Data controller: DomaFlow c/o Fiorenzo Comini, Via Alle Vigne 8, 6963 Pregassona, Switzerland. For any questions regarding data protection, you can write to privacy@domaflow.com. We respond within 30 days.
We process personal data of four categories of people, with different roles and rules:
For data that our customers upload to the platform — tenant and owner records, documents, assembly recordings — the data controller is the customer, not us. If you are a tenant or owner and want to exercise your rights, contact the property management company that engaged us.
| Who | In which context | Our role |
|---|---|---|
| Website visitors | Browsing domaflow.com | Controller |
| Platform users | Access and use of DomaFlow by our customers' staff | Controller for account, processor for content |
| Signatories of offers and contracts | Electronic signature of our business documents | Controller |
| People whose data is processed by our customers | Tenants, owners, suppliers and assembly participants | Processor, on customer instruction |
Name, surname, email address, phone number, company, role, preferred language.
Company details, address, business identification number, VAT number, payment details, documents issued (offers, contracts, invoices) and their status.
IP address, browser and device type, pages visited, date and time of accesses, application logs, technical and preference cookies.
For each signatory of an offer or contract we record: verified email address, declared name and function, date and time of each relevant event, IP address, browser identifier, signature image and cryptographic fingerprint of the signed document. This data constitutes proof of signature and we retain it for the duration specified in section 8.
Documents, records, audio recordings of assemblies and any other content uploaded to the platform. We act as a processor for this data.
Messages you send us, support requests, commercial correspondence.
We do not use identifiable personal data to train artificial intelligence models. We do not make automated decisions that produce legal effects or significantly impact individuals.
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service and performing the contract | 3.1, 3.2, 3.3, 3.5 | Contract performance |
| Managing the commercial cycle (offers, signing, billing, collection) | 3.1, 3.2, 3.4 | Contract performance and pre-contractual measures |
| Proving document signature | 3.4 | Legitimate interest in proof of relationship; contract performance |
| Fulfilling legal obligations (accounting, VAT, decennial retention) | 3.2 | Legal obligation (Swiss CO art. 958f, VAT Act) |
| Platform security, abuse prevention | 3.3 | Legitimate interest |
| Customer support | 3.1, 3.6 | Contract performance |
| Improving the service with aggregated and anonymized data | 3.3 | Legitimate interest |
| Commercial communications about similar services | 3.1 | Legitimate interest, with right to opt out at any time |
The platform uses artificial intelligence models for assembly transcription and verbalization, generation and modification of business documents, and conversational and voice assistance.
We use third-party providers that process personal data on our behalf. We have concluded a data processing agreement with each one.
| Provider | Function | Processing location |
|---|---|---|
| Microsoft (Graph API / Azure AD) | Outlook mail sync/send, OneDrive/SharePoint, OAuth login | Europe / USA |
| Google (Gmail, Calendar, Drive, OAuth) | Gmail sync, calendar sync, Drive search, Google OAuth | Switzerland or countries with adequate protection |
| Zernio (WhatsApp BSP) | WhatsApp messaging send/receive | Europe |
| Telegram | Telegram messaging send/receive | Russia / countries with adequate protection |
| Brevo | Transactional email delivery, verification codes | European Union |
| Payrexx | Payment / subscription billing | Switzerland |
We use one or more providers in this category, selected based on required functionality and model performance. As of this policy's update date, we use: Google (Gemini models), OpenAI, Anthropic, AssemblyAI (audio transcription), Mistral AI.
We share data with advisors (trustee, legal), financial institutions for collection and authorities, when required by law. We do not sell personal data and do not make it available to third parties for their marketing purposes.
Some of the providers listed in section 6 process data outside Switzerland.
The application infrastructure and database are hosted in Ireland. EU member states are on the list of countries whose laws provide adequate protection: the transfer requires no additional safeguards.
Under the data processing addendum we have accepted, Google commits to process data subject to Swiss DPA either in Switzerland or in a country with adequate protection.
Some providers — particularly AI model providers — may process data in the USA or other countries without recognized adequate protection laws. In these cases, transfer is based on standard contractual clauses recognized by FDPIC or the provider's certification under the Swiss–U.S. Data Privacy Framework. You can obtain a copy of applicable safeguards by writing to privacy@domaflow.com.
At expiry, data is deleted or irreversibly anonymized.
| Category | Duration |
|---|---|
| Account data | For the duration of the relationship, then 12 months |
| Business and contractual documents | 10 years from end of financial year |
| Electronic signature proofs | 10 years |
| Customer-uploaded content | For the contract duration, plus 12 months grace period for export |
| Application logs and technical data | 12 months |
| Commercial correspondence | 3 years from last contact |
We implement technical and organizational measures appropriate to risk: encryption of data in transit and at rest, access control based on least privilege principle, segregation of application secrets on server side, logging of activities to an immutable ledger, email verification via one-time code.
In the event of a security breach that poses a high risk to the personality or fundamental rights of individuals, we notify FDPIC and, where required, the affected individuals and customers, without undue delay.
Within the limits provided by law you have the right to: obtain information about your data; correct it if inaccurate; request its deletion or processing limitation; receive your data in electronic format; object to processing based on our legitimate interest; withdraw consent at any time.
To exercise these rights, write to privacy@domaflow.com. We may ask for information to identify you with reasonable certainty. If you believe processing violates the law, you can contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, and — where GDPR applies — the competent supervisory authority in your country of residence.
We use technical cookies necessary for site and platform functionality (authentication, security, language and theme preferences). We do not use advertising profiling cookies. You can delete cookies from browser settings; disabling technical cookies may prevent services from working.
We may update this policy. Previous versions remain available with effective date information. Material changes are communicated to customers at least 30 days in advance. Version 2.0 — effective from 02.09.2026. Version history: https://domaflow.com/en/privacy/versions