Privacy and data protection

Privacy Policy

This Privacy Policy explains how Cyberlocker Switzerland S.A., operating the SwissHosting service, collects, uses, protects, retains, and discloses personal data and service-related information.

Controller: Cyberlocker Switzerland S.A. Applies to SwissHosting services Last updated: August 6, 2026

1. Who controls your personal data

Cyberlocker Switzerland S.A. is the controller responsible for personal data processed in connection with SwissHosting orders, accounts, support, billing, website use, and service administration.

Complete before publishing: add the company’s registered address, privacy contact email, and any appointed data-protection representative or advisor.

2. Information we collect

We may collect information that you provide when requesting information, placing an order, opening an account, paying an invoice, contacting support, or otherwise using our services.

Identity and account dataName, company name, account identifiers, and authentication-related information.
Contact dataEmail address, mailing address, telephone number, and support contact details.
Order and billing dataServices ordered, invoices, payment status, transaction references, and billing communications.
Support and correspondenceMessages, tickets, troubleshooting details, abuse reports, and service-related communications.
Website and device dataIP address, browser type, device information, referring pages, timestamps, and security events where collected.
Compliance dataInformation reasonably required to investigate fraud, abuse, unauthorized access, or violations of applicable policies.

3. Service and infrastructure data

As an infrastructure provider, we may technically process or host information controlled by customers. Depending on the service and customer configuration, this can include:

  • Server content, files, applications, and backups;
  • Databases and storage volumes;
  • Electronic mail and related metadata;
  • Storage area network files;
  • VPN, network, authentication, or access records generated by configured systems;
  • Logs created by servers, security systems, support tools, or network equipment;
  • Any other information uploaded, stored, transmitted, or automatically generated through a customer’s service.

Customers remain responsible for the content they place on their services and for configuring their systems, applications, logging, user permissions, and retention settings. We do not use customer-hosted content for advertising or unrelated profiling.

4. How we use information

  • Process orders, activate services, maintain accounts, and administer invoices;
  • Provide technical support, troubleshooting, maintenance, and network operations;
  • Communicate about service availability, security, billing, policy, or abuse matters;
  • Protect accounts, systems, customers, networks, and infrastructure against fraud, intrusion, misuse, and operational threats;
  • Enforce our Terms of Service and Acceptable Use Policy;
  • Meet applicable legal, regulatory, accounting, and recordkeeping requirements;
  • Improve service reliability, capacity planning, and operational performance using appropriately limited technical data.

Customer-hosted content and service logs are accessed only when reasonably necessary for service delivery, security, troubleshooting, abuse investigation, policy enforcement, or compliance with a valid legal obligation.

6. How we protect information

We use technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, disclosure, or destruction. Measures may include:

  • Encrypted transmission using TLS/SSL where supported;
  • Encryption or secure hashing for selected sensitive data at rest;
  • Role-based and need-to-know access restrictions;
  • Authentication, access logging, monitoring, and network security controls;
  • Confidentiality obligations for personnel and contractors;
  • Incident response, backup, recovery, and operational security procedures.

No internet service or storage system can be guaranteed completely secure. Customers should maintain secure credentials, current software, backups, and appropriate access controls for their own systems.

7. Data retention

We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including service administration, security, dispute resolution, accounting, legal compliance, and enforcement of agreements.

  • Active-account data: generally retained while the account or service remains active.
  • Cancelled-service content: scheduled for deletion according to the service termination process and backup lifecycle.
  • Account and billing records: may be retained longer where required for accounting, tax, fraud prevention, legal claims, or regulatory obligations.
  • Security and abuse records: retained only as long as reasonably necessary for investigation, prevention, or legal defense.

Where operationally feasible and no longer subject to a legal or security hold, customer service data is targeted for deletion within 30 days after cancellation. Residual copies may remain temporarily in backups until they rotate out under the applicable backup schedule.

8. When information may be disclosed

We do not sell personal data. We may disclose limited information only where necessary to:

  • Authorized employees and contractors who require access for their duties and are bound by confidentiality obligations;
  • Payment, banking, fraud-prevention, communications, security, or infrastructure providers used to deliver the service;
  • Professional advisers such as lawyers, auditors, or insurers where reasonably necessary;
  • A successor entity in connection with a merger, restructuring, financing, or sale, subject to appropriate confidentiality protections;
  • Competent authorities where disclosure is required by applicable law or a legally binding order.

Service providers are expected to process information only for the contracted purpose and to apply appropriate confidentiality and security safeguards.

9. Legal requests and authorities

Cyberlocker Switzerland S.A. reviews legal demands for customer information and responds only where it reasonably determines that disclosure is legally required and the requesting authority has appropriate jurisdiction and authority.

Where legally permitted and operationally appropriate, we may notify the affected customer before disclosure. We may preserve or restrict data when required by a valid preservation request, court order, or other binding legal obligation.

Important: the previous “Public Debate Clause” has been removed. Publishing customer information merely because a customer posts a review or criticism would create serious privacy, trust, and legal risk.

10. International processing and service providers

Some support, payment, communications, security, or technical providers may process limited data outside Switzerland. Where this occurs, we use appropriate contractual, organizational, or legal safeguards as required by applicable data-protection law.

Customer-selected network destinations, remote users, domain providers, payment networks, and third-party software may also cause data to be transmitted internationally under the customer’s direction.

11. Your privacy rights

Subject to applicable law and any lawful limitations, you may request:

  • Confirmation of whether we process personal data about you;
  • Access to relevant personal data and information about its processing;
  • Correction of inaccurate or incomplete information;
  • Deletion or restriction of processing where legally available;
  • Withdrawal of consent for future processing where consent is the basis used;
  • Information about recipients, retention, source, or international disclosures where applicable.

We may need to verify identity before responding. Requests may be limited where necessary to protect other persons, confidential information, security, legal claims, or overriding lawful interests.

12. Cookies, analytics, and website technologies

Our website may use essential cookies and similar technologies for security, sessions, preferences, forms, fraud prevention, and website functionality. Analytics or non-essential technologies should be described in a separate cookie notice or consent interface where required.

Browser settings may allow you to block or delete cookies, although some website or account features may then function incorrectly.

13. Changes to this policy

We may update this Privacy Policy to reflect legal, operational, technical, or service changes. The revised version will be posted on the SwissHosting website with a new “Last updated” date. Material changes may also be communicated through account notices, email, or relevant service pages where appropriate.

14. Privacy contact

Questions, access requests, correction requests, or privacy complaints should be sent to the designated privacy contact for Cyberlocker Switzerland S.A.

Privacy email: [INSERT PRIVACY EMAIL]
Registered address: [INSERT REGISTERED COMPANY ADDRESS]
Company: Cyberlocker Switzerland S.A.

Contact SwissHosting

This template should be reviewed by qualified Swiss legal counsel before publication, especially the controller details, processor relationships, retention periods, international transfers, cookies, and legal-request procedures.

You May Also Be Interested