Privacy Policy — lisa i.G.
Governing Law: Swiss law (nDSG) + GDPR Last Updated: 2026-07-20 Version: 1.1
1. Introduction
This Privacy Policy explains how lisa i.G. ("we," "us," "lisa") processes personal data collected from customers, website visitors, and other individuals.
Scope:
- Website: https://www.runlisa.ch
- lisa SaaS platform
- All lisa business activities
Note: lisa currently operates as a simple partnership (Einfache Gesellschaft) under Swiss law. Upon incorporation of lisa GmbH, this Privacy Policy transfers automatically to lisa GmbH.
2. Data Controller
lisa i.G. is the Data Controller for all data processing described in this policy.
Contact:
- Co-Founder & Privacy Contact: Thierry Schuepbach
- Address: [Address TBD at GmbH registration] — Zurich, Switzerland
- Email: legal@runlisa.ch
- DPO / Privacy requests: dpo@runlisa.ch
3. Categories of Personal Data
3.1 Website Visitors
When you visit our website, we process:
- Technical data: IP address, browser type, pages visited, timestamps
- Cookie data: Session IDs, preferences (see Cookie Policy for details)
- Contact data (if you submit a contact form): name, email, message
3.2 lisa Customers (Assessment & Subscription)
When you use the lisa platform, we process:
A. Account & Billing Data
- Company name, address, contact person
- Email, phone
- Billing address (not credit card numbers — payments processed via Stripe)
- Subscription tier, contract duration
B. M365 Configuration Data (Assessment / Scanning)
- Security configurations (MFA policies, retention policies, etc.)
- Entity counts (user count, group count, app registrations)
- Audit logs (what was scanned, when, errors)
NOT processed:
- Email contents
- File contents (OneDrive, SharePoint)
- Chat messages (Teams)
- Calendars, contacts, or other user-generated content
- Passwords, API keys, or secrets
C. Pseudonymized Data
- Entity identifiers are pseudonymized immediately upon collection (HMAC-SHA256 hashing)
- Example: user "john.doe@customer.com" → hash "a3f7e2b91c..." (not reversible)
- Assessment results are not linked to real user identities
3.3 Special Categories of Data
lisa does not process special categories of data (race, ethnicity, religion, health, biometrics).
4. Legal Basis for Processing
| Data type | Legal basis | Details |
|---|---|---|
| Billing data | Contract performance (GDPR Art. 6(1)(b)) | Required for invoicing and account management |
| M365 configuration data | Contract performance (GDPR Art. 6(1)(b)) | Customer grants explicit consent via OAuth |
| Website visitor data | Legitimate interest (GDPR Art. 6(1)(f)) | Understanding usage, website optimization |
| Email marketing | Explicit consent (GDPR Art. 6(1)(a)) | Only for active subscribers |
| Non-essential cookies | Explicit consent (ePrivacy Directive) | Only after consent via banner |
5. Data Retention
| Data type | Retention period | Reason |
|---|---|---|
| Billing data | 10 years | Swiss tax law (invoice retention) |
| Assessment findings | Duration of subscription | Product dashboard access |
| M365 raw scan data | 30 days | Archived; then deleted |
| Website logs | 30 days | Security and optimization |
| Email lists (newsletter) | Until unsubscribe | Marketing; unsubscribable at any time |
| Cookies | See Cookie Policy | Depends on type (session to 12 months) |
After contract termination, lisa performs cryptographic erasure of your tenant: all encryption keys, pseudonym mappings, and PII are deleted, and the key linking any remaining data to your organization is destroyed. Assessment findings, security signals, and entity statistics are retained after this point only in de-identified form — with no way to re-link them to you — and are kept indefinitely for product improvement purposes (see Data Processing Agreement §3.2 and §4.5 for the technical detail). Billing data is retained separately for tax purposes (see above).
6. Third Parties & Sub-processors
We share data only with parties necessary to provide the service.
6.1 Non-critical recipients (no customer data)
- Stripe (payment processing) — billing address only
- GitHub — code repository (no customer data)
- Google Workspace — internal email (no customer data)
6.2 Critical recipients (with customer data)
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase | Database (findings, configs, metadata) | Switzerland (Zurich) | DPA signed — Adequacy Decision Art. 45 GDPR |
| Anthropic Claude API | Findings synthesis | USA | Standard Contractual Clauses |
| Microsoft Graph API | M365 configuration access (read-only) | Customer's tenant | Microsoft OST |
Important: lisa does not send raw tenant data to Anthropic — only pseudonymized, aggregated signals.
6.3 No sharing between customers
lisa does not share your findings with other customers. Findings are confidential.
6.4 Anonymized data for marketing & thought leadership
lisa may use anonymized, aggregated insights for marketing and thought leadership:
Permitted:
- Aggregate statistics (e.g., "73% of Swiss M365 tenants have MFA gaps")
- Industry benchmarks for whitepapers, blog posts, reports
- Named case studies — only with explicit written customer consent
Not permitted:
- Identifying a specific customer (name, domain, size, industry combined)
- Raw tenant data or specific findings
- Sharing with third parties
Legal basis: Legitimate interest (GDPR Art. 6(1)(f) / nDSG Art. 6).
7. International Data Transfers
7.1 Transfers to the USA (Anthropic)
Protected by Standard Contractual Clauses (SCCs) — GDPR Art. 46(2)(c). Anthropic has adopted SCCs per EU adequacy requirements.
7.2 Swiss perspective
lisa complies with the Swiss Federal Act on Data Protection (nDSG, in force September 2023), including Arts. 6–16 (data processing) and Arts. 19–24 (data subject rights).
8. Your Rights
8.1 Access (GDPR Art. 15 / nDSG Art. 15)
You may request what data we hold about you, what we use it for, and who we share it with.
8.2 Correction (GDPR Art. 16 / nDSG Art. 17)
You may request correction of inaccurate or incomplete data.
8.3 Deletion (GDPR Art. 17 / nDSG Art. 10)
You may request deletion of your data, except where we have an active subscription or legal retention obligation (e.g., tax law).
8.4 Restriction (GDPR Art. 18)
You may request that we freeze processing of your data while we investigate a complaint.
8.5 Objection (GDPR Art. 21)
You may object to processing for marketing purposes:
- Email marketing: Unsubscribe link in every email
- Cookies: Reconfigure via the cookie consent banner
8.6 Portability (GDPR Art. 20)
You may request your data in a portable format (CSV, JSON).
Response time: All requests answered within 30 days. Contact: dpo@runlisa.ch
9. Security Measures
- Encryption in transit — HTTPS/TLS for all connections
- Encryption at rest — AES-256 (Supabase)
- Read-only Graph API permissions — no write access to M365
- Pseudonymization — entity identifiers hashed immediately on collection
- Access controls — lisa staff cannot view raw tenant data
- Audit logging — all access is logged
Breach notification: If we suffer a data breach, we will notify affected customers within 72 hours (GDPR Art. 33).
10. Cookies & Tracking
See our separate Cookie Policy (cookie-policy.md) for details on which cookies we set, why, and how to disable them.
11. Children's Privacy
lisa is not directed at children. We do not process data from individuals under 16 years of age.
12. Supervisory Authorities
If you have a complaint, you may contact your local data protection authority:
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC) — https://www.edoeb.admin.ch
- EU: Your national data protection authority
- UK: Information Commissioner's Office (ICO) — https://ico.org.uk
13. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated 30 days in advance via email or website notice.
14. Contact
Questions about privacy or data subject requests (access, deletion, etc.)?
Email: dpo@runlisa.ch Address: [Address TBD at GmbH registration] — Zurich, Switzerland