Skip to content
Civena
Menu

Privacy policy

Last updated

This notice explains which personal data Civena processes, why, with whom it is shared and what rights you have under the Swiss Federal Act on Data Protection (FADP).

Controller

Controller for the processing described here: [to be completed by the operator: legal entity name, registered address, contact e-mail].

Data we process

Some of this can be sensitive personal data within the meaning of Art. 5 let. c FADP, for example data relating to administrative proceedings (such as residence-permit procedures), social assistance, or health information contained in a document you upload. Civena processes such data only to provide the service you request.

  • Account data: e-mail address, language, sign-in information.
  • Administrative profile: canton, commune, residence status and permit type, nationality group, civil status, household, employment situation, vehicle or property ownership — only the fields you provide or confirm.
  • Cases and actions: the life events you track, deadlines, notes and reference numbers you enter.
  • Documents you upload and the information extracted from them.
  • Messages you write to Civena and Civena’s answers.
  • Technical and usage data: security logs, error logs without content and — only with your consent — privacy-friendly usage statistics.

Purposes

  • Identifying which administrative procedures apply to you and explaining them.
  • Tracking cases, deadlines and reminders.
  • Storing and interpreting documents you upload.
  • Operating, securing and improving the service; preventing abuse.
  • Billing for paid plans.
  • Answering support requests.

Consent

AI-assisted interpretation of your messages and documents and product analytics are based on your choices at sign-up, which you can change at any time in Settings. Without AI consent, Civena still works with its rule engine and forms.

Recipients and processors

Civena uses the following service providers as processors, bound by contract to process data only on Civena’s instructions:

  • Supabase — database, authentication and private file storage.
  • Anthropic — AI language models for interpreting questions and documents.
  • Stripe — payment processing for paid plans.
  • PostHog (EU hosting) — product analytics, only with your consent.
  • Resend — sending e-mails such as reminders and sign-in links.

Disclosure abroad

Some processors are based in, or access data from, the United States. Under Annex 1 of the Data Protection Ordinance, the United States provides an adequate level of protection only for organisations certified under the Swiss-US Data Privacy Framework. Where a recipient is not certified, Civena relies on the standard contractual clauses recognised by the FDPIC (Art. 16 para. 2 FADP). Hosting regions: [to be completed by the operator].

AI processing

Before text is sent to an AI provider, direct identifiers the model does not need — AHV numbers, IBANs, card numbers, e-mail addresses, phone numbers — are removed. Civena does not use your data to train AI models. The contractual terms with AI providers regarding training and retention: [to be confirmed by the operator before launch].

Automated processing

Civena compares the facts in your profile with administrative rules to show which procedures may apply. This produces recommendations, not decisions with legal effect on you; decisions remain yours and the competent authorities’.

Retention

  • Account, profile, cases and messages: until you delete them or your account.
  • Documents: until you delete them, or until the retention period you set in Settings.
  • Security and usage logs (without content): up to 12 months.
  • Billing records: as long as Swiss law requires (generally 10 years for accounting records).

Your rights

You can request access to your data, correction, deletion and a copy in a common electronic format (data portability), and object to processing. Most of this is available directly in Settings (export, deletion, consent). Otherwise, contact us via the help page.

Security and breaches

Civena protects data with access control at database level, encryption in transit, private storage and audit logs. If a breach of data security is likely to result in a high risk for you, Civena notifies the Federal Data Protection and Information Commissioner (FDPIC) as quickly as possible and informs you where required.

Changes

We update this notice when processing changes. The date below shows the current version.