It is important to distinguish between the personal data you entrust to us for the use of our services, and the security of the data you host on Infomaniak's technical infrastructures.

Commitment to the confidentiality of your personal data

  • Infomaniak collects as little information about you as possible. In order to be able to deliver your order, guarantee the security of your data or collect your opinion on specific pages, we may nevertheless require certain personal information.

  • Infomaniak processes your personal data with care and ensures that your privacy is protected. Here are our three commitments regarding the confidentiality of your personal data:

Usage limited as much as possible

We never share your personal data with third parties without a valid reason.

Responsible processing

We protect and treat your personal information as if it were our own.

Transparent use

We use your personal information solely for the purposes described below.

What personal information does Infomaniak store?

Name, address and place of residence

Your name is stored, as you are more than just a customer number to us when you contact our support team. We also need your name and place of residence to prepare your invoices, contact you or visit you for a cup of coffee (if you invite us).

Email address

We store your e-mail address to send you important messages about your order or account. We also keep you informed of new developments at Infomaniak via newsletters. If necessary, you can choose to unsubscribe from these.

Phone number

We store your telephone number to contact you in case of emergency or to ask for your opinion. In addition, we use your number to send you SMS messages for two-step verification or to authenticate you.

Login details and customer number

We store your login details to secure access to your account and ensure that only authorised people can access your personal data. We also generate a unique customer number so we can help you more quickly and efficiently.

IP address

We store your IP address to give you an overview of the IP addresses used to connect to your account and to verify the origin of any changes. This information is also used to strengthen the protection of your account against unauthorised access from other locations.

Payment details

We store payment information such as your PayPal details, your credit card, your account number and your name as the account holder. The processing of your payments also involves other parties, such as companies affiliated with your payment method or credit cards. When you place an order, we also generate a unique offer or an invoice number which is then linked to your account.

Your use of our Internet site

Cookies and similar technologies allow us to understand how our website and services are used so that we can improve them. We track our website’s traffic using Matomo, software hosted on our own servers in Switzerland: this data is not shared with any third parties. This tracking is enabled only with your consent, which you can change at any time via the cookie management button. With your consent only, cookies are also used to measure the effectiveness of our advertisements and to personalize them. For details on how your data is used, please refer to the “Products, Services & Applications” section at the bottom of the page.

Photo of Yoann Lopez

Yoann Lopez - Data Protection Officer (DPO)


Infomaniak's Data Protection Officer (DPO)

He serves as Infomaniak’s internal compliance officer for data processing activities. He has the necessary resources to fulfill his role without any conflict of interest, in accordance with the obligations and best practices that Infomaniak must implement regarding the protection of personal data. You can contact him directly at dpo@infomaniak.com.

Combating fraud

Your personal information allows us to verify your identity when people contact us and try to impersonate you with false information.

Cookies

Cookies may contain personal information about you, such as your browsing behaviour and interests. See our cookie policy for more information.

Cookie use policy

Overview of your personal information

You can review and control most of your personal information through your Manager.

If you have any questions, please contact us.

Access the manager

Legal or contractual provisions for the provision of personal data

The provision of personal data may be required by law or result from contractual regulations. For example, we are obliged to collect and process personal data in order to conclude a contract. Otherwise, no contract can be concluded.

Duration of personal data storage

We process and store personal data only for the time necessary to achieve the purpose of storage or to the extent required by law. As a general rule, the purpose of processing is achieved when the contract is terminated.

  • You can edit and delete the data you store in our services yourself. After a service is terminated, we delete the data stored in it, including its backup copies, within the timeframe specified in the specific terms and conditions for that service.
  • Account and contact information: for the duration of the contract, and for six months after the account is closed.
  • Invoices and accounting documents: ten years from the end of the fiscal year (CO Art. 958f; LTVA Art. 70). Contractual data: ten years after the end of the contract (statute of limitations, CO Art. 127).
  • The information you provide during the process of placing an uncompleted order will be retained for a maximum of six months.
  • Log files for your account (IP addresses): up to twelve months.
  • Requests submitted to our support team (tickets, chat, emails): three years after the request is closed, or until the account is deleted, whichever comes first.
  • Recordings of phone calls with our support team: six months.
  • Identification documents submitted to our support team: deleted once verification is complete, no later than thirty days after submission; via Infomaniak Check: automatically deleted 24 hours after our support team processes the request or, if the request is not successful, after 72 hours.
  • Application files: six months after the end of the recruitment process, unless you agree to a longer retention period.
  • Web analytics (Matomo): thirteen months.
  • Cookies: as specified in our cookie policy.

Your personal data

  • User's personal data:

    We collect the personal data you provide to us when you use or register for any of our services, purchase and / or register a domain name and / or when you contact us directly through any communication channel (for example, support tickets, chat or calls; we also record information when you contact us, such as support queries, notes, or information about your requests and how we responded to you). This data collection is necessary to enable us to provide you with our services. We also use cookies and similar technologies on our sites and mobile applications to collect information about your interactions with and use of our services. Here are the types of personal data we collect about you:

    Contact data

    • your name
    • your first name
    • the name of your company, association or foundation
    • Your login email address
    • a recovery email address
    • your mobile phone number
    • a postal address

    Login details

    • Passwords and security information used for authentication and access.

    Interaction data

    • Device data
      • Device configuration
      • IP address(es)
      • Regional and language settings
      • Access points near your device
    • Geolocation data (please see the 'Products, Services & Applications’ section)
    • Personal data relating to payment, such as the billing address or credit card details (for users of paid services).
    • Personal data that you include in your communications with us (such as an identity card, passport, official company registration documents, minutes of an association, certificate of inheritance, death certificate).
    • Phone calls with our support team are recorded to improve the quality of our services and to maintain a record of our conversations. An announcement will inform you of this at the beginning of the call; you may contact us in writing if you do not wish to be recorded.
    • Data we do not collect directly from you: contact information for a domain name or users added to an organization, provided by our client; country and region inferred from your IP address during a payment (GeoIP); confirmation, provided by Awin, that an order originated from an affiliate partner.

  • Collection of your personal data is necessarily part of a specific use. Depending on the type of personal data collected, it may be used for:
    1. Enter into and perform the contract: provide and operate Infomaniak Services and Products, issue invoices, provide administrative and technical support, and notify you of events affecting your Services and Products—performance of the contract (GDPR Art. 6(1)(b); FADP Art. 31, para. 2, subpar. a).
    2. To enable the identification of new customers, secure accounts, and prevent fraud and abuse—legitimate interest in protecting our customers and our infrastructure (GDPR Art. 6(1)(f); FDA Art. 31(1)).
    3. To continuously improve Infomaniak’s services and products, gather your feedback, and record calls with our support team for quality assurance and evidentiary purposes—legitimate interest in developing our products and improving the quality of our service (GDPR Art. 6(1)(f); FADP Art. 31, para. 1).
    4. Sending our customers emails about our new products and offers related to similar services—legitimate interest in promoting our services to our customers (GDPR Art. 6(1)(f); FADP Art. 31(1); UCT Art. 3, para. 1, subpara. o).
    5. Sending our newsletter upon subscription, measuring our website’s traffic, measuring the effectiveness of our ads, attributing orders to our affiliate partners, and securing the business contact form with Google reCAPTCHA – consent (GDPR Art. 6(1)(a); FADP Art. 31, para. 1).
    6. To comply with applicable laws and regulations, particularly regarding record-keeping, and to respond to a request from the authorities—a legal obligation under Swiss law (Data Protection Act, Art. 31, para. 1); with regard to the GDPR, our legitimate interest in complying with the law applicable to us (Art. 6(1)(f)) and, for obligations arising under European Union law or the law of a Member State, Art. 6(1)(c).
    7. Processing job applications for positions posted by Infomaniak—pre-contractual measures taken at your request (GDPR Art. 6(1)(b); FADP Art. 31(2)(a); CO Art. 328b).
    You may object at any time, without giving a reason, to the use of your data for marketing purposes by using the unsubscribe link in our emails or through your contact preferences. Under Swiss law, processing that complies with the principles of the FADP does not require justification; references to Art. 31 FADP indicate the basis (consent, overriding interest, law) that we would invoke if justification were necessary.

  • We protect and handle your personal information as if it were our own, and we never share your personal data with third parties without a valid reason. Our service providers may only use your data on our behalf and in accordance with our instructions. Third parties acting as data controllers—whether affiliated or independent—process your data in accordance with their own privacy policies. Therefore, your personal data may be shared with companies within the Infomaniak Group, with third-party partners (e.g., to allow you to integrate their solutions into our services), or with trusted third-party service providers. For example, we may share your data in connection with processing a payment, obtaining feedback, or complying with a legal obligation.

    Form Security and Display of Customer Reviews – as soon as the pages load

    Legal basis: legitimate interest in protecting our forms from bots and in displaying our customers’ reviews (GDPR Art. 6(1)(f); FADP Art. 31(1)). Data transmitted: IP address, browser type and version, language, operating system, and URL of the page accessed.

    BAU Software s.r.o. (ALTCHA), Czech Republic

    • Purpose: to provide the form protection component against bots; the verification itself is performed on Infomaniak's servers
    • Data processing location: European Union; the script is served by the Bunny.net content delivery network (BunnyWay d.o.o., Slovenia) from the point of presence closest to you
    • Safeguards for International Transfers: Countries Recognized as Providing an Adequate Level of Protection (European Union Member States, Annex 1 of the OPDo)

    Trustindex Kft. (Trustindex Ltd), Hungary

    • Purpose: To display our customers' reviews
    • Data processing location: European Union (Germany); the widget files are served via the Amazon CloudFront network from the point of presence closest to you
    • Safeguards for international transfers: Countries recognized as providing an adequate level of protection (European Union member states, Annex 1 of the GDPR); for Amazon CloudFront: Amazon.com, Inc.’s certification under the EU–U.S. and Swiss–U.S. Data Privacy Frameworks; alternatively, standard contractual clauses

    Protection of the business contact form – only with your consent

    Google reCAPTCHA is loaded only on this form page, after you have given your consent. If you decline, you can contact us through the other channels listed on our contact page.

    Legal basis: consent (GDPR Art. 6(1)(a); FADP Art. 31(1)). Data transmitted: IP address, device and browser information, interactions with the page (mouse movements, keystrokes), and an identifier stored in the browser.

    Google Ireland Limited, Ireland (Google reCAPTCHA)

    • Purpose: To protect the sales contact form from bots
    • Data processing location: European Union, United States
    • Safeguards for international transfers: Countries recognized as providing an adequate level of protection (European Union member states, Annex 1 of the General Data Protection Regulation); Google LLC’s certification under the EU–U.S. and Swiss–U.S. Data Privacy Frameworks; alternatively, standard contractual clauses

    Payment – only when placing an order

    Legal basis: performance of the contract (GDPR Art. 6(1)(b); FADP Art. 31(2)(a)). Data transmitted: name, amount, order or invoice number, and, depending on the payment method, card or account information.

    Checkout SAS (Checkout.com), France

    • Purpose: to process card payments (Visa, Mastercard) and 3-D Secure authentication
    • Data processing locations: European Union, United Kingdom; United States (Amazon Web Services hosting)
    • Safeguards for international transfers: Countries recognized as providing an adequate level of protection (European Union member states, the United Kingdom, Annex 1 of the GDPR); standard contractual clauses; for Amazon Web Services: Amazon.com, Inc.’s certification under the EU–U.S. and Swiss–U.S. Data Privacy Frameworks

    PayPal Group

    • Purpose: To process the payment when you select PayPal
    • Data processing location: Singapore or Luxembourg, depending on your country of residence; PayPal also processes data in the United States and other countries, under its own responsibility
    • Safeguards for international transfers: Singapore does not have an adequacy decision; the transfer of data, limited to transaction data, is directly related to and necessary for the performance of the contract you enter into with us by choosing this payment method (FADP Art. 17(1)(b); GDPR Art. 49(1)(b)). PayPal then processes your data under its own responsibility, in accordance with its privacy policy
    • Responsible entity: PayPal Pte. Ltd. (Singapore) for residents of Switzerland; PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) for residents of the European Economic Area; or the PayPal entity responsible for your country of residence
    • Data transmitted by Infomaniak: only transaction data (amount, currency, order reference); other data is collected directly by PayPal

    TWINT SA, Switzerland

    • Purpose: to process the payment via TWINT
    • Data processing location: Switzerland

    PostFinance AG, Switzerland

    • Purpose: Process the payment through PostFinance
    • Data processing location: Switzerland

    SIX BBS SA (eBill), Switzerland

    • Purpose: To submit invoices via eBill
    • Data processing location: Switzerland; Germany, Austria, France, Italy, Liechtenstein, Poland, United Kingdom
    • Safeguards for international transfers: Countries recognized as providing an adequate level of protection (European Union member states, Liechtenstein, the United Kingdom, Annex 1 of the GDPR)

    Account Security and Fraud Prevention – During Authentication or Payment

    Legal basis: performance of the contract and legitimate interest in protecting accounts and preventing fraud (GDPR Art. 6(1)(b) and (f); FADP Art. 31(1) and (2)(a)). Data transmitted: to Twilio, your phone number and the verification code; to MaxMind, your IP address.

    Twilio Inc., United States

    • Purpose: To send two-step verification and authentication text messages
    • Data processing location: United States, European Union; mobile carrier networks in the recipient's country
    • Safeguards for international data transfers: Twilio Inc.’s certification under the EU–U.S. and Switzerland–U.S. Data Privacy Frameworks; the Twilio Group’s binding corporate rules; and, in the alternative, standard contractual clauses

    MaxMind, Inc., United States

    • Purpose: To detect payment fraud by geolocating the IP address (GeoIP)
    • Data processing locations: United States, United Kingdom, Singapore; Cloudflare's global network
    • Safeguards for international data transfers: MaxMind, Inc.’s certification under the EU–U.S. and Swiss–U.S. Data Privacy Frameworks; standard contractual clauses for other countries

    Affiliation – only with your consent

    Legal basis: consent (GDPR Art. 6(1)(a); FADP Art. 31(1)). Data transmitted: a random identifier stored in a cookie; technical characteristics of the device and browser that allow it to be recognized, including across devices; pages viewed; referring site; and, in the case of an order, order reference and amount; IP address.

    AWIN AG, Germany

    • Purpose: To attribute orders to affiliate partners and calculate their commissions, including through its SingleView attribution technology (domains dwin1.com, roeye.com, and roeyecdn.com)
    • Location of data processing: European Union; other countries where the Awin Group and its service providers are located, including those outside the European Union
    • Safeguards for international transfers: Countries recognized as providing an adequate level of protection (European Union member states, Annex 1 of the GDPR); standard contractual clauses
    • Joint Responsibility: Infomaniak and Awin are jointly responsible for tracking and attributing orders. Infomaniak informs you and obtains your consent; Awin handles the technical tracking and is responsible for the processing it subsequently performs. The key terms of their agreement are set forth inthe “Awin Data Processing Addendum.” You may exercise your rights with Infomaniak or directly with Awin. Withdrawing your consent terminates tracking; Awin retains data from already-attributed transactions for up to three years, for the purpose of calculating and verifying commissions, based on its legitimate interest.

    Measuring the effectiveness of ads—only with your consent

    These third parties are only contacted if you accept the "Ads" or "Personalized Ads" categories. Their tracking pixels are only present on certain action pages, such as an order confirmation page.

    Legal basis: consent (GDPR Art. 6(1)(a); FADP Art. 31(1)). Data transmitted: conversion event, advertising identifiers stored in cookies, IP address, and browser information.

    We are responsible, either alone or jointly with the relevant partner, for collecting this data on our website and for transmitting it; each partner is solely responsible for the processing it subsequently performs, in accordance with its own privacy policy. You may exercise your rights by contacting Infomaniak or directly contacting the relevant partner.

    Google Ireland Limited, Ireland (Google Ads)

    • Purpose: To track ad conversions and, if you agree, to personalize ads
    • Data processing location: European Union, United States
    • Safeguards for international transfers: Countries recognized as providing an adequate level of protection (European Union member states, Annex 1 of the General Data Protection Regulation); Google LLC’s certification under the EU–U.S. and Swiss–U.S. Data Privacy Frameworks; alternatively, standard contractual clauses

    Meta Platforms Ireland Limited, Ireland (Meta Ads)

    • Purpose: To track ad conversions and, if you agree, to personalize ads
    • Data processing location: European Union, United States
    • Safeguards for international data transfers: Countries recognized as providing an adequate level of protection (European Union member states, Annex 1 of the GDPR); Meta Platforms, Inc.’s certification under the EU–U.S. and Swiss–U.S. Data Privacy Frameworks; alternatively, standard contractual clauses
    • Joint Liability: The key provisions of the agreement are set forth inMeta's"Addendum Regarding Data Controllers."

    LinkedIn Ireland Unlimited Company, Ireland (LinkedIn Ads)

    • Purpose: To track ad conversions and, if you agree, to personalize ads
    • Data processing location: European Union, United States
    • Safeguards for international data transfers: Countries recognized as providing an adequate level of protection (European Union member states, Annex 1 of the GDPR); LinkedIn Corporation’s certification under the EU–U.S. and Swiss–U.S. Data Privacy Frameworks; alternatively, standard contractual clauses

    Microsoft Ireland Operations Limited, Ireland (Microsoft Advertising)

    • Purpose: To track ad conversions and, if you agree, to personalize ads
    • Data processing location: European Union, United States
    • Safeguards for international data transfers: Countries recognized as providing an adequate level of protection (European Union member states, Annex 1 of the GDPR); Microsoft Corporation’s certification under the EU–U.S. and Switzerland–U.S. Data Privacy Frameworks; alternatively, standard contractual clauses

    X Internet Unlimited Company, Ireland (X Ads)

    • Purpose: To track ad conversions and, if you agree, to personalize ads
    • Data processing location: European Union, United States
    • Safeguards for international transfers: Countries recognized as providing an adequate level of protection (European Union member states, Annex 1 of the GDPR); X Corp.’s certification under the EU–U.S. and Swiss–U.S. Data Privacy Frameworks; alternatively, standard contractual clauses

    Other categories of recipients

    • Domain name registries, ICANN-designated data repositories, and SSL certificate authorities, depending on the product ordered: name, mailing address, email address, and phone number of the domain holder and domain contacts. These organizations are located worldwide depending on the chosen domain extension (for example, in the United States for .com domains); this disclosure is directly related to and necessary for the performance of the contract entered into with you (FADP Art. 17(1)(b); GDPR Art. 49(1)(b)).
    • Banks, card networks, and issuers involved in processing your payments.
    • Subcontractors specific to certain services (for example, spam filtering for the Mail Service or the distribution of newsletters): they are listed in the “Third-Party Subcontractors” appendix of our Data Processing Agreement (DPA).
    • Companies within the Infomaniak Group, all of which are based in Switzerland, for the purposes described in this policy.
    • Survey companies, when we collect your feedback on our services.
    • Authorities, upon a request that is valid under Swiss law.

    Transfer of Data Abroad

    The member states of the European Union, Liechtenstein, and the United Kingdom provide a level of data protection recognized as adequate by the Federal Council (Annex 1 of the OPDo). Transfers to the United States are made to companies certified under the Swiss-U.S. Data Privacy Framework and the EU-U.S. Data Privacy Framework, which are recognized as providing an adequate level of protection by the Federal Council and the European Commission, respectively. Otherwise, they are covered by the European Commission’s Standard Contractual Clauses, as adapted to Swiss law. When a recipient is located in another country that does not benefit from an adequacy decision (for example, Singapore or, for domain name registries, the country of the relevant registry), the transfer is based on these same clauses or is directly related to the performance of the contract entered into with you and necessary for that purpose (FADP Art. 17(1)(b); GDPR Art. 49(1)(b)). You can obtain a copy of these safeguards by writing to dpo@infomaniak.com.

    Withdrawal of Consent

    You can modify or withdraw your consent to Google reCAPTCHA, audience measurement, affiliate marketing, and ad effectiveness measurement at any time using the cookie management button on each page. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

  • You have control over your personal information. See your choices about the data we collect to find out more.

  • We provide you with tools to control your account information as well as information on how it is used. Access your user account or contact us to:
    • Display and update your account information, such as your name, phone number and billing address;
    • View and update your contact preferences to receive messages about Infomaniak's account and products;
    • Display and update Whois information for your domain names registered through us.
    You can also unsubscribe from our marketing communications by clicking on the unsubscribe link at the bottom of each of our emails, with the exception of messages concerning technical interventions or the evolution of your products.

  • You may request that your account be closed if the following conditions are met:
    • All products and services must be terminated by you via your Manager before the account is closed. If the account still contains active products or services, the account cannot be closed;
    • Your prepaid account balance must be zero. If necessary, you can request that the remaining balance be refunded to the bank account of your choice;
    • The request can only be granted to the extent that your data is no longer necessary for the services you purchased, nor is it necessary to comply with a legal retention obligation or to establish, exercise, or defend legal rights.
    When you close your account, you may request that your personal data be deleted. Please note that it may take up to 30 days to delete all data associated with your account. Unless you specifically request otherwise, Infomaniak deletes your data six months after your account is closed, with the exception of data that we are required by law to retain, such as accounting records, which must be kept for ten years. You will no longer be able to access your account or your payment history once it has been deleted.

  • You can ask us for a copy of your personal data in electronic format, which you can pass on to other service providers if you wish. We will respond to your request within 30 days, providing you with a link enabling you to retrieve your data easily.

  • Here are some of the ways we help you protect your identity and personal data:
    • We encrypt the personal data you send us via online forms using the very latest encryption technologies to prevent anyone from intercepting your information.
    • We give you the option of strengthening the security of your user account with two-step verification.

  • Infomaniak cannot guarantee the security of your personal data without your cooperation. We recommend that you follow the recommendations below to best protect your personal data:
    • Use different, complex passwords for each of your services.
    • Never share your passwords.
    • Log out of your user account when using a computer you share with other people.
    • Modify your account password at least once a year.
    • Enable two-step verification on your user account.
    • Install a recognised antivirus software on your computer.

  • How is data processed when synchronising, backing up, importing or migrating data from an external service?

    As part of our productivity solutions, users can synchronise, back up or import data from services external to Infomaniak.

    Infomaniak Sync (kSync)

    As part of our productivity solutions, users can synchronise, back up or import data from services external to Infomaniak.

    What personal data does Infomaniak collect about me and for what purpose?

    When using this application, the following personal data is collected:
    • User's Infomaniak login credentials
      • Email address for connection
      • Log-in password
    • Address books stored on Infomaniak Mail (optional)
    • Diaries stored on Infomaniak Mail (optional)
    • User device localisation (optional)

    Use of your personal data

    The application uses this data exclusively for this purpose:
    • Login credentials: these are used to connect to an existing Infomaniak customer account, from which synchronisation will be performed.
    • Address books: customers can synchronise address books saved on Infomaniak Mail associated with the login credentials used.
    • Diaries: customers can synchronise diaries saved on Infomaniak Mail, associated with the connection credentials used.
    • Localisation: when the customer activates the 'Wi-Fi synchronisation only' option (account settings in the application) and wishes to restrict access to one or more Wi-Fi access points (SSIDs), localisation must be enabled. This option retrieves the Wi-Fi (SSID) to which the device is connected and compares it with the list of authorised Wi-Fi access points (SSIDs). If the network used is on the list, the application will synchronise the diary(ies) and / or address book(s) on the device.

    How is your personal data shared?

    The synchronisation of calendars and / or address books implies that events and contacts are available for consultation on the final device or application and are therefore subject to the conditions of use of the device and the native or third-party applications used.

    Infomaniac Check (kCheck)

    Infomaniak kCheck is an application that allows the user to securely transmit the elements required to perform security checks. When the user receives a request for identity verification (please refer to the specific terms and conditions for the different reasons), he or she is invited either to download the application or to use it if it is already installed on the device. All personal data transmitted as part of an identity verification request are kept for the time of processing, and for a maximum of 72 hours if the request is not finalised by the user. Data is automatically deleted from our servers 24 hours after processing. Once the procedure has been completed, the user can delete the application.

    What personal data does Infomaniak collect about me and for what purpose?

    The application collects personal data for the purpose of checking the identity of the person following the procedure. Depending on the nature of the procedure, the following information may be collected:
    • Mobile phone number: requested during the procedure.
    • Geolocation: requested during the procedure via the device's GPS.
    • Identity documents: passport, identity card or driver's licence (depending on the legislation in force in the user's country) are photographed via the application.
    • Selfie: users can be asked to take a selfie by holding their ID close to their face via the application.

    How is your personal data used?

    Personal data is used as follows:
    • Mobile phone number: used to send a verification code via text message for accounts that have this feature activated. The country code is used to cross-reference data with geolocation information.
    • Geolocation: used to cross-reference data with the telephone number code.
    • Identity documents: used to verify the user's identity.
    • Selfie: used for user identification.
    Legal basis: our legitimate interest and that of our customers in preventing identity theft and fraudulent access to accounts (GDPR Art. 6(1)(f); FADP Art. 31(1)). The comparison between the selfie and the ID document is performed by a member of our support team, without automated facial recognition.

    How is your personal data shared?

    With the exception of the phone number, which is shared with our SMS service provider to send the verification code (see “Does Infomaniak share my data with third parties?”), this data is processed by our support team and is not shared with any third parties.

    Synchronise, backup or migrate emails, contacts, appointments or documents from third-party services

    Infomaniak allows you to import, back up, or sync data from other providers, such as Google Drive, Dropbox, and Gmail. When performing an operation involving another provider, such as Gmail, you may need to log in to your account via OAuth. Infomaniak’s use and transfer of information received from Google APIs to any other application is in compliance with the Google API Services User Data Policy, including the Limited Use requirements.

    How is your personal data used?

    Personal data is processed securely and used exclusively for the purpose of migrating or restoring the data selected by the user. The imported data is not used for any other purpose (such as marketing) and is not disclosed to any third parties. Personal data is retained for the period necessary to achieve the aims described in this confidentiality policy. When the data retention period expires, we delete the data. Any connection to third-party services is then terminated.

  • In accordance with the Federal Data Protection Act (FDPA) and, where applicable, the General Data Protection Regulation (GDPR), you have the following rights:

    • access your data and receive a copy of it;
    • have your information corrected;
    • have your data deleted;
    • to have the processing of their personal data restricted;
    • have your data returned to you or transferred to a third party (data portability);
    • object to processing based on our legitimate interest and, at any time and for any reason, to commercial solicitation;
    • withdraw your consent at any time, without retroactive effect;
    • not be subject to a fully automated decision (GDPR) or request that it be reviewed by a person (LPD).
    These rights may generally be exercised free of charge by writing to dpo@infomaniak.com; we will respond within 30 days, a period that may be extended in cases provided for by law. Our dedicated guide describes the practical procedures.

    If you believe that the processing of your data does not comply with applicable law, you may contact the Federal Data Protection and Information Commissioner (FDPIC, Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch). If you reside in the European Economic Area, you may file a complaint with the supervisory authority in your country of residence, your place of work, or the location of the alleged violation.


This page always shows the latest version of our confidentiality policy. If you have any questions, please contact us.

This privacy policy was updated on September 18, 2026.