of the application process, we will assume that, where the data relates to an individual, you have obtained their consent for us to contact them and you consent to us obtaining the reference from that individual. If we ask for a reference, we will only contact them with your consent. Consent is given voluntarily and can be revoked at any time for the future.
In order to get a better picture of your professional background, we can visit your professional profiles on LinkedIn and Xing and, if there is a specific reason regarding your suitability, we can also carry out a Google search on you. We process this publicly available job-related data about you in our interest to find out whether you fit the advertised position and our company. If you do not want this, you can let us know.
Quality of your data when applying
The data you provide should be accurate, complete, not misleading, and up to date. Failure to do so may result in your application not being considered or appropriate legal consequences being drawn after you have already been recruited.
Storage period of your application
If the application procedure does not lead to a position being filled, your application will be deleted or anonymized at the latest four months after completion of the application procedure, unless the data is needed to defend legal claims asserted against us from the application procedure (this is done on the basis of our legitimate interests), unless a different period is provided for by law or you have expressly consented to further processing of your data. If your application leads to employment, all data required for this will be processed within the framework of your employment relationship in accordance with the statutory provisions.
Recommendations and references for our services
With your consent, we publish on our websites and other places (such as in our Newsletter) personal recommendations from you or references by photo, video or written statements as a satisfied customer or how to use our services. In some cases, we also use your company logo. This is done after you have given your consent. You can revoke your consent to this; details can be found in the specific declaration of consent.
Surveys about our services
We may conduct surveys on certain topics (e.g. to improve and expand our services). Your opinion is very important. A survey will help us determine customer satisfaction of current solutions and the needs of our customers. This is in our interest as well as yours when using our DeepServices. To do this, we send selected people an invitation email with the link to the survey, whereby we receive your name and email address as part of our contractual relationship with you or with the company for which you work. Participation in a survey is always voluntary and only takes place with your consent. By closing the browser, it is possible to terminate the survey at any time without any adverse consequences for you. We store and analyse the results of the survey based on legitimate interests to improve our DeepServices. We may also share the results of surveys with our business partners or prospects, but no personal information will be disclosed. As part of a survey, you also provide us with data such as your name, email address or the company you work for, as well as data resulting from the survey that you can provide (in a free text) within the survey. To carry out surveys, we use the MS Forms survey tool provided by Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. For further information on how Microsoft processes data when using Forms, please refer to their privacy policy at: https://www.microsoft.com/de-de/privacy/privacystatement
As the parent company of Microsoft, Microsoft LLC. is an US-American company, so there is a possibility that data could also be processed in the USA. Both the EU and Switzerland issued positive adequacy decisions concerning the USA after entering the corresponding Swiss/EU-US Data Privacy Frameworks, so that a data transfer to the USA is lawful following certification of such companies. In addition, we will try wherever possible, to provide further safeguards such as entering standard data protection clauses or obtaining consent to commissioned data processing to ensure lawful data transmission.
Use of Add-Ins with DeepServices
You have the option of using add-ins in DeepServices. This allows documents from document processing systems (such as MS Office and Google Docs) to be digitally signed directly using DeepSign.
Which diagnostic data is transmitted to DeepCloud AG when using the Add-Ins?
Diagnostic data (usage data and crash logs) is collected so that faults when using the Office Add-Ins can be optimally rectified. Diagnostic data does not contain any user-specific data and is transmitted to DeepCloud AG via Sentry. To find out how Sentry handles such information, see its privacy policy.
Usage data
The usage data contains anonymous data, including information on how the Office Add-Ins are used and with which device types.
Crash Logs
Crash logs contain detailed logs to improve the performance and stability of the Office Add-Ins.
How long is the Diagnostic saved?
Diagnostic data is deleted as soon as it is no longer needed for its purpose.
What is the purpose of the data processing?
Diagnostic data is intended to enable secure use of the Office Add-Ins and to help improve it.
What are the legal bases/justifications for data processing?
DeepCloud AG processes such informationbased on our legitimate interests in enabling secure and trouble-free use of the Office Add-Ins.
21.AbaNinja / 21.AbaSalary / NinjaBox
General use
21.AbaNinja / 21.AbaSalary and NinjaBox, collectively referred to as “Ninja”, are web-based software applications for in-house (payroll) accounting, offering the option to integrate your own payroll service provider, utilise interfaces with various banks and payment providers, and use time-tracking solutions via mobile Abacus applications such as AbaClock, AbaClik, AbaTrak or AbaPoint, which also enable data to be processed and exchanged between the parties involved. 21.AbaSalary enables Ninja owners, in particular, to manage wages – including payroll processing, payment, analysis and accounting – regardless of time or location, and also allows them to create documents such as payslips, monthly summaries and reports.
Once you have successfully registered on the Swiss21.org portal and opened a Ninja account – which requires you to provide your first name, surname, an email address and a password – you can log in to Ninja and also have the option to use 21.AbaSalary. You will need your username and password to log in. Alternatively, you can log in using another account, such as a Microsoft, Apple or Google account. Their data protection provisions apply.
Ninka comprises the permission to use the relevant software online and the storage of data through hosting. The owner responsible for the use of Ninja, as well as administrators authorised by them, may grant other users (as authorised users) access to Ninja.
When using Ninja, all data provided during registration is stored, as well as all data and documents that are recorded and processed within Ninja. This includes data relating to address registration, bookkeeping, invoices and quotations, time recording, expense claims, and payroll accounting, such as payroll processing, payment, analysis and posting of wages.
The data processed in Ninja may include the following: Personal master data such as name, address, date of birth, employer, contact details such as telephone number and/or email address, time and attendance data such as working hours, absences (sickness or holidays), overtime, expense claims, payslips and monthly summaries of these for all employees, payroll master data, reports on employees, payslips and salary statements, data and documents in personnel files, photographs of employees, product master data, data relating to contractual relationships and contract details including delivery, payment and invoicing details, bank account and credit card details, as well as all data recorded or migrated within Ninja. This data may come from current and former employees and job applicants, service providers, suppliers, banks and other payment providers, customers, business partners, prospective customers, and all the employees of the companies who act as contacts for these companies.
Using the ‘auto-complete’ function when entering an address
In Ninja, you can use an ‘auto-complete’ function when entering an address. Only business addresses are available; addresses of private individuals are not included.
Support at Ninja
You can contact us via the contact form for support. The support channel is managed by a team from Abacus Research AG. To send emails via Ninja (invoices, quotations, system notifications, etc.), we use the email provider Mailgun Technologies, Inc, 548 Market St, 43099 San Francisco, USA (Mailgun).
These are contracted service providers to whom data is disclosed for the purposes described above; we have entered into contractual agreements with these providers to ensure that their server solutions are located within the EU. They were carefully selected and commissioned, bound by our instructions and are regularly monitored. The data transmitted includes information required to provide the relevant service, such as your name, email address, company and the nature of your enquiry. This data is also processed outside Switzerland. At present, data processing is taking place within the EU, which offers a level of data protection that is adequate for Switzerland. Here you will find Mailgun’s current privacy policy: https://www.mailgun.com/privacy-policy/
Mailgun is a US-American company, so there is the possibility that data might also be processed in the U.S. Both the EU and Switzerland have issued positive adequacy decisions regarding the USA, after entering into a Swiss/EU-US Data Privacy Framework. In addition, we will try wherever possible, to provide safeguards such as entering standard data protection clauses or obtaining your consent to commissioned data processing to ensure lawful data transmission.
The data contained in Ninja is processed within the framework of the existing contractual relationship with the Ninja owner. DeepCloud processes this data as part of a data processing arrangement with the Ninja owner. A data processing agreement, in its current version, will be entered into for the purposes of this use.
Additional Services
If additional services are used as part of Ninja, the Ninja Owner agrees to their terms of use and data protection and authorises DeepCloud to enable the necessary data processing, data access, and data exchange so that these additional services can be integrated and used. These additional services are subject to their respective terms and conditions and privacy policies. Where the services of a trustee are used, the Ninja Owner shall grant the trustee access to the data in Ninja in order to carry out the necessary data processing and data synchronization.
Ninja contains the option of connecting to services of different payment providers such as banks or payment service providers. These providers can be connected to directly or a connection to these providers can be established by using the DeepPay service. If the Ninja Owner wishes to make use of these services, data must be exchanged between the respective parties. A unique ID is used to link the data to the relevant application, together with the necessary login details for the provider. This may include banking or payment-related data. Each party involved is only responsible for the data processing that takes place and for the security of the data in its area of responsibility in accordance with the agreed provisions. DeepCloud enables data to be exchanged exclusively through an interface to these providers in order to map them in the applications, without being involved in the services provided by the other parties or having influence on their services.
DeepCloud offers additional services such as DeepO (a workflow analysis software program for structuring data using machine learning and automated document posting in accounting using AI) or DeepV (a sharing and publishing platform that features additional elements such as a dashboard or chat function), which are integrated into Ninja. By accepting these DeepServices, data processing will also take place via a connection to Ninja. Separate data protection provisions apply to these additional DeepServices.
Ninja owners also have the option of using AbaClock, an iPad-based time-tracking app. To connect AbaClock to Ninja, you need to obtain a Ninja API token. This API token can be registered using the iPad’s front-facing camera. . Data such as first name and last name, employee language, flextime balance, planned hours, and vacation balance, as well as the recorded times is processed. To ensure that the data on Ninja is also recorded, the user receives time recording badge via the iPad terminals. Once an initial verification has been carried out to confirm their authorisation for time recording, their times can also be recorded in Ninja via the iPad terminals.
In addition, Ninja can also be connected to and used with AbaClik. AbaClik is a mobile app provided by Abacus Research AG that allows you to record working hours, expenses, services, and all types of information, assign projects, customers, or employees, and synchronize with the applications. The AbaClik mobile app can be downloaded free of charge for iOS and Android from the respective App Stores. If data from AbaClik is to be collected in Ninja, a connection will be established once the user has logged in using the email address and password stored in their Ninja account. The user must agree to the data being exchanged in order to use the connection. If you wish to use AbaClik without connecting it to Ninja, this is also possible. In such cases, the data collected remains stored locally on the smartphone, without any data being transferred to Ninja.
For information on how data is processed in mobile applications, please refer to the privacy policies of the respective providers.
Data processing by Google
Ninja uses Google Tag Manager (a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; hereinafter referred to as ‘Google’, acting as the data controller in the EU, the EEA and Switzerland). That way, it is possible to manage website-tags. Tags are little pieces of code on the website that facilitate using Google’s implemented services. No data is processed by Google Tag Manager alone, but it does allow cookies to be set.
In addition, Google Analytics (“GA”) and Google Signals (which are likewise Google services) are also used in Ninja. GA enables cookies to be set in order to analyse how users use AbaNinja and to improve its functionality. Google Signals collects additional information about Users who have activated personalized displays (interests and demographic data). This allows shipping displays to such Users in cross-device remarketing-campaigns. To that purpose, various data and information about the usage and its Users are collected and generally sent to a Google server in the USA, where that data is stored.
Ninja uses Google Analytics exclusive with the extension “anonymizeIp(),” which is designed to prevent any direct personal reference. That extension is used by Google to truncate the IP address within EU Member States or other Contracting States to the EEA Agreement. Only in exceptional cases is the full IP-address sent to a Google server in USA and truncated there. According to Google, the IP address sent by the browser within GA will not be combined with other Google data. During a visit, User behaviour is recorded in the form of “events”. Events can be:
- Page views
- First visit to the website
- Start of the session
- Websites visited
- “Click path”, interaction with the website
- Scrolls (whenever a user scrolls to the end of the page (90%))
- Clicks on external links
- Internal search queries
- Interaction with videos
- File downloads
- Viewed / clicked adverts
- Language setting
The following is also recorded:
- Approximate location (region)
- Date and time of the visit
- IP address (in abbreviated form)
- Technical information about the browser and the end devices used (e.g. language setting, screen resolution)
- Internet provider
- Referrer URL (via which website/advertising medium this website was accessed)
- Google uses this information to analyse a User’s pseudonymous use of Ninja and to compile reports on their activities.
Recipients of the data are/may be
- Google Ireland Limited (cf. above)
- Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA
- Alphabet Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, USA
This is a US-American company, so there is the possibility that data might also be processed in the USA. Both the EU and Switzerland have issued positive adequacy decisions regarding the USA, after entering into a Swiss/EU-US Data Privacy Framework. In addition, we will try wherever possible, to provide further safeguards such as entering standard data protection clauses or obtaining consent to commissioned data processing to ensure lawful data transmission.
We automatically delete the data within the scope of Google Analytics after 14 months of its collection, once a month.
The storage of cookies can be disabled by the corresponding setting in the browser-software. If the storage of all cookies is disabled, it may not be possible to use the full functionality of all of the features of the Ninja website or other websites. You can also prevent the transmission of the data generated by the cookies and related to the use of websites (including the IP address) to Google and the processing of this data by Google by downloading and installing the browser plug-in available under the following link. The same procedure should then be followed on all the devices used.
The current link is https://tools.google.com/dlpage/gaoptout?hl=de
Please note that if all cookies are deleted, you will need to perform steps outlined above again to prevent the use of GA.
Here you will find the current terms of use of GA: Google Analytics Conditions [https://marketingplatform.google.com/about/analytics/terms/de/ ]
You can find Google’s current privacy policy here: https://policies.google.com/privacy?hl=de
Using the Ninja API
If you are using a paid version of Ninja, you can use the Ninja API. Personal data may also be processed via this interface, depending on the specific use case.
Deletion of data and termination of use of Ninja
The Ninja owner may delete data from Ninja at any time, provided that the data is not related to a business-related transaction, or may terminate their use of Ninja altogether by deleting their Swiss21.org account. The Swiss21.org account and all data, including that stored in the relevant applications, will be deleted once a ‘soft deletion period’ of 30 days has elapsed and any existing backup periods have expired. Once this has been done, it will no longer be possible to recover the data. Only data which DeepCloud is obliged to retain in order to comply with statutory and contractual retention and documentation obligations will remain stored.
Otherwise, the remaining provisions of this privacy policy also apply when using Ninja.
Data processing when using plug-ins and other integrations with third-party services
DeepCloud’s digital services are linked to third-party functions and systems in a variety of ways, for example through the integration of third-party social media plug-ins or when you visit our presence on third-party websites (e.g. Facebook, etc.). If you have a customer account with these third parties, they may also be able to measure and analyse your use of our digital services. In doing so, further personal data, such as IP addresses, personal browser settings and other parameters, may be transmitted to these third parties and stored there. We have no control over the use of such personal data collected by third parties and accept no responsibility or liability in this regard.
Use of DeepCloud Support
Within the framework of existing contractual relationships, you have the option of contacting DeepCloud with support questions by email. The data processed is used to answer your support enquiry and is processed within the framework of contractual relationships.
MY Registration by email address is required to use the Customer Portal. The ticketing system may contain various types of information, including personal data (name of contact person, ticket handler, email address, content details). We use a third-party service provider for the ticketing system, which may receive the data for the purposes described above. The contracted service provider has been carefully selected and commissioned by us, is bound by our instructions and is subject to regular review.
The data processing carried out in the context of support services is based on our legitimate interests in providing our customers with the support they require and in ensuring the proper fulfilment of contractual obligations.
We will delete your data in this regard if storage is no longer necessary, the purpose of the processing has been fulfilled, you have withdrawn your consent or you have objected to the processing, unless there are storage or documentation obligations to the contrary or further processing is justified, about which we will inform you.
Data processing when using our websites
We use the services of commissioned service providers in Switzerland for the purpose of designing and operating our website. If data is also processed outside Switzerland as a result, it is contractually ensured that a level of data protection appropriate for Switzerland is established, either through existing guarantees or through corresponding regulations. We are happy to provide information about our commissioned service providers upon request. Through this data processing, contact data, content data, usage data, meta data, and communication data are processed by us or our service providers on our behalf when you use our website. This is done based on our legitimate interests in the efficient and secure provision of our website, to protect against misuse and other unauthorised use, on the basis of a service requested by you or a contract to be concluded with you following an order by you or, in certain cases, following your consent.
Automatic collection of access data and server log files
Access data and server log files are collected for each access to the server on which a service used by us is located (so-called server log files). These include:
- the domain visited and the files accessed
- the IP address of the terminal device used
- date and time and duration of the visit
- website from which the access was made
- Operating system of the end device used
- the browser used for access as well as all information from the ‘user-agent’, which the browser transmits to the server
- extent of the transmitted data volume
We use this information based on the following legitimate interests:
- to view our website
- to ensure the stability and security of our website
- for statistical evaluations of our websites
- to improve our web presence
- for clarification work of support cases
- for the analysis of technical problems
- for safety-relevant clarifications
- in suspected cases of unlawful use (e.g. to clarify acts of abuse or fraud)
This information is stored for a maximum of 90 days and then deleted, unless its retention beyond this period is necessary for evidential purposes, such as for use as evidence before authorities or courts for unlawful use of our website. We will then exempt them from deletion until the respective incident has been finally clarified and may keep them until a legally binding decision or judgement has been reached. This information is stored in such a way that, as a rule, it cannot be assigned to any specific person by us, except if you register for a special offer on the website. As a matter of principle, the above-mentioned data will not be passed on to third parties, unless it is necessary for the pursuit of our claims, for the fulfilment of the intended purposes, after your consent or there is a legal obligation to do so.
Cookies and other technical means
Here we would like to inform you which cookies or other technical means such as web beacons, pixels, other tracking technologies (hereinafter “cookies”) are used when using our website. Cookies are small text files that are stored on your terminal device. They do not cause any damage to your end device and do not contain viruses. The data obtained in this way may subsequently be evaluated by us or third parties and merged with other data. As a rule, they serve to make the entire internet offer secure, more user-friendly and more effective, which is in both your and our interest. For some cookies that are not essential for technical storage or access to our website, or that are not used only to enable the use of a service you have explicitly requested, we will ask for your consent by means of a so-called cookie consent banner.
What are the basic cookies?
Our websites may use cookies from us or third parties to fulfil certain purposes (such as displaying our website, improving functionality, statistical web analysis, product optimisation, personalisation of content). The cookies we use are either session cookies (they are automatically deleted after you close your browser) or so-called persistent cookies (these remain stored on your end device until a specified expiry date). The following cookies are generally possible:
Necessary including preferences
Necessary cookies are required for the secure operation of our website, to enable us to transmit and display our website content to you, to enable you to navigate the website or to enable us to quickly identify and rectify technical problems. Preference cookies allow you to use the website more comfortably by remembering options you have chosen (such as a language choice) or providing functionality you have requested (such as remembering a choice or performing a function). These cookies do not require your consent, but their use is based on justifiable interests.
Statistics
These cookies allow statistics and analyses to be created, whereby pseudonymized or anonymized data is collected to gain knowledge about website usage, to improve our service or to quickly identify and solve technical problems.
Marketing
Enable the display of personalized content by recording and analysing your usage behaviour. This is also performed outside of our websites, as these cookies can follow you. Cookies from third-party providers are also used and (pseudonymised) data about your surfing habits are given to them for evaluation and further use.
Which cookies do our websites use?
You can find out which specific cookies are used on our websites by means of informative banners on the respective websites. If only functional cookies are used, we can inform you accordingly by means of a cookie info banner or via this Privacy Policy. If cookies, possibly also from third parties, are used that require your consent, we will obtain your consent in advance by means of a Cookies Consent Banner before activating these cookies. For information on the data processing of possible third-party providers whose cookies you can consent to when using our websites, please refer to their data protection declarations. Please note that you can set the common browsers in such a way that you are informed about the setting of cookies and can decide individually about their acceptance or can exclude the acceptance of cookies for certain cases or generally. Each browser differs in the way it manages cookie settings. The help menu of each browser explains how you can change your cookie settings. We cannot guarantee that you will be able to access all functions of our websites without restriction if you do not allow cookies. We recommend that you regularly delete your cookies and browser history manually.
reCAPTCHA from Google
To protect our systems from bots and possible spam, we have integrated reCAPTCHA from Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 5, Ireland) on certain registration and login forms. This allows us to distinguish whether we are receiving a registration or login from a human or whether there is improper processing by an automated, machine program (e.g. a bot). For this purpose, certain entries are required before registration or login so that verification is possible. In addition, your IP address and, if applicable, other data such as the website that you visit with us and on which reCAPTCHA is integrated, the date and the time spent on our website, the identification data of the browser and operating system type, your Google account if you are logged into Google, mouse movements on the reCAPTCHA areas as well as the tasks in which you identify images are also required by Google for reCAPTCHA. They are sent to Google and processed by them. The analysis starts automatically as soon as you open the website with reCAPTCHA. We use reCAPTCHA from Google to ensure the security of our systems. Data and documents uploaded via a form are stored directly in our systems. If we did not install such a security tool, bots would be able to log on to our systems unhindered. This is how we protect ourselves from unwanted and dangerous automated calls. It is in our legitimate interest to protect our system security. If you would like to know more about reCAPTCHA or how Google processes data, you can find out more directly from Google on their website.
If you would like to know more about reCAPTCHA or how Google processes data, you can find out more directly from Google here:
Privacy policy: https://policies.google.com/privacy
Terms of Use https://policies.google.com/terms/update
Google LLC. as the parent company of Google is a US-American company, so there is the possibility that data might also be processed in the USA Both the EU and Switzerland issued positive adequacy decisions concerning the USA after entering the corresponding Swiss/EU-US Data Privacy Frameworks, so that a data transfer to the USA is lawful following certification of such companies. In addition, we will try wherever possible, to provide further safeguards such as entering standard data protection clauses or obtaining consent to commissioned data processing to ensure lawful data transmission.
Newsletter and promotional information
In the following, we will show you how we would like to inform you in terms of advertising.
Newsletter
With us you have the possibility to subscribe to a newsletter. In the following we explain the procedure involving newsletters.
- Content of the individual newsletter: We only send emails with promotional information (hereinafter “newsletter”) with your consent. Our newsletters contain information on our services and benefits, also those of the companies of the Abacus Group.
Automated processing: Web beacons are used in our newsletters. These are small, unrecognisable embedded images or objects (such as clear GIF, pixel tags and single pixel GIFs) that return information from you after you open the email you receive. In this way, we can measure success to compile statistics for the popularity of our offer. It also allows us to evaluate your user behaviour accordingly. We also store information about the browser you are using and the settings you have made in the operating system you are using, as well as information about the internet connection you are using to access our website. Through the newsletter sent to you, we receive, among other things, receipt and read confirmations as well as information about the links you have clicked on in our newsletter. Through this data processing (performance measurement), we aim to align our advertising approach to your interests and optimise our information on our website.
- Consent: The dispatch of the newsletter and the associated performance measurement is based on your consent when registering for the newsletter.
- Registration procedure and logging: To ensure that no one can register with other people’s email addresses, you will receive an email asking you to confirm your registration. This confirmation is necessary to receive the newsletter. If the registration is not confirmed within 4 days, the information will subsequently be deleted. Registrations for the newsletter are logged to be able to prove the registration process in accordance with the legal requirements and to clarify any possible misuse of your data. This includes the storage of the login and confirmation time as well as the IP address. Changes to your stored data are also logged.
- Login data: To subscribe to the newsletter, all you need to do is enter your email address. Optionally, you can enter a name for the purpose of a personal address in the newsletter.
- Recall: You can stop receiving a newsletter at any time, i.e. withdraw your consent, by sending an email to marketing@deepcloud.swiss and clicking on the unsubscribe link in the newsletter or through the contact details provided in the Imprint. You will not incur any costs other than the transmission costs according to the basic rates. You will find a corresponding link for revocation at the end of each newsletter.
- Storage after revocation: We may store unsubscribed email addresses for up to three years to prove consent was previously given. The processing of this data is limited to the purpose of a possible defence against claims. An individual deletion request is possible at any time, provided that the former existence of consent is confirmed at the same time. Your data will only be used for other purposes after you have withdrawn your consent if you have expressly consented to this or if further processing is justified, about which we will inform you.
Marketing measures by email to existing customers
If we have received your email address from you in connection with the provision of a DeepService and you have not objected to its subsequent use, we reserve the right to use your email address for direct advertising for our own similar DeepServices already purchased. After considering our interests, these marketing measures serve our legitimate interests in providing promotional information to our existing customers. The prerequisite is that we inform you when collecting the email address and each time it is used so that you can object to its use at any time (this does not incur any costs other than the transmission costs according to the basic rates).
Commissioned service providers for marketing measures
Marketing measures by email can be carried out by commissioned service providers. For this purpose, your data such as name and email address will be passed on. We use the service mailXpert GmbH, Schulstrasse 37, 8050 Zurich, among others, to send newsletters.
The data required for this is transferred to a server at mailXpert GmbH. Newsletters are sent with your consent or on the basis of our legitimate interests in addressing our existing customers in an advertising manner. Further information and the privacy policy of mailXpert GmbH can be found on their website.
We are happy to provide information about our other commissioned service providers upon request.
Telephone and postal advertising
We reserve the right to use your first and last name as well as your telephone number and postal address for our own advertising purposes to be able to send you interesting offers about us, our DeepServices or events organised by us by telephone or by post. Telephone advertising information is only carried out with your presumed consent. After considering our interests, the advertising approach by letter serves our justified interests in addressing our customers and potential interested parties. We will check and respect a possible advertising objection (e.g. through a star entry in public telephone directories) in advance. Promotional letter mail can be processed and sent by a commissioned service provider. For this purpose, we will pass on name and address data to them. We are happy to provide information about our commissioned service provider upon request.
Objection to advertising information and revocation of consent
You may withdraw your consent to receive marketing communications or object to the storage and use of your data for the purposes mentioned above (marketing activities) at any time by sending a message to marketing@deepcloud.swiss, by clicking on the unsubscribe link in the email (you will find a link to opt out at the end of any newsletter email) or by contacting us using the details provided in the legal notice. You will not incur any costs other than the transmission costs according to the basic rates. After that, your contact details (e.g. from the newsletter) will be deleted. Further processing of your data remains possible insofar as its use is further permitted or permitted by law.
Transfer of data for advertising information
Your contact details may be passed on to another company of the Abacus Group in Switzerland or Germany as well as to our solution partners. Promotional information will be carried out within the framework of legal requirements. If you have given your consent, if necessary, to a promotional information (e.g. by newsletter), and also to a transfer of personal data for this purpose to a company of the Abacus Group or one of our solution partners, this may be used for the corresponding promotional information by the authorised party.
Subscription to DeepServices status updates
With us, you can sign up to receive updates on DeepServices status notifications. Below, we explain the process involved in these status updates. We only send emails with updates with your consent. The emails contain information on the status of our DeepServices.
- Explicit consent: The sending of the email regarding updates is based on your explicit consent given when you signed up for the updates, as this may also involve the transfer of data to the USA to our third-party service providers.
- Registration procedure and logging: To ensure that no one else can register with other people’s email addresses, you will receive an email asking you to confirm your registration. This confirmation is necessary to receive the updates. If the registration is not confirmed within 2 days, the information will subsequently be deleted. Registrations are logged to be able to prove the registration process in accordance with the legal requirements and to clarify any possible misuse of your data. This includes storing the email address and the time of registration and confirmation. Changes to your stored data are also logged.
- Login data: To sign up for updates, we need your email address.
- Recall: You can stop receiving these update emails at any time – i.e. withdraw your consent – by clicking on the unsubscribe link in the email. You will not incur any costs other than the transmission costs according to the basic rates. You will find a corresponding link for revocation at the end of each update email.
- Storage after revocation: We may store unsubscribed email addresses for up to three years to prove consent was previously given. The processing of this data is limited to the purpose of a possible defence against claims. An individual deletion request is possible at any time, provided that the former existence of consent is confirmed at the same time. Your data will only be used for other purposes after you have withdrawn your consent if you have expressly consented to this or if further processing is justified, about which we will inform you.
Disclosure of data
We use the services of Instatus, Inc., 9450 SW Gemini Dr PMB 30900 Beaverton, Oregon 97008-7105 USA (“Instatus”) to send out update emails and to obtain email addresses. We also use the services of Mailgun, Technologies, Inc., 112 E Pecan Street, #1135, San Antonio, TX 78205, USA (‘Mailgun’) to send emails containing such updates. These services are used to provide information to our customers and interested parties regarding the provision of our DeepServices, which is in our legitimate interest. If you sign up for such updates, this is done with your express consent, as data may also be transferred to the USA. The service providers we engage, to whom your data will be disclosed for the purposes described above, are US-based companies; it is therefore possible that data may also be processed in the USA. Both the EU and Switzerland issued positive adequacy decisions concerning the USA after entering the corresponding Swiss/EU-US Data Privacy Frameworks, so that a data transfer to the USA is lawful following certification of such companies. Mailgun holds such certification under the Data Privacy Framework. Unless such certification is available, we provide suitable safeguards, such as entering into standard data protection clauses (with adjustment of the necessary contractual and technical measures), to ensure lawful data transmission to foreign countries. This is the case with Instatus. Furthermore, we resort to legally permissible exceptions, such as allowing data transmission to a Third Country that lacks an adequate level of data protection based on express consent by the data subject.
Our company’s presence on social media channelsOur company’s presence on social media channels
We maintain a corporate presence on LinkedIn, YouTube, Instagram and Facebook. Our websites contain links to our company presence on these platforms. There we can see all the information that visitors voluntarily provide to our corporate presence on this platform by either liking one of our posts or posting a comment. Your data will also be processed if you communicate with us within this platform, e.g. write articles on the various online presences or send messages. In addition, we are provided with statistical data of the visitors to our company website in our administrator account. This includes data evaluating visitors’ interactions with our respective posts, a follower demographic and its origin, as well as web traffic and activity on our corporate presence on the platform. We are not able to view any personal data of the visitors, but only general data without any personal reference. Further data processing carried out by the respective platform operator during your visit to the platform is not subject to this Privacy Policy, but to its own Privacy Policy. Nevertheless, we check our company presence on this platform at regular intervals for possible violations of the law to be able to take immediate action. We have no influence on the data collected and data processing operations by the platform operator. They store the data collected about you as a usage profile and uses this for the purposes of advertising, market research, and/or designing the website to meet your needs. Such an evaluation is carried out in particular (also for users who are not logged in) for the display of needs-based advertising and to inform other users of the network about your activities on our website. You have a right to object to the creation of these user profiles, whereby you must contact the respective platform operator directly to exercise this right. Data processing by a platform operator following the use of a link on our website takes place regardless of whether you have a user account there and are logged in. If you are logged in, your data will be directly assigned to your user account. We recommend that you log out regularly after using such a platform, as this allows you to avoid being assigned to your profile. For further information on the purpose and scope of data collection and processing, please refer to the respective Privacy Policy of the platform operator. There you will also find further information on your rights and setting options to protect your privacy.
LinkedIn: LinkedIn Corporation, 2029 Stierlin Court, Mountain View, California 94043, USA http://www.linkedin.com/legal/privacy-policy
Opt-Out: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out
LinkedIn is a US-American company, so there is the possibility that data might also be processed in the U.S. Both the EU and Switzerland issued positive adequacy decisions concerning the USA after entering the corresponding Swiss/EU-US Data Privacy Frameworks, so that a data transfer to the USA is lawful following certification of such companies. In addition, we will try wherever possible, to provide further safeguards such as entering standard data protection clauses or obtaining consent to commissioned data processing to ensure lawful data transmission.
YouTube, operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, ‘Google’: https://www.google.de/intl/de/policies/privacy
Google LLC. as the parent company of Google is a US-American company, so there is the possibility that data might also be processed in the U.S. Both the EU and Switzerland issued positive adequacy decisions concerning the USA after entering the corresponding Swiss/EU-US Data Privacy Frameworks, so that a data transfer to the USA is lawful following certification of such companies. In addition, we will try wherever possible, to provide further safeguards such as entering standard data protection clauses or obtaining consent to commissioned data processing to ensure lawful data transmission.
Facebook and Instagram from Meta Platforms (“Meta” formerly Facebook):
Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
https://www.facebook.com/privacy/policy
Google LLC. as the parent company of Google is a US-American company, so there is the possibility that data might also be processed in the U.S. Both the EU and Switzerland issued positive adequacy decisions concerning the USA after entering the corresponding Swiss/EU-US Data Privacy Frameworks, so that a data transfer to the USA is lawful following certification of such companies. In addition, we will try wherever possible, to provide further safeguards such as entering standard data protection clauses or obtaining consent to commissioned data processing to ensure lawful data transmission.
YouTube videos
We use the YouTube video player provided by Google Ltd. (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, hereinafter ‘Google’) to present YouTube videos, which are also stored on YouTube and can be played directly from our website. This is done for the optimal presentation of our DeepServices, which is in our legitimate interest.
To protect your data, these YouTube videos are integrated in “extended data protection mode” (YouTube nocookies). YouTube informs you that no information about visitors to this website is stored until they watch the video. However, this does not necessarily exclude the transfer of data to YouTube partners, such as those of the Google Double-Click network.
By visiting our website on which a YouTube video is embedded, Google at least receives the information that you have accessed the corresponding subpage of our website with the embedded video. In addition, information and data such as server log files, IP address and user agent are transmitted at the latest when the video is accessed. This takes place regardless of whether you have a YouTube user account through which you are logged in or whether no user account exists. If you are logged in, this data will be directly assigned to your user account.
When the video is accessed, YouTube uses various cookies and other tracking technologies. Google then stores your data as usage profiles and uses them for the purposes of advertising, market research and/or customised website design. Such an evaluation is carried out in particular (even for users who are not logged in) for the provision of customised advertising and to inform other users of the network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact Google directly to exercise this right.
For further information on the purpose and scope of data collection and processing, please refer to Google’s Privacy Policy. There you will also receive further information about your rights and setting options to protect your privacy: https://www.google.de/intl/de/policies/privacy
As the parent company of Google, Google LLC. is a US-American company, so there is a possibility that data could also be processed in the USA. Both the EU and Switzerland issued positive adequacy decisions concerning the USA after entering the corresponding Swiss/EU-US Data Privacy Frameworks, so that a data transfer to the USA is lawful following certification of such companies. In addition, we will try wherever possible, to provide further safeguards such as entering standard data protection clauses or obtaining consent to commissioned data processing to ensure lawful data transmission.
Vimeo Videos
We use the services of Vimeo, Inc. 555 West 18th Street, 10011 New York, USA (“Vimeo”) to host online events. In addition, we have integrated the Vimeo video player on some of our web pages in order to offer videos for the presentation of content. These are stored on Vimeo so that they can be played on our websites. This is done for the optimal provision of our DeepServices, which is in our legitimate interest. A connection to the Vimeo servers is established when you view one of these videos. In doing so, Vimeo receives the information that you have accessed the corresponding subpage of our website containing the embedded video and the IP address. Vimeo is set up so that your user activities are not tracked, and no cookies are set. For more information on the purpose and scope of data collection, its processing and your rights and settings options to protect your privacy, please refer to the Vimeo Privacy Policy.
Vimeo, Inc. is a US-American company, so there is the possibility that data might also be processed in the U.S. Both the EU and Switzerland issued positive adequacy decisions concerning the USA after entering the corresponding Swiss/EU-US Data Privacy Frameworks, so that a data transfer to the USA is lawful following certification of such companies. In addition, wherever possible, we will try to put in place further appropriate safeguards, such as standard data protection clauses, or to obtain consent for specific data processing operations, in order to ensure that data transfers comply with the law.
Links
Our websites may contain links to external websites of other companies outside DeepCloud. This Privacy Policy does not extend to the websites of these other companies. When using these websites, the data protection declarations of these companies must be observed as far as their data processing is concerned. Nevertheless, we check these websites at regular intervals to remove the link immediately in the event of possible infringements. If you have any indications of possible legal violations on the pages linked by us, we ask you to inform us so that we can stop a possible connection. If you click on such links, your data may be transferred to companies in countries outside Switzerland, the EU or the EEA that possibly do not ensure an adequate level of protection for the processing of personal data. Please remember this before clicking on a link and thereby triggering a possible transfer of data.
Data processing within the scope of our business operations, its purposes and its legal basis
In the following, we would like to inform you about the data processing that we carry out as a company within the scope of our business operations.
What data is processed and where does it come from?
We process data from our employees, customers, suppliers, applicants, interested parties, other business partners, or third parties and their employees. This data is either provided by the data subject or the respective company itself or we receive it from another company of the Abacus Group, from third parties such as other business partners (e.g. customers, suppliers or other service providers), public authorities or from publicly accessible sources (e.g. public telephone, address and trade directories, public notices or databases, the Internet, trade, cooperative or association registers). The data provided by you or the relevant company, for example when making an enquiry, registering, obtaining a quote, entering into a contract, completing a questionnaire or otherwise communicating with us, may be as follows:
- Contact data
- Master data contained in official documents in which you are mentioned (such as an extract from the commercial register), including your full name, position, company name, address, telephone number and email address
- Contractual data arising from pre-contractual measures or the fulfilment of a contract, including delivery data
- Payment data, including bank details, payment history, credit card data, debit card data, access data, as well as other data for smooth payment transactions
- Content data including entries in our CRM or project system, in contact forms, data of a communication made via email or another form of communication
- Registration data (such as username and password) when using offers requiring registration or login
- Data for the prevention of fraud, money laundering or other criminal offences
- All data in connection with an application or employment as an employee about the profession, the previous employer, the professional career including certificates and further training, all data that are provided or may be legitimately collected and processed in the context of an application procedure or employment relationship
- Sensitive data such as health data, which is only collected by us with the explicit, prior consent of the data subject, which can be revoked at any time, or where there is a legal obligation to process it
- Data on the company for which a person works
- Data as described above when using one of our websites
Data obtained through other companies, public authorities or publicly available sources, such as:
- Credit information
- Contact data (name, company, postal addresses, email addresses, telephone numbers, publicly accessible data as can be seen in the commercial register) from credit agencies that are used within the legal framework for an advertising information.
- Data from banks or insurance companies in connection with the fulfilment of a legal or contractual obligation
- Data from judicial or official proceedings
- References from previous employers or business partners
- Data related to fraud and money laundering prevention or screening related to export restrictions
- Data from publicly accessible sources such as the internet, the press or public registers such as the commercial register
For what purposes is data processed and on what legal basis?
Data is processed for different purposes and based on different legal bases:
- Carrying out pre-contractual measures in the context of an application or in connection with the conclusion of contracts with customers or other business partners, such as when preparing an offer. Due to their function at the contractual partner, data of their employees is also processed, in which we have the legitimate interest of a successful business development
- Processing of employee data based on contract, legal obligation, given consent or legitimate interests
- Provision of contractual services and customer care in the fulfilment of contracts, implementation of contractual measures, payments and accounting, guarantee of contractual claims. Due to their function at the contractual partner, data of their employees is also processed, in which we have the legitimate interest of a successful business development
- Processing of contact requests based on the legitimate interest of customer satisfaction or pre-contractual measures
- Communication with the media based on a legitimate interest in successful business development
- Sending personalised newsletters, carrying out other marketing measures, sending Christmas mail/gifts as well as internal market and opinion research to provide customers in an advertising manner about our companies and services in order to increase sales after consent has been granted or in special cases due to justified interests in direct marketing within the framework of existing legal requirements
- Exchange information and maintain contact with the press on the basis of legitimate interests of successful business development
- Improvement of our online offers, products, and services due to legitimate interests of a successful business development
- Collection of data from publicly accessible sources on the basis of legitimate interests for customer acquisition
- To establish, maintain and protect the operation and security of our IT, online offering, products, services and other offerings, based on legitimate interests to prevent potential security threats, criminal offences, or other adverse activities
- Video surveillance to safeguard domiciliary rights and damage prevention and other IT security measures to protect persons, intangible assets and tangible assets
- Compliance with internal policies or industry standards due to legitimate interests to comply with specified regulations
- Enforcing contracts, settling, asserting or defending legal claims in judicial or official proceedings based on our legitimate business interests
- Mergers, transfers, and acquisitions of companies, parts thereof or business divisions, as well as other transactions under company law, including the transfer of data based on legitimate interests of successful business development or after consent has been granted
- Provision of certain online services for the management of customers and business partners and communication in the context of the use of online services requiring registration (including orders, payments, document management, other information) based on legitimate business interests
- Examination of companies for possible cooperation based on our legitimate business interests
- Enabling participation in interactive functions of our online offer due to legitimate interests upon request
- Determination of winners of sweepstakes/competitions and, if applicable, publication of winners based on consent
- Obtaining references as part of an application procedure after consent has been given
- Verification of identity to be able to fulfil rights and obligations under data protection law, due to legal obligation
- Credit assessments based on (pre-) contractual relationships or after consent has been given
- Other data processing after consent has been given
- Fulfilment of legal obligations and due diligence for the prevention or investigation of criminal offences, economic crime or money laundering
- To fulfil the purposes which you specified when you provided the data or that we notified you of when we collected the data
- Legal protection, enforcement of our claims/defence against claims; due to legitimate interests in the protection of our rights, as well as the rights of persons associated with us (such as employees) or group companies
In addition, data from different sources are brought together, which can also be processed for the purposes listed above. This allows us to compare, match and use customer or sales partner data from the individual companies within the Abacus Group and manage it in a central system. For current and correct delivery and address data, we may match existing data with other sources, correct it if necessary and use it; this is due to legitimate business interests.
Data transmission to foreign countries
As a company, we use various tools provided by US-based companies (such as Microsoft products and Zoom telephony), whilst ensuring, as far as possible, that we enter into contractual agreements with these companies to stipulate that data is stored in Switzerland or the EU. Nevertheless, data may be sent to their servers in the USA during use or in cases of support. Both the EU and Switzerland issued positive adequacy decisions concerning the USA after entering the corresponding Swiss/EU-US Data Privacy Frameworks, so that a data transfer to the USA is lawful following certification of such companies. In addition, we will try wherever possible, to provide further safeguards such as entering standard data protection clauses or obtaining consent to commissioned data processing to ensure lawful data transmission.
For data processed in a Third Country that lacks an adequate level of data protection, we provide suitable safeguards, such as entering into standard data protection clauses (with adjustment of the necessary contractual and technical measures), to ensure lawful data transmission to foreign countries. We resort to legally permissible exceptions only in isolated cases, such as allowing data transmission to a Third Country that lacks an adequate level of data protection based on express consent by the data subject.
Time limits for the deletion or blocking of data
In principle, we process and store your data for as long as is necessary and permissible for the purposes for which we received the data. Specifically, this means that we will retain your data for as long as we have a (business) relationship with you or the company for which you work, when you use our website, when you are employed, when you send us newsletters, when we perform a contract or a continuing obligation, for as long as you have given us permission to store the data, for as long as any obligations exist or are owed to us, for as long as a particular legal situation requires, such as with regard to legal disputes, limitation periods or official investigations, or for as long as you were notified when the data was collected. In addition, legislation has provided for a variety of documentation and retention obligations and periods, so that if such a legal obligation for retention or documentation exists, we also store data – possibly limited – for a correspondingly long period of time. In Switzerland, for example, there are retention obligations under tax or commercial law of up to 10 years, as well as possible retention obligations of 30 years due to existing statutes of limitation, plus obligations under special laws. For this reason, an examination of the respective storage period takes place in each individual case for the corresponding data processing. After exercising your right of revocation or objection, after the stated purposes have been achieved or after the expiry of existing tax or commercial law, other legal or contractual documentation and storage obligations and periods, we will delete your data or, if permissible, restrict its processing, unless you have consented to further use of your data or we have expressly reserved the right to use data beyond this, as permitted by law or contract, about which we will inform you accordingly.
Data security
If you use areas that require registration or login, you should store the login data carefully and protect it from access by third parties. If you log in from computers or other devices that are used by multiple people, please remember to properly log out after each session and close the browser window you are using. We take data security very seriously and treat your data confidentially and in accordance with the statutory provisions. To this end, we have taken technical and organisational measures to ensure a level of protection appropriate to the risk. These measures may include the pseudonymisation and encryption of data, security measures relating to the confidentiality, integrity, availability and resilience of systems, the ability to rapidly restore the availability of and access to data in the event of a physical or technical incident, and the regular review, assessment and evaluation of the effectiveness of technical and organisational measures to ensure the security of processing. That way, we provide your data with state-of-the-art protection against loss, misuse, change, destruction and unauthorized access. Our standard of security is constantly upgraded to the latest technological developments. Our employees and commissioned service providers are bound to confidentiality and act within the framework of our instructions. It is possible that emails are sent in unencrypted form (i.e. that they are immediately readable without any required prior decryption), especially if you cannot access encrypted emails yourself. Such unencrypted emails are exposed to a greater risk than encrypted emails, which is why we hereby expressly advise you not to send any confidential information such as application documents without encryption. When using website forms or in the context of email communication with us, your data will be transmitted encrypted according to the current state of the art when it is sent. Our website including the areas requiring registration and login are secured (https). Bear in mind that online security gaps can never be ruled out completely. We cannot guarantee 100% security of all systems, especially when using our websites. We assume no liability for wrongful actions by authorized third parties.
Decisions based solely on automated processing, including profiling
In the application procedure, data is used in the context of partially automated processing according to certain criteria in order to evaluate personal aspects of an applicant (profiling). We use these assessments to make a prediction of suitability for employment. However, the decision on employment is made by the respective line managers and employees in the HR department. As a matter of principle, when concluding a contract or executing it, no decisions are made exclusively on the basis of automated processing which would produce legal effects against you or which would significantly affect you in a similar way. We will inform you in advance if this should take place in individual cases and ensure that data processing is lawful.
Applicable law
It is possible that different law applies to certain data processing. Thus, it must be examined in each individual case whether the Federal Data Protection Act (FDAP), the Ordinance to the Federal Data Protection Act (FDAP) as well as national law of Switzerland or another, foreign law such as the General Data Protection Regulation and in each case national law of another state is applicable to data subjects. DeepCloud will review this on a case-by-case basis and will carry out the data processing that takes place within the framework of the respective legal requirements.
Your rights
You are entitled to the following rights about your data, insofar as we have been able to duly establish your identity and the respective conditions for this are met:
- Right to information
- Right of rectification
- Right to erasure
- Right to restrict processing
- Right to object to processing
- Right to data portability or transfer
Furthermore, you have the right to assert your claims in court and to complain to a data protection supervisory authority about the processing of your data by us.
Here you can find a list of authorities in the EEA: https://edpb.europa.eu/about-edpb/board/members_de
We will comply with your request for deletion unless it conflicts with an obligation to retain data or we need the data to assert, exercise or defend our legal claims. You can revoke your consent to the processing of your data at any time for the future. Such a revocation shall not affect the lawfulness of the processing carried out based on the consent until the revocation. If we base the processing of your data on our legitimate interests or those of a third party following a balancing of interests, you may object to such processing. In such a case, we will review your objection and either stop or adapt the data processing or show you our compelling interests worthy of protection why we want to continue the processing. These must override your interests, rights and freedoms or the processing must serve the assertion, exercise or defence of legal claims. Should we process your data to conduct direct advertising with it, you have the right to object to this processing of your data for the purpose of direct advertising at any time. This also applies to any profiling that may take place if it relates to such direct advertising. In such a case, we will stop this data processing. You are not obliged to provide us with your data. However, it is possible that certain functions of our website will not be available or will only be available to a limited extent if you do not provide any data. Furthermore, it is possible that no contractual relationship can be entered into with you without the corresponding data. If you have any questions about data protection or if you wish to exercise your rights, withdraw consent or object to data processing, please contact us using the contact details provided above under “Responsible party”. We have appointed a Data Protection Officer. They are available at:datenschutz@deepcloud.swiss
If you have any questions about data protection, you may contact us at any time.
Amendment to this Privacy Policy, as of August 2026
This Privacy Policy is subject to periodic review and may be amended, if necessary, in the event of legal or technical changes or due to new or revised services, at any time with effect for the future without prior notice. For this reason, we ask you to read this Privacy Policy at regular intervals to be aware of possible changes.