Your guests’ data stays in Switzerland.
Grondia is hosted exclusively in Swiss data centres and built from the ground up to the revised Federal Act on Data Protection. This is how we keep it safe.
100% Swiss, with no exceptions
Where your data lives is not a setting or a nice-to-have. It is the foundation everything else is built on.
Swiss data centres only
Every byte — databases, backups, file storage — lives in ISO 27001-certified data centres inside Switzerland. Nothing is replicated abroad.
No cross-border transfer
Guest data never leaves the country. There is no US sub-processor, no EU fallback region, no “data at rest in Frankfurt”.
Swiss company, Swiss law
CampOne GmbH is domiciled in Herrliberg and operates under Swiss jurisdiction, including the revised Federal Act on Data Protection.
Built to the revised Federal Act on Data Protection
Compliance is not a document we produced once. It is baked into how the product collects, stores and deletes data.
Data minimisation
We collect only what a booking and a legal HESTA record require. Optional fields stay optional.
Consent & purpose
Guests see why each field is asked for. Marketing consent is separate, explicit and revocable.
Retention & deletion
Records are retained for the legally required period, then deleted automatically. Guests can request erasure at any time.
Audit log
Every access to guest data is logged with user, timestamp and action — a complete, tamper-evident trail.
Reporting that satisfies the auditor
Guest records are captured once, at check-in, in exactly the shape the Federal Statistical Office and your canton require. HESTA figures and tourist-tax settlements are generated from the same authoritative record — so what you file always matches what you took.
Because every record carries its own audit trail, a cantonal or municipal audit becomes an export, not a fire drill.
- Guest data flows straight into HESTA — no manual re-entry
- Tourist tax calculated and settled per municipality
- Records retained for the legally required period, then deleted
- Every figure traceable to its source booking
Encrypted end to end, accessible only to those who should
Encryption in transit
All traffic runs over TLS 1.3. HSTS is enforced; there is no unencrypted path to your data.
Encryption at rest
Databases and backups are encrypted at rest with AES-256. Backup media is encrypted independently of the live store.
Role-based access
Staff see only what their role needs. Reception, finance and owner permissions are separate, and every account is individually revocable.
Daily encrypted backups
Automated daily backups with point-in-time recovery, tested restores, and 30-day retention — all inside Switzerland.
Swiss payment rails, handled by the specialists
Swiss QR-Bill
Invoices are issued as compliant Swiss QR-Bills. Payment references reconcile back to the booking automatically.
TWINT & cards
TWINT, Visa, Mastercard, PostFinance and LSV are supported through a licensed Swiss payment provider.
PCI DSS via provider
Card data is tokenised and handled by a PCI DSS Level 1 provider. Raw card numbers never touch Grondia servers.