Friendly Automate processes different types of data. Some of this data is the responsibility of Friendly (“we”), while other data is the responsibility of Friendly’s customers (“you”). The following sections explain these roles and how the respective obligations are fulfilled.

Legal basis

In accordance with the GDPR and the Swiss FADP, we follow these principles whenever we process data:

Purpose limitation

We only retain data where there is a clear purpose for doing so. We define this purpose for each data category (see table below), document it and review it regularly. Once the purpose no longer applies, we delete the data.

Data minimisation

We only collect and retain data that we genuinely need to operate our services, provide support or meet legal requirements. Features are designed to avoid generating unnecessary data.

Retention requirements

We retain data where this is necessary to fulfil our contractual obligations, handle support requests, ensure technical quality or comply with legal requirements. Retention periods are defined for each data category and supported by a clear rationale (see table below).

Deletion requirements

Once the defined retention period has expired, data is deleted automatically. This applies both to production systems and to actively used archive areas.

Accountability and documentation

We maintain a central overview of all retention periods. We can explain at any time why specific data is retained, for how long, and how it is deleted.

Technical and organisational measures

Deletion processes are automated and tested regularly. Access to systems is protected, and relevant activities are logged. Internal responsibilities for data retention and deletion are clearly defined.

Backups