Privacy policy and personal data protection
This policy explains how TalentWide SA processes personal data in connection with the website and application DiagNow. It has been prepared in accordance with the Swiss Federal Act on Data Protection (FADP/revised FADP) and, where applicable, the GDPR.
- 1. Controller and contact details
- 2. Respective roles
- 3. Data processed
- 4. Purposes of processing
- 5. Processors and recipients
- 6. Data location and transfers
- 7. Product analytics and tag management
- 8. Payments
- 9. Emails and SMTP
- 10. Android app and offline copies
- 11. Retention periods
- 12. Security
- 13. Data subject rights
- 14. Cookies
- 15. Changes
1. Controller and contact details
TalentWide SA
Rue de Lausanne 127, 1202 Geneva, Switzerland
UID: CHE-260.347.514
Data protection contact: info@diagnow.ch
2. Respective roles
TalentWide SA is responsible for processing related to the website, user accounts, security, billing, support, product analytics and operation of the platform.
For business data entered into DiagNow by an organisation, including its customers, contacts, reports, photographs, plans, quotations, invoices, appointments and comments, the user organisation remains responsible for determining whether it is entitled to collect and process that data. TalentWide SA then acts as a technical service provider to host, process, display, export and secure that data as part of the service.
3. Data processed
Depending on how you use DiagNow, we may process the following categories:
| Category | Examples |
|---|---|
| User account | Last name, first name, email address, hashed password, preferences, signature, professional title and security settings. |
| Organisation | Company name, address, billing email, company settings, members, roles, invitations, user quotas and storage quotas. |
| Subscription and billing | Selected plan, free trial, number of users, subscribed storage, subscription status, subscription history and billing portal. |
| Business data | Customers, contacts, quotations, invoices, payments, reminders, pollutant reports, VDI reports, plans, photographs, attachments, comments, appointments and PDF exports. |
| Potentially sensitive data | Photographs, signatures, documents or comments uploaded by users that may contain personal data, depending on their content. |
| Sending configuration | SMTP settings, host, port, username, encrypted password, recipients, subjects and bodies of scheduled emails. |
| Technical data | IP address, user agent, session identifiers, security logs, application errors, timestamps and metadata required for proper operation. |
| Product analytics | Pages viewed, clicks, forms submitted, registration journey, free trial, subscription, module use, consent choices and technical data related to loading the tag manager. |
| Contact and support | Name, email, organisation, message, any attachments, date and IP address at the time of submission. |
| Android app and synchronisation | Device identifier, synchronisation token, connection state, business data and files stored locally for offline mode, and photos, plans or documents selected with your permission. |
4. Purposes of processing
Data is processed only for specified purposes, including:
- Creating and managing user accounts and organisations.
- Providing DiagNow modules: reports, CRM, quotations, invoices, calendar, PDF exports, client portal and settings.
- Ensuring security, authentication, abuse prevention and separation between organisations.
- Managing the free trial, subscriptions, payments, invoices and access to the service.
- Providing assistance, responding to contact requests and resolving technical issues.
- Measuring actual product use to understand user journeys, improve usability, prioritise development and identify underused features.
- Running integrations selected by the organisation, including Bexio, Swiss geographical sources and mapping services. No external LIMS is currently used in production.
- Providing the Android app, photo capture, access to requested files and secure synchronisation, including temporary offline use.
- Complying with legal obligations, including accounting, tax and security requirements.
5. Processors and recipients
We use a limited number of service providers that are necessary to operate the service:
| Provider | Role | Primary location |
|---|---|---|
| Infomaniak Network SA | Hosting of the application, database, files and backups. | Switzerland |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Online payments, subscriptions, billing portal, payment methods, invoices and payment events. | European Union / United States, depending on the services used |
| PostHog | Product analytics, usage events, registration journey, subscription and application use. | PostHog Cloud EU, AWS eu-central-1 region, Frankfurt (Germany) |
| Google Tag Manager — Google Ireland Limited / Google LLC | Loading and managing the tag container and communicating consent signals to compatible Google tags. | European Union / United States, depending on Google’s infrastructure |
| SMTP provider configured by the organisation | Sending emails through the external provider selected and configured by the organisation. DiagNow does not provide an SMTP server. | Depends on the provider selected by the organisation |
| bexio AG (if enabled by the organisation) | Synchronisation of contacts, quotations, invoices, payments and accounting references selected by the organisation. | Switzerland |
| swisstopo, FSO RegBL/MADD and SITG Geneva | Searches for addresses, buildings, parcels and cadastral information from Swiss public sources. | Switzerland |
| OpenStreetMap Foundation / Nominatim | Geocoding and reverse geocoding of an address or coordinates when this function is used. | United Kingdom / Europe depending on the service infrastructure |
| External LIMS | No external LIMS is currently used in production. This policy will be updated before any such service is activated. | Not currently applicable |
| Google Maps or Apple Maps (when explicitly opened) | Opening an address or route in the mapping app selected on the device. | European Union / United States depending on provider and device |
| Google Play / Android | Android app distribution and updates, platform security and diagnostics provided by Google. | European Union / United States depending on Google infrastructure |
No personal data is sold. Data is disclosed to third parties only when necessary to operate the service, process payments, ensure security, provide support, perform product analytics, send emails, perform geocoding or mapping, run an integration enabled by the organisation, or when required by law.
6. Data location and transfers
The application, database, files and backups are hosted by Infomaniak in Switzerland. PostHog Cloud EU is hosted in the AWS eu-central-1 region in Frankfurt, Germany; according to PostHog, event data, user data and the product on this European instance are not transferred to the United States. Stripe, Google, Google Play/Android, OpenStreetMap/Nominatim, Apple and the SMTP provider selected by the organisation may process the required data in the European Union or other countries depending on the service used. Bexio and official Swiss geographical sources primarily process data in Switzerland. No external LIMS is currently used in production. Where a transfer is made to a country whose level of protection is not recognised as adequate, we rely on the contractual safeguards and measures provided by the relevant provider.
7. Product analytics and tag management
With your consent, DiagNow uses PostHog to understand how the website and application are used: pages and routes viewed, types of clicks and forms, journeys towards the free trial, account creation, organisation creation, checkout and use of the main modules. Refusing consent does not prevent you from using the service. Platform administration dashboard pages send no events to PostHog and load neither PostHog nor Google Tag Manager.
Session replay is limited to public presentation pages after consent. It is never started in the authenticated application or administration dashboard. On public pages, form inputs are masked and support as well as areas marked sensitive are excluded from recording. Session recordings are retained for no more than 30 days. Analytics events exclude free text, business content, messages, detailed errors, tokens or other secrets. PostHog receives only internal identifiers for users and organisations, never their email address or name in analytics properties.
Google Tag Manager loads on pages to manage container GTM-PPXWSRVL. Before any decision, DiagNow sends analytics and advertising states as denied. Acceptance grants analytics storage only; advertising storage and uses remain denied. Loading the container may communicate the IP address, normal request-level technical data, site origin and consent state to Google. Any new tag or purpose added to the container must honour this choice and be documented here before activation.
You can accept, refuse or change this choice at any time in our cookie policy. Your choice is stored in your browser’s local storage.
8. Payments
Payments and subscriptions are processed by Stripe. When you access checkout or the billing portal on the website, Stripe may process information required for payment, fraud prevention, billing and subscription management. The Android app does not display Stripe payments or purchase links. DiagNow does not store complete payment card numbers.
9. Emails and SMTP
DiagNow does not provide an email delivery service or SMTP server. The organisation or user connects their own email provider to send automated emails, quotations, invoices, reports and messages from their address. SMTP credentials are stored in encrypted form and are used only to establish this connection. We do not read the user’s email inbox. For emails scheduled or sent through DiagNow, we process the recipients, subject, message content and attachments required for sending. Processing terms and location depend on the provider selected by the organisation or user.
10. Android app and offline copies
The Android app may store a local database and copies of business data, photos, plans and documents on the device to allow viewing, entry and synchronisation when connectivity is temporarily unavailable. This data remains under the control of Android and may remain on the device after sign-out.
Deleting an account revokes server-side mobile sessions and tokens and prevents further synchronisation. A server cannot, however, remotely erase a copy on a device that never reconnects. For immediate removal from the device, the user must clear DiagNow app data in Android settings or uninstall the app.
Camera, photo, file or notification access is used only for the requested function and depends on permissions granted in Android. Google Play and Android may process their own technical and diagnostic data according to account and device settings.
11. Retention periods
- Active account: for as long as the service is used.
- Deleted account: deleted or anonymised within a reasonable period, unless retention is required by law or for security purposes.
- Organisation data: retained for the term of the contract, then deleted or made available for export in accordance with the agreed arrangements.
- Accounting records: issued invoices, payments and supporting documents actually subject to retention are kept for 10 years from the end of the relevant financial year, in particular under Art. 958f CO. When an organisation is closed, these records are separated from operational data and placed in a sealed legal archive retaining the organisation identity, references and integrity hashes needed for later retrieval. This archive is available only to authorised administrators and is purged at expiry unless a legal hold applies. Drafts and ordinary quotations are not automatically accounting records requiring ten-year retention.
- Technical and security logs: retained for as long as necessary for security, diagnostics and abuse prevention.
- PostHog data: session recordings are retained for no more than 30 days. Analytics events follow the retention period configured in the PostHog project or are deleted following a verified erasure request.
- Contact/support requests: retained for as long as necessary to handle the request and provide sales or support follow-up.
12. Security
We implement appropriate technical and organisational measures, including:
- HTTPS encryption for communications.
- Passwords stored in hashed form.
- Two-factor authentication available.
- Encryption of sensitive secrets, such as SMTP passwords.
- Separation of organisations and access rights control.
- Backups and business continuity measures provided by the hosting provider.
- Internal access limited to operational, support and security needs.
13. Data subject rights
Under the FADP, you may request access to your personal data, its rectification or deletion where the applicable conditions are met, as well as information about how it is processed. You may also object to certain processing where permitted by law.
To exercise these rights, contact us at info@diagnow.ch and clearly state your request. We may ask for proof of identity where necessary. You may also contact the Federal Data Protection and Information Commissioner (FDPIC).
If your request concerns data entered into DiagNow by a user organisation, we may need to forward or coordinate the request with that organisation, as it remains responsible for its own business data.
The detailed procedure for requesting deletion of a DiagNow account is publicly available.
14. Cookies
DiagNow uses cookies that are necessary to operate the service, including session, CSRF security and preference cookies. The payment provider may use cookies during checkout or when the billing portal is accessed. Google Tag Manager loads with optional storage denied by default; PostHog and optional measurement tags are activated only after your explicit consent. Google advertising storage remains denied. For more details or to change your choice, see our cookie policy.
15. Changes
This policy may be updated to reflect legal, technical or functional developments. The date of the latest update appears at the top of the page. If a material change is made, we may inform users by email, an in-application notification or a message on the website.