Controller
FinanceRock GmbH, to be added, registered office Cham, UID CHE-142.042.105.
Contact for data protection questions: to be added.
This policy is based on the Federal Act on Data Protection (FADP, in force since 01.09.2023) and the Data Protection Ordinance (DPO). For people in the EU or EEA, the EU General Data Protection Regulation (GDPR) may also apply; see below.
The key points in brief
- You can use the premium calculator and all tools without registering and without giving contact details.
- We ask no health questions. Health information is sensitive personal data (Art. 5 let. c FADP); we do not need it.
- Our statistics count visits without cookies and without profiles (Umami, self-hosted).
- We store a Google advertising identifier only with your consent. No advertising tag ever runs on calculator, results or request pages.
- We only contact you if you ask us to, and only through the channel you choose.
What data we process and when
Visiting the website
When you open a page, the server processes technical information: shortened IP address, time, requested address, browser type, status code. Purpose: operation, security, troubleshooting. We delete the server logs after 14 days; we do not store full IP addresses.
Statistics without cookies
We use a self-hosted instance of Umami to measure which pages are viewed and how often. Umami sets no cookies, creates no profiles and respects “Do Not Track”. Address parameters (for example calculator inputs) are not transmitted. Events never contain names, email addresses, phone numbers, years of birth or postcodes.
Calculators and tools
Your inputs (for example postcode, year of birth, deductible, accident cover) are used only for the calculation. They appear in the address bar so that you can share a result or open it again later. Names, email addresses or phone numbers never belong in an address.
“My account”
An account is optional. All calculators work without one.
- Sign-in: with a 6-digit code sent to your email address, no password. The code is valid for 10 minutes and becomes invalid after 5 incorrect attempts. We store it only as a hash and delete it after use. To prevent misuse, we count requests per email address and per IP address; both only as hashes and for no longer than 24 hours.
- What we store: your email address, saved calculations (tool, title, the inputs as an address, the calculated result, date), your household (municipality, years of birth, deductibles, accident cover, current insurer and insurance model), your alerts, a sending log (which reminder was sent when) and your consents with version and time. No names, no postal address, no health information. People in your household are called “Person 1”, “Person 2” on our site.
- Session: a technically necessary, protected cookie (HttpOnly) keeps you signed in for up to 30 days; the session is stored in our database and ends when you sign out.
- Purpose and legal basis: providing the account that you open yourself (contract or consent).
- Export and deletion: under “Settings” you can download all your data as a JSON file or delete your account. Deletion takes effect immediately and removes your account, household, calculations, alerts, logs and consents.
- Changing your email address: you confirm the new address with a code sent to that new address.
Premium alert and deadline reminders
If you switch them on, we recalculate your saved household on the day the FOPH releases the new premiums and send you the possible savings by email. Deadline reminders (notice of cancellation by 30.11., switching as of 30.06.) arrive two weeks before the deadline. Every email contains an unsubscribe link that switches off all alerts with one click; you can switch them back on at any time in your account. The newsletter is separate and only active if you expressly request it.
Request for advice
Only if you actively submit a request do we process the information from the form: your concern, municipality, years of birth, preferred channel and time slot, contact details, message, your consent (text and time) and an origin log (page, time, confirmation “not from cold calling”). The only recipient is FinanceRock GmbH. After successful transfer to the customer system of FinanceRock GmbH, we delete the request on this platform after 30 days.
Emails
We send sign-in codes, confirmations and alerts through an email service. Emails contain no tracking pixels and no external images. You only receive newsletters and alerts if you switch them on yourself; every alert email contains an unsubscribe link.
Google Ads
If you arrive via a Google ad, the address contains an identifier (gclid, gbraid or wbraid). We then ask you whether we may store it.
- Accept: we store the identifier and the time in your browser (session storage and the cookie
dk_ads, 30 days). If you later submit a request, we pass the identifier with the request to FinanceRock GmbH, which uses it to measure whether the ad led to a request (import into Google Ads). - Decline: we store nothing. Calculators and results work in exactly the same way.
We only load a Google script in your browser if the operator has switched it on and you have consented, and never on calculator, results, request or account pages. The recipient is then Google Ireland Limited (Ireland) or Google LLC (USA). You can view and withdraw your choice at any time via “Settings” in the footer.
AI assistant and search
The AI assistant is currently not switched on. If it is activated, requests will be processed by a provider based in Switzerland or the EU; we filter out personal data and health information beforehand. The search computes text comparisons on our own servers (self-hosted embedding model), without third-party providers.
Recipients and processors
| Task | Recipient | Location |
|---|---|---|
| Hosting and database | to be added | Switzerland |
| Email sending | to be added | Switzerland or EU |
| Statistics | Umami, self-hosted | Switzerland |
| Search (embeddings) | self-hosted | Switzerland |
| AI assistant (currently off) | to be added | Switzerland or EU |
| Requests, advice | FinanceRock GmbH | Switzerland |
| Ad measurement (only with consent) | Google Ireland Limited, Google LLC | Ireland, USA |
Processors process data only on our instructions and under a contract (Art. 9 FADP). We do not sell data and do not pass contact details on to insurers.
Disclosure abroad
As a rule, we process data in Switzerland. EU and EEA states provide an adequate level of protection (Annex 1 DPO). Data is disclosed to the USA only for ad measurement with your consent, to companies certified under the Swiss-U.S. Data Privacy Framework or on the basis of standard contractual clauses (Art. 16 FADP).
Retention
| Data | Period |
|---|---|
| Server logs | 14 days, without full IP address |
| Requests | 30 days after successful transfer |
| Account, household, calculations, alerts, consents | until you delete them or your account |
| Sign-in code | until you sign in, at most 10 minutes |
| Counters against misuse (hashes of email and IP address) | at most 24 hours |
| Account session | until you sign out, at most 30 days |
| Sending log of alerts | until the account is deleted |
| Reminders and alerts without an account | until you unsubscribe |
| Advertising identifier in the browser | 30 days or until you withdraw consent |
Cookies and browser storage
| Name | Purpose | Duration |
|---|---|---|
dk_ads (cookie and session storage) | advertising identifier, only with consent | 30 days |
dk_tbar_closed (session storage) | remembers that you closed the transparency notice | until you close the tab |
authjs.session-token (account) | sign-in, technically necessary, HttpOnly | until you sign out, at most 30 days |
authjs.csrf-token, authjs.callback-url (account) | protection against forged requests, return after sign-in | session |
dk_handoff (account) | one-time handover after the code check, HttpOnly | 2 minutes |
We set no other cookies. There are no social media advertising pixels here and no recordings of your mouse or typing movements.
Security
The connection is encrypted (HTTPS). We store requests in encrypted form. Access is limited to a small number of people. We report any data security breach likely to result in a high risk to the Federal Data Protection and Information Commissioner (FDPIC) (Art. 24 FADP).
Your rights
At any time, you can request information (Art. 25 FADP), have incorrect data corrected and data deleted, object to processing, withdraw consent and receive your data in a common format (Art. 28 FADP). To do so, write to to be added. You can also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC): edoeb.admin.ch.
People in the EU/EEA (GDPR)
If you are in the EU or EEA, for example as a cross-border commuter, the EU General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) may apply in addition to the Swiss FADP where our processing relates to offering our services to you or to monitoring your behaviour (Art. 3(2) GDPR). The controller is FinanceRock GmbH, Switzerland (contact details above).
- Legal bases: your contract or request (Art. 6(1)(b) GDPR), your consent (Art. 6(1)(a) GDPR, for example for the advertising identifier) and our legitimate interest in operating the website securely (Art. 6(1)(f) GDPR).
- Adequate protection: the European Commission has recognised that Switzerland ensures an adequate level of data protection (Commission Decision 2000/518/EC, confirmed in its 2024 review).
- Your rights under Art. 15–22 GDPR: access, rectification, erasure, restriction of processing, data portability and objection. Write to to be added.
- Complaint: you can lodge a complaint with the supervisory authority of your EU/EEA state, in particular where you live or work (Art. 77 GDPR).
Changes
We update this policy when our services or the law change. The version published on this page applies; the date is shown at the top right.