Protecting your data is central to Pal Tech AG. In line with the Swiss Federal Act on Data Protection (revFADP) and the EU GDPR, this policy explains the nature, scope and purpose of how we process data.
1. Controller
The controller is Pal Tech AG, Zurich, Switzerland (see Legal Notice). Please direct privacy enquiries to the contact address stated there.
2. Data processed and purposes
We process master data (name, email, company), communication data (enquiries, project notes), contract and payment data, and usage data. Processing takes place to perform contracts, provide solutions, training and memberships, support customers and meet legal obligations.
Payments are handled by our payment provider; we do not store card data.
3. Cookies and local storage
We use technically necessary cookies and local storage, for example for sign-in, language and interface theme. You can delete or block cookies in your browser at any time; some features may then become unavailable.
4. Authentication logging in the Control Room
Sign-ins, roles and access within the protected Control Room (admin area) are logged to prevent misuse and ensure traceability, including time, user identifier and security-relevant actions. Logs are used only for security, audit and support purposes by authorised personnel.
5. Protection of SAP integration data
Data from connections to customer SAP systems is protected using state-of-the-art measures: encryption in transit (TLS) and at rest, strict role and access concepts based on need-to-know, tenant separation and regular review of security controls. Credentials and system information are never shared with third parties and are used only within the agreed engagement.
6. Disclosure and processors
Data is shared only with carefully selected providers (hosting, payment processing, email delivery) who are contractually bound to data protection. For transfers to countries without adequate data protection we ensure appropriate safeguards, such as standard contractual clauses.
7. Retention
We keep personal data only as long as needed for the relevant purpose or as required by statutory retention obligations.
8. Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection, and to withdraw consent at any time. You may also lodge a complaint with the competent supervisory authority (FDPIC in Switzerland).
9. Changes
We may update this policy at any time. The version published here applies.
