Privacy Statement

iUseFlow — dispatch and field-service platform for Swiss SMEs · Version 2026-10-18

This statement applies to the iUseFlow platform (web application and technician app) and to its use by companies ("customers" or "company") and their employees ("users").

1. Applicable law

The Swiss Federal Act on Data Protection (FADP) and its ordinance (DPO) govern. Where foreign data protection law additionally applies in an individual case, processing follows the applicable law. We deliberately make no blanket compliance claim in respect of foreign legal systems here.

2. Controller — two separate roles

The roles are not the same for all data. This is not a formality: it determines whom you need to approach.

3. What data we process

4. Purposes of processing

5. Recipients

We do not sell data. The technician app contains no advertising and no third-party analytics or tracking services. Fonts are served from our own servers; no connection is made to Google Fonts.

For the current V1 scope, a server-enforced allowlist determines whether a provider route is reachable. Stored credentials or earlier account connections do not open a technically disabled route.

RecipientRolePurposeData concernedContracting party / country
Exoscale (Akenes SA)processorOperation of the application, database and file storage since 16 September 2026; nightly database backupsall data actively processed in the platform; backups may contain time-limited remnants of data already deletedSwitzerland (Zurich, zone CH-DK-2; data-centre operator Equinix). Contracting party: Akenes SA, Boulevard de Grancy 19A, 1006 Lausanne, Switzerland (CHE-423.524.322). The Data Processing Addendum is governed by Swiss law (jurisdiction: canton of Vaud) and was accepted in the legal section of the account before provisioning (as at 16 September 2026); it permits transfers only within Switzerland, the EU/EEA or countries with adequate data protection. Sub-processor Aiven Oy (Helsinki, Finland) for the orchestration of the managed database; the database data itself is stored in zone CH-DK-2
Railway (former)former processorOperation of the platform until 16 September 2026; on 28 September 2026 the three former production services were removed and each of the three original production volumes received one supported, one-time wipe (no PITR card remains afterward, no proven rollback); the current Exoscale production path transmits no new data to these former Railway production servicesmetadata for 18 historical backups is still returned by the provider API; no final statement is made about remaining content, recoverability or provider-side deletionUnited States, region US West (sfo, historical). The account-specific DPA was executed by both parties with effect from 27 August 2026 and remains relevant for the earlier processing and any remaining storage; it is not the contract for the current Exoscale operation. Its scope for employee data remains subject to separate assessment
Google Maps Platform (server-side)provider route technically disabled for V1no active processing; the platform uses a local zone approximationno transmission to Google through this routemust be reassessed before activation
Google Maps Platform (in the browser)provider route technically disabled for V1no address completion or Google map at presentno transmission of an address, IP address or staff coordinate through this routemust be reassessed before activation
Sign-in with Googleprovider route technically disabled for V1no Google sign-in at present; historical links remain only as unavailable account informationno new transmission through this routemust be reassessed before activation; sign-in and recovery use email/username and password
Sign-in with Microsoftprovider route technically disabled for V1no Microsoft sign-in at presentno transmission through this routemust be reassessed before activation
Sign-in with Appleprovider route technically disabled for V1no Apple sign-in at present; historical links remain only as unavailable account informationno new transmission through this routemust be reassessed before activation; sign-in and recovery use email/username and password
Microsoft 365 / Graphprovider route technically disabled for V1no e-mail read/send or calendar synchronisation at presentno transmission through this route; historical connections and tokens can still be disconnected and cleaned upaccount region and permissions must be reassessed before activation
Anthropic (Claude API)provider route technically closedno active processing at presentno platform transmission — see section 11must be reassessed before activation
Expo, and Apple or Google as delivery/update serviceprovider route technically disabled for V1no push registration/delivery or EAS/OTA runtime update at presentno new device token, message or update-request transmission; deletion of historical tokens remains availablemust be reassessed before activation
Stripeindependent controller for payment data — under its own terms Stripe determines purposes and means itselfSubscription, payment and billing of the companypayment and billing details of the companycontracting party outside North and South America: Stripe Payments Europe, Limited (Ireland); transfer to Stripe, LLC, United States
Sentryprovider route technically disabled for V1no external error telemetry at presentno transmission; local platform logs remain availablemust be reassessed before activation
ResendprocessorSending fixed platform notices where no own mail server is configuredrecipient address, fixed subject/notice text and technical delivery metadata; no attachments, free text or medical informationprimary processing in the United States; the DPA provides for standard contractual clauses with Swiss adaptation. There is no Swiss DPF certification

Regarding Sentry: the provider route is technically disabled for the current V1 scope. The closed allowlist remains in code as an additional dormant control; setting a DSN does not open the route.

6. Transmission to Google from the browser

The server-side and browser-side Google Maps routes are technically disabled for the current V1 scope. A configured key does not change that; nothing is currently transmitted to Google through these routes. Dispatch planning uses a local zone approximation instead. Before any later activation, these routes would require renewed review:

Provider terms, account region and the data actually required must be evidenced again before either route is activated.

Google's own terms govern its processing: Google Privacy Policy / Terms of Service.

7. Push notifications and mobile runtime updates

Expo Push is technically disabled for the current V1 scope. The app does not register for push, requests no permission for it, registers no new Expo token, and the platform sends no message to Expo, Apple or Google. Historical tokens can still be deleted.

Local reminders (optional). For a job with advance notice, the signed-in person can explicitly choose "Reminder on this device". Only then does the app ask the operating system for permission to show notifications. The reminder is scheduled and shown on the device only. No push token is created and no data is transmitted to Expo, Apple, Google or any other provider. The reminder text contains neither names nor phone numbers. Scheduled reminders are removed when travel starts, on sign-out and when local data is erased. The permission can be withdrawn at any time in the device settings.

EAS/OTA runtime updating is also technically disabled. The app does not request a runtime update from Expo; updates to this V1 are distributed only as newly reviewed store builds. Other platform functions remain usable without these two provider routes.

8. Disclosure abroad

The platform — application, database and file storage — has been operated since 16 September 2026 at Exoscale (Akenes SA, Lausanne) in zone CH-DK-2 (Zurich, Switzerland); the nightly backups are stored encrypted in the same zone. In the current scope, disclosure abroad takes place only through the remaining routes named in section 5: Resend and Stripe, as well as — where enabled — sign-in with Google or Apple, may process data wholly or partly outside Switzerland; Aiven Oy (Finland), as a sub-processor of Exoscale, orchestrates the managed database whose data is stored in Switzerland. On 28 September 2026 the three former Railway production services were removed and each of the three original production volumes received one supported, one-time wipe; no PITR card remains afterward, no proven rollback exists. Protected Railway staging resources and three new, service-less volume instances remain preserved unchanged pending a further owner decision, and the current Exoscale production path transmits no new data to these former Railway production services. The Railway API still returns metadata for 18 historical backups; whether their content remains recoverable or was purged by the provider is unproven. The B2 remediation completed on 28 August 2026 removed the verified legacy health data from active primary storage; backups at the infrastructure operator may retain remnants until their scheduled replacement or deletion. New absence requests accept no medical attachment or free-text reason. Routes expressly described in section 5 as technically disabled receive nothing at present.

Art. 16 FADP applies to any disclosure abroad:

Where officially established, we already name the contracting party and country in the table in section 5. Established to date:

The register distinguishes human-resources data from other data. Railway (former) and Sentry are listed there for other data only. Whether the historical backup metadata retained at Railway and the employee information formerly processed there fall within that is a legal question; we do not answer it here and therefore do not claim that every disclosure is covered by adequacy.

Before any future activation of Sign-in with Apple, the following would require renewed review: Apple Distribution International Limited (Ireland) controls the personal data of individuals in Switzerland; it is generally stored by Apple Inc. in the United States. Apple states that international transfers of Swiss data are governed by standard contractual clauses; whether and how that applies to this service and account must be evidenced before activation. The route is technically disabled at present.

9. Location access (technician app)

Capturing the device location of individual staff members is disabled. No action in the technician app — a status update, photo upload, warehouse scan, customer link, native status update, or a GPS form field — produces a new coordinate today, regardless of whether a location permission was granted. There is no continuous or background tracking.

Coordinates from before this was disabled may still be stored in job, status, photo, scan or form records. These are no longer shown in any output of the platform — including to the person's own company or authorised roles — until a cleanup of this legacy data has been decided (section 12). The only exception is the statutory access or data portability response to the person concerned (section 15): for a registered request with verified identity, it contains the coordinates attributed to that person. The company's data export does not contain them.

The typed job/customer address is unaffected: in the current V1 it is used only for the local zone approximation. The Google Maps routes are disabled (section 6); the address concerns the job location, not a person's location.

Any operating-system permission prompt can be revoked at any time in the device settings; status reporting works in either case — with or without location permission — without a new coordinate being produced.

The "Arriving in about" indication when setting off is not location data. It is chosen (or left out) by the person themselves, and neither the device location nor a travel time derived from location tracking is used.

10. Camera and photo access (technician app)

The technician app uses the camera to take photos evidencing work — for example the work carried out, a delivery or a defect. The device's photo library is accessed only when the user attaches an existing image to a job. Absence requests accept no images or files.

The technician app records neither video nor audio, and there is no continuous visual monitoring. Capture takes place only upon an explicit action by the user.

Hidden details in photos. Photos often contain hidden extra details, such as where the picture was taken (GPS coordinates), the device used or editing details. iUseFlow removes these details from uploaded photos (JPEG, PNG, WebP) before they are stored; only the cleaned image is stored. This happens on the server, whether a photo is uploaded via the technician app or the web application. Images in other formats, such as HEIC, cannot currently be cleaned by iUseFlow; they are stored and output unchanged. The same applies to attachments of received e-mails. Photos stored before this cleaning was introduced remain stored unchanged, but are also output without these details — in the app, in the customer portal, in exports and in documents that are newly generated. Exceptions are sealed job reports and documents generated and filed earlier: they are always delivered exactly as they were created and may contain such an older photo together with its hidden details.

Browser speech recognition for service reports is disabled.

Scanning codes. In addition, the technician app uses the camera to read QR codes and barcodes. No photo is taken or stored; only the code read is used. A torch can be switched on, and without a camera the code can be entered by hand.

11. AI-assisted functions and automatic assignment

The external AI-provider route is technically closed. E-mail text, PDFs, photos, supporting documents, health information and speech transcripts are not transmitted to Anthropic. Any later activation requires a new documented provider and data-flow assessment.

AI drafts (optional, switched off by default). iUseFlow is prepared for AI drafts: a job draft from an e-mail or PDF, a report draft from spoken text, a time entry from a short sentence, a structured damage report and an explanation of the area suggestion. These functions are optional and switched off by default; none of them is active today. Only once the platform releases them and your company explicitly switches them on after the AI notice has been shown do they run on Anthropic models via AWS Bedrock (EU) or Google Vertex AI (EU) or on OpenAI models via Microsoft Azure (Switzerland), depending on configuration; only with AI switched on; no use for training. Before sending, e-mail addresses, phone numbers, IBANs, AHV numbers and known names are replaced by placeholders; health information is never sent. Every result is a draft next to the original that a person checks and confirms; the AI does not rate people and does not decide any assignment. Only the function, model, token count, cost and duration are logged, never the content.

Automatic assignment is disabled. Whether a job arrives through an automatic interface — a connected mailbox, an interface or a webhook — or is entered through the web interface, the platform does not assign it automatically to a member of staff. It can at most show a recommendation (the best-matching candidates, read-only); the actual assignment is in every case an explicit, reviewed individual action by dispatch. The assigned person sees the assignment in their job list in the app or the web application; no push notification is currently sent for it (section 7).

Voice input. Browser speech recognition is disabled. The platform sends neither microphone audio nor raw transcripts to a browser provider or Anthropic.

Your rights in this respect. If such an assignment leads in an individual case to a decision with legal consequences for you or that significantly affects you, you may under Art. 21 FADP state your point of view and request that the decision be reviewed by a natural person. Please contact your company as controller for this. Without a configured AI interface the platform's enabled core functions remain usable; it then operates without this extraction.

12. Health data and high risk

New absence requests accept no health type, medical attachment, reason or comment. On 28 August 2026 the verified legacy health data was deleted from active primary storage. The atomic remediation deleted the sole target row and generically redacted the related audit and notification rows; it left no active primary row and no active blob reference.

13. Storage on your device

14. Retention

What we must say honestly here: there is currently no automatic deletion at the end of the contract. Deletion happens on express request. New medical absence information is not accepted; the verified legacy health data was deleted from active primary storage on 28 August 2026. Backup copies remain at the infrastructure operator, as do retention periods at the recipients named in section 5; deletion at our end does not take immediate effect there. Binding periods per data category are currently being established.

15. Your rights

Under the FADP you have in particular:

Address your request first to your company as controller. For matters concerning account, contract or billing data, contact info@iuseflow.ch. We must verify your identity in order to act on the request; for that we ask only for the information necessary.

You also have the right to contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.

16. Account deletion

The technician app does not create accounts. Access is set up and administered exclusively by the company (your employer) as controller; for that reason the app deliberately has no button with which an employee could delete their own company account. Working times, signatures and completion records are attached to an account, for which the company bears statutory retention obligations.

You can request deletion of an account and the associated data as follows:

The user account and the personal information tied to it are deleted. Data subject to statutory retention obligations (e.g. working-time and billing data) is retained until the relevant period expires. The deletion that follows does not happen by itself: section 14 applies — we delete on express request, binding periods per data category are currently being established, and backup copies as well as retention periods at the recipients persist independently.

17. Data security

Access runs exclusively over HTTPS/TLS. Each company is a separate tenant; accesses are confined to the company's own data. Access is role-based, sessions are time-limited, and two-factor authentication is available. Further information is available under Security.

18. Contact

For questions about data protection, contact the responsible company (your employer) or the platform operator:

iUseFlow, Abdi-Aziz Ibrahim, Hofwiesenstrasse 158, 8057 Zurich, Switzerland
E-mail: info@iuseflow.ch
Further details in the legal notice.

19. Changes

The version published here governs. The current version bears the date given above. We notify the company of material changes.