Privacy
Version dated 14 September 2026
This statement explains what data Inspectra processes, why, where it is held and what rights you have. It addresses Article 19 of the Swiss Federal Act on Data Protection (FADP) and, where the European regulation applies, Articles 13 and 14 of the GDPR.
1. Data controller
Gilles Monferini, sole proprietorship trading as “Inspectra”, Rue des Alpes 42, 1700 Fribourg, Switzerland — contact@inspectra.ch. The Service is aimed at the Swiss market; no representative under Article 27 GDPR has been designated.
2. Two distinct roles
Inspectra is the controller for its clients’ account and billing data.
For data its clients enter about their own clients, including owners, tenants, installers, addresses, phone numbers, EGIDs, findings and photographs, Inspectra acts as a processor. The inspection body decides on this processing and is responsible to the people concerned.
3. Website language and cookie
On your first visit, the language is selected from your browser settings: French, German, English or Italian, with French used for other languages. When you choose a language, the inspectra_language cookie remembers it for six months. It contains only fr, de, en or it and is used solely for your language preference. The language selector also works without cookies. This website uses no local storage, audience analytics or advertising trackers.
The server retains technical access logs, including IP address, date, requested page and browser, for 30 days solely for security and diagnostics.
Fonts are loaded from Google Fonts (fonts.googleapis.com, fonts.gstatic.com). This does not set a cookie, but it sends your IP address to Google LLC. No other data is transmitted and no profile is created.
4. Data processed in the application
- Account: name, email address, encrypted password, language, role in the organisation and inspector’s K number.
- Organisation: business name, address, settings, members, working hours and team absences.
- Inspection files: identity and contact details of people concerned by the installation, property address, EGID, meter number, findings, measurements, photographs and imported documents.
- Billing: quotations, invoices, credit notes and payment reconciliations from camt files uploaded by the client.
- Technical logs: authentication records, versions of validated reports and SHA-256 fingerprints.
5. Purposes and legal bases
- Providing the Service — performance of the contract.
- Billing and collecting payments — performance of the contract and statutory accounting retention obligations.
- Ensuring security — legitimate interest in preventing abuse and intrusion.
- Responding to support requests — performance of the contract.
- Ensuring the integrity of archived reports — performance of the contract and the parties’ legitimate interest in retaining evidence.
No data is sold, rented or shared for advertising purposes. No profiling or automated decision-making is performed.
6. Where data is held
Databases, files and archives are hosted on Google Cloud Platform (Firebase) in the europe-west6 region in Zurich. Backups remain in the same region.
7. Processors
- Google Cloud EMEA Limited (Ireland), for hosting, authentication, file storage and server functions. Data is stored in Zurich. Operational access from third countries remains possible and is governed by standard contractual clauses.
- Stripe Payments Europe Ltd (Ireland), for card payments. Inspectra neither sees nor stores card numbers.
- Infomaniak Network SA (Geneva, Switzerland), for hosting the public website. Servers are in Switzerland.
- Transactional emails for address verification and password resets are sent by Firebase Authentication (Google). No commercial email or newsletter service is used.
When an address is searched, a request is sent to the federal interface api3.geo.admin.ch to find the building’s EGID in the Federal Register of Buildings and Dwellings. The request contains the address being searched.
SMS reminders do not pass through a provider. The app prepares the message and opens it in the user’s phone messaging app. The user sends it from their own number. Inspectra does not transmit message content or phone numbers to a third party.
8. Cookies and storage in the application
The application uses an authentication token, essential to keep you signed in, and local storage in your browser for your personal findings library and display preferences. These are strictly necessary for operation and are not used for audience analytics or advertising. They therefore do not require consent.
9. Retention periods
- Account data and files: for the duration of the subscription, then one year after it ends.
- Accounting records: ten years, under Article 958f of the Swiss Code of Obligations.
- Technical access logs: 30 days.
- Support correspondence: 2 years.
10. Security
Data is encrypted in transit using TLS and at rest by the hosting infrastructure. Access to each organisation’s data is isolated and enforced on the server. Validated reports are server-locked and their integrity can be checked by fingerprint. Administrative access is limited to those who need it.
11. Your rights
You may request access to your data, correction, erasure, restriction of processing and delivery in a common format, and object to processing based on legitimate interests. Write to contact@inspectra.ch; proof of identity may be requested. You will receive a response within thirty days.
If you are a client of an inspection body and your data appears in a file, contact that body first: it decides on the processing. Inspectra will forward your request if it receives it directly.
You may also contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, or, if European law applies to you, the supervisory authority in your country.
12. Changes
This statement may be updated. The current version is the one published here with its date. Any material change is announced within the Service.