We only describe functions that are actually implemented here — no certifications without real evidence.
Each company is a separate tenant. Database access is automatically limited to the own company; an account only sees its own company's data.
Owner, dispatcher, employees and custom roles with fine-grained rights. Each company decides who may see and do what.
All access runs exclusively over HTTPS/TLS. Sign-in passwords are hashed; supported third-party credentials (e.g. OAuth tokens) are stored encrypted.
Important changes are logged traceably (who, what, when) — including administration and access events.
Our backups follow their own retention; our cloud provider's backup practice is governed by contract and not specified in detail here. Companies can additionally retrieve their data themselves through an on-request export (owner permission). The nightly encrypted backups cover the database; a complete backup and restore of files and receipts from these backups is not promised here.
An export (e.g. as JSON) can be requested by the owner — it is not a guaranteed complete result on every request; if a single table fails, this is reported instead of silently leaving data out. We currently offer no automated self-service deletion — an actual deletion runs through a separate, manually supported process. Backups with us and with the cloud provider follow their own retention and are not deleted retroactively. Requests for access, correction, deletion or handover under the Swiss FADP are handled through the designated process — with no commitment on timing or scope here.
Photos, signatures and documents are bound to the respective job and company. The customer portal shows each customer only their own jobs.
Time-limited session tokens, lockout after too many failed sign-ins (brute-force protection) and optional two-factor authentication (TOTP).
Since 16.09.2026 iUseFlow runs at Exoscale (Akenes SA, Lausanne) in zone CH-DK-2 (Zurich, Switzerland) — application, database and file storage. Encrypted backup copies of the database are stored nightly in the same zone; a complete backup of the file storage is not promised here. The former provider Railway (United States, region sfo) ran the platform until 16.09.2026; on 28.09.2026 the three former production services were removed and the original production volumes wiped once each. No conclusive statement is made about any remaining contents of historical backups at Railway, and current operation sends no new data there. We communicate this openly. The legal meaning is set out in section 8 of the privacy notice.
Please report vulnerabilities or suspected incidents to security@iuseflow.ch. We take reports seriously and will get back to you.
More: Privacy notice · Cookie-Einstellungen · Terms · Legal notice