Swiss 4th Dimension Engineering · Media · Zug Back to site

Legal · Data protection

Technical & Organizational Measures.

Company Swiss 4th Dimension Development GmbH
Address Zugerstrasse 41, 6312 Steinhausen, Switzerland
Registration CH-170.4.017.790-3
Version 1.0 — July 2026
01

Purpose & scope

This document describes the technical and organizational measures (TOMs) implemented and maintained by Swiss 4th Dimension Development GmbH (the “Company”) to ensure an appropriate level of security for personal data processed in the course of its business, in accordance with the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR), and the Standard Contractual Clauses (Annex II). These measures apply to all personal data processed by the Company, whether on its own behalf or in connection with services provided to its partners and clients.

02

Organization of information security

  • Information security is owned at founder level; a named person (Nikola Bjelogrlic, Founder) is responsible for data protection and acts as the single point of contact for privacy matters.
  • The team is deliberately small and senior; access to personal data is restricted to persons who need it to perform their role (need-to-know / least-privilege principle).
  • All persons with access to personal data are co-founders or senior members of the Company, bound by a written confidentiality agreement in addition to their statutory duties of loyalty and confidentiality under Swiss company law; external contractors are not granted access to personal data unless bound by a written confidentiality undertaking.
  • Security measures are reviewed when systems, providers, or processing activities change, and at least annually.
03

Access control, identification & authorization

  • Unique, personal accounts for every system; shared accounts are not used for systems containing personal data.
  • Multi-factor authentication (MFA) is enforced on all business-critical services (email, hosting, cloud infrastructure, code repositories, advertising platforms).
  • Strong, unique passwords are generated and stored in an encrypted password manager.
  • Administrative privileges are limited to the minimum number of persons and reviewed regularly.
  • Access rights are revoked promptly when a role changes or a collaboration ends (documented offboarding).
04

Encryption & pseudonymization

  • All data in transit is encrypted using industry-standard transport encryption (TLS 1.2 or higher); unencrypted transport protocols are not used.
  • Data at rest on servers is hosted with providers that apply at-rest encryption in certified data centres.
  • All company endpoints (laptops, workstations, mobile devices) use full-disk encryption and automatic screen locking.
  • Where personal data is used for analysis or reporting, it is aggregated or pseudonymized wherever feasible; direct identifiers are separated from working datasets where practicable.
05

Physical & environmental security

  • The majority of the Company's systems, including all email, are hosted in Switzerland with an established Swiss provider whose data centres are ISO 27001 certified and physically secured (access control, video surveillance, redundant power and cooling).
  • Remaining workloads run with established international cloud providers, all operating certified, physically secured data centres.
  • The Company does not operate its own server rooms; no personal data is stored on physical media such as USB drives or external disks.
  • Paper records containing personal data are avoided; where unavoidable they are stored locked and destroyed securely.
06

Availability, backup & resilience

  • Hosting and email providers operate redundant infrastructure with documented availability commitments.
  • Data is protected by provider-managed backups, complemented by the Company's own scheduled backup routine; backups are stored separately from production systems.
  • Restores from backup are tested periodically to verify that data and access can be re-established.
  • Code and configuration are kept under hosted version control (git), allowing systems to be rebuilt reproducibly.
07

Logging & monitoring

  • Access to production systems and administrative actions are logged by the respective platforms.
  • Authentication events (including failed logins) on business-critical services are logged and reviewable.
  • Logs are protected against manipulation by the respective providers and retained in accordance with their retention policies.
08

System configuration & hardening

  • Operating systems and software are kept up to date; security updates are applied promptly (automatic updates enabled where available).
  • Default credentials are changed and unused services and accounts are disabled.
  • Malware protection appropriate to the platform is in place on all endpoints.
  • Development, staging, and production environments are separated; production personal data is not used for development or testing.
09

Data minimization, quality & retention

  • Only personal data necessary for the specific purpose is collected and processed.
  • Personal data is kept accurate and up to date; inaccurate data is corrected or deleted when identified.
  • Personal data is retained only as long as necessary for the purpose or as required by law, and is deleted or anonymized thereafter.
10

Data subject rights, portability & erasure

  • Processes are in place to respond to data subject requests (access, rectification, erasure, portability, objection) without undue delay.
  • Data can be exported in commonly used, machine-readable formats.
  • Upon termination of a service relationship, personal data is returned or deleted in accordance with contractual and legal obligations.
11

Sub-processors & international transfers

  • The Company relies primarily on Swiss-based providers for hosting and email and, where required, on established international cloud providers, each operating under its standard data processing agreement; an up-to-date list of sub-processors is provided to contracting partners on request.
  • Providers are selected with preference for Swiss or EU/EEA hosting and recognized security certifications (e.g. ISO 27001).
  • Where personal data is transferred to countries without an adequacy decision, appropriate safeguards (such as the Standard Contractual Clauses included in the providers' data processing terms) are in place.
12

Incident management

  • Security incidents are assessed and documented; containment and remediation measures are initiated immediately upon detection.
  • Where an incident affects personal data processed on behalf of a partner or client, the affected party is notified without undue delay, with the information required to meet its own regulatory obligations.
  • Lessons learned from incidents are fed back into the security measures.
13

Review & evaluation

  • The effectiveness of these measures is reviewed regularly, at least once per year, and whenever significant changes occur to systems, providers, or processing activities.
  • This document is updated as measures evolve; the current version is always available at this URL.

Questions regarding this document or our data protection practices can be addressed to privacy@swiss4thdimension.ch .