Skip to content

Data Protection Impact Assessment (DPIA)

Pursuant to Art. 22 nDSG | Version 1.1 | June 2026

1. Subject matter

This Data Protection Impact Assessment (DPIA) documents the risks and protective measures in the processing of personal data by Clino. This particularly concerns the processing of AHV numbers (personal identification numbers whose systematic use is restricted by law, Art. 153b et seq. AHVG; we treat them like particularly sensitive personal data) and payroll data of household employees.

Responsible body

Salvador Jovells, Loogartenstrasse 17, 8048 Zürich

E-Mail: datenschutz@clino.ch

2. Personal data processed

CategoryDataLegal basis
Employer dataName, address, email, phonePerformance of contract (Art. 31 para. 2 lit. a nDSG)
Employee dataName, date of birth, nationality, residence permitLegitimate interest + legal obligation (AHVG)
AHV numberPersonal identification number (Art. 153b et seq. AHVG) — treated like particularly sensitive personal dataPerformance of contract + statutory employer obligations (AHVG)
Payroll dataGross/net, social deductions, working hoursPerformance of contract + statutory retention (CO Art. 957–958f / DBG Art. 126)
Payment dataStored at Stripe (PCI DSS)Performance of contract

3. Data flow

Employer (browser)

│ TLS 1.3 encrypted

Cloudflare (CDN/DDoS protection, global) — IP addresses in transit

Vercel (hosting + server-side PDF generation, EU/USA)

├── Supabase (database, Zurich) — AHV encrypted via pgcrypto

├── Stripe Payments Europe Ltd. (payment, Ireland) — PCI DSS Level 1

├── Resend (email, USA) — email addresses, names; payslips as PDF attachments at the user's request, no AHV numbers

├── Google Ireland (analytics/advertising) — pseudonymous usage data, no AHV/payroll data

└── DeepL SE (CV tool translation, Cologne/EU) — CV tool input only

 

PDF generation: server-side (Vercel) — payslip, contract, annual overview, AK form, certificate; delivered via TLS, no permanent storage

Demo mode: localStorage only, no server contact

4. Risk assessment

RiskBefore measuresProtective measureResidual risk
Unauthorised access to AHV numbersMediumEncryption, RLS, auth, rate limiting, auditLow
Database breachMediumpgcrypto field-level encryption, RLS, audit trailLow
Identity misuseLowEncryption + masking in UIVery low
Unencrypted transmissionLowTLS 1.3, HSTSVery low
Sub-processor accessLowDPAs, no AHV in emailsVery low
Data lossLowSupabase backups, complete deletion routineVery low
PDF sharing by usersMediumConfidentiality footer on all PDFsLow
Third-country transfer (USA)LowSCCs, no sensitive data via emailLow
Tracking via analytics/advertisingLowIP anonymisation, no direct identifiers in the Measurement Protocol, opt-out availableVery low

5. Technical protective measures

  • AHV encryption: Field-level encryption in the database (pgcrypto). Separate key as environment variable, not in source code.
  • AHV masking: The user interface shows only 756.XXXX.XXXX.90. The full number appears only in generated PDFs.
  • Row-level security: Each employer can only see their own data. Enforced at database level (Supabase RLS).
  • Authentication: JWT-based with server-side validation. Email verification mandatory.
  • Transport encryption: TLS 1.3 on all connections. HSTS enabled.
  • Security headers: Content Security Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff.
  • Input validation: All API endpoints with schema validation (Zod). Rate limiting on sensitive routes.
  • Audit trail: Automatic logging of all changes to employer, employee, and payroll data.
  • Consent tracking: Timestamp and IP address of AHV consent are stored.

6. Data processors

ProviderLocationPurposeSensitive data?
SupabaseZurich, SwitzerlandDatabase, authenticationYes (AHV encrypted)
VercelEU/USAHosting, serverless functions, server-side PDF generationYes (payroll and contract data during PDF generation, no permanent storage)
Stripe Payments Europe Ltd.IrelandPayment processingNo (payment data only)
ResendUSATransactional emailsPartially (email addresses, names; payslips as PDF attachments at the user's request — no AHV numbers)
Google Ireland Ltd.Ireland/USAWeb analytics and advertising (GA4, Google Ads)No (pseudonymous usage data)
Cloudflare Inc.USA/globalContent delivery, DDoS protectionTransit (IP addresses, connection data)
DeepL SECologne, EUAutomatic translation (CV tool)No (CV text input only)

7. Result

Residual risk: Low

The processing of AHV numbers and payroll data by Clino is protected with appropriate technical and organisational measures. The remaining risk is low. Consultation with the FDPIC pursuant to Art. 23 nDSG is not required.

8. Planned improvements

  • Two-factor authentication (2FA) for employer accounts (Q3 2026)
  • Automatic data deletion after the retention period expires (Q3 2026)
  • Annual review of this DPIA (next: June 2027)

9. Contact

For questions about this Data Protection Impact Assessment or data protection at Clino, please contact: datenschutz@clino.ch

Version 1.1 — June 2026

Ready? First payslip in 5 minutes.

Start for free