Privacy Policy

Last updated: 05.10.2026

This policy applies to the current version of the Service since its commercial launch. It may be updated to reflect legal, technical or regulatory developments, or the activation of new processors. Last updated: 05.10.2026.

1. Purpose and scope

This policy describes how personal data is processed in connection with the use of IMOZ.CH (hereinafter imoz), a Swiss rental management software operated as a SaaS service. It applies to the imoz.ch website, to the authenticated web application and to the mobile applications, as well as to the documents generated by the service. It is drafted in accordance with the Swiss Federal Act on Data Protection of 25 September 2020 (FADP) and its implementing ordinance.

imoz is a software publisher: it provides a management tool and never collects the rents or the deposits of its users. The only flow of money received by imoz is the subscription to the service. imoz does not provide legal advice; for liability and the scope of the service, please refer to the Terms of Use.

2. Data controller

The data controller, within the meaning of art. 5 let. j FADP, is DIZZUS GmbH, having its seat in Zug (Switzerland), UID number CHE-469.903.322. Any request relating to data protection may be submitted using the form on the Help page (imoz.ch/support) or by post to the address given in section 14.

This qualification applies to the landlord's own account data. For the data that the landlord enters about its tenants and applicants, imoz's role is different and is set out in section 5. As DIZZUS GmbH is established in Switzerland, the obligation to designate a representative in Switzerland (art. 14 FADP, which concerns controllers established abroad) does not apply.

3. Data processed and data subjects

imoz processes several categories of data, depending on the data subject. Landlord account data: identity, email address, postal address, IBAN, and where applicable the information of its company (company name, UID, VAT number, logo). Business data entered by the landlord: properties, buildings, leases, payments and arrears, expenses, service charge statements, condition reports with photos, tenant requests and listings. Tenant and co-holder data: identity, contact details, language of correspondence, lease data, payment history, documents and requests. Applicant data: identity, personal and professional situation, income and the supporting documents of the application file.

Depending on the case, some of this data may constitute sensitive data within the meaning of art. 5 let. c FADP; it then benefits from enhanced protection. imoz does not voluntarily collect sensitive data that is not necessary for rental management and invites landlords not to enter any without a legal basis.

4. Purposes of processing

The data is processed in order to: provide the property management service (lease management, rent tracking and reconciliation without any collection of funds, reminders up to formal notice, condition reports, statements, applications); generate documents with evidentiary and accounting value (leases, QR-bills, reminders, terminations, certificates, statements); manage the account, the subscription and billing; communicate with users; ensure the security of the service and prevent abuse; comply with DIZZUS's legal obligations, in particular accounting obligations.

Processing is based on the performance of the contract concluded with the landlord, on compliance with legal obligations (in particular the accounting retention of art. 958f of the Code of Obligations) and, where the law requires it, on consent. The FADP does not make lawful processing subject to a formal legal basis as the GDPR does; these grounds are stated for the sake of transparency (art. 31 FADP).

When a property is entered, imoz offers autocompletion of Swiss addresses. For this purpose, imoz's server queries the public geoinformation service of the Confederation (swisstopo, geo.admin.ch), operated in Switzerland: only the address string or postal code entered is transmitted in order to obtain the corresponding suggestions, to the exclusion of any user identifier or IP address.

Automatic checking of supporting documents (paid option): when the landlord activates this feature, the documents concerned (for example a liability insurance certificate or a rent deposit certificate) are analysed by an image analysis model operated on DIZZUS GmbH's own infrastructure in Switzerland, for the sole purpose of verifying their nature and legibility. These documents are not transmitted to any third-party provider on this occasion. As they may constitute sensitive data within the meaning of art. 5 let. c FADP, access to them remains restricted and the result of the analysis is indicative only, without any automated decision with legal effect.

5. Dual role: controller and processor

For the landlord's account data (identity, contact details, subscription), DIZZUS GmbH is the data controller. For the data that the landlord enters about its tenants and applicants, it is the landlord who determines the purposes and the means: the landlord is the data controller and imoz acts as a processor within the meaning of art. 9 FADP, that is, it processes this data on behalf of and on the instructions of the landlord. A data processing agreement may be offered to landlords in order to frame these obligations.

imoz provides the landlord with the means to inform the data subjects at the time of collection (art. 19 FADP), for example a notice when an application is submitted. Tenants and applicants who wish to exercise a right over their data address themselves in principle to the landlord concerned, who is the data controller; imoz, in its capacity as processor, assists the landlord according to the agreed terms.

6. Recipients and processors

imoz does not sell or rent personal data. It may be shared with processors strictly necessary to operate the service, each bound by a data processing agreement.

Stripe, for secure subscription payment. Stripe, Inc. (headquartered in the United States) processes billing data (identity, card or IBAN details, amounts and billing dates) in order to charge the subscription from your bank or card issuer. This processing involves a transfer of your payment data to the United States, a third country within the meaning of art. 16 FADP. imoz ensures that this transfer benefits from recognised contractual safeguards (standard contractual clauses) to provide an adequate level of protection within the meaning of art. 16 and 17 FADP. Stripe's privacy policy is available at stripe.com.

Resend (a provider established in the European Union), for sending transactional emails: tenant invitations, rent reminders and formal notices, request notifications and service charge statements. Resend processes the recipient's email address and the message content. The European Union is among the states recognised by the Federal Council as providing an adequate level of protection.

Cloudflare, for the routing and protection of traffic. All traffic to the website and the application (imoz.ch and its application interface) passes through the network of Cloudflare, Inc. (headquartered in the United States), which provides domain name resolution (DNS), TLS encryption of connections, terminated at Cloudflare, and protection against attacks and bots, including the Turnstile service on the contact form. For this purpose, Cloudflare processes the IP address, technical connection data and, transiently, the content of the exchanges between the browser and imoz, without retaining them beyond what this service requires. This processing may involve a transfer to the United States, a third country within the meaning of art. 16 FADP; it is framed by recognised safeguards, namely the Swiss-U.S. Data Privacy Framework, under which Cloudflare is certified, or failing that standard contractual clauses, within the meaning of art. 16 and 17 FADP.

The advanced (AES) and qualified (QES) electronic signature of the deeds that require it will rely on Skribble, a provider established in Switzerland. This feature is being rolled out and is not yet active; once it is, Skribble will process the identity and signature of the signing person as well as the document to be signed.

Data may also be disclosed to authorities where the law requires it. imoz keeps an up-to-date register of its processing activities and its processors.

7. Hosting and location

imoz's infrastructure is self-hosted: the backend (PostgreSQL database, authentication, application interface and file storage) runs on a dedicated server, without relying on an external database managed by a third party. Data sovereignty is a guiding principle of the project.

This dedicated server is operated in Switzerland by DIZZUS GmbH itself; no third-party host is involved in the provision or operation of the infrastructure. Business data therefore resides in Switzerland; the only disclosures to service providers are those described in section 6.

8. Retention periods

Data is kept only for as long as is necessary for the purposes pursued, then deleted or anonymised. An important reservation applies: under art. 958f of the Swiss Code of Obligations, the books and the accounting records or records with evidential value must be kept for ten years. Consequently, certain documents (leases, QR-bills, certificates, statements, formal notices and canonical copies of deeds) cannot be deleted immediately at a person's request, even where a valid deletion request exists: they are kept at least until the end of the ten-year legal period, with restricted access, then anonymised or deleted.

When a landlord leaves the service, the data is not destroyed indiscriminately: deletion takes the roles into account, so that the landlord's departure does not deprive the tenant of access to its own lease, and the records subject to retention are anonymised rather than destroyed where possible. The precise periods per category are documented in the register of processing activities.

Application files: the documents of rejected applications (identity, situation, income, supporting documents) are deleted automatically six months after the application is submitted, unless a legal obligation provides otherwise or a dispute is pending. Accepted applications follow the fate of the data of the corresponding lease. As these files may contain sensitive data within the meaning of art. 5 let. c FADP, access to them is restricted throughout the retention period.

9. Your rights

In accordance with the FADP, every data subject has the following rights: access (art. 25), which makes it possible to know whether data concerning them is being processed and to obtain a copy of it, in principle free of charge (art. 25 para. 6); rectification of inaccurate data; erasure or destruction (art. 25 para. 1), subject to the legal retention obligations described in section 8; portability, that is the handing over of the data in a common electronic format (art. 28); objection to a processing operation or withdrawal of a consent.

imoz provides a complete and reusable export function for the account data. To exercise these rights, submit your request using the form on the Help page (imoz.ch/support) or by post to DIZZUS GmbH, Chamerstrasse 172, 6300 Zug, Switzerland; a reasonable identity verification may be requested in order to avoid any disclosure to a third party. imoz does not take any automated individual decision producing legal effects (art. 21 FADP): the reconciliation of payments and the rent reminders are mere aids with no legal effect of their own. A courtesy reminder may be sent automatically to the tenant after a grace period following the due date, whereas acts with legal effect, in particular formal notice and termination, are never automatic and remain triggered or validated by the landlord. The data subject may finally refer the matter to the Federal Data Protection and Information Commissioner (FDPIC) and, where applicable, to the courts.

10. Data security

imoz implements appropriate technical and organisational measures (art. 8 FADP). The isolation between landlords relies on access control at the database row level (Row Level Security), which constitutes the service's single authorisation contract and is the subject of automated anti-regression tests. Communications are encrypted in transit (TLS). Account access is protected by a password policy with a minimum length, rate limits on authentication attempts, session expiry in the event of inactivity and a logout that purges cached data. Sensitive operations (for example changing the IBAN or deleting the account) require re-authentication at the time of their execution. Sensitive changes are logged.

In the event of a data security breach entailing a high risk for the data subjects, imoz follows a procedure of notification to the FDPIC and, where applicable, to the data subjects (art. 24 FADP). Where imoz acts as a processor for tenant or applicant data, it notifies the responsible landlord as soon as possible of any breach of which it becomes aware (art. 24 para. 3 FADP).

11. Cookies and audience measurement

imoz limits cookies and trackers to what is strictly necessary for the operation of the service, for example to maintain the session of the authenticated user and to ensure security. For aggregate audience measurement only, imoz uses Plausible Analytics, self-hosted by DIZZUS GmbH on a same-origin basis (no transfer to a third party), without cookies or individual identifiers: the statistics are anonymous and cannot identify a visitor, so no consent is required. imoz does not share browsing data for profiling purposes and uses no advertising tracker. The routing and protection of traffic by Cloudflare (see section 6), including Turnstile on the contact form, serve only the security of the service: Cloudflare sets no advertising tracker or audience-measurement cookie in this context, and any technical cookies it uses are strictly necessary for that purpose.

12. Verifiable documents

Certain documents carry evidential or accounting value and are associated with a public verification page at the address imoz.ch/verify followed by an identifier. This page checks the authenticity and integrity of a document by means of a cryptographic fingerprint computed over its complete content (SHA-256), without exposing the document or any personal data in plain text.

For as long as the ten-year legal retention applies to a record, the verification point is maintained in order to preserve its evidential value. When a document and its fingerprint are deleted at the end of the retention periods, the corresponding verification no longer returns a confirmation.

13. Changes

imoz may amend this policy, in particular to take account of legal or technical developments or the activation of new processors. The applicable version is the one published on imoz.ch. In the event of a substantial change, users are informed by an appropriate means. The date of the last update appears at the top of the page.

14. Contact

For any question regarding this policy or the exercise of your rights, contact DIZZUS GmbH, Chamerstrasse 172, 6300 Zug (Switzerland), UID CHE-469.903.322, by post or using the form on the Help page (imoz.ch/support). You also have the right to contact the FDPIC, the competent supervisory authority in Switzerland. Swiss law applies, subject to the mandatory jurisdictions provided for by law.