Designed for controlled use of AI in line with the principles of Swiss data protection law.
Whether a particular use is lawful depends on its purpose, data, roles and configuration. This statement is not a general legal or compliance assurance.
STEREO / AI platform for Swiss SMEs
STEREO combines Swiss platform operations with capable AI. You can see which models and integrations are used and decide where your team stays in control.
Security maturity
STEREO distinguishes between the controls already in place and the evidence still outstanding.
Whether a particular use is lawful depends on its purpose, data, roles and configuration. This statement is not a general legal or compliance assurance.
The first operating cycle is under way; an independent review of effectiveness is still outstanding.
The data and control path
The following layers are not combined into a blanket claim about data residency or compliance.
STEREO's standard SaaS service and the platform, customer and operational data for which STEREO is responsible are hosted and stored in Switzerland. External model inference is enabled only through individually reviewed EU processing routes. Required content may therefore be processed outside Switzerland. Integrations selected by the customer may create their own, separately disclosed data routes.
Capable AI may require content to be processed through controlled external model routes outside Switzerland. Provider, region, retention class and permitted purpose must be disclosed for the actual route before activation; there is no silent global fallback.
Connected email, calendar, file or business systems receive only the data and actions required for the approved task. Roles, storage locations and transfer conditions depend on the destination system and the customer's agreement with that provider.
hy gmbh does not use customer data to train its own model across customers or for a new content purpose of its own. Training, abuse monitoring and retention by external providers are assessed separately for the activated account, model and endpoint route.
Work records, files, security evidence, backups and provider routes have different lifecycles. Binding retention periods are stated in the specific offer and the related privacy documents.
Member removal, data export, primary deletion, backup expiry and tenant closure are handled separately. Statutory duties or documented legal holds may limit deletion; the real exit path is evidenced before customer release.
Roles, autonomy profiles, policies and approvals limit actions. Depending on the use, operator information, a data processing agreement, technical and organisational measures and a release-specific provider schedule may be made available. None of these is a certificate or legal advice.
STEREO is neither ISO 27001 certified nor SOC 2 audited today. Data location, model routes and contractual scope are promised only on the basis of actual technical, contractual and independent evidence.
Need information for an internal review? Contact us to clarify which statements and documents can be supported for your intended use.
Authoritative sources
These links explain Swiss data protection requirements in general. They do not replace an assessment of the specific use or legal advice.