Privacy Policy
Version 1.1, in force since 30 September 2026 (fonts hosted on sokkan.ch, log and backup retention specified; 1.0: same day). This policy meets the Swiss Federal Act on Data Protection (FADP) and, for people located in the European Union or the EEA, the General Data Protection Regulation (GDPR, Art. 13 and 14). This is a translation of the French text; in case of divergence, the French text prevails. Version française · Deutsch (Datenschutzerklärung).
2. Scope
3. Data processed, purposes, legal bases
4. The Nina assistant (AI)
5. What we do not do
6. Processors and recipients
7. Transfers outside Switzerland and the EU
8. Retention
9. Cookies and local storage
10. Your rights
11. Security
12. Changes
1. Controller
Ninabot Sàrl, c/o Openest coworking SA, Chemin de Riantbosson 19, 1217 Meyrin, Switzerland
Company number (UID): CHE-287.575.522 · Commercial Register of the Canton of Geneva
For any question or request about your data: [email protected] (subject “Data protection”). We answer within the legal deadlines, as a rule within 30 days.
Full legal notice (Impressum): sokkan.ch/en/legal.
2. Scope
This policy covers the sokkan.ch website, the chat with the Nina assistant on this site, the SOKKAN Missions forms and the SOKKAN Cloud account (served by app.sokkan.ch), and the few network exchanges between the self-hosted SOKKAN software and our servers.
- For these processing activities, Ninabot Sàrl is the controller.
- For the data a SOKKAN Cloud customer puts into their environment (code, files, project memory, sessions), the customer is the controller and Ninabot Sàrl acts as a processor (FADP Art. 9, GDPR Art. 28) under the data processing agreement (DPA), which lists the sub-processors of that service.
- SOKKAN installed on your own server (self-host) runs on your machine: its data stays with you and we have no access to it (see 3.8).
3. Data processed, purposes, legal bases
The legal bases below are those of the GDPR (Art. 6(1)). Under Swiss law, these activities follow the principles of Art. 6 FADP; none of them requires your consent within the meaning of the FADP.
3.1 Visiting the site
Like any web server, ours record for each request the IP address, date and time, requested page, referring page and browser identifier (user agent). These technical logs are used to run the site, secure it and diagnose incidents. Legal basis: legitimate interest (security and operation of the site, Art. 6(1)(f)).
The site is served by our own servers in Switzerland, behind the Cloudflare network (see section 6), which receives the same technical information to deliver pages and filter abuse. sokkan.ch logs are deleted after 30 days (daily rotation); for app.sokkan.ch, see section 8.
3.2 Cookie-free audience measurement
We measure traffic with Umami, open-source software that we host ourselves in Switzerland: no data goes to a third-party vendor. Umami sets no cookie, does not store your IP address and does not follow you across sites. It records page views, the referring page, browser, operating system and device type, language, country, region or city derived from the connection, and a few button clicks (for example “Book a demo”). Legal basis: legitimate interest (knowing which pages are useful, Art. 6(1)(f)).
3.3 Fonts
The site's fonts are hosted on sokkan.ch: your browser contacts no third-party font provider.
3.4 Chat with the Nina assistant
If you write to Nina, your message and at most the ten previous messages of the conversation are sent to our server (app.sokkan.ch), then to the language model that writes the answer (section 4). Legal basis: legitimate interest in answering your questions and, where relevant, pre-contractual steps (Art. 6(1)(f) and (b)).
3.5 E-mail
If you write to us (for example to [email protected]), we process your address, your message and whatever information it contains, to answer you and follow up. Legal basis: legitimate interest and, for an offer or a contract, pre-contractual steps or performance of the contract (Art. 6(1)(f) and (b)).
3.6 SOKKAN Missions
- Mission brief (sokkan.ch/en/missions): e-mail address, company, indicative budget, deadline, description, and whether you allow an anonymised publication on the missions board. The brief is stored and notified to us by e-mail; an acknowledgement is sent to you.
- Post-payment form: e-mail address, mission, brief, access information and definition of done, sent by e-mail to our team. Do not put passwords in it: we agree on a secure channel for access.
- Paying for a mission happens on a Stripe payment page. We never see or store your card number; Stripe gives us your name, e-mail address, the amount and the payment status.
- Developer network (sokkan.ch/en/missions/devs): e-mail address, Cloudflare Turnstile anti-bot check, then a link valid 24 hours to complete your profile: name, headline, stack, GitHub profile, links, experience, availability, motivation, country, declared self-employed status (Swiss AVS) and SOKKAN usage. Every profile is reviewed by a person before approval. If you apply for a mission, we record your address, the mission and your message.
- Public tenders (members' area): sign-in by a link sent to your e-mail address, and the tenders or roles you are interested in.
Legal basis: pre-contractual steps and performance of the contract (Art. 6(1)(b)); legal obligation for accounting records ((c)); legitimate interest for the anti-bot check ((f)).
3.7 SOKKAN Cloud account (app.sokkan.ch)
At sign-up: business e-mail address, company (optional), and the version of the terms and of the DPA you accept. Then: your plan, the resources you order, Stripe customer and subscription identifiers, your invoices and the inference volume consumed (token counts, never the content). Payment goes through Stripe; we never see your card number. Legal basis: performance of the contract ((b)); legal obligation to keep invoices ((c)).
3.8 Self-hosted SOKKAN software
The software contains no telemetry. Only three kinds of request reach our servers, and they carry only what any web request carries (IP address, user agent):
- downloading the installer and the archive from sokkan.ch;
- one update check per day (
sokkan.ch/dist/VERSION, user agentsokkan-selfhost/<version>), disabled withSOKKAN_UPDATE_CHECK=0; - the open-missions counter, fetched at most once every six hours with no identifier, disabled with
SOKKAN_FEATURE_MISSIONS_LINK=0.
Legal basis: legitimate interest (distributing the software and announcing updates, (f)).
4. The Nina assistant (AI)
Nina is an artificial intelligence, not a person. Its answers are generated automatically from a knowledge base about SOKKAN and may contain mistakes; for any commitment (price, contract), only a written answer from our team is binding.
- The model that writes the answers is served by Infomaniak, in Switzerland, through our inference gateway. Content is not kept there and trains no model.
- We do not keep the content of the conversation on our servers: our gateway keeps only an overall count of tokens consumed. Your IP address is used, in memory, to cap the number of messages per hour against abuse, and appears in the technical logs like any request (3.1).
- The history (last ten messages) is kept in your browser (local storage
nina_hist) so the conversation survives a page change. You can erase it by clearing this site's data in your browser. - Do not send Nina sensitive data or data about other people.
- No decision producing legal effects for you is taken solely by automated means.
5. What we do not do
- We do not sell or rent any data.
- We set no advertising trackers and do no profiling.
- We do not use your data, or the content of your environments, to train AI models.
6. Processors and recipients
Each provider acts only for the function shown. Providers specific to a SOKKAN Cloud customer's environment (Exoscale hosting, inference, administration channel) are listed in the DPA and on the Trust & Sovereignty page.
| Provider | Function | Location |
|---|---|---|
| Ninabot Sàrl (own servers) | Website, Umami audience measurement, app.sokkan.ch, inference gateway | Switzerland |
| Cloudflare, Inc. | Content delivery and protection (sokkan.ch, app.sokkan.ch), DNS, Turnstile anti-bot, routing of e-mail sent to @sokkan.ch | United States, global network |
| Infomaniak Network SA | Language model of the Nina assistant | Geneva, Switzerland |
| Google (Google Workspace) | Mailbox receiving e-mail sent to [email protected] and form notifications | United States / EU |
| Resend, Inc. | Transactional e-mail (acknowledgements, sign-in links); our sending domain is configured in Resend's EU region | Ireland, EU (sending); company in the United States |
| Stripe (Stripe Payments Europe, Ltd.) | Payments; Stripe also processes some data for its own obligations (fraud prevention, legal duties) under its own policy | Ireland, EU; United States |
| Exoscale (Akenes SA) | Backups of the SOKKAN Cloud control plane (accounts, missions); hosting of customer environments | Geneva, Switzerland |
We may also disclose data to an authority where the law requires it.
7. Transfers outside Switzerland and the EU
Our servers, the audience measurement and Nina's model are in Switzerland. Switzerland benefits from an adequacy decision of the European Commission: for a person in the European Union, processing in Switzerland is not a transfer to a non-adequate third country.
Some providers listed above (Cloudflare, Google, Resend, Stripe) may process data in the United States. These transfers are limited to what their function requires and are covered by the EU–US and Swiss–US Data Privacy Framework where the provider is certified, or otherwise by the European Commission's standard contractual clauses, recognised by the Swiss FDPIC.
8. Retention
- sokkan.ch technical logs: 30 days.
- app.sokkan.ch technical logs (application server): deleted by our server's automatic log rotation, which depends on volume rather than a fixed date (a few weeks in practice); copies sent to our monitoring tool are deleted after 15 days.
- Audience measurement: statistics without cookies or IP addresses, containing no identifier that could single you out; they have no automatic purge period and are used to follow traffic over time.
- Nina chat: content not kept on our servers; the history stays in your browser until you erase it.
- E-mail, Missions briefs and profiles: for the duration of the relationship (request, mission, application), then as long as a follow-up is useful; you may ask for deletion at any time, subject to legal obligations.
- SOKKAN Cloud account: as long as the account exists; on termination the environment is destroyed and its data deleted no later than 30 days after the end of the paid period (DPA, Art. 2). Control-plane backups (accounts and Missions data) are kept 60 days in Geneva (Exoscale) and 7 days on our server.
- Invoices and accounting records: 10 years, as Swiss law requires (Art. 958f Code of Obligations).
9. Cookies and local storage
sokkan.ch sets no advertising or analytics cookie.
| Name | Where | Purpose | Duration |
|---|---|---|---|
lang | sokkan.ch | Remembers the language you chose, only if you click FR / EN | 1 year |
nina_hist (local storage) | sokkan.ch | History of your conversation with Nina, in your browser | until erased |
| session cookie | app.sokkan.ch | Keeps you signed in to your SOKKAN Cloud account or the Missions area (httpOnly, secure) | 30 days |
These are strictly necessary for the service you ask for. The Cloudflare Turnstile check (developer sign-up) analyses technical signals from your browser to tell a human from a bot.
10. Your rights
At any time you may request access to your data, its rectification, its erasure, the restriction of a processing, a copy in a common machine-readable format (portability), object to a processing based on our legitimate interest, and withdraw any consent you gave. Write to [email protected]; we may ask you to confirm your identity.
If our answer does not satisfy you, you may contact the Swiss Federal Data Protection and Information Commissioner (FDPIC, Bern, edoeb.admin.ch). If you live in the European Union or the EEA, you may also lodge a complaint with the data protection authority of your country of residence, place of work or place of the alleged infringement.
Providing your data is neither a legal nor a contractual obligation, except what an order or an account requires: without an e-mail address we cannot answer you or open an account.
11. Security
All exchanges are encrypted in transit (HTTPS). Access to servers and databases is limited to the people who operate them. In case of a data breach likely to result in a high risk for you, we inform you and report it to the FDPIC and, for data subjects in the European Union, to the competent authority, within the legal deadlines.
12. Changes
Any change is published on this page with a new date of entry into force. SOKKAN Cloud customers are told of any significant change by e-mail.