Privacy Policy

Last updated: June 20, 2026

1. Scope and controller

This Privacy Policy explains how SwissGPU handles personal data when you visit our website, create an account, rent a Server, make a payment, contact us or otherwise use the Service.

The controller is LongLink sagl (operating "SwissGPU"), la Stráda Valdaé 9, 6963 Cureggia (Lugano), Switzerland, UID CHE-150.642.313. Privacy enquiries and requests may be sent to info@swissgpu.ch.

The definitions in our Terms of Service also apply to this Policy where relevant.

2. Our roles

We act as controller for personal data used to operate accounts, authentication, billing, support, security, abuse prevention and our business. This Policy primarily describes those activities.

When a customer places personal data in Content on a rented Server, the customer generally decides why and how that data is processed and is the controller. SwissGPU generally acts as processor for that Content. The data-processing provisions in the Terms of Service or a signed DPA govern that processing. Customers are responsible for providing their own notices and establishing a lawful basis for personal data they process through the Service.

3. Personal data we process

  • Account and identity data: internal account ID, authentication provider and provider ID, name, email address, optional avatar URL, country, latest successful-login IP address, account creation and last-login times, email confirmation status, role, account status and account preferences.
  • Authentication data: a password hash for email/password accounts, or profile information returned by the OAuth provider you choose. We use OAuth tokens during sign-in but do not intentionally store them in our account database.
  • Connection and log data: IP address, request method and path, timestamps, response status, duration, errors, session information and security events. We derive and store a country code from the IP address at login.
  • Billing and transaction data: Stripe customer ID, payment or refund identifiers, account balance, top-up and grant amounts, usage, electricity and installation charges, related Server ID and transaction dates. Stripe and the selected payment method process full card, bank and payer details; SwissGPU does not receive or store full card or bank-account credentials.
  • Rental and operational data: allocated Server and hardware details, rental and release times, status, selected operating-system image, network ports, installation state, metered energy use, availability and fault information, and access configuration required to provision and support the Server.
  • Notification data: low-balance thresholds, requested hardware-availability alerts and records needed to send service and account notifications.
  • Communications: messages, attachments and related contact details when you contact support or otherwise communicate with us.
  • Customer Content: data stored or processed on a Server. We do not routinely inspect Content, but authorised personnel may access it where reasonably necessary to provide requested support, investigate abuse or a security incident, enforce the Terms, or comply with law.

We receive data directly from you, from your use of the Service, from the OAuth provider you use, from Stripe and payment-method providers, and from our infrastructure and security systems. The country code associated with an IP address is obtained from an IP geolocation provider.

We do not sell personal data. We do not currently use third-party advertising trackers or analytics to build advertising profiles about visitors.

4. Why we process personal data

  • create and administer accounts and authenticate users;
  • allocate, provision, meter, bill, maintain and support Servers;
  • process top-ups, payments, refunds, invoices and accounting records;
  • send confirmation, machine-ready, low-balance, credit and service messages;
  • secure accounts and infrastructure and prevent fraud, abuse and prohibited use;
  • diagnose errors, monitor reliability and improve the Service;
  • respond to support requests, complaints and legal-rights requests;
  • establish, exercise or defend legal claims; and
  • comply with accounting, tax, sanctions, regulatory and other legal obligations.

Swiss data-protection law generally permits private-sector processing unless it unlawfully infringes personality rights. Where another law requires a legal basis, including where the EU or UK GDPR applies, we rely as appropriate on performance of a contract, compliance with legal obligations, our legitimate interests in operating and protecting the Service, or consent for an optional use that specifically requests it. You may withdraw consent at any time, without affecting earlier processing.

5. Service providers and other recipients

We disclose only the data reasonably needed for the recipient's role:

  • OAuth providers: authentication when you select a third-party provider. They receive the information required for sign-in and return your provider ID, name, email and, where available, avatar.
  • Stripe and payment-method providers, including TWINT where selected: customer creation, checkout, payment processing, refunds, fraud prevention and legally required financial records. We send Stripe your name and email when an account is created, even if you have not yet made a payment.
  • Infomaniak: email delivery and DNS or infrastructure services. Email delivery involves your email address, name and the content of the service message.
  • IP geolocation provider: receives the login IP address and returns a country code for account administration and security.
  • Logging and monitoring providers: incident investigation, security and service reliability. Log data may include IP addresses, request paths, Server identifiers and error information.
  • Internal communications providers: restricted operational alerts. Alerts may include an account name, Server ID and configuration, and top-up or credit amount, but not full payment credentials or Customer Content.
  • Professional advisers and authorities: legal, accounting, audit, insurance or regulatory recipients where reasonably necessary, and public authorities where disclosure is required or permitted by law.
  • Corporate transactions: a prospective or actual buyer, investor or successor in a merger, financing, reorganisation or transfer of all or part of the business, subject to appropriate confidentiality and legal safeguards.

Some recipients, particularly payment and authentication providers, also act as independent controllers for their own security, fraud-prevention and legal obligations. Their privacy policies govern those activities.

6. International transfers

Our Servers and primary application infrastructure are hosted in Switzerland. Some providers or their subprocessors may process personal data in the European Economic Area, the United States or other countries where they operate. This applies in particular to authentication, payment, monitoring and communications providers.

Where required, transfers are based on a destination recognised as providing adequate protection, the Swiss-US Data Privacy Framework for a certified recipient, recognised standard contractual clauses adapted for Swiss law, or another safeguard or exception permitted by applicable law. You may contact us for more information about the safeguards relevant to a particular transfer.

7. Cookies and similar storage

We currently use only storage needed for the Service. A signed, HTTP-only session cookie keeps you authenticated and contains session account information. OAuth and payment providers may set their own cookies when you visit them.

You can block or delete cookies through your browser, but blocking the session cookie prevents account login. We do not currently set advertising or cross-site behavioural-tracking cookies. If that changes, we will update this Policy and provide any choices required by law before using them.

8. Retention

We keep personal data only for as long as reasonably necessary for the stated purposes:

  • account, profile and preference data are generally kept while the account is active and then deleted or anonymised when no longer required for security, disputes or legal obligations;
  • transaction, invoice, payment-reconciliation and related accounting records are generally kept for 10 years in accordance with Swiss record-keeping requirements;
  • application, access and security logs are generally kept for up to 12 months, but may be kept longer where necessary to investigate an incident, abuse or legal claim;
  • support communications are generally kept for up to three years after resolution;
  • active Server allocation and access-configuration data are kept while needed to provide the rental; transaction records linked to a Server follow the accounting period above; and
  • Customer Content may be erased without a recovery period when a Server is reinstalled, released, suspended or terminated. You are responsible for backups and exporting Content before release.

Data may remain for a limited period in protected backups or with a provider under its own legally required retention schedule. When deletion is due, we delete, anonymise or securely isolate the data until deletion from backups occurs in the ordinary cycle.

9. Automated operational actions

The Service automatically calculates charges from rental time and measured electricity use, sends configured balance notifications, and may stop and release a Server when the account balance is exhausted. These actions use rental status, metering and balance data rather than behavioural profiling. A release may cause immediate loss of Content. Contact support@swissgpu.ch if you believe an automated action or charge was incorrect and want human review.

We do not otherwise use personal data for automated decisions that produce legal or similarly significant effects.

10. Security and data incidents

We use technical and organisational measures appropriate to the nature and risk of the processing, including access controls, transport encryption, network segmentation, credential hashing or encryption where appropriate, logging and restricted administrative access. No system is completely secure, and you are responsible for securing and backing up Content as described in the Terms.

We assess personal-data breaches and notify the Federal Data Protection and Information Commissioner (FDPIC) where a breach is likely to result in a high risk to a person's personality or fundamental rights. We notify affected individuals where required by law or where notification is necessary for their protection.

11. Your rights

Subject to applicable conditions and exceptions, you may request access to personal data we hold about you, correction of inaccurate data, deletion or restriction, object to processing, and receive or transfer certain data in a commonly used machine-readable format. You may also request account closure and withdraw consent where processing relies on consent.

Send requests to info@swissgpu.ch. We may ask for information reasonably needed to verify your identity and protect the account. We generally respond within 30 days. Access is normally free, although the law permits a fee for manifestly unfounded, excessive or disproportionately burdensome requests. We may retain or withhold information where permitted or required by law and will explain an applicable restriction.

You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) or another competent data-protection authority.

12. Children

The Service is for users aged 18 or older. We do not knowingly collect personal data from children. Contact us if you believe a child has provided personal data so that we can investigate and take appropriate action.

13. Changes to this Policy

We may update this Policy as the Service, providers or legal requirements change. We will post the revised Policy with a new update date. If a change materially affects how we use existing account data, we will provide reasonable advance notice through email or the Service where required.

14. Contact

LongLink sagl (operating "SwissGPU"), la Stráda Valdaé 9, 6963 Cureggia (Lugano), Switzerland, UID CHE-150.642.313.

Privacy: info@swissgpu.ch. Technical and account support: support@swissgpu.ch.

LongLink SAGL - v0.8.5 - All Rights Reserved