Data Protection Policy
Effective from: 9/2/2026

1. Who we are and how to contact us

Data controller: DomaFlow c/o Fiorenzo Comini, Via Alle Vigne 8, 6963 Pregassona, Switzerland. For any questions regarding data protection, you can write to privacy@domaflow.com. We respond within 30 days.

2. Who this policy applies to

We process personal data of four categories of people, with different roles and rules:

Important distinction

For data that our customers upload to the platform — tenant and owner records, documents, assembly recordings — the data controller is the customer, not us. If you are a tenant or owner and want to exercise your rights, contact the property management company that engaged us.

WhoIn which contextOur role
Website visitorsBrowsing domaflow.comController
Platform usersAccess and use of DomaFlow by our customers' staffController for account, processor for content
Signatories of offers and contractsElectronic signature of our business documentsController
People whose data is processed by our customersTenants, owners, suppliers and assembly participantsProcessor, on customer instruction

3. What data we process

3.1 Account and contact data

Name, surname, email address, phone number, company, role, preferred language.

3.2 Contractual and billing data

Company details, address, business identification number, VAT number, payment details, documents issued (offers, contracts, invoices) and their status.

3.3 Usage and technical data

IP address, browser and device type, pages visited, date and time of accesses, application logs, technical and preference cookies.

3.4 Electronic signature data

For each signatory of an offer or contract we record: verified email address, declared name and function, date and time of each relevant event, IP address, browser identifier, signature image and cryptographic fingerprint of the signed document. This data constitutes proof of signature and we retain it for the duration specified in section 8.

3.5 Content uploaded by customers

Documents, records, audio recordings of assemblies and any other content uploaded to the platform. We act as a processor for this data.

3.6 Communications

Messages you send us, support requests, commercial correspondence.

4. Why we process it and on what legal basis

Automated decisions

We do not use identifiable personal data to train artificial intelligence models. We do not make automated decisions that produce legal effects or significantly impact individuals.

PurposeDataLegal basis
Providing the service and performing the contract3.1, 3.2, 3.3, 3.5Contract performance
Managing the commercial cycle (offers, signing, billing, collection)3.1, 3.2, 3.4Contract performance and pre-contractual measures
Proving document signature3.4Legitimate interest in proof of relationship; contract performance
Fulfilling legal obligations (accounting, VAT, decennial retention)3.2Legal obligation (Swiss CO art. 958f, VAT Act)
Platform security, abuse prevention3.3Legitimate interest
Customer support3.1, 3.6Contract performance
Improving the service with aggregated and anonymized data3.3Legitimate interest
Commercial communications about similar services3.1Legitimate interest, with right to opt out at any time

5. Artificial intelligence features

The platform uses artificial intelligence models for assembly transcription and verbalization, generation and modification of business documents, and conversational and voice assistance.

How it works in practice:

  • Content needed for processing (document text, audio tracks, user instructions) is transmitted to the model provider, who processes it and returns the result.
  • Content transmitted is not used by providers to train their models. We use only commercial offerings that contractually exclude such use.
  • Processing may occur on infrastructure located outside Switzerland and the European Economic Area. See section 7.
  • We do not transmit signature images, access credentials or bank details to AI providers.

6. Who we share data with

We use third-party providers that process personal data on our behalf. We have concluded a data processing agreement with each one.

6.1 Infrastructure and core services

ProviderFunctionProcessing location
Microsoft (Graph API / Azure AD)Outlook mail sync/send, OneDrive/SharePoint, OAuth loginEurope / USA
Google (Gmail, Calendar, Drive, OAuth)Gmail sync, calendar sync, Drive search, Google OAuthSwitzerland or countries with adequate protection
Zernio (WhatsApp BSP)WhatsApp messaging send/receiveEurope
TelegramTelegram messaging send/receiveRussia / countries with adequate protection
BrevoTransactional email delivery, verification codesEuropean Union
PayrexxPayment / subscription billingSwitzerland

6.2 Artificial intelligence model providers

We use one or more providers in this category, selected based on required functionality and model performance. As of this policy's update date, we use: Google (Gemini models), OpenAI, Anthropic, AssemblyAI (audio transcription), Mistral AI.

6.3 Other recipients

We share data with advisors (trustee, legal), financial institutions for collection and authorities, when required by law. We do not sell personal data and do not make it available to third parties for their marketing purposes.

7. International transfers

Some of the providers listed in section 6 process data outside Switzerland.

European Union

The application infrastructure and database are hosted in Ireland. EU member states are on the list of countries whose laws provide adequate protection: the transfer requires no additional safeguards.

Google

Under the data processing addendum we have accepted, Google commits to process data subject to Swiss DPA either in Switzerland or in a country with adequate protection.

USA and other countries

Some providers — particularly AI model providers — may process data in the USA or other countries without recognized adequate protection laws. In these cases, transfer is based on standard contractual clauses recognized by FDPIC or the provider's certification under the Swiss–U.S. Data Privacy Framework. You can obtain a copy of applicable safeguards by writing to privacy@domaflow.com.

8. How long we retain data

Deletion

At expiry, data is deleted or irreversibly anonymized.

CategoryDuration
Account dataFor the duration of the relationship, then 12 months
Business and contractual documents10 years from end of financial year
Electronic signature proofs10 years
Customer-uploaded contentFor the contract duration, plus 12 months grace period for export
Application logs and technical data12 months
Commercial correspondence3 years from last contact

9. Security

We implement technical and organizational measures appropriate to risk: encryption of data in transit and at rest, access control based on least privilege principle, segregation of application secrets on server side, logging of activities to an immutable ledger, email verification via one-time code.

Security breaches

In the event of a security breach that poses a high risk to the personality or fundamental rights of individuals, we notify FDPIC and, where required, the affected individuals and customers, without undue delay.

10. Your rights

Within the limits provided by law you have the right to: obtain information about your data; correct it if inaccurate; request its deletion or processing limitation; receive your data in electronic format; object to processing based on our legitimate interest; withdraw consent at any time.

How to exercise your rights

To exercise these rights, write to privacy@domaflow.com. We may ask for information to identify you with reasonable certainty. If you believe processing violates the law, you can contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, and — where GDPR applies — the competent supervisory authority in your country of residence.

11. Cookies

We use technical cookies necessary for site and platform functionality (authentication, security, language and theme preferences). We do not use advertising profiling cookies. You can delete cookies from browser settings; disabling technical cookies may prevent services from working.

12. Changes

We may update this policy. Previous versions remain available with effective date information. Material changes are communicated to customers at least 30 days in advance. Version 2.0 — effective from 02.09.2026. Version history: https://domaflow.com/en/privacy/versions