Data Protection Impact Assessment (DPIA)
Pursuant to Art. 22 nDSG | Version 1.1 | June 2026
1. Subject matter
This Data Protection Impact Assessment (DPIA) documents the risks and protective measures in the processing of personal data by Clino. This particularly concerns the processing of AHV numbers (personal identification numbers whose systematic use is restricted by law, Art. 153b et seq. AHVG; we treat them like particularly sensitive personal data) and payroll data of household employees.
2. Personal data processed
| Category | Data | Legal basis |
|---|---|---|
| Employer data | Name, address, email, phone | Performance of contract (Art. 31 para. 2 lit. a nDSG) |
| Employee data | Name, date of birth, nationality, residence permit | Legitimate interest + legal obligation (AHVG) |
| AHV number | Personal identification number (Art. 153b et seq. AHVG) — treated like particularly sensitive personal data | Performance of contract + statutory employer obligations (AHVG) |
| Payroll data | Gross/net, social deductions, working hours | Performance of contract + statutory retention (CO Art. 957–958f / DBG Art. 126) |
| Payment data | Stored at Stripe (PCI DSS) | Performance of contract |
3. Data flow
Employer (browser)
│ TLS 1.3 encrypted
▼
Cloudflare (CDN/DDoS protection, global) — IP addresses in transit
▼
Vercel (hosting + server-side PDF generation, EU/USA)
│
├── Supabase (database, Zurich) — AHV encrypted via pgcrypto
├── Stripe Payments Europe Ltd. (payment, Ireland) — PCI DSS Level 1
├── Resend (email, USA) — email addresses, names; payslips as PDF attachments at the user's request, no AHV numbers
├── Google Ireland (analytics/advertising) — pseudonymous usage data, no AHV/payroll data
└── DeepL SE (CV tool translation, Cologne/EU) — CV tool input only
PDF generation: server-side (Vercel) — payslip, contract, annual overview, AK form, certificate; delivered via TLS, no permanent storage
Demo mode: localStorage only, no server contact
4. Risk assessment
| Risk | Before measures | Protective measure | Residual risk |
|---|---|---|---|
| Unauthorised access to AHV numbers | Medium | Encryption, RLS, auth, rate limiting, audit | Low |
| Database breach | Medium | pgcrypto field-level encryption, RLS, audit trail | Low |
| Identity misuse | Low | Encryption + masking in UI | Very low |
| Unencrypted transmission | Low | TLS 1.3, HSTS | Very low |
| Sub-processor access | Low | DPAs, no AHV in emails | Very low |
| Data loss | Low | Supabase backups, complete deletion routine | Very low |
| PDF sharing by users | Medium | Confidentiality footer on all PDFs | Low |
| Third-country transfer (USA) | Low | SCCs, no sensitive data via email | Low |
| Tracking via analytics/advertising | Low | IP anonymisation, no direct identifiers in the Measurement Protocol, opt-out available | Very low |
5. Technical protective measures
- ●AHV encryption: Field-level encryption in the database (pgcrypto). Separate key as environment variable, not in source code.
- ●AHV masking: The user interface shows only 756.XXXX.XXXX.90. The full number appears only in generated PDFs.
- ●Row-level security: Each employer can only see their own data. Enforced at database level (Supabase RLS).
- ●Authentication: JWT-based with server-side validation. Email verification mandatory.
- ●Transport encryption: TLS 1.3 on all connections. HSTS enabled.
- ●Security headers: Content Security Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff.
- ●Input validation: All API endpoints with schema validation (Zod). Rate limiting on sensitive routes.
- ●Audit trail: Automatic logging of all changes to employer, employee, and payroll data.
- ●Consent tracking: Timestamp and IP address of AHV consent are stored.
6. Data processors
| Provider | Location | Purpose | Sensitive data? |
|---|---|---|---|
| Supabase | Zurich, Switzerland | Database, authentication | Yes (AHV encrypted) |
| Vercel | EU/USA | Hosting, serverless functions, server-side PDF generation | Yes (payroll and contract data during PDF generation, no permanent storage) |
| Stripe Payments Europe Ltd. | Ireland | Payment processing | No (payment data only) |
| Resend | USA | Transactional emails | Partially (email addresses, names; payslips as PDF attachments at the user's request — no AHV numbers) |
| Google Ireland Ltd. | Ireland/USA | Web analytics and advertising (GA4, Google Ads) | No (pseudonymous usage data) |
| Cloudflare Inc. | USA/global | Content delivery, DDoS protection | Transit (IP addresses, connection data) |
| DeepL SE | Cologne, EU | Automatic translation (CV tool) | No (CV text input only) |
7. Result
Residual risk: Low
The processing of AHV numbers and payroll data by Clino is protected with appropriate technical and organisational measures. The remaining risk is low. Consultation with the FDPIC pursuant to Art. 23 nDSG is not required.
8. Planned improvements
- Two-factor authentication (2FA) for employer accounts (Q3 2026)
- Automatic data deletion after the retention period expires (Q3 2026)
- Annual review of this DPIA (next: June 2027)
9. Contact
For questions about this Data Protection Impact Assessment or data protection at Clino, please contact: datenschutz@clino.ch
Version 1.1 — June 2026

Ready? First payslip in 5 minutes.
Start for free