Privacy Policy

Data stored in Switzerland (Zurich) - nFADP and GDPR compliant

1. Introduction

At Pregia, we take the confidentiality of your data very seriously. This privacy policy explains how we collect, use and protect your personal information in accordance with the Swiss Federal Act on Data Protection (nFADP) and the General Data Protection Regulation (GDPR).

Commitment: Your data is stored in Switzerland (Zurich), on infrastructure certified to ISO/IEC 27001:2022. International transfers necessary for service operation are governed by the EU-US Data Privacy Framework.

2. Data Controller

Pregia

3. Data Collected

We collect the following information:

3.1 Identification Data

  • Full name
  • Professional email address
  • Phone number
  • Company name
  • Login information (if you use third-party login)

3.2 Technical Data

  • IP address
  • Browser type and operating system
  • Pages visited and visit duration
  • Application usage data

3.3 Configuration Data

  • Information about your establishment (services, rates, hours)
  • Your AI voice agent configuration
  • Phone conversation history

3.4 Contextual Memory Data

To provide personalized service, our voice agent uses a contextual memory system to recognize regular callers and remember their preferences:

  • Phone number: kept in plain text in the establishment's call history, which needs it to call you back. Stored preferences, however, are indexed on an irreversible fingerprint of that number (SHA-256), not on the number itself
  • Preferences and interaction history with the voice agent
  • Conversational context to ensure continuity between calls

3.5 Payment Data

  • Billing information
  • Transaction history (banking data is processed by our secure payment provider)

4. Data Usage

Your data is used to:

  • Create and manage your account
  • Provide our AI voice agent services
  • Process your payments and billing
  • Provide technical and customer support
  • Improve user experience and our services
  • Generate intelligent responses during phone calls
  • Personalize caller experience through contextual memory
  • Communicate with you about your account and our services
  • Ensure the security of our services
  • Comply with our legal and regulatory obligations

5. Legal Basis for Processing

The processing of your data is based on:

  • Contract execution : provision of our services
  • Your consent : for marketing communications
  • Our legitimate interest : improvement of our services and security
  • Legal obligations : compliance with tax and accounting laws

6. Data Hosting and Processing

Primary storage in Switzerland - Maximum protection for your data

Your data is stored in Switzerland (Zurich). Processing services necessary for voice agent operation are governed by GDPR compliance guarantees (EU-US Data Privacy Framework and standard contractual clauses).

6.1 Data Hosting

  • Main database : Hosted in Switzerland (Zurich) - Full nFADP and GDPR compliance
  • Web infrastructure : European points of presence (Frankfurt, Amsterdam)

6.2 Artificial Intelligence Processing

To operate your AI voice agent, we use cutting-edge artificial intelligence technologies:

  • Conversational AI Technologies
    • State-of-the-art speech recognition (Speech-to-Text) with over 95% accuracy rate
    • Conversational AI model optimized for intelligent response generation
    • High-definition voice synthesis of the latest generation (Text-to-Speech)
    • Contextual memory system for caller recognition
    • GDPR compliant - Data processed via API without retention
    • Conversations are not used to train models

6.3 Other Providers

  • Payments : PCI-DSS certified payment provider (European servers)
  • Telephony : Cloud telephony infrastructure with Swiss +41 numbers
  • Transactional emails : Transactional email service
  • Authentication : Login via third-party providers (Google, LinkedIn)

7. International Transfers

Legal Framework for Transfers

Your data is stored in Switzerland (Zurich). For service operation (voice processing, telephony, emails), some data may be transmitted to providers located in the United States.

These transfers are governed by:

  • EU-US Data Privacy Framework (DPF) : Our American providers are DPF certified
  • Standard Contractual Clauses (SCCs) : GDPR-compliant contractual guarantees

This legal framework guarantees an adequate level of protection in accordance with Swiss nFADP and European GDPR.

8. Data Security

We implement technical and organizational security measures to protect your data against unauthorized access, including:

  • Data encryption in transit (HTTPS/TLS 1.3)
  • Data encryption at rest (AES-256)
  • Two-factor authentication available
  • Secure password storage (bcrypt hashing)
  • Caller phone number anonymization (SHA-256 hashing)
  • Regular security monitoring
  • Strict data access control
  • Regular security audits
  • Automatic encrypted backup

9. Data Retention

We retain your personal data for the following periods:

  • Account data : as long as your account is active
  • Configuration data : contract duration + 30 days after termination (to allow export)
  • Billing data : 10 years (Swiss legal obligation)
  • Call transcripts : 90 days maximum - No audio recordings kept
  • Call metadata : 12 months (analytics and billing)
  • Customer requests : 12 months
  • Contextual memory : contract duration (deleted upon termination)
  • Technical logs : 12 months maximum
  • Marketing data : until withdrawal of your consent

You can request deletion of your account at any time by contacting us. Data subject to legal retention obligations will be securely archived.

10. Your Rights

In accordance with the Swiss nFADP and GDPR, you have the following rights:

  • Right of access : obtain a copy of your data
  • Right to rectification : correct inaccurate data
  • Right to erasure : delete your data (subject to legal obligations)
  • Right to portability : receive your data in a structured format
  • Right to object : object to processing of your data
  • Right to restriction : restrict processing of your data
  • Right to withdraw consent : at any time for consent-based processing

To exercise these rights, contact us at: contact@pregia.ch

We are committed to responding to your request within a maximum of 30 days. If you believe your rights are not being respected, you can file a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland or the competent supervisory authority in your country.

11. Cookies and Similar Technologies

We use cookies and similar technologies to:

  • Essential cookies : maintain your login session (required for service operation)
  • Analytics cookies : understand site usage and improve our services (with your consent)
  • Preference cookies : remember your choices (language, display settings)

You can manage cookies through your browser settings. Disabling essential cookies may affect the operation of our services.

12. International Privacy Rights

Depending on your location, you may have additional privacy rights under your local laws. This section details the specific rights applicable to residents of the United Kingdom, the United States, and Canada.

United Kingdom : UK GDPR

If you are a UK resident, your data is protected under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. You have the same rights as listed in Section 10 above, plus:

  • The right to lodge a complaint with the Information Commissioner's Office (ICO)
  • The right to be informed about international data transfers and the safeguards in place
  • The right to object to automated decision-making and profiling

UK supervisory authority: Information Commissioner's Office (ICO) | ico.org.uk | casework@ico.org.uk | +44 303 123 1113

United States : CCPA / CPRA (California) and State Privacy Laws

If you are a resident of California or another US state with privacy legislation (Colorado, Connecticut, Virginia, Utah, etc.), you have additional rights:

  • Right to know : what personal information we collect, use, disclose, and sell
  • Right to delete : request deletion of your personal information
  • Right to opt-out : of the sale or sharing of your personal information
  • Right to non-discrimination : for exercising your privacy rights
  • Right to correct : inaccurate personal information

We do NOT sell, share, or use your personal information for targeted advertising. We do not sell data to third parties.

You can exercise your opt-out rights at any time via our dedicated page: Do Not Sell or Share My Personal Information

Canada : PIPEDA and Quebec Law 25

If you are a Canadian resident, your data is protected under the Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Quebec residents, under Law 25 (formerly Bill 64).

  • Consent : we obtain your explicit consent before collecting, using, or disclosing your personal information
  • Withdrawal of consent : you may withdraw your consent at any time, subject to legal or contractual restrictions
  • Access and correction : you can request access to and correction of your personal information
  • Privacy officer : our designated privacy officer can be reached at contact@pregia.ch

Cross-border transfers: Your data may be transferred outside Canada (Switzerland, EU, USA) for service operation. These transfers are governed by contractual clauses ensuring equivalent protection.

Canadian supervisory authority: Office of the Privacy Commissioner of Canada (OPC) | priv.gc.ca. For Quebec: Commission d'accès à l'information du Québec (CAI).

13. Changes to This Policy

This privacy policy may be updated to reflect changes in our practices or for legal reasons. We will inform you of any significant changes by email or via a notification on our platform. We encourage you to regularly review this page. The last update date is indicated below.

14. Contact

For any questions regarding this privacy policy, exercising your rights, or our data protection practices, contact us:

We are committed to answering all your questions as soon as possible.

Last updated: February 9, 2026

Version 4.0 : Multi-jurisdiction (nFADP, GDPR, UK GDPR, CCPA/CPRA, PIPEDA)