Security and Privacy Policy » History » Version 4
Nico Schottelius, 02/05/2020 09:35 AM
1 | 1 | Nico Schottelius | h1. Security and Privacy Policy |
---|---|---|---|
2 | |||
3 | 2 | Nico Schottelius | {{toc}} |
4 | |||
5 | 1 | Nico Schottelius | h2. Status |
6 | |||
7 | This document is **PRE PRODUCTION** |
||
8 | |||
9 | h2. Introduction |
||
10 | |||
11 | The following chapters describe our policy in regards to security and privacy concerns. |
||
12 | 4 | Nico Schottelius | This document is kept simple and short with the intention of being easy to understand. |
13 | 1 | Nico Schottelius | |
14 | |||
15 | 3 | Nico Schottelius | h2. Logging only the necessary |
16 | 1 | Nico Schottelius | |
17 | Logs are taken only where necessary and kept only as long as relevant to operation procedure. |
||
18 | Specifically network traffic **content** is not logged. |
||
19 | |||
20 | h2. Non disclosure |
||
21 | |||
22 | No information is given to the public about our customers or customer use cases. |
||
23 | An exception to this is prior public information or explicit consent from the customer. |
||
24 | |||
25 | h2. Acting by Swiss law |
||
26 | |||
27 | According to Swiss laws, the **only** authority that is allowed to request network access |
||
28 | is the "PTSS":https://www.li.admin.ch/en . It may only request access after a Swiss court ruling and only for |
||
29 | cases that violate Swiss law. |
||
30 | |||
31 | h2. Access to data or network traffic from foreign entities |
||
32 | |||
33 | No access is granted. |
||
34 | |||
35 | h2. Access to data or network traffic from domestic entities |
||
36 | |||
37 | Access to our infrastructure is granted based on Swiss laws and requires a Swiss court order. |
||
38 | |||
39 | h2. Access to data or network traffic from our staff |
||
40 | |||
41 | For operational activities staff members can and will investigate network traffic to ensure the stability of our platform. |
||
42 | Access to customer specific data is strictly forbidden. |
||
43 | |||
44 | An exception to above rule is if the customer specifically granted permission for it. |