Swiss Rotor Services
MySRSCustomer Portal
Close

Version 2026-08-13

Privacy Policy

Effective date: 14 August 2026

1. Controller and contact

Swiss Rotor Services AG ("SRS", "we", "us") is responsible for personal data processed through MySRS.

Swiss Rotor Services AG<br>
Winterhaldenstrasse 14 A<br>

CH-3627 Heimberg<br>

Switzerland<br>

Company identification number: CHE-227.898.128<br>

Telephone: +41 33 657 70 00<br>

Email: info@swissrotorservices.com

For privacy requests or suspected security incidents, email us with the subject “MySRS privacy request” or “MySRS
security incident”, as appropriate.

2. Scope and personal data

MySRS is a closed portal for approved business customers. Depending on the functions you use, we process:

- business and account data, such as your name, business email, telephone number, company, business address, company
or VAT number, access request, account status, role, permissions and acceptance of portal terms;

- login, security and audit data, such as password hashes, session and authentication data, IP address, browser or

device information, login and reset events, and records of relevant actions in the portal;

- shared documents and document activity, including files, filenames, revisions, form entries, comments, tasks,

authorship and timestamps;

- if the shop is used, order, billing, delivery and recipient data, products, quantities, prices, currency, tax and

fee information, invoice and shipping details, payment method, payment references and payment status;

- transactional emails, support messages and information needed to investigate security or privacy incidents.

Please provide only data and documents that are necessary for the approved business purpose and that you are
authorised to share.

3. Why we use personal data

We use personal data to:

- review access requests and manage personal B2B accounts and permissions;
- make authorised working documents available and support document collaboration;

- process enquiries and, where used, review and fulfil spare-parts orders, invoices, payments and deliveries;

- send account, document, order, payment, security and service messages;

- protect, operate, troubleshoot, back up and restore MySRS;

- carry out required customer, payment, shipping, export, end-use or legal checks; and

- meet applicable record-keeping duties, handle requests, establish or defend claims, and manage incidents.

These activities support our business and contractual relationships, legitimate operational and security interests,
and applicable legal duties. We rely on consent where the applicable law requires it. Customer admission and product

access are reviewed by SRS. After a binding order, SRS also performs manual availability, delivery, export, end-use

and other execution checks; these checks are not solely automated.

4. Who receives personal data

Within MySRS, access is limited to authorised SRS personnel and authorised users of the relevant customer. We use the
following main service providers for the portal:

- **Hetzner Cloud** hosts the MySRS application, database and operational logs in Falkenstein, Germany (production
availability zone `fsn1-dc8`, verified for this release on 14 August 2026).

- **Cloudflare R2**, configured with EU jurisdiction for the relevant buckets, stores private portal document copies

and encrypted MySRS backups.

- **Resend** delivers transactional email. It receives the recipient address and message content, but MySRS does not

send portal files as email attachments. Provider account data, email metadata and logs may be processed in the

United States, and delivery also involves the recipient's mail provider.

- **Stripe** is used only if SRS enables hosted card payment. Stripe then receives the data needed for checkout and

payment, such as email, order reference, line-item description, amount, fees, tax and currency. MySRS does not

receive or store the full card number or card security code. Stripe and payment participants process data under

their own regulatory, security and privacy obligations.

Where necessary for a specific order or legal duty, SRS may also share the minimum required data with banks,
accounting providers, carriers, freight forwarders, customs brokers, insurers, professional advisers or authorities.

Selected final records may be transferred manually to SRS's existing business, quality or accounting systems outside

MySRS. SRS does not sell personal data through MySRS.

5. International disclosures

SRS is based in Switzerland, while customers, email recipients, payment participants, providers and shipping
recipients may be in other countries. The disclosures described above may therefore involve Germany, the European

Union, the United States and the country connected with a customer or order.

Where the destination does not provide an adequate level of data protection recognised under Swiss law, SRS uses an
applicable safeguard, such as recognised standard contractual clauses with the necessary Swiss adaptations, and

assesses whether additional measures are required. A legal exception is used only where the applicable law permits

it.

6. Retention and official records

We keep personal data only for as long as needed for the relevant account, document, order, security, support,
contractual or legal purpose. We then delete, anonymise or restrict it, subject to required record retention, open

claims, incident evidence and the limited period needed for backup and recovery cycles. The relevant purpose and

applicable duty determine the period; MySRS does not claim one fixed deletion period for all records.

MySRS is a working and exchange platform. It is not the sole official aviation, quality, accounting or statutory
archive. Binding originals and records that SRS must retain are kept in the existing SRS systems and processes

outside MySRS. Portal working copies do not replace those records.

7. Security, cookies and local storage

SRS uses access controls, encrypted connections, password hashing, private file storage, security logging, backups
and other organisational and technical measures appropriate to the portal. No system is completely secure. Users

must protect their personal credentials and devices and promptly report suspected misuse.

MySRS uses only technically necessary first-party session and authentication cookies. It also stores the user's
essential-only cookie preference in browser local storage. The reviewed portal code contains no analytics,

advertising or marketing trackers. This statement must be checked again if the code or deployed configuration

changes.

8. Your rights

Subject to applicable law, you may ask whether SRS processes personal data about you and request access, correction
or deletion. Depending on the law that applies, you may also request restriction or portability, object to certain

processing, or withdraw consent for the future. SRS may verify your identity and may retain or restrict data where a

contract, legal duty, security need, legal claim or another lawful reason requires it.

Send requests to info@swissrotorservices.com with the subject “MySRS privacy request”. You may also contact the Swiss
Federal Data Protection and Information Commissioner (FDPIC/EDÖB) and, where another data protection law applies,

the competent supervisory authority.

9. Security and privacy incidents

SRS assesses suspected incidents without undue delay. If a personal data breach is likely to result in a high risk
to affected persons, SRS will notify the FDPIC as quickly as possible. SRS will inform affected persons where this is

required or necessary for their protection. Any additional notification duty under an applicable foreign law is

assessed separately.

10. Changes

SRS may update this policy when the portal, providers or legal requirements change. MySRS records the accepted policy
version. Where SRS requires acceptance of a new version, the relevant portal areas remain restricted until the new

version is accepted.

swissrotorservices.comWebsitePrivacy PolicyPrivacy PolicyTermsTermsCookiesCookiesImprintImprint

© 2026 Swiss Rotor Services AG