Datenschutzrichtlinie
v1.0 — gültig ab 01.01.2026
Privacy Policy
Effective date: 1 July 2025 — Version 1.0
1. Introduction
This Privacy Policy explains how personal data is collected, used, stored, and protected when you use PlanningMe CH ("the Service"). It applies to all employees and administrators who access the Service.
Your employer ("Company") is the data controller — it determines the purposes for which your personal data is processed. ithubdigital ("Provider") acts as the data processor, processing data solely on the Company's documented instructions.
Processing is carried out in compliance with the Swiss Federal Act on Data Protection (nFADP / LPD) and, where applicable, the EU General Data Protection Regulation (GDPR — Art. 13).
2. Data We Process
The following categories of personal data are processed within the Service:
| Category | Data | Purpose |
|---|---|---|
| Identity | Full name, email address | Authentication, account management |
| Employment | Working days, role, department | Shift planning and scheduling |
| Absences | Absence requests, dates, type, status, balance | Absence management and approval workflow |
| Planning | Shift codes assigned per date | Workforce planning records |
| Technical | IP address, browser user-agent, login timestamps | Security, audit trail, fraud prevention |
| Policy records | Acceptance timestamp, IP address, document version | Legal compliance and GDPR audit trail |
3. Legal Basis for Processing
- Performance of a contract (Art. 6(1)(b) GDPR / nFADP Art. 31): processing necessary to manage your employment relationship, schedule, and absence entitlements.
- Legitimate interests (Art. 6(1)(f) GDPR / nFADP Art. 31): security logging, audit trails, and fraud prevention.
- Legal obligation (Art. 6(1)(c) GDPR): retention of records required by Swiss employment and accounting law.
- Consent (Art. 6(1)(a) GDPR): acceptance of these policies, recorded with timestamp and IP address.
4. Data Retention
Personal data is retained for as long as your employment relationship is active and for a period of 10 years thereafter, unless a shorter period is required by applicable law or requested by your Company. Technical logs (IP addresses, login events) are retained for 12 months. Policy acceptance records are retained indefinitely as a legal compliance archive.
5. Data Sharing and Sub-processors
Your data is not sold or shared with third parties for marketing purposes. The Provider may engage sub-processors solely to operate the Service (e.g. cloud infrastructure, email delivery). All sub-processors are bound by data processing agreements providing equivalent protection.
The Service is hosted on Microsoft Azure infrastructure located in the Switzerland North region. Data does not leave Switzerland unless your Company's configuration explicitly requires it.
6. Your Rights
Subject to applicable law, you have the following rights regarding your personal data. Requests should be directed to your Company administrator, who is the data controller responsible for responding.
- Right of access — obtain a copy of the data held about you.
- Right to rectification — request correction of inaccurate data.
- Right to erasure — request deletion, subject to legal retention obligations.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests.
- Right to restriction — request that processing be limited in certain circumstances.
You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch.
7. Cookies and Technical Storage
The Service uses the following browser storage mechanisms:
- Authentication cookie — stores your session after login. Strictly necessary; expires after 8 hours of inactivity.
- Consent cookie (
gdpr_consent) — records that you have acknowledged this notice. Valid for 365 days. - Culture cookie (
.AspNetCore.Culture) — stores your preferred language. Valid for 365 days.
No tracking cookies, advertising cookies, or third-party analytics are used.
8. Security
The Provider implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. These include TLS encryption in transit, encryption at rest, role-based access controls, one-time password authentication, and regular security reviews.
9. Changes to this Policy
This policy may be updated from time to time. When a new version is published, you will be required to review and accept it before continuing to use the Service. The acceptance date and version are recorded in our systems as part of the GDPR audit trail.
10. Contact
For privacy-related enquiries, contact your Company administrator or the Provider's data protection contact at privacy@planningme.ch.