Privacy Policy
Last updated: February 9, 2026
1. Data Controller
The party responsible for data processing under the Swiss Federal Act on Data Protection (FADP) is:
codebar Solution AG
Hauptstrasse 91
4455 Zunzgen
Switzerland
Email: info@codebar.ch
2. Applicable Law
This privacy policy is governed by the Swiss Federal Act on Data Protection (FADP). If you access our service from the EU/EEA, the provisions of the General Data Protection Regulation (GDPR) also apply.
3. Data Collected
We collect and process the following personal data:
- Account data: Email address, name, language preference
- Organization/tenant data: Company name, address (street, postal code, city, country), VAT number
- Third-party credentials: DocuWare URL, DocuWare username and password, AWS credentials (access key, secret key, bucket, region) — all stored encrypted
- Export data: Export configurations, export logs, document metadata
- Technical data: IP address, user agent (browser type and device information) via session data
- Activity logs: Login/logout events, changes to account settings and export configurations
4. Purpose and Legal Basis for Processing
We process your data for the following purposes:
- Contract performance: Providing and managing your user account, performing export functionality, storing your configurations and credentials
- Legitimate interest: Improving our service, analyzing website usage (via privacy-friendly analytics), ensuring system security
- Legal obligation: Fulfilling statutory retention requirements
- Consent: Communication about service updates and non-essential notifications (where applicable)
5. Third-Party Services
We use the following third-party services to provide our service:
- Postmark (ActiveCampaign, LLC, USA): Email delivery for authentication links and notifications. Data processed: email address, name.
- Amazon Web Services (AWS) S3 (Amazon, USA / region per user configuration): Storage of exported documents. Data processed: exported documents and metadata, user-provided AWS credentials.
- DocuWare (DocuWare GmbH, Germany): Source system for document export. Data processed: user-provided DocuWare credentials, document metadata.
- Fathom Analytics (Conva Ventures Inc., Canada / EU-hosted): Privacy-friendly, cookieless website analytics. Data processed: anonymized page views and events. No personal data is collected or stored.
- Bunny Fonts (BunnyWay d.o.o., Slovenia): Web font delivery. Data processed: IP address, user agent on each page load.
6. International Data Transfers
Some of our service providers are located outside of Switzerland and the EU/EEA:
- Postmark (USA): Transfers are made on the basis of Standard Contractual Clauses (SCC) and appropriate data protection safeguards.
- AWS (USA / user-configured region): Transfers are made on the basis of Standard Contractual Clauses (SCC). The storage region is configured by the user.
- Fathom Analytics (EU-hosted): Data processing takes place on EU servers. No personal data is transferred.
7. Data Security
We implement technical and organizational security measures to protect your data:
- All third-party credentials (DocuWare, AWS) are stored encrypted in our database
- All data transmissions are conducted via TLS encryption
- Access to personal data is restricted to authorized personnel
- Passwordless authentication via one-time, time-limited magic links
8. Data Retention
We retain your data according to the following periods:
- Account data: Until deletion of your account
- Export data: Deleted within 48 hours after export completion
- Session data: Cleared on logout or after inactivity
- Activity logs: Retained for 12 months
- Legal retention obligations: Where required by law, certain data is retained for the legally prescribed period
9. Cookies and Tracking
We only use technically necessary session cookies for application authentication and security. These cookies are essential for the operation of the service and cannot be disabled.
Our website analytics are provided by Fathom Analytics, a privacy-friendly service that does not use cookies and does not collect any personal data. No advertising or tracking cookies are used.
10. Your Rights
You have the following rights regarding your personal data:
- Right of access: Request access to your stored data
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your data
- Right to restriction of processing: Request restriction of processing of your data
- Right to data portability: Receive your data in a structured, commonly used format
- Right to object: Object to the processing of your data
- Withdrawal of consent: Withdraw any given consent at any time
To exercise your rights, please contact us at info@codebar.ch.
11. Right to Lodge a Complaint
You have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC):
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
3003 Bern
Switzerland
www.edoeb.admin.ch
For users in the EU/EEA, you may also contact the competent data protection supervisory authority in your country of residence.
12. Contact
For questions about data protection, please contact us:
codebar Solution AG
Hauptstrasse 91
4455 Zunzgen
Switzerland
Email: info@codebar.ch