Updated: · privacy-2026-09-11
01Controller and contact
Swissi Holding AG, Baarerstrasse 78, 6300 Zug, Switzerland, company identifier CHE-189.603.726, is the controller for the EAID account, identity and authority service. Contact hello@swissi-ai.institute for privacy requests, complaints and questions, or write to our registered address marked ‘EAID Privacy’.
This policy covers EAID websites, account interfaces and identity services used through connected applications. Each connected service is responsible for the purposes it determines, including its customer relationship and the information it receives. A service operated by another Swissi business remains subject to the same recipient approval requirements.
02Minimum collection and voluntary information
To open and maintain your EAID account, we require only the minimum personal information needed for that purpose and our applicable legal obligations. Each required field serves the account purpose identified at collection or a specified legal duty.
You decide which additional identity facts and documents to provide, how many instances to keep, which confirmations to request and which information to release. Additional identity information is voluntary. Protected identity values are stored encrypted in your Vault using the algorithms specified below. Public profile information and information you release to a recipient follow your selected visibility and disclosure settings.
03Information and its sources
Account creation requires the information marked as required in the registration flow and the credentials needed to authenticate you. Additional facts and disclosures are selected by you. A service can require particular information or confirmation before providing a particular service; declining that request can prevent that transaction. The service determines and communicates its requirements.
When information comes from another source, we provide the source and the information needed to exercise your rights within the applicable statutory period, including at the first communication or disclosure when required. You can request the available source information from us.
- Account and authentication: email address, account and profile identifiers, screen names, language, country of residence, account status, password registration records, public keys, device registrations, authentication challenges, session records and security events.
- Identity facts: the names, dates, addresses, contact details, nationalities, identity documents, qualifications and other information you provide. Each fact can have several instances and historical versions.
- Confirmations: the exact fact examined, confirmer and source, evidence, method, jurisdiction, dates, validity and withdrawal status. Sources include your chosen sign-in provider, credential issuer, register, verification service and authorised human verifier. A register can supply information about you without your entering the value yourself.
- Authority and represented subjects: organisations, memberships, representation rights, machine and device identities, mandates, accountable people, and relationships to animals and objects. A business or another authorised person can supply a relationship that concerns you; its source and authority form part of the record.
- Requests and receipts: the requesting service, selected profile, requested facts, purpose, recipient, storage terms, your decision, signature, delivery, future-update permission, revocation and evidence of reliance. Business signatures also record the act and the authority under which it was signed.
- Technical and support records: IP addresses, request times, browser and device characteristics, error and security signals, correspondence, operational access records and case evidence. An email delivery service also processes delivery status and technical delivery events.
04Purposes and legal grounds
Swiss processing follows the Federal Act on Data Protection, including proportionality, purpose limitation, transparency and the rules governing justification for an interference with personality rights. For processing subject to the GDPR, the grounds below apply to the specified purposes.
| Purpose | Information used | GDPR ground |
|---|---|---|
| Create and administer your account; authenticate you; maintain your selected profiles and requested identity records | Account, credentials, profile and selected identity facts | Article 6(1)(b): performance of the EAID contract and steps requested before it |
| Carry out a requested confirmation, signed disclosure, connection or business act | Selected facts, confirmation evidence, recipient request, authority and receipts | Article 6(1)(b) for the operation you request; Article 6(1)(a) for processing separately presented for your consent |
| Protect accounts, prevent abuse, investigate faults and maintain service integrity | Minimum technical signals, access records, authority and relevant case evidence | Article 6(1)(f): our and account holders’ legitimate interests in a secure, reliable service, assessed against your rights |
| Answer support and rights requests; satisfy a binding legal obligation | Contact details, proportionate identity checks and records relevant to the request | Article 6(1)(b) for contractual support; Article 6(1)(c) for applicable legal duties |
| Establish, exercise or defend legal claims | Relevant contractual, security, approval and delivery evidence | Article 6(1)(f): our or an affected party’s interest in resolving a specific claim; Article 6(1)(c) for a legal preservation duty |
A signed disclosure defines what EAID is authorised to deliver. The recipient must separately establish its own lawful basis for collecting and using the information. Accepting the Terms of Service and acknowledging this policy are distinct from consenting to optional processing.
Consent can be withdrawn for the future. Withdrawal preserves the lawfulness of processing before withdrawal. A new purpose requiring consent receives its own request; a change to this policy does not supply that consent.
05Sensitive information and device biometrics
Identity material can contain sensitive personal data, including health information, religious or political beliefs, or biometric data used to identify a person uniquely. We process such material only for the selected purpose with a valid ground under the applicable sensitive-data rules. Under GDPR Article 9, optional sensitive-data processing requires your explicit consent unless another specific statutory exception applies, such as necessity for legal claims. Criminal-conviction data requires the separate authority and safeguards of GDPR Article 10.
For Face ID, Touch ID or a comparable device authentication method, the device or credential provider performs the biometric check. EAID receives a cryptographic authentication result and credential information. The face or fingerprint template used for that device check stays within the device or its credential system. A biometric identity fact you separately submit for verification follows the identity-fact and sensitive-data rules above.
06Your signed disclosures and future updates
A recipient request identifies the service, selected profile, exact information or representations, purpose, storage terms, validity and any continuing access. Your signature authorises that package. A permission for future updates also defines the fields, admissible successor versions, freshness, frequency and expiry. A machine mandate authorises only its recorded capabilities and profile scope; consequential approvals follow the requirements attached to that authority.
You can revoke future access. Revocation stops subsequent authorised retrieval under that permission. Information already delivered remains subject to the recipient’s stated purpose, lawful basis, retention duties and your rights against that recipient. We retain the evidence necessary to establish what was authorised, delivered and revoked.
A selected profile gives a connected service its own subject identifier. EAID retains the account-to-profile relationship to operate the service. A recipient can recognise you from information you choose to disclose, and profile separation must be considered together with the contents of that disclosure.
07Operational recipients and legal access
Authorised Swissi personnel process information required for their assigned support, security, administration or legal task. Access is scoped and recorded. Contracted infrastructure providers process the data needed to supply hosting, database, storage, security and transactional email services under processing and confidentiality obligations.
The service uses Vercel for web hosting, delivery and BotID abuse protection; Neon for PostgreSQL database infrastructure; Hetzner for private service workers and object storage; and Resend for transactional email delivery. The information handled depends on the task: web and security requests, database records, encrypted stored objects, or email addresses and message content. Your selected sign-in providers, verifiers and disclosure recipients also receive the data involved in the operation you request.
A binding legal requirement can require disclosure to a court, regulator or other competent authority. We assess authority, necessity and scope and record the disclosure. Access to highly protected values follows the exceptional custodian procedure or your signed recipient approval. The custodian procedure requires the prescribed approvals; a support request alone supplies no authority to open those values. We inform you of a legal disclosure unless notification is legally restricted.
08International processing
Swissi Holding AG is established in Switzerland. Our infrastructure suppliers include Hetzner Online GmbH in Germany and Vercel Inc., Databricks, Inc. with its affiliate Neon, LLC, and Plus Five Five, Inc. (Resend) in the United States. Supplier establishment and the location of a particular processing operation are separate facts. Access by a supplier or its subprocessor from abroad is included in our transfer assessment.
Transfers require an applicable adequacy decision or appropriate safeguards under Swiss FADP Article 16 and GDPR Chapter V. Standard contractual clauses require the applicable Swiss adaptations, an assessment of the destination’s laws and supplementary measures where needed. Reliance on a data privacy framework requires the relevant recipient and processing to be covered by a valid certification. An exception for a particular transfer is confined to its statutory conditions.
Contact hello@swissi-ai.institute for the destination countries applicable to your processing and a copy of the relevant transfer safeguards. We protect third-party confidential information when providing copies. A disclosure to a recipient you choose also identifies that recipient and the applicable destination in the approval information.
Resend’s transactional email processing takes place primarily in the United States. Its published processing addendum includes standard contractual clauses and provisions for Swiss data. Supplier processing terms and subprocessor information are available through the links below.
09Encryption and access controls
Protected vault values use AES-256-GCM authenticated encryption with a separate 256-bit data key per value, a random 96-bit nonce and a 128-bit authentication tag. Encryption occurs at the application layer before the protected value is stored in PostgreSQL. Signup information drafts also use AES-256-GCM.
Recipient key envelopes use Hybrid Public Key Encryption (HPKE): DHKEM with P-256 and HKDF-SHA256, HKDF-SHA256 key derivation, and AES-256-GCM. This binds access to the designated recipient key. Highly protected values use Shamir secret sharing with a 2-of-3 threshold for the exceptional custodian path, alongside the holder’s own access.
Password authentication uses OPAQUE (RFC 9807), the ristretto255-SHA512 suite and Argon2id with 64 MiB memory, three iterations and parallelism four. Password-based key protection derives an AES-256-GCM key using HKDF-SHA256 from the OPAQUE export key. Qualified-device approvals use ECDSA with P-256 and SHA-256 (ES256). HTTPS/TLS protects communication with the service.
The protection applies according to the data’s role. Account and routing metadata, public presentations and signed verification evidence have their own access rules. Private profile images use access-controlled object storage and authorised download links. Operational access to ordinary protected values is scoped and recorded; highly protected values follow holder approval or the exceptional custodian procedure. An authorised recipient can process the released plaintext under its own duties.
10Verification networks and retained evidence
EAID records cryptographic commitments, public verification identifiers, authority events and timestamps on its verification networks. Network operators and parties with access to the relevant network can process those records. Identity values and the protected account-to-profile relationship are held in operational data domains. A commitment, public key or pseudonymous identifier can still constitute personal data when it is linkable to a person.
Network records persist through account closure and can be technically difficult to alter or remove. We assess requests for erasure, restriction and objection against each record’s purpose, lawful basis and available technical measures. Removing an off-network association does not by itself establish anonymisation. Your privacy rights continue to apply to retained network records. Continued retention requires a lawful reason.
11Retention, correction and account closure
We retain active account information for the account relationship and selected functions. A replacement identity value starts a new version; confirmations continue to identify the value that was examined. Historical evidence is retained only to the extent necessary for an active authorisation, an identifiable reliance obligation, a legal duty or a specific claim.
Authentication challenges, signup permissions and sessions have limited validity. Their expiry ends their use for authentication; deletion of the corresponding database or security record follows its retention purpose. Browser storage durations are listed in the Cookies and device storage notice.
Security and support records are retained for the time needed to resolve the incident or request and establish the relevant outcome. Evidence preserved for a claim is limited to the material required until the applicable limitation period expires or the proceeding and any enforceable preservation duty end. Statutory accounting records, where created, are retained for the applicable accounting period, including ten years under Swiss law.
On account closure or a valid erasure request, we delete or anonymise information whose purpose has ended and restrict information that must be retained. Restricted backup copies remain protected and expire under the applicable backup cycle; a restoration must reapply the relevant deletion and restriction decisions. We identify the reason and duration or governing criteria for any retained personal information when responding to your request. Recipients’ copies and verification-network records require the separate treatment described above.
12Automated checks and review
EAID automatically checks credentials, current authority, confirmation sources, binding, validity and the requirements declared by a service. The result indicates whether the submitted facts and authority meet that particular request. Several confirmations can concern one fact; each retains its own source and dates. A service uses the result to decide access to its own service. Abuse checks also use technical signals to allow, challenge or reject a request.
You can contest an inaccurate fact, confirmation, authority record or EAID result through hello@swissi-ai.institute and request human review. For an exclusively automated decision with legal or similarly significant effects, you can express your view and obtain the review and safeguards required by applicable law. For a connected service’s decision, contact that service; we address errors in the EAID information or processing that contributed to it.
13Your rights and complaints
- Access: obtain confirmation of processing and the personal data and related information needed to understand it.
- Correction: correct inaccurate facts and complete incomplete records; disputed confirmations retain their provenance and can be challenged.
- Erasure and restriction: request deletion or restricted processing under the applicable statutory conditions.
- Portability: receive qualifying data in a structured, commonly used, machine-readable format and request transmission where the statutory conditions and technical feasibility permit.
- Objection: object to processing based on legitimate interests on grounds relating to your situation. We stop that processing unless an overriding lawful ground or the defence of legal claims justifies continuation.
- Withdrawal: withdraw optional consent and revoke future recipient access. Your right to complain and the lawfulness of earlier processing remain intact.
Send your request to hello@swissi-ai.institute or our registered address. You can use the same route after losing account access. We verify identity proportionately and request only the information necessary to prevent disclosure to the wrong person. Requests are normally free. We respond within 30 days under Swiss access rules and within one month under the GDPR; a permitted extension or restriction is communicated with its reason within the applicable deadline.
You can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland. Under the GDPR, you can also complain to the supervisory authority in your habitual residence, place of work or the place of the alleged infringement. Judicial remedies remain available.
14Policy changes
The revision identifier and date identify this policy. Material changes are communicated before the changed processing begins, using the account interface or the contact details held for service notices. A change requiring a new legal ground or a fresh consent is implemented only after that requirement is met. You can request the policy version associated with your account registration or a particular authorisation.