Legal Information
Data Compliance
Table of Contents
Personal Data
Abrantix handles a limited set of personal data, strictly for the purposes described below. This overview helps you assess GDPR compliance and understand how your data flows through our systems.
Under the GDPR, personal data is any information that relates to an identifiable natural person. The table below lists what we collect, where it comes from, and why.
| Data | Source | Purpose |
|---|---|---|
| Name | Provided during sign-up | Billing, email notifications, support |
| Email Address | Provided during sign-up | Authentication, billing, service notifications |
| Address | Provided during sign-up | Billing and invoicing |
| Password | Provided during sign-up | Authentication |
| IP Address | Extracted from network communication | Debugging and analysis |
| Browser Data | Extracted from the user's browser | Debugging and analysis |
We do not sell or share this data with third parties beyond the subprocessors listed on this page, and only to the extent necessary to deliver our services.
GDPR
What is the GDPR?
The General Data Protection Regulation (GDPR) is the EU's framework for data protection and privacy. It came into effect on May 25, 2018, replacing a 1995 Directive. The GDPR applies to any organization that targets or processes data from people in the EU, regardless of where the organization itself is based.
For more information, see the Official Journal of the European Union.
Our commitment
Abrantix is committed to full GDPR compliance. We treat the privacy and security of your data as a fundamental responsibility, not an afterthought. Our processes, contracts, and technical measures are designed to meet GDPR requirements across all our entities and services.
If you have questions about GDPR compliance at Abrantix, reach out to us directly. We're happy to walk you through the details.
CH-FADP (CH-nDSG)
What is the FADP?
Switzerland's revised Federal Act on Data Protection (nDSG / FADP) applies to all companies based in Switzerland and to foreign companies whose data processing activities have an effect in Switzerland. It came into force in September 2023 and significantly raises the bar for data protection standards, bringing Swiss law closer in line with the GDPR.
For more information, see the Official Federal Act on Data Protection.
Our commitment
As a Swiss company, Abrantix is fully committed to complying with the FADP. Your data is handled in accordance with Swiss data protection requirements, and we continuously review our processes to ensure ongoing compliance.
If you have questions about FADP compliance at Abrantix or ReconHub, get in touch. We're glad to help.
ISO 27001
What is ISO 27001?
ISO 27001 is the internationally recognized standard for information security management. It requires organizations to systematically identify risks and address them through defined policies, documented processes, and technical controls. The standard is built on three core principles:
- Confidentiality: Information is protected from unauthorized access.
- Integrity: Information is accurate and protected from unauthorized modification.
- Availability: Information is accessible when you need it.
Abrantix is certified
ATTESTA Schweizer Zertifizierungsgesellschaft AG, Akr.-Nr. ASCBm 3132143_A, in CH-8806 Bäch - UID: CHE-357.699.924 - certifies that the companies:
- Abrantix AG, Förrlibuckstrasse 66, 8005 Zurich, Switzerland
- Abrantix Deutschland GmbH, Ledererstrasse 19, 68033 München, Germany
- Abrantix Pty Ltd, Level 5, Suite 6, 400 Hunter Street, Newcastle NSW 2300, Australia
- Abrantix d.o.o, Sermin 71, 6000 Koper, Slovenia
The certification covers the development and distribution of IT products (hardware and software), consulting services, and product trading.
What this means for you
Working with an ISO 27001-certified partner means information security is not just a policy on paper. It is embedded in how we work every day: standardized workflows, clearly defined responsibilities, and continuously maintained technical systems. This systematically reduces security risks and gives you a reliable foundation for your own compliance requirements.
PCI-DSS
What is PCI-DSS?
The Payment Card Industry Data Security Standard (PCI-DSS) is an information security standard for organizations that handle primary account numbers (PANs) and other cardholder data from major card schemes such as Visa and Mastercard. The standard is administered by the Payment Card Industry Security Standards Council and exists to reduce credit card fraud through consistent security controls.
Abrantix and PCI-DSS
Payment security is at the core of what Abrantix does. Our teams have extensive experience designing, implementing, and auditing payment systems that operate within PCI-DSS scope. Abrantix products and services are built with PCI-DSS requirements in mind from the ground up. Where our solutions touch cardholder data environments, we apply the technical and organizational controls required by the standard.
Payment Platform: in PCI-DSS scope
The Abrantix Payment Platform processes cardholder data as part of its core function and operates fully within PCI-DSS scope. The Payment Platform is designed and maintained in accordance with PCI-DSS requirements, ensuring that all handling of PANs and related data meets the security standards mandated by the card schemes.
ReconHub: out of PCI-DSS scope
ReconHub does not process complete PANs, cryptographic key material, or other PCI-relevant cardholder data. It is therefore out of scope for PCI-DSS.
Where ReconHub receives transaction data that includes card information, PANs are either absent or already truncated by the upstream data provider, in line with their own PCI compliance obligations. These providers include POS solution providers, payment processors, and payment service providers.
In specific cases, such as ep2 transactions, ReconHub may receive enciphered PANs as part of a transaction receipt. In these situations, Abrantix does not hold or have access to the key material needed to decrypt the data. Responsibility for the PCI compliance of enciphered PANs lies with the data provider — in the ep2 case, the payment terminal.
PCI-PIN
What is PCI-PIN?
The PCI PIN Security Standard defines requirements for the secure management, processing, and transmission of personal identification numbers (PINs) during card-based payment transactions. It applies specifically to organizations involved in the acceptance and processing of PIN-based payments — primarily through payment terminals and other point-of-interaction (POI) devices. The standard covers how PINs are entered, encrypted, and transmitted, as well as the management of the encryption keys that protect PIN data end-to-end. Like PCI-DSS, it is administered by the Payment Card Industry Security Standards Council.
Payment Platform Processing: PCI-PIN certified
The Abrantix Payment Platform Processing operates as a PIN-processing environment and is PCI-PIN certified. This confirms that all PIN handling within the processing infrastructure meets the security requirements mandated by the payment industry for the secure transmission and management of encrypted PIN data.
Payment Acceptance: PCI-PIN certified
Abrantix's Payment Acceptance solutions, including terminal software and point-of-interaction implementations, are PCI-PIN certified. This gives you the assurance that PIN entry, encryption, and transmission, as well as key loading and key exchange within the acceptance environment, comply with the highest security standards required by the card schemes.
SOC 1 Type 2
What is SOC 1 Type 2?
A SOC 1 Type 2 report is an independent audit that confirms a service provider's internal controls relevant to financial reporting are properly designed and effective in practice. The Type 2 designation is key: the auditor does not simply verify that controls exist on paper. They test whether those controls operated effectively over a defined period.
ReconHub is SOC 1 Type 2 audited
SOC 1 Type 2 is a product-level certification. At Abrantix, it applies specifically to ReconHub — not to Abrantix as a company. ReconHub has successfully completed a SOC 1 Type 2 audit, with controls independently tested over a twelve-month period.
This is relevant because ReconHub sits between your operational transaction systems — point-of-sale, payment service providers — and your general ledger. The accuracy and reliability of its reconciliation output directly affects your financial reporting. The SOC 1 Type 2 report gives you and your auditors independent confirmation that these processes are built on solid, tested controls across six areas: data security and access, system availability, financial interfaces, change management, incident handling, and audit trails.
Your external auditor can rely on the SOC 1 Type 2 report rather than auditing ReconHub independently, reducing both audit effort and cost. The documented effectiveness of ReconHub's controls also reduces inherent risk in your financial reporting. For regulated industries or listed companies, the report fulfills the requirement for evidence of effective controls at critical service providers.
The report is available upon request under NDA for customers, auditors, and partners. Contact us to request access.
Technical and Organizational Measures
What are Technical and Organizational Measures?
Technical and Organizational Measures (TOM) are the concrete steps an organization takes to protect personal data — both through technical systems and internal processes. Implementing effective TOM is a core requirement under both the EU General Data Protection Regulation (GDPR) and Swiss data protection law (DSG/DSV).
How Abrantix applies TOM
Abrantix's TOM apply to all personal data processed within its systems, platforms, and processes — covering customers, partners, employees, and all other data subjects. The measures are designed to ensure that data protection is not an afterthought, but is built into how we operate from the ground up.
Our approach is guided by four key principles:
-
Confidentiality, integrity, availability, and recoverability — Personal data is protected from unauthorized access, kept accurate, accessible when needed, and recoverable in the event of an incident.
-
Risk-based and proportionate — Measures are scaled to the sensitivity of the data and the risks involved, ensuring effort and protection are always appropriate.
-
Privacy by design and by default — Data protection is embedded into technical systems and processes from the start, applying least-privilege and need-to-know principles throughout.
-
Traceability and accountability — Actions involving personal data are documented, and responsibilities are clearly assigned.
The adequacy of our TOM is reviewed on a regular basis and adjusted as needed to reflect changes in technology, regulation, and risk. The full TOM documentation is available upon request — contact our Data Protection Officer.
Abrantix Subprocessors
What Is a Subprocessor?
To deliver its services, Abrantix works with a limited number of third-party vendors who may access customer data as part of their service. These vendors are called subprocessors. We select them carefully and hold them to the same data protection standards we apply to ourselves.
Current Subprocessors
| Vendor | Applicable Data Center | Type of Service |
|---|---|---|
| Atlassian | Germany | Internal support collaboration |
| Darktrace | Netherlands | Email intrusion detection |
| Datadog Inc. | Germany | Monitoring and analyzing |
| Microsoft Corporation (Azure) | Switzerland | Infrastructure provider |
| Microsoft Corporation (Microsoft 365) | European Union | Communication and document management |
| ProCloud | Switzerland | Infrastructure provider |
| TD Synnex | Switzerland | Infrastructure provider |
| Zoho Corporation | Netherlands, Ireland | Support ticketing and customer service |
Abrantix Group Entities
The following Abrantix entities may act as data processors or subprocessors depending on your service agreement:
- Abrantix AG, Switzerland
- Abrantix Deutschland GmbH, Germany
- Abrantix Pty Ltd., Australia
- Abrantix d.o.o. Koper, Slovenia
If you have questions about our subprocessor list or data processing agreements, contact us.
Contacting Us
For any questions about the compliance topics covered on this page — including GDPR, CH-FADP, ISO 27001, PCI-DSS, or data protection in general — reach out to our Data Protection Officer directly:
-
Mirko Oberholzer, Abrantix AG, Switzerland, dpo@abrantix.com
- Matthieu Michel, EU Representative, Abrantix Deutschland GmbH, Germany, dpo.eu@abrantix.com
SHARE