Legal
Privacy Policy
Last updated: 20 August 2026. What we process, why, where it lives, who touches it, and what you can ask of us.
Concierca ("we", "us") is operated by Concierca AI OÜ, a company in formation, Tallinn, Estonia. This policy explains what personal data we process when you visit concierca.com or use the Concierca platform, why we process it, and what rights you have. It follows the EU General Data Protection Regulation (GDPR) and, for customers in Switzerland, the Swiss Federal Act on Data Protection (FADP).
1. Who is responsible
Concierca AI OÜ, a company in formation, Tallinn, Estonia. Contact: privacy@concierca.ch. Until the company is entered in the commercial register, the founder is the responsible party and reachable at the same address. Your platform data is stored in Switzerland, see section 6.
2. Scope of this policy
This policy covers the concierca.com website and the Concierca platform, and it describes personal data. Where your company is the customer, your company decides what goes into the platform and we process it on their instruction. Market statistics about watch brands, which contain no personal data about you, are described in section 4.
3. What we process
Website visitors. Technical data your browser sends (IP address, browser type, pages visited, time). We use it to run the site and to understand which pages are read. If you fill in the contact form we process the details you enter (name, e-mail, company, message).
Platform users. Account data (name, work e-mail, role, company), login and session data, and the content you or your team put into the platform: documents, rules, strategy notes, messages, connected-app data you choose to link (for example your storefront, inbox or spreadsheets), and the outputs the system produces for you.
Watch Market Intelligence (WMI). WMI is built from publicly available market information about watch brands and their distribution, aggregated and analysed. It is used to answer market questions. We do not sell, license or hand out lists of third-party contacts.
4. Where your data comes from
From you: what you type into the site or the platform. From your company: the account it creates for you and the role it gives you. From the systems you connect: your storefront, inbox or spreadsheets, only after you connect them and only for the data you release. From public sources: Watch Market Intelligence is built from publicly available market information about watch brands and their distribution, aggregated and analysed. That flow runs one way. Your data is not written into it.
5. Why we process it and on what basis
To provide the platform you or your company signed up for (contract). To keep the service secure, to log actions and approvals, and to prevent abuse (legitimate interest, security). To answer your enquiries (contract preparation, legitimate interest). To improve the product using aggregated, non-identifying usage data (legitimate interest). Where the law requires consent, we ask for it and you can withdraw it at any time.
6. Where your data lives
Your platform data is stored in Switzerland, in the Zurich region of our database provider. Every customer is a separate tenant, and how that separation works is described in section 7. Some processing, for example sending an e-mail you approved or running a model request, involves providers outside Switzerland. Those are named in sections 8 and 9.
7. How your company is separated from every other
Every company is a separate tenant. Records carry the company they belong to, access is filtered on that basis in the application, and the same rule is enforced again in the database itself, so a query cannot reach another company's rows. Inside your company, access is limited further by department, role and per-item visibility, and an assistant cannot read what its owner cannot read. We do not run a separate database per customer, and we do not claim to.
8. Service providers (processors)
We use the following categories of providers under data processing agreements: database and storage (Supabase, Zurich region); authentication (Clerk); background job execution (Trigger.dev); connections to the apps you link (Composio); model routing (OpenRouter and the model providers reachable through it); website hosting (Framer); e-mail and messaging channels you connect (for example Gmail, Telegram) at your instruction. A current list with locations is available on request. Where a provider is outside Switzerland or the EU/EEA, we rely on adequacy decisions or standard contractual clauses.
9. International transfers
Your platform data is stored in Switzerland. Some processing happens outside Switzerland, and we name it rather than describe it as a category. Clerk for identity, Trigger.dev for background jobs, Composio for the connections to the tools you link, and OpenRouter for model routing run on infrastructure in the United States. Where a provider sits outside Switzerland or the EEA we rely on an adequacy decision, on the EU-US Data Privacy Framework where that provider is certified, or on standard contractual clauses. If you connect a third-party tool yourself, that provider receives what passes through it and keeps it under its own terms.
10. AI processing and model training
The platform uses large language models to draft, analyse and propose. Your data is sent to model providers only to process your requests. We do not use your data to train our own models, and we do not allow model providers to train on it. We route model requests through providers whose terms exclude training on API data. Outputs are proposals until a person in your company approves them; actions that send mail, spend money or are otherwise hard to reverse wait for that approval.
11. Human approval and the decision log
Actions that are hard to undo wait for a person. Spending money, sending anything outbound, deleting data and passing a mission checkpoint pause until someone approves them, in the app or on Telegram. Every decision, tool call, approval and escalation is written to an audit log with the identity that took it and the time it happened. The log exists so that you can reconstruct what the system did, and so that we can.
12. Security measures
The database is encrypted at rest with AES-256 and in transit with TLS. Provider keys are held encrypted and are never displayed in full again after they are entered. Authentication uses hashed passwords, screening against known breached passwords, short-lived sessions and multi-factor login. Machine access over MCP runs server-side as a named user with a per-tool allowlist, and secrets never travel through the model channel. We hold no SOC 2 or ISO certification of our own and we do not claim one. The providers we build on hold theirs, and we name them in section 8.
13. If something goes wrong
If a breach of personal data occurs and it is likely to result in a risk to people, we notify the competent supervisory authority without undue delay and, where the law requires it, the people affected. If a breach happens at one of our processors, we expect notice from them without undue delay and we pass it on. If you believe something has gone wrong, write to privacy@concierca.ch. We would rather hear it early.
14. Automated decision-making
The platform drafts, analyses and proposes. It does not take decisions that produce legal effects for you, or that affect you similarly significantly, without a person involved. Outputs are proposals until someone in your company approves them. If that ever changes, this policy changes first.
15. How long we keep it
Account and platform data for as long as your company uses the service and for a limited period afterwards to allow export and to meet legal obligations. Logs and approval records for as long as needed to demonstrate what the system did and who approved it. You can request deletion at any time; we delete or anonymise unless a legal duty requires retention.
16. Your rights
You can ask for access, correction, deletion, restriction, and a copy of your data in a portable format. You can object to processing based on legitimate interest and withdraw consent. Write to privacy@concierca.ch. You may also complain to the supervisory authority at our registered seat, to your local EU authority, or, in Switzerland, to the Federal Data Protection and Information Commissioner (FDPIC).
17. Export
Your company can export its platform data at any time. Ask us and we provide it in a machine-readable format.
18. Cookies
The website uses only technically necessary cookies and, if enabled, privacy-friendly analytics. The platform uses session cookies for login. You can block cookies in your browser; the platform may then not work.
19. Children
The service is for businesses and not directed at people under 18.
20. Changes to this policy
We update this policy when the service changes. The date at the top tells you when. Material changes to how we handle platform data are announced to account holders.
21. Complaints and contact
Write to privacy@concierca.ch. If our answer does not satisfy you, you can complain to a supervisory authority: the Estonian Data Protection Inspectorate as the authority at our seat, the authority in the EU country where you live or work, or, in Switzerland, the Federal Data Protection and Information Commissioner.

