Legal
Privacy Policy
Last updated 7 July 2026 · DemyTix, an Appogee product
1. Data controller and contact
This privacy policy describes how DemyTix (hereinafter DemyTix or we) collects, uses and protects the personal data of users of the DemyTix service (hereinafter the Service). DemyTix is a product published by Appogée Sàrl (a limited liability company under Swiss law), whose registered office is located at Chemin de Paudex 5, 1132 Lully, Switzerland, which acts as data controller within the meaning of this policy. Appogée Sàrl acts as data controller for the data relating to account management and to the contractual relationship, and as data processor for the data that the Client processes by means of the Service in the course of its business (for example the supporting documents of its own clients). For the latter, the Client remains the data controller and DemyTix makes available to it, on request, a Data Processing Agreement compliant with Article 28 of the GDPR and Article 9 of the nFADP.
The Service is aimed primarily at a professional clientele in Switzerland and processes data in accordance with the Swiss Federal Act on Data Protection (FADP, also referred to as nFADP or LPD) and, where it applies, the European Union's General Data Protection Regulation (GDPR) for persons located in the European Union.
For any question relating to this policy or to the exercise of your rights, you may contact the data controller, Appogée Sàrl, by post at the address Chemin de Paudex 5, 1132 Lully, Switzerland, or by email at the address contact@demytix.com, as well as from the Contact page of the site.
2. Data collected
We collect the account data that you provide to us upon registration and use of the Service: last name and first name, email address, name of the company or workspace, as well as the subscription and billing information necessary to process payments. The payment itself is processed by a payment provider, and DemyTix does not retain the complete data of your means of payment.
We also process the supporting documents that you upload (receipts, tickets, invoices) as well as the data extracted therefrom (amount, date, supplier, VAT, category and other accounting fields). This content belongs to you and is processed on your behalf within the framework of your workspaces.
When you write to us via the contact form, we collect the information you enter there (name, email address, company where applicable and the content of your message).
3. Purposes and legal bases
We process the account data and the uploaded content in order to provide the Service (digitization, extraction and synchronization to Bexio), to manage your subscription, your access and your workspaces, and to provide support. The legal basis for this processing is the performance of the contract between us, as well as compliance with our legal obligations, in particular accounting and tax obligations.
We process certain data on the basis of our legitimate interest, in particular to ensure the security of the Service, to prevent fraud and abuse and to improve our features. This interest is balanced against your rights and freedoms, and you may object to processing based on this ground under the conditions of Article 9.
Where the law requires it, certain processing operations are based on your consent, which you may withdraw at any time without such withdrawal affecting the lawfulness of prior processing. The processing of contact-form data is based on your voluntary decision to contact us and on our legitimate interest in responding to it.
4. Extraction by artificial intelligence (Claude, Anthropic)
In order to automatically extract information from a supporting document, the image of that document is transmitted to the Claude artificial intelligence model, provided by the company Anthropic, via its application programming interface (API). This processing is strictly limited to the extraction of the relevant fields (amount, date, supplier, VAT and other accounting data) and constitutes the only case in which a piece of data leaves DemyTix's Swiss infrastructure. This extraction does not constitute an automated individual decision producing legal effects within the meaning of Article 22 of the GDPR or Article 21 of the nFADP: it assists data entry, and the Client checks and validates the data before its use.
Under the terms applicable to Anthropic's API, the data transmitted by this means is not used to train Anthropic's models and is not subject to lasting retention by Anthropic beyond what is necessary to process the request. Anthropic acts in this respect as DemyTix's data processor for this extraction operation.
We are keen to be transparent about the limits of our guarantee: the protection we offer you stops where Anthropic's stops. DemyTix cannot be held liable for any improper use of the data by Anthropic, nor for any data breach that would result from Anthropic's fault. We select Anthropic precisely because its commitments regarding the API (no training and no retention) are suited to the processing of professional data.
5. Hosting in Switzerland and absence of sharing
All the data of the Service (accounts, supporting documents, extracted data, contact data) is hosted in Switzerland, with the Swiss host Infomaniak (https://www.infomaniak.com). DemyTix has chosen hosting in Switzerland in order to retain control of the infrastructure and to limit to the strict minimum the intermediaries having access to the data.
Apart from the artificial intelligence extraction described in Article 4, no data is shared with third parties for commercial, advertising or profiling purposes. We do not sell your data and do not transfer it to data brokers.
6. Data sharing and processors
The only sharing of data with a technical third party inherent in the operation of the Service is the transmission of the images of supporting documents to Anthropic for extraction purposes (Article 4). Furthermore, synchronization to Bexio takes place only at your request and to your own Bexio account: the data transmitted to Bexio is transmitted under your responsibility and according to Bexio's terms.
We use a limited number of processors: the Swiss host Infomaniak (https://www.infomaniak.com) for hosting the infrastructure and the data in Switzerland, the payment provider for processing subscriptions, and Anthropic for extraction by artificial intelligence (Article 4). These processors are selected for their security and confidentiality guarantees and are contractually bound to process the data only on our instructions and for the purposes described in this policy.
We may be required to disclose data where the law obliges us to do so or in response to a valid request from a competent authority, within the strict limits of that obligation.
8. Retention periods
The account data and the content that you upload are retained for as long as your account is active. The length of time during which your data history remains viewable depends on your subscription plan: entry-level plans offer a limited history (for example three months), while higher plans offer an extended history or unlimited retention. The applicable window is indicated on the subscription page.
In the event of cancellation of a paid subscription, your account reverts to the free plan and your data remains accessible within the limits of that plan; it is not automatically deleted as a result of the cancellation. You may at any time export your data or delete it from your space, and permanent deletion occurs at your request or upon the closure of your account. Appogée Sàrl nonetheless remains obliged to retain the billing documents that have been sent to you for the statutory accounting retention period (ten years, Article 958f of the Code of Obligations); your supporting documents and the data extracted therefrom, which pertain to your own accounting, are not subject to this obligation on our part and are deleted at your request. Temporary technical backups are purged within a reasonable time.
The data transmitted via the contact form is retained for a period not exceeding two (2) years after the processing of your request. We retain personal data only for as long as necessary for the purposes for which it was collected or for the legal obligations incumbent upon us.
9. Rights of data subjects
In accordance with the Swiss FADP and, where it applies, the GDPR, you have a right of access to your data, a right to rectify inaccurate data, a right of deletion (right to be forgotten), a right to the restriction of and objection to certain processing operations, as well as a right to the portability of your data in a structured and machine-readable format.
You may exercise these rights at any time from your space (export and account management) or by contacting us via the Contact page. We respond to your request within the time limits provided for by applicable law and may ask you to prove your identity in order to prevent any unauthorized access.
If you consider that the processing of your data is not compliant, you may refer the matter to the competent authority: in Switzerland, you may report the facts to the Federal Data Protection and Information Commissioner (FDPIC), your civil claims being otherwise exercised before the courts; in the European Union, you may lodge a complaint with the supervisory authority of your country of residence.
10. Data security
We implement appropriate technical and organizational measures to protect the data against loss, unauthorized access, alteration or disclosure. These measures include in particular the encryption of communications, access control, the logical separation of workspaces (multi-tenant) and regular backups.
No system, however, offers absolute security. In the event of a data breach likely to result in a high risk to your rights, we will inform you and notify the competent authority in accordance with the applicable legal obligations.
11. Transfers outside Switzerland and the EU
In principle, your data remains hosted in Switzerland. The only transfer likely to occur outside Switzerland and the European Economic Area is the occasional and limited transfer of the images of supporting documents to Anthropic's infrastructure (Anthropic PBC, United States) for the purpose of extraction by artificial intelligence (Article 4).
This transfer to a country that does not offer a level of protection recognized as adequate is governed by appropriate safeguards, in particular the standard contractual clauses and the Data Processing Agreement applicable to the processing by Anthropic, in accordance with the FADP and the GDPR. We endeavour to limit these transfers to what is strictly necessary for the provision of the Service.
12. Updates to the policy
We may update this policy in order to reflect changes to the Service, to our practices or to the legal framework. The date of the last update appears at the top of the page.
In the event of a substantial change, we will inform you by an appropriate means (email or notification in the application) before it takes effect. We invite you to consult this page regularly.
13. Jurisdiction and compliance
This policy and the processing operations it describes are governed by Swiss law, in particular the FADP, and by the GDPR where the latter applies by reason of the location of the data subjects in the European Union.
Any dispute relating to data protection that cannot be resolved amicably falls within the jurisdiction of the courts of the Canton of Vaud, Switzerland, subject to the remedies available before the data protection authorities.