What personal data snodo processes, where it is stored, who it is shared with, and how to have it deleted.
snodo is operated by Martina Camusso, Switzerland. Until the planned company is entered in the Swiss commercial register, Martina Camusso is the data controller as a natural person. This page will be updated with the company name, registered address and UID once registration is complete.
Contact for any data-protection question: martina.camusso@snodo.ch.
We have not appointed a data protection officer and are not required to under Swiss law. We have no representative in the EU.
snodo is a business tool for restaurants and hotels. It reads supplier invoices and point-of-sale exports, links them, and explains where margin moved and why. It sits on top of the systems a business already uses. It does not replace a till, an accounting package or a payroll system.
Almost everything snodo handles is business data, not personal data: prices, quantities, recipes, sales lines. This policy covers the personal data that nevertheless occurs, and the data of the people who use the product.
Name, work email address, chosen language, role within the organisation, password hash, session and login records. Provided by you or by whoever administers your organisation's account.
Supplier invoices, delivery notes, supplier statements, point-of-sale exports, recipes and product lists. These are business records, but they routinely contain some personal data: the name and contact details of a supplier's employee on an invoice, or a staff identifier attached to a till transaction.
If your organisation enables it, staff can send a voice note by WhatsApp to record a recipe change or log waste. We then process the sender's phone number, the audio recording, and the text transcription produced from it. This channel is optional and is covered in detail in section 6.
Server logs, IP addresses, error reports and timestamps, generated automatically when you use the service. Used to keep the service running and secure, not to build a profile of you.
If you use the contact form on snodo.ch, we process your name, work email address, company, the message you write and the language you chose, so that we can answer you and, if you book one, hold a meeting.
We do not store your IP address. The form checks it to stop automated abuse, which needs it for about an hour, and it is held in memory for that hour and never written to disk. It used to be recorded alongside the enquiry; we removed it, because nothing read it and keeping it served no purpose we could name.
We do not use tracking cookies, advertising pixels or third-party analytics. We do not sell personal data, and we never will.
We process personal data to provide the service your organisation has contracted us to provide, to keep it secure and available, and to meet our legal obligations. The legal basis under the Swiss Federal Act on Data Protection is the performance of that contract and our overriding legitimate interest in operating the service. Where the GDPR applies, the corresponding bases are Art. 6(1)(b) and Art. 6(1)(f).
Relationship between us and our clients. For the business documents a client sends us, the client is the controller and snodo is the processor: we act on their instructions under a data processing agreement. For account data and for our own website, snodo is the controller.
Client data is stored in Switzerland. Where a step cannot be performed in Switzerland, we use European providers and say so plainly rather than describing it as Swiss.
| Provider | What it does | Where |
|---|---|---|
| Exoscale | Servers, database, and the object storage holding documents and our nightly database backups. Your invoices, recipes and results live here. | Switzerland |
| Delivers the email and the calendar invitation created when someone writes to us through the contact form on our website. Not used for client data inside the product. | EU and United States | |
| Sentry | Error reporting, so we find faults before you do. Reports come both from our servers and from your own browser. | EU |
| Meta Platforms | Delivers WhatsApp messages. Only if your organisation uses that channel. See section 6. | See section 6 |
Each of these acts as our sub-processor under a written agreement. We keep this list current; if we add a provider that handles client data, we update this page before it goes live.
What reaches Google, precisely. Only what someone types into the contact form on our website: their name, email address, company, message and chosen language. The IP address does not — it stays on our own server. Nothing from inside the product, and no client document, invoice or figure, is sent to Google. Google LLC is certified under the Swiss–U.S. Data Privacy Framework, which the Swiss Federal Council recognises as providing adequate protection.
Named here but not yet in use. Two further providers are planned and are listed so that this section stays honest as the product grows: Mailgun EU, to receive invoices sent to a snodo intake address, and a separate AI service for reading documents. Neither is connected today and neither receives any data. We will name the AI provider and update this page before either goes live.
Transfers to the EU rely on the Swiss Federal Council's recognition of the EEA as providing adequate protection. Transfers that may reach the United States are covered just above for Google, and in section 6 for WhatsApp.
This section describes an optional channel. If your organisation has not enabled it, none of it applies to you.
How it works. A member of staff records a voice note and sends it to snodo's WhatsApp number. We download the recording, convert speech to text, and turn it into a draft entry, for example a waste log or a recipe change. Nothing is written into your figures until a person confirms the draft.
What this means for where the data goes. WhatsApp is operated by Meta. Message content passes through Meta's global infrastructure, which includes servers in the United States, for a short processing window before it comes to rest. We request Meta's regional storage so that stored content stays in Europe, but the transit itself is a property of the WhatsApp network and cannot be switched off. If that is unacceptable for your business, use the app or the email intake instead: neither touches Meta.
Meta Platforms, Inc. and WhatsApp LLC are certified under the Swiss–U.S. Data Privacy Framework, which the Swiss Federal Council recognises as providing adequate protection for transfers to certified recipients.
What we do with the recording. We store it on Swiss infrastructure, transcribe it, and delete the audio once the resulting entry has been confirmed. The transcript is kept as the record of what was reported.
We do not analyse voices. We transcribe what was said. We do not use voiceprints, we do not attempt to identify or verify a speaker from their voice, and we do not infer anything about a person from how they sound. Only the phone number the message came from, which your organisation registered in advance, tells us who sent it.
Only phone numbers your organisation has registered can use the channel. A message from an unregistered number is refused and not processed. Any member of staff can have their number removed and their voice data deleted at any time, without giving a reason, by asking their manager or by writing to us directly. See Data deletion.
snodo uses AI models to read documents and to write plain-language explanations. Two limits are built into the product rather than promised in a policy:
Model processing takes place in the EU (Frankfurt). No automated decision produces legal effects for any individual: snodo flags and explains, people decide.
| Data | Kept for |
|---|---|
| Original documents | The life of the contract. Kept unchanged so any result can be re-derived and audited. |
| Calculated results | The life of the contract. |
| Voice recordings | Deleted once the entry made from them is confirmed. |
| Voice transcripts | Kept with the entry they created. |
| Enquiries from our website | Your name, email address, company, message and language, held only until the enquiry reaches us — normally seconds. Anything that fails to reach us is deleted after 90 days at the latest. No IP address is kept. |
| Account data | Until the account is closed, then removed within 30 days. |
| Server and error logs | 90 days. |
| Backups | A copy of the database is taken nightly and stored in Swiss object storage. Each copy is deleted after 14 days. |
When a contract ends we return or delete your data at your choice. Deletion is completed within 30 days, except for copies held in backups, which fall away on the rolling schedule above.
Data is encrypted in transit and at rest. Access is limited to the small number of people who need it to run the service, over individual accounts with two-factor authentication. Each client organisation's data is separated at the database level, so one client's query cannot reach another's records even if application code is wrong.
We do not use real client data for development or testing. Development runs on synthetic fixtures.
If a data breach occurs that is likely to result in a high risk to affected people, we notify the Federal Data Protection and Information Commissioner and the affected client organisations without undue delay.
Under Swiss data protection law you may ask us to tell you what personal data we hold about you, correct it if it is wrong, delete it, hand it over in a machine-readable format, or stop a particular use of it.
Write to martina.camusso@snodo.ch. We answer within 30 days and do not charge for it. We may need to confirm your identity first, so that we do not disclose your data to someone else.
If your data reached us through your employer's use of snodo, we may need to pass your request to them, since they decide what happens to that data. We will tell you if we do.
You can also complain to the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
We update this page when the service changes. The date at the top always reflects the current version. For changes that materially affect how we handle personal data, we notify client organisations directly rather than relying on you to re-read the page.