Privacy Policy — BeMyTalent

    Version: 1.4 Last updated: August 21, 2026 Data controller: Ekylibr SA (Switzerland)

    This policy describes how BeMyTalent collects, uses and protects your data in accordance with the Swiss Federal Act on Data Protection (FADP/revFADP) and, where applicable, the European General Data Protection Regulation (GDPR).

    🇨🇭 Data hosted in Switzerland. Since August 8, 2026, all of your application data — database, authentication, files (accounting documents, invoices, payroll documents) and server functions — has been hosted in Switzerland (Supabase, Zurich region eu-central-2). Antivirus scanning of attachments also runs in Zurich (Google Cloud Run europe-west6).


    1. Who are we?

    Ekylibr SA publishes the BeMyTalent application ("BMT"), a financial management platform (forecasting, accounting, payroll, invoicing, CRM, quotes, inventory, mandates) intended for entrepreneurs, self-employed professionals and small businesses/SMEs based in Switzerland.

    Data protection contact:


    2. Data we process

    2.1 Data you provide directly

    CategoryExamplesLegal basis
    User accountemail, password (hashed), name, role within the projectperformance of the contract
    Project datacompany name, industry, planning horizon, currency, financial settingsperformance of the contract
    Accounting datajournal entries, chart of accounts, opening balances, VAT, expense reports, supplier and customer invoicesperformance of the contract + legal obligation (Art. 957 et seq. of the Swiss Code of Obligations (CO) — 10-year retention)
    Payroll datayour company's employees: identity, AVS number, salary, activity rate, family allowances (number of children), deductions, payslipsperformance of the contract + legal obligation
    CRM datacontacts, leads, deals, client companiesperformance of the contract
    Supporting documentsreceipts, invoices, other supporting documents you upload (PDF/JPG/PNG, ≤ 10 MB)performance of the contract + legal obligation
    IntegrationsBexio / Gmail / Shopify OAuth tokens (encrypted), WhatsApp / Instagram identifiersperformance of the contract (opt-in consent per integration)
    CRM messagesdrafts, conversations, templatesperformance of the contract

    Third-party data (employees, clients, contacts). When you enter into BMT data relating to persons other than yourself — your employees (Payroll module), your clients, your CRM contacts — you are the controller of that data within the meaning of the FADP/GDPR; BMT acts as a processor on your behalf. It is your responsibility to inform those persons and to have a legal basis for that processing.

    2.2 Data collected automatically

    CategoryExamplesLegal basisRetention
    Accounting audit logsensitive actions (posting, reversal, chart-of-accounts changes, attachment access) with timestamp and user identifierlegal obligation (accounting audit trail)10 years (Art. 958f CO)
    IP address in the audit logIP of the author of a sensitive actionlegitimate interest (security)rolling 90 days, then nullified
    Technical logsserver errors, performance, API requestslegitimate interest (operations)30 days
    Essential cookiessession, authentication, preferencesperformance of the contractsession or ≤ 12 months

    We do not use advertising cookies or third-party marketing tracking (no Google Analytics, no Meta Pixel, no Hotjar).

    2.3 Mobile application (iOS)

    BMT is also available as an installable application (PWA and iOS application distributed via the App Store). The application processes the same data as the web version — no additional processing, with the following clarifications:

    • Camera, microphone, photo library: used only when you scan a document, dictate a note or attach a photo. Capture takes place on your device; only the file you confirm is transmitted to our servers. No background access.
    • No advertising tracking: the application contains no advertising SDK, no tracking identifier (IDFA) and no cross-app tracking.
    • Account deletion: available directly in the application (Settings → Account), with the same effects as from the web (see §6).

    3. Why we process this data

    • Providing the Service: bookkeeping, payroll, forecasting calculations, CRM management, generation of quotes and invoices, statutory exports.
    • Security: audit trail, anomaly detection, authentication.
    • Legal compliance: Swiss accounting obligations (Art. 957–963 CO), VAT, archiving.
    • User support: responding to your requests, debugging where you explicitly authorize us to do so.
    • Billing: Stripe for subscription management (see §5).

    We never process your data for third-party marketing, resale, automated decision-making profiling or AI model training.


    4. OCR — Mistral, Mindee and OpenAI as processors

    Read carefully if you use the assisted Accounting module. When you upload a receipt or an invoice for automatic extraction, the content of the document is transmitted to one or more third-party processors, in the order described below (each tier is called upon only if the previous one fails or returns a low-confidence extraction).

    4.1 Mistral AI — primary OCR provider (since 2026-08-11)

    • Identity: Mistral AI SAS, France (EU)
    • Role: processor within the meaning of Art. 28 GDPR and Art. 9 revFADP
    • Data transmitted: the binary content of the document (PDF/JPG/PNG) that you upload via the "Upload a document" or "Expense report" feature
    • Purpose: extraction of structured fields (supplier, date, amounts excl./incl. VAT, VAT, currency, payment method)
    • API used: api.mistral.ai/v1/ocr (model mistral-ocr-latest)
    • Retention at Mistral: under their DPA, data submitted via the API is not used for model training; temporary retention for processing and abuse monitoring, then deletion. Check their policy: https://mistral.ai/terms/#privacy-policy
    • Server location: EU
    • Transfers outside the EU: none in the configuration used.

    4.2 Mindee — OCR fallback

    • Identity: Mindee SAS, France (EU)
    • Role: processor within the meaning of Art. 28 GDPR and Art. 9 revFADP
    • Data transmitted: the binary content of the document, only if the Mistral extraction fails or returns a confidence level below 60%
    • Purpose: extraction of the same structured fields
    • APIs used: mindee/expense_receipts/v5 and mindee/invoices/v4
    • Retention at Mindee: under their DPA, temporary retention for processing, then deletion. Check their policy: https://mindee.com/legal/privacy-policy
    • Server location: France / EU (EU hosting available)
    • Transfers outside the EU: none if the EU option is enabled. Otherwise, transfers to the USA governed by standard contractual clauses.

    4.3 OpenAI — last-resort OCR fallback (vision)

    • Identity: OpenAI, L.L.C., United States
    • Role: processor within the meaning of Art. 28 GDPR and Art. 9 revFADP
    • Data transmitted: the binary content of the document, only if neither Mistral nor Mindee produced a usable extraction (confidence < 60%)
    • Purpose: extraction of the same structured fields, model gpt-4o
    • Endpoint: api.openai.com (USA)
    • Retention at OpenAI: OpenAI states that it does not train its models on data submitted via the API (by default since March 2023). Maximum 30-day retention for abuse monitoring, then deletion.
    • Location: United States
    • Transfers outside the EU/CH: governed by the Standard Contractual Clauses (SCC). For Swiss users, the revFADP recognizes the SCC as appropriate safeguards.

    4.4 Your OCR-specific rights

    • Opting out: if you do not wish to use OCR, simply do not upload any documents. The Accounting module remains fully usable with manual entry.
    • Deletion: deleting an attachment in BMT triggers deletion of the file from our Storage. The temporary copy held by Mistral/Mindee/OpenAI follows their respective policies (deletion within 30 days at most).
    • No OpenAI fallback: if you wish to prohibit the transmission of your documents to OpenAI even where the Mistral/Mindee extraction is poor, let us know and we will disable the fallback for your project (accepting a loss of quality for atypical documents).

    4bis. Bexio migration and synchronization (processor)

    Read this if you enable the Bexio integration. The Bexio integration is optional but, if enabled, it involves bidirectional transfers of accounting data between BMT and Bexio AG.

    4bis.1 Bexio AG — processor

    • Identity: Bexio AG, Pulverstrasse 11, 3063 Ittigen, Switzerland
    • Role: processor within the meaning of Art. 9 revFADP and Art. 28 GDPR (equivalent)
    • Legal framework: Switzerland — EU → Switzerland adequacy decision in place (GDPR-compatible)

    4bis.2 Use cases and data concerned

    Initial OAuth connection: the Bexio access token is stored encrypted on the Supabase side (AES-GCM, scope limited to the accounting / contact / kb_offer / kb_bill / journal endpoints).

    Outbound synchronization BMT → Bexio (quotes, Shopify invoices, etc.):

    • Quotes and customer invoices that you create in BMT and choose to push to Bexio
    • Product lines, amounts, VAT, due dates
    • Associated contacts (customers) at the time of the push

    Outbound migration Bexio → BMT (Accounting module, opt-in):

    • Tier 1 (opening balances): pull of the chart of accounts + non-archived contacts + balances as at the cut-over date. Volume: ~200 accounts + ~500 contacts + 200 balances for a typical project.
    • Tier 2 (aggregated history): pull of monthly balances per account over 1 to 10 years, at your discretion. Volume: N accounts × M months.
    • Tier 3 (detailed entries): pull of all Bexio accounting entries over 1 to 10 years, at your discretion. Volume: potentially several thousand entries, with descriptions, accounts, amounts, dates.

    4bis.3 Direction of the data and purpose

    • Bexio → BMT pulls: the imported data becomes your data in BMT, subject to the 10-year retention period (Art. 958f CO). Bexio remains the historical source, but BMT becomes a copy of it.
    • BMT → Bexio pushes: the pushed data is stored at Bexio under your contract with Bexio, independently of BMT.
    • No third-party use: we do not consult your Bexio accounting data for any other purpose (statistics, recommendations, etc.). The migration pipeline is purely transitory.

    4bis.4 Rate limit and Bexio API plan

    To respect the Bexio API limits (free ~100 req/min, pro ~500 req/min), you declare your plan in BMT when launching each migration. This information is used solely to adjust throttling on the BMT side and is not transmitted to Bexio.

    4bis.5 Post-migration verification

    At the end of each Bexio → BMT migration, BMT automatically compares the imported balances with the Bexio balances (a control re-pull) to detect any discrepancies. This double read does not create an additional transfer: it involves the same data already imported.

    4bis.6 Retention at Bexio

    Bexio applies its own retention policy. See: https://bexio.com/fr-CH/dpa

    4bis.7 Disabling the integration

    You may revoke the Bexio connection at any time via Settings → Bexio → Disconnect. Disconnecting:

    • Deletes the encrypted OAuth token on our side
    • Does not erase the data already imported into BMT (that data has become yours)
    • Does not erase the data pushed into Bexio (your contract with Bexio governs that data)

    5. Other processors (sub-processors)

    Sub-processorRoleDataLocationSafeguards
    Supabase (Supabase Inc., USA)Database hosting, authentication, storage, edge functionsAll of your application dataZurich (Switzerland) — region eu-central-2 (until 2026-08-08: Frankfurt, EU)Supabase DPA + SCC
    Vercel (Vercel Inc., USA)Frontend hosting (CDN)No application data — front-end code onlyUSA + global edge CDNVercel DPA + SCC
    Google Cloud Run (Google LLC, USA)ClamAV antivirus scanning of accounting attachmentsBinary content of uploaded attachments (PDF, JPG, PNG ≤ 10 MB), scanned then deletedeurope-west6 (Zurich, CH)Google DPA + SCC
    Stripe (Stripe Payments Europe, IE)Subscription paymentsEmail, name, amount, payment methodEUStripe DPA + EU adequacy framework
    Mistral AI (Mistral AI SAS, FR)Accounting document OCR — primary provider (opt-in usage)Content of attachments uploaded in AccountingEUMistral DPA + GDPR
    Mindee (Mindee SAS, FR)Accounting document OCR — fallback (opt-in usage)Same (only if Mistral fails)EUMindee DPA + GDPR
    OpenAI (OpenAI L.L.C., USA)Vision OCR fallback — last resort (opt-in usage)Same (only if Mistral and then Mindee fail)USAOpenAI DPA + SCC
    Bexio (Bexio AG, CH)Third-party accounting — sync, migration, quote/invoice pushes (opt-in)Chart of accounts, contacts, balances, monthly balances, detailed accounting entries, quotes, invoices, product lines. See §4bis for details.SwitzerlandFADP (CH) + EU/CH adequacy framework
    Google (Gmail API)Reading project emails if you enable GmailGmail emails and attachmentsEU/USAOAuth + user consent
    Shopify (Shopify Inc., CA)E-commerce synchronizationOrders, products, inventoryCanada/USAOAuth + consent
    Meta / WhatsApp (Meta Platforms, IE)WhatsApp/Instagram CRM messagesMessages and conversation identifiersEU/USAOAuth + consent
    Resend (Resend Inc., USA)Transactional email delivery (notifications, invitations)Recipient email, content of the transactional messageUSAResend DPA + SCC
    Apple (Apple Inc., USA)Distribution of the iOS application via the App StoreNo application data — Apple processes your Apple account data under its own policy when you download the appUSAApple policy

    This list is kept up to date. For any material update, we will notify you by email at least 15 days before it takes effect.


    6. Retention periods

    DataRetention
    Active accountfor as long as your account exists
    Accounting data (entries, attachments, audit)10 years after the relevant financial year (Art. 958f CO)
    Payroll data10 years (accounting documents); certain AVS/LPP records according to the applicable statutory periods
    CRM datafor as long as your account exists + 30 days after deletion
    Technical logs30 days
    Audit IP addressesrolling 90 days
    CRM drafts never sent30 days, then deleted
    Auth sessions≤ 12 months
    Data after terminationfull export available on request for 30 days, then complete deletion

    7. Your rights

    Under the Swiss FADP/revFADP and, where applicable, the European GDPR, you have the following rights:

    • Access: obtain a copy of your data — "Export all data" button in Project settings.
    • Rectification: modify your data via the application or by email request.
    • Erasure ("right to be forgotten"): subject to statutory retention obligations (10 years for accounting). Account deletion available in Settings → Account (web and iOS application).
    • Restriction: request the suspension of a processing operation.
    • Portability: retrieve your data in a structured format (CSV, Excel, PDF — already available via the native exports).
    • Objection: object to processing based on legitimate interest.
    • Withdrawal of consent: at any time for processing based on consent (OAuth integrations, OCR).
    • Complaint: you may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or with the supervisory authority of your EU country of residence.

    To exercise these rights, send your request to privacy@bemytalent.com. Response time ≤ 30 days.


    8. Security

    • TLS 1.3 encryption in transit, at-rest encryption on Supabase Storage and Postgres.
    • Private attachment buckets — access only via short-lived signed URLs (15 minutes).
    • Hashed passwords (bcrypt via Supabase Auth).
    • OAuth tokens encrypted in the database with a server-side key.
    • Postgres RLS (Row-Level Security) enforced on all tables — a user can never read another project's data.
    • Full audit trail on sensitive accounting actions.
    • Strict MIME whitelist on uploads (PDF/JPG/PNG only, 10 MB max).
    • Antivirus scanning: every uploaded attachment is scanned (ClamAV on Google Cloud Run, Zurich). Download and preview remain blocked until the scan is complete, and permanently if the file is flagged as infected.

    9. Changes to this policy

    We may update this policy. Material changes (a new processor, a new processing purpose, more restrictive terms) will be communicated:

    • By email to your contact address ≥ 15 days before they take effect.
    • In-app via a persistent banner until accepted.

    The version in force and its change log are permanently published at https://www.bemytalent.com/en/privacy.


    10. Change log

    VersionDateChanges
    1.02026-05-12Initial creation. Documentation of the processors Supabase, Vercel, Stripe, Mindee, OpenAI, Bexio, Google, Shopify, Meta. Assisted Accounting module MVP1 + MVP2.
    1.12026-05-12MVP3 delivered: new §4bis detailing Bexio migration and synchronization (3 tiers, pull + push, automatic post-import verification). Added sub-processor Google Cloud Run (ClamAV worker for antivirus scanning of accounting attachments, hosted in europe-west6 Zurich). Bexio row in the §5 table expanded (explicit list of data: chart of accounts, contacts, balances, entries).
    1.22026-08-08Hosting migrated to Switzerland: Supabase application data (database, auth, storage, edge functions) is now hosted in Zurich (eu-central-2) instead of Frankfurt (EU). "Data hosted in Switzerland" notice at the top of the document; §5 table updated. No other change to processing.
    1.32026-08-15OCR: Mistral AI becomes the primary provider (§4.1, Mistral AI SAS, France/EU, api.mistral.ai/v1/ocr); Mindee becomes the fallback (§4.2) and OpenAI the last resort (§4.3). Chain effective since 2026-08-11. §5 table updated. No new type of data transmitted.
    1.42026-08-21Publication on the website (this page) and iOS mobile application: new §2.3 (camera/microphone/photo library on demand only, no advertising tracking, in-app account deletion). "Payroll data" category added to §2.1 with the "third-party data" note (you are the controller for your employees/clients). Sub-processors Resend (transactional emails) and Apple (App Store distribution) added to §5. §8: the obsolete "no antivirus scanning yet" statement replaced by the actual state (ClamAV scanning active, blocked until scanned).

    This policy is written in French. The French version prevails.