Privacy

Privacy Policy

How DSWaldron GmbH collects, uses, and protects personal data, under the Swiss Federal Act on Data Protection (FADP / revised nDSG) and the EU General Data Protection Regulation (GDPR).

Last updated: 11 August 2026

1. Who we are (Controller)

DSWaldron GmbH, a Swiss limited liability company (UID CHE-218.721.502), based at Maistrasse 10, 5430 Wettingen, Switzerland, is the controller responsible for the personal data described in this policy. Full contact details are in our Impressum.

Privacy contactdarrenw@dswaldron.ch

2. Scope

This policy covers two things:

  • The marketing site at siteacta.ch and related domains, where DSWaldron GmbH is the controller.
  • The SiteActa platform (the signed-in application), where DSWaldron GmbH acts as a processor for our customers, on their documented instructions and under a data processing agreement (DPA) where one has been entered into. A standard DPA is not yet published as a document; we will enter into one on request. Customers remain controllers of the project data they upload.

3. What we collect on the marketing site

Contact form

If you use the contact form, your details are sent to us by email from our server. We receive: name, company, email, optional phone number, and message content. Nothing is stored in a database on the marketing site itself.

Server logs

Our hosting provider records standard technical logs (IP address, user-agent, timestamp, requested URL) for a short retention period, used only to keep the site secure and operational.

No tracking cookies

The marketing site does not set third-party analytics or advertising cookies. There is no Google Analytics, no Meta pixel, no LinkedIn Insight tag, no session recording. Fonts are loaded from Google Fonts to render the page; no cookies are set for tracking purposes. Because we do not track visitors, we do not display a cookie banner.

4. What is processed in the SiteActa platform

When our customers use SiteActa, they upload project documentation such as: contracts, photographs and site images, emails and .msg files, PDF documents, and notes. These may contain personal data of employees, subcontractors, consultants, or third parties.

DSWaldron GmbH processes this data only on the customer's documented instructions, for the purpose of operating the SiteActa service, and under a data processing agreement where one has been entered into. Customers are responsible for the lawful basis of uploading personal data and for informing the individuals concerned where required.

Account-level personal data (name, email, role, workspace membership) is processed by DSWaldron GmbH as controller for the purposes of authentication, access control, billing, and support.

5. Purposes and legal bases

  • Responding to enquiries, legitimate interest (Art. 6(1)(f) GDPR) / Art. 31(1) FADP.
  • Operating the SiteActa service for signed-in users, performance of a contract (Art. 6(1)(b) GDPR).
  • Security, fraud prevention, service integrity, legitimate interest.
  • Complying with legal obligations, Art. 6(1)(c) GDPR, e.g. accounting and tax records.
  • Processing customer project data, on behalf of the customer, under a DPA where one has been entered into (Art. 28 GDPR / Art. 9 FADP).

6. Hosting and processing location

Project content at rest is stored in the EU, and AI processing of that content is pinned to the EU. Edge delivery and email transport involve providers with global infrastructure.

  • Database, authentication and object storage, Supabase on AWS, eu-central-1 (Frankfurt, Germany).
  • AI inference and embeddings, Google Vertex AI, europe-west4 (Netherlands), pinned in code.
  • Application runtime and edge/TLS, Cloudflare global edge; the nearest point of presence serves the request, which may be outside the EU depending on where the request originates.
  • Inbound email, SendGrid; the processing region is not restricted to the EU.
  • Outbound email, Resend, sent via the Lovable connector gateway.
  • Timestamping, DigiCert RFC 3161, which receives only a SHA-256 hash and never content.
  • Platform management, Lovable.

We do not claim that all processing takes place within Europe, and we make no representation here about signed data processing agreements or specific transfer mechanisms with these providers.

7. Subprocessors

The providers we use to operate SiteActa, the data each one touches and where it processes that data are published in the subprocessor register on our security page, which states its own last-updated date. Customers will be notified before a new subprocessor is engaged or an existing one changes materially.

8. Retention

  • Contact enquiries: retained only as long as needed to respond and for a reasonable follow-up period, then deleted or archived under our records-retention rules.
  • Server logs: retention is determined by the hosting platform. It is not configured by us and we have not independently verified it.
  • Customer project data in SiteActa: retained for the term of the customer's contract. On termination, data is deleted or returned in accordance with the customer's written agreement and any data processing agreement entered into, subject to any legal retention obligation.
  • Account data: retained while the account is active; deleted or anonymised after closure, subject to legal retention.

9. Your rights

Under FADP and GDPR you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data corrected (rectification).
  • Have your data deleted where the legal grounds apply.
  • Restrict or object to certain processing.
  • Receive your data in a portable format (GDPR).
  • Withdraw consent at any time, where processing is based on consent.

If your data is held by DSWaldron GmbH as processor on behalf of a SiteActa customer (for example, you appear in a project record uploaded by a contractor using SiteActa), please contact that customer first; we will support them in responding.

To exercise your rights, contact darrenw@dswaldron.ch. We respond within the timeframes required by applicable law.

10. Complaints

You have the right to lodge a complaint with a data-protection authority.

  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC / EDÖB), Bern.
  • EU / EEA: the supervisory authority of your country of residence, workplace, or where the alleged infringement occurred.

11. Security

SiteActa is designed around evidence integrity: uploaded records are content-hashed and sealed. We use TLS in transit and role-based access control. Encryption at rest for the database and object storage is provided by the underlying hosting platform and is inherited from that provider rather than independently verified by us. No system is perfectly secure, but we apply industry-standard technical and organisational measures appropriate to the risk.

12. International transfers

Project content at rest is stored in the EU and AI processing of that content is pinned to the EU. Some processing nevertheless takes place outside Switzerland and the EEA: the application runtime and TLS termination run on Cloudflare's global edge, where the nearest point of presence serves the request, and inbound email is received through SendGrid, whose processing region is not restricted to the EU. The browser-side providers listed in the subprocessor register are also served globally. As stated in section 6, we make no representation here about specific transfer mechanisms with these providers.

13. Automated decision-making

SiteActa uses AI to organise, summarise, and search customer-uploaded documents. These features are advisory: they surface information for humans to review. We do not use them to make decisions with legal or similarly significant effect about individuals in the sense of Art. 22 GDPR.

14. Changes to this policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes are highlighted at the top of this page. The "Last updated" date always reflects the current version.