Privacy policy
Last updated: 17 September 2026
1. Introduction
This privacy policy describes how GlassCount (hereinafter "GlassCount", "we" or "the Company") collects, uses and protects the personal data of users of the glasscount.ch website and related services.
Processing takes place in compliance with the new Swiss Federal Act on Data Protection (nFADP, in force since 1 September 2023) and, for users resident in the European Economic Area, Regulation (EU) 2016/679 (GDPR).
2. Data controller
Robert Mihai Ichim
CHE-278.039.704
Switzerland
For questions about this policy or to exercise your rights, you can contact us through the contact form on the website.
3. Data collected
We process the following categories of personal data:
- Contact form data: name, fiduciary firm name, email address, accounting software used, band of the number of mandates and optional message, collected through the form on the website.
- Consent data: privacy consent status, date and time of submission, IP address and browser User-Agent, retained as proof under Art. 6 nFADP.
- Data processed in the course of mandates: accounting documents of fiduciaries' clients (invoices, bank statements, receipts, payroll documents), processed solely on the fiduciary's instructions.
- Technical data: IP address, browser type, operating system and system access logs, limited to what is necessary for security and site operation.
4. Purposes and legal bases of processing
| Purpose | Legal basis (nFADP / GDPR) |
|---|---|
| Responding to requests submitted through the contact form | Explicit consent (Art. 6 nFADP / Art. 6(1)(a) GDPR) |
| Performance of document collection, digitisation and bookkeeping mandates | Performance of a contract (Art. 31(2)(a) nFADP / Art. 6(1)(b) GDPR) |
| Security, fraud and abuse prevention | Legitimate interest (Art. 31(1) nFADP / Art. 6(1)(f) GDPR) |
| Compliance with Swiss legal and accounting obligations | Legal obligation (Art. 31(1) nFADP / Art. 6(1)(c) GDPR) |
5. Recipients and processors
Data may be disclosed to the following recipients, solely for the stated purposes:
- Hosting and infrastructure providers — operational service data is hosted exclusively in data centres located in Switzerland.
- The mandating fiduciary or the user's adviser, within the agreed collaboration.
- Competent authorities where required by Swiss law or a binding order.
We do not sell or transfer personal data to third parties for marketing purposes.
6. Transfers abroad
Any transfer of personal data outside Switzerland takes place exclusively to countries that guarantee an adequate level of protection recognised by the Federal Council (in particular EU/EEA Member States) or on the basis of approved standard contractual clauses (SCCs), and only with prior written agreement from the mandating fiduciary.
7. Data retention
- Contact form data: retained for as long as needed to handle the request and subsequently for up to 24 months, unless earlier deletion is requested.
- Proof of consent: retained for the duration of processing and for 12 months after withdrawal, for accountability purposes.
- Accounting and tax data processed in the course of mandates: retained under the terms agreed with the fiduciary and, where applicable, for 10 years as required by the Swiss Code of Obligations (Art. 958f CO).
- Security logs: retained for 12 months.
8. Data security
We implement appropriate technical and organisational measures (TOMs) to protect data against unauthorised access, loss, alteration or destruction:
- Encryption in transit (TLS 1.2+) and at rest
- Hosting in certified data centres located in Switzerland
- Regular encrypted backups
- Role-based access controls and two-factor authentication
- Data separation per mandate and audit log available on request
9. Your rights
As data subjects, you have the right to:
- obtain information about whether processing takes place (right of access, Art. 25 nFADP);
- request rectification of inaccurate data (Art. 32(1) nFADP);
- request erasure or destruction of data;
- object to processing on legitimate grounds;
- receive data in a structured format or transfer it to another controller (portability, Art. 28 nFADP);
- withdraw consent at any time.
To exercise your rights, use the contact form. You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch).
10. Cookies and measurement tools
We use essential technical cookies for the website to function. We do not currently use analytics, advertising or profiling cookies.
For the full list of cookies, their purposes, durations and instructions on managing preferences, see our Cookie Policy.
11. Profiling and automated decisions
We do not make fully automated decisions that produce legal effects on the data subject under Art. 21 nFADP. Any automated processing of accounting documents is subject to human review.
12. Minors
The service is not intended for persons under 16 years of age. We do not knowingly collect data from minors.
13. Changes to this policy
We reserve the right to update this policy to reflect regulatory or organisational changes. In the event of material changes, we will inform you through a notice on the website. Please consult this page periodically.