CampOne has a new name and a new home: meet Grondia.Read more
Grondia
Security & hosting

Your guests’ data stays in Switzerland.

Grondia is hosted exclusively in Swiss data centers and built from the ground up to the revised Federal Act on Data Protection. This is how we keep it safe.

Data residency

100% Swiss, with no exceptions

Where your data lives is not a setting or a nice-to-have. It is the foundation everything else is built on.

Swiss data centers only

Every byte (databases, backups, file storage) lives in ISO 27001-certified data centers inside Switzerland. Nothing is replicated abroad.

No cross-border transfer

Guest data never leaves the country. There is no US sub-processor, no EU fallback region, no “data at rest in Frankfurt”.

Swiss company, Swiss law

CampOne GmbH is domiciled in Herrliberg and operates under Swiss jurisdiction, including the revised Federal Act on Data Protection.

CCPA/CPRA compliance

Built to the revised Federal Act on Data Protection

Compliance is not a document we produced once. It is baked into how the product collects, stores and deletes data.

Data minimization

We collect only what a booking and a legal occupancy reporting record require. Optional fields stay optional.

Consent & purpose

Guests see why each field is asked for. Marketing consent is separate, explicit and revocable.

Retention & deletion

Records are retained for the legally required period, then deleted automatically. Guests can request erasure at any time.

Audit log

Every access to guest data is logged with user, timestamp and action: a complete, tamper-evident trail.

occupancy reporting & municipal reporting

Reporting that satisfies the auditor

Guest records are captured once, at check-in, in exactly the shape the Federal Statistical Office and your municipality require. occupancy reporting figures and lodging-tax settlements are generated from the same authoritative record, so what you file always matches what you took.

Because every record carries its own audit trail, an audit by whichever authority asks becomes an export, not a fire drill.

  • Guest data flows straight into occupancy reporting: no manual re-entry
  • Lodging tax calculated and settled per municipality
  • Records retained for the legally required period, then deleted
  • Every figure traceable to its source booking
Encryption & access

Encrypted end to end, accessible only to those who should

Encryption in transit

All traffic runs over TLS 1.3. HSTS is enforced; there is no unencrypted path to your data.

Encryption at rest

Databases and backups are encrypted at rest with AES-256. Backup media is encrypted independently of the live store.

Role-based access

Staff see only what their role needs. Front desk, finance and owner permissions are separate, and every account is individually revocable.

Daily encrypted backups

Automated daily backups with point-in-time recovery, tested restores, and 30-day retention. All on servers inside Switzerland.

Payment security

Local payment rails, handled by the specialists

invoice

Invoices are issued as compliant invoices. Payment references reconcile back to the booking automatically.

tap to pay & cards

tap to pay, Visa, Mastercard, Amex and ACH debit are supported through a licensed Swiss payment provider.

PCI DSS via provider

Card data is tokenised and handled by a PCI DSS Level 1 provider. Raw card numbers never touch Grondia servers.

At a glance

The compliance checklist

Hosted 100% in Switzerland
CCPA/CPRA-compliant by design
TLS 1.3 in transit, AES-256 at rest
Role-based access control
Tamper-evident audit log
Daily encrypted backups
occupancy reporting & municipal reporting built in
PCI DSS payments via provider
Right to erasure honored
Automated data retention & deletion
Get started

See it running on your own park.

Book a 30 minute demo. We set your park up in Grondia first, then walk you through the switch. Nothing to install on your side.