Privacy
Controller
Quartiero GmbH
Bernstrasse 27b
3122 Kehrsatz
Switzerland
The Swiss Data Protection Act (revDSG) applies. Quartiero GmbH is the controller for the processing. Please direct privacy questions to info@quartiero.ch.
Territorial scope
Quartiero's offering is currently aimed at business customers in Switzerland, and the revDSG applies. Use from the European Union is not excluded. Where the European General Data Protection Regulation (GDPR) applies to a specific processing activity, the data subject rights it provides apply in addition to the rights under the revDSG.
What data we process
When you visit the website and the portals, the server briefly logs technical connection data such as IP address, time, the page requested and the browser type. These server logs serve secure operation and troubleshooting and are deleted after a short time.
For signing in to the portals (management portal, advertising portal, operator portal) we use Amazon Cognito. This processes the account data of the signed-in person, usually email address and name, so they can sign in and use the respective portal.
When you write to us through the contact form or by email, we process the details you provide (name, email, phone if given, and your message) in order to answer your enquiry.
We only use technically necessary cookies needed for sign-in and the session. There is no tracking and there are no advertising cookies on the website.
Purposes of processing
We process this data to provide and securely operate the website and the portals, to manage sign-ins and accounts, to play out the stairwell content on behalf of the property management, to answer enquiries, and to keep the anonymous reach and click measurement for advertising.
Content in the portals
The property management maintains the stairwell content in the portal, such as notices, house rules or contact details. Where such content contains personal data, for example the name of a caretaker, we process it on behalf of the management. The data processing agreement applies to this.
Data from the screens in the stairwell
The screens count anonymously only. We record whether a movement occurred and whether a click happened, each as a plain count without any link to a person. There is no camera or person recognition, and residents do not sign in.
Measurement uses a motion or presence sensor (infrared or radar) that only detects presence and movement and does not capture or store any images. The anonymous counts serve to measure reach and clicks for advertising.
Advertising
Advertisers and agencies receive only anonymous, aggregated figures, such as the reach and the number of clicks of a campaign. No personal data is passed to advertisers, and there is no advertising targeted at an individual.
Resident app
Anyone using the resident app pairs it with the public building code shown on the screen in the stairwell. No sign-in with personal data is needed for this. The app shows the same anonymous building information that already runs on the screen.
Disclosure to third parties
We do not sell personal data. Disclosure only happens to processors who support us in operating the service and are bound by our instructions. This is essentially Amazon Web Services for hosting, database, sign-in (Amazon Cognito) and sending email. Beyond that, we disclose data where we are legally required to.
Hosting and storage location
The data is processed and stored at Amazon Web Services, as a rule in the eu-central-2 region (Zurich, Switzerland). For the real-time connection of the devices, such as status messages and commands, the eu-central-1 region (Frankfurt, Germany) is also used, because the service required for it is not offered in Zurich. Only technical and anonymous data is transmitted there in real time, such as status messages and commands. No data is stored in eu-central-1. It merely passes through the region for the moment of delivery and is neither written nor retained there. From a Swiss perspective, Germany provides adequate data protection.
Amazon Web Services is a US company. Even though the data is processed in Switzerland, and in Germany for the technical real-time connection, access by US authorities based on US law, such as the CLOUD Act, cannot be ruled out with absolute certainty. We address this residual risk with encrypted transmission and storage, by limiting processing to the Zurich and Frankfurt regions, and by keeping data to a minimum.
Data security
We take appropriate technical and organisational measures to protect the data, such as encrypted transmission, access limited to authorised persons and separate processing per tenant. No one can guarantee absolute security for transmission over the internet.
Retention
The anonymous raw counts from the screens are given an automatic deletion period (TTL) of 90 days and are removed after they are summarised into anonymous daily totals. Technical device error logs expire automatically after 30 days. Content and accounts in the portals are kept for the duration of the contractual relationship and deleted afterwards. Enquiries via the contact form are kept for as long as needed to handle them. Server logs are deleted shortly.
Your rights
Under revDSG you have the right to access, rectification and erasure, as well as to restriction of processing. Please contact the office named above. If you disagree with our processing, you can lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).
Changes to this policy
We adjust this privacy policy when our processing or the legal requirements change. The version published on this page applies.
Last updated: July 2026