How DSWaldron GmbH collects, uses, and protects personal data — under the Swiss Federal Act on Data Protection (FADP / revised nDSG) and the EU General Data Protection Regulation (GDPR).
DSWaldron GmbH, a Swiss limited liability company (UID CHE-218.721.502), based at Maistrasse 10, 5430 Wettingen, Switzerland, is the controller responsible for the personal data described in this policy. Full contact details are in our Impressum.
This policy covers two things:
If you use the contact form, it opens your email client with the details you entered and sends them to us. We receive: name, company, email, and message content. Nothing is stored on the marketing site itself.
Our hosting provider records standard technical logs (IP address, user-agent, timestamp, requested URL) for a short retention period, used only to keep the site secure and operational.
When our customers use SiteActa, they upload project documentation such as: contracts, photographs and site images, emails and .msg files, PDF documents, notes, and any voice notes their team records. These may contain personal data of employees, subcontractors, consultants, or third parties.
DSWaldron GmbH processes this data only on the customer's documented instructions, for the purpose of operating the SiteActa service, under a Data Processing Agreement. Customers are responsible for the lawful basis of uploading personal data and for informing the individuals concerned where required.
Account-level personal data (name, email, role, workspace membership) is processed by DSWaldron GmbH as controller for the purposes of authentication, access control, billing, and support.
The SiteActa platform runs on Google Cloud in the europe-west4 region (Eemshaven, Netherlands), with AI processing pinned to the same region. Application hosting and edge delivery are configured to keep traffic within Europe. Customer data is processed inside the EU / Switzerland data-residency envelope; incidental transfers to Switzerland are covered by the FDPIC's adequacy status for Switzerland–EU flows.
We use the following categories of subprocessor to operate SiteActa. Each is bound by a written data-processing agreement and is required to apply appropriate technical and organisational measures.
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud (Vertex AI, Cloud infrastructure) | AI inference, embeddings, storage of processed artefacts | europe-west4 (NL) |
| Supabase | Database, authentication, object storage | eu-central-1 (Frankfurt, DE) |
| Cloudflare Workers | Application hosting and edge delivery | Global edge (EU points of presence) |
| Resend | Outbound transactional email (invitations, notifications, password resets) | EU (Ireland) |
| SendGrid Inbound Parse (Twilio) | Inbound email ingest at project addresses | EU / US (Twilio global) |
An up-to-date list is available on request. Customers subscribed under a DPA are notified of material changes before new subprocessors are engaged.
Under FADP and GDPR you have the right to:
If your data is held by DSWaldron GmbH as processor on behalf of a SiteActa customer (for example, you appear in a project record uploaded by a contractor using SiteActa), please contact that customer first; we will support them in responding.
To exercise your rights, contact darrenw@dswaldron.ch. We respond within the timeframes required by applicable law.
You have the right to lodge a complaint with a data-protection authority.
SiteActa is designed around evidence integrity: uploaded records are content-hashed and sealed. We use TLS in transit, encryption at rest, role-based access control, and audited administrative access. No system is perfectly secure, but we apply industry-standard technical and organisational measures appropriate to the risk.
We do not routinely transfer personal data outside Switzerland and the EEA. Where a subprocessor operates outside this envelope, transfers are covered by EU Standard Contractual Clauses, the Swiss FDPIC-approved addendum, or an equivalent legal mechanism.
SiteActa uses AI to organise, summarise, and search customer-uploaded documents. These features are advisory: they surface information for humans to review. We do not use them to make decisions with legal or similarly significant effect about individuals in the sense of Art. 22 GDPR.
We may update this policy to reflect changes in our practices or legal requirements. Material changes are highlighted at the top of this page. The "Last updated" date always reflects the current version.