Data Security

Data Security

How we protect your information

At sweetch AI, we take the security of your data seriously. This page outlines the technical and organizational measures we have implemented to protect your personal information from unauthorized access, disclosure, alteration, or destruction.

Technical Security Measures

Encryption

All data transmission is encrypted using industry-standard SSL/TLS protocols. Data at rest is encrypted using AES-256 encryption.

Secure Infrastructure

Our infrastructure is hosted on Supabase, a secure cloud platform with SOC 2 Type II certification and GDPR compliance.

Access Controls

Multi-factor authentication, role-based access controls, and principle of least privilege ensure only authorized personnel can access sensitive data.

Regular Audits

We conduct regular security audits, vulnerability assessments, and penetration testing to identify and address potential security issues.

Payment Data Security

PCI-DSS Compliance: All payment processing is handled by Stripe, a PCI-DSS Level 1 certified payment processor. We never store your credit card information on our servers.

Encrypted Transactions

Fraud Detection

3D Secure Support

Organizational Security Measures

  • Security Training: All employees undergo regular security awareness training
  • Confidentiality Agreements: All staff sign strict confidentiality agreements
  • Incident Response Plan: We maintain a comprehensive incident response plan
  • Data Backup: Regular automated backups with encryption and secure storage
  • Vendor Management: All third-party vendors undergo security assessments

Session Management

We implement robust session management to protect your account:

  • Secure session tokens with automatic expiration
  • Device-based session tracking
  • Multi-device login detection and management
  • Automatic logout on suspicious activity
  • Session invalidation on password change

Compliance & Certifications

sweetch AI complies with the following data protection regulations:

GDPR

General Data Protection Regulation (EU)

Swiss DPA

Swiss Federal Data Protection Act

Data Breach Response

In the unlikely event of a data breach, we will:

  1. Contain and investigate the breach immediately
  2. Notify affected users within 72 hours
  3. Report to relevant data protection authorities as required by law
  4. Take corrective actions to prevent future breaches
  5. Provide support and guidance to affected users

Your Security Responsibilities

While we implement strong security measures, you also play a crucial role:

  • Use a strong, unique password for your account
  • Never share your login credentials
  • Log out when using shared devices
  • Keep your email account secure
  • Report suspicious activity immediately
  • Keep your devices and software updated

Security Concerns?

If you have questions about our security practices or believe you've discovered a security vulnerability, please contact us immediately:

CoreTrek GmbH

Email: hello@sweetch.app

For security vulnerabilities, please use the subject line "SECURITY" for priority handling.