Version 1.1 · in force from 14 Sep 2026. Every change receives a new version number; earlier versions are archived under What’s new in the customer account.
General information
To process payments we pass on the payment data required for this to the selected payment institution. Which payment service providers are used is set out in our list of sub-processors. The protection of your personal data is of particular importance to us. We treat your personal data confidentially and in accordance with the statutory data protection regulations (GDPR, Swiss Data Protection Act) as well as this privacy policy. This policy informs you about what data we collect on our website, how we use it and what rights you have as a user.
Data Controller
Traniva AG Zimbergstrasse 11 8335 Hittnau, Switzerland Telephone: +41 79 730 06 60 Email: info@traniva.com
Collection and Storage
a) When visiting the website When you access our website, information is automatically collected (e.g. IP address, browser type, time of access) . This information is used to ensure the technical operation of the website and to optimise our services. b) When using the contact form When you contact us via a form or by email, we store your details (e.g. name, email address, telephone number) in order to respond to your enquiry.
Disclosure of data
Your data will only be disclosed if this is permitted by law, if you have given your consent, or if it is necessary for the performance of a contract.
Cookies
Cookies are small files that enable specific, device-related information to be stored on the user’s device (PC, smartphone, etc.). On the one hand, they serve to enhance the user-friendliness of websites and thus benefit users (e.g. by storing login details). On the other hand, they are used to collect statistical data on website usage and to analyse this data with a view to improving the service. Users can control the use of cookies. Most browsers have an option to restrict or completely prevent the storage of cookies. However, please note that the use of the website, and in particular the user experience, will be restricted without cookies. To continue using the site, each visitor must manually confirm the storage of cookies and the saving of the relevant data. The cookie is valid for 365 days; once this period has expired, the cookie must be reconfirmed. Alternatively, the use of cookies can be individually configured by the user in each browser to suit their needs. Users can manually configure settings to accept cookies automatically or manually. Furthermore, on this page, the use of cookies is highlighted on every first visit and after 365 days; users can manually select from the following three options, which must be manually accepted by the user/visitor to continue using the site. Users can enquire directly about which data is stored; see the section on this page: * GDPR – requesting personal data. You can configure your browser so that you are notified when cookies are set and can decide individually whether to accept them, or to block the acceptance of cookies in specific cases or in general. You can find the relevant instructions here: Internet Explorer: http://windows.microsoft.com/de-DE/windows-vista/Block-or-allow-cookies Firefox: https://support.mozilla.org/en-US/kb/cookies-erlauben-und-ablehnen Chrome: http://support.google.com/chrome/bin/answer.py?hl=de&hlrm=en&answer=95647 Safari: Opera:
Your rights at a glance
You have the right at any time to: access the personal data we hold about you; rectify inaccurate data; erasure or restriction of processing; object to data processing; data portability; and withdraw any consent you have given. Please contact us at: info@traniva.com
Data security
Transmission is encrypted (SSL or TLS). You can recognise an encrypted connection by https:// in the address bar and the padlock symbol in your browser. While the connection is encrypted, the data you send us cannot be read by third parties.
Beyond that, we protect our systems by technical and organisational measures against loss, destruction, access, alteration and unauthorised disclosure. No method on the internet offers complete protection; we therefore keep our measures in line with the state of the art.
Validity and amendments to this privacy policy
This privacy policy is currently valid and is dated September 2025. Amendments may be necessary due to further development of our website or changes to legal requirements.
Contact
When contacting the provider (for example, via the contact form or by email), the user’s details are stored for the purpose of processing the enquiry and in the event that follow-up questions arise.
Liability and copyright
Liability for our own content and for external links, as well as copyright, are governed in the legal notice.
Data Protection
When you visit our website, information regarding access (date, time, page accessed) may be stored on the server. This does not constitute the processing of personal data (e.g. name, address or email address). Where personal data is collected, this is done – where possible – only with the prior consent of the website user. Data will not be passed on to third parties without the user’s express consent. We expressly point out that the transmission of data over the internet (e.g. by email) may involve security vulnerabilities. Complete protection of data against access by third parties cannot be guaranteed. We cannot accept any liability for damages resulting from such security vulnerabilities. We expressly object to the use of published contact details by third parties for advertising purposes. We reserve the right to take legal action in the event of unsolicited advertising material being sent, e.g. via spam emails.
See further information in the ‘Cookies’ section on this page. Users may request details of which data is stored directly; see the relevant section on this page: * GDPR – requesting personal data; for exceptions, see the * Shop section.
Registration and user account
Full use of our services requires registration. We use the data entered to maintain the account and provide the service. We inform you by e-mail to the address on file about changes to the scope of the service or technical adjustments.
Which data is stored, how long it stays and when it is deleted is set out in the sections on retention periods and deletion further down this page.
Information
You may request information from us as to whether we are processing your personal data, and if so, you have the right to be informed about this personal data and the additional information specified in Article 15 of the GDPR.
Right to rectification
You have the right to have any inaccurate personal data concerning you rectified;
you may request that incomplete personal data be completed in accordance with Article 16 of the GDPR.
Testing, verification and traceability in Process Studio
Anyone using the «Testing and verification» add-on licence records additional details on the process step: whether it must be verified, which risks and controls attach to it, which test cases exist and which results are available. These details come from the customer and are stored in their workspace. The legal basis is performance of the contract (Art. 6(1)(b) GDPR); in regulated environments the fulfilment of the customer’s legal obligations is added (point (c)). See GTC, clause 5.10.
Identifier per account
So that it remains apparent who created a piece of content and who approved it, every account receives a permanent identifier. It is non-speaking – it contains neither name nor address nor user name – and is stored on the content created with that account. Anyone reading a file outside our environment sees a number, not an account. Resolving it is possible only within the respective customer’s environment.
This assignment is a condition of the functions named and cannot be switched off: without it, origin and approval cannot be kept apart. Anyone not using the add-on licence is unaffected. See GTC, clauses 5.10.5 and 16.15.
Retention after an account is deleted
When a user account is deleted, we remove the associated master data. The identifiers on records already approved remain, however. The reason: without them it would no longer be possible to establish who created a verification record and who approved it – the customer’s chain of evidence would be broken and approvals given would lose their evidential value.
This retention rests on the fulfilment of the customer’s retention and record-keeping obligations and on the legitimate interest in the evidential value of approvals given. It falls under the exceptions to erasure in Art. 17(3)(b) and (e) GDPR. Only the non-speaking identifier is retained, not name or address. The customer determines the duration under the rules applying to them.
Identifiers cannot be changed
Identifiers for process steps, risks and test cases are assigned automatically and cannot subsequently be changed or removed. A link that can be altered unnoticed carries no evidence. This too is a condition of use and cannot be switched off (GTC, clause 16.16).
Operational log
Events are logged for operation and fault finding – logins, saves and error messages, for instance. The log contains user names and is therefore personal data. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR). Older entries are removed automatically; the default is 30 days. Customers may adjust the period in their environment. See GTC, clause 16.17.
Consent at purchase and its record
A purchase is not possible without express agreement to the GTC. We record the time of agreement and the version in force on the order; where performance starts immediately, also the separate consent to that and the associated notice that the right of withdrawal lapses. These details appear on the invoice and in the licence document and are filed in the customer account. The legal basis is performance of the contract and the fulfilment of our record-keeping obligations (Art. 6(1)(b) and (c) GDPR). They are retained together with the invoice documents within the statutory periods.
Special Enterprise configurations and zero data retention
For Enterprise customers, the model provider, model, hosting, processing region and data retention can be agreed individually. Where configurations are technically suitable and enabled by the respective provider, this may also include zero data retention (ZDR). In a ZDR configuration, the content transmitted to the model provider for the AI request concerned and the responses produced are not permanently stored once the processing has finished, in accordance with the properties confirmed by contract with the model provider.
ZDR is not part of the TAOM standard configuration and applies only to the Enterprise configuration expressly agreed and confirmed by Traniva. The providers, places of processing and sub-processors used in each case follow from the documentation governing the contract and from the list of sub-processors.
Responsibility for customers in the EEA
Where a customer uses TAOM within the scope of the GDPR and we process personal data exclusively on that customer’s behalf, the customer is the controller and Traniva the processor. The obligations of the controller, in particular informing data subjects and handling data subject requests, remain with the customer. We support them within the framework of the Data Processing Agreement (DPA) (GTC, clause 16.19).
Principle: as long as necessary, no longer
We store personal data only for as long as it is required for the respective purpose or as long as statutory and contractual record-keeping obligations demand. Once the purpose ceases and no retention obligation stands in the way, the data is deleted or anonymised – without you having to ask.
What is excluded from the right to erasure
If you request erasure, we carry it out – except for the following data. The exceptions are not a matter of discretion but are provided for in Art. 17(3) GDPR:
- Invoicing and accounting records – ten years, under commercial and tax law retention obligations (Art. 17(3)(b) GDPR). This covers the order, invoice, payment details and the record of agreement to the GTC.
- Identifiers on approved verification records – for as long as the customer must retain them under their own rules. Without them it would no longer be possible to establish who created a record and who approved it; the chain of evidence would be broken and approvals given would lose their evidential value (Art. 17(3)(b) and (e) GDPR). Only the non-speaking identifier is retained, neither name nor address.
- Verification details on the process step – verification duty, risks, controls, test cases and results belong to the customer’s model, not to your account. They remain even if your account is deleted; the customer as controller decides on their retention.
- The deletion record itself – it evidences that erasure took place and contains your address only as a checksum.
As soon as the respective obligation ends, this data is deleted too. See GTC, clauses 16.18, 16.20 and 16.21.
Retention periods at a glance
Enquiries via the contact form are kept for a further twelve months after being dealt with – so that the history is still known should there be a follow-up – and are then deleted. User accounts are deleted 90 days after the contract ends; the period allows content to be secured or continued, and deletion may be requested earlier at any time. Invoice documents are kept for ten years (statutory obligation), the operational log for 30 days. Workspaces are subject to level-dependent retention. The identifiers on approved records remain unaffected (see above). See GTC, clauses 16.20 and 16.21.
How a deletion is carried out
If you request the deletion of your data, we first check what will be deleted and what must be retained, then carry out the deletion. You then receive a confirmation with a case reference setting out both explicitly. Please keep that message – we can only confirm the case later by means of that reference. We keep a record of the deletion itself; your address appears in it not in clear text but only as a checksum. A record containing the address would defeat the deletion.
Right to erasure
You have the right to request that we erase your personal data without undue delay. We must erase it immediately, in particular for one of the following reasons: your personal data is no longer necessary for the purpose for which it was collected or otherwise processed. You withdraw your consent, which formed the basis for the processing of your data, and there is no other legal basis for the processing. Your data has been processed unlawfully. The right to erasure does not apply if your personal data is necessary for the establishment, exercise or defence of our legal claims.
Right to restriction of processing
You have the right to request that we restrict the processing of your personal data if: you contest the accuracy of the data and we are verifying its accuracy; the processing is unlawful and you object to the erasure of the data, requesting instead that its use be restricted; we no longer require the data, but you require it to establish, exercise or defend legal claims. you have objected to the processing of your data and it is not yet clear whether our legitimate grounds override your reasons.
Right to data portability
You have the right to receive the personal data you have provided in a structured, commonly used and machine-readable format, and you have the right to transmit this data to another controller without hindrance from us, provided that the processing is based on consent or a contract, and our processing is carried out by automated means.
Right to withdraw consent
You have the right to withdraw your consent to the processing of data at any time with future effect. In the event of withdrawal, we will erase the relevant data without delay, provided that further processing cannot be based on a legal ground for processing without consent. The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to withdrawal.
Right to object
Without prejudice to any other administrative or judicial remedies, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or the place where the alleged infringement occurred, if you consider that your personal data is being processed in breach of the GDPR. The supervisory authority to which the complaint has been lodged shall inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Article 78 of the GDPR.
Withdrawal, amendments, corrections and updates
The user has the right, upon request and free of charge, to obtain information about the personal data stored about them. Furthermore, the user has the right to have inaccurate data rectified, and to have their personal data restricted or erased, provided this does not conflict with any statutory retention obligations.
Contact regarding data protection
To contact us regarding data protection, please feel free to use one of the following contact options. Data controller under the GDPR: Laurenc Riese Zimbergstrasse 11 8335 Hittnau (CH/Switzerland) Email:
info(at)traniva(dot)com Telephone: +41 79 730 0660 The data controller under the GDPR is the person who determines the purposes and means of processing personal data (such as names, email addresses, etc.).
What is personal data?
Personal data is data that reveals or could reveal the identity of the customer. We adhere to a data minimisation policy. Wherever possible, we avoid collecting personal data.
Handling of personal data
Personal data is used exclusively for the purpose of drawing up a contract, determining its content, executing or processing a contractual agreement (Article 6(1)(b) of the GDPR). Data is only passed on to third parties for the provision of services and the fulfilment of the contract. Please see the list of third-party providers below.
Data collection when visiting our website
If you visit our website for information purposes (such as reading content) without registering or otherwise providing us with information, we only collect general technical information that your browser transmits to our server. These include: The page YOU visited; IP address (possibly in anonymised form); date and time of access; duration of the visit; browser type; the referring page; the operating system used. For technical reasons, this data is recorded in a server log file and may be used and stored for the purpose of statistical analysis of this website. This data is not transferred or used for any other purpose. We reserve the right to review the server log files retrospectively if there are specific indications of unlawful use. The use of certain external services, such as embedded videos, may in some cases require the transmission of technical data to third-party providers and is described below.
Data processing for order fulfilment (SHOP)
To process your order, we work with service providers who assist us, either fully or in part, in the fulfilment of concluded contracts. Personal data is transferred to these service providers as explained below.e.The legal basis for the transfer of data is Article 6(1)(b) of the GDPR.
Shop / e-shop
All shop items and the terms and conditions relating to the respective items are set out here or directly in the item description. Data is stored for further use in connection with the shop and invoicing. For invoicing purposes, at least the first name and surname, user name, postal address and email address must be stored. In the case of software and the purchase of software licences, the user name and the associated licence must also be stored for the purpose of subsequent recovery. The following shop content is affected: software licences and add-on licences, training courses and workshops, enquiries and appointment bookings. Users can request information directly from the shop regarding which data is stored; see the section on this page: * GDPR – requesting personal data
Booking workshops and training courses
All terms and conditions relating to the respective items are set out here or directly in the item description in the shop. See the previous section * Shop on this page. Users can request information about which data is stored directly themselves; see the section on this page: * GDPR – requesting personal data The statutory right of withdrawal for consumers, its conditions, its early lapse where performance starts immediately, the address for withdrawal and the model withdrawal form are set out in the GTC, clause 18.
Processing of AI Data
In order to provide the functions of the TAOM Process Studio, user inputs (prompts), uploaded documents, generated models, metadata and technical log data may be processed. This processing is carried out exclusively for the purpose of providing the requested services, for fault analysis, quality assurance, system security and the technical further development of the platform. Depending on the function selected, external AI service providers may be used for this purpose. Only the data required for the respective processing is transferred. Further information on the technologies used or individual enterprise solutions is available via our contact page.
TAOM
Who besides us processes data
Which services process personal data on our behalf in delivering TAOM – with purpose, data types, location and basis – is published openly in the list of sub-processors. The full picture on data, AI, security and responsibility is in the Trust Center.