Privacy Policy for Engage366
Last Updated: July 2026
1. Overview & Data Controller
SwissHelios S.à.r.l. (“SwissHelios,” “we,” “us,” or “our”) is a Swiss company registered at Route du Village 1a, 1066 Epalinges, Switzerland (UID: CHE-341.748.617). We respect your privacy and are committed to protecting personal data in compliance with the Swiss Federal Act on Data Protection (nFADP), the European Union General Data Protection Regulation (EU GDPR), the UK GDPR, and other applicable global data protection laws.
This Privacy Policy governs the collection, use, and processing of personal data when you visit our website at https://engage366.ch, access our web platforms, use our mobile applications, or interact with our software-as-a-service solutions (collectively, “Engage366” or the “Platform”).
Controller vs. Processor Roles
Data Controller: SwissHelios acts as a Data Controller for personal data collected directly from our direct clients, website visitors, and platform users for account setup, billing, marketing, platform security, and operational management.
Data Processor: When our commercial customers use Engage366 to store, manage, and process their own end-user, lead, or client data (e.g., executing marketing campaigns, managing contact pipelines, sending SMS/emails), SwissHelios acts strictly as a Data Processor. In those cases, the respective customer’s privacy policy applies to their end users' data.
2. Information We Collect
We collect information directly from you, automatically when you interact with our Platform, and occasionally from third-party partners.
A. Information Provided Directly
Account & Billing Details: Name, business email address, phone number, company name, physical address, billing address, account credentials, and payment card/banking details.
Communications & Support: Information provided when scheduling appointments, submitting support tickets, filling out web forms, or participating in surveys.
Third-Party Data Submission: If you provide personal data regarding employees or representatives, you confirm you have the legal authority and consent to share such information under this policy.
B. Automatically Collected Data
Technical & Device Information: IP addresses, browser types, operating systems, unique device identifiers, network connection type, and language preferences.
Usage & Analytics: Pages viewed, feature utilization, time spent on the Platform, error logs, diagnostic reports, and cookie/pixel telemetry.
3. How We Use Your Information & Legal Basis
We process personal data under valid legal bases established under the Swiss nFADP and EU GDPR:
| Purpose / Function | Categories of Data | Swiss nFADP / GDPR Legal Basis |
|---|---|---|
| Platform Provision & SaaS Delivery | Account details, device logs, billing data | Performance of Contract (Art. 6(1)(b) GDPR / Art. 31 nFADP) |
| Customer Support & Service Tickets | Contact info, support interactions, system logs | Performance of Contract / Legitimate Interests |
| AI Features & Automation | User inputs, query history, workflow prompts | Performance of Contract / Legitimate Interests |
| Billing & Financial Operations | Payment history, corporate addresses | Compliance with Legal Obligations (Tax/Accounting) |
| Platform Security & Fraud Prevention | IP addresses, login activity, diagnostic logs | Legitimate Interests (Information Security) |
| Marketing & Communications | Name, email address, preferences | Legitimate Interests / Consent |
AI Features & Processing
Engage366 incorporates artificial intelligence (AI) and automated tools to enhance user productivity, generate content, and facilitate automated workflows.
Zero Generalized Model Training: Your proprietary operational data and personal data are never used to train generalized public AI models.
Third-Party Subprocessors: AI features process data via enterprise-grade specialized subprocessors subject to strict data handling and confidentiality agreements.
4. Data Sharing & Subprocessors
We do not sell, rent, or trade your personal data. We disclose personal data only in the following controlled circumstances:
Authorized Service Providers: We engage trusted third-party vendors and cloud infrastructure partners to supply web hosting, payment gateway processing, transactional email delivery, SMS gateways, and analytics tools. All subprocessors are bound by Data Processing Agreements (DPAs) that mandate strict security controls and data protection standards matching our own.
Corporate Transactions: If SwissHelios undergoes a merger, acquisition, restructuring, or asset transfer, personal data may be transferred as part of corporate assets, subject to continued privacy protections.
Legal Compliance & Safety: We may disclose personal data to Swiss or international public authorities, law enforcement agencies, or courts if required by mandatory law, subpoena, or official judicial order.
5. International Data Transfers
SwissHelios operates globally, offering Engage366 to customers in Europe, the Americas, and beyond. Personal data collected by SwissHelios may be stored and processed on secure cloud servers located within Switzerland, the European Economic Area (EEA), or the United States.
When personal data originating from Switzerland or the EEA/UK is transferred to countries lacking an adequate level of data protection (such as the United States), we implement approved legal safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission and adapted for the Swiss Federal Data Protection and Information Commissioner (FDPIC).
- Transfers to entities certified under recognized international frameworks, such as the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the Swiss-U.S. DPF.
6. Data Security & Retention
Security Safeguards
SwissHelios deploys industry-standard administrative, physical, and technical security measures to protect your data against unauthorized access, loss, destruction, or alteration. These measures include end-to-end TLS encryption for data in transit, AES-256 encryption at rest, secure access controls, multi-factor authentication (MFA), and regular infrastructure auditing.
Data Retention
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, including contractual obligations, tax accounting, and statutory recordkeeping mandates (typically up to 10 years under Swiss corporate law). When data is no longer required, it is permanently deleted or anonymized.
7. Your Data Protection Rights
Depending on your geographic location, you hold specific legal rights regarding your personal data under the Swiss nFADP, EU GDPR, UK GDPR, or US state privacy statutes:
Right to Access: Request confirmation and a copy of the personal data we hold about you.
Right to Rectification: Request correction of inaccurate or incomplete personal data.
Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data where statutory retention exceptions do not apply.
Right to Restriction / Objection: Object to processing based on legitimate interests or request processing restrictions.
Right to Data Portability: Receive your data in a structured, commonly used, and machine-readable format.
Right to Withdraw Consent: Withdraw previously granted consent for direct marketing or analytics processing at any time.
To exercise any of these rights, please contact us at juliosalgado@swisshelios.com. We respond to all formal privacy requests within statutory timelines (generally within 30 days).
8. Third-Party Links & Services
Engage366 may contain links to third-party applications, plugins, marketplaces, or external websites. Connecting external accounts or services to Engage366 subjects your data handling to those third-party providers' respective privacy policies. SwissHelios is not responsible for the privacy practices or security of third-party platforms.
9. Children's Privacy
Engage366 is an enterprise and business software solution and is not intended for use by minors. We do not knowingly collect or solicit personal data from children under the age of 16. If we discover that a minor has provided us with personal data, we will immediately purge the information from our servers.
10. Updates & Inquiries
SwissHelios reserves the right to update this Privacy Policy periodically to reflect technological, legal, or operational changes. The latest version will always be accessible at https://engage366.ch/privacy with an updated revision date.
Contact Us
For any inquiries, requests, or complaints regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer:
SwissHelios S.à.r.l.
Attn: Legal & Data Privacy Department
Route du Village 1a
1066 Epalinges, Switzerland
Email: juliosalgado@swisshelios.com
Phone: +41 21 652 59 56 / +41 79 791 59 56
Website: https://swisshelios.com
If you reside in Switzerland or the EEA and believe your data has been handled in violation of applicable privacy laws, you have the right to lodge a complaint with your local supervisory authority (in Switzerland: the Federal Data Protection and Information Commissioner — FDPIC).