This English page is a translation for convenience. The German version at tourlio.ch/avv is the binding one; in case of any difference, the German wording applies.
A business that uses Tourlio records the data of its drivers and other staff in it. Tourlio processes that data only on the business’s behalf and only to run the application. This agreement sets out what is permitted, how the data is protected and what happens to it at the end.
1 Parties and precedence
This agreement is made between the business that uses Tourlio (the “customer”) and Tourlio Yükseldi, Brunaustrasse 181, 8951 Fahrweid, Switzerland (the “operator”). For the data of its staff the customer is the controller, and the operator is the processor within the meaning of Art. 9 of the Swiss Federal Act on Data Protection (FADP).
This agreement forms part of the terms and conditions and is concluded together with them; no separate signature is required.
Where this agreement and the terms cover the same matter, this agreement prevails as regards the processing of personal data. In all other respects the terms apply.
Everything else is in the terms and conditions.
2 Subject matter and duration
The subject matter is the operation of Tourlio as an application over the internet — the admin web for planning and payroll, and the web app for drivers — including maintenance, backups and support.
The agreement starts when a trial account is opened and runs for as long as a trial or a subscription exists. It ends only once the data has been deleted under clause 13. The duty of confidentiality continues beyond that.
3 Purpose of processing
The operator does not use the customer’s data for its own purposes. It does not sell it, does not analyse it for advertising and does not use it to build profiles of the customer’s staff. An overview of the processing is given in Annex 1.
It processes the data solely to provide the customer with the functions of Tourlio. Depending on use, these include:
- Planning: creating tours, assignments and rosters and showing them to drivers.
- Recording: receiving item counts, receipt photos, odometer readings and drivers’ notes.
- Absences: managing holidays and sick leave, including medical certificates.
- Payroll: producing monthly payslips, payroll accounts, salary certificates, annual reports and the export for the accountant.
- Vehicles and tracking: managing vehicles and, where the driver has consented, recording the position during an assignment and condensing it into a trip.
- System emails: sending invitations, confirmations and password resets to the customer’s users.
4 Data subjects and data
The data subjects are the customer’s staff, in particular drivers, dispatchers and the people who administer the business’s account.
The customer ensures that it may process the data and informs its staff that it uses Tourlio. Tracking is not switched on by the customer: it runs only if the driver has accepted the notice in the app, and the driver can stop it at any time.
Medical certificates are health data and therefore sensitive personal data (Art. 5(c) FADP). The customer uploads them only where it needs them for continued pay during sickness.
The customer decides which data it records. The application is designed for the following categories:
- Account: name, email address, role, password as a hash, logins and failed attempts.
- Staff: personal details, AHV (social security) number, start and end dates, pay model, supplements and deductions.
- Assignments: tours, rosters, times, item counts, receipt photos and vehicle details.
- Tracking: position points during an assignment and the distance and duration derived from them.
- Absences: period, type, approval and medical certificate.
- Payroll: released payslips, corrections and the log of who changed what and when.
5 Instructions
The operator processes the data only on the customer’s instructions. Instructions are this agreement, the terms and everything the customer sets up and triggers in the application itself — a release, an export, an invitation.
The customer gives further instructions by email to info@tourlio.ch. Where they go beyond the agreed scope of service, the operator says beforehand whether and at what cost it will carry them out.
If the operator considers an instruction unlawful, it tells the customer and may suspend it until the customer confirms or changes it.
6 Confidentiality and access
The operator treats the customer’s data as confidential. Where it engages assistants, it first commits them to confidentiality in writing, including after their work has ended.
The operator accesses the content of the data — wages, receipt photos, medical certificates — only where this is necessary for operation, for fixing a fault or for a support request from the customer, and only to the extent required.
7 Data security
The operator takes the technical and organisational measures that Art. 8 FADP and the Data Protection Ordinance require for data of this kind. They are described in Annex 2.
The operator may adapt the measures to the state of the art. It replaces a measure only with one that is at least as effective.
An overview of the application’s security is on the About page.
8 Sub-processors
The customer agrees that the operator may engage the service providers listed in Annex 3. The operator binds them to the same obligations this agreement places on the operator itself and is responsible for them as for itself.
The operator engages a further service provider only after informing the customer at least 30 days in advance, by email to the owner’s address and in the application. The same applies if it replaces an existing one.
The notice is a change to the terms under clause 9 of the terms and conditions. The customer may object; the consequences and any refund follow that clause.
9 Place of processing
The data is stored and processed in Switzerland, backups included. No disclosure abroad takes place.
Should that ever change, clause 8 applies, and the operator discloses data only to a country that meets the requirements of Art. 16 and 17 FADP.
10 Rights of data subjects
If a member of the customer’s staff asks for access, correction, deletion or a copy of their data, the customer is responsible for the request. The application helps: details can be corrected at any time, and payslips, payroll accounts and exports are ready to download.
During the contract, staff are deactivated rather than deleted, because released payslips must remain unchanged. If the customer needs to delete individual data it cannot remove in the application itself, the operator helps on request.
If a data subject contacts the operator directly, the operator forwards the request to the customer and does not answer it itself.
11 Data security breaches
If the operator discovers a data security breach affecting the customer’s data, it reports it to the customer as soon as possible and within 48 hours at the latest, by email to the owner’s address (Art. 24(3) FADP).
As far as known, the report states what happened, which data and how many people are affected, what consequences are likely and what the operator has done about it. Anything not yet known at the first report follows later.
The customer decides whether the breach must be reported to the Federal Data Protection and Information Commissioner (FDPIC) and whether its staff must be informed. The operator provides the information needed.
12 Assistance and audits
The operator assists the customer with its obligations under the FADP as far as they concern the application, in particular with a data protection impact assessment, and provides the information needed.
The operator demonstrates compliance with this agreement first through the description in Annex 2 and through written information. If that is not enough, the customer may audit compliance itself or have it audited by a professional bound to confidentiality. It gives at least 30 days’ notice of an audit.
One audit per calendar year is free of charge; the operator may charge for further ones at cost, unless a specific incident justifies them. Other customers’ data is not disclosed during an audit.
13 Return and deletion
During the contract the customer can download a complete archive of its data at any time. This is also the return of the data; no separate request is needed.
After the contract ends, the archive remains available for 90 days, with reminders 30, 7 and 1 day before the period expires. On day 91 the operator deletes all of the business’s data, including receipt photos and medical certificates. It disappears from the backups as they expire, at the latest 31 days after deletion.
Subscription details and invoices to the customer are not deleted. They are not staff data but the operator’s own business records. On request the operator confirms the deletion in writing.
The periods in detail are set out in clause 6 of the terms and conditions.
14 Liability and final provisions
Liability is governed by clause 8 of the terms and conditions. Mandatory statutory liability is reserved.
The customer is responsible for processing the data it records in Tourlio lawfully. If third parties bring claims against the operator because the customer did not do so or gave an unlawful instruction, the customer indemnifies the operator.
The operator announces changes to this agreement in the same way as changes to the terms (clause 9 of the terms and conditions). Governing law and jurisdiction follow clause 10 of the terms and conditions.
Questions about this agreement and about data protection: info@tourlio.ch, or by post to Tourlio Yükseldi, Brunaustrasse 181, 8951 Fahrweid, Switzerland.
Annex 1 — Overview of processing
- Subject matter: operation of the Tourlio software for route planning and payroll at courier and transport businesses.
- Duration: term of the trial and the subscription, then until deletion under clause 13.
- Nature: recording, storing, calculating, displaying, exporting, backing up and deleting.
- Purpose: planning, recording, absences, payroll, vehicles and tracking (clause 3).
- Data subjects: the customer’s staff: drivers, dispatch, administration.
- Data: account, staff, assignment, tracking, absence and payroll data; medical certificates as sensitive personal data.
- Location: Switzerland.
Annex 2 — Technical and organisational measures
The application as it is built today:
- Data centre: servers, database and file storage are hosted by Infomaniak Network SA in Switzerland. Physical access and protection are the hosting provider’s responsibility.
- Login: personal accounts; passwords stored only as an Argon2id hash. After five failed attempts within 15 minutes the account is locked for 15 minutes, and login and password reset are rate-limited. Invitation and reset links can be used once and expire.
- Tenant separation: every query is bound to the business of the logged-in user. Without a valid business it returns nothing; the separation is enforced centrally and covered by automated tests.
- Roles: a driver sees only their own roster, their own recordings and their own payslips. Receipt photos and medical certificates are kept outside the database and can be reached only through checked access paths of the business itself, medical certificates only by its administration.
- Transmission: encrypted via TLS only, with HSTS. The admin web sends a strict Content Security Policy and cannot be embedded in other sites.
- Traceability: corrections to recorded figures are logged with time and author. A released payslip is frozen and cannot be changed.
- Backups: a full backup of database and file storage every day, copied encrypted to Swiss Backup in Switzerland and kept for 31 days. The key is not stored on the server. Restoring has been tested.
- Data minimisation: tracking only during an assignment and only with the driver’s consent; individual position points are deleted after 90 days, leaving the condensed trip.
- Operations: the application runs with restricted privileges; operating system and components are kept up to date. Credentials are not stored in the source code.
- Organisation: confidentiality obligation for assistants, contractual obligations for sub-processors and a fixed procedure for data security breaches (clause 11).
Annex 3 — Sub-processors
These service providers process the customer’s data on the operator’s behalf:
- Hosting of application, database, file storage and backups: Infomaniak Network SA, Geneva; processing in Switzerland.
- Delivery of system emails: Infomaniak Network SA (Mailhosting, Schweiz)
- Not a sub-processor: payment processing: PostFinance Checkout (PostFinance AG) handles the subscription fees. It processes the customer’s billing and payment details, not the data of its staff; Tourlio never sees or stores card details.
Last updated: 17.09.2026