Last updated: 23 August 2026
Privacy Policy
This Privacy Policy explains how Alex Földvári, trading as "Solory", collects, uses, shares and protects personal data in connection with the Solory service at solory.ch. We take data protection seriously and process personal data in accordance with the Swiss Federal Act on Data Protection (revised FADP / revDSG, in force since 1 September 2023) and, where it applies, the EU General Data Protection Regulation (GDPR).
At a glance
| Question | Short answer | Full answer in |
|---|---|---|
| Who holds my data? | Solory, a Swiss sole proprietorship in Zurich. | Section 1 |
| Whose data is it? | Yours - and the data you keep about your own clients. Two different roles. | Section 2 |
| What is collected? | Your account details, the business records you enter, and technical log data. | Section 3 |
| Why? | To run the service you asked for, to bill you, to keep it secure, and to meet legal duties. | Section 4 |
| Is it used to train AI? | No. Our AI provider is contractually barred from training on it. | Section 5 |
| Am I tracked on the website? | Only with your consent. Refuse, and no analytics script is loaded at all. | Section 6 |
| Are the emails tracked? | Yes. Our emails record whether you opened them and which links you clicked. You can stop it. | Section 6 |
| Can anyone at Solory see my data? | Only to support you, and every such session is recorded in your audit log. | Section 11 |
| Who else sees it? | A short list of named service providers, each under a written contract. | Section 7 |
| Is it sold? | No. We do not sell personal data and do not share it for third-party advertising. | Section 7 |
| Where is it kept? | In Europe by default. Every exception is named. | Section 8 |
| For how long? | While your account exists, plus the retention the law requires. | Section 9 |
| What can I do? | Export it, correct it, delete it, object - most of it yourself, in the app. | Section 10 |
1. Controller
- Responsible person / controller
- Alex Földvári (Solory)
- Address
- Wartauweg 19, 8049 Zürich, Switzerland
- support@solory.ch
The person named above decides why and how personal data is processed for the purposes described in this policy, and is your point of contact for any data-protection question or request.
2. Our two roles
We process personal data in two distinct roles. First, we are the controller of the personal data of our own account holders (for example your name, email, login and billing details) and of visitors to our website. This policy covers that processing.
Second, when you use the Service to manage information about your own clients, contacts, leads and correspondents, you are the controller of that data and we act only as your processor (Auftragsbearbeiter), on your instructions. That relationship is governed by our Data Processing Agreement, not by this policy. You are responsible for informing your own clients about your use of the Service and for having a lawful basis to process their data.
3. Categories of personal data we process
- Account data: your name, email address, password (stored only as a secure hash), language and interface preferences, and any team or collaborator relationships.
- Content data: the business information you enter or upload, such as clients, leads, projects, quotes, invoices, expenses, payments, contracts, documents, calendar entries and email you send or receive through the Service. This may contain personal data about third parties, for which you are the controller (see section 2).
- Billing data: your chosen plan, subscription status and payment records. We do not store full card numbers.
- Usage and technical data: log data such as IP address, device and browser information, timestamps, and security and audit events generated when you use the Service.
- Support and communications data: the content of messages you send us and our replies, including support tickets and in-app chat.
- Signature data: when a contract or quote is signed through the Service, we record the signer's email address, the IP address and browser used, the time of signature, the one-time code sent to confirm it, and the drawn signature image. This is evidence that the signature happened, and it is deliberately kept with the signed document.
- Location data, only if you switch it on: the timer can record the coordinates where a work session was started and stopped. This is off unless you enable it and your browser asks for permission each time.
- Notification data: if you enable browser notifications, the address your browser gives us to reach that device, together with the keys needed to encrypt the message. If you connect the Telegram assistant, your Telegram user id.
- Waiting-list data: if you signed up before launch, your name, email, language, the campaign parameters of the link you arrived through, and the personal discount code we issued to you.
4. Purposes and legal bases
We process personal data for the following purposes. Under the GDPR, where it applies, the corresponding legal bases are shown in brackets.
- To provide, operate and maintain your account and the Service, including its core features (performance of a contract, Art. 6(1)(b) GDPR).
- To handle billing, subscriptions and the Free/Pro plans (performance of a contract, Art. 6(1)(b) GDPR).
- To keep the Service secure, prevent abuse and fraud, and maintain audit logs (legitimate interests, Art. 6(1)(f) GDPR; under the revDSG, our overriding interest in a secure service).
- To provide support and respond to your requests (performance of a contract and legitimate interests, Art. 6(1)(b) and (f) GDPR).
- To improve and develop the Service, using data in an aggregated or minimised form where possible (legitimate interests, Art. 6(1)(f) GDPR).
- To send service messages you need to receive, such as security, billing or important account notices (performance of a contract and legitimate interests). Optional messages such as a newsletter are sent only with your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
- To comply with legal obligations, including accounting and record-keeping duties under Swiss law (legal obligation, Art. 6(1)(c) GDPR).
Under the revDSG, processing by a private person is lawful when it does not unlawfully breach the personality of the data subject; we rely on the performance of our contract with you, your consent where required, applicable law, and our legitimate interests as the justification for the processing described above.
5. AI features
Some features use a third-party artificial-intelligence provider (OpenAI) to draft text, summarise your data, or read documents you submit to those features. Only the content needed to perform the task you invoked is sent, over an encrypted connection. Our AI provider processes this data on our behalf to return a result and, under our agreement with it, does not use data submitted through its API to train its models. AI output can be inaccurate and is always presented to you as a draft to review before you rely on it. We do not use these features to take decisions about you by automated means alone that would produce legal effects for you or similarly significantly affect you: they prepare text and summaries for you to check and act on.
One use is not something you press a button for: when you save an expense, its description and supplier name are sent to the same provider to compute a numeric representation, which is what lets the app suggest a category for the next similar expense. It happens only while AI features are enabled for your account, and you can turn them off under Settings.
AI features can be switched off for your whole account. With them off, nothing is sent to the AI provider - including the automatic step described above.
6. Cookies, website measurement and email tracking
We use only strictly necessary, first-party cookies and similar storage. Specifically: a session cookie that keeps you signed in, a cookie that remembers your chosen language, and a cookie that remembers interface preferences such as whether the sidebar is collapsed. Your theme choice is stored locally in your browser.
These strictly necessary cookies are set without asking, because the Service cannot be provided without them. A further cookie records your cookie choice itself, so that we do not have to ask again on every page.
On our public website we also use Google Analytics 4, a measurement service of Google Ireland Limited, to understand how the site is found and used: which pages are read, which country a visit came from, and which advertisement or link brought a visitor to us. This is not strictly necessary, so it runs only if you agree to it. Until you agree, no Google script is loaded and nothing is sent to Google.
Where you do agree, Google Analytics sets first-party cookies (named _ga and _ga_*) and receives your shortened IP address, your device and browser type, an approximate location derived from that IP address, and the pages you open. We reduce page addresses to their general shape before they are sent: an address such as /invoices/<identifier> is transmitted as /invoices/[id]. Pages reached through a personal link we send to you or to your clients - client portal, contract signature, quote and file-share links - are excluded from measurement entirely, and their addresses are never transmitted.
If you additionally agree to marketing cookies, the same measurement data may be used to evaluate our advertising campaigns and to build advertising audiences. Declining this changes nothing about the Service and nothing about the measurement above.
You can change or withdraw your choice at any time using the Cookie settings link in the footer of every page, or under Settings, Privacy once signed in. Withdrawal takes effect immediately for everything that follows. You can also clear cookies in your browser at any time, though signing in again will set the session cookie needed to use the Service.
When you make that choice we record it on our server: what you agreed to, when, from which country, and which version of this policy was in force. We keep this as proof that consent was given, which the law requires us to be able to show, and we keep it for as long as we may have to demonstrate it.
Separately from cookies, the emails we send you are tracked. Each message contains a small invisible image and links that pass through our email provider, so we can see whether the message was opened, when, and which links were clicked. We use this to tell whether important messages are arriving at all, to spot delivery problems, and to stop writing to addresses that no longer work. This is not done through a cookie and does not depend on your cookie choice.
You can prevent it at your end: most email programs can be set not to load remote images, which stops the open from being recorded, and you can copy a link rather than clicking it. We would rather be exact than reassuring here - our email provider applies this to our whole sending domain and offers no way to switch it off for one recipient or one message, so we cannot honour an objection by disabling it for your address alone. If you object, write to us and we will stop reading the results for your address and delete the ones we hold.
The same tracking applies to email that YOU send to your own clients through the Service, and the results are shown to you in the message history. For those messages you are the controller: it is for you to decide whether that tracking is lawful and proportionate in your own relationship with your recipients, and to tell them about it in your own privacy notice. It cannot currently be turned off for individual messages, because it is a property of the sending domain rather than of the message.
7. Recipients and subprocessors
We do not sell your personal data. We share it only with the service providers that help us run the Service, each bound by a data-processing agreement and permitted to use the data only to provide their service to us. Our current subprocessors are:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | Zurich, Switzerland (eu-central-2) |
| Vercel | Application hosting, serverless compute and content delivery | Frankfurt (fra1), with a global edge network |
| Mailgun (Sinch Email) | Sending and receiving business and transactional email for your own verified domains, and the open/click tracking described in section 6 | US (EU region available) |
| OpenAI | AI assistant, drafting, document reading and expense categorisation | US (API data not used to train models) |
| Stripe | Subscription payments and card processing. Receives your email, billing details and what you bought - never your business records. | EU / US |
| Google (Google Ireland Limited) - Analytics | Website measurement on our public pages, only if you consent. Receives no account or client content. | EU / US |
| Google - Calendar | Only if you connect your calendar: the events you choose to sync, including their titles, descriptions, locations and times. | EU / US |
| Telegram | Only if you connect the assistant: the messages you exchange with it, which contain whatever you ask about. | Outside Switzerland and the EU |
| Discord | Only if you configure a notification webhook: the notifications you chose to forward, which name the client or invoice concerned. | US |
The last four are OPTIONAL and off until you switch them on. Telegram and Discord are consumer messaging platforms that we do not control and that are not bound to us by a data-processing agreement; connecting them is your decision, and what you route through them leaves our infrastructure. We would not recommend forwarding client data to either of them.
We may also disclose personal data where required by law, to enforce our Terms, or to protect our rights, safety or property or those of others. A current list of subprocessors is maintained in our Data Processing Agreement.
8. Where your data is stored, and international transfers
Your account and content data are held in a database hosted in Switzerland, in the Zurich region (eu-central-2) operated by our infrastructure provider. Some of our subprocessors process limited data outside Switzerland, in the European Union or the United States, as shown in the table above (for example email delivery, the AI features and, where you have consented to it, website measurement).
Where personal data is transferred abroad, we rely on appropriate safeguards: transfers to countries recognised by the Swiss Federal Council and the EU as providing adequate protection, and, for other countries such as the United States, the European Commission's Standard Contractual Clauses together with the Swiss addendum recognised by the FDPIC, plus additional technical measures such as encryption in transit.
9. How long we keep data
We keep personal data only as long as needed for the purposes above. Account and content data are kept for as long as your account is open. When you close your account, we begin the deletion process described in section 10.
Some data is kept longer where the law requires it, in particular records needed to meet accounting and retention duties under the Swiss Code of Obligations (generally up to ten years). Backups are rotated and overwritten on a regular cycle.
The audit log is different, and we would rather say so plainly than imply otherwise. It records who did what in your account - and every time we accessed it to support you - and it cannot be edited or deleted, by you or by us. That is the point of it: a record that can be quietly amended is no evidence of anything. When your account is erased the entries stay, for the same reason - but your name, email address, IP address and browser details are scrubbed out of them, which is the part of an entry that identifies you.
10. Your rights and how to exercise them
Subject to the conditions of the revDSG and the GDPR, you have the right to access your personal data, to have inaccurate data corrected, to have data deleted, to receive your data in a portable format, to object to or request restriction of certain processing, and, where processing is based on consent, to withdraw that consent at any time without affecting past processing.
You can exercise the most important of these rights yourself, directly in the app, without contacting us:
- Access and portability: from Settings > Privacy you can export a complete copy of your data as a ZIP archive containing a structured JSON file, provided under your right of access and data portability.
- Erasure: from Settings > Privacy you can request account deletion. Deletion starts a 30-day grace period during which you can cancel, after which your sign-in is permanently disabled and your email address removed from it, your files, your stored credentials and every connected channel are deleted, and the rest is irreversibly anonymised.
- Rectification: you can correct most of your data at any time by editing it directly in the app.
- Direct marketing: you can object to receiving marketing messages at any time and without giving a reason, by using the unsubscribe link in any such message or by writing to us. We then stop, and we keep only the record needed to honour the objection.
Erasure has limits, and they are worth stating before you rely on it rather than after. What survives, and why:
- Accounting records - invoices, the payments booked against them and the expenses claimed - are kept for ten years from the end of the financial year, because Art. 958f of the Swiss Code of Obligations requires it. The personal details attached to them are scrubbed as far as the record still makes sense without them.
- Contracts that were signed stay, with the signature evidence described in section 3. An executed agreement is not ours alone to erase: the other party has a legitimate interest in it, and a signature that can be deleted is not evidence of anything.
- The audit log stays as an audit log. After an erasure the entries remain, with your name, email address, IP address and browser details scrubbed out of them.
- The deletion request itself is kept, so that we can show when the request was made and when it was carried out.
- Backups are not edited. A deletion reaches them as they are rotated and overwritten on their normal cycle, within a few weeks.
If a step of the erasure fails, the request stays open and is retried, rather than being marked complete. You will not be told your data is gone while any of it is not.
For any other request, or if you need help, contact us at support@solory.ch. We may need to verify your identity before acting. You also have the right to lodge a complaint with a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC / EDÖB, Bern); in the EU, your local data-protection authority.
11. Security
We take appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access. These include database row-level isolation so each account can reach only its own data, optional two-factor authentication, encryption of data in transit, private file storage with short-lived access links, least-privilege access controls, and audit logging. No system can be guaranteed completely secure, so we cannot promise absolute security, but we work continuously to protect your data.
Solory is operated by one person, who administers the platform and can open an account in order to answer a support request or investigate a fault. Doing so writes a record to that account's own audit log, which the account holder can read; it is visible on screen while it lasts; and it is limited to what the question needs. Nobody else has access.
If a breach of personal data does occur, we have a written procedure with a fixed clock rather than an intention to do our best. We notify the Federal Data Protection and Information Commissioner where the revDSG requires it, and, where the GDPR applies, the competent supervisory authority within 72 hours of becoming aware. Where a breach is likely to put you at high risk we tell you directly, in your own language, saying what happened and what it means for you. Every breach is recorded internally, including those that did not meet the threshold to be notified.
12. Children
The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this Privacy Policy to reflect changes to the Service or to legal requirements. We will post the updated version with a new date and, for material changes, take reasonable steps to notify you. Please review it from time to time.
14. Contact
For any question about this policy or about how your personal data is handled, contact Alex Földvári at support@solory.ch or by post at Wartauweg 19, 8049 Zürich, Switzerland.