APPROVALS & MANDATE

Your company decides. For every switch.

Who reviews, who signs and when data access is granted: the complete process, clearly explained.

CLEAR RESPONSIBILITIES. EXPLICIT APPROVALS.

You stay in control of your data.

An account lets you get started. It does not automatically grant access to company data. Every switch follows the same protected process.

No approval, no data access. No second approval, no transfer.
  1. Responsible: You

    Create an account & describe the switch

    Verify your email, enter your company and choose the source, destination and data you need. Do not upload customer files yet.

    Case details only
  2. Responsible: Switona

    Independently verify the company

    We check the company, representative, contact and ownership of the source provider account. A self-declared email address alone is not sufficient.

    Data access locked
  3. Responsible: Company representative

    Sign the digital mandate

    The verified person receives an email, even without a Switona account. They sign in with that address, verify a second factor and decide on the exact request.

    No transfer yet
  4. Responsible: Switona

    Complete the final review

    We review the submitted declaration again. Data preparation is unlocked only after approval. Our reviews usually take 1–2 business days, plus the company’s response time.

    Preparation unlocked
  5. Responsible: Technical participants

    Prepare data & check the test run

    Supply authorized exports or REST connections, match fields and resolve errors. Costs and the paying party are explicitly confirmed before starting.

    Test without destination transfer
  6. Responsible: Company & authorized operator

    Approve this specific transfer

    The company separately approves the prepared transfer. Authorized participants can then approve the start. Results and temporary-file deletion are recorded.

    Authorized scope only

What does this mean for me?

I represent the company moving its data.

Describe your switch and select its scope. The verified company representative provides the approvals. Authorized providers or partners can handle technical tasks.

I am a provider or migration partner.

You can prepare a case and perform your assigned tasks. You cannot appoint yourself as the affected company’s representative. Paying for the switch does not replace company authorization.

I received an approval email.

Open your personal link. Use the exact recipient email and review the company, scope, destination and participants. You can decline. Opening the link grants no permission.

What if the request changes or consent is revoked?

Material changes invalidate prior approvals. Revocation blocks further actions that require authorization. It cannot recall data already transferred to a destination.

Do I need to configure the technology myself?

No. Your IT team or an authorized provider can prepare files and connections. Reusable connections save setup time, while each switch still requires its own approvals.

Is the mandate GDPR consent?

No. It records authorization from the company. Personal data also requires a lawful basis, information to data subjects, processing terms and deletion rules. The digital declaration is not a qualified electronic signature.

Your next environment shouldn’t be decided by your old data.

Choose where you go next. We'll help your data get there.