Privacy Policy
Platform “POWER DUCK Augmented Vital@Work Navigator” & Services of WIN-WIN FOR WORK GmbH
This privacy policy informs you transparently about how WIN-WIN FOR WORK GmbH (hereinafter “we” or “us”) processes personal data. Our data processing is in accordance with the Swiss Data Protection Act (revDSG), the EU General Data Protection Regulation (GDPR), and the transparency obligations of the EU AI Act.
Table of Contents
- Dogmatic separation of roles: Controller vs. Data Processor
A. WIN-WIN FOR WORK as Controller
B. WIN-WIN FOR WORK as Data Processor - Responsible body in Switzerland and representatives in the EU
- Categories of processed personal data
A. General business data
B. Specific application data in the SaaS platform - System guardrails and strict processing rules
- Use of AI and legal assurances
5.1 Purpose and delimitation
5.2 Mandatory legal assurances
5.3 Transparency regarding residual risks in AI evaluations - Absolute AI decoupling for quantitative surveys
- Data disclosure and technology partners
A. Technical system infrastructure (SaaS modules)
B. AI model providers
1. Global infrastructures (security monitoring and temporary storage)
2. Local infrastructure in Switzerland (hosted by Infomaniak in Switzerland)
C. General commercial & administrative service providers
D. Third-country transfers and legal bases - Website services, cookies, and social media
- International data transfer and data security
- Your rights and free exercise thereof
- Applicable law
1. Dogmatic separation of roles: Controller vs. Data Processor
A. WIN-WIN FOR WORK as Controller
We are the controller for data processing where we decide on the purposes and means ourselves. This essentially concerns:
-
-
- visiting our websites (winwinforwork.org, weEmpower.ch, mypowerduck.com, powerduck.ai, powerduck-app.ai).
- registration for our community, newsletter, or blog use.
- the processing of contracts for physical training, consulting, online shop orders, and commercial processes.
- the administrative support of collaborations with independent, certified partners and resellers.
-
B. WIN-WIN FOR WORK as Data Processor
When operating our SaaS applications “POWER DUCK Augmented Vital@Work Navigator” and “Human to Human Hub” for our B2B corporate customers, WIN-WIN FOR WORK acts as a data processor bound by instructions.
| Exception to data processing: When processing telemetry and usage data to ensure system stability and product improvement, we are an independent controller. |
-
-
- Customer data sovereignty: The respective B2B customer is the sole controller, possesses full data sovereignty, and decides autonomously on the purposes of processing and user accounts. We process personal content data strictly bound by instructions on the basis of a data processing agreement (DPA).
- Platform operation as a purely process-oriented tool: The system is operated exclusively as a process-oriented tool for structuring, organizing, and accompanying projects, transformation, and change processes. It serves to document milestones, resource planning, and provide aggregated progress measurements at the department level. It anchors the “Vital@Work” model as a sustainable standard for organizational development.
- Clear distribution of duties: The B2B customer bears sole responsibility for all entered content data, knowledge modules, and instructions in the H2H Hub. They ensure that the system is not used contractually for monitoring employees or for automated task distribution. We provide the technical infrastructure and perform exclusively automated format and structure optimizations of the data streams without conducting content analysis.
-
2. Responsible body in Switzerland and representatives in the EU
The following bodies are responsible for data protection matters:
Controller Switzerland:
-
-
- WIN-WIN FOR WORK GmbH, Gisibachstrasse 13, 6405 Immensee, Switzerland
- Email: Datenschutz@winwinforwork.org
- Managing Director: Christian Czupalla
-
Representative in the EU:
-
-
- LEXR Germany Rechtsanwalts GmbH, Gormannstr. 14, 10119 Berlin
- EU contact person for data protection
- Email: contact@lexr.com
-
3. Categories of processed personal data
A. General business data
-
-
- Master data: Name, contact details, function, information on the business relationship.
- Contract and billing data: Payment details, billing data.
- Partner and consultant data: Certification status, billing and commission data of resellers.
- Communication data: Content from emails, contact forms, or chats.
-
B. Specific application data in the SaaS platform
-
-
- Account data: Email address, name, encrypted password.
- Consultant profiles: Name/initials, short profile, location (city/country), contact links.
- Project data: Project name, descriptions, target states, milestones, assigned project teams.
- Permissions: Release status of documents, access permissions.
- Inactivity deletion: To minimize data, inactive accounts including all profile data and project documents are automatically deleted after 6 months of inactivity.
- Employee data: Data processing is legally based on the necessity for the performance of the employment relationship or the legitimate interests of the employer.
-
4. System guardrails and strict processing rules
To comply with data protection and labor law, the “POWER DUCK Augmented Vital@Work Navigator” processes data using unavoidable technological guardrails:
| Data category | Processing purpose | Technical protective measure / Guardrail |
| General text inputs | Navigation and methodical orientation in the transformation process. | The system reacts exclusively to text inputs. No collection of behavioral metadata. |
| Text inputs on emotions/perspectives | Detection of structural blockages of the overall organization. | Best possible pseudonymization according to the current stage of development of the solution. There is a system-side separation of name, email, and role before AI processing. Management is only provided with generalized, cross-departmental process feedback. Inference regarding individuals is minimized by these integrated prompt and content filters (which are implemented as strict instructions and system prompts at the application level). These filters do not change the data through physical masking (whereby the processing quality and precise inference of the Navigator are fully maintained), but consistently exclude performance evaluations at the application level. |
| Biometric data | ARE NOT COLLECTED | The system is completely “blind” to biometric data and has no sensors for facial expressions or voice analysis in order to comply with the ban on emotion recognition in the workplace. |
| Personal performance data / KPIs | ARE NOT COLLECTED | System-integrated system prompts and instructions proactively block any attempts to query individual performance profiles, behavioral assessments, or personal KPIs. |
| Explicit prohibition of purpose limitation violation: The platform is technically and conceptually explicitly not intended for the recording, monitoring, or evaluation of employee behavior. If a user abusively feeds the system with behavioral data, they leave the purpose technically and contractually intended by the provider. |
5. Use of AI and legal assurances
The Navigator serves as a purely assisting orientation tool for the digitalization of the Vital@Work model. The artificial intelligence exclusively supports the human user.
5.1 Purpose and delimitation
-
-
- Pure assistance tool: The system supports process navigation and gives impersonal recommendations for action. It has no decision-making power of its own and does not assign tasks algorithmically.
- No behavioral assessment: The system is technically not capable of evaluating, monitoring, or predicting the performance, motivation, or psychological state of individual, identifiable employees.
-
5.2 Mandatory legal assurances
-
-
- Absolute exclusion of profiling: No profiling within the meaning of Art. 22 GDPR or the revDSG takes place. Individual characteristics for predicting work performance or behavior are categorically not evaluated.
- No automated individual decisions: The strict “human-in-the-loop” principle applies. The AI acts purely preparatorily. Every labor law or organizational decision is made exclusively by the human user.
- Compliance with Swiss labor law: Through integrated filters, data-saving aggregation, and the irreversible pseudonymization of feedback, the protection of personality and the ban on behavioral monitoring systems are guaranteed by the system. Since the system-side system prompts and instructions block inadmissible performance queries, it is contractually and technically ensured that no performance or behavioral assessments can be determined through the use of the Navigator.
- Integrated Prompt and Content Filters (Input & Output via System Prompts and Instructions): Before text inputs are passed on system-side to generative language models (input layer) and before generated responses are delivered (output layer), the platform applies integrated, dynamic software prompt and content filters implemented directly at the application level as strict system instructions and system prompts. These system-side system prompts and instructions expressly do not serve for physical, distortive masking (redaction) of entered text data, thereby fully preserving the semantic processing quality, contextual content, and precise functionality of the Navigator for the user. Instead, these instruction filters at the application level ensure that users cannot determine, query, or generate performance appraisals, behavioral assessments, or personal KPI analyses of employees via the Navigator. They function as native guardrails directly embedded in the processing logic to enforce the processing prohibition on performance data (purpose limitation). This avoids external security and latency risks (e.g., via unreliable third-party proxies) while keeping full processing quality uncompromised to ensure Navigator functionality.
-
5.3 Transparency regarding residual risks in AI evaluations
We transparently point out that even with optimally functioning prompt and content filters, a system-inherent residual risk exists. Generative language models could theoretically draw conclusions about individuals from the remaining pure text context. Through this risk disclosure, the responsibility for the output and its lawful use is shifted back to the B2B customer. The customer acts as the data protection controller and must always critically check the generated results as part of their duty of care (“human-in-the-loop”).
6. Absolute AI decoupling for quantitative surveys
To eliminate any data protection risks regarding surveys and progress measurements, the following strict system architecture applies:
-
-
- Complete technical decoupling: Optional online surveys for progress monitoring are handled exclusively via the external platform 2ASK (orbiz Software GmbH, Konstanz, Germany). There is no data or API connection between the surveys and the AI systems or language models of the platform.
- No performance or behavioral KPIs: No personal data, free text, or metadata are collected via the survey tool. The questions are based exclusively on standardized, quantitative multiple-choice questions on procedural framework conditions.
- Anonymity at the team level: Results are evaluated exclusively in anonymized, mathematically aggregated form at the level of large organizational units. An assignment of answers to specific persons or their individual performance is technically impossible.
- Secure server location: All survey data is hosted and processed on dedicated servers of orbiz Software GmbH in Germany.
-
7. Data disclosure and technology partners
The processing of content data via programming interfaces (APIs) always takes place while ensuring full freedom of choice for our customers and according to the principle of data minimization. In order to offer you the greatest possible customer benefit, maximum flexibility, and uncompromising security, our system architecture is based on the fact that you can independently choose between global APIs and closed models operated in Switzerland for your various assistants. We ensure that the functionality, system security, and your administrative benefit are always applied and continuously optimized in accordance with the current specifications and technical possibilities of the respective technology contract partners. Permanent model training by the respective contract partners on your entered content data is consistently excluded contractually.
A. Technical system infrastructure (SaaS modules)
-
-
- Operation of Power Duck applications: AI now AG, Switzerland
- Infrastructure & Cloud Hosting: Microsoft Ireland Operations Limited (Data residency: Switzerland / Geneva/Zurich). Own Azure resources in the controller’s tenant for encrypted system storage.
- Database service: MongoDB, Inc. (Data residency: Switzerland). Cloud database service on Azure infrastructure for storing Powerduck data.
- Frontend hosting: Netlify, Inc. (Data residency: EU).
- Identity management & SSO: Okta, Inc. / Auth0 (Data residency: EU).
- System notifications (Email): Twilio Inc. / SendGrid (Data residency: EU).
- Stability monitoring & system optimization: Sentry (Data residency: EU) and PostHog (Data residency: EU, configured purely for technical-operational purposes).
-
B. AI model providers
When creating the individual customer configuration (individualization) and operating the various digital assistants on the platform, the client (customer) always has the free and unrestricted choice as to which programming interfaces (APIs) and infrastructures the data processing for the respective assistant should take place. The following are available for selection:
-
-
- Global infrastructures (involving global contractual partners where technical processing takes place in the US or EU), or
- Local Swiss infrastructures with a closed, self-contained model (hosted on Swiss servers at Infomaniak in Geneva), where the entirety of data processing (inference) and temporary execution takes place exclusively, seamlessly, and physically in Switzerland with no data leaking to third-party providers.
-
Through this flexible architecture, the customer’s digital sovereignty and autonomy are fully safeguarded. The principal can independently decide for individual assistants which model to actively use, change or adapt model configurations for its operational assistants at any time, and flexibly respond to changing internal compliance requirements. No specific model is prescribed for the assistants by the platform provider.
1. Global infrastructures (security monitoring and temporary storage)
Summary statement on the security monitoring of US-based contract partners: In order to ensure the security, stability, and integrity of the services provided, the technical infrastructure of the US-based contract partners standardly provides for automated, temporary security and abuse monitoring. This runs in the background and serves exclusively to detect and ward off unauthorized system access, abuse, or serious policy violations. It is expressly agreed and contractually guaranteed that the transmitted content data (prompts and completions) will under no circumstances be used for the training of AI models or for product improvement by the providers.
Not all US-based contract partners have an approved special agreement for zero data retention (ZDR) or modified abuse monitoring; the transmitted content data for abuse detection and ensuring system security is temporarily cached on the protected infrastructures of the respective contract partners. This security check takes place depending on the corresponding specifications of the respective operator. After this check window has expired, this data is automatically and permanently deleted in the backend, provided there is no concrete, justified suspicion of system abuse or a security incident. In the event of justified suspicion of abuse or security incidents, this period can be extended for the duration of the clarification and securing of evidence.
Anthropic Ireland, Limited
-
-
- Processing location: USA (Inference is performed on servers of Anthropic, PBC in the USA).
- Setup: Claude API under the Commercial Terms of Service and DPA.
- Exclusion of model training: No model training on customer data. All API traffic is contractually guaranteed to never be used for training Claude models.
- Customer freedom of choice: The customer always has a free choice during operation and can independently decide to use this model, change the configuration, or switch to a closed model in Switzerland.
-
Microsoft Azure AI Foundry
-
-
- Place of processing (inference): Switzerland / CH. Inference takes place exclusively via regional deployments (Northern Switzerland) or Data Zone deployments (Data Zone Standard), whereby the physical retention of data in Switzerland is contractually guaranteed.
- Setup: Dedicated Azure resources within the controller’s tenant (no dedicated PTU capacity on shared infrastructure).
- Exclusion of model training: No model training on customer data; no transfer to OpenAI.
- Customer freedom of choice: The customer always has a free choice during operation and can independently decide to use this closed Swiss model or switch flexibly to another model.
-
OpenAI Ireland Limited
-
-
- Place of processing: USA (technical inference on servers operated by OpenAI OpCo, LLC in the USA).
- Setup: API platform subject to the OpenAI Business Terms with an integrated Data Processing Addendum (DPA).
- Exclusion of model training: Completely excluded by contract. Customer data (prompts and completions) via the API will under no circumstances be used for the training of OpenAI models.
- Customer freedom of choice: The customer always has a free choice during operation and can independently decide to use this model, change the configuration, or switch to a closed model in Switzerland.
-
Google AI Studio
-
-
- Processing location: USA / EU (on global Google servers).
- Setup: Gemini Developer API in the Paid Tier (with active billing) under the Gemini API Additional Terms.
- Exclusion of model training: Contractually completely excluded. In the paid Paid Tier (with active billing), any model training and manual review by human reviewers are excluded.
- Customer freedom of choice: The customer always has a free choice during operation and can independently decide to use this model, change the configuration, or switch to a closed model in Switzerland.
-
Perplexity AI, Inc.
-
-
- Processing location: USA (Inference takes place on servers of Perplexity AI, Inc. in the USA).
- Setup: Chat Completions API. When using real-time research, the entered queries or the search terms derived therefrom are transmitted to the search and index infrastructure of Perplexity as well as to the model providers used.
- Exclusion of model training: Contractually completely excluded. A strict Zero Data Retention Policy (ZDR) applies to API content; the content data is not used for training models.
- Customer freedom of choice: The customer always has a free choice during operation and can independently decide to use this model, change the configuration, or switch to a closed model in Switzerland.
-
2. Local infrastructure in Switzerland (Hosted by Infomaniak in Switzerland)
Infomaniak Network SA
-
-
- Setup & legal framework: Cloud hosting and operation of the models on physical infrastructure operated entirely in Switzerland (Geneva/Zurich, Rue Eugène-Marziano 25, 1227 Acacias) in accordance with the Personal Data Processing Agreement (DPA) concluded between the parties under the application of Swiss law and exclusive data processing in Switzerland.
- Data residency & processing location (inference): Switzerland / CH. The content data is processed and stored exclusively on the Swiss infrastructure. A transmission or release of the data to countries outside Switzerland or the EU/EEA is strictly prohibited contractually according to Art. 13.1 of the Infomaniak DPA without the prior written consent of the customer (Data Controller).
- Contractual & technical exclusion of model training: Any use of the entered or generated data (prompts and completions) for training the open-source models (Apertus, Qwen, Kimi, Mistral, Gemma) or for other purposes outside the provision of the agreed services is contractually and technically excluded according to Art. 2.1.2 and 2.1.3 of the Infomaniak DPA.
- Absolute protection against data leakage to third-party LLM providers: Since the open-source models (Apertus, Qwen, Kimi, Mistral, Gemma) are executed completely encapsulated and isolated within our Swiss tenant on Infomaniak’s servers, there is technically at no time an API, data, or network connection to the original model developers (such as Alibaba Group for Qwen or Moonshot AI for Kimi) or other external AI platforms. A flow of customer data to foreign third-party providers is thereby made technically impossible; full data sovereignty remains seamlessly in Switzerland.
- Customer freedom of choice: The customer always has a free choice during operation and can independently decide to use this closed Swiss model or switch flexibly to another model.
-
Apertus
-
-
- Processing location (inference): Switzerland / CH. Special model for structural analysis, executed on Infomaniak’s data protection-compliant cloud infrastructure.
- Storage location (security monitoring): No storage. Execution takes place exclusively transiently in the random access memory (RAM) of the Swiss servers; no logging of prompt content takes place.
- Customer freedom of choice: The customer always has a free choice to select or change this model during ongoing operation.
-
Qwen
-
-
- Processing location (inference): Switzerland / CH. Open-source language model for text analysis, operated in the isolated Swiss environment.
- Storage location (security monitoring): No storage. Volatile RAM processing; no logging and no data leakage.
- Customer freedom of choice: The customer always has a free choice to select or change this model during ongoing operation.
-
Kimi
-
-
- Processing location (inference): Switzerland / CH. Language model for context analysis of large documents, operated in isolation at Infomaniak.
- Storage location (security monitoring): No storage. Volatile RAM processing; no logging and no data leakage.
- Customer freedom of choice: The customer always has a free choice to select or change this model during ongoing operation.
-
Mistral
-
-
- Processing location (inference): Switzerland / CH. Open-source language model for text analysis and logical structuring, operated in the isolated Swiss environment of Infomaniak.
- Storage location (security monitoring): No storage. Volatile RAM processing; no logging and no data leakage.
- Customer freedom of choice: The customer always has a free choice to select or change this model during ongoing operation.
-
Gamma
-
-
- Processing location (inference): Switzerland / CH. Open-source language model specialized for assistance tasks operated in the isolated Swiss environment.
- Storage location (security monitoring): No storage. Volatile RAM processing; no logging and no data leakage.
- Customer freedom of choice: The customer always has a free choice to select or change this model during ongoing operation.
-
C. General commercial & administrative service providers
-
-
- ERP & accounting software: Bexio AG, Rapperswil, Switzerland.
- Project and work organization: com Ltd. (Data centers in the EU/USA).
- Office infrastructure & cloud storage: Google Ireland Limited (Google Workspace, EU) and Microsoft Ireland Operations Limited (Office 365, EU).
- Payment service providers: Stripe, PayPal, or PostFinance process credit card and billing data under their own data protection responsibility.
-
D. Third-country transfers and legal bases
If processing by the named providers takes place in countries without an adequate level of data protection (in particular the USA), the transfer is secured by the conclusion of the Standard Contractual Clauses (SCC) of the EU Commission (taking into account the Swiss adaptations of the FDPIC) as well as additional technical and organizational security measures (such as server-side pseudonymization, the implementation of integrated prompt and content filters at the application level by means of strict system prompts and instructions to prevent performance evaluations while maintaining processing quality, and local Swiss alternative routings via Infomaniak). Individual providers are also certified under the Swiss-U.S. and EU-U.S. Data Privacy Framework (DPF).
8. Website services, cookies, and social media
To provide, secure, and optimize our website and our SaaS platform, we use various cookies, analysis, and third-party services:
-
-
- Use of cookies, local storage, and telemetry: To ensure operational security, system stability, and the error-free provision of our SaaS platform, we use exclusively technically mandatory cookies and local storage technologies. Since advertising or marketing tracking requiring consent is consistently avoided on our SaaS platform, no cookie banner is active or required. Data processing serves exclusively technical operation and system optimization.
- Cookies: We use small text files to distinguish visitors from one another without identifying them personally.
- Functional cookies: Necessary for settings, language, and login; consent-free.
- Analytical cookies: Measure reach and optimize content; notice is given via info banner when the website is accessed.
- Deactivation: Possible via browser settings; may restrict functionality.
- Google reCaptcha: To distinguish between human input and automated access in forms. Processes IP address, website use, duration of stay, Google account, mouse movements, and image puzzles. The service runs in the background without separate notice.
- Google Analytics: Analyzes usage behavior to improve the website. Collects pages accessed, clicks, approximate location, IP address, technical details, and source of origin. The IP address is shortened via “anonymizeIP” in the EU/EEA. Data deletion takes place after 12 months. The service is based on your consent.
- Google Ads / AdWords: Measures the success of Google advertisements. When an ad is clicked, a cookie (30-day validity, no personal identification) is set. Records the total number of forwarded users for anonymous statistics. Objection by deactivating cookies in the browser or blocking the domain googleleadservices.com.
- Google Maps: Integrates maps directly. Google records your page view and assigns the data to your Google account if you are logged in. Google uses data for advertising, market research, and demand-oriented design. Objection is to be directed directly to Google.
- Google Tag Manager: Management interface for website tags. The Tag Manager itself does not process any personal data.
- WordPress Plugins: To provide our online shop and member area, we use WordPress plugins from Automattic Inc. (USA) / WooCommerce Inc. (USA/Ireland).
- Plugins: WooCommerce (shop system), YITH WooCommerce Membership Premium, YITH Event Ticket, WP Jobmanager.
- Processed data: Name, address, company, billing/delivery address, email, telephone number, role/department, payment information, and server log files.
- Note: Automattic processes data as an independent controller also for its own marketing purposes and uses cookies/web beacons. Processing also takes place in the USA, whereby the US providers are certified according to the Swiss-US or EU-US Data Privacy Framework or we have concluded standard contractual clauses to ensure an adequate level of data protection. Objection and cookie deactivation in the browser possible.
- Social media plugins (share buttons): Enable the sharing of content in your profiles. By using them, personal data is transmitted to the respective operator, who processes it under their own responsibility.
- Facebook (Facebook Inc., USA): Establishes a direct connection to the server and transmits IP address and website visit. Objection by logging out before visiting the website or using browser add-ons.
- X (X Corp., USA): Links visited pages with your account. Objection by logging out or adjusting the privacy settings at X.
- LinkedIn (LinkedIn Corp., USA): Assigns your visit with IP address to LinkedIn (Recommend button).
- Xing (Xing AG, Germany): Connection to the server without storing personal data, IP address, or usage behavior analysis.
- YouTube (Google Ireland Ltd.): Integrates YouTube videos; data processing takes place in accordance with Google’s terms of use and privacy policy.
-
9. International data transfer and data security
-
-
- Securing data transfer: For third-country transfers, we conclude standard contractual clauses and rely on the Swiss-US or EU-US Data Privacy Framework. We also conduct Transfer Impact Assessments.
- Data Residency: The permanent storage of your platform data takes place exclusively in Switzerland (preferred) or the European Union.
- Access protection (2FA): Two-factor authentication is activated by default and mandatory for all administrative super-admin accounts of the platform.
- State-of-the-art encryption: All data transfers are encrypted. We refrain from statically naming rigid algorithms in order to ensure agile adaptation to future technological security standards.
-
10. Your rights and free exercise thereof
Under the revDSG and the GDPR, you are entitled to free rights of access, rectification, erasure, restriction, objection, and data portability.
Please send your request to Datenschutz@winwinforwork.org. For identity verification, we use exclusively data-saving procedures: If you make the request by email, we verify your identity via a short, informal confirmation to the email address stored with us. Alternatively, you can submit your request directly and verified via your password-protected login area of the platform. We will process your request within the legal period of 30 days.
-
-
- The competent supervisory authority in Switzerland is: Federal Data Protection and Information Commissioner, Feldeggweg 1, CH-3003 Bern. Website: www.edoeb.admin.ch
- Right of appeal in the European Union: If you are located in the European Union or the provisions of the GDPR apply to you, you have the right, in addition to the right of appeal in Switzerland, to complain to a data protection supervisory authority in the EU member state of your habitual residence, your place of work, or the place of the alleged data protection violation if you believe that the processing of personal data concerning you violates the GDPR.
-
11. Applicable law
This declaration is subject to Swiss law (excluding the conflict of laws). For consumers with habitual residence in the EU, mandatory consumer protection provisions of their home country remain applicable.
