Security & Privacy
Your data deserves the best possible protection. Evoya AI is designed around the requirements of the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR) and relies on transparent, controllable security standards.
- Data protection under FADP & GDPR
- ISO 27001-certified data centres
- Hosting in Switzerland
Our Security Standards at a Glance
Clear standards for data protection, security, and control – transparently documented.
Swiss Hosting
Platform data is stored by default in ISO 27001-certified data centres in Switzerland. When using international AI models, the respective provider's terms also apply.
Data Protection under FADP and GDPR
Platform and processes are designed around the Swiss FADP and the EU GDPR. Our data processing agreement (DPA) applies to business customers.
Encrypted Transmission
Data is transmitted encrypted via TLS – protecting sensitive content in transit.
Confidentiality & Access Control
Clear role and access concepts ensure that data is only accessible to authorized persons and for defined purposes.
Zero Data Retention
You decide how long your chat content is stored, or use Zero Data Retention. We transparently indicate whether a model provider also offers Zero Data Retention.
Transparent AI Models
For every AI model you see the provider and server location – so you can choose the right level of data protection for each use case.
No Model Training with Customer Data
We do not use your data to train AI models. We connect third-party models via business APIs whose providers commit not to use API data for training.
On-Premise Available
For the highest requirements for control and compliance: operation entirely within your own infrastructure possible.
Frequently Asked Questions on Security & Privacy
The storage location of your data depends on the selected AI model. Platform data is stored by default in ISO 27001-certified data centres in Switzerland and is subject to the Swiss FADP. When using international AI models, inputs are processed by the respective provider under its terms. For each model, we transparently show the server location.
Evoya AI is designed around the requirements of the Swiss FADP and the EU GDPR. Our data processing agreement (DPA) applies to business customers. Whether a specific use is compliant also depends on the data you enter and the AI models you choose – which is why we show the server location for every model. Details can be found in our Privacy Policy.
No. We do not use your inputs and data to train AI models, only to provide our services. We connect third-party models via their business APIs; the providers commit in their terms not to use API data for training.
Zero Data Retention means that your chat content is not stored on our platform after the session ends. You decide how long chat content is stored. Please note: some model providers temporarily store inputs under their own terms, e.g. for abuse monitoring. We indicate on the platform which providers support Zero Data Retention.
For each available AI model, we transparently display the server location. This allows you to select the appropriate model with the desired data protection level for each use case.
Yes, for organizations with particularly high security requirements, we offer on-premise installations. All data remains on your own servers and operation takes place entirely within your infrastructure. More information can be found on our page about on-premise solutions.
Yes. You can delete chat histories on the platform yourself. On request, we provide a copy of your data in a common electronic format, including up to 30 days after the end of the contract; your data is deleted thereafter. You also have the right to access, rectification, erasure and data portability under the FADP and GDPR.
Questions About Security & Privacy?
Our team is happy to answer your questions about security, privacy, and compliance.