1. Controller and scope
The service operator shown below is the controller for the A2Trust website, free checks, customer area, orders, support and direct client communication.
Swiss data protection law, including the Federal Act on Data Protection (Swiss FADP), is the primary framework. The EU or UK GDPR also applies where its territorial scope is met.
Where A2Trust handles personal data solely on a business customer's documented instructions for a paid report, the Data Processing Terms also apply.
2. Information we collect
We may collect the submitted website, business email, language, answers, public scan evidence, screenshots, account and order history, package scope, billing references, tax status, report files, feedback and support messages.
Security and service records can include timestamps, page or event paths, browser information and limited diagnostic data. Optional analytics identifiers are created only after consent.
3. Where information comes from
Information comes from you, the public website and public technical or search signals. For deeper reports, you may optionally provide exports or viewing access to search, analytics, advertising, local-profile, domain or content tools.
A2Trust does not ask for passwords, recovery codes, payment-card details or unrestricted administrator credentials.
4. Purposes and legal grounds
We process information to answer a requested check, take steps before a contract, perform and deliver an order, provide the client area and support, prevent abuse, maintain security, meet accounting duties and defend legal claims.
Depending on the activity, the legal ground is performance of a contract or pre-contract steps, a legal obligation, our legitimate interest in a reliable and improved B2B service, or consent for optional analytics and marketing.
5. Email and product feedback
Submitting a free check sends the requested result and secure access link. It does not add the address to a newsletter. Necessary messages about an order, account, evidence request, delivery or support are service communications.
A promotional reminder or marketing sequence is sent only after a separate, informed choice. A private product survey may be offered; honest positive and negative feedback is treated equally and is not published without permission.
6. Service providers and recipients
We use carefully selected providers where needed: Hetzner for hosting and email infrastructure, Stripe for payment, invoicing and tax calculation, and Google services for optional analytics or customer-authorised integrations. Optional advertising tags from Google, Meta or LinkedIn run only when configured and consented to.
Information may also be shared with professional advisers, authorities or courts where necessary. Providers receive only what is needed for their role and are bound by contractual and security obligations.
7. International transfers
Core hosting and email are operated in Europe. Some global providers may process information in Switzerland, the EEA, the United States or other countries where they operate.
Where a destination does not offer recognised adequate protection, we rely on an approved safeguard such as contractual clauses, an applicable certification framework or another lawful exception, and assess the transfer as required.
8. Retention
We retain checks, customer-area records and reports only while needed for delivery, account continuity, quality, security and legitimate business administration, then delete or anonymise them when they are no longer required.
Invoices, payment and accounting records may be retained for the statutory period, generally up to ten years in Switzerland. A valid legal hold or dispute may require longer retention.
9. Automated analysis
The free check uses automated rules to analyse public signals and produce a preliminary score. It is an informational diagnosis, not a decision with legal or similarly significant effect.
Paid reports can add human review. You can contact us if a result appears inaccurate or needs context.
10. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent for future processing. We may need to verify the request and may retain information where law requires it.
You may also complain to the Swiss Federal Data Protection and Information Commissioner or the competent supervisory authority where you live or work.
11. Security and contact
We use access controls, limited permissions, encrypted transport, backups and operational monitoring appropriate to the service. No online service can promise absolute security.
Send privacy requests to the contact below. Please do not include passwords, recovery codes or unnecessary sensitive information.
Service operator
A2Trust is the commercial service name used for this product.
- A2Trust
- A2Arch Sàrl
- Swiss UID
- CHE-458.958.276
- Swiss VAT number
- CHE-458.958.276 MWST
- Registered address
- Rue Neuve 14, 1260 Nyon, Switzerland
- Legal and privacy contact
- desk@a2trust.ch