1. Data controller
Pillarum Sàrl (Société à responsabilité limitée)
Registered office: Route de Saint-Cergue 303, 1260 Nyon, Suisse
Operational address: Route de Saint-Julien 7-9, 1227 Carouge, Suisse
UID: CHE-453.876.406
Email: support@pillarum.ch
2. Data collected
To carry out a full search of your LPP assets, we collect strictly the data we need:
- Identity: first name, last name, date of birth, nationality (extracted from your ID document via OCR).
- 13-digit AVS number: essential to query Swiss pension funds.
- ID document (front + back): photo or scan, kept to sign the power of attorney.
- Contact details: email and phone to keep you informed.
- Career context: country of residence, time spent in Switzerland, cantons, employers (chat answers).
- Electronic signature: capture of your signature stroke for the power of attorney.
- Technical data: IP address, browser type, timestamp (security and eIDAS legal traceability).
- Attribution data (UTM, referral code) when applicable, for billing between partners.
3. Purposes of processing
Your data is used exclusively to: (a) run the full LPP search across Swiss pension institutions; (b) keep you informed of your file's progress; (c) meet our Swiss legal obligations (AMLA, nFADP); (d) improve our services on aggregated, anonymised data.
4. Legal basis
Under nFADP (Switzerland) and GDPR (EU), the legal bases are:
- Performance of the contract: LPP search you expressly requested via your electronic signature of the power of attorney.
- Legal obligation: keeping the power of attorney and traceability of actions.
- Consent: for secondary purposes (newsletter, product communications).
5. Retention
Powers of attorney and signatures: 10 years (Swiss legal retention requirement for signed instruments). File data after delivery of the summary: 3 years, then encrypted archiving. Marketing data: until consent is withdrawn. You may request deletion at any time, subject to legal retention obligations.
6. Hosting and processors
Data is hosted in the European Union. Our main processors are:
- Supabase (Frankfurt, DE): database, storage, edge functions. GDPR/SCC compliant.
- Anthropic (US, CCPA + DPA): ID document OCR (Claude Vision). No reuse of data for training.
- Vercel (US/EU): frontend hosting. SCC compliant.
- Make.com (EU): notification automation.
No data is ever sold to commercial third parties, in any case.
7. Security
TLS 1.3 in transit, AES-256 at rest. Access restricted to authorised personnel with strong authentication. Regular audits. Breach notification within 72 hours in case of incident.
8. Your rights
You have the following rights at any time:
- Access to your data.
- Rectification of inaccurate data.
- Erasure (subject to legal retention).
- Restriction of processing.
- Portability in a structured format.
- Objection to processing for direct marketing.
- Withdrawal of consent at any time.
To exercise these rights: support@pillarum.ch. Response within 30 days. You may also file a complaint with the Federal Data Protection and Information Commissioner (FDPIC, Switzerland) or your European data protection authority.
9. Changes
This policy may be updated. The version that applies is the one displayed on this page. In case of major change, we notify you by email.
10. Contact
For any question about this policy: support@pillarum.ch