Data protection
Notice on the processing of personal data of users of the
tachogest.com website and of customers of the TachoGest program.
Art. 19 of the Swiss Federal Act on Data Protection (FADP) · art. 13 and 14 of Reg. (EU) 2016/679 (GDPR).
Introduction
This notice is provided pursuant to art. 19 of the Swiss Federal Act on Data Protection (hereinafter the «FADP») and, where applicable, art. 13 and 14 of Regulation (EU) 2016/679 (hereinafter the «GDPR») by Securdata Sagl (hereinafter «Securdata») in relation to data processed through the tachogest.com website and its third-level domains (hereinafter the «Site»), as well as to data processed in connection with the licence for the TachoGest program.
Definitions and scope of this notice
For the purposes of this notice, «personal data» means any information that directly or indirectly allows a natural person to be identified (hereinafter the «Data Subject»). Processing means any operation involving personal data, such as collection, storage, use, disclosure, archiving or erasure.
The data covered by this notice is collected through the Site while browsing, when the user requests the free trial, fills in a form or makes a purchase, or when the user runs the TachoGest program with an active licence.
Controller and contact details
The controller (hereinafter the «Controller») is Securdata Sagl, Via per Gaggiolo 27,
6855 Stabio (Ticino), Switzerland · UID CHE-246.572.621.
For matters concerning the protection of personal data and to exercise the related rights, you may write to
info@securdata.ch or to the postal address above.
Categories of data processed
a) Traffic and log data. The computer systems and software procedures that operate the Site acquire, in the course of their normal operation, certain personal data whose transmission is inherent in the use of internet communication protocols: IP addresses, URI/URL addresses of the resources requested, the time of the request, the method used, the size of the file received in response, the status code of the response and parameters relating to the user's operating system and computing environment.
b) Form data. For the free trial request: company name, name of the person in charge, email address, telephone number, postal address, number of vehicles with a tachograph and of drivers, sector of activity and any program already in use. For the contact form: name, company, email, telephone and the content of the message.
c) Purchase data. For orders placed through the Site: billing and shipping details (company name, name, address, email, telephone) and the order details. Payment card details never pass through our servers and are not stored by us: payment takes place on the pages of the payment service provider, which receives the data directly from the user.
d) Program licence data. The installed program sends the licence server the licence key, a technical fingerprint of the computer (derived from system identifiers, not traceable to a person), the computer name, the version of the program and of the operating system, and two numbers only: how many vehicles and how many drivers are held in the archive.
e) Cookies. The Site uses neither profiling cookies nor third-party analytics, loads no fonts or scripts from external servers and shows no consent banner, because there is no need for one. Forms keep the page you came from in the browser tab's memory (sessionStorage) for a short while; that information is erased when the tab is closed and is not passed to third parties.
Tachograph data stays with the customer
This point deserves spelling out, because it is the main difference from programs that run in a browser. Data downloaded from driver cards and vehicle units — drivers' names, activities, driving and rest times, infringements, positions recorded by the tachograph — stays on the customer's computer or network and is not transmitted to Securdata. In respect of that data the customer is an independent controller and answers for the obligations arising from OLR 1 and the FADP towards its own drivers.
Securdata can access it only if the customer expressly asks for support, and only for the duration of that support.
Purposes and legal bases of processing
a) Free trial, licences and support. To create and manage the licence, send the key and the download link, provide support and give notice of expiry dates. Legal basis: performance of a contract or of pre-contractual measures (art. 31 para. 2 let. a FADP; art. 6(1)(b) GDPR).
b) Purchases, invoicing and shipping. To fulfil the order, deliver the goods, issue the invoice and meet accounting and tax obligations. Legal basis: performance of a contract and legal obligation (art. 6(1)(b) and (c) GDPR).
c) Enquiries. To deal with the contact request and any related obligation. Legal basis: the Data Subject's consent.
d) Commercial communications. To send, subject to specific and separate consent, information about updates, regulatory news and offers. Legal basis: the Data Subject's consent, which may be withdrawn at any time by an informal request to info@securdata.ch.
e) Security and operation. To ensure the operation and security of the Site and of the licence service, and to prevent abuse and unauthorised use of keys. Legal basis: the Controller's legitimate interest (art. 31 para. 1 FADP; art. 6(1)(f) GDPR).
Retention periods
Personal data is kept in a form which permits identification of the Data Subject for no longer than is necessary for the purposes for which it was collected, having regard to applicable law. In particular:
a) contact form data: for as long as it takes to deal with the enquiry and, if nothing follows, no
longer than twelve months;
b) unconfirmed free trial requests: erased after forty-eight hours;
c) licence and order data: for the duration of the relationship and thereafter for the retention periods
for accounting records required by law (ten years, art. 958f CO);
d) consent to commercial communications: until withdrawal and in any event no longer than two years of
inactivity;
e) web server logs: for a limited period and in any event no longer than twelve months.
How data is processed
Processing is carried out with the aid of computer systems and, where necessary, on paper, and is always guided by the principles of lawfulness, fairness, transparency, purpose and storage limitation, minimisation, accuracy, integrity and confidentiality. Securdata takes the technical and organisational measures appropriate to prevent loss, unlawful or incorrect use of the data and unauthorised access by third parties, including an encrypted connection (HTTPS) on every page of the Site.
Disclosure of data
For the purposes set out above, personal data may be disclosed to:
a) employees and collaborators of the Controller who are authorised to process it;
b) suppliers carrying out activities on behalf of the Controller as processors, in particular
Infomaniak Network SA (Geneva, Switzerland) for hosting the Site, the licence server and email, the
payment service provider for online purchases and the carrier responsible for shipping the goods;
c) advisers, fiduciaries and banks, to the extent necessary;
d) judicial or supervisory authorities, public administrations and bodies, in accordance with the law and
upon a formal and legitimate request.
The complete and up-to-date list of processors is held at the registered office of Securdata Sagl and is available to Data Subjects who make a reasoned written request.
Transfer of data abroad
Data is processed on servers located in Switzerland. The payment service provider may also process the data needed for the transaction within the European Union. Transfer to countries outside the European Union takes place only where there is an adequate level of protection under Annex 1 of the Data Protection Ordinance (DPO, SR 235.11) or on the basis of other appropriate safeguards. The Data Subject has the right to obtain a copy of those safeguards by writing to info@securdata.ch.
Rights of the Data Subject
The Data Subject may at any time, by applying to the Controller at the addresses given above, exercise the rights granted by the FADP and, where applicable, by the GDPR:
a) obtain confirmation as to whether data concerning them is being processed, and access it
(art. 25 para. 2 FADP);
b) be given the data or require its transmission to a third party (art. 28 FADP);
c) not be subject to automated decisions (art. 21 para. 2 FADP);
d) obtain rectification of inaccurate data (art. 32 para. 1 FADP);
e) request that particular processing or disclosure to third parties be prohibited (art. 32 para. 2
FADP);
f) request erasure or destruction of the data (art. 32 para. 2 FADP).
Exercising these rights generally requires proof of the Data Subject's identity. Where processing falls within the territorial scope of art. 3 GDPR, the Data Subject may assert the rights under art. 15-22 GDPR.
In the event of infringements, the Data Subject may contact the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) or, for those within the scope of the GDPR, the supervisory authority of the Member State in which the infringement occurred.
Imprint
Securdata Sagl
Via per Gaggiolo 27
6855 Stabio (Ticino), Switzerland
info@securdata.ch
UID: CHE-246.572.621
The TachoGest program is developed and distributed by Securdata Sagl. Despite the care taken over its content, Securdata Sagl does not warrant that the information on the Site is complete and up to date; references to legislation are for information only and replace neither the official text of the ordinances nor expert advice.
Notice updated on 6 October 2026.