Skip to content

Privacy Policy

1. Responsible body

The party responsible for data processing is:
Salvador Jovells
Loogartenstrasse 17
8048 Zürich, Schweiz
E-Mail: datenschutz@clino.ch

2. Data we collect

In the course of providing our services, we process the following personal data:

Employer data

  • Name, address, postcode, city, canton
  • Email address, phone number
  • Payment details (for payment processing via Stripe)

Employee data

  • Name, date of birth, nationality
  • Residence permit (type B, C, L, etc.)
  • AHV number (personal identification number whose systematic use is restricted by law, Art. 153b et seq. AHVG; we treat it like particularly sensitive personal data)
  • Hourly wage, working days, holiday entitlement
  • Language

Payroll data

  • Gross/net salary, social deductions (AHV, ALV, UVG, withholding tax)
  • Working hours per month
  • Holiday compensation, employer contributions

3. Roles: employer and employee data

For the personal data of employees, the respective employer is the controller under data protection law. Clino processes this data as a processor within the meaning of Art. 9 nDSG, exclusively on the employer's instructions and for the provision of the Service. The employer is obliged to inform employees about the processing of their data. For the data of employers themselves and of website visitors, Clino is the controller.

4. Purpose of data processing

  • Calculation of payslips and social insurance contributions
  • Generation of employment contracts, payslips, and annual summaries (PDF)
  • Generation of AHV registration aids for cantonal compensation offices
  • Processing of subscription and payment
  • Improvement of the service and bug fixing

5. Legal basis

The processing is based on:

  • Performance of contract (Art. 31 para. 2 lit. a nDSG) — for the provision of the agreed service to the employer
  • Statutory employer obligations — employee data including the AHV number is processed to fulfil the employment contract and the employer's legal obligations (AHVG, UVG, CO), not on the basis of the employee's consent
  • Legal obligation — retention obligations pursuant to CO Art. 957–958f and DBG Art. 126 (10 years for business and payroll records)
  • Overriding private interest (Art. 31 para. 1 nDSG) — for web analytics, ad measurement, and improvement of the service (see section 11)

6. Handling of AHV numbers

The AHV number is a personal identification number whose systematic use is restricted by law (Art. 153b et seq. AHVG). We treat it like particularly sensitive personal data and take the following measures:

  • Encryption during storage in the database (field-level encryption)
  • Masked display in the user interface (only last digits visible)
  • Access control: only the respective employer can view their employees' AHV numbers
  • No disclosure to third parties except to competent authorities (compensation office) at the employer's instruction
  • Transmission exclusively via encrypted connections (TLS)

7. Retention and deletion

Payroll and business records are retained for 10 years in accordance with statutory retention obligations (CO Art. 957–958f and DBG Art. 126). After the retention period expires, the data is deleted. Account data (login) is deleted upon termination and after the payroll data retention period expires.

8. Data processors (sub-processors)

We use the following service providers:

  • Supabase Inc. — database hosting (region: Zurich, Switzerland)
  • Vercel Inc. — web hosting and server-side PDF generation (EU/USA)
  • Stripe Payments Europe Ltd. — payment processing (Ireland; PCI DSS certified)
  • Resend Inc. — transactional emails (USA). Email addresses, names, and — at the user's request — payslips as PDF attachments are transmitted. No AHV numbers.
  • Google Ireland Ltd. — web analytics and advertising (Ireland/USA; see section 11)
  • Cloudflare Inc. — content delivery and DDoS protection (USA/global) — processes IP addresses and connection data in transit
  • DeepL SE — automatic translation of user input in the CV tool (Cologne, EU)

Data processing agreements (DPAs) that meet the requirements of the nDSG have been or will be concluded with all processors.

9. Data transfer abroad

Where data is transferred to service providers based outside Switzerland — in particular to the USA and the EU/Ireland — we ensure adequate data protection through appropriate safeguards pursuant to Art. 16 et seq. nDSG (standard contractual clauses, adequate level of data protection according to the FDPIC country list).

10. Your rights

Under the nDSG, you have the following rights:

  • Right of access (Art. 25 nDSG) — you may request information about your stored data
  • Right to rectification (Art. 32 para. 1 nDSG) — you may request the correction of inaccurate data
  • Right to deletion (Art. 32 para. 2 lit. c nDSG) — you may request the deletion of your data, provided there is no statutory retention obligation
  • Data portability (Art. 28 nDSG) — you may request your data in a common electronic format
  • Right to object (Art. 30 et seq. nDSG) — you may object to a specific data processing at any time, in particular to processing for analytics and advertising purposes

To exercise your rights, contact us at datenschutz@clino.ch.

11. Cookies, analytics and advertising

We use Google Analytics 4 and Google Ads conversion tracking (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland). Cookies are set that enable an analysis of the use of our website. The IP address is anonymised.

For business-critical conversion events (successful registration, subscription), we additionally transmit pseudonymised signals (employer ID, transaction value) server-side to Google Analytics via the Measurement Protocol. No direct identifiers such as name, email address, or IP address are transmitted.

The legal basis is our overriding private interest in measuring and improving our service (Art. 31 para. 1 nDSG).

You can object to data collection at any time: via your browser's cookie settings, with the Google Analytics opt-out add-on or — for personalised advertising — at adssettings.google.com.

We also use technically necessary cookies (session, language setting, partner login). These are required for the operation of the Service.

12. Further offerings

We also process personal data in the following contexts:

  • Newsletter and leads: email address, name, and originating page — to inform you about Clino and for follow-up messages. Unsubscribe at any time via the link in every email.
  • Referral programme: referral codes and credits are assigned to the respective account.
  • Free certificate for cleaners: name, canton, and email address — for issuing the certificate. Here, Clino itself is the controller.
  • CV tool: input may be transmitted to DeepL SE (Cologne, EU) for automatic translation.

13. Data Protection Impact Assessment (DPIA)

Due to the processing of AHV numbers, a Data Protection Impact Assessment pursuant to Art. 22 nDSG was conducted. The result: the residual risk is low. The full DPIA is available at clino.ch/dsfa. The DPIA is reviewed annually or upon significant changes.

14. Right to file a complaint

You have the right to file a complaint with the competent supervisory authority:

Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, 3003 Bern
www.edoeb.admin.ch

Data Breach Notification

In the event of a data security breach that is likely to result in a high risk to the personality or fundamental rights of the data subject, we act in accordance with Art. 24 nFADP:

  • We report the breach to the FDPIC as soon as possible.
  • We inform affected individuals if necessary for their protection or if the FDPIC requires it.
  • We document the incident, the measures taken, and the decisions made.

Our internal processes ensure that data breaches are detected, assessed, and reported in a timely manner.

15. Changes

We reserve the right to amend this privacy policy at any time. The current version is always available on this page.

Last updated: June 2026

Ready? First payslip in 5 minutes.

Start for free