Swiss Due Diligence & Compliance Pack
SWISS nFADP COMPLIANTLegal, architectural, and data governance framework ensuring full compliance with the revised Swiss Federal Act on Data Protection (revFADP / nFADP) and FINMA data outsourcing standards.
1. Confidentiality, Ownership & Permitted Use
All client financial data, banking tokens, and accounting documents processed via Digintu remain the absolute property of the customer. Digintu processes data strictly on documented instructions from the controller. Data is never monetized, analyzed for commercial gain, or shared with unauthorized third parties.
2. Data Hosting Locations & Sub-Processors
Core hosting is operated by Infomaniak Network SA within sovereign Swiss data centers (Geneva/Zurich) with geo-redundant Swiss backup. Primary sub-processors include Infomaniak (Cloud Infrastructure) and Stripe Inc. (secure payment processing).
3. Categories of Personal Data Stored
To operate user authentication, Digintu stores minimal data: (a) User Identity: Name, email, bcrypt password hashes; (b) Workspace Metadata: Tenants, seats; (c) Integrations: Encrypted endpoint credentials; (d) Audit Logs: Pseudonymized actor IDs, timestamps, and IP addresses. Raw financial files are never permanently stored.
4. Data Retention & Cryptographic Caching
Digintu operates on a zero-retention storage model. This applies equally to statements and invoices received via automated feeds. Only non-sensitive cryptographic fingerprint hashes (SHA-256) are stored in staging to prevent duplicate processing. Source documents reside natively within your own systems.
5. Information Security & Access Controls
Storage volumes are protected using disk-level LUKS encryption. Data in transit is secured via TLS 1.3. Stored credentials and webhook secrets are encrypted at the application layer using AES-256 GCM. Access controls enforce strict role separation alongside IP CIDR whitelisting, HMAC-SHA256 signatures, and MDC execution tracing.
6. Incident Notification & Liability
Digintu relies on standard server error logs and asynchronous audit routines. In the event of a confirmed breach, controllers will be notified without undue delay. Digintu's total aggregate liability is strictly limited to the total subscription fees paid by the client in the preceding twelve (12) months.
7. Absence of AI Functionality
Digintu operates zero automated machine learning or AI inference models. No customer files, banking records, invoice payloads, or metadata are ever used for artificial intelligence training or model development.
8. Termination & Immutability (GeBüV)
Financial ledgers reside completely in your core ERP or bank archives ensuring GeBüV immutability compliance. For Digintu middleware data, workspace owners can execute an immediate hard deletion directly from their dashboard, instantly purging tenant records.
Verified Sovereign Swiss Infrastructure Compliance
This document serves as Digintu's official compliance declaration. For customized vendor risk assessments, contact pay@digintu.tech.