Effective date: September 10, 2026
This Privacy Policy explains how Typewise AG, Buckhauserstrasse 36, 8048 Zurich, Switzerland, Commercial Register No. CHE-222.930.167 (Typewise, we, us) handles personal data as a controller for our website, Platform signup, account administration, subscriptions, support, and business communications.
The short version: Typewise uses limited business account information to provide and administer the service. Stripe handles payment-card processing. When a customer puts personal data into the Platform, the customer generally acts as controller and Typewise acts as processor under Schedule 1 to the Typewise Terms of Service (Data Processing Terms). We do not sell personal data or share it for cross-context behavioral advertising.
This policy covers only Typewise's website and Platform. Customers are responsible for giving their own end-customers and other data subjects appropriate privacy notices for Customer Data they process through the Platform.
1. Who is responsible and how to contact us
The controller is:
Typewise AG
Buckhauserstrasse 36
8048 Zurich, Switzerland
Commercial Register No. CHE-222.930.167
info@typewise.app
Typewise's Data Protection Officer is Janis Berneker. You can contact him at janis.berneker@typewise.app. General privacy questions may also be sent to info@typewise.app.
2. Personal data we collect
We limit controller-side collection to information reasonably needed for the relevant interaction. Depending on how you use Typewise, this may include:
- Business account data: your name, business email address, company, role, and limited account or administrator identifiers needed to create and manage access.
- Subscription and billing data: the selected plan and subscription status; billing name, email, and required billing address; optional tax or VAT identification; Stripe customer, invoice, payment, and webhook-event identifiers; amounts, currency, invoice and payment status; and card brand and the last four digits. Full card details are submitted directly to Stripe. Typewise does not store full card details or raw Stripe webhook payloads.
- Service and security data: limited Account, configuration, usage, authentication, and diagnostic records needed to operate, secure, troubleshoot, and meter the service.
- Communications: information you choose to provide in support requests, feedback, meetings, or other business communications, together with our response records.
- Preferences: choices about required service communications and optional business marketing.
- Customer Personal Data processed for customers: conversations, identifiers, knowledge documents, integration data, prompts, outputs, and other Customer Data handled under customer instructions and the Data Processing Terms. This is processor activity, not the controller-side account processing described above.
3. Where personal data comes from
We receive personal data:
- directly from you or your organization;
- automatically when you visit our website or use the Platform;
- from Customer administrators who create or manage your User access;
- from connected services and integrations at Customer's direction for processor activities;
- from Stripe and other providers supporting payments, security, communications, and service operation; and
- from public and professional business sources where lawful, such as company websites and professional profiles.
4. Why we use personal data and our legal bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide the website, Platform, signup, Accounts, and administration | Business account, company, limited service and security data | Contract or steps requested before a contract; legitimate interests in delivering and administering business services |
| Process subscriptions, payments, invoices, tax, and accounting | Subscription and billing status, contact, company | Contract; legal obligations; legitimate interests in receiving payment and managing records |
| Provide support and respond to requests | Account, contact, communications, diagnostics | Contract; legitimate interests in customer service and resolving issues |
| Authenticate Users and protect the Services | Account, device, logs, security, fraud and abuse signals | Contract; legitimate interests in security, fraud prevention, abuse prevention, and service integrity; legal obligations where applicable |
| Measure use, diagnose errors, and improve the website and Services | Limited service, security, diagnostic, and feedback data | Legitimate interests in reliable, useful, and secure services; consent where required for cookies or similar technologies |
| Send required service and contractual communications | Account, contact, organization, subscription | Contract; legal obligations; legitimate interests in keeping business users informed |
| Send and manage business marketing | Contact, organization, role, preferences, interactions | Legitimate interests in relevant business marketing; consent where required; you may opt out at any time |
| Establish, exercise, or defend legal claims and comply with law | Relevant account, billing, communications, security, and transaction records | Legal obligations; legitimate interests in compliance and protecting legal rights |
| Evaluate or complete a merger, financing, acquisition, reorganization, or asset transfer | Relevant business, account, contract, and due-diligence data | Legitimate interests in corporate transactions; legal obligations |
Where we rely on legitimate interests, we consider the impact on individuals and do not use that basis where their rights and interests override ours. Where processing is required to enter into or perform a contract, we may be unable to provide the relevant Account or service without the necessary data.
5. Customer Personal Data processed on behalf of customers
For processor activities, Typewise uses Customer Personal Data only on documented customer instructions, to provide and secure the Services, and as otherwise permitted by the Data Processing Terms and applicable law. The Data Processing Terms describe the processing, data-subject categories, subprocessors, locations, retention, security, assistance, and transfer safeguards.
Questions or rights requests about Customer Personal Data should normally be directed first to the customer that controls the relevant account, conversation, or business relationship. We assist customers as required by the Data Processing Terms in Schedule 1 to the Terms of Service.
6. Who receives personal data
We disclose personal data only as needed for the purposes described above, including to:
- Stripe, which provides hosted checkout, payment processing and authentication, tax-calculation tooling, invoicing, the customer billing portal, and authorized off-session card charging. Typewise AG remains the seller and merchant of record;
- Amazon Web Services (AWS), which supports website hosting, signup, Account hosting, and Typewise-hosted error logging;
- PostHog, which provides product analytics and session diagnostics;
- Microsoft 365, which supports business and support email where communications are not handled through the Platform;
- HubSpot, which supports customer-relationship management;
- Loops, which supports service and lifecycle email;
- AI and model-inference providers used to deliver configured Platform features;
- other authentication, website-hosting, communications, customer-support, security, and business-system providers used for the relevant service;
- professional advisers, auditors, insurers, and financial institutions under appropriate duties;
- courts, regulators, law-enforcement bodies, and other authorities where required or permitted by law; and
- potential or actual transaction counterparties and advisers in a merger, financing, acquisition, reorganization, or asset transfer, subject to appropriate safeguards.
These are necessary operational disclosures, not sales of personal data or sharing for cross-context behavioral advertising. This is a category-based description, not an exhaustive list of every controller-side provider. Processor-side subprocessors and their relevant processing locations are listed in Schedule 1 to the Terms of Service.
We do not disclose personal data to third parties for their own unrelated purposes unless we have a lawful basis and provide any notice required by law.
7. International transfers
Customer Data processed under the Data Processing Terms is processed in the European Union and/or Switzerland, subject to those terms and the listed subprocessor arrangements.
For controller activities, personal data may be processed in Switzerland and in the following destination states, depending on the provider and feature used:
- AWS: Germany (Frankfurt) for website hosting, signup, Account hosting, and Typewise-hosted error logging. Ancillary AWS services may process limited data elsewhere where configured or required for support, security, or resilience.
- PostHog: Germany for PostHog Cloud EU analytics data; PostHog Account and support administration may also involve the United States.
- Microsoft 365: the EU/EFTA Data Boundary, which includes Austria, Belgium, Denmark, Finland, France, Germany, Greece, Iceland, Ireland, Italy, Liechtenstein, the Netherlands, Norway, Poland, Spain, Sweden, and Switzerland, subject to Microsoft's documented limited-transfer exceptions.
- HubSpot: Germany for its EU data center. Depending on enabled features, support, security, routing, and affiliate access may also involve the United States, Ireland, Australia, Singapore, Japan, Colombia, Sweden, France, the United Kingdom, Belgium, Canada, Spain, the Netherlands, and India.
- Loops: the United States.
- Stripe: Ireland, the United States, India, and other countries where Stripe, payment methods, financial partners, or service providers operate. Stripe states that most of its service providers are based in the European Union, the United States, and India.
Some destination states may not provide a level of data protection equivalent to Switzerland. Where required, we rely on an adequacy decision, approved standard contractual clauses, Swiss-law adaptations or recognized safeguards, binding corporate rules, or another lawful transfer mechanism. We also assess and supplement safeguards where required.
You may contact info@typewise.app to ask for more information about relevant destination states and safeguards.
8. How long we retain personal data
We retain personal data only for as long as reasonably necessary for the relevant purpose, contractual relationship, legal obligation, dispute, or security need.
- Customer Personal Data: retained and deleted under the Data Processing Terms. After services involving Customer Data cease, Schedule 1 requires deletion within 30 business days unless law requires retention.
- Processor feature logs: where the relevant features apply, AI-agent trace logs are deleted after 14 days, session-replay data after 90 days, and error logs after 30 days, as described in Schedule 1.
- Account and administrator data: generally retained for the duration of the service relationship and then deleted or anonymized within the applicable service offboarding period, subject to legal retention and dispute needs.
- Billing and tax records: retained for the period required by applicable accounting, tax, and commercial law.
- Support, security, and legal records: retained according to the nature of the request, risk, limitation period, or legal obligation.
- Marketing data: retained until you opt out or we determine that it is no longer current or necessary, subject to a limited suppression record to respect the opt-out.
Backups may persist for a limited cycle before secure deletion. We may retain de-identified information that can no longer reasonably identify an individual.
9. Cookies and analytics
Our website and Platform may use cookies, local storage, pixels, or similar technologies for authentication, preferences, security, performance, diagnostics, and analytics. Some are necessary for the requested service; others may require consent depending on your location and the technology used.
You can use browser controls to delete or block cookies, although doing so may affect functionality. Where Typewise provides a cookie or preference control, you can use it to manage non-essential technologies. We do not promise support for a particular browser privacy signal unless we expressly state that support in the relevant interface.
10. Security
We use technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, or disclosure. Measures are selected according to the nature of the processing and risk and may include access controls, encryption in transit, confidentiality obligations, monitoring, and incident-response procedures.
No system is completely secure. Customers and Users must protect credentials and promptly report suspected unauthorized Account activity. Additional measures for Customer Personal Data are described in the Data Processing Terms and Typewise's technical and organizational measures.
11. Your rights
Depending on your location and applicable law, including the GDPR and Swiss Federal Act on Data Protection, you may have rights to:
- request access to personal data and information about its processing;
- correct inaccurate or incomplete personal data;
- request deletion or restriction of processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests or for direct marketing;
- withdraw consent at any time, without affecting earlier lawful processing; and
- lodge a complaint with a supervisory authority.
In Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC). In the EEA or United Kingdom, you may contact the competent authority where you live, work, or believe an infringement occurred.
To exercise a right, contact info@typewise.app. We may verify identity and authority before acting. An authorized agent may submit a request where applicable, but we may require evidence of authorization. Rights are subject to legal conditions, exceptions, and the roles described in Section 5.
12. United States state privacy rights
Residents of US states with applicable privacy laws may request the rights available to them under those laws, subject to scope, thresholds, definitions, and exceptions. Typewise does not state through this policy that it meets any particular statutory threshold.
Typewise does not sell personal data or share it for cross-context behavioral advertising. This does not prevent the limited disclosures to service providers and other recipients described in Section 6.
Applicable requests may be submitted to info@typewise.app. We will not discriminate against an individual for exercising an applicable statutory right.
13. Automated decisions
Typewise does not use controller-side Account, billing, support, or website data to make decisions based solely on automated processing that produce legal or similarly significant effects for individuals.
Customers may configure AI Agents and automated workflows for their own purposes. Processing performed by Typewise on a customer's behalf follows the customer's instructions and the Data Processing Terms. The customer is responsible for determining whether its use involves automated decision-making, providing required notices, establishing a legal basis, and implementing appropriate safeguards and human review.
14. Business users and children
The Platform is offered only to organizations and individuals acting in a business or professional capacity. Users must be at least 18 years old. The Platform is not directed to children, and Typewise does not knowingly collect children's personal data for controller-side Account or billing purposes.
Customer Data may include information about minors only where a customer lawfully submits it under its own instructions and the Data Processing Terms. The customer remains responsible for the legal basis and required safeguards.
15. Changes to this policy
We may update this policy to reflect changes in our Services, practices, or law. We will post the updated version with a new effective date and provide additional notice where a material change or applicable law requires it.
16. Contact
Questions, requests, and complaints may be sent to Janis Berneker, Data Protection Officer, at janis.berneker@typewise.app; to info@typewise.app; or by mail to Typewise AG, Buckhauserstrasse 36, 8048 Zurich, Switzerland.
