Privacy first -
Our privacy policy.

SAPIO GMBH

Effective Date: April 13, 2025

Last Updated: September 1, 2026

Privacy Policy SAPIO GmbH
SAPIO GmbH (“SAPIO”, “we”, “us” or “our”) provides digital credential infrastructure that enables organisations to create, issue, manage and verify digital credentials.We take a privacy-by-design approach and aim to process only the personal data necessary to provide, secure and improve our services.This Privacy Policy explains how personal data is processed when you visit our website, communicate with us, use the SAPIO platform, or interact with digital credentials through our services.

1. Who We Are

SAPIO GmbH
Ennermattstrasse 17
6314 Unterägeri
Switzerland

Email: info@sapio.id

SAPIO is subject to the Swiss Federal Act on Data Protection (“FADP”). Where applicable, we also process personal data in accordance with the EU General Data Protection Regulation (“GDPR”) and other applicable data protection legislation.

2. Our Role in Processing Personal Data

Our role depends on the context in which personal data is processed.

SAPIO as controller. SAPIO generally acts as controller when we process personal data for our own purposes, including: operating our website; managing SAPIO platform accounts and access; communicating with customers, prospects and partners; managing contractual and business relationships;maintaining the security and integrity of our services;meeting legal and regulatory obligations.

SAPIO as processor. When an organisation uses SAPIO to create, issue or manage credentials for its learners, employees, members or other recipients, that organisation generally determines the purposes and relevant content of the processing.In these circumstances, the organisation is generally the controller and SAPIO processes personal data on its behalf and in accordance with its instructions. If you have received a credential through an organisation using SAPIO and have questions concerning why your personal data is being processed or the content of your credential, you should normally contact the issuing organisation. SAPIO will support our customers in fulfilling their applicable data protection obligations.

3. Personal Data We Process

The personal data we process depends on how you interact with SAPIO.

Website and communications. When you visit our website or contact us, we may process:your email address;information you provide in your communications with us;business contact information;technical information generated when accessing our website, such as IP address, browser information and server or security logs.Information submitted through our website may be transmitted to our business communication systems so that we can respond to you.

SAPIO platform accounts. If you are authorised to use the SAPIO platform, we may process information such as:name;email address;organisation;account and access information;role and permissions;authentication-related information;security and technical information necessary to operate and protect the account.

Organisations. When organisations use SAPIO, we may process information relating to the organisation and its authorised representatives, including:organisation name and contact information;addresses;contact persons;logos and organisational information;account and service configuration;contractual and billing information.

Digital credentials. When SAPIO is used to issue or manage a digital credential, personal data may include:recipient name and email address;credential identifiers;education, training or achievement information;qualification, programme or course information;skills or competencies;award, issuance, validity or expiry information;information relating to the issuing organisation;credential status and lifecycle information;other attributes defined by the issuing organisation for the relevant credential.The exact data contained in a credential is determined by the relevant use case and, where SAPIO acts as processor, by the issuing organisation.Issuing organisations are responsible for ensuring that the personal data they provide to SAPIO is appropriate and lawful for the intended credential.

Technical and security data. We may process limited technical data necessary to operate and protect our services, including:IP addresses;timestamps;authentication and access information;system and security events;request and error information;diagnostic information.We aim to limit such processing to what is reasonably necessary for security, reliability, troubleshooting and the operation of our services.

4. How We Obtain Personal Data

Depending on the circumstances, personal data may be provided:directly by you;by an organisation using SAPIO;through an authorised platform user;through credential issuance processes, including manual entry or structured data imports;automatically when our website or services are accessed;through communications and contractual relationships with us.Where an organisation provides recipient data to SAPIO for credential issuance, the organisation is responsible for ensuring that it has an appropriate basis for doing so and for providing any information required under applicable law.

5. Why We Process Personal Data

We process personal data where necessary to:provide and operate SAPIO’s services;create, issue, deliver, manage and verify digital credentials;manage credential status, including revocation where applicable;authenticate users and manage access;maintain the security, availability and integrity of our services;communicate with customers, users and partners;respond to inquiries and support requests;administer contractual and commercial relationships;comply with applicable legal obligations;establish, exercise or defend legal claims.Where the GDPR applies and SAPIO acts as controller, processing may be based, as appropriate, on performance of a contract or steps taken prior to entering into a contract, compliance with legal obligations, our legitimate interests, or consent where consent is specifically required.Where SAPIO acts as processor, the relevant controller determines the applicable legal basis for processing.

6. Digital Credentials and Wallets

SAPIO is designed around interoperable digital credentials.Credentials may be delivered to compatible digital wallets selected or used by credential recipients. The use of a particular external wallet may be subject to the privacy terms and conditions of the wallet provider.SAPIO does not control independent third-party wallets merely because a SAPIO-issued credential can be stored or presented through them.The presentation of a credential to a verifier is initiated by the credential holder or through the relevant wallet and verification process.Depending on the verification method used, SAPIO services may be involved in facilitating or supporting verification. Independent compatible verification mechanisms may also be available.

7. Data Minimisation

SAPIO aims to minimise centralised processing of personal data and to process only information reasonably necessary for credential issuance, management, verification, security and related service functions.Credential-related information may be retained where necessary to provide credential lifecycle functionality, including issuance records, status management, revocation, support, auditability and security.We encourage issuing organisations to limit credential attributes to information necessary for the relevant purpose and not to include unnecessary or disproportionate personal data.

8. Service Providers and Recipients

We use selected service providers where necessary to operate SAPIO.These may include providers of:cloud hosting and infrastructure;digital credential infrastructure;business email and communications;website hosting;security, monitoring and technical services;professional, legal, accounting or administrative services.These providers may process personal data only to the extent required for the relevant services and subject to applicable contractual and data protection requirements.Where SAPIO acts as processor for a customer, subprocessors are governed by the applicable contractual arrangements with that customer.We may also disclose personal data where required by law, a competent authority or legal process, or where necessary to establish, exercise or defend legal claims.SAPIO does not sell personal data.

9. International Data Transfers

SAPIO is established in Switzerland and uses service providers in Switzerland, the European Economic Area and potentially other jurisdictions.Where personal data is transferred to a country that does not provide an adequate level of data protection under applicable law, we use appropriate safeguards where required. These may include recognised standard contractual clauses or other legally permitted transfer mechanisms.Further information concerning relevant international transfers and safeguards may be requested by contacting us at info@sapio.id.

10. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it is processed, taking into account contractual requirements, credential lifecycle requirements, security needs and applicable legal retention obligations.Retention periods therefore depend on the category and purpose of the data.Account and customer relationship information may be retained for the duration of the relevant relationship and subsequently where required for legal, contractual or legitimate business purposes.Credential-related information processed on behalf of an issuing organisation is retained in accordance with the applicable service arrangements, the instructions of that organisation and requirements necessary to provide credential lifecycle functionality.Temporary data used for processing or importing credentials is intended to be retained only for the time necessary to complete the relevant operation, subject to technical, security and backup requirements.Backups and security records may remain for limited additional periods where necessary to maintain system resilience, security or legal compliance.Personal data is deleted or anonymised when it is no longer required, subject to applicable legal and technical requirements.

11. Data Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, alteration, disclosure or destruction.Our security measures are selected according to the nature of the processing and associated risks and include controls relating to access management, authentication, data protection, infrastructure security and organisational security practices.No information system can provide absolute security. We therefore continuously assess and improve our security measures as our services and relevant risks evolve.

12. Cookies and Website Technologies

Our website may use cookies and similar technologies necessary for its operation and, where applicable, analytics or other optional functionality.Where consent is required by applicable law, optional technologies are activated in accordance with the choices made through our consent management mechanism.You can manage applicable choices through the cookie controls provided on our website.Further information is available in our Cookie Policy.

13. Your Data Protection Rights

Depending on the applicable law and circumstances, you may have rights concerning your personal data, including the right to:request information about personal data processed about you;obtain access to your personal data;request correction of inaccurate personal data;request deletion of personal data;object to or request restriction of certain processing;withdraw consent where processing is based on consent;receive certain personal data in a portable format where applicable.These rights may be subject to statutory conditions, exceptions and limitations.Where SAPIO acts as controller, requests can be submitted to: info@sapio.id Where SAPIO processes personal data solely on behalf of an issuing organisation, we may refer your request to that organisation or assist it in responding to your request.You may also have the right to contact or lodge a complaint with the competent data protection supervisory authority.In Switzerland, the competent federal authority is the Federal Data Protection and Information Commissioner (FDPIC).

14. Automated Individual Decisions

SAPIO does not currently use personal data to make automated individual decisions that produce legal effects or similarly significant effects concerning individuals on SAPIO’s own behalf.Automated technical processes used to assess cryptographic validity, credential integrity or credential status are used to support the technical operation and verification of digital credentials and do not, by themselves, constitute a substantive decision about an individual.If this changes, we will provide the information and safeguards required under applicable law.

15. Children’s and Minors’ Data

SAPIO provides infrastructure to organisations and does not intentionally offer consumer services specifically directed at children.An issuing organisation may use SAPIO in contexts involving minors. In such cases, the issuing organisation is responsible for determining whether the processing is lawful and for satisfying applicable transparency, consent or other requirements. SAPIO processes such data in accordance with the applicable contractual arrangements and instructions where it acts as processor.

16. Changes to This Privacy Policy

We may update this Privacy Policy when our services, processing activities or legal requirements change.The current version is published on our website together with the date of the latest update.Material changes may be communicated through additional appropriate means where required.

17. Contact

For questions concerning privacy or the processing of personal data by SAPIO, or to exercise applicable data protection rights, contact:

SAPIO GmbH
Ennermattstrasse 17
6314 Unterägeri
Switzerland

Email: info@sapio.id