Available only in Switzerland

Schweizerform is currently available exclusively for users in Switzerland. Account creation from your region is restricted.
Legal

Privacy Policy

Last Updated: 6 September 2026

1. Introduction

Schweizerform ("we", "us", "our") operates the Schweizerform platform — a Swiss-made, end-to-end encrypted form building service. This Privacy Policy explains how we collect, use, store, and protect your information when you use our platform.

We are committed to protecting your privacy through our zero-knowledge architecture. This means that the majority of data you process through Schweizerform is encrypted in your browser before it reaches our servers, and we are technically unable to access it.

2. Zero-Knowledge Architecture

Schweizerform uses a zero-knowledge, end-to-end encryption model. This is not merely a feature — it is the foundation of our platform. Here is what this means for your data:

  • Form Responses: All form submission data is encrypted in the respondent's browser using AES-256-GCM encryption before being transmitted to our servers. We store only encrypted blobs that we cannot decrypt.
  • File Attachments: Uploaded files are encrypted client-side before upload. Original file names are replaced with randomised identifiers on our servers.
  • Vault Key: Your master key is derived in your browser from your vault key using PBKDF2-HMAC-SHA256 with 600,000 iterations and an individual salt. Your vault key is at no time transmitted to or stored on Schweizerform's systems, and the master key exists in clear only in your browser's memory. In addition, we store a copy of your master key encrypted with your recovery code, so that you can regain access with that code. The recovery code itself is never transmitted to or stored by us, so this copy is of no use to Schweizerform.
  • Encryption Keys: RSA private keys and form-level AES keys are encrypted with your master key before storage. We store only encrypted key material.

3. Information We Collect

3.1 Account Information

When you create an account, we collect your email address and your full name. These are used for account authentication, password recovery, and service-related communications. We do not collect your postal address, telephone number, or payment details during registration.

3.2 Form Metadata

We store form metadata necessary for the operation of the service, including form titles, creation dates, status information, scheduling settings, and submission counts. Form response content is always encrypted and inaccessible to us.

3.3 Subscription & Billing

Payment processing is handled entirely by our contracting entity Stripe Payments Europe, Ltd., Dublin, Ireland. Stripe Payments Europe, Ltd. may pass payment data on within the Stripe group to Stripe, LLC (USA), which is certified under the Swiss–U.S. Data Privacy Framework; Annex 1 of the Swiss Data Protection Ordinance recognises certified recipients in the USA as providing adequate protection. Where that framework does not apply, Stripe's data processing addendum relies on the standard contractual clauses of the European Commission. We do not receive or store your credit card number. We receive from Stripe only a customer identifier, subscription status, plan details, and billing cycle information necessary to manage your subscription.

3.4 Analytics Data

We collect a limited amount of analytics data to improve our service. On our own website and application pages we record page views, a session identifier derived from browser characteristics without cookies, device type, and country. That identifier is pseudonymous, not anonymous, and we treat it accordingly. We do not use any third-party analytics, advertising, or tracking services, and all analytics data is stored in our own Swiss infrastructure. On public form pages, none of this applies: there is no analytics session, no browser fingerprint, no country evaluation, and no third-party analytics, advertising, or tracking service. For public forms we keep: per-form, per-day aggregate counters (the number of views, the number of submissions, the device class — desktop, mobile, or tablet — and the access channel, link or QR code); per-question aggregate counters (how often a question was shown and how often it was answered); and, for each submission, the time taken to fill in the form, the number of questions, the number answered, the total stored size of the submission (the encrypted answers plus any encrypted attachments), and the display language used. The device class is derived on our server at the time of submission from the user agent; the user agent itself is not stored. The aggregate counters are never cross-tabulated with one another, with individual questions, or with individual submissions. They are deleted together with the form. The identifier is kept in your browser's sessionStorage only for the duration of your visit and is deleted when you close the tab; we do not recognise you across separate visits. When you sign in, usage recorded during that same visit is associated with your account.

3.5 Technical Data

When you use the platform, we may collect technical data necessary for service delivery, including session tokens (stored as HTTP-only cookies), CSRF tokens, language preferences, and error logs. Error logs are sanitised to exclude any sensitive or personally identifying information.

3.6 Automatic Translation & Submitted Language

If you, as a form owner, enable automatic translation on a form, the form's own content that you authored — question text, options, and labels — is sent to Infomaniak AI Services and processed end-to-end in Switzerland to generate translated versions. No respondent or submission data is ever involved in this process. When a respondent submits a form, we also record the language their interface was displayed in — a bounded, anonymous value — as part of our aggregate, non-identifying analytics.

4. How We Use Your Information

We use the information we collect exclusively for the following purposes:

  • To operate and maintain the Schweizerform platform
  • To authenticate your identity and manage your account
  • To process subscription payments via Stripe
  • To send service-related communications (e.g., password recovery, subscription confirmations, notifications about activity on your own forms)
  • To improve our service based on aggregate and pseudonymous analytics
  • To diagnose and resolve technical issues using sanitised error logs

We do not sell, rent, or share your personal information with third parties for marketing purposes. We do not use your data for advertising or profiling.

As an account holder, you may occasionally receive emails from us about new features, improvements and platform announcements. Every such email contains an unsubscribe link, and unsubscribing takes effect immediately. Emails about your account and its security — sign-in codes, password resets, billing and the notifications you switch on for your own forms — are necessary to provide the service and are sent for as long as your account exists.

5. Cookies & Local Storage

Schweizerform uses the following client-side storage mechanisms:

  • Session Cookie: An HTTP-only, secure session cookie authenticates you. It lasts up to 30 days and is renewed as you keep using the app; a separate, configurable inactivity timer (2 hours by default) signs this browser out and clears your vault from its memory. Your other devices and sessions are unaffected.
  • CSRF Token Cookie: A cookie containing a CSRF token is used to prevent cross-site request forgery attacks.
  • Local Storage: If you choose to save your vault key locally, an encrypted version is stored in your browser's localStorage. The encryption key is a non-extractable CryptoKey stored in IndexedDB. Your plaintext vault key is never stored.
  • Language Preference: Your selected language is stored locally for consistent user experience.
  • Country Cookie: A functional cookie caches the country we resolve for your connection so we don't re-check it on every page. It is used only to enforce that sign-up is limited to Switzerland — never for tracking or advertising.
  • Analytics Session Identifier: A pseudonymous identifier for our own audience statistics is kept in sessionStorage for the duration of your visit and deleted when you close the tab. It never persists across visits, no third party receives it, and it is not used on public form pages.

We do not use advertising cookies, tracking cookies, or third-party analytics cookies.

6. Data Sharing

We share your information only as described below, strictly as necessary for operating the Service:

  • Stripe Payments Europe, Ltd. (Ireland): For payment processing. Our contracting entity is Stripe Payments Europe, Ltd., Dublin, Ireland; it processes your payment details directly — we never receive your full card information. Stripe may pass payment data on within its group to Stripe, LLC (USA), which is certified under the Swiss–U.S. Data Privacy Framework; where that framework does not apply, Stripe's data processing addendum relies on the standard contractual clauses of the European Commission.
  • Infrastructure Providers (hosting, storage, and transactional e-mail delivery): Our hosting and storage providers, located exclusively in Switzerland for hosting and storage, store encrypted data on our behalf and deliver our transactional e-mails. This item covers hosting, storage, and the sending of transactional e-mail. They do not have access to encryption keys and cannot decrypt any user data.
  • Infomaniak AI Services (optional): If you enable automatic form translation, the text content of your form is sent to Infomaniak's AI Services — processed exclusively in Switzerland — solely to produce translations. If you use AI form creation, the prompt you type is likewise sent to Infomaniak's AI Services in Switzerland, only to draft a form for you. In both cases, respondent answers and submission content are never sent.
  • Team Workspaces (if you create or join one): Forms, submissions, tags, and profiles inside a workspace are shared with its other members according to their role (owner, admin, member, or viewer). This data stays end-to-end encrypted — each member holds the workspace key wrapped to their own keys — and is never shared outside the workspace. The workspace owner acts as the data controller for its content.
  • Bjørnerås Labs (service «EuSend»), Org. no. 938 162 336, Norway: We use this provider to send transactional e-mails (one-time codes, account and invitation messages, and notifications about activity on your own forms). It processes the recipient address, the subject, and the message content. Message content is processed and stored exclusively on EEA infrastructure in Germany and Finland. The provider deletes its send logs, including rendered message bodies, after 30 days. It never receives form submissions or respondents' answers.

Apart from the recipients listed above, we do not sell, rent, or share your personal information with third parties, and we never share it for marketing or advertising purposes. We disclose information beyond the above only where Swiss law requires it. Even in such cases, our zero-knowledge architecture means we can only provide encrypted data that we cannot decrypt.

7. Data Retention

We retain your account data and associated encrypted form data for as long as your account remains active. If you delete your account, all personal data, form data, encrypted submissions, and associated files are permanently deleted from our systems; deletion through the self-service function takes effect immediately and irreversibly, so please complete any exports beforehand. Our database is backed up daily by our infrastructure provider in Switzerland with a rolling seven-day retention; deleted data is normally overwritten in backups within eight days, and in any event within 30 days.

Specific retention periods apply to our operational records: the IP address and user agent stored with an audit-log entry are automatically removed after 90 days, while the event entry itself is retained; e-mail send-log entries, including the rendered message content, are deleted after 90 days. Both are enforced by an automatic recurring process. The per-form, per-day aggregate counters described in section 3.4 contain no personal data — they are integer totals per form and per day — and are deleted together with the form itself. The measurement data of our marketing and application pages described in section 3.4 is pseudonymous, not anonymous, and is kept only for as long as it is needed for statistical evaluation.

8. Your Rights

Under Swiss data protection law (nFADP) and applicable regulations, you have the following rights:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate personal data.
  • Right to Deletion: Request deletion of your account and all associated data.
  • Right to Data Portability: Request your data in a portable format. Note: encrypted form data can only be decrypted with your vault key.
  • Right to Object: Object to the processing of your data for specific purposes.
  • Right to Lodge a Complaint: Lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC / EDÖB / PFPDT / IFPDT), Feldeggweg 1, 3003 Bern, Switzerland.

To exercise any of these rights, please contact us at support@schweizerform.ch.

If a breach of data security occurs that is likely to result in a high risk to your personality or your fundamental rights, we will notify the Federal Data Protection and Information Commissioner as soon as possible, and we will inform you where that is necessary for your protection or where the Commissioner requires it, as provided by Art. 24 nFADP. Where you use Schweizerform to collect personal data through your own forms, you are the controller for that data and the duty to inform the people who fill in your forms is yours; our Data Processing Agreement governs how we support you in meeting it.

A notification under this section is made to comply with legal obligations and does not constitute an admission of fault or liability.

9. Swiss Data Protection Compliance

Schweizerform is governed by the Swiss Federal Act on Data Protection (nFADP), which came into effect on September 1, 2023. All form data, submissions, files, and our database are hosted exclusively in Switzerland with Infomaniak. Two processing operations take place abroad: payment processing in Ireland and the sending of transactional e-mail in the EEA (Norway, with processing in Germany and Finland). These countries are listed in Annex 1 of the Swiss Data Protection Ordinance as providing an adequate level of protection, so disclosure is permitted under Art. 16 para. 1 nFADP without additional safeguards. Our zero-knowledge architecture exceeds the data protection requirements set by Swiss federal law, as the majority of user data is encrypted in a way that prevents even the service operator from accessing it.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated policy on our website and updating the "Last Updated" date. Your continued use of the platform after changes constitutes acceptance of the updated policy.

11. Contact

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Balathanusan Jeyarasan, sole proprietorship trading as «Schweizerform»c/o ExpertFid & Audit SAChurerstrasse 1588808 PfäffikonSwitzerland

Email: support@schweizerform.ch

For personal data that we process on behalf of our customers, our data processing agreement applies.

Want to learn more about how we protect your data?