Privacy policy
Last updated: 29 June 2026
This policy describes how CreativMinds Sàrl (“CyberPassport”) processes personal data, in accordance with the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the General Data Protection Regulation (GDPR).
Data controller
The data controller is CreativMinds Sàrl, Rue de la Gare 1, 1260 Nyon (Switzerland). For any data protection question: contact@cyberpassport.ch.
Personal data collected
We process: account data (name, e-mail address, encrypted password), organisation data (legal name, IDE number, sector), self-assessment questionnaire answers and associated comments, the evidence you upload, billing data (processed by our payment provider), and technical logs (IP address, timestamps, security events).
Purposes and legal bases
Your data is processed to provide and maintain the service (contract performance), manage billing and subscriptions (contract performance), ensure platform security and prevent abuse (legitimate interest), and provide support (contract performance). No data is sold to third parties.
Processors and recipients
Only the data necessary for their service is accessed by: Infomaniak Network SA (hosting, Switzerland), Resend (transactional e-mail), Stripe (payments), and our artificial intelligence provider for report generation. If you choose to sign in with a Google or Microsoft account, Google Ireland Limited or Microsoft Ireland Operations Limited is also involved, solely for authentication: these providers pass us your account identifier, your name and your e-mail address, and receive none of your assessment data from us. You may use an e-mail address and password instead at any time. One organisation's data is never shared with another.
Hosting and data transfers
The database and files (evidence, logos) are hosted in Switzerland, at Infomaniak. Transactional e-mails are routed through a provider located in the European Union (Ireland), which offers an adequate level of protection. Payments are processed by Stripe on the basis of appropriate contractual safeguards. If you use Google or Microsoft sign-in, the authentication exchange takes place with those providers, whose contracting entities are established in Ireland; it covers your sign-in identity only. No assessment data, no document from your evidence vault and no report leaves Switzerland as a result.
Retention period
Account and assessment data is kept for the duration of the subscription, then deleted within 6 months of account closure. Evidence is kept until deleted by your organisation. Billing data is kept for 10 years in accordance with Swiss accounting law. Technical logs are kept for up to 12 months.
Data security
Sensitive data is encrypted at rest (per-tenant encryption, AES-256-GCM) and in transit (TLS). Each organisation is strictly isolated from the others, and access is restricted and logged.
Your rights
You have the right to access, rectify, erase, restrict, object to and port your data. You can exercise these rights at any time by writing to contact@cyberpassport.ch.
Cookies and trackers
CyberPassport only uses cookies strictly necessary for the operation of the service (session and authentication). No advertising cookies or third-party trackers are used.
Contact and complaints
For any question regarding your data: contact@cyberpassport.ch. You also have the right to refer the matter to the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.