Data Security
How we protect your information
At sweetch AI, we take the security of your data seriously. This page outlines the technical and organizational measures we have implemented to protect your personal information from unauthorized access, disclosure, alteration, or destruction.
Technical Security Measures
Encryption
All data transmission is encrypted using industry-standard SSL/TLS protocols. Data at rest is encrypted using AES-256 encryption.
Secure Infrastructure
Our infrastructure is hosted on Supabase, a secure cloud platform with SOC 2 Type II certification and GDPR compliance.
Access Controls
Multi-factor authentication, role-based access controls, and principle of least privilege ensure only authorized personnel can access sensitive data.
Regular Audits
We conduct regular security audits, vulnerability assessments, and penetration testing to identify and address potential security issues.
Payment Data Security
PCI-DSS Compliance: All payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment processor. We never store your credit card information on our servers.
Encrypted Transactions
Fraud Detection
3D Secure Support
Organizational Security Measures
- Security Training: All employees undergo regular security awareness training
- Confidentiality Agreements: All staff sign strict confidentiality agreements
- Incident Response Plan: We maintain a comprehensive incident response plan
- Data Backup: Regular automated backups with encryption and secure storage
- Vendor Management: All third-party vendors undergo security assessments
Session Management
We implement robust session management to protect your account:
- Secure session tokens with automatic expiration
- Device-based session tracking
- Multi-device login detection and management
- Automatic logout on suspicious activity
- Session invalidation on password change
Compliance & Certifications
sweetch AI complies with the following data protection regulations:
GDPR
General Data Protection Regulation (EU)
Swiss DPA
Swiss Federal Data Protection Act
Data Breach Response
In the unlikely event of a data breach, we will:
- Contain and investigate the breach immediately
- Notify affected users within 72 hours
- Report to relevant data protection authorities as required by law
- Take corrective actions to prevent future breaches
- Provide support and guidance to affected users
Your Security Responsibilities
While we implement strong security measures, you also play a crucial role:
- Use a strong, unique password for your account
- Never share your login credentials
- Log out when using shared devices
- Keep your email account secure
- Report suspicious activity immediately
- Keep your devices and software updated
Security Concerns?
If you have questions about our security practices or believe you've discovered a security vulnerability, please contact us immediately:
CoreTrek GmbH
Email: hello@sweetch.app
For security vulnerabilities, please use the subject line "SECURITY" for priority handling.