The German version of this page is legally binding. → Deutsch
Privacy policy
Applies to buchify.ch and app.buchify.ch · Basis: Swiss Federal Act on Data Protection (FADP) and GDPR
As of: 8 October 2026
1. Controller
BE United Group, Bosnjak (Buchify), owner Gabriel BosnjakAlte Aach 1, 8599 Salmsach, Switzerland
info@pixify.ch
2. Two roles – and the difference matters
With accounting software, we process two kinds of data, and we do so in two different roles. This is not a formality: it determines who decides about what.
| Your account and contract data | Name, company, address, email, payment status, subscription term. Here we are the controller. We decide the purposes for which we process this data – namely solely to provide the software to you and to bill you for it. |
|---|---|
| What you record in Buchify | Your customers, documents, entries, bank statements, salaries, attachments. Here you are the controller, and we process on your behalf (Art. 9 FADP, Art. 28 GDPR). We do not look at this data, analyse it or pass it on. We store it so that the software works – nothing more. |
The details of processing on your behalf – being bound by instructions, sub-processors, security, deletion – are set out in section 8 of our General Terms and Conditions and constitute a data processing agreement.
3. What data we process
- Account data: name, email address, password hash, time of login, role. We never store passwords in plain text.
- Client company data: company name, address, UID, IBAN and QR-IBAN, VAT details – the data that must appear on your invoices.
- Payment data: Payments are handled by Stripe. We do not store any credit card data, only the payment status and the subscription reference.
- Content data: everything you record yourself – see section 2, second row.
- Technical data: server log files and rate limiting to prevent misuse. These are not analysed in connection with your person.
- Audit log: Buchify keeps an immutable log of who finalised, reversed or credited which document and when. This is a requirement of the Ordinance on the Keeping and Retention of Accounting Records (GeBüV) and cannot be switched off.
4. Access from Pixify-AI
If you have booked Buchify as an extension to your website subscription, you get from the customer panel into your accounts with one click. In doing so, Pixify transmits to Buchify a signed access token containing your order number, company name, address, email address, language and the status of your subscription.
The token is valid for 60 seconds and can be used exactly once; after that it is worthless. It is signed with a key pair – Buchify only knows the public part and can verify tokens but cannot issue any. The master data is transferred once, so that your client company is already filled in on first access; after that you maintain it in Buchify, and Pixify does not write it back.
The two applications have separate databases. Your accounting data is not stored in the database of the website builder.
5. Bank statements
If you upload a camt.053 file from your bank, we read the incoming payments, amount, date, reference and the details of the paying party from it and match them to your open invoices. Processing takes place on our server; the file is not passed on to third parties. There is no access to your bank account – Buchify reads a file; it does not connect to any bank.
6. Sending emails
If you send invoices or reminders from Buchify, they go via our mail server to the recipients you have entered. We store the recipient address, time and delivery status – so that you can see what has gone out, and so that a failed delivery can be retried.
7. Feedback and error reports from the app
If you report an error or an idea in Buchify via “Feedback & errors”, the report goes to the Pixify-AI backend (same operator), where we process it. We transmit your message, any screenshots, the page of the app you were on, browser and device, your name, your email address and the name of the client company. We use this solely to follow up on the report and to reply to you. Screenshots may show data from your accounts; they are only viewed by us and are not passed on.
8. The assistant on buchify.ch
At the bottom right of buchify.ch, an assistant answers questions about Buchify. What you type there goes to our platform pixify-ai.ch and from there to the AI interface of Anthropic, which writes the answer. We store the question with date, language and page – without an IP address and without a cookie – to see what visitors want to know. Please do not enter any personal, account or accounting data there. The assistant has no access to Buchify or to your data in the app.
9. Receipt reading (add-on)
If you have activated the “Receipt reading” add-on and have a receipt read, the photo or PDF of the document is sent, together with the numbers and names of your expense accounts, to our platform pixify-ai.ch and from there to the AI interface of Anthropic. It extracts supplier, date, amount and VAT and suggests an account. What comes back is a proposal that you check – nothing is posted without your confirmation.
Before the first receipt is read, Buchify explicitly asks for your permission – once per user, and in every session in the demo company. Without permission nothing is sent to Anthropic; photographed receipts are then only filed. You can withdraw the permission at any time under “Photograph a receipt”.
Pixify-AI does not store the photo; only the time, client company, file size and duration are recorded, for billing the add-on and for operations. Anthropic does not use the data for training and deletes it after 30 days at the latest. Without the add-on – and for everything else in the app – nothing goes to an AI service.
In the demo company, three receipts can be read per visitor and day. To count them, Buchify stores, with each reading in the demo, a fingerprint of your IP address derived with a secret key – not the address itself, and it cannot be traced back without that key. It is deleted every night together with the demo data.
10. Cookies, visitor counting and your settings
In the app (app.buchify.ch) there are no marketing or tracking cookies and no advertising pixel – no advertising network sees what you book there. On the website buchify.ch, the advertising pixels of Meta and TikTok only load if you allow “Advertising” in the cookie box (see below). After you log in to the app, a technically necessary session cookie is set, which keeps you logged in and becomes invalid when you log out or when the session expires. The demo company (View the demo) logs you in without a form and sets the same session cookie for this purpose; its data is deleted every night.
Visitor counting without cookies. This website (buchify.ch) counts page views anonymously: when a page is opened, a tiny image is loaded from the counting point of our own platform pixify-ai.ch. All that is stored is that the page was viewed once more on that day – no IP address, no cookie, no fingerprint, no profile. Counting is switched on by default unless you decline it; you can switch it off with the “Statistics” toggle in the cookie box, and the image is then not loaded at all.
External content. The box also offers a toggle for embedded videos and posts from third-party providers. buchify.ch currently does not embed any such content; the toggle therefore has no effect until there is some.
Advertising (Meta pixel, only on buchify.ch). With your consent, buchify.ch loads the pixel of Meta Platforms Ireland Ltd. (Dublin, Ireland), the operator of Facebook and Instagram; the script comes from our platform pixify-ai.ch. The pixel tells Meta which pages you view and what you do there – for example whether you open the demo or go on to order – together with technical data such as your IP address and browser identifier. For this it sets the cookies “_fbp” and, if you arrive via an ad, “_fbc” (90 days each). Orders are placed on pixify-ai.ch: if you also allow “Advertising” there, the platform reports the start of your trial month to Meta (Conversions API) – your email address and phone number only as a checksum (SHA-256), plus IP address, browser identifier and the two cookies; never any content from your accounts. No pixel runs in the app itself. We use this to see which ads work and to show ads to people who know Buchify. Meta may link this data to your account and transfer it to the USA; Meta’s privacy policy applies (facebook.com/privacy/policy). You can withdraw your consent at any time using the cookie button at the bottom left; the pixel will then no longer load.
Advertising (TikTok pixel, only on buchify.ch). With the same consent, buchify.ch also loads the pixel of TikTok Technology Limited (Dublin, Ireland); this script also comes from our platform pixify-ai.ch. The pixel tells TikTok which pages you view and what you do there – for example whether you open the demo or go on to order –, together with technical data such as your IP address and browser identifier. We do not pass your name, your contact details or any content from your accounts to TikTok. For this it sets the cookies “_ttp” and “ttcsid” and, if you arrive via an ad, “ttclid” (up to 13 months each). No pixel runs in the app itself. We use this to see which ads work on TikTok. TikTok may link this data to your account and transfer it to countries outside Europe, including countries without adequate data protection such as China; TikTok’s privacy policy applies (tiktok.com/legal/page/eea/privacy-policy). You can withdraw your consent at any time using the cookie button at the bottom left; the pixel will then no longer load.
Google ads. For ads on Google, no Google script and no Google cookie run on buchify.ch. If you arrive via an ad, the page address carries campaign parameters such as “utm_source” or “gclid”; like any address, they appear in the server log and are not sent to Google. Google counts the clicks on its ads itself.
Your choice stays with you. What you choose in the box is remembered by your browser in its local storage (entry “pxaConsent”, for one year); this information does not leave your device. You can change your choice at any time using the cookie button at the bottom left or here: Open cookie settings.
What else your browser remembers. If you close the hint about another language with “No, thanks”, your browser records this in its local storage (entry “buchifySprTipp”). The conversation with the assistant is kept only in your browser’s session storage until you close the tab. Neither leaves your device.
10a. The Buchify app for iPhone, iPad and Android
The app shows your accounts on app.buchify.ch; the same data and purposes apply as in the browser. The only additions are what a phone can do on top:
- Staying signed in: after you sign in (email, password and the code from your authenticator app), the app receives a device key. You stay signed in for up to 90 days after you last used it. Under “Security → Logged-in devices” you see every phone and sign it out with one tap.
- Face ID, Touch ID, fingerprint: the app lock is checked by the phone itself. We receive no biometric data, only the answer “unlocked” or not.
- Camera and photos: only when you photograph a receipt or pick an image. It is uploaded to your accounts as a document; the app reads no other photos.
- Notifications: only once you switch them on under “More” do we store a device identifier for notifications (push token) with your access. Delivery goes through Apple’s service (Apple Push Notification service) or, on Android, through Google’s Firebase Cloud Messaging. The text contains the company, amount and invoice number – never the name of your customer. Each type can be switched off per phone.
- No advertising and no analytics: the app contains no advertising pixel and no usage-tracking tool.
11. Disclosure to third parties
We work with a small number of carefully selected partners. There are no others – we do not sell data and do not operate advertising networks.
- Stripe – payment processing and subscription management. You enter your payment details directly with Stripe.
- Pixify-AI (pixify-ai.ch, same operator) – the anonymous visitor counting for this website (section 10; no personal data is transferred), the assistant (section 8), receipt reading with the add-on (section 9) and the backend where your feedback reports arrive (section 7).
- Anthropic (USA) – for the assistant on buchify.ch (section 8): your question is transmitted so that it can be answered; and only with the “Receipt reading” add-on, for reading your receipts (section 9). Other data in the app never goes to Anthropic. The transfer to the USA is based on appropriate safeguards (standard contractual clauses).
- Apple and Google – only if you switch on notifications in the app: they deliver the notification to your phone (section 10a).
- Hostinger – hosting of the application and the database. Server location: Frankfurt am Main, Germany. Your accounting data is stored there, not in Switzerland. The FADP and the GDPR apply to processing within the EU; a data processing agreement is in place.
- Meta (Meta Platforms Ireland Ltd.) – only on buchify.ch and only with your consent in the cookie box: the advertising pixel and the report of your trial start (section 10). Nothing from the app goes to Meta.
- TikTok (TikTok Technology Limited) – only on buchify.ch and only with your consent in the cookie box: the advertising pixel (section 10). Nothing from the app goes to TikTok.
Apart from the receipts you have read with the add-on (section 9), Buchify does not transmit your content to any AI service. What you record in the app stays on our servers; a feedback report, too, only goes to our own backend (section 7).
12. Retention
We retain account and contract data for the duration of the subscription and within the scope of statutory retention obligations – for business records, generally ten years.
Cancelling does not switch anything off. The ten-year retention obligation under Art. 958f of the Swiss Code of Obligations (CO) applies to you, not to us. That is why your access is switched to read-only mode after cancellation: you can still get to your documents and export everything. We only delete once you expressly request deletion and no retention obligation stands in the way.
13. Your rights
You have the right at any time to information about the data we store about you, and to its correction or deletion, unless statutory retention obligations prevent this. A short message to info@pixify.ch is sufficient.
Where we process data on your behalf (section 2, second row), requests from data subjects are to be addressed to you. If we receive such a request, we forward it to you and do not answer it ourselves.
14. Data security
Transmission is always encrypted (TLS); requests over HTTP are redirected before a page is delivered. Passwords are only stored as a hash; after five failed attempts, access is temporarily locked. Invoice PDFs and attachments are stored outside the web directory and cannot be accessed via any address. Access tokens from Pixify are valid for 60 seconds and can be used once. Your data is backed up daily.
If you find a security vulnerability, please report it to info@pixify.ch. We will reply and let you know what we have done about it.
15. Changes
We may amend this privacy policy as required. The version published here at the relevant time applies.
