Privacy Policy
As of: August 5, 2025
Table of Contents
- 1. Introduction
- 2. Responsible party
- 3. What data we process
- 4. Purposes and legal bases
- 5. Cookies & tracking
- 6. Recipients & processors
- 7. International data transfers
- 8. Data security
- 9. Storage period
- 10. Your rights
- 11. Minors
- 12. Social media & third-party content
- 13. Necessity of the information
- 14. Automated decisions
- 15. Beta-specific information
- 16. Changes to this privacy policy
- 17. Contact
1. Introduction
This Privacy Policy provides information about the processing of personal data when using our beta platform encosphera.io ("Platform"). It applies to www.encosphera.io and its subpages (and any associated apps). We process personal data in accordance with the Swiss Data Protection Act (DSG), the EU General Data Protection Regulation (GDPR) (where applicable) and other relevant provisions.
2. Responsible party
EncoSphera GmbH
Dorfstrasse 23
8234 Stetten SH, Switzerland
Email: service@encosphera.io
3. What data we process
3.1 Provided by you:
Registration data (name, email, password), profile data (profile picture, bio, preferences/settings), content data (content created/shared by you, comments, uploads), communication data (support requests, feedback, contact form), payment data (if relevant; transactions via payment service providers), beta feedback (bug reports, suggestions, survey responses).
Model calculation data (HumanDividend & AI transformation):
- Company data (revenue, profit, cost structures)
- Employee data (number, categories, salaries, working hours)
- AI investment parameters (budget, efficiency values)
- Industry-specific parameters (material shares, energy costs)
- Calculation results and simulations
3.2 Automatically collected:
Device/technical data (IP address, browser/OS, device ID), usage data (pages visited, clicks, dwell time, search terms), technical log/error data, approximate location (from IP), referrer URL.
3.3 Data from third-party sources (if used):
Social login (basic data from the provider), public sources, business partners within the scope of cooperation agreements.
4. Purposes and legal bases
- Platform operation & account (login, administration) – contract/legitimate interests.
- Model calculations (Human Dividend, AI transformation, simulations) – contract/legitimate interests.
- Beta testing & development (error analysis, performance, features) – legitimate interests.
- Communication (support, important updates) – contract/legitimate interests.
- Security (IT security, abuse/fraud prevention, two-factor authentication) – legitimate interests.
- Legal obligations (retention/reporting obligations) – legal obligation.
- Marketing (newsletter/product information, personalized content where applicable) – only with consent.
(GDPR, if applicable: Art. 6 para. 1 lit. b/c/f; marketing via Art. 6 para. 1 lit. a.)
5. Cookies & tracking
We use cookies/similar technologies for login functions, preferences, reach/performance measurement, and security.
We only use analysis/marketing cookies with your consent (where required by law). You can revoke/change your consent at any time via the "Cookie settings" link in the footer or via our consent tool (Usercentrics). Browser blocking is possible but may restrict functions.
6. Recipients & processors
Service providers process data on our behalf based on data processing agreements:
- Hosting/Cloud/CDN: Azure, Cloudflare, GStatic
- Email/newsletter: hostpoint.ch
Data will only be disclosed to authorities if required by law. Data will only be disclosed to third parties for their own purposes with your consent.
7. International data transfers
Depending on the service provider, processing may take place outside Switzerland/the EU/the EEA (e.g., the US). We ensure an adequate level of protection, for example through standard contractual clauses (SCC), adequacy decisions, the EU-U.S. Data Privacy Framework (DPF), the Swiss-U.S. DPF and, where applicable, the UK extension to the DPF – or we rely on legal exceptions, where permitted.
Note: Despite guarantees, a residual risk may exist for transfers to the USA.
8. Data security
8.1 Technical and organizational measures
We implement appropriate technical and organizational measures:
- SSL/TLS encryption (TLS 1.3)
- Encryption of stored data (AES-256)
- Web application firewall (WAF)
- Access controls and two-factor authentication
- Regular security updates and encrypted backups
8.2 Confidentiality of business data
Special protection for your company data:
- Strict access restrictions on model calculation data
- Encrypted storage of all business data
- No disclosure to third parties without explicit consent
- Separate data storage per user/company possible on request
- Confidentiality agreements with all employees
- Anonymized aggregation for statistical purposes only
No system is completely secure – choose strong passwords and protect your access data.
Data breaches: We will inform affected parties and the relevant authorities in accordance with legal requirements.
9. Storage period
Principles: Storage only for as long as necessary or required by law.
Guidelines:
- Usage/log data: 6 months
- Cookies: depending on type, session up to 12 months
- Beta feedback: until the end of the beta period + 6 months
- Marketing: until revoked
- Contract data: 10 years (legal retention obligation)
- Payment data: 10 years (accounting)
- Model calculations: 3 years or until deleted by the user
- Simulation results: 1 year after last access
Account deletion: After closure, we delete/anonymize personal data within 30 days, unless longer obligations prevent this.
10. Your rights
Within the scope of applicable law, you have the right to information, correction, deletion, restriction/objection, data portability, and revocation of consent given.
To exercise these rights, please contact us at service@encosphera.io; we may request proof of identity. We will respond as soon as possible, at the latest within one month (extendable in accordance with the GDPR, if applicable).
Complaints:
- Switzerland – EDÖB, Feldeggweg 1, CH-3003 Bern, www.edoeb.admin.ch
- EU/EEA: competent local data protection authority
11. Minors
Our platform is not intended for persons under the age of 16. If you believe that we have data relating to minors, please contact us and we will delete it immediately.
12. Social media & third-party content
Social media plugins (Facebook, X/Twitter, LinkedIn) are only activated after you have given your consent via our consent tool and may transmit data to the respective provider.
We only load embedded content (YouTube videos, Google Maps) after you have given your consent; these providers may set their own cookies.
13. Necessity of the information
Mandatory information for registration: at least email address and password.
Voluntary information improves your user experience.
14. Automated decisions
We do not make any decisions that are based solely on automated processing and have legal effects or significantly affect you; no profiling in this sense.
15. Beta-specific information
- More frequent changes/updates to processing
- Extended error logging for debugging purposes (Sentry)
- Possible risk of data loss in beta status
- Your feedback will be used to improve the product
When transitioning to the final version, we will inform you of any changes and obtain new consent if necessary.
16. Changes to this privacy policy
The current version is always available on the platform. We will inform you of any significant changes by email or by means of a clearly visible notice.
17. Contact
EncoSphera GmbH
Dorfstrasse 23
8234 Stetten SH, Switzerland
Email: service@encosphera.io
Last update: August 5, 2025