Last update: 30th November 2022
This notice summarises how we collect and process your personal data in relation to purchase of subscriptions to the “Swiss qualified electronic signature” cloud products and services of SwissSign AG ("SwissID Sign Services"). Any terms used with initial letters shall have the same meaning as in the Terms of Sale, unless defined otherwise.
This notice does not describe our privacy practices relating to our website, tresorit.com and the Tresorit Services in general. If you are a visitor of tresorit.com and/or a user of the Tresorit Services, please visit the Tresorit Privacy Policy to learn more about the privacy practices that apply to you.
Also, this notice does not apply to the privacy practices of SwissSign AG and the provision of the SwissID Sign. To learn more about the data processing practices of SwissSign AG, please click here.
Who will process your personal data?
Tresorit AG (company registration no: CH-300.3.017.920-5; address: Pfingstweidstrasse 60b, CH-8005 Zurich) ("Tresorit") is the reseller of subscriptions to the SwissID Sign services. Accordingly, in relation to the purchase of subscriptions to the SwissID Sign Services, Tresorit will act as an independent controller in respect of your personal data specified below.
What kind of personal data do we process?
When you purchase a subscription to the SwissID Sign Services, we need to process some information about you to make the services work. This information may include the following personal data about you.
Registration data: When you sign up for a subscription with us, we process some identification and contact data. Certain basic information, like your name, the name of your organization, and your email address , is necessary for setting up a subscription to the SwissID Sign Services.
Billing information: At the time of the purchase of your subscription, we also collect certain billing information about you. You might also provide payment information, such as payment card details, which we collect via secure payment processing services. This data is necessary for setting up your subscription to the SwissID Sign Services.
Usage data: We process certain limited data to review the applicable usage limits of your subscription (see clause 4.2 of the Terms of Sale), such as the number of Electronic Signatures created within Customer’s Signing Room. Where necessary, we may also process the email address of Users relating to Customer’s Signing Room.
Additional Data Provided by You: You may decide to share further information, including personal data, with us when you contact us, provide feedback to us regarding the SwissID Sign Services or otherwise communicate with us. It is solely your decision to share any other data with us during such communications, so our processing of such data will be based on your consent.
Logs: As most websites and services provided through the Internet, we gather certain information and store it in log files in relation to the subscription flow. This information includes internet protocol (IP) addresses as well as browser type, operating system, identification numbers associated with your devices, time of access, and error logs.
What is the legal basis for processing? (for EEA users)
If you are an individual in the European Economic Area (EEA), we collect and process information about you only where we have legal bases for doing so under applicable EU laws. This means we collect and use your information only where:
How do we use your data?
We may process your personal data for several purposes, such as:
Managing subscriptions and payments
Usage limit monitoring purposes
Communications
Developing Services
Security
Protecting our legitimate business interests and legal rights
Providing support (in relation to subscription management)
Other purposes
Do we share your personal data with third parties?
We will share your personal data with third parties only in accordance with this notice. We will never sell your personal data to third parties. However, we may need to share some information, including personal data, we obtain from your use of our service in the following circumstances.
Where do we transfer your data?
Tresorit AG is a company organized and existing under the laws of Switzerland, having affiliates within the territory of the EEA (Germany and Hungary). Switzerland was already granted a data protection adequacy status by the European Commission. The effect of such a decision is that, if you are located in the EEA, transfer of your personal data to Switzerland are practically considered as intra-EU transmission of data.
We primarily store personal data within the EEA, in particular, on Microsoft Azure servers in Ireland. Your personal data stored with us may also be transferred to countries outside of the EU. All such transfers of personal data are and will be made in accordance with applicable laws.
How do we protect your data?
We take appropriate technical and organizational measures to protect your personal data against loss or other forms of unlawful processing. Tresorit is ISO 27001:2022 certified.
How long will we retain your information?
We will retain your personal data as long as it is needed to fulfill the purposes specified above, unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements). When we have no ongoing legitimate business need to process your personal data, we will either delete or anonymize it as soon as it technically possible.
Your privacy rights
You may ask us:
You can request this by send an email to support@tresorit.com. We will respond to your request within thirty days. Please note that we may ask you to verify your identity before complying with the request.
You also have the right to complain to a data protection authority or claim damages before the court. For more information, please contact your local data protection authority. A list of contact details for the EU data protection authorities is available here.
Withdrawal of consent
In cases where the processing of your personal data is based on your consent, you can withdraw your consent any time by contacting us at support@tresorit.com. If you withdraw your consent, we will no longer process your personal data for the relevant purpose. However, please note that such withdrawal of your consent does not affect the lawfulness of our processing activities based on consent before its withdrawal.
Changes to this policy
As every high-quality service, our service is constantly improved in effort to keep users satisfied, but these improvements necessarily mean changes. Due to the ongoing changes in the law and the changing nature of technology, data practices are changing from time to time. Thus, we reserve the right to alter or modify this policy when it is necessary.
Any further question?
If you have any questions, please contact us at support@tresorit.com.
We have also appointed a data protection officer, whom you can reach at dpo@tresorit.com. We speak English.
As Tresorit AG is located outside of the EU, we appointed our EU affiliate to represent us in relation to any GDPR-related issues. This does not change the fact that Tresorit AG is the controller who ultimately handles your data. If you wish, you can also contact them directly. The details of our EU located affiliate is available here.