Swiss Due Diligence & Compliance Pack
SWISS nFADP COMPLIANTLegal, architectural, and data governance framework ensuring full compliance with the revised Swiss Federal Act on Data Protection (revFADP / nFADP) for Xero-integrated accounting automation workflows.
1. Confidentiality, Ownership & Permitted Use
All client financial data, banking tokens, and accounting documents processed via Digintu remain the absolute property of the customer. Digintu processes data strictly on documented instructions from the controller. Data is never monetized, analyzed for commercial gain, or shared with unauthorized third parties.
2. Data Hosting Locations & Sub-Processors
Core hosting is operated by Infomaniak Network SA within Swiss data centers (Geneva/Zurich) with geo-redundant Swiss Backup. Sub-processors include Infomaniak (Hosting) and Stripe Inc. (secure payment). Inbound file integrations utilize Google Drive APIs and email plus-inboxes operated via European mailservers (scheduled for migration to Infomaniak for 100% sovereign Swiss routing).
3. Categories of Personal Data Stored
To operate user authentication, Digintu stores minimal data: (a) User Identity: Name, email, bcrypt hashes; (b) Workspace Metadata: Tenants, seats; (c) Integrations: Xero OAuth credentials; (d) Audit Logs: Pseudonymized actor IDs and IPs. Raw financial files are never permanently stored.
4. Data Retention & Cryptographic Caching
Digintu operates on a zero-retention storage model. This applies equally to statements and invoices received via automated feeds. Only non-sensitive cryptographic fingerprint hashes are stored in database staging to prevent duplicate processing. Source documents reside natively within Xero.
5. Information Security & Access Controls
Storage volumes are protected using disk-level LUKS encryption. Data in transit is secured via TLS 1.3. OAuth secrets are encrypted at the application layer. Access controls enforce strict role separation alongside IP whitelisting, HMAC-SHA256 signatures, and MDC execution tracing.
6. Incident Notification & Liability
Digintu relies on standard server error logs and asynchronous audit routines. In the event of a confirmed breach, controllers will be notified without undue delay. Digintu's total aggregate liability is strictly limited to the total subscription fees paid by the client in the preceding twelve (12) months.
7. Absence of AI Functionality
Digintu operates zero automated machine learning or AI inference models. No customer files, banking records, invoice payloads, or metadata are ever used for artificial intelligence training or model development.
8. Termination & Immutability (GeBüV)
Financial ledgers reside completely in Xero ensuring GeBüV immutability compliance. For Digintu middleware data, workspace owners can execute an immediate account hard-deletion directly from their dashboard, instantly purging tenant records.
Verified Sovereign Swiss Infrastructure Compliance
This document serves as Digintu's official compliance declaration. For customized vendor risk assessments, contact xero@digintu.tech.