Privacy Notice Power IMS Apps

    How personal data is processed in the Power IMS modules – processing on behalf within the customer tenant; exception: Power Apps for Power Platform run entirely in the customer environment.

    Version 2.3 · As of 03 October 2026

    Provider

    Power Manufaktur GmbH, UID CHE-153.237.765, Mettenwilstrasse 1, 6203 Sempach Station, Switzerland. Data protection officer: Heinz Süess, info@powermanufaktur.com. The company is domiciled in Switzerland; the modules are provided to customer organisations throughout the DACH region (Germany, Austria and Switzerland).

    This privacy notice applies exclusively to the software products of the Power IMS family (Power Risk, Power Audit, Power Safety, Power Maintenance, Power QMS, Power CI, Power Knowledge, Power Energy, Power SRM, Power Hub and further modules of the suite – the «apps»). It reflects the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR).

    Out of scope: processing on our websites (www.power-ims.com, www.powermanufaktur.com, www.power-copilot.com and www.power-vibecoding.com) such as analytics, newsletter, contact and quote forms, AI chat or meeting booking. The separate website privacy notice applies to those. We use no analytics, marketing or tracking tools inside the apps; in particular, no Google Analytics runs there.

    Special case: Power Apps for Microsoft Power Platform. Modules delivered as Power Apps for Microsoft Power Platform (e.g. Power QMS for Power Platform) run entirely in the customer's environment. The provider only supplies the application files, templates and documentation; all processing of personal data takes place exclusively in the customer's Microsoft 365 tenant and Power Platform environment. Therefore no processing on behalf of the customer by Power Manufaktur GmbH takes place for these modules; the customer remains the sole controller for data processing.

    This English version is a convenience translation. In case of discrepancies the German version prevails.

    1. Roles

    Situation
    Operating the apps for customer organisations (content in the customer's Microsoft 365 / SharePoint)
    Role of Power Manufaktur GmbH
    Processor (Art. 28 GDPR) – the separate DPA applies
    Situation
    Trial access, licence and contract administration
    Role of Power Manufaktur GmbH
    Controller (Art. 4 no. 7 GDPR)

    For data processed by a customer organisation in its own Microsoft 365 tenant, the customer organisation is the controller. Power Manufaktur GmbH processes such data solely on documented instructions.

    2. Data processed in the apps

    2.1 Use of the apps (processing on behalf)

    • Identity and account data from Microsoft Entra ID: name, email/UPN, object ID, tenant ID, language, role in the app.
    • Business data: content entered by users (e.g. risks, assessments, actions, findings, checklist items, reports) including person fields such as risk owner, responsible person, audit lead.
    • Attachments and evidence: files stored in SharePoint.
    • This business data resides in the customer organisation's Microsoft 365 tenant, not in a database of Power Manufaktur GmbH. The app accesses it via Microsoft Graph on behalf of the signed-in user.

    2.2 Technical logs

    • Error logs: timestamp, tenant identifier, error code / HTTP status, method, requested path (without query parameters), truncated error message, correlation ID. Retention: 30 days, then automatic deletion.
    • Server and edge logs of the hosting provider: IP address, timestamp, requested resource, user agent. Retention 30 days.

    2.3 Trial access and contact requests in the app context

    Company name, contact person, business email address, tenant identifier, time of the request. Purpose: providing and administering trial access and responding to enquiries.

    2.4 Licence administration

    Tenant identifier, licence key, licence status, validity period, number of usage rights.

    2.5 AI features

    When users trigger AI features (report drafts, summaries, translations), the selected content is submitted as a prompt to the configured AI service. Details in section 5.

    2.6 Notification emails

    The apps send transactional notifications (e.g. assignments, due dates, approvals) to recipients within the customer tenant. These are sent via Brevo.

    3. Purposes and legal bases

    Purpose
    Provision and operation of the apps
    Legal basis GDPR
    Art. 6(1)(b) (contract) resp. Art. 28 (processing on behalf)
    FADP
    performance of contract
    Purpose
    Security, error analysis, abuse prevention
    Legal basis GDPR
    Art. 6(1)(f) (legitimate interest)
    FADP
    overriding interest
    Purpose
    Trial access and pre-contractual steps
    Legal basis GDPR
    Art. 6(1)(b) / (f)
    FADP
    performance of contract
    Purpose
    Licence and invoice administration
    Legal basis GDPR
    Art. 6(1)(b) / (c)
    FADP
    legal obligation
    Purpose
    AI-assisted text features
    Legal basis GDPR
    Art. 6(1)(b) (triggered by the user)
    FADP
    performance of contract

    4. Recipients and subprocessors

    The authoritative list is the subprocessor register. As of this version:

    Provider
    Microsoft (Azure / Microsoft 365)
    Service
    Identity (Entra ID), data storage (SharePoint), AI (Azure OpenAI)
    Processing region
    customer tenant region resp. West Europe
    Provider
    Lovable / operated edge infrastructure
    Service
    Hosting and delivery of the web application, error logs
    Processing region
    Europe (Ireland)
    Provider
    Brevo
    Service
    Sending transactional notification emails
    Processing region
    Europe (France)
    Provider
    Partner Hub (licence service of Power Manufaktur GmbH)
    Service
    Licence validation, trial administration
    Processing region
    Europe (Ireland)

    Data is never sold or shared for advertising purposes.

    5. AI processing

    • The AI provider is configurable. The default for production use is Azure OpenAI in the West Europe region. The contracting party is Microsoft; the Microsoft DPA and the EU Data Boundary apply.
    • Microsoft does not use Azure OpenAI inputs to train models.
    • Alternatively, a customer organisation may select a different provider in the settings (e.g. Google Gemini via the Lovable gateway). This may involve a transfer outside Switzerland/the EU and may only be activated with the consent of the responsible customer organisation.
    • AI output is a draft. It does not replace professional review; there is no automated individual decision with legal effect within the meaning of Art. 22 GDPR.

    6. Transfers abroad

    Where data is processed outside Switzerland or the EEA, we rely on an adequacy decision or on the EU Standard Contractual Clauses (in the version recognised by Switzerland) together with supplementary safeguards (encryption in transit and at rest, access restrictions, data minimisation).

    7. Retention and deletion

    Data category
    Business data in SharePoint
    Retention
    controlled and deleted by the customer organisation
    Data category
    Error logs
    Retention
    30 days, then automatic deletion
    Data category
    Server and edge logs
    Retention
    30 days
    Data category
    Trial / contact requests in the app context
    Retention
    up to 12 months after last contact
    Data category
    Licence data
    Retention
    contract term + statutory retention (usually 10 years)
    Data category
    AI inputs
    Retention
    not stored by us beyond the session
    Data category
    Data in the provider's area of responsibility after contract end
    Retention
    deleted within 90 days in accordance with the DPA

    8. Security

    Access exclusively via Microsoft Entra ID (single sign-on, MFA as configured by the customer organisation), transport encryption (TLS), role-based permissions, server-side authorisation checks, outgoing email restricted to recipients of the customer's own tenant, logging of security-relevant errors. Further measures are described in the DPA, Annex A (TOM).

    9. Rights of data subjects

    Access, rectification, erasure, restriction, data portability and objection. If a request concerns data held in a customer organisation's app, that organisation is the controller; we forward the request and support them in responding. Requests to info@powermanufaktur.com.

    Right to lodge a complaint: Federal Data Protection and Information Commissioner (FDPIC), Bern, and – within the scope of the GDPR – with the competent supervisory authority of the place of residence or work.

    10. Related documents

    11. Changes

    We may amend this notice. The version published on our website at the time is authoritative.