Privacy notice for service companies
How we handle the data that arises when a service company uses ASSETLY. For end customers who scanned a label, the separate notice applies.
As of September 2026
01Who is responsible
For your own account data – name, e-mail address, role, sign-in records and billing details – we are the controller under the revised Swiss Data Protection Act.
For your end customers' data you are the controller. We process it solely on your instructions.
02What data we process
Account data: name, e-mail address, password hash, role, organization membership.
Usage data: sign-in times, changes recorded in the audit log, technical logs with personal data masked.
Content you enter: customers, sites, machines, requests, documents and photos.
03Purpose and legal basis
We process your data to provide the service, to invoice, to prevent abuse and to meet legal obligations. The basis is the contract between us.
No analysis is ever run across tenants. Your data is not sold and is not used for third-party advertising.
04Processing on your behalf
For your end customers' data we act as processor. The data processing agreement covers instructions, confidentiality, technical and organisational measures, notification of data security breaches, and deletion and return.
It forms part of the main contract and is put to you for signature before the first production use.
05Subprocessors
We use providers for hosting, database, file storage, e-mail delivery, bot protection, error logging and product analytics. Each is listed individually with its purpose and location on the subprocessor page. Changes are announced in advance.
06Where the data sits
Depending on the deployment variant, data is stored in the European Union or in Switzerland. Which variant applies to your installation is stated in the contract and on the subprocessor list. We do not claim Swiss data residency where there is none.
07Retention and deletion
Attachments on requests are deleted after 24 months, closed requests after five years, scan records after 24 months and kept only as a monthly total thereafter, audit records after 24 months.
After the contract ends, your tenant is deleted in full following a thirty-day grace period. The deletion is carried out by an automated process rather than by intention in the individual case.
08Cookies and audience measurement
In the portal we set a strictly necessary session cookie and a cookie for the chosen language. Both are required for operation.
On the public equipment pages your customers see, we set no analytics cookies and measure no behaviour across pages.
09Your rights
You have the right to access, rectification, deletion and data portability. Write to the address given in the imprint. You may also lodge a complaint with the Federal Data Protection and Information Commissioner.
10Security and changes
Access to data is enforced per tenant in the database, transfers are encrypted, files are scanned before they are delivered, and write operations are logged.
This notice may be amended. We tell you about material changes in advance.
This text is the version maintained by the operator. It is not legal advice; for any concrete case the signed contract governs.