ConcrITConcrIT

Privacy Policy

How ConcrIT collects, uses, and protects your personal data.

Last updated: June 2026

In brief
  • Your data is hosted exclusively in Switzerland (Infomaniak & AWS Zurich).
  • No data is sold, rented, or shared with third parties for commercial purposes.
  • No tracking cookies, no behavioral analytics tools (Google Analytics or equivalent).
  • No banking data is collected or stored — payments are validated manually.
  • You can exercise your rights (access, deletion, portability) at any time by contacting us by email.

Data Controller

The data controller for personal data collected via concrit.ch is:

ConcrITSole proprietorship under Swiss law
Owner

[First name LAST NAME]

Data protection contact

team@concrit.ch

Address

Rue de Mussel 7 1124 Gollion VD Switzerland

Data Collected

ConcrIT collects the data necessary for the provision and development of the service, grouped into three main categories. ConcrIT reserves the right to collect any additional data made necessary by the evolution of the service, in accordance with this policy.

Account data

Data necessary for the creation, management, and security of the user account, including identification data, professional contact details, and account preferences.

Billing data

Data necessary for invoicing and subscription management, including billing details, payment history, and tax data where applicable. No banking data is collected or stored on our servers.

Project data (business data)

All data created, imported, or generated by the user in the course of using the service, including calculation projects, structural models, design parameters, and associated results. This data remains the property of the user.

Purposes and Legal Basis for Processing

Each processing activity is based on an identified legal basis in accordance with the revFADP (SR 235.1) and GDPR (EU 2016/679):

Performance of a contract

Account management, provision of the calculation service, invoicing and billing. Legal basis: art. 31 para. 2 let. a revFADP / art. 6 §1 b) GDPR.

Legitimate interest

Platform security, abuse prevention, technical support. Legal basis: art. 31 para. 1 revFADP / art. 6 §1 f) GDPR.

Legal obligation

Retention of accounting documents and invoices (art. 958 ff. CO and VATL). Legal basis: art. 31 para. 2 let. c revFADP / art. 6 §1 c) GDPR.

Consent

Marketing communications or newsletters, where applicable. You may withdraw your consent at any time without affecting the lawfulness of prior processing. Legal basis: art. 31 para. 2 let. b revFADP / art. 6 §1 a) GDPR.

Sub-processors and Recipients

ConcrIT does not sell or rent your data to third parties. The following technical service providers access data strictly within the scope of their mission, and are bound by a Data Processing Agreement (DPA). ConcrIT reserves the right to modify its sub-processors at any time, provided that an equivalent level of protection is maintained:

Web hosting and infrastructure

Infomaniak Network SA

Route de Meyrin 267, 1217 Meyrin (Geneva), Switzerland — infomaniak.com

Website and application hosting — servers located in Switzerland.

Database

Supabase Inc. / Amazon Web Services (AWS)

Region eu-central-2, Zurich, Switzerland

Storage of user data and projects — hosted exclusively in Switzerland.

International Data Transfers

User data is stored on servers located in Switzerland (AWS eu-central-2, Zurich), ensuring a level of protection compliant with the revFADP.

Supabase Inc. is a US-incorporated company. Data transfers to the United States are governed by Standard Contractual Clauses (SCCs) in accordance with art. 16 revFADP, ensuring a level of protection equivalent to that guaranteed under Swiss law.

No data is transferred to a country lacking an adequate level of protection without the guarantees required by applicable law.

Retention Periods

Data is retained for the period strictly necessary for each purpose:

Account and project data

Retained for the duration of the active subscription. Following termination or account deletion, data is deleted within a reasonable timeframe, unless a legal retention obligation applies.

Accounting documents and billing

Retained for 10 years in accordance with statutory accounting obligations (art. 962 CO) and VAT prescription periods (VATL).

Logging data (where applicable)

Any logging data collected for security or abuse detection purposes is retained for the strictly necessary period and for no longer than 12 months.

Your Rights

In accordance with the revFADP (SR 235.1) and, for users in the European Economic Area, the GDPR (EU 2016/679), you have the following rights:

Right of access

To obtain confirmation that data concerning you is being processed and to receive a copy thereof (art. 25 revFADP / art. 15 GDPR).

Right to rectification

To have inaccurate or incomplete data concerning you corrected (art. 32 revFADP / art. 16 GDPR).

Right to erasure

To request the deletion of your personal data, subject to statutory retention obligations (art. 32 revFADP / art. 17 GDPR).

Right to data portability

To receive your data in a structured, commonly used, and machine-readable format (art. 28 revFADP / art. 20 GDPR).

Right to restriction

To request the restriction of processing of your data in certain circumstances (art. 18 GDPR — applicable to EU users).

Right to object

To object to the processing of your data based on legitimate interest, in particular for direct marketing purposes (art. 21 GDPR).

To exercise any of these rights, send your request by email to team@concrit.ch stating your identity. ConcrIT undertakes to respond within 30 days.

Cookies and Trackers

ConcrIT uses only cookies strictly necessary for the application to function. No prior consent is required as no non-essential cookies are used:

  • Session cookie: maintains your connection during navigation (deleted when the browser is closed).
  • CSRF token: protection against cross-site request forgery attacks.
  • Language preference: stores your chosen language.

No advertising, profiling, or third-party tracking cookies are deposited. No behavioral analytics tools (Google Analytics or equivalent) are used.

Data Security

ConcrIT implements appropriate technical and organizational measures to protect your data against unauthorized access, loss, destruction, or accidental disclosure, including: encryption of data in transit (TLS 1.2+) and at rest, access control through authentication, regular backups, and access logging. These measures do not constitute an obligation of result.

The user is solely responsible for the data they import, create, or store within the platform, and warrants that such data does not infringe any third-party rights. ConcrIT reserves the right to use aggregated and anonymized data for service improvement purposes, in a form that does not allow identification of any individual user.

In the event of a personal data breach likely to result in a high risk to your rights and freedoms, ConcrIT will use its best efforts to notify you as soon as possible, in accordance with art. 24 revFADP and art. 33-34 GDPR.

Policy Amendments

ConcrIT reserves the right to modify this policy at any time, without prior notice, in particular to adapt to changes in legislation or processing practices. The current version is the one published on the website at the time of consultation. In the event of a major change, ConcrIT will use its best efforts to inform active users.

Contact & Complaints

For any questions regarding this policy or to exercise your rights: team@concrit.ch