Privacy Policy
Last updated: 19. Januar 2026 | Version 1.0
1. Responsible party
Mergixa (operated by MProfi AG)
[Strasse + PLZ — siehe Handelsregister Zürich]
8000 Zürich
Schweiz
E-Mail: datenschutz@mergixa.ch
2. Introduction
Mergixa (operated by MProfi AG) takes the protection of your personal data seriously. This privacy policy explains how we collect, use, and protect your data.
3. Data we collect
- Name
- Organisation
- IP-Adresse (anonymisiert)
- Login-Daten
3a. Tenant isolation & multi-tenant data segregation
Mergixa is designed as a multi-tenant platform for M&A advisers. Every adviser organisation (tenant) has a fully isolated data space. Cross-tenant data mixing is technically impossible:
- PostgreSQL Row-Level Security (RLS) on 39+ tables — every database query is automatically filtered by tenant context. Advisers can never access other advisers' data, even through faulty application logic.
- Object-storage isolation: uploaded documents (data-room contents) are stored under tenant-specific S3 bucket paths. Cross-bucket access is blocked at the application layer.
- Per-tenant audit logs — every adviser only sees their own audit history, never others'.
- Tenant-isolation tests in CI — cross-tenant access attempts are automatically rejected with HTTP 403 and are part of the continuous-integration pipeline.
This guarantee applies to all tiers (Starter / Professional / Enterprise) and is not tied to white-label configuration. Further details in the white-label concept (on request: datenschutz@mergixa.ch).
4. Cookies
| Cookie | Purpose | Duration |
|---|---|---|
| session_token | Authentication | Session |
| refresh_token | Token refresh | 7 days |
| csrf_token | CSRF protection | Session |
5. Data retention
| Data | Retention |
|---|---|
| Account | Until deletion + 14 days |
| Projects | Until deletion by user |
| Logs | 90 days |
| Audit | 10 years (legal) |
6. Your rights (revFADP / GDPR)
Art. 15 GDPR / Art. 25 DSG
Right of access
Art. 16 GDPR / Art. 6 DSG
Right to rectification
Art. 17 GDPR / Art. 6 DSG
Right to erasure
Art. 20 GDPR / Art. 28 DSG
Data portability
7. Contact
Mergixa - Datenschutz
E-Mail: datenschutz@mergixa.ch