Privacy policy

2026-09-21

This English version of the privacy policy is provided for convenience. In case of discrepancies between the English and the German version, the German version prevails.

1. Overview

This privacy policy explains which personal data Suisse IT GmbH processes in connection with Suisse Speech, for what purposes, where and for how long, and what rights you have. It applies to:

  • visits to the website suisse-speech.ch,
  • requests through the contact form, in particular requests for a free API key, and communication with us by e-mail or phone,
  • the customer console at console.suisse-speech.ch,
  • the use of the Suisse Speech API at api.suisse-speech.ch,
  • payments for credit.

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the General Data Protection Regulation of the European Union (GDPR).

The key points in brief:

  • The website sets no cookies and uses no analytics or tracking tools.
  • Audio, text and transcripts that you send to the API are processed in memory and not stored.
  • For your API requests, we keep only content-free metadata, for billing and security.
  • Your content is not used to train AI models.

2. Controller

Unless stated otherwise, the controller for the processing described in this privacy policy is:

Suisse IT GmbH
Kesslernmattstrasse 20
8965 Berikon
Switzerland

UID: CHE-168.610.867
E-mail: info@suisse-it.ch
Phone: +41 44 505 55 58

For questions and requests concerning data protection, please contact us at info@suisse-it.ch.

For personal data contained in content that customers have processed through the API, the respective customer is the controller; we act as its processor (section 10).

3. Visiting the website

3.1 No cookies, no tracking

The website suisse-speech.ch is a static website. It sets no cookies, uses no analytics or tracking tools and does not load fonts or scripts from third parties.

3.2 Server logs

The website is hosted on a server in Germany (EU). For every request, the web server records in its logs:

  • the IP address,
  • the date and time of access,
  • the page or file requested,
  • the referrer (the page visited before, if your browser transmits it),
  • the user agent (information on browser and operating system).

We process these data to keep the website secure, in particular to detect and fend off attacks and abuse. The logs are kept for a limited period and then deleted, unless they are needed to investigate a specific security incident. The provider of the server processes these data on our behalf.

4. Contact form and requests

When you request a free API key or write to us through the form on the website, we process the information you provide: name, work e-mail address, company, use case, expected audio volume per month and your message. The information is stored on the web server and delivered to us by e-mail through a Swiss e-mail provider. To prevent abuse, we also store the time of the request and a hash of your IP address, which we use to limit the number of requests per sender. By submitting the form, you consent to this processing; you may withdraw your consent at any time.

We use this information solely to answer your request and to set up your account. If no business relationship results, we delete it as soon as it is no longer needed to handle your request. If we set up an account, the information becomes part of the account data (section 5).

When you contact us by e-mail or phone, we process your details and the content of your message to respond to your enquiry.

5. Customer console

In the customer console at console.suisse-speech.ch, we process:

  • Account data: name, e-mail address and role of each user.
  • Session cookie: after you sign in, the console sets a strictly necessary session cookie so that you stay signed in. It serves no other purpose, in particular not analytics or advertising.
  • Two-step sign-in: if you activate the optional two-step sign-in, we process the information required for it.
  • Audit trail: we record sign-ins and changes in the account with the time and the user who acted. This allows you and us to trace who did what and when, and to detect misuse.
  • Notifications: we inform the users of an account by e-mail about credit usage, for example when 80 % and 95 % of the credit has been used. We also use the e-mail addresses for notices concerning the contract, for example about changes to the prices or to the terms of service.

We keep account data and the audit trail for the duration of the business relationship. Afterwards we delete them unless statutory retention obligations apply or we need them to establish, exercise or defend legal claims.

6. Using the API

6.1 Your content is not stored

Audio, text and transcripts processed through the API are processed in memory and not stored. There is no cache: the same text is synthesised anew with every request.

For jobs (long recordings and texts), the input is held only until the job ends: the text of a synthesis job and the vocabulary and recording of a recognition job are deleted as soon as the job ends. We hold the result until you collect it, for 48 hours at most.

Your content is not used to train AI models.

6.2 Content-free metadata

For billing and security, we store content-free metadata for each request, assigned to the account: time, service and mode, language, dialect, voice, audio format, length and outcome of the request. We keep this metadata for twelve months. You see the same information in the console and through the usage endpoint of the API.

6.3 Access logs

The access logs of our API servers record the IP address a request comes from, but not its content. We keep them for 180 days to detect and investigate misuse and attacks.

6.4 Sandbox

Requests made with sandbox keys (prefix sv_test_) are answered on our servers with synthetic test data and are not passed on to processing partners.

7. Payments and invoices

Online top-ups of credit with TWINT or card are processed by the Swiss payment service provider Payrexx. You enter your card or TWINT details directly with Payrexx; they never reach us. From Payrexx we receive only the information we need to record the payment, such as the amount, time, reference and status of the payment. Payrexx’s own privacy policy also applies to its processing.

For payment by invoice, we process the billing details (company and billing address) and incoming payments.

We keep accounting records and invoices for the statutory period of ten years (art. 958f of the Swiss Code of Obligations).

8. Recipients

We disclose personal data only where necessary for the purposes described, namely to:

  • the provider of the server on which the website runs (Germany),
  • the operator of the data centre that houses our API servers (Switzerland),
  • specialised processing partners for speech recognition and for parts of speech synthesis (section 9),
  • a Swiss e-mail provider,
  • the payment service provider Payrexx (Switzerland),
  • other service providers that support us in our operations, for example in IT or accounting,
  • authorities and courts, where we are legally obliged to do so or where it is necessary to protect our rights.

Our service providers and processing partners process the data on our behalf and are contractually bound to data protection and data security. The list of our processors forms part of our data processing agreement and is available on request.

9. Processing locations and disclosure abroad

  • Website: server in Germany (EU).
  • API: our API servers are located in a data centre in Switzerland.
  • Speech recognition: takes place in the EU.
  • Speech synthesis: parts of speech synthesis are handled by specialised processing partners outside Switzerland and the EU, including in the USA.

The processing partners receive only the data needed for the respective request, for example the audio to be recognised or the text to be spoken.

According to the Swiss Federal Council, the member states of the EU, including Germany, ensure an adequate level of data protection; for transfers from the EU to Switzerland, there is an adequacy decision of the European Commission. Where we disclose personal data to a country without adequate data protection, we safeguard the disclosure with appropriate guarantees, in particular the standard contractual clauses of the European Commission as recognised by the Federal Data Protection and Information Commissioner (FDPIC), with the adaptations required for Switzerland. Further details on the processing partners and the safeguards are set out in our data processing agreement and are available on request.

10. Processing on behalf of customers

Where content that customers have processed through the API contains personal data, for example recordings of conversations or texts, we process these data as a processor on behalf of the customer. In this case:

  • the customer is the controller, in particular for informing the persons concerned and obtaining any consent required;
  • we process the data solely to provide the services and in accordance with the customer’s instructions;
  • we take appropriate technical and organisational measures to protect the data;
  • we provide the customer with a data processing agreement (DPA) under the FADP and the GDPR on request.

If you are affected by such content, please address your request to the respective customer. As we do not store the content, we are generally unable to provide information about it.

11. Retention and deletion

We keep personal data only for as long as necessary for the respective purpose or required by law:

  • website server logs: for a limited period (section 3.2);
  • information from the contact form: until your request has been dealt with; if an account is opened, as account data;
  • account data and the console audit trail: for the duration of the business relationship;
  • content (audio, text, transcripts): not stored; job results until collected, for 48 hours at most;
  • request metadata: twelve months;
  • API access logs with IP address: 180 days;
  • accounting records and invoices: ten years.

Longer retention remains reserved where it is necessary in an individual case to investigate a security incident or to establish, exercise or defend legal claims.

12. Data security

We protect personal data with appropriate technical and organisational measures. These include:

  • encrypted transmission (HTTPS/TLS) for the website, the console and the API,
  • separate keys for live and sandbox use; additional API keys are stored only as a fingerprint,
  • roles, optional two-step sign-in and an audit trail of all sign-ins and changes in the console,
  • access to personal data only for persons who need it for their tasks,
  • data minimisation: content is not stored.

Where the GDPR applies, we base the processing on:

  • the performance of a contract or pre-contractual measures (art. 6(1)(b) GDPR), for example for requests, the account, the use of the API and payments,
  • legal obligations (art. 6(1)(c) GDPR), for example retention obligations,
  • our legitimate interests (art. 6(1)(f) GDPR), in particular in the security of our website and services, in the prevention of abuse and in establishing, exercising or defending legal claims,
  • your consent (art. 6(1)(a) GDPR), where we ask for it, for example when you submit the contact form. You may withdraw your consent at any time with effect for the future.

14. Your rights

Under applicable data protection law, you have in particular the right:

  • to request information on whether and which personal data we process about you,
  • to have incorrect personal data corrected,
  • to request the deletion of your personal data,
  • to request the restriction of processing,
  • to receive personal data that you have provided to us in a common electronic format, or to have them transferred,
  • to object to the processing,
  • to withdraw consent with effect for the future.

To exercise your rights, write to us at info@suisse-it.ch. We may ask for proof of your identity and generally respond within 30 days. Statutory restrictions, such as retention obligations, remain reserved.

You may also contact the competent supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch. Where the GDPR applies, you may also lodge a complaint with a supervisory authority in the EU, in particular in the member state of your habitual residence.

15. Changes to this privacy policy

We may amend this privacy policy, for example when our services or the legal situation change. The version published on this website applies. We inform our customers of material changes by e-mail or in the console.