Legal
Privacy Notice
Last updated: 5 June 2026 · Deutsche Version
This notice explains how Neatly Zürich ("we", "us") processes personal data in connection with our cleaning services and this website. It applies to clients, prospective clients, employees, suppliers and visitors. We comply with the Swiss Federal Act on Data Protection (FADP / nFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Controller and contact
Neatly Zürich, Hofstrasse 62b, Zürich, Switzerland.
Email: contact@neatlyzurich.ch · Phone: +41 78 340 63 62
For privacy questions or to exercise your rights, write to contact@neatlyzurich.ch with the subject "Privacy".
2. What data we collect
2.1 Clients and leads
Name, email, phone, postal address, the service you request, message content, locale, preferred date, and any access notes you share.
2.2 Bookings and addresses
Service date, location, scope and recurrence, and any special instructions you provide.
2.3 Keys and access codes
Where you entrust us with keys, key tags, alarm or door codes for the duration of our engagement.
2.4 Employee data
For our staff: identity and contact details, work permit / AHV number, bank details, salary, time sheets and references — collected and processed for HR, payroll and legal compliance.
2.5 Photos
Before/after photos of cleaned areas and, where relevant, photos documenting pre-existing conditions or damage.
2.6 Complaints and damage reports
Descriptions, correspondence, photographs and insurance claim references in connection with any incident.
2.7 Payment and invoice data
Invoice details, amounts, IBAN, payment references and VAT data.
2.8 Website data
Technical data your browser sends automatically (IP address, user agent, time of access) is processed by our hosting provider for security and stability. We do not currently use third-party analytics or advertising cookies.
3. Why we process data and on what legal basis
We process data to respond to enquiries, prepare quotes, deliver our cleaning services, manage staff, comply with accounting and tax law, handle complaints and insurance matters, and keep our website secure. The legal bases are: performance of a contract (or steps prior to entering a contract), compliance with a legal obligation (e.g. accounting, payroll, tax), our legitimate interests (service quality, security, dispute defence), and your consent where required.
4. Who receives your data
We share data only with parties who need it to deliver the service or where required by law:
- Our trained cleaners (only the address and access information needed for their assignment).
- Hosting and database provider: Lovable Cloud (Supabase, EU — Frankfurt).
- Liability insurer and legal counsel in case of a claim or dispute.
- Public authorities (tax office, AHV/SUVA, courts) where required by law.
5. International transfers
Personal data is primarily processed in Switzerland and the EU. Any limited transfers outside this area take place on the basis of the European Commission Standard Contractual Clauses and the FDPIC recognised safeguards.
6. Retention
- Quote leads without a contract: up to 3 years from last contact.
- Client booking and service records, invoices and payment data: 10 years (Swiss Code of Obligations Art. 958f).
- Employee records: 10 years after the end of employment.
- Before/after photos without incident: up to 2 years.
- Complaint and damage files: 10 years (legal limitation period).
- Keys and access codes: until the end of the engagement plus 30 days.
- Server / security logs: 90 days.
7. Your rights
Under the FADP and the GDPR you may request access to your data, correction of inaccurate data, deletion, restriction of processing, and (where applicable) data portability. You may object to processing based on our legitimate interests and withdraw any consent at any time. Contact contact@neatlyzurich.ch — we respond within 30 days.
You can also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) or, if you are in the EU/EEA, your local supervisory authority.
8. Security
We use TLS encryption in transit, encrypted database storage, row-level access controls, multi-factor authentication for admin accounts, and the principle of least privilege for staff and processors.
9. Children
Our services are not directed to children and we do not knowingly collect data from minors.
10. Changes to this notice
We may update this notice as our services or legal requirements evolve. The "Last updated" date above reflects the latest version. Material changes will be communicated by email or via a notice on this page.