
Last updated: April 2026 · Effective: January 2026
SwissLuxe Engine operates under the principle of minimum data. We collect only information necessary to provide the service: session identifier, type of document processed (without content), and usage metadata for billing. We never collect the content of processed documents beyond the active session.
All documents uploaded to the system are automatically deleted within 24 hours of processing via automated webhooks. Ephemeral URLs expire at 60 minutes. No sensitive data is retained on any infrastructure node.
All data in transit is protected with TLS 1.3. Data at rest uses AES-256-GCM. Encryption keys rotate automatically every 90 days. We never store third-party keys (Twilio, client API keys) in plain text.
European client data is processed exclusively on EU and Switzerland nodes (Geneva Primary, Zurich Backup). No data transfers outside the EEA without explicit consent and adequate safeguards under GDPR.
Under the General Data Protection Regulation, you have the right to: access your personal data, rectification, erasure ("right to be forgotten"), portability, and objection to processing. To exercise these rights: privacy@swissluxe-engine.com.
We use only technically necessary cookies for service operation (session, authentication). We do not use tracking, advertising or third-party analytics cookies. See our Cookie Policy for details.