Privacy Policy
Last updated: August 12, 2026
Your privacy matters to us. This Privacy Policy describes how Ortena collects, uses, and protects your data. The municipal fee data we publish comes from official public sources and is not personal data — this policy is about the information we hold on you as a visitor, subscriber, or municipality administrator.
1. What We Collect
Account Info
We collect your email address, and optionally your name, to manage your account and send transactional emails (e.g. sign-in links, subscription and billing notices, service announcements). We process this data to fulfil our contract with you (Art. 6(1)(b) GDPR).
Organisation and Verification Data
If you register as a municipality administrator, we process your work email address to verify that its domain matches the municipality's official domain, along with the organisation you belong to and your role within it. This is necessary to establish that you are authorised to manage that municipality's page (Art. 6(1)(b) and (f) GDPR).
Documents You Upload
Verified municipality administrators can upload fee regulations and similar official documents. These are intended to be public municipal publications, not personal data. We store them, extract the fee information they contain, and cite them as the source behind the published figures — so uploaded documents are retained as source evidence for as long as the data derived from them is published. Please do not upload documents containing personal data of third parties.
API Usage Data
For API subscribers we log which key made which request, when, and against which endpoint. We need this to enforce quotas, bill accurately, detect abuse, and debug problems — based on our contract with you and our legitimate interest in securing the Service (Art. 6(1)(b) and (f) GDPR).
Payment Details
Payment information is handled by Stripe to fulfil our contract with you (Art. 6(1)(b) GDPR). We don't store your credit card details.
Usage Data
We collect basic analytics like page views and device info to improve our Service, based on our legitimate interest (Art. 6(1)(f) GDPR). You can at any time.
Security
All data is encrypted in transit. API keys are stored hashed, never in plain text, and we apply regular security updates to keep your data safe. These measures are taken in accordance with our obligation to ensure the security of processing (Art. 32 GDPR).
2. Service Providers
We work with trusted service providers to deliver our Service. Your data is shared only as needed for the stated purposes.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner | Cloud compute and document storage | EU |
| Cloudflare | Web application firewall, bot protection, object storage | EU |
| Stripe | Payment processing | US |
| PostHog | Product analytics | EU |
| Sentry | Bug tracking | EU |
For providers located outside Switzerland and the European Economic Area (EEA) — marked US above — we rely on the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) to ensure an adequate level of data protection.
Separately, we retrieve municipal fee data from public bodies and partner services — including federal and cantonal registers and the metatarif electricity tariff API. These are sources of public data, not recipients of your personal data.
3. Your Data & Rights
You are in control of your data at all times. Here is what you can do:
- Revoke any API key at any time from your organisation settings
- Close your account (all data deleted within 30 days)
- product analytics at any time
- Request a copy of all your personal data
How Long We Keep Data
Account data is kept for as long as your account is active, and deleted within 30 days of closure. Data may remain for up to 14 days in an encrypted backup system after deletion before being permanently removed.
API request logs are retained for 12 months for billing, abuse prevention, and debugging. Uploaded municipal documents are retained as published source evidence, as described in Section 1. Payment records are kept for 10 years to comply with tax regulations.
4. Legal Bases
We comply with the Swiss Federal Act on Data Protection (FADP) and the European General Data Protection Regulation (GDPR). Under these regulations, you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data when it is no longer needed
- Restriction: Request that we limit how we process your data
- Portability: Receive your data in a standard format to transfer elsewhere
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Revoke any previously given consent at any time
- Complaint: File a complaint with a data protection authority (in Switzerland: FDPIC)
To exercise any of these rights, email us at [email protected].
Ortena accounts are for users 18 and older only.
5. Data Breach Notification
In the event of a data breach that affects your personal data, we will notify you within 72 hours of becoming aware of the incident. We will inform you which data was affected, the potential consequences, and the measures we are taking.
6. Changes to This Policy
For material changes, we will notify you by email. Continued use constitutes acceptance of the updated Policy.
7. Contact Information
Responsible for the content and operation of this website:
Siegenthaler Informatik
Ackersteinstrasse 11
8049 Zürich
Switzerland
Owner: Loris Siegenthaler
Business type: Sole proprietorship
Company UID: CHE-234.330.548
VAT: Not VAT-liable per Art. 10 Swiss VAT Act
Email: [email protected]
See also our terms and conditions.