Swiss data protection law
The revised Federal Act on Data Protection (nDSG) has applied since 1 September 2023. For each solution, we document which personal data it processes, why it is needed, and where it is processed and stored.
You decide where your data is stored, who can read it and which decisions stay with people. We build every solution around those decisions.
Sovereign AI means AI systems whose data, models and operation stay under the control of the company that uses them, inside the legal framework of its own country. For a Swiss company, that covers three questions:
The AI models run in Swiss data centers operated by us or by certified Swiss partners, or on your own infrastructure. If a model is trained or fine-tuned on your data, that happens only with your written consent, and the model stays in Switzerland under your control. Data is encrypted in transit and at rest.
The revised Federal Act on Data Protection (nDSG) has applied since 1 September 2023. For each solution, we document which personal data it processes, why it is needed, and where it is processed and stored.
Doctors, lawyers and notaries are bound by professional secrecy under the Swiss Criminal Code. Keeping data in a controlled Swiss environment, with access limited to approved people, is the basis for using AI under that duty. We sign a confidentiality agreement and a data processing agreement before we see any data.
If you sell into the EU, the EU AI Act can apply to AI systems whose results are used there. We document each solution so you can show what it does and who oversees it.
You decide which results need approval and by whom.
We build on open-source technology and document every solution. You are never tied to a single model or hosting provider.
For administrative work such as reading documents, extracting data and drafting text, models hosted in Switzerland perform well. We test the quality on your own data in the Detailed Design, before you commit.
No. It requires safeguards for transfers abroad. Many companies prefer to avoid the transfer entirely, especially those bound by professional secrecy.
Yes, if your infrastructure meets the requirements. We check this in the Detailed Design.