Legal

Privacy Policy

How Alloy & Ledger processes personal and studio data when you use the platform.

Version 1.2 · Effective 24 July 2026

Available in English and French. If versions differ, the English text prevails unless mandatory Swiss law requires otherwise.

1. Data controller

Alloy & Ledger

Route de Lavaux 44, 1802 Corseaux, Vaud, Switzerland

Email: contact@alloyandledger.com

For the Swiss Federal Act on Data Protection (FADP / nDSG) and, where applicable, the EU General Data Protection Regulation (GDPR), the controller is Alloy & Ledger, operating from the Canton of Vaud, Switzerland. Alloy & Ledger is a trade name operated by the Provider.

2. Scope

This Privacy Policy describes how we process personal data when you visit public marketing pages, register, log in, use authenticated studio features, install the Progressive Web App companion, or interact with our APIs and support channels.

It does not govern third-party sites such as Stripe Checkout or social profiles linked from marketing pages.

3. Data categories and what we collect

We process the following categories of data when you use the Platform:

  • Account & Billing Data: Identity and account details needed to create and manage your studio account, authenticate you, and process subscriptions (including payment-provider markers where paid billing is enabled).
  • Confidential Studio Operational Data: Workspace content you enter or upload to run your studio (such as inventory, production, pricing, sales, and related business records). This is your proprietary workspace data. We process it strictly to provide the Service to you. We do not view, analyze, share, or monetize your business or client information.
  • Technical & Security Data: Technical signals needed to operate and secure the Service (such as session and device metadata, hashed identifiers where noted, language preference, and optional approximate location on public marketing pages when geo analytics is enabled).

4. Purposes and legal bases

We process account personal data to perform the SaaS contract (Art. 31 nFADP / Art. 6(1)(b) GDPR). Billing via our payment processor is contract performance. Fraud and abuse prevention (anti-scraping, rate limits) relies on legitimate interest (Art. 31(1) nFADP / Art. 6(1)(f) GDPR). Aggregated, non-content analytics on public pages uses legitimate interest. Legal compliance uses legal obligation where applicable.

We do not use your studio operational data to train public AI models or for behavioral advertising.

5. Confidentiality of studio operational data

Studio operational data is confidential customer property.

We do not sell, rent, broker, or commercialize studio operational data to data brokers, metal traders, competitors, or unrelated third parties for their independent commercial purposes.

Multi-tenant isolation is enforced via database row-level security. Provider access to production data is limited to need-to-know support, security, or legal compliance.

We may publish non-identifiable, aggregated service metrics that cannot reasonably be linked to your studio.

6. Service providers and data categories

We engage carefully selected third-party service providers ("Processors") to support the infrastructure, delivery, and security of the Platform. These providers process data strictly on our behalf under confidentiality and data protection obligations.

Categories of service providers include:

  • Database & File Storage: Cloud infrastructure located in the EU / United States for secure data storage and authentication.
  • Application Hosting & Edge Delivery: Web application hosting and global CDN services.
  • Payment Processing: Subscription billing and processing handled via Stripe, Inc.
  • Transactional Email: Gateway services for account alerts, password resets, and notifications.
  • Market Data Feeds: Precious metal spot price data feeds (queried anonymously without user content).
  • Security & Infrastructure: DNS management, security telemetry, and network protection.

We will notify account holders of material changes to processor categories via the Platform or email.

7. International data transfers

Some processors host or process data in the United States or other third countries without an adequacy decision under Swiss or EU law.

For such transfers we implement Standard Contractual Clauses (SCCs) and supplementary measures consistent with guidance from the FDPIC and, for EU data subjects, the European Commission SCC modules.

You may request copies of applicable SCCs at contact@alloyandledger.com.

8. Security measures

  • TLS encryption in transit.
  • Content Security Policy and hardened HTTP headers.
  • Database row-level security for tenant isolation.
  • Password hashing via our authentication provider; privileged server credentials restricted to server-side processing.
  • Automated security testing, vulnerability management, and strict tenant access controls.
  • Session re-validation and authentication failure handling.

No system is perfectly secure. Report suspected incidents to contact@alloyandledger.com.

9. Retention

  • Account data: duration of account plus statutory limitation periods.
  • Studio operational data: until you delete or request erasure, subject to backup cycles (typically up to 30 days).
  • Billing records: 10 years (Swiss commercial record-keeping).
  • Document uploads: until you delete associated records or close your account.
  • Security logs: as needed for incident investigation.

10. Your rights

Under the Swiss FADP (nDSG) you may request access, information, correction, deletion (subject to legal exceptions), and portability where feasible. You may lodge a complaint with the FDPIC.

Where GDPR applies, you additionally have rights of restriction, objection to legitimate-interest processing, and withdrawal of consent where processing is consent-based.

Exercise rights at contact@alloyandledger.com.

11. Children

The Service is not directed at persons under 18. The Apprentice tier is for learning and practice, not minors without parental authority.

12. Automated decision-making

The Platform performs deterministic calculations based on your inputs. We do not make legally significant decisions about you solely by automated means without human review. Where document classification assists routing, you confirm extracted before commit.

13. Cookies and local storage

  • Authentication session cookies (essential).
  • Companion mode preference for the Progressive Web App (essential).
  • Locale preference for language routing (functional).

We do not use third-party advertising cookies on authenticated studio features.

14. Changes to this policy

We may update this Privacy Policy. Material changes will be notified via the Platform or email. The effective date at the top will be revised accordingly.

15. Contact and supervisory authority

For data protection requests (access, correction, deletion, portability, or complaint), contact the controller at the email below. We respond within 30 days, extendable once where permitted by law.

Data protection contact: contact@alloyandledger.com

Swiss supervisory authority: Federal Data Protection and Information Commissioner (FDPIC / EDÖB), Feldeggweg 1, 3003 Bern, Switzerland. edoeb.admin.ch.