🛡️ Data Policy
System: CIMS (Convence Internal Management System)
Organization: Convence
Governing Entity: Convence Group CHE
1. Purpose of Data Logging and Session Tracking
CIMS collects and logs certain user actions and sessions to ensure the secure and compliant handling of data within our internal platforms. This includes the use of session tracking and replay tools that record user interactions (such as navigation, form inputs, and changes made within the system).
These features exist solely to ensure compliance with data protection and operational integrity regulations, both local and international. They allow the Convence Compliance Team to review access logs and verify that:
Personal or client data is accessed, viewed, or modified only when necessary,
Any changes to sensitive data are justified and properly documented,
Client requests for access, correction, or deletion of data are handled transparently and securely.
2. Data Categories Collected
The system may record and store the following information for internal audit purposes:
User session identifiers and timestamps,
User actions within the platform (e.g., data access, edits, deletions),
Navigation and system interaction logs,
Technical information (e.g., browser type, device, and session duration).
No sensitive personal content (such as passwords or private correspondence) is intentionally recorded.
3. Legal Basis and Compliance
All processing of session and log data is carried out under the principles of:
Lawfulness, fairness, and transparency (as per Swiss FADP and EU GDPR standards),
Purpose limitation – Data is used exclusively for compliance monitoring, not for profiling or employee surveillance,
Data minimization – Only essential information required for compliance validation is stored,
Integrity and confidentiality – All records are securely stored and accessible only to authorized members of the Convence Compliance Team.
4. Data Retention
Session logs and replay records are retained only for the period necessary to fulfill compliance and audit requirements. After this period, they are securely deleted or anonymized.
5. User Rights
Users whose sessions are recorded retain the following rights under applicable privacy laws:
Right to access their data logs upon request,
Right to rectification of any inaccurate information,
Right to deletion of personal data if it is no longer necessary for compliance or legal purposes,
Right to restriction of processing under certain conditions.
Requests can be raised via ticket system on CIMS.
6. Security and Access Control
All logs and session recordings are stored in protected data environments under Convence Group CHE’s internal data infrastructure.
Access is strictly restricted to authorized compliance officers and system administrators.
Any unauthorized access, sharing, or manipulation of such data constitutes a violation of company policy and data protection law.
7. Consent
By accessing and using the CIMS platform, you acknowledge and consent to:
The recording of your system interactions for compliance and audit purposes,
The secure and limited use of your session data as described above,
Convence’s right to process and store such data under applicable data protection regulations.
If you do not agree with these terms, please refrain from using the CIMS system and contact the Convence Compliance Team for guidance.
© Convence Group CHE — All rights reserved
Last updated: November 2025