Skip to content
Data protection

Privacy policy.

This policy explains what personal data we collect, why, for how long, and what rights you have under the Swiss Federal Act on Data Protection (FADP). It is written to be read, not skimmed past.

Applies to
FADP
Retention (audit)
10 yr
Rights response
30 days
Cross-border transfer
None*
Last updated: 25 August 2026Document version 4.1
Demonstration content

MediVault AG is a fictional company built for a portfolio / demo website. This page is illustrative template content only — it is not real legal advice, it has not been reviewed by counsel, and it creates no actual rights or obligations. Do not rely on it for an actual product, business or legal decision.

A hand completing a printed form with a pen.
Intake, consent, the paper trail
Illustrative only — this photograph does not depict an actual patient record or consent form.

Two very different roles,
and we hold both.

This is the single most important distinction on this page. Read it before anything else.

1.1

We are the controller — for you

If you visit medivaultzurich.site, request a demo, sign up for a sales call, or hold a MediVault staff or administrator account, MediVault AG is the controller of that personal data. We decide why and how it is processed, and this policy governs it in full.

1.2

We are the processor — for patient data

If you are a patient, or a clinician entering patient data, your data is processed inside the MediVault platform on behalf of a healthcare provider — a clinic, hospital or network — that is our customer. That customer is the controller of your medical data. MediVault is the processor, bound by a data processing agreement (see our AVV / DPA) that lets us act only on that customer's documented instructions.

If you have a question about your medical record, the correct first contact is your healthcare provider, not MediVault. We will route any request we receive directly to the responsible controller and tell you we have done so.

Who is
accountable.

Controller
MediVault AG, Handelsregisteramt des Kantons Zürich, CH-020.3.048.912-4
Data Protection Officer
Dr. Anne-Sophie Reber, Group Data Protection Officer — dpo@medivaultzurich.site
EU representative (Art. 27 GDPR)
MediVault Europe Vertretung GmbH, Maximilianstrasse 13, 80539 München, Germany
Supervisory authority
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), Feldeggweg 1, 3003 Bern
Applicable law
Swiss Federal Act on Data Protection (FADP / nDSG), in force since 1 September 2023

Three categories,
three different bases.

3.1

Website visitors

IP address (truncated and stored for 30 days for abuse prevention, then deleted), pages viewed, referrer, browser and device type, and — only with consent — analytics identifiers. Contact-form submissions (name, work email, company, message) are kept for 24 months or until you ask us to delete them, whichever is sooner.

Legal basis — legitimate interest in operating and securing the site (Art. 31 FADP), and consent for optional analytics.

3.2

Platform users (clinicians, administrators)

Name, work email, institutional affiliation, role, authentication factors (hashed passwords, FIDO2 public keys, TOTP seeds — never recoverable by us), session metadata and every access event tied to your identity. Account data is retained for the life of the contract plus 90 days; audit-log entries referencing your identity are retained for the audit period agreed with the customer (typically 1–7 years, per plan).

Legal basis — performance of the contract between MediVault and your employer, and our legitimate interest in platform security and non-repudiable audit records.

3.3

Patient data (processed, not controlled, by us)

Medical records, clinical documents, diagnostic reports, imaging metadata, laboratory results, referrals, treatment records, consent forms and insurance documentation, as configured by the controlling healthcare provider. MediVault does not decide what is stored, who a patient is, or how long records are retained — those are the controller's decisions, implemented through platform configuration and retention policy.

Legal basis — determined and documented by the controller (typically treatment necessity, consent, or a legal retention obligation under cantonal medical law). MediVault processes only under instruction, per our data processing agreement.

Who else
sees it.

Sub-processors
A published list of infrastructure and operational vendors that may process data on our behalf, each bound by a data processing agreement. See the sub-processor register for names, purpose and location.
Cross-border transfer — patient data
None. Patient data remains on Swiss soil, in Swiss-operated data centres, at rest and in processing, at all times.
Cross-border transfer — website / account data
Limited to email delivery and error-monitoring vendors under standard contractual clauses recognised by the FADP, where a service has no Swiss-only option. See the sub-processor register.
Legal disclosure
Disclosed to Swiss authorities only where legally compelled, and — where legally permitted — we notify the affected controller or data subject first.
Never disclosed for
Marketing, advertising, data brokering, or any form of resale. We do not operate an advertising business.

How it is
protected.

Full detail lives on our security page. In summary: encryption at rest and in transit, strict internal access controls, and independent audits.

Encryption at rest
AES-256-GCM envelope encryption, HSM-backed key hierarchy, per-tenant key roots
Encryption in transit
TLS 1.3 only, HSTS preloaded
Internal access
No standing employee access to customer data; every access is ticketed, time-boxed and logged
Independent verification
SOC 2 Type II, ISO 27001, ISO 27701 — see the compliance centre

What you can
ask us to do.

Under Art. 25–29 FADP, anyone whose data we control (website visitors, account holders) has the following rights. Patients should first approach their healthcare provider, who will involve us as needed.

Access (Art. 25)
Confirmation of whether we process your data, and a copy of it, free of charge for the first request each year.
Rectification
Correction of inaccurate personal data without undue delay.
Deletion / restriction (Art. 26)
Deletion where retention is no longer justified, or restriction of processing while a dispute is resolved.
Objection (Art. 30–31)
Objection to processing based on legitimate interest, including profiling, on grounds relating to your situation.
Data portability (Art. 28)
A structured, commonly used, machine-readable copy of data you provided to us, where technically feasible.
Withdraw consent
Where processing is based on consent, you may withdraw it at any time with effect for the future.
How to exercise
Email dpo@medivaultzurich.site. Statutory response within 30 days.
Complaints
You may lodge a complaint with the Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), Feldeggweg 1, 3003 Bern.

This policy
will change over time.

7.1

Notice of changes

We update this policy as our processing activities, sub-processors or legal obligations change. Material changes are announced at least 30 days in advance by email to registered account holders and by a notice on this page. The document version and last-updated date at the top of this page always reflect the current text.

7.2

Prior versions

A record of prior versions is retained internally and is available on request to the Data Protection Officer for compliance and audit purposes.

Data protection

Questions about
your data?

Our Data Protection Officer answers FADP requests, DPA questions and records-of-processing enquiries directly — no ticket queue.

Statutory response within 30 days · EDÖB, Feldeggweg 1, 3003 Bern