Skip to content

Data protection

Data protection declaration for the website Lua.ch and the Lua application.

As of: July 14, 2026

1. Responsible body

The responsible body for the website Lua.ch and for its own data processing in connection with Lua is:

Datascale GmbH
Bankstrasse 1
8610 Uster

Ramon Egger
info@Lua.ch

2. Scope

This privacy policy applies to:

  • the website Lua.ch;

  • Contact, demo, newsletter and contract inquiries;

  • the use of the Lua application;

  • Support, security, operational and administrative processes related to Lua.

For data that institutions collect in Lua about their clients, employees, contact persons or other people, the respective contract with the institution, in particular the order processing contract, also applies.

3. Role distribution in the Lua application

When using Lua by institutions, the respective institution is generally responsible for data protection. The institution decides which data is recorded in Lua, for what purposes it is processed and who has access to it.

Datascale GmbH operates Lua as a technical service provider and processes this data on behalf of the institution. Datascale GmbH does not process this data for its own purposes, but only to provide, maintain, secure and support Lua and in accordance with the contract and instructions of the respective institution.

Datascale GmbH is responsible for its own data processing, for example website visits, demo requests, customer administration, communication, invoicing, security and operations.

4. Processed personal data

Depending on usage, we process the following data in particular:

4.1 Website Lua.ch

When you visit the website, technical data may be generated, in particular:

  • IP address;

  • date and time of access;

  • pages accessed;

  • browser type and operating system;

  • Referrer URL;

  • technical log data for security and error analysis.

If you contact us, book a demo or register for information, we will also process:

  • personal details;

  • email address;

  • Telephone number, if provided;

  • organization/institution;

  • function/role;

  • content of the request;

  • appointment booking details;

  • Communication history.

4.2 Lua application

In Lua, institutions can record and edit comprehensive data in the area of client management. These include in particular:

  • Master data of clients;

  • Contact and address details;

  • Date of birth, gender, AHV numbers or other identifiers, if recorded by the institution;

  • Dossiers, progress reports, notes and documentation;

  • care information;

  • Contact persons, relatives, legal representatives and network persons;

  • Attendances, absences, attendance planning and performance;

  • Entries and exits;

  • diagnoses, medications, health information and medical claims;

  • Orders, tariffs, payer and billing information;

  • Assessments, assessments, measures and individual processes;

  • File uploads such as PDF, images, medical reports, contracts, correspondence or other documents;

  • User accounts of employees of the institution;

  • roles, permissions and access information;

  • Login, security and audit logs.

Lua can process particularly sensitive personal data, in particular health data, data about social assistance measures, data about minors and other sensitive data, to the extent that these are recorded by the respective institution.

5. Purposes of data processing

We process personal data in particular for the following purposes:

  • Provision of the website Lua.ch;

  • responding to inquiries;

  • Carrying out demo appointments;

  • Sending information or newsletters, if offered and subscribed to;

  • Conclusion and execution of contracts;

  • Provision, operation and further development of the Lua application;

  • user management, authentication and authorization control;

  • technical security, error analysis and misuse prevention;

  • support and maintenance;

  • backup, recovery and operational security;

  • Fulfilling legal, contractual and regulatory obligations;

  • Enforcement or defense of legal claims.

6. Legal basis

We process personal data in accordance with the Swiss Data Protection Act. To the extent that the EU General Data Protection Regulation is applicable in individual cases, we base the processing on the following bases in particular:

  • Fulfillment of contract or pre-contractual measures;

  • legitimate interests, in particular secure operation, support, improvement and protection of the systems;

  • legal obligations;

  • Consent, if such consent is required, for example for newsletters;

  • express consent or other special legal basis, insofar as particularly sensitive data is concerned and this is necessary in individual cases.

For data that institutions collect in Lua, the respective institution is responsible for the legality of the collection and processing.

7. Website analysis with Fathom Analytics

On the website Lua.ch we use Fathom Analytics, a service provided by Conva Ventures Inc. based in Canada, to evaluate the use of the website in a data protection-friendly manner.

Fathom Analytics is used exclusively on the public website, not within the Lua application. Fathom does not use tracking cookies for website analysis and does not track visitors across different websites.

When you access the website, the page accessed, the referring website, technical information about the browser and device as well as the IP address and the user agent are processed. Fathom only processes IP address and user agent temporarily to create data-efficient usage statistics and does not store them along with browsing history. For visitors from the EU, IP addresses are processed and anonymized within the EU according to Fathom. For access from other countries, processing can take place in Canada, the USA or other countries.

We use Fathom to understand what pages are viewed, how the site is used, and how we can improve content. To the extent that the GDPR is applicable, we base this processing on our legitimate interest in data-efficient reach measurement and improvement of the website. If consent is required in individual cases, processing is carried out on the basis of this consent.

Further information can be found in theFathom Analytics Privacy Policy.

8. Google Tag Manager and Google Analytics

We use Google Analytics on the public website and may use Google Tag Manager to centrally manage analytics and other website tags. Both services are offered by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Tag Manager is used to trigger website tags according to the set rules. It does not create any independent usage profiles itself. What additional data is processed depends on the services integrated through it.

When using the Google Tag Manager, when the script is accessed, for technical reasons the IP address, the user agent, the time of retrieval and other standard HTTP data are transmitted to Google. Google may also process aggregated diagnostic information about the stability, performance and quality of the integration. According to Google, standard HTTP log data is deleted within 14 days.

Google Analytics helps us understand how the website is used. In particular, the pages accessed, the origin of the visits, interactions, approximate location information and technical information about the browser and device can be processed. IP anonymization is activated. Google Analytics may use cookies or similar technologies and process pseudonymous identifiers.

Non-technically required analytics and marketing tags will only be activated after you have consented via the consent banner. You can revoke your consent at any time via the consent settings. To the extent that the GDPR is applicable, this processing is based on your consent. The technical management of the tags and the security of the integration may also be based on our legitimate interest in a secure and efficiently managed website.

The services integrated via Google Tag Manager are each described separately in this data protection declaration. Google may also process data through Google LLC and other group companies in the USA or other countries. The applicable contractual and legal guarantees are used for such data transfers. Google Analytics and, if used, Google Tag Manager are not used within the Lua application.

Further information can be found in theGoogle privacy policyand in theData protection information about Google Tag Manager.

9. Cookies and local storage

The website and the Lua application may use technically necessary cookies or comparable storage technologies. These include in particular:

  • session cookies;

  • login and authentication cookies;

  • CSRF protection;

  • Remember me function;

  • language settings;

  • security-related information.

These technologies are necessary for operations, security and usability.

No marketing or tracking tools are used in the Lua application.

10. Contact forms, demo bookings and newsletters

If you use a contact form, book a demo or contact us by email, we will process the data you provide to process your request.

We can use Cal.com for demo bookings. The data required to book an appointment is processed, for example name, email address, organization, time of appointment and information about the request. Cal.com processes the data required for appointment bookings and can use its own sub-service providers for this purpose.

If we offer newsletters, we only send them to people who have registered for them or who have a legally permissible basis. You can unsubscribe at any time.

If a CRM system such as HubSpot or a comparable service is used in the future, this data protection declaration will be updated accordingly. Such a service is integrated contractually and in terms of data protection law.

11. Email Communications

We can use Microsoft 365 for email communication and sending messages.

Emails may contain personal information. If possible, particularly sensitive content should not be sent directly by email, but should be made available via protected access in Lua.

Microsoft 365 data residency depends on tenant, geography, service, and configuration; Corresponding settings and contractual data protection conditions are checked separately.

12. AI features

Lua can use AI functions, in particular via Azure AI / Azure OpenAI in Switzerland.

AI functions are used to support work processes, for example for summaries, structuring, formulation aids or evaluations, as long as such functions are activated in Lua.

When using AI functions, content from Lua can be transferred to Azure AI. Datascale GmbH configures these services so that they are processed in Swiss Azure regions where possible. It is important that the specific deployment type is relevant for Azure AI: With standard or regional deployments, the inference takes place in the deployment region, while global deployment types can also include other Azure regions.

Azure OpenAI or Microsoft Foundry Models prompts, outputs, embeddings, and training data are not available to other customers, are not available to OpenAI, and are not used to train generative foundation models without permission.

13. Hosting, operation and data storage

Lua is operated on private or dedicated server environments, which are administered by Datascale GmbH. The technical infrastructure runs at Infomaniak in Switzerland, in particular on Infomaniak Public Cloud. AWS S3 can also be used in Switzerland for file storage or object storage.

Infomaniak operates its public cloud data centers as Tier 3+ data centers in Switzerland with certifications such as ISO 27001, ISO 9001, ISO 14001 and ISO 50001.

Backups are created via Infomaniak Swiss Backup with Acronis. Swiss Backup serves as encrypted backup in Swiss data centers with ISO 27001 certification, geographical redundancy and confidentiality.

14. Error tracking, monitoring and security

To ensure operation, stability and security, we use monitoring, logging and error analysis systems.

These include in particular:

  • own LGTM stack monitoring;

  • Laravel Nightwatch for error tracking and performance analysis;

  • technical server and application logs;

  • Snyk or comparable security checks for dependencies and code security;

  • monthly patching and security processes.

Laravel Nightwatch is used for error analysis and performance monitoring. Laravel Nightwatch uses the EU region for Lua. Data retention depends on the configuration booked.

We configure error tracking and monitoring so that sensitive content is avoided, shortened or masked wherever possible. Nevertheless, technical logs may contain personal data in individual cases, such as user IDs, IP addresses, URLs, error messages or context information.

15. Access by Datascale employees

Employees or agents of Datascale GmbH only access customer data in Lua if this is necessary, in particular:

  • in an emergency;

  • for troubleshooting;

  • for security analysis;

  • upon specific request from the institution;

  • to the extent necessary to fulfill the contract.

Access is limited to the minimum required and logged as far as technically possible.

16. Retention and deletion

Personal data will only be retained for as long as is necessary for the respective purposes, as long as there is a legal or contractual obligation or as long as there are legitimate interests.

The following applies in particular to Lua:

  • Productive data is retained for the duration of the contract.

  • After the end of the contract, data will be deleted, returned or anonymized according to the instructions of the institution.

  • Backups are retained for 35 days.

  • Audit logs and security-relevant protocols can be retained for traceability, security and compliance during the term of the contract or according to customer configuration.

  • Deletion or anonymization takes place upon request or in accordance with contractual regulations.

17. Data Security

We take appropriate technical and organizational measures to protect personal data.

These include in particular:

  • Hosting and object storage in Switzerland;

  • encrypted transport via TLS;

  • Storage on encrypted storage at Infomaniak Public Cloud and AWS S3 in Switzerland;

  • Web Application Firewall (incl. OWASP Core Ruleset);

  • Role and authorization concept with spatie permissions;

  • tenant-related access restrictions;

  • two-factor authentication;

  • technical access restrictions;

  • Logging of security-related events;

  • regular backups;

  • monthly patching processes;

  • Vulnerability testing with Snyk or comparable tools;

  • monitoring and error response;

  • Access only on a need-to-know basis.

18. Disclosure to third parties and sub-processors

We only pass on personal data to the extent that this is necessary for the provision, operation, security or fulfillment of the contract or if there is a legal basis.

Service providers used can in particular be:

Service provider Purpose Location/Note
Infomaniak Hosting, public cloud, backup, infrastructure Switzerland
Amazon Web Services (AWS S3) Object storage and file storage Switzerland
Microsoft 365 Email communication depending on tenant, service and configuration
Azure AI / Azure OpenAI AI features Switzerland, if configured regionally accordingly
Laravel Forge Deployment and server management Infrastructure/deployment data
Laravel Nightwatch Error tracking, performance, stability EU region configured
Cal.com Demo and appointment bookings Website / Sales
Fathom Analytics Website analysis Canada; EU isolation for visitors from the EU; other processing locations possible
Google Tag Manager (if used) / Google Analytics Tag management and website analytics Ireland; Processing possible in the USA or other countries; only website, no Lua application
Snyk Security testing of code and dependencies no productive HIS content is planned

When data is transferred abroad, we ensure appropriate data protection or suitable guarantees. Switzerland maintains a binding list of states with adequate data protection; In addition, the EU has confirmed the adequacy of the Swiss data protection level.

19. Rights of Data Subjects

Affected persons can, within the framework of applicable data protection law, request information, correction, deletion, restriction, data release or objection.

If a request relates to data that an institution has recorded in Lua, we generally forward the data subject to the respective institution or support the institution in processing the request.

Inquiries can be directed to info@Lua.ch.

20. Data Breaches

If a data security breach is identified, we will investigate the incident and take appropriate action. If an institution's data is affected, we will inform the institution as quickly as possible so that it can fulfill its own legal obligations.

21. Changes to this Privacy Policy

We can adapt this data protection declaration at any time. The current version is published on Lua.ch.

If there are significant changes to the Lua application, users can be referred to the data protection declaration again the next time they log in.

Consent

This site uses third party services that need your consent.