Enterprise Privacy & Data Protection

    At iXZepta, privacy and data protection are foundational to how the platform is designed and operated.

    Data Residency & Sovereignty

    All iXZepta customer data is hosted exclusively in Switzerland. Data is subject to Swiss jurisdiction and protected under the Swiss Federal Act on Data Protection (nFADP) and applicable European data-protection laws. We do not rely on offshore data storage as part of our standard service.

    Encryption & Key Management

    Data is protected using strong encryption at rest and in transit. Encryption keys are managed within the iXZepta service environment using hardened key-management controls aligned with industry best practices. Access to encryption keys is strictly limited to authorized system components and governed by internal security and access-control policies. In the event that key access is revoked or disabled at the system level, stored data becomes unreadable.

    Data Roles & Processing

    For data collected through the iXZepta website and customer communications, iXZepta acts as a data controller.

    For customer content processed within the iXZepta platform, iXZepta acts solely as a data processor, while customers remain the data controllers at all times. Customer data is processed strictly in accordance with documented customer instructions and applicable law.

    Purpose Limitation & Data Minimization

    We collect and process personal data only to provide and operate the iXZepta service, to maintain security, and to meet legal or contractual obligations. We do not sell personal data, use it for advertising, or monetize it in any form.

    Sub-Processors

    iXZepta may engage carefully selected sub-processors (such as infrastructure or email service providers) to support service delivery. All sub-processors are contractually bound to confidentiality, security, and data-protection obligations consistent with this policy. Information about sub-processors is available upon request.

    Data Retention & Deletion

    Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal obligations. Upon termination of the service, customer data is deleted or rendered inaccessible within a commercially reasonable timeframe, unless retention is required by law or explicitly requested by the customer.

    International Data Transfers

    iXZepta does not transfer customer data outside Switzerland as part of its standard operations. Any exceptional international data transfers are performed in compliance with applicable legal safeguards under GDPR and Swiss data-protection law.

    Individual Rights

    Individuals have the right to access, correct, delete, or receive a copy of their personal data, and to withdraw consent where applicable. Requests are handled in accordance with GDPR and Swiss nFADP requirements.

    Children's Privacy

    iXZepta is a professional, business-focused platform and is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from minors.

    Transparency & Accountability

    iXZepta maintains documented technical and organizational measures to protect personal data and supports customer privacy and security reviews as part of enterprise procurement and vendor-risk assessments.

    Contact

    For privacy-related inquiries or to exercise data-protection rights, please contact:

    privacy@ixzepta.com