Privacy Policy
Last updated: 10 September 2026
Who is responsible
Netgen Switzerland AG, Seestrasse 356, 8038 Zürich, Switzerland (UID CHE-178.296.873) is the controller for the personal data processed through Crew and this website. Contact: support@avidia.ai.
We are a Swiss company hosting in the European Union, so this policy is written to satisfy both the Swiss Federal Act on Data Protection (revFADP/revDSG) and the EU General Data Protection Regulation (GDPR).
What we do not do
We use no analytics, no tracking and no advertising cookies. There is no Google Analytics, no Matomo, Plausible, PostHog or Hotjar, and no advertising pixel of any kind. We do not profile visitors, and we do not sell or rent personal data.
Because we set only strictly necessary cookies, no consent banner is required.
One exception we want to name rather than gloss over: our interface font is currently loaded from Google Fonts, which means your browser contacts a Google server and Google sees your IP address when a page loads. No cookie is set and nothing is stored by us. We are moving to self-hosted fonts to remove this.
Cookies
Crew sets a session cookie when you sign in, so that you stay signed in between pages. It is strictly necessary for the service to work and is deleted when your session ends. Some interface preferences (for example your colour scheme or panel width) are stored locally in your browser and are never sent to us.
What we process, and why
- Account data — name, email address, password hash, role and preferences, so that you can sign in and use the product. Legal basis: performance of a contract (GDPR Art. 6(1)(b); revFADP Art. 31).
- Content you create — tasks, comments, notes, time entries, attachments and similar, which we store on your behalf so the service can function.
- Contact and beta requests — the fields you submit in our forms (company, name, email, phone, message, and for beta access your website, team size and reason), so that we can answer you. Legal basis: your consent and our legitimate interest in responding (GDPR Art. 6(1)(a)/(f)).
- Server logs — IP address, timestamp and requested resource, kept briefly for security and to diagnose faults. Legal basis: legitimate interest in operating a secure service (GDPR Art. 6(1)(f)).
Where your data is hosted
Crew runs on servers operated by Hetzner Online GmbH in Germany (Nuremberg), with file storage in Falkenstein, Germany. Your data therefore stays within the European Union by default. Swiss hosting and on-premise installations are available on request.
Processors we use
| Processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and file storage | Germany (EU) |
| Resend | Sending transactional email | EU / USA |
| Anthropic PBC | AI assistance features, when you use them | USA |
Where a processor is outside Switzerland or the EEA — Anthropic in particular — the transfer is covered by the EU Standard Contractual Clauses together with the Swiss addendum. Content is sent to Anthropic only when you actively use an AI feature; it is not used to train their models.
If you connect Crew to a third-party system — for example Jira, Slack, GitHub, Microsoft Entra or Tempo — data is exchanged with that system at your instruction, and that provider’s own privacy terms apply to it.
How long we keep it
Account data and the content you create are kept for as long as your account exists, and are deleted on request or after termination, subject to any statutory retention we are required to observe. Contact and beta enquiries are kept for as long as needed to deal with them and for our records afterwards. Server logs are kept briefly and then rotated.
Your rights
You have the right to access your personal data, to have it corrected or deleted, to restrict or object to its processing, and to receive it in a portable form. Where processing rests on consent, you may withdraw that consent at any time, without affecting what was lawful beforehand.
Write to support@avidia.ai and we will respond. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), or with your local supervisory authority in the EU.
Security
Traffic is encrypted in transit with TLS, passwords are stored only as salted hashes, and access to production systems is restricted and logged. No system is perfectly secure, but we take appropriate technical and organisational measures to protect your data.
Changes
We may update this policy as the product changes. The date at the top of this page always shows when it was last revised.