Privacy Policy

Zuletzt aktualisiert:

BG Image

Information about how Asemly GmbH processes personal data for edel.plus and the edel platform.

Version of 30 September 2026

1. Controller

Asemly GmbH, Blumenfeldstrasse 15, 8046 Zürich, Switzerland

Email: info@asemly.ch

edel is a product of Asemly GmbH.

2. Scope

This notice applies to the edel.plus website and the edel platform. The Swiss Federal Act on Data Protection applies. Where applicable, the EU General Data Protection Regulation and the German Telecommunications Digital Services Data Protection Act also apply. Section 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021) also applies to storing and accessing information on devices in Austria.

Edel uses and shares information received from Google APIs only in accordance with the Google API Services User Data Policy, including its Limited Use requirements. Section 14 explains the data, purposes, providers, human access and deletion in detail.

3. Website, contact and appointment booking

When you contact us through a form, we process your name, business email address, company and message. We use this information to handle your request, prepare a possible contract and maintain the business relationship. The legal bases are Article 31 FADP and, where applicable, Article 6(1)(b) and (f) GDPR.

Form submissions are processed through Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands, and forwarded to hoi@edel.plus by email.

Calendly loads in the appointment section only after you allow it through the cookie banner or privacy settings. We do not load Calendly content or scripts before your consent. Once enabled, Calendly LLC and its service providers may process your IP address, device and browser data, and the contact and appointment details you enter. Where applicable, loading the widget and accessing your device rely on your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. We process your booking for precontractual steps under Article 6(1)(b) GDPR and Article 31 FADP. You can withdraw consent at any time through Privacy settings.

4. Roles and responsibilities

For data in a customer tenant, the respective customer is the controller.

Asemly processes this data as a processor under Article 28 GDPR and Article 9 FADP.

For privacy enquiries, contact info@asemly.ch.

5. Platform purposes and legal bases

Website and platform operation, security and technical logs: legitimate interests under Article 6(1)(f) GDPR and Article 31 FADP.

User accounts, service delivery and support: contract performance under Article 6(1)(b) GDPR and Article 31 FADP.

Billing and statutory retention: compliance with legal obligations under Article 6(1)(c) GDPR.

Service information for existing customers: legitimate interests under Article 6(1)(f) GDPR. You may object at any time.

AI supported functions in customer tenants are processed on the customer's instructions under the contract and data processing agreement. Asemly does not make solely automated decisions through this website that produce legal or similarly significant effects.

6. Data categories and sources

Master data, contract data, usage and log data, support data and payment data. Data is collected directly from users or technically when our services are used.

7. Cookies and tracking

The website uses essential storage for operation, security and language selection. We store your Calendly choice locally in your browser so it applies across pages. The Calendly widget and script load only after your active consent. We currently use no other marketing or tracking technologies.

Essential access supports secure operation and your chosen language. In Germany, Section 25(2) TDDDG applies. In Austria, Section 165(3) TKG 2021 applies. Related personal data processing relies on Article 6(1)(f) GDPR and Article 31 FADP. You can accept or reject Calendly equally easily in the banner and change your choice at any time through Privacy settings. Withdrawal applies to future use.

Framer Analytics may provide aggregated usage statistics without cookies or cross device profiles. If the configuration changes or consent based analytics or marketing technology is added, we will obtain consent first and update this notice.

8. Recipients and processors

  • Hosting and forms: Framer B.V., Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands.

  • Appointment booking: Calendly LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA.

  • Platform operations: Microsoft Azure, with primary application servers, databases and search indexes in Switzerland.

  • Document storage: Google Cloud Storage in Switzerland for uploaded and imported documents and generated chat files.

  • Default AI processing: Infomaniak in Switzerland for AI chat and embeddings.

  • Customer-selected external AI providers and workflow destinations: according to explicit configuration; details appear in the Google API user data section.

  • Other recipients only where required by law, supported by a legitimate interest or covered by your consent.

For Google user data, only the transfers and access limits described in the Google API user data section are permitted. General processing purposes or legitimate interests do not broaden those limits.

9. International transfers

Calendly and individual subprocessors may process data in the USA or other countries outside Switzerland and the European Economic Area. We rely on applicable adequacy decisions, recognised privacy frameworks or standard contractual clauses and adopt additional safeguards where needed.

Further information is available in Framer's privacy statement at https://www.framer.com/legal/privacy-statement/, Calendly's privacy notice at https://calendly.com/legal/privacy-notice and Calendly's data processing addendum at https://calendly.com/legal/data-processing-addendum.

Edel’s primary hosting, document storage and default AI processing are located in Switzerland. Customer-selected external services and some provider support or operational activities may involve processing outside Switzerland. The region of Edel’s primary systems does not automatically apply to every connected service. The additional limits in the Google API user data section apply to Google data.

10. Retention

  • Contract and billing data is retained in line with statutory obligations, generally for ten years in Switzerland.

  • Enquiries and support data are kept only as long as needed for handling, evidence and possible follow up questions.

  • Technical logs are kept only as long as needed for security, stability and troubleshooting. The specific period depends on the purpose and system configuration.

  • Appointment and Calendly data are kept until the purpose no longer applies and in line with our Calendly account settings. Statutory retention and evidence obligations remain reserved.

The differentiated retention and deletion rules in the Google API user data section apply to Google user data. General retention of contract and billing records is not a blanket retention period for Google content.

11. Your rights

Depending on the applicable law, you may request access, correction, deletion, restriction, data portability, object to processing and withdraw consent.

Send requests to info@asemly.ch. We may ask for proof of identity. Where the GDPR applies, we generally respond within one month. Swiss law provides its own applicable time limits.

12. Complaints

Switzerland: Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch.

EU: You may complain to the competent supervisory authority at your place of residence.

13. Security

For the Edel platform, we use HTTPS for public connections, encrypt stored OAuth credentials and customer-owned AI API keys, and limit internal administrative access to technical administrators and responsible product owners. Managed Azure operating system and data disks use encryption with platform-managed keys; the Google Cloud Storage document store uses Google-managed encryption by default. Retention, database backups and their limits are explained in the Google API user data section. This does not promise complete or always-available recovery of all data.

14 Google API user data and limited use

Edel is operated by Asemly GmbH, Blumenfeldstrasse 15, 8046 Zurich, Switzerland. This section supplements the rest of this privacy policy. It explains how Edel accesses, uses, stores, shares and deletes data from Google APIs. The use and access limits below apply to Google data even where other sections describe broader processing purposes.

Data and purposes

The data Edel accesses depends on the connected service, the permissions granted and the features selected. It may include:

  • Account information such as name and email address.

  • Gmail messages, metadata, drafts, labels and attachments.

  • Google Calendar calendars and events; Google Chat spaces, members and messages.

  • Google Cloud project information, Cloud Storage buckets and objects, including metadata and access rights, and Pub/Sub topics, subscriptions and messages for configured triggers.

  • Contact data from Google Contacts and the Google Workspace directory.

  • Google Docs documents, Drive files and folders, Forms forms and responses, Sheets spreadsheets and Slides presentations.

  • Google Search Console properties and reports; Google Tasks lists and tasks.

  • YouTube account, channel, video, playlist and related data.

Edel uses this data for the connections and automations you configure, displaying execution results, selected Drive imports into Knowledge and requested AI features. Depending on the configured action, Edel may read, create, change, send or delete data. This includes scheduled and event-triggered workflows. Connecting Google does not mean that every accessible file is imported into Knowledge.

Edel does not sell Google user data or use it for advertising, retargeting, data brokerage, credit scoring or lending. Edel does not use Google user data to train or improve shared or general AI models and does not permit selected AI providers to do so. This also applies when customers use their own API keys.

Drive Knowledge and AI

After you select files and consent, Edel copies and processes the selected Drive files and folders for Knowledge search and answers. This may include text extraction, OCR, embeddings and search indexes. If configured, synchronization can import updates within your selection. Import only content that you own or are authorized to process for this purpose.

When you request an AI feature, relevant Google content, derived information and included conversation history may be sent to the AI provider configured for that feature. This applies to Knowledge answers and to workflow AI steps configured accordingly.

Microsoft Azure in Switzerland runs the application servers, databases and search indexes. Google Cloud Storage in Switzerland stores uploaded and imported documents and generated chat files. Infomaniak in Switzerland provides the default AI chat and embedding services. Infomaniak's API terms exclude using submitted inputs and outputs to train its AI; temporary processing and billing or operational information are separate matters. Edel itself continues to store the content needed for the features you choose, as described here.

Customers may explicitly configure another available AI provider using their own API keys. Supported choices include Infomaniak, OpenAI API, Anthropic API, Google Gemini API, Azure OpenAI and OpenRouter. Listing these options does not mean they all receive your data. The provider configured for the feature you use determines where data is sent. Its processing and retention depend on that service and account; processing outside Switzerland is possible. Google services and other selected workflow destinations have their own processing terms.

Customer-owned keys do not create an exception to Google's use restrictions. For Google data, the applicable API terms and privacy settings must be compatible; enabling shared or general model training is not permitted. Edel's responsibility for compliant handling of Google data is not transferred to the customer. Adding an API key does not mean that Edel has automatically verified the provider's terms or the account's privacy settings.

Microsoft and Google may process some support, operational and account information outside Switzerland. Providers may use subprocessors under their data processing terms. The Swiss location of Edel's primary systems is therefore no guarantee that all processing takes place in Switzerland. The sharing and human access limits below continue to apply.

Sharing and human access

Google data is shared with service providers needed for the disclosed features or with the workflow and AI destinations you select, with your consent and only as permitted by applicable Google rules. Other permitted sharing is limited to security purposes, legal obligations or a merger, acquisition or asset sale after the affected users' prior explicit consent.

People may read Google user data only when:

  • Your explicit consent to access specified messages, files or other data has been obtained and documented;

  • access is necessary for security, such as investigating a security-related malfunction or abuse;

  • access is necessary to comply with legal obligations; or

  • the data, including derived data, is aggregated and anonymized and used for internal operations in accordance with applicable law.

These limits also apply to service providers and contractors. A general support request, routine troubleshooting, mere anonymization or existing administrator rights do not give blanket permission to read content.

Storage and security

Google data may appear in workflow configurations, inputs and outputs, execution logs, sample data, trigger states, generated files and Knowledge copies or indexes.

Stored Google OAuth credentials and customer-owned AI API keys are encrypted. Public connections to the Edel application use HTTPS. Managed Azure operating system and data disks use encryption with platform-managed keys. The document store in Google Cloud Storage uses Google-managed encryption by default. Internal administrative access to production data is limited to technical administrators and responsible product owners; the human content access limits above apply in addition.

Retention and deletion

OAuth credentials are stored to maintain the relevant connection. Execution log content, temporary step files and trigger payloads are configured for 30 days' retention with hourly scheduled cleanup. Diagnostic records have a 30-day expiry with daily scheduled cleanup. Technical traces are configured for 48 hours. Background processing or storage errors may delay cleanup. These settings are not guaranteed deletion deadlines for every copy.

Workflow definitions, sample data, trigger states, execution metadata and intentionally retained documents are separate records. The same 30-day period does not apply to all of them. Selected Drive Knowledge content is kept for the requested Knowledge function and remains subject to the deletion options described here and applicable retention requirements.

Removing a Drive Knowledge source or disconnecting its Google connection stops new imports for that source and queues the associated imported Edel copies and indexes for background deletion. Deletion is not immediate. Pending writes and storage cleanup errors may delay it; technical administrators may need to intervene. A pending status does not mean the data has been deleted.

Original files in Google and copies retained by other authorized users are not deleted by this action. Separate workflow results, generated files and historical execution data are not automatically deleted with it. A Google action expressly configured to delete original data is a different operation.

Deleting a chat session initiates deletion of its generated chat files. Storage failures may require a retry or administrative action. Independently exported or copied documents are unaffected.

After deletion is accepted by the cloud document store, objects remain recoverable for seven days under its soft-delete rule. This period starts when storage deletion occurs, not when you request deletion in Edel. It is not a seven-day lifetime for active documents.

Before replacing an application version, the deployment process creates a PostgreSQL database backup on the same Swiss server. On deployment, up to three detected backups are retained; older backups are removed according to a seven-day age rule, while the newest backup is always kept. This is not daily cleanup or a guaranteed maximum retention period of seven days. Deleting active data does not immediately remove backup copies. These backups do not cover every data store by themselves and are not an independent backup of all customer data outside the server.

Disconnecting and making requests

Disconnecting an integration in Edel disables the affected local connection and starts the associated cleanup. It does not automatically revoke Google authorization or delete all separately stored data.

You can also remove Edel in your Google Account third-party connections. This may affect other connections using the same authorization. Revoking access in Google does not itself delete copies already stored by Edel. Use the relevant deletion features or contact us.

Send account or data deletion requests to info@asemly.ch. We verify identity and authority, handle the request under applicable law and follow up on incomplete cleanup. We explain remaining copies and their retention instead of describing pending deletion as complete.

Limited Use

Edel commits to using and sharing information received from Google APIs in accordance with the Google API Services User Data Policy, including its Limited Use requirements and applicable product-specific Google policies.

15. Changes

We update this notice when necessary. The current version is available on this website.