Privacy Policy

Version 1.0 · July 2026

This is a translation of the German original. In the event of any discrepancy, the German version at https://pype.ch/datenschutz prevails.

Privacy at a glance

Controller

Pype – a brand of SOTA Cooperations GmbH

What data we process

Depending on how you use our platform, we process in particular the following personal data:

  • first and last name
  • email address
  • user account
  • company details
  • billing information
  • login information
  • IP address
  • browser and device data
  • usage data
  • uploaded files
  • images
  • videos
  • documents
  • social media schedules
  • comments
  • share links
  • workspace information
  • payment information (never full credit card details)

What we use your data for

We process personal data in particular in order to:

  • provide the platform
  • manage your user account
  • authenticate you
  • schedule and publish social media posts
  • manage workspaces
  • provide share links
  • store and manage media
  • process payments
  • issue invoices
  • diagnose errors
  • maintain system security
  • prevent fraud
  • support our customers
  • develop our platform further
  • meet our legal obligations

Social media integrations

When you connect your social media accounts to Pype, we process only those permissions and access tokens that the respective function requires.

Pype supports integrations with, in particular:

  • Meta (Facebook and Instagram)
  • LinkedIn
  • TikTok
  • YouTube
  • Google Business Profile

Use of these integrations is additionally subject to the privacy policies and terms of service of the respective platforms.

Payment processing

For paid services, Pype works with external payment service providers.

These may include in particular:

  • Stripe
  • TWINT
  • credit card providers
  • banks

As a rule, Pype does not store full credit card details.

Hosting and infrastructure

We use professional cloud and hosting providers to operate our platform.

These may include in particular:

  • Google Cloud / Firebase
  • Cloudflare
  • further hosting or cloud providers

These providers process personal data solely within the scope of their respective tasks.

Cookies

Pype uses strictly necessary cookies, which are required to operate the platform.

Depending on the features in use, analytics or security cookies may also be used.

Marketing or tracking cookies are used only where there is a legal basis for doing so or where consent has been given.

Retention

As a rule, we store personal data only for as long as

  • your user account exists,
  • it is necessary to perform the contract,
  • statutory retention obligations apply,
  • or legitimate interests require it.

Once the respective purposes cease to apply, personal data is deleted or anonymised.

Your rights

You have, in particular, the right to:

  • information
  • rectification
  • erasure
  • restriction of processing
  • data portability
  • withdrawal of consent
  • objection to certain processing
  • lodge a complaint with the competent data protection authority

Data security

Pype applies appropriate technical and organisational security measures to protect personal data against loss, misuse and unauthorised access.

These include, among others:

  • TLS/SSL encryption
  • secure password storage
  • role-based permissions
  • firewalls
  • monitoring
  • backup systems
  • security updates
  • access controls

Despite extensive security measures, complete security of electronic data transmission or storage cannot be guaranteed.

Contact

For questions about data protection or to exercise your rights, you can reach us at:

Pype – a brand of SOTA Cooperations GmbH

1. Preamble

Protecting your privacy and your personal data is of central importance to Pype. We handle all personal data responsibly, confidentially and in accordance with the applicable data protection legislation.

This privacy policy tells you transparently

  • which personal data we process,
  • why we process it,
  • how long we store it,
  • to whom data may be disclosed,
  • what rights you have,
  • what security measures we take.

This privacy policy applies to all services, products and digital offerings of Pype.

2. Controller

The controller for all data processing within the meaning of the Swiss Federal Act on Data Protection (FADP) and, where applicable, the General Data Protection Regulation (GDPR) is:

3. Scope

This privacy policy applies in particular to:

  • visitors to our website
  • registered users
  • administrators
  • workspace owners
  • invited team members
  • recipients of share links
  • newsletter subscribers
  • applicants
  • business partners
  • suppliers
  • support enquiries

as well as all persons who use our services in any form.

4. Applicable data protection law

Pype processes personal data on the basis of, in particular,

  • the Swiss Federal Act on Data Protection (FADP),
  • the General Data Protection Regulation (GDPR), where applicable,
  • further applicable national data protection provisions.

Processing takes place exclusively within these legal bases.

5. Definitions

For the purposes of this privacy policy, the following terms apply in particular:

Personal data

Any information relating to an identified or identifiable natural person.

Processing

Any handling of personal data. This includes in particular

  • collecting
  • storing
  • altering
  • using
  • transmitting
  • disclosing
  • archiving
  • deleting
  • destroying

Data subject

Any natural person whose personal data is processed.

Workspace

An organisational area within Pype in which users can jointly manage, schedule or edit content.

Share link

A link generated by Pype through which authorised persons can view or download files or content without a user account of their own.

6. Which personal data we process

Depending on how you use our services, we process in particular the following categories of personal data.

6.1 Master data

When you register for or use our platform, the following master data may be processed in particular:

  • first name
  • last name
  • company
  • position
  • billing address
  • country
  • language
  • email address
  • telephone number
  • VAT/UID number
  • profile picture

6.2 Account data

To operate our platform we process in particular

  • username
  • encrypted password
  • workspace
  • user role
  • permissions
  • login history
  • security information
  • two-factor authentication (if enabled)
  • language settings
  • time zone

Passwords are stored in encrypted form only.

Pype has no access to your original password.

6.3 Contract data

In connection with paid services we process in particular

  • subscriptions taken out
  • contract terms
  • invoices
  • payment status
  • payment references
  • reminders
  • cancellations
  • support cases

6.4 Payment data

Depending on the payment method chosen, the following data may be processed:

  • payment method
  • payment status
  • invoice number
  • billing address
  • VAT information
  • transaction ID

As a rule, credit card details are not stored by Pype but processed exclusively by certified payment service providers.

6.5 Usage data

While you use our platform, the following information in particular may be collected automatically:

  • IP address
  • browser type
  • browser version
  • operating system
  • device type
  • screen resolution
  • language settings
  • time zone
  • date
  • time
  • session ID
  • click paths
  • error logs
  • log files
  • performance information

This data serves in particular the stability and security of our platform.

6.6 Content data

Depending on use, we process in particular the following content:

  • images
  • videos
  • documents
  • texts
  • social media posts
  • comments
  • versions
  • file names
  • shares
  • calendar information
  • metadata

As a rule this content remains the property of the respective customer.

Pype processes it solely in order to provide the platform technically.

6.7 Communication data

When you contact us we process in particular

  • name
  • email address
  • telephone number
  • content of the enquiry
  • support tickets
  • chat messages
  • attachments
  • correspondence
  • time of the communication

6.8 Device data

To improve security, the following may additionally be processed:

  • device identifier
  • browser fingerprints
  • login devices
  • operating system version used
  • app version used
  • security information

7. Origin of the data

As a rule, personal data comes from the following sources:

  • directly from you
  • from your use of the platform
  • from users you have invited
  • from connected workspaces
  • from payment service providers
  • from integrations with third-party platforms
  • from cookies
  • from log files
  • from support enquiries

As a rule, Pype does not collect personal data from publicly accessible sources unless this is permitted by law or necessary to perform the contract.

8. Purposes of processing

We process personal data in particular for the following purposes:

  • providing the platform
  • registering user accounts
  • authentication
  • managing workspaces
  • storing media
  • scheduling social media content
  • creating share links
  • collaboration within teams
  • synchronisation with third-party platforms
  • performing the contract
  • invoicing
  • payment processing
  • support
  • error analysis
  • security
  • detecting misuse
  • developing our platform further
  • meeting legal obligations
  • communicating with our customers
  • sending newsletters (where permitted)
  • statistical analysis
  • improving usability

9. Principles of processing

Pype undertakes to process personal data in accordance with the following principles:

  • lawfulness
  • transparency
  • proportionality
  • purpose limitation
  • data minimisation
  • accuracy
  • integrity
  • confidentiality
  • storage limitation
  • security

Personal data is processed only to the extent necessary for the respective purpose.

10. Cookies and similar technologies

10.1 General

Pype uses cookies and comparable technologies (e.g. local storage, session storage, pixels or similar) to ensure the functionality of the platform, improve usability, provide security features and carry out statistical analysis.

Cookies are small text files stored on your device that allow your browser to be recognised.

10.2 Strictly necessary cookies

Certain cookies are strictly required to operate the platform. These include in particular cookies for

  • signing in to the user account
  • session management
  • security
  • two-factor authentication
  • language settings
  • user preferences
  • workspace assignment
  • load balancing
  • protection against misuse
  • protection against automated attacks

These cookies cannot be disabled if the platform is to be used.

10.3 Analytics cookies

Where enabled, Pype uses analytics cookies to improve the platform. These serve in particular to analyse

  • page views
  • use of individual features
  • errors
  • loading times
  • usability
  • performance
  • crashes
  • anonymised usage statistics

Analytics cookies are used only where this is permitted by law or where consent has been given.

10.4 Marketing cookies

Where marketing or remarketing features are used, cookies may be used in order to

  • measure advertising campaigns,
  • optimise ads,
  • build audiences,
  • carry out conversion measurement.

Marketing cookies are used only where the required consent has been given or another legal basis exists.

10.5 Browser settings

You can restrict or delete cookies at any time in your browser settings.

Disabling strictly necessary cookies may mean that individual functions of the platform cannot be used, or only to a limited extent.

11. Log files

When our platform is accessed, technical information is processed automatically. This includes in particular

  • IP address
  • browser
  • operating system
  • device type
  • language
  • date
  • time
  • referrer
  • URL
  • error messages
  • loading times
  • server responses

This data serves exclusively

  • system security,
  • error analysis,
  • stability,
  • detection of misuse,
  • technical administration.

As a rule, it is not combined with other personal data unless this is necessary to investigate misuse.

12. Hosting and cloud infrastructure

Pype uses external hosting and cloud providers to operate the platform. These handle in particular

  • server operation
  • data storage
  • backups
  • load balancing
  • content delivery networks (CDN)
  • databases
  • security monitoring

Pype selects these providers carefully and obliges them to comply with appropriate data protection and security standards.

13. Payment service providers

For paid services, Pype may use external payment service providers. These include in particular

  • Stripe
  • TWINT
  • credit card providers
  • banks
  • further payment providers

Personal data is processed in accordance with the privacy policy of the respective payment service provider.

As a rule, Pype does not receive full credit card details.

14. Integrations with third-party platforms

Pype allows you to connect various external platforms. These may include in particular:

  • Meta
  • Facebook
  • Instagram
  • LinkedIn
  • TikTok
  • Pinterest
  • YouTube
  • Google Business Profile
  • Google Drive
  • Dropbox
  • Microsoft OneDrive
  • further future integrations

Where such integrations are used, only the data required to provide the respective function is processed.

Data processing within the respective third-party platform is governed exclusively by that platform's privacy policy.

Pype accepts no responsibility for data processing by these third parties.

Use of the YouTube API Services

If you connect a YouTube channel in Pype, Pype uses the YouTube API Services to do so. By connecting, you agree to the YouTube Terms of Service: https://www.youtube.com/t/terms

Data that Pype obtains through the YouTube API Services is additionally subject to the Google Privacy Policy: https://policies.google.com/privacy

Through the YouTube API Services, Pype processes only:

  • the channel ID and channel name of the channel you connected;
  • the access and refresh tokens (OAuth) for that channel;
  • view counts and comments on videos you published through Pype.

View counts and comments are retrieved from YouTube only at the moment they are displayed and are not stored by Pype.

Processing serves the sole purpose of uploading videos you created to your channel at the scheduled time and showing you the public response to them inside Pype. No further use takes place.

Access tokens are stored for as long as the channel remains connected. If you disconnect it, Pype revokes the token with Google immediately and deletes it.

You can revoke access at any time. Within Pype this is done under Settings › Connections, which causes Pype to revoke the token with Google immediately. Alternatively, you can withdraw access directly in your Google account security settings: https://security.google.com/settings/security/permissions

15. Share links

Pype allows share links to be created. Authorised persons can retrieve files or content through such links.

The respective workspace owner is responsible for

  • whom share links are sent to,
  • which content is shared,
  • whether passwords are used,
  • whether expiry dates are set.

Pype expressly recommends making confidential content available only through password-protected share links.

16. Processors

To provide our services we engage carefully selected processors. These may provide services in particular in the areas of

  • hosting
  • cloud computing
  • payment processing
  • email delivery
  • analytics
  • monitoring
  • error analysis
  • customer support
  • data backup
  • content delivery networks
  • security
  • AI services (if used in future)

Processors receive only the data they need to perform their respective tasks.

They are contractually obliged to comply with the applicable data protection provisions.

17. Transfers abroad

In the course of using our services, personal data may also be transferred to countries outside Switzerland or the European Economic Area.

Such a transfer takes place only if

  • an adequate level of data protection exists,
  • suitable contractual safeguards (e.g. standard contractual clauses) have been concluded,
  • a statutory exception applies,
  • or the data subject has expressly consented.

Pype takes appropriate measures to ensure an adequate level of data protection for international transfers as well.

18. Data security

Pype applies appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction. These include in particular

  • encrypted data transmission (TLS/SSL),
  • encrypted password storage,
  • role-based access permissions,
  • logging of security-relevant events,
  • firewalls,
  • monitoring,
  • intrusion detection,
  • regular security updates,
  • backups,
  • access restrictions,
  • security reviews.

Despite extensive security measures, complete security of electronic data transmission or storage cannot be guaranteed.

19. Retention

19.1 Principle

Pype processes and stores personal data only for as long as this is necessary to fulfil the respective purposes or as long as statutory retention obligations apply.

The specific retention period depends in particular on

  • the duration of the business relationship;
  • statutory retention obligations;
  • legitimate interests of Pype;
  • pending court or administrative proceedings;
  • technical requirements;
  • security interests.

19.2 User accounts

As a rule, the personal data of a user account is stored for as long as the account exists.

After the contractual relationship ends, Pype may continue to store personal data for a reasonable period where this is necessary in particular to

  • meet legal obligations;
  • assert, exercise or defend legal claims;
  • prevent fraud;
  • ensure IT security.

Personal data is then deleted or anonymised, unless statutory retention obligations prevent this.

19.3 Invoicing and accounting data

Data that must be retained under commercial, tax or accounting law is stored for the period prescribed by law.

19.4 Log files

As a rule, technical log files are stored only for as long as this is necessary for the secure operation of the platform.

They are then deleted or anonymised.

19.5 Backups

For technical reasons, backups may persist for a limited period.

As a rule, individual personal data is restored from backups only to ensure system integrity or as part of a technical recovery process.

20. Rights of data subjects

Where the statutory requirements are met, you have in particular the following rights.

20.1 Information

You may request information at any time about

  • whether personal data is being processed;
  • which data is being processed;
  • for what purposes it is being processed;
  • to whom data is disclosed;
  • how long data is stored.

20.2 Rectification

You may request the rectification of inaccurate or incomplete personal data.

20.3 Erasure

You may request the erasure of personal data where

  • no statutory retention obligation applies;
  • no legitimate interests conflict with it;
  • no pending proceedings require further storage.

20.4 Restriction of processing

Subject to the statutory requirements, you may request that the processing of personal data be restricted.

20.5 Data portability

Where provided for by law, you may request to receive personal data in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.

20.6 Withdrawal of consent

Consent given may be withdrawn at any time with effect for the future.

Withdrawal does not affect the lawfulness of processing carried out up to that point.

20.7 Objection

Where provided for by law, you may object to the processing of personal data.

20.8 Right to lodge a complaint

You have the right to lodge a complaint with the competent data protection authority if you believe that the processing of your personal data infringes applicable data protection law.

In Switzerland this is, in particular, the Federal Data Protection and Information Commissioner (FDPIC).

21. Automated decisions

As a rule, Pype does not take decisions based solely on automated processing that produce legal effects concerning data subjects.

Should such features be introduced in future, data subjects will be informed separately where this is required by law.

22. Minors

Pype's services are generally directed at adults or businesses.

Persons under the age of 18 may use our services only with the consent of their legal guardian.

Pype does not knowingly collect personal data from children unless there is a legal basis for doing so.

23. Changes to this privacy policy

Pype reserves the right to amend this privacy policy at any time. Changes may become necessary in particular because of

  • new statutory provisions;
  • regulatory requirements;
  • technical developments;
  • new platform features;
  • new integrations;
  • changes to our services.

The current version published on pype.ch applies in each case.

Registered users will be informed in an appropriate manner of any material changes.

24. Contact

If you have questions about data protection or wish to exercise your rights, you can contact us at any time.

Privacy Policy — pype · pype