Infomaniak and the protection of your personal data

If your organisation processes personal data, you are probably subject to the provisions of the Federal Act on Data Protection (FADP), which took effect on 1 September 2023, and its implementing regulations, the OPDo. In this regard, you are subject to certain obligations that must be complied with. The same applies to Infomaniak, which, depending on its role, has specific obligations as either a subcontractor or a data controller.
It's essential to distinguish between the security of the infrastructure on which your data is hosted and the way in which you operate and implement it.
The customer's role
He is solely responsible for the security of the resources and application systems he uses with Infomaniak services.
Infomaniak's role
We are committed to ensuring the security of our infrastructure, in particular through a security policy that meets the requirements of various standards and certifications, as well as the FADP and the GDPR.
Our commitments as a subcontractor
As a web hosting provider, Infomaniak is committed to complying with its obligations under the FADP. As a result, you are also able to comply with the aspects of your regulatory obligations that are linked to our services.
As a subcontractor, Infomaniak undertakes to:
Implement appropriate technical and organisational measures to guarantee the confidentiality, availability, integrity and traceability of the personal data entrusted to us.
Implement high security standards and maintain continuous improvement processes to provide you with a high level of security as part of our services.
Maintain and develop our physical security measures to prevent unauthorised access to the infrastructures on which your data is stored.
Be exemplary in terms of our responsiveness to security updates on the systems we manage.
Be transparent when we use subcontractors who may process your data.
Notify you as soon as possible in the event of a data breach.
Store your data in our data centers, which are located exclusively in Switzerland.
Have physical and / or logical isolation systems (depending on the services) to isolate customer hosting solutions from each other and carry out intrusion tests once a year to ensure that data is watertight between customers.
These commitments are set out in our general terms and conditions and special terms and conditions.
Frequently asked questions about the FADP
Do I comply with the FADP when I use Infomaniak's services?
By hosting your data, Infomaniak acts as a subcontractor and complies with the obligations imposed on it by the FADP.
However, it is essential to distinguish between the obligations incumbent upon Infomaniak as a subcontractor and those incumbent upon the customer as data controller. It is indeed the latter's responsibility to ensure that it complies with the legislation by virtue of its role as data controller.
What are Infomaniak's role and responsibilities under the FADP?
As a Swiss company, Infomaniak is responsible for ensuring its compliance with current legislation in order to guarantee the protection of the personal data it processes.
Further information can be found on the following pages:
- ●
Our data confidentiality policy describes the data we hold in order to provide and implement our services.
- ●
The Data Processing Agreement (DPA) outlines Infomaniak’s commitments in its capacity as a subcontractor hosting all your data, including personal data.
- ●
Has Infomaniak appointed a data protection advisor?
Yes, Yoann Lopez is Infomaniak's coordinator for the use, management and protection of personal data. As Data Protection Officer, he is responsible for informing and advising data controllers, all company employees and our subcontractors.
If necessary, please contact us directly at dpo@infomaniak.com.


