PRIVACY

Privacy

Temporary processing, controlled access and auditable deletion.

AT A GLANCE

What data does Switona need, and why?

Your account

Email and authentication information enable protected access. Registration does not grant access to company data.

Your approvals

Company details and mandate evidence support independent verification and document your decision.

Your migration data

Authorized files are processed for the specific switch. Your file retention period is separate from the rules for evidence and accounts.

The approval process, step by step →

Controller and contact

Switona is operated by:

Flaaq Holding GmbH
Großer Kamp 5a
31633 Leese
Germany
Managing director
Christoph Pfad
Contact for privacy requests
security@switona.com

Website visits

Vercel processes technical request information, including IP address, time, requested address and browser details, to deliver and protect the website and diagnose faults. The application server region is Frankfurt; the delivery network and other provider operations may be international. Article 6(1)(f) GDPR may support secure technical operation. The controller must establish the specific interests assessment and log retention.

Accounts and company cases

Registration and use involve email addresses, authentication information, organizations, participants, roles and case information. This includes source, destination, scope, mappings, approvals, status and evidence. Supabase provides authentication, the database and private file storage in Frankfurt. Contract-related processing may rely on Article 6(1)(b) GDPR; company contact processing may, depending on context, rely on legitimate interests under point (f). Company authorization is not blanket GDPR consent from every person whose data is involved.

Authority checks and digital mandates

Processing includes company details, registry or account references, contacts, evidence of authority, uploaded mandates where applicable, and the digital declaration with signer, role, case and timestamps. These serve authority checks, abuse prevention and documentation of the assignment. Sensitive decisions require a second factor. The declaration is not a qualified electronic signature.

Migration data

Authorized source and destination data is read, structured, mapped and validated, then made available as a package or transferred to a configured destination API after explicit approval. The customer must hold the necessary permissions and lawful bases for that content. Where Switona processes personal data on instructions, the assignment and processing terms must comply with Article 28 GDPR. Technical access remains gated by the required company authorizations.

Emails and recipients

Supabase authentication emails and Switona authorization requests are sent through Resend. Processing includes recipient address, message content and delivery information. Company requests include the company, source, destination, authorization stage and a time-limited link. Migration files are not attached. Invitation links should only be shared with their intended participants.

Cookies, fonts and analytics

The application uses cookies needed for sign-in, sessions, language and returning to the intended authorization step. Protected cases cannot be used securely without those functions. Public website language is determined by its URL. Fonts are served with the application. No marketing pixels or external analytics scripts are integrated into the application code. Current migration processing uses no external AI service and does not train models on customer data.

Retention and deletion

Temporary migration files and related processing configurations are cleaned up after completion according to the selected period: immediately, 24 hours, 7 days or 30 days. Cleanup runs regularly and records completion. This does not automatically erase accounts, mandates, security and migration evidence, reusable profiles, active cases or external copies. Separate purposes and retention periods must be established for those categories and provider backups. Statutory obligations and necessary legal defense may prevent immediate erasure of some evidence.

International processing

Vercel, Supabase and Resend are international providers. Even with EU regions configured, processing outside the EEA can occur for delivery, support or subprocessors. The applicable transfer mechanism under Articles 44 onward GDPR depends on provider, recipient and contractual arrangement. Providers publish processing terms including transfer information; their effective incorporation must be checked for the operation.

Your rights

Subject to GDPR conditions, data subjects may request access, correction, erasure, restriction and portability. Processing based on legitimate interests is subject to the right to object under Article 21. Data protection consent may be withdrawn prospectively. You may complain to a data protection supervisory authority. For personal data a customer processes through Switona, that customer is generally the controller and point of contact; Switona assists under the agreed processing terms.

Required information and decisions

Protected functions cannot be provided without the necessary account, company and authority information. The application checks permissions and data quality; authority checks and final company review include human decisions. The described workflow does not involve solely automated decisions about a person with legal or similarly significant effects within Article 22 GDPR.

Updated 29 September 2026. Binding contractual and retention rules are being completed.

Data flows, providers and safeguards