Two roles, and the difference matters
For your firm’s data - addresses, mandates, search profiles, documents - your agency is the controller; IT Hub GmbH processes it on its behalf and on its instructions. For the user accounts themselves - name, sign-in, log entries - IT Hub GmbH is the controller. Mixing the two means promising either too much or too little.
What data arises
For the account: user name, display name, e-mail address, office, roles and the details of the second factor. While working: what you create and change, each with your name and the time - which is exactly what later shows who created an address. During operation: technical logs with time, request and error message.
When registering
Whoever registers their company is not yet a customer. In step one we store your e-mail address, the language, the time and the IP address the request came from - for the confirmation link (valid 48 hours) and to limit abuse. If the link is not opened, these details are deleted after seven days. In step two company, first and last name, phone, the chosen address and the password are added; with that your company comes into being, and from then on the responsibility for its data lies with it (section "Two roles"). As proof of the contract the time and the version of the accepted terms remain stored.
What it is used for
Solely to provide the application, keep it secure and find faults. There is no analysis of your behaviour, no advertising, no disclosure to third parties for their purposes and no automated decision with legal effect.
Where it is kept
On servers in Switzerland. Files - documents, images, attachments - are stored next to the application in the file system of the same server, in a separate directory per customer. The application's data does not leave Switzerland. What goes abroad is listed exhaustively under "Third-party services": a check against automated sign-ups, map tiles and - only for addresses outside Switzerland - the determination of coordinates. Customer data in the sense of contacts, mandates and documents is not among it.
Who sees it
Within your firm, only those entitled to; every query is restricted to your tenant, and data of other agencies is technically out of reach. On the side of IT Hub GmbH, only the people responsible for operation and maintenance have access - and only as far as a particular task requires.
How long it stays
Deleted addresses, mandates, search profiles and documents first go to a recycle bin and can be restored for 90 days; after that they are removed for good, together with the associated files. A deleted user account loses password, roles and office assignment at once; the name remains so that the records still show who created them. Technical logs are overwritten after a short time.
What is stored in the browser
No advertising or tracking cookies. The browser storage holds: the sign-in for the lifetime of the tab, the language, the chosen columns and the state of your lists. All of it serves operation and never leaves your device.
Third-party services
Mandatfeed embeds no analytics or advertising services and no fonts from foreign servers. Five services are used for individual tasks, each only there:
Google reCAPTCHA v3 (Google Ireland Ltd. / Google LLC, USA) on the forms without sign-in - registration, sign-in, "forgot password" - to fend off automated sign-ups. The browser loads a script from Google, and Google receives your IP address, browser details and your interaction with the page. Google's Privacy Policy and Terms of Service apply.
OpenStreetMap (OpenStreetMap Foundation, servers in Europe) provides the map tiles when you open a map; the map server receives your IP address and the map section.
swisstopo (Federal Office of Topography, Switzerland) determines coordinates for Swiss addresses; the property's address is transmitted, no person.
Google Geocoding (Google LLC, USA) determines coordinates only for addresses outside Switzerland; the property address is transmitted.
OpenAI (OpenAI, L.L.C., USA) answers the AI functions - only when you press an AI button, and only with what the respective suggestion needs: for listing texts the details that go to the portal anyway; for classifying and answering an enquiry its sender and message; for a to-do the text of the phone note; for the marketing report the ticked figures; for the second opinion on duplicates name, address, phone, e-mail and industry of the compared entries. Notes, documents and clients do not go along. The answer is only saved when you apply it. OpenAI's privacy policy applies; under its terms for the programming interface, transmitted content is not used to train the models.
Data processing agreement
For your company's data, IT Hub GmbH acts as processor under Art. 9 of the Swiss Data Protection Act. What that means in detail - instructions, confidentiality, measures, sub-processors, breach notification, return and deletion - is set out in the data processing agreement. It is part of the contract with every company.
Your rights
You have the right to information, correction, deletion and release of your data. If your request concerns your firm’s data, address it to the firm - it decides. If it concerns your user account, use the address at the end of this page. You may also turn to the Federal Data Protection and Information Commissioner.
Security
Transmission is encrypted. Passwords are never stored in clear text. Access can be secured with a second factor. Access is logged, and the separation between agencies is not a setting but a rule in the data model.
Provider
The provider details could not be loaded just now.