Privacy Policy
Version 2026-08 · 7 August 2026This policy describes which personal data we process, for which purposes and on which legal basis. The German version is authoritative.
1. Controller and contact
The controller for the processing of personal data in connection with RealityTwin.io is Ruznic Marketing, Leimgrubstrasse 5, 8340 Hinwil, Schweiz, owner Ajdin Ruznic.
For data protection questions and to exercise your rights: hello@realitytwin.io.
We have not appointed a data protection adviser within the meaning of Art. 10 revFADP, as there is no obligation to do so. Please direct enquiries to the address above.
Note: we keep under review whether a representative in the EU under Art. 27 GDPR is required for us. While none is designated, please contact the address above directly.
2. Scope
This policy applies to our websites, the application, the programming interfaces and the associated services.
It does not apply to third-party websites we link to. Their operators alone are responsible for their processing.
The Swiss Federal Act on Data Protection (revFADP) applies and, where our processing falls within its territorial scope, the General Data Protection Regulation (GDPR).
3. Our role: controller or processor
For our customers' data — account, contract, billing, support, use of the application — we are the controller within the meaning of Art. 5(j) revFADP and Art. 4(7) GDPR.
For data of people who talk to a customer's AI Twin or provide it with their contact details, we are the processor. The controller in that case is the customer operating the Twin. Rights concerning that data must be exercised against that customer; on request we will name the responsible entity where we are able to.
Processing on behalf is governed by our Data Processing Addendum, which implements the requirements of Art. 9 revFADP and Art. 28 GDPR.
4. Which data we process
Account data: name, email address, password in hashed form, language, time of registration and last sign-in, acceptance of the Terms and this policy with timestamp and document version.
Company data: company name, legal form, address, country, industry, website, logo, description, verification details and — when using the marketplace — invoicing and payout details including IBAN and account holder.
Content data: texts, documents and website content you provide, their machine representations (embeddings) and the answers generated from them.
Usage and log data: requests, timestamps, IP address, browser identification, error logs, security events.
Communication data: support requests, email correspondence, information from contact forms.
Signature data: when contracts are signed electronically we record the signatory's name, the time, the IP address, the browser identification, the email address and a cryptographic checksum of the signed text. This data serves as evidence of the signature.
Payment data: payment status, amount, currency, reference. Full card details are processed exclusively by the payment service provider; we do not receive them.
5. Purposes and legal bases
Providing the Service, the account, and generating and operating the Twin: performance of the contract (Art. 31(2)(a) revFADP; Art. 6(1)(b) GDPR).
Billing, payment processing and payouts: performance of the contract and compliance with legal obligations (Art. 6(1)(b) and (c) GDPR).
Security, abuse prevention, logging, rate limiting: legitimate interest in secure operation (Art. 31(1) revFADP; Art. 6(1)(f) GDPR).
Support and communication: performance of the contract and legitimate interest in handling enquiries.
Product improvement based on aggregated, non-personal analysis: legitimate interest.
Evidence of consents and signatures: legitimate interest in being able to prove them, and compliance with statutory retention duties.
Product emails and newsletters: consent where required (Art. 6(1)(a) GDPR), revocable at any time via the unsubscribe link or the notification settings.
Compliance with legal obligations, in particular accounting and tax retention duties: Art. 6(1)(c) GDPR.
6. Processing by language models
To generate answers we transmit requests and relevant excerpts of the knowledge base to language model providers. These providers act as processors or sub-processors.
If you enter personal data into a conversation, it is transmitted to the model provider as part of the request. Please do not enter information you do not want processed.
We do not use your content to train general language models and have agreed corresponding terms with the providers we use, where their offering provides for this.
Users are informed that they are interacting with an AI system.
The Twin's answers are logged with a timestamp, source attribution and a checksum, to ensure traceability and evidential value.
7. Cookies and similar technologies
We use technically necessary cookies to enable sign-in, session management, language selection and security. These are required for operation; the legal basis is our legitimate interest in a functioning service.
The language setting is stored in a cookie and in the browser's local storage so that the chosen language persists.
Cookies can be deleted or blocked via your browser settings. If necessary cookies are blocked, the Service cannot be used, or only to a limited extent.
8. Recipients and sub-processors
We pass personal data to carefully selected service providers that support our operations: hosting and database, content delivery and overload protection, language model providers, payment processing and transactional email delivery.
The complete, current list of sub-processors with purpose and region is publicly available on the sub-processors page.
Otherwise we disclose data only where you have consented, where we are legally or officially required to, or where necessary to establish or defend legal claims.
We do not sell personal data.
9. Disclosure abroad
Application data is stored in the European Union (Ireland). From a Swiss perspective the European Union provides adequate protection within the meaning of Art. 16(1) revFADP.
To generate answers and for individual infrastructure services, data may be transferred to countries without protection recognised as adequate by Switzerland or the EU, in particular the United States.
We base such transfers on the European Commission's Standard Contractual Clauses in the version recognised by the FDPIC, or on another permitted mechanism under Art. 16 f. revFADP and Art. 46 GDPR, supplemented by appropriate additional measures.
10. Retention and deletion
We retain personal data for as long as necessary for the stated purposes or as required by statutory retention obligations.
Account data and content remain available for export for 30 days after the contract ends and are then deleted.
Records of accounting relevance, including invoices and payout evidence, are retained for ten years (Art. 958f CO).
Evidence of consents and electronic signatures is retained for the limitation periods of the relevant claims, generally ten years (Art. 127 CO).
Security and server logs are generally deleted or anonymised after 90 days, unless needed to investigate a specific incident.
11. Data security
We take appropriate technical and organisational measures to protect against unauthorised access, loss and misuse. These include transport encryption, encryption at rest at the hosting provider, tenant-separated storage with row-level access control, least-privilege access restrictions and regular backups.
Absolute security cannot be guaranteed for transmission over the internet.
In the event of a data security breach likely to result in a high risk to the persons concerned, we notify the FDPIC under Art. 24 revFADP and, within the scope of the GDPR, the competent supervisory authority under Art. 33 GDPR and, where required, the data subjects.
12. Your rights
You have the right to information about the personal data we process (Art. 25 revFADP; Art. 15 GDPR).
You have the right to rectification of inaccurate data (Art. 32 revFADP; Art. 16 GDPR) and to erasure and restriction of processing where the statutory conditions are met (Art. 17 and 18 GDPR).
You have the right to receive or transfer your data in a common electronic format (Art. 28 revFADP; Art. 20 GDPR).
You may object to processing where we base it on a legitimate interest (Art. 30(2) revFADP; Art. 21 GDPR).
You may withdraw consent at any time with effect for the future.
A message to the address in section 1 is sufficient to exercise these rights. To prevent misuse we may request proof of identity. We respond within 30 days; if that is not possible we inform you of the reasons and the expected timeframe.
13. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority.
In Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
Within the scope of the GDPR: the supervisory authority of your habitual residence, place of work or the place of the alleged infringement.
14. Automated decisions and profiling
We do not take decisions based solely on automated processing that produce legal effects or similarly significantly affect a person within the meaning of Art. 21 revFADP or Art. 22 GDPR.
The Service generates automated assessments, such as an estimate of the fit between companies or a prioritisation of enquiries. These are decision aids for users; a human always makes the decision.
The basis and composition of such assessments are disclosed in the product so that they remain traceable.
15. Data of visitors to a Twin
When you talk to a company's Twin, your inputs and any contact details are transmitted to that company. That company, not us, is responsible for the further processing.
We process this data exclusively on behalf of and on the instructions of that company, and to ensure secure operation.
Exercise your rights against that company. If you nevertheless contact us, we will forward your request or name the responsible entity where we are able to.
16. Changes to this policy
We adapt this policy when our processing, the service providers we use or the legal situation changes.
The version in force is available on this page with a version designation and date. In the case of material changes we additionally inform customers in text form.
Version 2026-08, effective 7 August 2026.
17. Language versions
This Privacy Policy exists in German and English. In the event of discrepancies, the German version prevails.
Contact: Ruznic Marketing, Leimgrubstrasse 5, 8340 Hinwil, Schweiz, hello@realitytwin.io.