Privacy

Privacy Policy

How DSWaldron GmbH collects, uses, and protects personal data — under the Swiss Federal Act on Data Protection (FADP / revised nDSG) and the EU General Data Protection Regulation (GDPR).

Last updated: 24 July 2026

1. Who we are (Controller)

DSWaldron GmbH, a Swiss limited liability company (UID CHE-218.721.502), based at Maistrasse 10, 5430 Wettingen, Switzerland, is the controller responsible for the personal data described in this policy. Full contact details are in our Impressum.

Privacy contactdarrenw@dswaldron.ch

2. Scope

This policy covers two things:

3. What we collect on the marketing site

Contact form

If you use the contact form, it opens your email client with the details you entered and sends them to us. We receive: name, company, email, and message content. Nothing is stored on the marketing site itself.

Server logs

Our hosting provider records standard technical logs (IP address, user-agent, timestamp, requested URL) for a short retention period, used only to keep the site secure and operational.

No tracking cookies

The marketing site does not set third-party analytics or advertising cookies. There is no Google Analytics, no Meta pixel, no LinkedIn Insight tag, no session recording. Fonts are loaded from Google Fonts to render the page; no cookies are set for tracking purposes. Because we do not track visitors, we do not display a cookie banner.

4. What is processed in the SiteActa platform

When our customers use SiteActa, they upload project documentation such as: contracts, photographs and site images, emails and .msg files, PDF documents, notes, and any voice notes their team records. These may contain personal data of employees, subcontractors, consultants, or third parties.

DSWaldron GmbH processes this data only on the customer's documented instructions, for the purpose of operating the SiteActa service, under a Data Processing Agreement. Customers are responsible for the lawful basis of uploading personal data and for informing the individuals concerned where required.

Account-level personal data (name, email, role, workspace membership) is processed by DSWaldron GmbH as controller for the purposes of authentication, access control, billing, and support.

5. Purposes and legal bases

6. Hosting and processing location

The SiteActa platform runs on Google Cloud in the europe-west4 region (Eemshaven, Netherlands), with AI processing pinned to the same region. Application hosting and edge delivery are configured to keep traffic within Europe. Customer data is processed inside the EU / Switzerland data-residency envelope; incidental transfers to Switzerland are covered by the FDPIC's adequacy status for Switzerland–EU flows.

7. Subprocessors

We use the following categories of subprocessor to operate SiteActa. Each is bound by a written data-processing agreement and is required to apply appropriate technical and organisational measures.

SubprocessorPurposeLocation
Google Cloud (Vertex AI, Cloud infrastructure)AI inference, embeddings, storage of processed artefactseurope-west4 (NL)
SupabaseDatabase, authentication, object storageeu-central-1 (Frankfurt, DE)
Cloudflare WorkersApplication hosting and edge deliveryGlobal edge (EU points of presence)
ResendOutbound transactional email (invitations, notifications, password resets)EU (Ireland)
SendGrid Inbound Parse (Twilio)Inbound email ingest at project addressesEU / US (Twilio global)

An up-to-date list is available on request. Customers subscribed under a DPA are notified of material changes before new subprocessors are engaged.

8. Retention

9. Your rights

Under FADP and GDPR you have the right to:

If your data is held by DSWaldron GmbH as processor on behalf of a SiteActa customer (for example, you appear in a project record uploaded by a contractor using SiteActa), please contact that customer first; we will support them in responding.

To exercise your rights, contact darrenw@dswaldron.ch. We respond within the timeframes required by applicable law.

10. Complaints

You have the right to lodge a complaint with a data-protection authority.

11. Security

SiteActa is designed around evidence integrity: uploaded records are content-hashed and sealed. We use TLS in transit, encryption at rest, role-based access control, and audited administrative access. No system is perfectly secure, but we apply industry-standard technical and organisational measures appropriate to the risk.

12. International transfers

We do not routinely transfer personal data outside Switzerland and the EEA. Where a subprocessor operates outside this envelope, transfers are covered by EU Standard Contractual Clauses, the Swiss FDPIC-approved addendum, or an equivalent legal mechanism.

13. Automated decision-making

SiteActa uses AI to organise, summarise, and search customer-uploaded documents. These features are advisory: they surface information for humans to review. We do not use them to make decisions with legal or similarly significant effect about individuals in the sense of Art. 22 GDPR.

14. Changes to this policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes are highlighted at the top of this page. The "Last updated" date always reflects the current version.