This translation is provided for information only; the French version is legally binding.
This page describes how the application actually works, not an intention.
Who is responsible for processing
Gestorent Sàrl, whose full identity appears above. Contact: contact@gestorent.ch.
When you use Gestorent to manage your properties, you yourself are responsible for processing your tenants' data; we then act as a processor on your behalf. This distinction is not rhetorical: it is your decisions (sending a reminder, producing a settlement) that trigger processing, and we make none of them in your place.
What data
Your account: name, e-mail address, password (hashed, never readable), display preferences, and your second-factor details if you enable it.
Your portfolio: properties, holding entities, mortgages, leases, expenses, settlements, imported bank statements.
Your tenants and applicants: identity, contact details, amounts due and paid. An application file may carry a salary, a date of birth, an IBAN and a debt collection extract (these are the only data belonging to people who may never become our users), and they are destroyed (see "How long").
What we do not collect: no sensitive data within the meaning of art. 5 FADP is requested by our forms. The field catalogue of an application file is closed and defined in the code, precisely so that an unlawful question cannot be added to it.
For what purposes
Providing the service: keeping your portfolio, producing your QR-bills, your reminders and your settlements, reconciling your bank statements.
Securing access: verifying your address, authenticating your sign-ins, logging the actions that commit: who sent what, when.
Billing the subscription, and writing to you about your account.
What we do not do: no advertising, no resale, no profiling, and no automated decision concerning you or your applicants. The affordability ratio shown on an application file is a figure next to the file; it sorts nothing and rejects no one.
Who else has access
Our subcontractors, and them alone:
· Nine Internet Solutions AG, Zurich (Switzerland) — application, database and storage.
· Infomaniak (Switzerland): sending e-mails.
· Infomaniak (Switzerland): managing the domain name.
· Infomaniak (Switzerland): AI reading of documents, only if you have enabled it (see the next section); during this reading, your documents stay in Switzerland and are neither retained nor used to train a model.
· Infomaniak (Switzerland): keeping an encrypted backup copy of the database, outside our main host; the backup covers the database, never your documents.
· Infomaniak (Switzerland): technical error monitoring for the application, without your IP address, without your e-mail address and without your identifier.
· The drive provider you choose (OneDrive, Dropbox or Google Drive): your files stay with them, we only keep references to them. Gestorent hosts your data in Switzerland; if you connect your own storage, your documents are stored there under that provider's terms, which may be outside Switzerland.
· Payrexx (Switzerland): payment of YOUR Gestorent subscription, never your tenants'. Your card number never reaches us: Payrexx tokenises it, we only keep a reference, the last four digits and the expiry date.
GitHub (United States) hosts our source code, and no customer data appears there.
AI reading of documents
It is disabled by default, including on existing accounts. No document leaves the application until you have enabled it, and the box that enables it is the one that collects your consent: it states on the spot which third party receives what, what they do with it, and how long the record is kept.
If we change provider or retention period, the question is asked again: consent given for one third party does not carry over to the next.
You can switch it off at any time. A document's content is treated as data, never as an instruction.
Audience measurement on the site
This site (the public pages you are reading right now) may be measured with Google Analytics (Google, United States). The application itself is never measured: no third-party tracker enters the screens where your properties, your tenants, your documents and your IBANs live.
Nothing is loaded until you have accepted: no script, no image, no request. Refusing is one click, in the same place as accepting, and not answering counts as refusing.
Your answer is kept in a cookie of our own ("gestorent-consent"), for six months. It measures nothing and goes nowhere; it is used so as not to ask you the question again on every page. The "Cookies" link at the bottom of the page reopens the choice at any time.
What we place on your device
A cookie is a small file the site writes in your browser. Here are ours, by use: only the last group asks for your consent.
Necessary for operation. These cannot be refused: without them, you can neither sign in nor stay signed in. The session; the sign-in in progress and its second factor ("gestorent.login", ten minutes); the screen you were returning to after signing in ("gestorent.login.next"); confirming an address ("gestorent.verification") and resetting a password ("gestorent.reset"), for the duration of the link; the round trip to your drive ("gestorent_drive_state", "gestorent_drive_verifier", ten minutes). A device you have marked as trusted is recognised for thirty days ("gestorent.device"); you can revoke it from your settings.
Your preferences, kept for one year: language ("gestorent.locale"), theme ("gestorent.theme"), light or dark mode ("gestorent.color-scheme"), the navigation column ("gestorent.nav-column") and the per-entity viewpoint ("gestorent.view"). They tell no one anything about you; they prevent the screen from changing appearance on every page.
Audience measurement, and it alone asks for your consent. Your answer is kept for six months in a cookie of our own ("gestorent-consent"); it measures nothing. If you accept, Google Analytics then places its own ("_ga" and "_ga_…"), on the showcase site only. If you refuse, or if you do not answer, none of these are placed.
We use no advertising pixel, no social network cookie, and no third-party tracker in the application.
How long
Your account and your portfolio: as long as your account exists. A closed account is kept for ninety days, restorable during that period, then permanently erased: a departure decided on a Tuesday is undone by Thursday.
Application files: destroyed as soon as they are no longer needed, at the latest three months after the decision concerning the applicant or the allocation of the dwelling. The date is announced to them on the form, and destruction is carried out by the product itself, every night: it depends on no one. Three months is a ceiling, never an extendable duration: retention with no limit is not retention, it is a stockpile.
Accounts created and never confirmed: thirty days.
The log of actions that commit is kept with the account: it is what allows us to say who sent which document, and it never contains a password, a code or a token.
Referral codes: if you give one out, the recipient's address is used to know who you gave it to. We erase it ninety days after the code has expired or been revoked; the code's line remains, so that the destruction date stays verifiable.
Your rights
Access, rectification, erasure, objection, and portability. Write to contact@gestorent.ch: we reply within thirty days.
Exporting does not require writing to us. From your settings, "Your data" produces an archive of your entire account: all your tables in CSV, and all the documents we have produced for you in PDF. It also states, at the top, what it does not contain. Accounting exports remain available entity by entity, in CSV and as a workbook, for what goes to a trustee.
You can lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).
Security
Encryption in transit, hashed passwords, second factor available to everyone and mandatory for our administration accounts. Access tokens to your drive are encrypted at rest and are never returned to your browser.
Our administration only sees metadata from your account (name, dates, counters). It cannot read your tenants, your amounts or your documents, and it cannot change your password, change your sign-in address, or open a session in your place.
No system is unbreachable: we would inform you without delay of a breach presenting a high risk to your rights, as required by art. 24 FADP.
Changes
This page carries its last-updated date. A change affecting what we do with your data (one more subcontractor, a new purpose) is announced to you by e-mail before it takes effect, not noted afterwards on this page.
Last updated: 2 October 2026.