Legal

Privacy Policy

How Gottshalden handles personal data across our website, our client portal and our product, SwissAML. We keep what we collect to a minimum, use it only for the purposes described here, and never sell it.

Last updated: 20 June 2026

Who is responsible

Gottshalden GmbH (‘Gottshalden’, ‘we’, ‘us’), Sinserstrasse 67, 6330 Cham, Switzerland, is the controller for the personal data described in this policy. For any question about this policy or your data, contact servicedesk@gottshalden.ch.

One important boundary: your clients’ data

SwissAML is used by regulated professionals — law firms, fiduciaries, trust companies and other financial intermediaries — to carry out anti-money-laundering checks. When you use SwissAML, you upload data about your own clients. That data remains yours. You are its controller and the party bound by professional secrecy over it; we only process it on your instructions, as your processor. How we handle it is governed by the Data Processing Agreement and the client professional-secrecy notice you accept with your subscription — not by this policy. This policy covers the data we hold as controller: the data about you and your firm’s users, and the data of visitors to our website. Nothing here gives us any control over your clients’ data.

What we collect, and why

We keep data collection to a minimum and collect only what the purposes below require.

When you visit our website

Server logs

Our hosting provider records standard technical data for each request — your IP address, the time, the page requested and your browser type — which is necessary to operate and secure the site.

Enquiries

If you contact us through the enquiry form or by email, we process the name, email address and message you provide, to respond to you.

Waitlist

If you ask to be notified when a product becomes available, we store your email address for that single purpose.

When you sign up and use the product

Account and identity

Your work email and name, your firm and role, your chosen language, and (if you provide them) your telephone and postal address. You sign up and manage your profile through our client portal; accounts run on Microsoft Entra External ID, on a self-service basis — you sign in by receiving a one-time log-on code by email from Microsoft, and we hold no password of yours. You then sign in to SwissAML from the same account.

Billing

When you subscribe, we collect the billing details needed to set up and run your subscription. Card payments are handled by our payment providers; how payment data is processed is covered in our billing terms.

Security log

A record of account events — sign-in, sign-out and registration — each with the time, IP address and browser, used for account security and an access trail. You can view your own log in the product.

We collect only what these purposes require. We do not build a profile of you and we do not use your data for advertising.

Cookies, analytics and local storage

This website and product set no advertising or tracking cookies, and run no cross-site tracking. Our website analytics (Plausible) is cookieless, stores no personal data, creates no persistent identifier, and is hosted in the European Union. In the product, we use a strictly-necessary login cookie (which JavaScript cannot read) and a small amount of local storage for your language and layout preferences and to record a choice you have made inside the application. Because we set no non-essential cookies, no cookie-consent banner is shown. Our website forms are protected by Cloudflare Turnstile, which checks that a submission comes from a person rather than a script, using technical signals such as your IP address and no tracking cookies.

Emails we send

We use your email address to send: authentication — the one-time log-on code, sent by Microsoft, which is needed to sign in; service messages — for example a welcome and how-to-get-started message, a reminder before a trial ends, and billing notices, which are part of operating the service; and product news — only if you have opted in, and you can stop these at any time. We keep authentication and service messages to what running the service requires, and treat product news as separate and consent-based.

Who else processes your data

We use a small number of providers, each acting on our instructions. Microsoft acts as our host (the service and its data run on Microsoft Azure in Switzerland), our identity provider (Microsoft Entra, which manages sign-in and sends the log-on-code emails), and to send our service and product-news emails (through Microsoft 365). Plausible (cookieless website analytics, European Union) and Cloudflare (bot protection on our forms) handle only limited technical data and build no profile of you. The providers that handle your clients’ data (our host’s document-recognition service and our screening provider) are named and bound in the Data Processing Agreement; our billing and payment providers process your firm’s account and billing data — not your clients’ data — and are not part of that agreement.

Where your data is held, and transfers abroad

The service and its stored data are hosted on Microsoft Azure in Switzerland. Some identity and communications data — chiefly your email address and sign-in identifiers — may be processed outside Switzerland by Microsoft, and our bot-protection provider may process technical data such as an IP address abroad, including in the United States. Where data is processed abroad, the transfer is covered by appropriate safeguards, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, and the providers’ own data-processing terms.

How long we keep it

We keep personal data no longer than necessary. Account and profile data is kept while your account is open and for a limited period afterwards; the security log for a defined operational period; enquiries for as long as needed to handle them; waitlist addresses until the notification is sent or you unsubscribe; server logs for a short period. The handling and deletion of your clients’ data, and of trial data, is governed by the Data Processing Agreement and the trial terms, not by this policy.

Your rights

For the data we hold about you, you may access it, have it corrected or deleted, object to or restrict its processing, and receive it in a portable form. To exercise any of these, contact us at servicedesk@gottshalden.ch; we respond free of charge and within the statutory period. You may also complain to the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or, in the EEA, to your local data-protection authority. A request about your clients’ data (the data your firm uploads) is handled by your firm as that data’s controller — we support your firm but do not answer those requests ourselves.

How we protect it

We take technical and organisational measures appropriate to the risk, including isolating each firm’s data from every other firm’s and encrypting sensitive fields at rest.

Legal basis

We process this data under Swiss data-protection law (the revised Federal Act on Data Protection). Product news is sent on the basis of your consent, which you may withdraw at any time. If your firm is established in the European Economic Area, the GDPR applies in parallel, on the bases of performing our contract with you, our legitimate interest in securing the service, and your consent for product news.

Changes to this policy

We may update this policy as our service or the law changes. The current version is always available here, with the date of the last update shown above; we will notify you of material changes.

Contact

For any question about this policy or your personal data, write to servicedesk@gottshalden.ch.