Skip to content
VynCo is in early access — some features may be unavailable.

Informativa sulla privacy

Ultimo aggiornamento: 4 marzo 2026

1. Panoramica

VynCo (“we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our platform at vynco.ch, including the dashboard, API, documentation, and related services (the “Service”).

This policy is provided in accordance with the Swiss Federal Data Protection Act (“nDSG” / Neues Datenschutzgesetz) as the primary legal framework. For users in the European Union, this policy also complies with Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

2. Titolare del trattamento

VynCo.com LLC (i.G.)

Uster, 8610, Switzerland

Email: privacy@vynco.ch

VynCo.com LLC (i.G.) is the data controller responsible for your personal data. For questions about this policy or our data practices, contact our Data Protection Officer (see Section 14).

This policy complies with the Swiss Federal Data Protection Act (nDSG) as our primary legal framework, supplemented by the EU General Data Protection Regulation (GDPR) for EU residents, and the Swiss Federal Act on Data Protection (FADP / DSG) requirements.

3. Dati raccolti

We collect the following categories of personal data:

3.1 Account Data

  • Full name, email address, and organization name
  • Password (stored as Argon2 hash; we never store plaintext passwords)
  • Account role and team membership information
  • Communication preferences

3.2 Usage Data

  • API request logs (endpoint, timestamp, response code, latency)
  • Credit consumption and generation job metadata
  • Dashboard interaction patterns (pages visited, features used)
  • Subscription tier and billing cycle information

3.3 Payment Data

  • Billing address and company details for invoicing
  • Payment method type and last four digits (full card details are processed and stored exclusively by Stripe; we never store full card numbers)
  • Transaction history and invoice records

3.4 Technical Data

  • IP address and approximate geolocation (country/region level)
  • Browser type, version, and operating system
  • Device identifiers and screen resolution
  • Referring URL and landing page

5. Come utilizziamo i suoi dati

  • To provision and maintain your account, API keys, and subscription
  • To process generation jobs and track credit consumption
  • To charge fees, process refunds, and generate invoices
  • To send transactional emails (account confirmations, billing receipts, security alerts)
  • To detect and prevent abuse, fraud, and unauthorized access
  • To improve the Service through aggregated, anonymized analytics
  • To provide customer support and respond to inquiries
  • To send marketing communications (only with your explicit opt-in consent)

6. Condivisione dei dati e terze parti

We do not sell your personal data. We share data only with the following categories of recipients, under appropriate data processing agreements:

ProviderPurposeData Shared
Microsoft AzureCloud infrastructure and hostingAll service data (encrypted at rest and in transit)
StripePayment processingBilling details, payment method, transaction amounts
SendGrid (Twilio)Transactional email deliveryEmail address, name, email content

We may also disclose personal data when required by law, legal process, or to protect the rights, property, or safety of VynCo, our users, or the public.

For a complete list of our sub-processors, see our Sub-processors List.

6.1 Attribuzione dei dati governativi aperti (OGD)

VynCo sources data from open government data (OGD) sources published by the Swiss authorities:

  • Zefix (Swiss Commercial Register): Maintained by the Federal Office of Justice (FOJ), providing company registration and structural information.
  • LINDAS (Linked Data Service): Operated by the Swiss Federal Statistical Office (FSO), providing linked data on Swiss entities in RDF format.

These data sources are public, published under open licenses, and do not contain personal data in the sense of data protection law. By using VynCo, you acknowledge that we source and may process information from these official Swiss government data registries.

7. Conservazione dei dati

Data CategoryRetention Period
Account dataDuration of account + 30 days after deletion
API request logs90 days (rolling)
Generation output data30 days after job completion (then purged)
Billing and transaction records7 years (legal/tax obligation)
Technical/analytics data24 months (anonymized after 12 months)
Support correspondence3 years after ticket resolution

8. I suoi diritti

Under GDPR and applicable data protection laws, you have the following rights regarding your personal data:

  1. Right of Access (Art. 15). You may request a copy of the personal data we hold about you.
  2. Right to Rectification (Art. 16). You may request correction of inaccurate or incomplete personal data.
  3. Right to Erasure (Art. 17). You may request deletion of your personal data, subject to legal retention obligations.
  4. Right to Restriction (Art. 18). You may request that we restrict processing of your data in certain circumstances.
  5. Right to Data Portability (Art. 20). You may request your data in a structured, commonly used, machine-readable format (JSON or CSV).
  6. Right to Object (Art. 21). You may object to processing based on legitimate interests, including direct marketing.
  7. Right to Withdraw Consent. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, email privacy@vynco.ch or use the self-service tools described below.

8.1 Come esercitare i suoi diritti

  • Self-service: Most rights can be exercised directly from your dashboard at Settings → Privacy.
  • Data export: Download all your data in JSON format from Settings → Privacy → Export Data.
  • Account deletion: Request full account deletion from Settings → Privacy → Delete Account. This permanently removes all personal data within 30 days.
  • API for rights: Use the DELETE /v1/account endpoint for programmatic account deletion.

8.2 Tempi di risposta

  • We respond to all data subject requests within 30 days of receipt.
  • Complex requests may take up to 60 days; we will notify you of any extension and the reasons for the delay within the initial 30-day period.
  • All requests are logged and tracked for compliance audit trail purposes.

8.3 Diritto di presentare reclamo

If you are unsatisfied with our response to a data subject request, you have the right to lodge a complaint with your local supervisory authority:

9. Cookie e tracciamento

We use browser localStorage for the following purposes:

CategoryPurposeClassificationConsent Required
Local StorageAuthentication tokens, session managementStrictly NecessaryNo
Local StorageUser preferences (theme, dashboard layout)FunctionalNo

We do not currently use any HTTP cookies, analytics tracking, or third-party advertising cookies. Authentication and preferences are stored using browser localStorage. For more details, see our Cookie Policy.

10. Trasferimenti internazionali

Our primary infrastructure is hosted on Microsoft Azure in the United States and Western Europe. Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards through:

  • EU-US Data Privacy Framework certification (where applicable)
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements with all subprocessors

For details on international transfer mechanisms, see our Data Processing Agreement.

11. Misure di sicurezza

We implement technical and organizational measures to protect your personal data, including:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest (Azure Storage Service Encryption)
  • Argon2id hashing for passwords and API key secrets
  • Role-based access controls with principle of least privilege
  • Regular penetration testing and vulnerability assessments
  • Audit logging of all administrative and data access operations

12. Privacy dei minori

The Service is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If we learn that we have collected personal data from a child under 16, we will promptly delete that data.

13. Modifiche alla presente informativa

We may update this Privacy Policy from time to time. Material changes will be communicated via email and/or a prominent notice on the dashboard at least 30 days before taking effect. The “Last updated” date at the top reflects the most recent revision.

14. Responsabile della protezione dei dati

Our Data Protection Officer can be reached at:

VynCo Data Protection Officer

Email: dpo@vynco.ch

Web: vynco.ch

If you are unsatisfied with our response to a privacy concern, you have the right to lodge a complaint with your local data protection supervisory authority.