Privacy Policy

Last modified: September 17, 2026

Note: This is a convenience translation. Only the German version of this Privacy Policy is legally binding. In case of any discrepancy, the German version prevails.

This Privacy Policy describes how Haus der Finanzen GmbH, under the Pontora brand, collects, processes and protects personal data. It applies to the Pontora website (pontora.ch), the Pontora platform, and to all user groups: trustees, SME Customers and their employees.

1. Responsible Entity

Responsible for the processing of personal data within the meaning of the Swiss Data Protection Act (revDSG — the revised Swiss Federal Act on Data Protection) and — where applicable — the EU General Data Protection Regulation (DSGVO / GDPR):

CompanyHaus der Finanzen GmbH
Brand / PlatformPontora — pontora.ch
AddressFreiburgstrasse 443, 3018 Bern, Switzerland
UIDCHE-462.314.248
ManagementBesar Rexhepaj
Data protection e-maildatenschutz@pontora.ch
General e-mailinfo@pontora.ch

2. Applicable Law

This Privacy Policy is governed primarily by the revised Swiss Federal Act on Data Protection (revDSG) and the associated Data Protection Ordinance (DSV). Insofar as the EU General Data Protection Regulation (DSGVO / GDPR) applies to individual processing operations (in particular where persons resident in the EU are affected, or where employees of customers operating in the EU are processed), its provisions apply in addition.

3. What Data Is Collected — and For What Purpose?

3.1 When visiting the website pontora.ch

When visiting the public areas of pontora.ch, certain technical information is recorded automatically — as is customary for any website:

  • IP address (truncated / pseudonymised);
  • browser type and browser version;
  • operating system;
  • date and time of access;
  • pages accessed;
  • referrer URL (where the visitor comes from).

This data serves the technical provision of the website, security (protection against misuse) and aggregated statistics. It is not used to identify individual persons and is deleted or anonymised after a maximum of 90 days.

3.2 When using the Pontora platform

When using the platform, the following personal data is processed depending on the user group and module:

a) Trustee Customers

  • identification and contact data of the trustee (name, company name, e-mail, telephone, UID);
  • login and usage data (time of login, IP address, clients supervised);
  • communication with the Provider (support requests, tickets).

b) SME Customers

  • company master data (company, address, UID, industry, number of employees);
  • contact data of the contracting parties and administrators;
  • contract and billing data (subscription, payment information);
  • login and usage data.

c) Employees of SME Customers

  • personnel master data: first name, surname, date of birth, AHV number (Swiss social security number), marital status, address, contact data, photo;
  • employment data: function, workload, start/end date, employment contracts, letters of termination, employment references;
  • bank details for salary payment;
  • salary and remuneration data, social insurance deductions;
  • working time data, breaks, absences, holidays, overtime;
  • sick notes and medical certificates (sensitive personal data);
  • accident reports and accident records (sensitive personal data);
  • uploaded documents (identity card/passport, residence permit, diplomas, further personnel-related documents).

d) Suppliers and creditors of the SME Customer

  • company name, address, contact;
  • invoice data and contents;
  • bank details for payments;
  • supporting documents (receipts, invoices, cash receipt images).

3.3 Who is the controller under data protection law?

With regard to the personal data that an SME Customer enters into the platform — in particular the data of its employees, suppliers and creditors — the SME Customer acts as the controller under data protection law. The Provider (Pontora / Haus der Finanzen GmbH) processes this data exclusively on behalf of the SME Customer on the basis of the Data Processing Agreement (DPA).

For the data directly related to the contractual relationship between the Provider and its Trustee Customers or SME Customers (e.g. account and billing data), the Provider is itself the controller.

The Provider processes personal data for the following purposes:

  • provision, operation and further development of the Pontora platform;
  • administration of user accounts, permissions and client structures (multi-tenant administration);
  • provision of the OCR-supported receipt recognition (cash book, creditors) — see section 5;
  • technical support and troubleshooting;
  • billing and contract administration;
  • compliance with legal obligations (in particular retention obligations under Art. 958f OR — Swiss Code of Obligations — and Art. 70 MWSTG — Swiss VAT Act);
  • ensuring secure operation (detection of security incidents, prevention of misuse);
  • information about product updates and service notifications to existing customers;
  • anonymised statistical analyses for product improvement.

The legal bases are in particular:

  • performance of contract (usage agreement) — for the provision and billing of the platform;
  • legitimate interest — for ensuring operation, security and further development;
  • legal obligation — for compliance with the retention obligations;
  • consent — for the activation of optional AI functions, insofar as the SME Customer decides so by opt-in.

5. AI-Supported Processing (OCR and Receipt Recognition)

5.1 The platform offers optional, AI-supported functions for the automatic recognition of receipt contents — in particular for the digital cash book and creditor receipt management. These functions are technically implemented via the “Claude” interface (API) of Anthropic, PBC, San Francisco/USA.

5.2 What happens: When a receipt is uploaded to the platform, the receipt image or PDF is transmitted to the Claude API. Claude returns a structured recognition of the contents (e.g. date, supplier, amount, VAT). The return value is proposed within the platform; the definitive booking is made by the user.

5.3 Data protection aspects:

  • the transmission to Anthropic in the USA is encrypted (TLS) and takes place on the basis of the Standard Contractual Clauses (SCC) of the EU Commission or of the EDÖB (the Swiss Federal Data Protection and Information Commissioner);
  • Anthropic is contractually obliged to use the transmitted data exclusively for receipt recognition and not for training AI models (“no training on customer data”);
  • receipt data is not permanently stored at Anthropic (in accordance with the current Anthropic API policy);
  • the AI function is deactivated by default and must be actively enabled by the SME Customer (opt-in).

5.4 No automated individual decision-making: The AI-supported recognition does not produce legal effects or significantly adverse effects for data subjects. It merely serves as a proposal; the final booking decision is always taken by a human (an employee of the SME Customer or its trustee). The conditions of an automated individual decision within the meaning of Art. 21 revDSG are therefore not met.

6. Data Exchange Between the User Groups

6.1 SME ↔ Trustee: An SME Customer may grant its trustee access to the platform. By activating trustee access, the SME Customer declares its consent that the Provider enables the corresponding data access for the trustee. The scope of access is governed by the permission concept of the platform; the SME Customer retains control and may restrict or withdraw access at any time.

6.2 SME → Employees: Employees of the SME Customer receive their own login and can access the functions released for them (self-service during onboarding, time recording, sickness/accident reporting). The data access of employees is limited to their own data.

6.3 Within the platform: No data transfer takes place between different SME Customers. The multi-tenant architecture technically isolates the data of the individual tenants from one another.

7. Disclosure of Personal Data to Third Parties

Personal data is disclosed to third parties only in the following cases:

7.1 Sub-processors (processors)

The Provider engages carefully selected sub-processors who are contractually bound to the same level of data protection:

Sub-processorPurposeLocationData location
Amazon Web Services (AWS)Cloud hosting, data storage, computeLuxembourg / EUZurich, CH (eu-central-2)
Supabase Inc.Database platform, authentication, file storageUSAZurich, CH (on AWS)
Anthropic, PBCAI-supported OCR recognition of receipts (“Claude” API) — only where AI functions are activatedUSAUSA (with SCC protection)
Vercel Inc.Hosting of the public marketing websiteUSAEU (Frankfurt)
Cloudflare Inc.CDN, DDoS protection, DNSUSAGlobal edge network
EnacTon Infotech LLPSoftware development — NO access to productive personal dataIndiaDevelopment/test data only

International data transfer: In the case of sub-processors domiciled in the USA (Anthropic, Supabase Inc., Vercel, Cloudflare), the data transfer takes place — insofar as productive personal data is affected at all — on the basis of the Standard Contractual Clauses (SCC) of the EU Commission or of the EDÖB. The Provider ensures an adequate level of protection through supplementary technical measures (encryption, access restriction, data minimisation).

The Provider discloses personal data to authorities or courts insofar as this is required by law or necessary for the establishment, exercise or defence of legal claims.

7.3 No disclosure for third-party marketing purposes

The Provider does not disclose personal data for marketing purposes or for commercial purposes of third parties. No data exchange takes place with affiliated companies or advertising networks.

8. Cookies and Tracking

8.1 Pontora platform (logged-in area)

In the authenticated area of the platform, only technically necessary cookies and comparable technologies (local storage, session storage) are used. These serve to ensure login, session management and basic functionality. They cannot be deactivated without making use of the platform impossible.

8.2 Marketing website pontora.ch

On the public marketing website, the following categories of cookies are used — insofar as the Provider activates them:

  • technically necessary cookies (session, security) — no consent required;
  • statistics cookies for anonymised reach measurement — only with consent;
  • functional cookies (e.g. for storing the selected language) — only with consent.

On the first visit to the marketing website, the user is informed about the cookies used by means of a cookie banner and can make their selection. The selection can be adjusted at any time via the “Cookie settings” link in the footer.

No third-party advertising or tracking cookies: The Provider does not use advertising cookies, no Google Analytics, no Facebook pixel and no comparable third-party tracking tools.

9. Retention Periods

The Provider stores personal data for as long as is necessary for the fulfilment of the contractual and legal obligations:

Data categoryRetention period
Contract data / master dataDuration of the business relationship + 10 years (Art. 958f OR)
Employee dataDuration of the employment relationship + 10 years, insofar as required by law
Salary and social insurance data10 years (Art. 958f OR, social insurance law)
Cash book and receipt data10 years (Art. 958f OR, Art. 70 MWSTG)
Log files / audit logsMaximum 12 months
Server access logs (web server)Maximum 90 days, thereafter anonymised or deleted
Data after contract end30-day right to retrieval, thereafter deletion — except for statutory retention

10. Data Security

The Provider protects personal data by means of appropriate technical and organisational measures (TOM) in line with the current state of the art. The most important measures:

  • all productive personal data is stored exclusively on AWS in Zurich (Switzerland);
  • encrypted data transmission (TLS 1.2 or higher);
  • encryption of data at rest (AES-256);
  • role-based permission concept applying the principle of least privilege;
  • mandatory two-factor authentication for administrative accounts;
  • deactivation by default of super-administrator access to productive customer data;
  • multi-tenant isolation at database level;
  • daily automated backups;
  • strict separation of development, staging and production environments;
  • regular training of employees on data protection and data security.

A complete description of the TOM can be found in Annex B of the Data Processing Agreement. However, complete security of data transmission over the internet cannot be guaranteed — as is the case with any online service.

11. Sensitive Personal Data

Within the scope of the HR and personnel functions, the platform processes sensitive personal data within the meaning of Art. 5 lit. c revDSG, in particular:

  • health data (sick notes, medical certificates, accident reports);
  • data on social assistance or on administrative or criminal proceedings and sanctions, insofar as such data is recorded in the platform by the SME Customer (e.g. wage garnishments).

This data is treated with particular care, protected by additional permission restrictions and made accessible exclusively to the persons expressly authorised by the SME Customer. Responsibility for the lawful collection and for informing the data subjects lies with the respective SME Customer.

12. Rights of Data Subjects

Every data subject has the following rights under revDSG (and additionally under DSGVO / GDPR, where applicable):

  • right of access (Art. 25 revDSG): information about the processing of their own personal data;
  • right to rectification: correction of inaccurate data;
  • right to erasure: insofar as no statutory retention obligation exists;
  • right to restriction: restriction of further processing;
  • data portability: release of the data in a common, machine-readable format;
  • right to object: objection to the processing on legitimate grounds.

Employees of SME Customers should address their requests primarily to their employer (the SME Customer), which is the controller under data protection law for the processing of their data. Requests addressed to the Provider are forwarded to the controller.

Requests can be submitted in writing to datenschutz@pontora.ch. Proof of identity may be requested in order to verify identity.

Right to lodge a complaint: Every data subject has the right to lodge a complaint with the competent data protection authority. In Switzerland this is the Federal Data Protection and Information Commissioner (EDÖB), www.edoeb.admin.ch.

13. Minors

The Pontora platform is aimed at companies and their employees. Insofar as an SME Customer employs apprentices or interns under the age of 16 and records their data in the platform, the SME Customer is responsible for compliance with the special requirements for the processing of minors’ data (in particular the involvement of legal representatives). The Provider itself does not collect personal data directly from minors.

14. Amendments to This Privacy Policy

The Provider may amend this Privacy Policy if and insofar as its processing practices change or legal requirements so demand. The version applicable at any given time is available at pontora.ch. In the event of material changes, registered users will be informed by e-mail or by in-app notification.


Pontora · a product of Haus der Finanzen GmbH · datenschutz@pontora.ch · pontora.ch · Version 1.0 · 5 May 2026

cta-image

Secure Your Operations with Pontora

Allows you to streamline company settings, locations, timesheets, tasks, documents, and trustee approvals from a single dashboard.