Privacy Notice Power IMS Apps
How personal data is processed in the Power IMS modules – processing on behalf within the customer tenant; exception: Power Apps for Power Platform run entirely in the customer environment.
Version 2.3 · As of 03 October 2026
Provider
Power Manufaktur GmbH, UID CHE-153.237.765, Mettenwilstrasse 1, 6203 Sempach Station, Switzerland. Data protection officer: Heinz Süess, info@powermanufaktur.com. The company is domiciled in Switzerland; the modules are provided to customer organisations throughout the DACH region (Germany, Austria and Switzerland).
This privacy notice applies exclusively to the software products of the Power IMS family (Power Risk, Power Audit, Power Safety, Power Maintenance, Power QMS, Power CI, Power Knowledge, Power Energy, Power SRM, Power Hub and further modules of the suite – the «apps»). It reflects the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR).
Out of scope: processing on our websites (www.power-ims.com, www.powermanufaktur.com, www.power-copilot.com and www.power-vibecoding.com) such as analytics, newsletter, contact and quote forms, AI chat or meeting booking. The separate website privacy notice applies to those. We use no analytics, marketing or tracking tools inside the apps; in particular, no Google Analytics runs there.
Special case: Power Apps for Microsoft Power Platform. Modules delivered as Power Apps for Microsoft Power Platform (e.g. Power QMS for Power Platform) run entirely in the customer's environment. The provider only supplies the application files, templates and documentation; all processing of personal data takes place exclusively in the customer's Microsoft 365 tenant and Power Platform environment. Therefore no processing on behalf of the customer by Power Manufaktur GmbH takes place for these modules; the customer remains the sole controller for data processing.
This English version is a convenience translation. In case of discrepancies the German version prevails.
1. Roles
| Situation | Role of Power Manufaktur GmbH |
|---|---|
| Operating the apps for customer organisations (content in the customer's Microsoft 365 / SharePoint) | Processor (Art. 28 GDPR) – the separate DPA applies |
| Trial access, licence and contract administration | Controller (Art. 4 no. 7 GDPR) |
For data processed by a customer organisation in its own Microsoft 365 tenant, the customer organisation is the controller. Power Manufaktur GmbH processes such data solely on documented instructions.
2. Data processed in the apps
2.1 Use of the apps (processing on behalf)
- Identity and account data from Microsoft Entra ID: name, email/UPN, object ID, tenant ID, language, role in the app.
- Business data: content entered by users (e.g. risks, assessments, actions, findings, checklist items, reports) including person fields such as risk owner, responsible person, audit lead.
- Attachments and evidence: files stored in SharePoint.
- This business data resides in the customer organisation's Microsoft 365 tenant, not in a database of Power Manufaktur GmbH. The app accesses it via Microsoft Graph on behalf of the signed-in user.
2.2 Technical logs
- Error logs: timestamp, tenant identifier, error code / HTTP status, method, requested path (without query parameters), truncated error message, correlation ID. Retention: 30 days, then automatic deletion.
- Server and edge logs of the hosting provider: IP address, timestamp, requested resource, user agent. Retention 30 days.
2.3 Trial access and contact requests in the app context
Company name, contact person, business email address, tenant identifier, time of the request. Purpose: providing and administering trial access and responding to enquiries.
2.4 Licence administration
Tenant identifier, licence key, licence status, validity period, number of usage rights.
2.5 AI features
When users trigger AI features (report drafts, summaries, translations), the selected content is submitted as a prompt to the configured AI service. Details in section 5.
2.6 Notification emails
The apps send transactional notifications (e.g. assignments, due dates, approvals) to recipients within the customer tenant. These are sent via Brevo.
3. Purposes and legal bases
| Purpose | Legal basis GDPR | FADP |
|---|---|---|
| Provision and operation of the apps | Art. 6(1)(b) (contract) resp. Art. 28 (processing on behalf) | performance of contract |
| Security, error analysis, abuse prevention | Art. 6(1)(f) (legitimate interest) | overriding interest |
| Trial access and pre-contractual steps | Art. 6(1)(b) / (f) | performance of contract |
| Licence and invoice administration | Art. 6(1)(b) / (c) | legal obligation |
| AI-assisted text features | Art. 6(1)(b) (triggered by the user) | performance of contract |
4. Recipients and subprocessors
The authoritative list is the subprocessor register. As of this version:
| Provider | Service | Processing region |
|---|---|---|
| Microsoft (Azure / Microsoft 365) | Identity (Entra ID), data storage (SharePoint), AI (Azure OpenAI) | customer tenant region resp. West Europe |
| Lovable / operated edge infrastructure | Hosting and delivery of the web application, error logs | Europe (Ireland) |
| Brevo | Sending transactional notification emails | Europe (France) |
| Partner Hub (licence service of Power Manufaktur GmbH) | Licence validation, trial administration | Europe (Ireland) |
Data is never sold or shared for advertising purposes.
5. AI processing
- The AI provider is configurable. The default for production use is Azure OpenAI in the West Europe region. The contracting party is Microsoft; the Microsoft DPA and the EU Data Boundary apply.
- Microsoft does not use Azure OpenAI inputs to train models.
- Alternatively, a customer organisation may select a different provider in the settings (e.g. Google Gemini via the Lovable gateway). This may involve a transfer outside Switzerland/the EU and may only be activated with the consent of the responsible customer organisation.
- AI output is a draft. It does not replace professional review; there is no automated individual decision with legal effect within the meaning of Art. 22 GDPR.
6. Transfers abroad
Where data is processed outside Switzerland or the EEA, we rely on an adequacy decision or on the EU Standard Contractual Clauses (in the version recognised by Switzerland) together with supplementary safeguards (encryption in transit and at rest, access restrictions, data minimisation).
7. Retention and deletion
| Data category | Retention |
|---|---|
| Business data in SharePoint | controlled and deleted by the customer organisation |
| Error logs | 30 days, then automatic deletion |
| Server and edge logs | 30 days |
| Trial / contact requests in the app context | up to 12 months after last contact |
| Licence data | contract term + statutory retention (usually 10 years) |
| AI inputs | not stored by us beyond the session |
| Data in the provider's area of responsibility after contract end | deleted within 90 days in accordance with the DPA |
8. Security
Access exclusively via Microsoft Entra ID (single sign-on, MFA as configured by the customer organisation), transport encryption (TLS), role-based permissions, server-side authorisation checks, outgoing email restricted to recipients of the customer's own tenant, logging of security-relevant errors. Further measures are described in the DPA, Annex A (TOM).
9. Rights of data subjects
Access, rectification, erasure, restriction, data portability and objection. If a request concerns data held in a customer organisation's app, that organisation is the controller; we forward the request and support them in responding. Requests to info@powermanufaktur.com.
Right to lodge a complaint: Federal Data Protection and Information Commissioner (FDPIC), Bern, and – within the scope of the GDPR – with the competent supervisory authority of the place of residence or work.
10. Related documents
- Terms of service – contractual basis for using the modules
- DPA – processing on behalf incl. TOM
- Subprocessor register
- Website privacy notice
11. Changes
We may amend this notice. The version published on our website at the time is authoritative.