Privacy Policy

Data protection · Swiss FADP

Privacy Policy
how your personal data is handled

Robuste Fiduciaire processes personal data in accordance with the Swiss Federal Act on Data Protection (FADP), in force in its revised form since 1 September 2023. This policy explains what data may be collected, why it is used, who may receive it, how long it is retained and how you can exercise your rights.

At a glance FADP 2023
Controller: Robuste Fiduciaire, operating in the Canton of Vaud
Data is used only for stated business, website and fiduciary purposes
Personal data is not sold
Processors receive only the access required for their task
Retention follows the purpose, mandate and applicable law
Access requests are generally answered within 30 days

Last updated: 11 July 2026 · English version 3.0

Swiss law — FADP
Proportionate security measures
No sale of personal data
Contractual confidentiality

Section 1

Controller and applicable framework

Robuste Fiduciaire is responsible for the personal data it determines how and why to process through this website and in connection with enquiries, consultations and fiduciary mandates.

Controller contact details
ControllerRobuste Fiduciaire
Operating areaCanton of Vaud, Switzerland
Privacy emailinfo@robuste.ch
Supervisory authorityFDPIC — Bern
Federal Act on Data Protection (FADP)
The revised Swiss FADP has applied since 1 September 2023. It governs transparency, data security, data subject rights, processors, international disclosures and breach reporting.
Swiss Code of Obligations — Article 958f
Accounting records, accounting vouchers, annual reports and audit reports must generally be retained for ten years from the end of the financial year.
Tax, social insurance and AML rules where applicable
Additional duties may apply to a specific mandate, including tax and VAT records, payroll and social insurance documentation, or identity checks where the service falls within an applicable legal obligation.

Section 2

Personal data, sources and processing purposes

The categories below depend on the service requested. Robuste seeks to collect only data that is relevant and proportionate to the stated purpose, the mandate and applicable legal duties.

Contact and onboarding data
  • Name, business name and role
  • Postal address, email and telephone
  • Company identification and registration details
  • Identity documents where required
📋 Enquiry, contract and mandate
Accounting, tax and corporate records
  • Invoices, receipts, bank records and ledgers
  • Annual accounts and management information
  • Tax returns, VAT returns and supporting documents
  • Contracts, shareholder and company records
⚖️ Mandate and statutory duties
Payroll and social insurance data
  • Employee identity and salary information
  • Swiss social security numbers
  • AVS/AHV, LPP/BVG, accident and insurance data
  • Annual salary certificates and payroll variables
⚖️ Payroll and employer obligations
Website and technical data
  • IP address and security logs
  • Browser, device and operating system data
  • Visited pages, referral source and interaction data
  • Cookie and consent choices where applicable
🔐 Security and website operation
Enquiries and consultation data
  • Contact form messages and email correspondence
  • Information describing the requested service
  • Postal address where needed for identification or billing
  • Call metadata and meeting notes where relevant
📋 Response, scoping and billing
Sensitive personal data
  • Processed only where necessary for the mandate or law
  • May include identity, payroll, health or social insurance details
  • Subject to stricter access and confidentiality controls
  • Not used for unrelated profiling or advertising
🛡️ Necessity and enhanced safeguards

Section 3

Your rights under the Swiss FADP

The rights available depend on the circumstances and may be limited by legal retention duties, third-party rights, overriding interests or statutory exceptions. Access requests are generally answered within 30 days and are normally free of charge.

01

Right of access

You may ask whether personal data concerning you is processed and request the information and data provided for by Article 25 FADP.

Usually within 30 days
02

Right to correction

You may request correction of inaccurate personal data. Where accuracy is disputed, an appropriate note may be added where the law requires it.

03

Deletion or restriction

You may request deletion or cessation of unlawful processing, subject to accounting, tax, social insurance, AML, evidentiary and other retention duties.

04

Right to object

You may object to processing. Robuste will stop the relevant processing or explain the justification for continuing where Swiss law permits it.

05

Data portability

Where Article 28 FADP applies, data processed by automated means with your consent or under a contract may be provided or transferred in a commonly used machine-readable format.

06

Automated decisions and remedies

Robuste does not currently make decisions with significant legal effects solely by automated means. You may contact the FDPIC or pursue available judicial remedies if you believe your rights have been infringed.

Section 4

Retention periods and deletion principles

Data is retained only for as long as required by the relevant purpose, the mandate, legal obligations, limitation periods, dispute management and security needs. A legal hold or a special statutory rule may require a longer period.

Data category Main purpose Typical period Basis / qualification
Accounting records and supporting vouchers Bookkeeping, annual accounts and evidence 10 years CO Article 958f, counted from the end of the financial year
Tax, VAT and mandate documentation Returns, reviews, audits and file defence Usually up to 10 years Applicable tax/VAT rules; longer periods may apply in specific cases
Payroll and social insurance records Payroll, certificates, declarations and employer evidence Usually up to 10 years Depends on the document, mandate and applicable social insurance rules
Identity and due-diligence documents Onboarding, verification and legal compliance As legally required Contractual or statutory duty, including AML rules where applicable
Mandate correspondence and work product Service history, instructions, evidence and claims Mandate + relevant limitation period Often retained with the mandate file where needed
Enquiries without an active mandate Reply, follow-up and quotation history Normally up to 24 months Deleted earlier if no longer needed; longer only for a documented reason
Server, security and access logs Fraud prevention, troubleshooting and security Limited operational period Depends on the hosting and security configuration
Cookie and analytics data Website operation and measurement Tool-specific As disclosed in the consent interface and provider settings

Section 5

Cookies, analytics and third-party website tools

The website may use cookies and similar technologies for operation, security, preferences and measurement. The tools actually enabled must correspond to the cookie banner and the website configuration in force at the time of your visit.

Section 6

Recipients, processors and international disclosures

Robuste does not sell personal data. Data may be disclosed only where needed for the website, a requested service, the mandate, professional coordination, legal compliance or the protection of legitimate rights.

✓ Categories of authorised recipients

Access is limited to the data required for the recipient’s task and is subject to professional, contractual or statutory confidentiality where applicable.

  • Hosting, email, form, security and IT support providers
  • Accounting, payroll, document-management and collaboration providers
  • Tax authorities and social insurance institutions where required
  • Banks, notaries, lawyers, auditors and other advisers where instructed or necessary
  • Courts, authorities or counterparties where disclosure is legally required

⚠ Processing outside Switzerland

Some technical or professional providers may process data in the EU/EEA, the United States or other countries. The relevant country and safeguard must be assessed for the provider actually used.

  • Adequacy decision under Article 16 FADP where available
  • Recognised standard contractual clauses and supplementary measures where needed
  • Swiss–US Data Privacy Framework for certified recipients where applicable
  • Statutory exceptions under Article 17 FADP in limited cases
  • Transparency about the destination country or region as required

Frequently asked questions

Practical answers about your personal data

Robuste applies proportionate technical and organisational safeguards, including access controls, confidentiality obligations, secure transmission methods, backups and provider due diligence where relevant. Access is limited to persons and processors who need the data for the mandate. No security measure can eliminate every risk, but incidents are assessed and handled under Article 24 FADP.

Depending on the service, Robuste may process contact and identification data, company information, accounting and tax records, payroll and social insurance data, correspondence, billing information and limited website or technical data. Only data that is relevant to the stated purpose or mandate should be collected.

Retention depends on the purpose and the applicable legal or contractual requirements. Accounting records are generally retained for ten years under Article 958f of the Swiss Code of Obligations. Other data is kept only for as long as needed for the mandate, legal claims, statutory duties, security or documented business follow-up.

Send a request to info@robuste.ch and state the right you wish to exercise. Robuste may ask for information needed to verify your identity. Requests for access are generally answered within 30 days, subject to the exceptions and extensions permitted by Swiss law.

Robuste does not sell personal data. Data may be disclosed to service providers, public authorities, social insurance bodies, banks, notaries, lawyers or other professional partners when this is necessary for the mandate, required by law or instructed by the client. Processors are selected and contractually managed in accordance with Article 9 FADP where applicable.

Robuste assesses the nature and likely consequences of the incident and takes containment and remediation measures. A breach that is likely to result in a high risk to the personality or fundamental rights of affected persons is reported to the FDPIC as soon as possible. Affected persons are informed where this is necessary for their protection or required by the FDPIC.

A question about your personal data?

Contact Robuste for access, correction, deletion, objection, portability or any other privacy-related enquiry. Access requests are generally handled within 30 days, subject to the conditions and exceptions of Swiss law.

Please identify the request clearly and provide only the information needed to verify your identity. 🔒 Information submitted for a rights request is used to verify and answer that request.