Privacy policy of Auftrion
Status: 31 July 2026 · Swiss Data Protection Act
1. Responsibilities
The Auftrion provider is responsible for data relating to its own SaaS contract, the website, security, billing and communication. For personal data that a tenant records in Auftrion about employees, customers, contacts and sites, the respective tenant is generally responsible; Auftrion processes this data according to the tenant’s documented instructions under the data processing agreement.
2. Category from Pax dates
- Companies-, Contact-, Treaty- and Payment dates
- User-, roles-, Login-, Security- and Minutes dates
- Customers-, property-, assignment-, quotes-, Invoice- and Communication dates
- Working time-, leave-, Illness-, expenses-, payroll- and Employee documents
- Photos, Pdfs, checklists, Inspection- and Quality dates
- Devices-, warehouse-, Handover-, Servicing- and Returns dates
- optional Site dots, Precision, Timestamp and technical Tracking status
3. Purposes
The data is processed to provide, secure, maintain and improve the platform, to carry out the business processes configured by the tenant, for billing, communication, error analysis, prevention of misuse and compliance with legal obligations. Employee data is not sold for third-party advertising.
4. Location services for employees
Location services are disabled by default. A tenant can choose “voluntary” or “required to start work”. Before the first transmission, the purpose, mode, interval, retention period and contact point are displayed and acknowledgement is documented. In voluntary mode, consent can be withdrawn in the portal. In required mode, the employer must ensure the employment-law and data-protection basis, necessity and a reasonable alternative for justified objections or technical failures.
Data is transmitted only when the employee app/PWA is open, device permission has been granted and a work phase is active, or when a start check is triggered directly. The app clearly shows the active status. At the end of work, the live status is removed; location history is deleted after the short period selected by the tenant, up to a maximum of 30 days. No hidden tracking takes place when the web app is fully closed.
5. Especially protecting values data
Health-, payroll-, Treaty- and Discipline arda tens will only for The respective Personnel process processed. Hits are On expressly authorized roles to restrict. Medical certificates should none Diagnose Included, soweit this for The Employers not required is.
6. Recipient and Unter contractors
Depending on the enabled feature, hosting, email, push, SMS, mapping, geocoding, payment, PDF or AI service providers may receive data. Only the data required for the service is transmitted. Current subprocessors, locations, safeguards and change procedures are documented in the data processing agreement or its annexes.
7. Announcement into the Overseas
Will data in States without appropriately Data levels announced, will appropriate Warranty how recognised Default treaty clauses or Other legally intended Shelter mechanisms utilized. the Tenant considered this at his own Information the Concerned.
8. technical and organizational Measures
Measures include HTTPS, role-based access, logical tenant separation, CSRF protection, password hashing, optional or mandatory 2FA for highly privileged accounts, protected file storage, audit logs, short GPS retention, backup and recovery processes, and security updates. Absolute security cannot be technically guaranteed.
9. Safekeeping and Erasure
Data is retained for as long as necessary for the contract, operation, evidence, security, legal obligations or legitimate claims. Location history follows the tenant’s short retention period. Accounting and payroll documents may be subject to longer statutory retention periods. After the contract ends, the data processing agreement, export period and deletion policy apply.
10. Cookies, PWA and Device permissions
Es will technical requisite Session- and Security storage used. location, Camera, Notifications and App-Installation will only after visible Users action relationships wisely Browsers interrogation enabled. the Operating Can Permissions everytime ent pull.
11. permissions afflicted Pax
Affected Pax can in the statutory Frames Information, Rectification, Erasure, Herausgabe or Restriction desire. at Tenants dates wend You sich fundamentally First an The liability Employers relationships wisely Tenants. Auftrion aided The Tenants according AVV.
12. Security incidents and Contact
Suspected security incidents must be reported immediately to support@auftrion.ch. The provider investigates incidents, limits their impact and assists the responsible tenant with legally required notifications and information.
13. Changes
This Explanation Will at essence Function-, provider- or Legal changes adjusted. the Publication date and The Version remain comprehensible.
Confirmation and evidence logs
When GTC, DPA or employee information is accepted, the user and tenant assignment, document version and content hash, time, IP address, browser details, login method, session hash and request ID are logged. The purpose is traceable evidence of contracts and information as well as the detection of misuse. Access is restricted to authorised platform administrators. The raw IP address is not used for advertising or profiling and is deleted or anonymised after the period required for evidence, security and legal claims has expired.
Supplier url, actual Unter contractors, Hosting locations and Contact particulars must before the Live gait complete supplemented will.