Data Protection Charter
Our privacy commitments, in plain language.
2026-07-09 Carewell processes data that touches on the most intimate aspects of life: health, daily care, family ties. This charter summarises, in plain language, the commitments we make to you. It complements — but does not replace — our privacy policy.
1. You own your data
Your data belongs to you and you have rights over it. We process it to provide a service, never to resell it to third parties for commercial purposes. You can at any time request a copy, correct, delete or transfer your data by writing to our DPO.
2. We collect the bare minimum
We follow a simple principle: only collect what is useful for the stated purpose. If a piece of data is not necessary for a service, we don’t ask for it. If it is no longer necessary, we delete it, archive it in accordance with our legal obligations or anonymise it where possible.
3. Your data stays in Switzerland as much as possible
Our main servers and backups are hosted in Switzerland by providers subject to Swiss law. Where data processing or transfers abroad are necessary, we favour, as far as possible, countries recognised as providing an adequate level of protection within the meaning of the revFADP. When a sub-processor is located outside Switzerland, we clearly identify it in the list of sub-processors and put in place appropriate contractual safeguards (such as recognised standard contractual clauses or applicable certification mechanisms).
4. We secure your data
We take appropriate security measures (both organisational and technological) to protect your information against unauthorised access, alteration, disclosure or destruction, in accordance with Articles 1 to 3 of the Swiss Data Protection Ordinance (DPO).
For more information, see the list of our technical and organisational measures (TOMs) in our Security policy.
5. You stay in control of access
Within your institution or family circle, you decide who can see what. Roles and permissions are configurable and every access is logged.
6. We don’t hide behind our algorithm
When we use automated processing to suggest a mission, a professional or a recommendation, you can ask for an explanation and request human intervention, in accordance with Art. 21 FADP.
7. We communicate quickly in the event of an incident
If a data breach occurred and posed a risk to your rights, we would inform you and the competent authorities (FDPIC) as quickly as possible, in accordance with the revFADP.
8. We train our teams and partners
Any person with access to personal data as part of their work signs a confidentiality undertaking and regularly follows training in Swiss data protection law.
9. We assess the impact before launching
Before any new processing likely to entail a high risk to your rights (for example a new service using artificial intelligence), we carry out a Data Protection Impact Assessment (DPIA). The conclusions are available on request from our DPO.
10. You can always reach us
Our Data Protection Officer (DPO) can be contacted at dpo@carewell.ch. You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) if you consider that we have not honoured our commitments.