Transparency before transmission

Privacy notice

This notice explains which data the current Assistenzdienst compass processes and when data leaves your device.

Last updated: 31 July 2026

Controller

DASTI AG, Sihleggstrasse 23, CH-8832 Wollerau, Switzerland · UID CHE-157.444.808 · CH-ID CHE-020.4.067.365-7 · info@dasti.ch · +41 56 555 03 55

Use without registration

The main page, compass and calculator can be used without a name, address, diagnosis or insurance number. Answers initially remain in browser memory. Accessibility preferences are stored locally under the key “dasti-accessibility-v1” and can be reset at any time.

Signed verification record

Only when you initiate signing are selected answer categories and calculation parameters sent to the server. The technical IP address is processed temporarily to limit abuse. The server recalculates the result and creates a signed token containing the report ID, rule version, timestamp, expiry date and result fingerprint.

The token contains no names, diagnoses, addresses or insurance numbers. Verification confirms the token signature; it does not confirm the integrity of an arbitrary PDF file.

Purpose, recipients and retention

Processing is limited to the requested guidance, technical verification, security and abuse prevention. Nothing is automatically sent to care providers, insurers, authorities or partners.

The site is hosted through ChatGPT Sites. For people in Switzerland, OpenAI Ireland Ltd. acts as processor for Hosted Data generated through the published site. This may include log, usage and device data and, after consent, statistical data. Under the ChatGPT Sites DPA, transfers outside Switzerland or the EEA rely on Standard Contractual Clauses or an adequacy decision.

The application stores neither compass answers nor report tokens in a case database. Statistics queries are limited to the current UTC day and the preceding 89 days. On every new statistics event and cockpit read, older rows are deleted deterministically. With no statistics activity at all, no independent scheduler currently runs; this limitation is disclosed instead of promising an unproven delayed deletion. Technical Hosted Data remain subject to the DPA and legal retention duties.

Open the ChatGPT Sites Data Processing Addendum ↗

Cookies and anonymous statistics

The website uses no advertising or third-party trackers. Necessary functions remain available without consent. Only if you allow anonymous statistics does DASTI count the event, day, language and page path. To measure the journey from page view to compass, report and contact, the browser also creates a random session ID. It is processed server-side with a secret hash separated by day; it contains no contact details and does not link visits across different days. Names, compass answers, health data, full IP addresses and advertising profiles are not stored.

Consent is stored under “dasti-analytics-consent-v1” and the random ID only for the current browser session. The choice can be changed at any time. Rows outside the rolling 90-day window are removed on every new event and cockpit read. Global Privacy Control is respected.

External contact routes chosen voluntarily

Only appointment booking voluntarily opens a Microsoft service. You leave this website only when you open that link; Microsoft and DASTI may then process the details entered there and technical usage data. The page displays DASTI’s shared provider name “BERATUNGSDIENST DASTI AG”. General feedback uses Assistenzdienst email directly.

Do not enter health, identity or confidential case data in the booking. For documents or incidents, first request a confirmed confidential route. The previous external feedback and incident forms are not offered until their owners and privacy notices are reliably confirmed.

Your rights

You may request access, correction, deletion or restriction and object to unnecessary processing. Contact DASTI AG using the details above. Statutory retention obligations remain reserved.

Privacy by design and risk screening

DASTI applies data minimisation, server-side validation, signed records, short abuse-control windows and restrictive security headers. The documented screening of the current version did not identify a likely high risk because there is no persistent case database, automated benefit decision or automatic partner transfer.

Before any expansion involving persistent health data, partner access, profiling or automated decisions, the screening will be repeated and a data protection impact assessment completed before launch where a high risk is likely.

Back to the Assistenzdienst compass
Cookie Consent mit Real Cookie Banner