How DSWaldron GmbH collects, uses, and protects personal data, under the Swiss Federal Act on Data Protection (FADP / revised nDSG) and the EU General Data Protection Regulation (GDPR).
DSWaldron GmbH, a Swiss limited liability company (UID CHE-218.721.502), based at Maistrasse 10, 5430 Wettingen, Switzerland, is the controller responsible for the personal data described in this policy. Full contact details are in our Impressum.
This policy covers two things:
If you use the contact form, your details are sent to us by email from our server. We receive: name, company, email, optional phone number, and message content. Nothing is stored in a database on the marketing site itself.
Our hosting provider records standard technical logs (IP address, user-agent, timestamp, requested URL) for a short retention period, used only to keep the site secure and operational.
When our customers use SiteActa, they upload project documentation such as: contracts, photographs and site images, emails and .msg files, PDF documents, and notes. These may contain personal data of employees, subcontractors, consultants, or third parties.
DSWaldron GmbH processes this data only on the customer's documented instructions, for the purpose of operating the SiteActa service, and under a data processing agreement where one has been entered into. Customers are responsible for the lawful basis of uploading personal data and for informing the individuals concerned where required.
Account-level personal data (name, email, role, workspace membership) is processed by DSWaldron GmbH as controller for the purposes of authentication, access control, billing, and support.
Project content at rest is stored in the EU, and AI processing of that content is pinned to the EU. Edge delivery and email transport involve providers with global infrastructure.
We do not claim that all processing takes place within Europe, and we make no representation here about signed data processing agreements or specific transfer mechanisms with these providers.
The providers we use to operate SiteActa, the data each one touches and where it processes that data are published in the subprocessor register on our security page, which states its own last-updated date. Customers will be notified before a new subprocessor is engaged or an existing one changes materially.
Under FADP and GDPR you have the right to:
If your data is held by DSWaldron GmbH as processor on behalf of a SiteActa customer (for example, you appear in a project record uploaded by a contractor using SiteActa), please contact that customer first; we will support them in responding.
To exercise your rights, contact darrenw@dswaldron.ch. We respond within the timeframes required by applicable law.
You have the right to lodge a complaint with a data-protection authority.
SiteActa is designed around evidence integrity: uploaded records are content-hashed and sealed. We use TLS in transit and role-based access control. Encryption at rest for the database and object storage is provided by the underlying hosting platform and is inherited from that provider rather than independently verified by us. No system is perfectly secure, but we apply industry-standard technical and organisational measures appropriate to the risk.
Project content at rest is stored in the EU and AI processing of that content is pinned to the EU. Some processing nevertheless takes place outside Switzerland and the EEA: the application runtime and TLS termination run on Cloudflare's global edge, where the nearest point of presence serves the request, and inbound email is received through SendGrid, whose processing region is not restricted to the EU. The browser-side providers listed in the subprocessor register are also served globally. As stated in section 6, we make no representation here about specific transfer mechanisms with these providers.
SiteActa uses AI to organise, summarise, and search customer-uploaded documents. These features are advisory: they surface information for humans to review. We do not use them to make decisions with legal or similarly significant effect about individuals in the sense of Art. 22 GDPR.
We may update this policy to reflect changes in our practices or legal requirements. Material changes are highlighted at the top of this page. The "Last updated" date always reflects the current version.