1. Scope and roles
This agreement is between your company (the controller) and Wiiseto, LLC (the processor). It covers the personal data in your workspace, and fulfils Art. 9 revFADP and Art. 28 GDPR. It is part of the Terms of Service and applies automatically. If you need a signed copy for your records, write to [email protected] and we countersign one.
Your account, billing, security and analytics data are not covered here: for those we are the controller, and the Privacy Policy applies.
2. Subject matter of the processing
| Purpose | Providing Wiiseto to your company: storing, displaying, syncing, searching, sharing and, if enabled, analysing workspace data with AI |
| Duration | While your company uses Wiiseto, plus the 100-day recovery window after the company is deleted |
| Data subjects | Your members, your employees (including those without an account), your clients, contacts and subcontractors, and anyone who uploads through your upload links |
| Types of data | Names and contact details; employee records (birthday, start date, contract type, location, notes, photo, absences and availability); contact records; project, task, planning and calendar content; comments and chat messages, with edit history; files and the text read from them; audio notes; vehicle assignments; IP address of anonymous uploaders |
| Special categories | None on purpose. Absences marked as sick leave can reveal health information, and free text can contain anything you type. You decide what you record and must have a lawful basis for it. |
3. Our obligations
We:
- process the data only on your documented instructions, which are these terms, the settings you choose in the app, and anything you ask in writing;
- tell you if we think an instruction breaks the law;
- make sure everyone with access is bound by confidentiality;
- apply the measures in section 6;
- help you answer data subject requests, carry out impact assessments and consult authorities, as far as we reasonably can;
- never sell the data, and never use it to train AI models.
4. Data subject requests
Most requests can be handled directly in the app by your admins (edit, delete, export documents). If a data subject contacts us directly, we pass the request on to you and do not answer it ourselves unless you ask us to. Whole-workspace exports and account deletions are done by hand for now, within 30 days of your request.
5. Security incidents
If we become aware of a breach affecting your data, we act on it at once and tell you as soon as possible, and in any case within 72 hours, with what we know, what we are doing, and who to contact. Within 31 days, we send you a detailed report: what happened, what data and people were affected, and what we changed to prevent it happening again. Notifying the authorities and the people affected is your decision as controller; we help you with the information you need.
6. Technical and organisational measures
- Encrypted connections (TLS) between browsers, our network provider and our servers.
- Passwords hashed with bcrypt; two-factor authentication for every plan.
- Application-level encryption (AES-256-GCM) of two-factor secrets, backup codes, calendar connection tokens and single sign-on secrets.
- Permission checks on the server for every request, by company and by project, denied by default.
- Rate limiting on sign-in and on the API; sign-in risk checks.
- Location data (EXIF, GPS) removed from photos.
- Nightly database backups, kept 7 days on the server and 30 days in EU storage, encrypted at rest by the storage provider.
- Access to production is limited to the people who run Wiiseto, and only used for operations, support you ask for, or legal obligations.
7. Sub-processors
You give us a general authorisation to use the sub-processors listed on the Sub-processors page.
- Before adding or replacing one, we email your company's founder at least 30 days in advance.
- You may object within those 30 days on reasonable data protection grounds. If we cannot find a solution together, you may end the affected part of the service, and we refund the unused prepaid fees.
- We bind each sub-processor to written terms at least as protective as these, and we remain fully liable to you for them.
8. Location and international transfers
- Application servers and the database: Switzerland.
- Files and backups: Cloudflare R2, EU jurisdiction.
- Application servers and database run on Amazon Web Services in Zurich. Any AWS service not available in Zurich, and email delivery where needed, run in Frankfurt.
- Analytics (only for members who opt in): PostHog in the EU.
- Network traffic passes through Cloudflare's global network.
- If AI is enabled, requests go to the AI providers listed on the Sub-processors page, some of them in the United States. Switching AI off in Company > AI & Credits stops those transfers.
- A copy of the data your members can see is kept in their browsers for offline use.
Transfers outside Switzerland and the EU/EEA rely on an adequacy decision, the EU-US Data Privacy Framework (with its Swiss extension) where the provider is certified, or the standard contractual clauses with the Swiss addendum.
9. Audit
We make available the information you need to check that we comply with this agreement.
- First, we answer your written questions, and share any third-party report or certification we hold, free of charge.
- If that is not enough, you may audit us, or have an independent auditor do it, once a year, with at least 30 days' notice, during business hours, without disrupting the service. The auditor must be bound by confidentiality and must not be a competitor.
- The audit is at your cost, including our reasonable time spent on it. If the audit finds that we materially breached this agreement, we bear its cost instead.
- A further audit is possible at any time if an authority requires it or after a security incident affecting your data.
10. Return and deletion
When your company is deleted, you have 100 days to restore it or ask for an export. After that, the data is deleted from our database, and from backups as they rotate out.
Current gap. Files stored in Cloudflare R2 are not yet deleted automatically when a company is purged. We delete them on request to [email protected], and we are building the automatic deletion.
We keep only what we must keep as proof or for tax: acceptance records and invoices.
11. Liability and precedence
The liability limits in the Terms apply to this agreement, except where mandatory data protection law says otherwise. On anything about personal data, this agreement prevails over the Terms.