Privacy Policy —
how your personal data is handled
Robuste Fiduciaire processes personal data in accordance with the Swiss Federal Act on Data Protection (FADP), in force in its revised form since 1 September 2023. This policy explains what data may be collected, why it is used, who may receive it, how long it is retained and how you can exercise your rights.
Last updated: 11 July 2026 · English version 3.0
Section 1
Controller and applicable framework
Robuste Fiduciaire is responsible for the personal data it determines how and why to process through this website and in connection with enquiries, consultations and fiduciary mandates.
Section 2
Personal data, sources and processing purposes
The categories below depend on the service requested. Robuste seeks to collect only data that is relevant and proportionate to the stated purpose, the mandate and applicable legal duties.
- Name, business name and role
- Postal address, email and telephone
- Company identification and registration details
- Identity documents where required
- Invoices, receipts, bank records and ledgers
- Annual accounts and management information
- Tax returns, VAT returns and supporting documents
- Contracts, shareholder and company records
- Employee identity and salary information
- Swiss social security numbers
- AVS/AHV, LPP/BVG, accident and insurance data
- Annual salary certificates and payroll variables
- IP address and security logs
- Browser, device and operating system data
- Visited pages, referral source and interaction data
- Cookie and consent choices where applicable
- Contact form messages and email correspondence
- Information describing the requested service
- Postal address where needed for identification or billing
- Call metadata and meeting notes where relevant
- Processed only where necessary for the mandate or law
- May include identity, payroll, health or social insurance details
- Subject to stricter access and confidentiality controls
- Not used for unrelated profiling or advertising
Section 3
Your rights under the Swiss FADP
The rights available depend on the circumstances and may be limited by legal retention duties, third-party rights, overriding interests or statutory exceptions. Access requests are generally answered within 30 days and are normally free of charge.
Right of access
You may ask whether personal data concerning you is processed and request the information and data provided for by Article 25 FADP.
Usually within 30 daysRight to correction
You may request correction of inaccurate personal data. Where accuracy is disputed, an appropriate note may be added where the law requires it.
Deletion or restriction
You may request deletion or cessation of unlawful processing, subject to accounting, tax, social insurance, AML, evidentiary and other retention duties.
Right to object
You may object to processing. Robuste will stop the relevant processing or explain the justification for continuing where Swiss law permits it.
Data portability
Where Article 28 FADP applies, data processed by automated means with your consent or under a contract may be provided or transferred in a commonly used machine-readable format.
Automated decisions and remedies
Robuste does not currently make decisions with significant legal effects solely by automated means. You may contact the FDPIC or pursue available judicial remedies if you believe your rights have been infringed.
Section 4
Retention periods and deletion principles
Data is retained only for as long as required by the relevant purpose, the mandate, legal obligations, limitation periods, dispute management and security needs. A legal hold or a special statutory rule may require a longer period.
| Data category | Main purpose | Typical period | Basis / qualification |
|---|---|---|---|
| Accounting records and supporting vouchers | Bookkeeping, annual accounts and evidence | 10 years | CO Article 958f, counted from the end of the financial year |
| Tax, VAT and mandate documentation | Returns, reviews, audits and file defence | Usually up to 10 years | Applicable tax/VAT rules; longer periods may apply in specific cases |
| Payroll and social insurance records | Payroll, certificates, declarations and employer evidence | Usually up to 10 years | Depends on the document, mandate and applicable social insurance rules |
| Identity and due-diligence documents | Onboarding, verification and legal compliance | As legally required | Contractual or statutory duty, including AML rules where applicable |
| Mandate correspondence and work product | Service history, instructions, evidence and claims | Mandate + relevant limitation period | Often retained with the mandate file where needed |
| Enquiries without an active mandate | Reply, follow-up and quotation history | Normally up to 24 months | Deleted earlier if no longer needed; longer only for a documented reason |
| Server, security and access logs | Fraud prevention, troubleshooting and security | Limited operational period | Depends on the hosting and security configuration |
| Cookie and analytics data | Website operation and measurement | As disclosed in the consent interface and provider settings |
Section 6
Recipients, processors and international disclosures
Robuste does not sell personal data. Data may be disclosed only where needed for the website, a requested service, the mandate, professional coordination, legal compliance or the protection of legitimate rights.
✓ Categories of authorised recipients
Access is limited to the data required for the recipient’s task and is subject to professional, contractual or statutory confidentiality where applicable.
- Hosting, email, form, security and IT support providers
- Accounting, payroll, document-management and collaboration providers
- Tax authorities and social insurance institutions where required
- Banks, notaries, lawyers, auditors and other advisers where instructed or necessary
- Courts, authorities or counterparties where disclosure is legally required
⚠ Processing outside Switzerland
Some technical or professional providers may process data in the EU/EEA, the United States or other countries. The relevant country and safeguard must be assessed for the provider actually used.
- Adequacy decision under Article 16 FADP where available
- Recognised standard contractual clauses and supplementary measures where needed
- Swiss–US Data Privacy Framework for certified recipients where applicable
- Statutory exceptions under Article 17 FADP in limited cases
- Transparency about the destination country or region as required
Frequently asked questions
Practical answers about your personal data
Robuste applies proportionate technical and organisational safeguards, including access controls, confidentiality obligations, secure transmission methods, backups and provider due diligence where relevant. Access is limited to persons and processors who need the data for the mandate. No security measure can eliminate every risk, but incidents are assessed and handled under Article 24 FADP.
Depending on the service, Robuste may process contact and identification data, company information, accounting and tax records, payroll and social insurance data, correspondence, billing information and limited website or technical data. Only data that is relevant to the stated purpose or mandate should be collected.
Retention depends on the purpose and the applicable legal or contractual requirements. Accounting records are generally retained for ten years under Article 958f of the Swiss Code of Obligations. Other data is kept only for as long as needed for the mandate, legal claims, statutory duties, security or documented business follow-up.
Send a request to info@robuste.ch and state the right you wish to exercise. Robuste may ask for information needed to verify your identity. Requests for access are generally answered within 30 days, subject to the exceptions and extensions permitted by Swiss law.
Robuste does not sell personal data. Data may be disclosed to service providers, public authorities, social insurance bodies, banks, notaries, lawyers or other professional partners when this is necessary for the mandate, required by law or instructed by the client. Processors are selected and contractually managed in accordance with Article 9 FADP where applicable.
Robuste assesses the nature and likely consequences of the incident and takes containment and remediation measures. A breach that is likely to result in a high risk to the personality or fundamental rights of affected persons is reported to the FDPIC as soon as possible. Affected persons are informed where this is necessary for their protection or required by the FDPIC.
A question about your personal data?
Contact Robuste for access, correction, deletion, objection, portability or any other privacy-related enquiry. Access requests are generally handled within 30 days, subject to the conditions and exceptions of Swiss law.
Please identify the request clearly and provide only the information needed to verify your identity. 🔒 Information submitted for a rights request is used to verify and answer that request.