Privacy Policy
This policy informs you which personal data trimio.ch collects, processes and stores. It follows the revised Swiss Federal Act on Data Protection (nFADP) and the EU General Data Protection Regulation (GDPR).
1. Controller
The controller for data processing under nFADP is the operator of trimio.ch named in the imprint. Privacy questions to info@trimio.ch.
2. Data collected
We process the following categories of personal data:
- Account data: name, email, password (hash), workshop name, role.
- Workshop orders and customer data: vehicle data, owner info, service history, invoices — you are the controller for this data under nFADP, we act as processor.
- Usage data: IP address, browser type, access time, technically necessary logs.
- Communication data: support email content, contact requests.
3. Purpose of processing
- Providing the software and agreed features.
- Billing and subscription management.
- Ensuring security, troubleshooting and misuse prevention.
- Communicating with you about your account and system changes.
4. Hosting and data location
Your data is hosted on servers in Switzerland [VERIFY — specific provider, e.g. Hetzner Nuremberg (EU) or a Swiss DC]. No transfer to third countries lacking adequate data protection.
5. Cookies and tracking
We only use technically necessary cookies for login and session management. No third-party tracking, no ad cookies, no fingerprinting.
6. Retention period
We retain personal data only as long as required for the stated purposes or by law (in particular Swiss Code of Obligations Art. 958f, 10 years for business records).
7. Your rights
You have the right to:
- Access to your processed data;
- Rectification of incorrect data;
- Erasure (unless retention is required by law);
- Objection to certain processing;
- Data portability in a structured format.
To exercise your rights, write to info@trimio.ch. Inside the app, under Settings → GDPR export you find one-click export and deletion for your workshop data.
8. Security
We implement state-of-the-art technical and organisational measures, notably TLS encryption, hashed passwords (bcrypt), role-based access controls and daily encrypted backups.