
Version 2026-08-13
Privacy Policy
Effective date: 14 August 2026
1. Controller and contact
Swiss Rotor Services AG ("SRS", "we", "us") is responsible for personal data processed through MySRS.
Swiss Rotor Services AG<br>
Winterhaldenstrasse 14 A<br>
CH-3627 Heimberg<br>
Switzerland<br>
Company identification number: CHE-227.898.128<br>
Telephone: +41 33 657 70 00<br>
Email: info@swissrotorservices.com
For privacy requests or suspected security incidents, email us with the subject “MySRS privacy request” or “MySRS
security incident”, as appropriate.
2. Scope and personal data
MySRS is a closed portal for approved business customers. Depending on the functions you use, we process:
- business and account data, such as your name, business email, telephone number, company, business address, company
or VAT number, access request, account status, role, permissions and acceptance of portal terms;
- login, security and audit data, such as password hashes, session and authentication data, IP address, browser or
device information, login and reset events, and records of relevant actions in the portal;
- shared documents and document activity, including files, filenames, revisions, form entries, comments, tasks,
authorship and timestamps;
- if the shop is used, order, billing, delivery and recipient data, products, quantities, prices, currency, tax and
fee information, invoice and shipping details, payment method, payment references and payment status;
- transactional emails, support messages and information needed to investigate security or privacy incidents.
Please provide only data and documents that are necessary for the approved business purpose and that you are
authorised to share.
3. Why we use personal data
We use personal data to:
- review access requests and manage personal B2B accounts and permissions;
- make authorised working documents available and support document collaboration;
- process enquiries and, where used, review and fulfil spare-parts orders, invoices, payments and deliveries;
- send account, document, order, payment, security and service messages;
- protect, operate, troubleshoot, back up and restore MySRS;
- carry out required customer, payment, shipping, export, end-use or legal checks; and
- meet applicable record-keeping duties, handle requests, establish or defend claims, and manage incidents.
These activities support our business and contractual relationships, legitimate operational and security interests,
and applicable legal duties. We rely on consent where the applicable law requires it. Customer admission and product
access are reviewed by SRS. After a binding order, SRS also performs manual availability, delivery, export, end-use
and other execution checks; these checks are not solely automated.
4. Who receives personal data
Within MySRS, access is limited to authorised SRS personnel and authorised users of the relevant customer. We use the
following main service providers for the portal:
- **Hetzner Cloud** hosts the MySRS application, database and operational logs in Falkenstein, Germany (production
availability zone `fsn1-dc8`, verified for this release on 14 August 2026).
- **Cloudflare R2**, configured with EU jurisdiction for the relevant buckets, stores private portal document copies
and encrypted MySRS backups.
- **Resend** delivers transactional email. It receives the recipient address and message content, but MySRS does not
send portal files as email attachments. Provider account data, email metadata and logs may be processed in the
United States, and delivery also involves the recipient's mail provider.
- **Stripe** is used only if SRS enables hosted card payment. Stripe then receives the data needed for checkout and
payment, such as email, order reference, line-item description, amount, fees, tax and currency. MySRS does not
receive or store the full card number or card security code. Stripe and payment participants process data under
their own regulatory, security and privacy obligations.
Where necessary for a specific order or legal duty, SRS may also share the minimum required data with banks,
accounting providers, carriers, freight forwarders, customs brokers, insurers, professional advisers or authorities.
Selected final records may be transferred manually to SRS's existing business, quality or accounting systems outside
MySRS. SRS does not sell personal data through MySRS.
5. International disclosures
SRS is based in Switzerland, while customers, email recipients, payment participants, providers and shipping
recipients may be in other countries. The disclosures described above may therefore involve Germany, the European
Union, the United States and the country connected with a customer or order.
Where the destination does not provide an adequate level of data protection recognised under Swiss law, SRS uses an
applicable safeguard, such as recognised standard contractual clauses with the necessary Swiss adaptations, and
assesses whether additional measures are required. A legal exception is used only where the applicable law permits
it.
6. Retention and official records
We keep personal data only for as long as needed for the relevant account, document, order, security, support,
contractual or legal purpose. We then delete, anonymise or restrict it, subject to required record retention, open
claims, incident evidence and the limited period needed for backup and recovery cycles. The relevant purpose and
applicable duty determine the period; MySRS does not claim one fixed deletion period for all records.
MySRS is a working and exchange platform. It is not the sole official aviation, quality, accounting or statutory
archive. Binding originals and records that SRS must retain are kept in the existing SRS systems and processes
outside MySRS. Portal working copies do not replace those records.
7. Security, cookies and local storage
SRS uses access controls, encrypted connections, password hashing, private file storage, security logging, backups
and other organisational and technical measures appropriate to the portal. No system is completely secure. Users
must protect their personal credentials and devices and promptly report suspected misuse.
MySRS uses only technically necessary first-party session and authentication cookies. It also stores the user's
essential-only cookie preference in browser local storage. The reviewed portal code contains no analytics,
advertising or marketing trackers. This statement must be checked again if the code or deployed configuration
changes.
8. Your rights
Subject to applicable law, you may ask whether SRS processes personal data about you and request access, correction
or deletion. Depending on the law that applies, you may also request restriction or portability, object to certain
processing, or withdraw consent for the future. SRS may verify your identity and may retain or restrict data where a
contract, legal duty, security need, legal claim or another lawful reason requires it.
Send requests to info@swissrotorservices.com with the subject “MySRS privacy request”. You may also contact the Swiss
Federal Data Protection and Information Commissioner (FDPIC/EDÖB) and, where another data protection law applies,
the competent supervisory authority.
9. Security and privacy incidents
SRS assesses suspected incidents without undue delay. If a personal data breach is likely to result in a high risk
to affected persons, SRS will notify the FDPIC as quickly as possible. SRS will inform affected persons where this is
required or necessary for their protection. Any additional notification duty under an applicable foreign law is
assessed separately.
10. Changes
SRS may update this policy when the portal, providers or legal requirements change. MySRS records the accepted policy
version. Where SRS requires acceptance of a new version, the relevant portal areas remain restricted until the new
version is accepted.