Layer Nine
提供サービス 導入アプローチ AI基盤 セキュリティ AIエージェント
EN/DE/JA
無料相談を申し込む

日本語法律翻訳は現在審査中です。

このページは英語版の内容をそのまま掲載しています。日本語訳が確定するまで、英語版が正式な内容となります。

Japanese legal translation pending. This page displays the English version as-is. The English version remains authoritative until the Japanese legal translation is finalised.

法務情報

プライバシーポリシー

Effective date: 22 July 2026Version 2.0Microfiche.app GmbH

1. Overview and Data Controller Identity

1.1. Microfiche.app GmbH (trading as Layer Nine), a Swiss company registered in Domat/Ems, Canton of Graubünden (UID: CHE-469.286.682, Commercial Register No.: CH-350.4.007.922-2), respects your privacy and is committed to protecting your personal data in full compliance with Swiss and international data protection laws.

1.2. This Privacy Notice describes how we collect, process, store, and share personal data when you visit our website at layer-nine.ai (the "Website"), request information or demonstrations, communicate with us, or interact with our business services.

1.3. For the purposes of the revised Swiss Federal Act on Data Protection ("FADP" / "DSG") and, where applicable, the EU General Data Protection Regulation ("GDPR"), the Data Controller responsible for data collection and processing on this Website is:

Microfiche.app GmbH
Via Giuvs 17
7013 Domat/Ems, Switzerland
UID: CHE-469.286.682 | Commercial Register: CH-350.4.007.922-2
Email: privacy@layer-nine.ai / luca@layer-nine.ai
Website: https://layer-nine.ai

2. Controller vs. Processor Roles

2.1. Layer Nine as Data Controller: Layer Nine acts as a Data Controller for personal data collected directly through the Website, contact forms, demo requests, sales communications, newsletter subscriptions, and administrative B2B billing records.

2.2. Layer Nine as Data Processor: When Layer Nine provides AI execution layer technology, software integration, and workflow automation services to enterprise Clients, Layer Nine acts as a Data Processor on behalf of the Client (the Data Controller). The processing of personal data contained within Client systems (e.g., ERPs, CRMs, email servers) is governed exclusively by a dedicated Master Data Processing Agreement (DPA) in accordance with FADP and Article 28 GDPR. Data subjects whose data is processed within Client systems should direct privacy inquiries directly to the respective Client.

3. Applicable Legal Frameworks

We process personal data in strict compliance with:

  • The Swiss Federal Act on Data Protection of 25 September 2020 (revised FADP / DSG, SR 235.1, effective 1 September 2023) and the Swiss Data Protection Ordinance (DPO / VDSG);
  • The EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), insofar as we process personal data of individuals located in the European Union / European Economic Area (EEA).

4. Data Collection and Processing Operations

4.1 Visiting the Website and Server Log Files

When you access our Website, our web servers automatically collect and store technical information transmitted by your browser in server log files. This data includes:

  • IP address of the requesting device;
  • Date, time, and duration of access;
  • Name and URL of accessed web pages or files;
  • Referring website / HTTP referrer URL;
  • Browser type, browser version, and operating system;
  • Internet service provider.

Purpose & Legal Basis: Processed to ensure system connectivity, stability, network security, and administrative diagnostics. Legal basis: Legitimate interest under FADP / Art. 6(1)(f) GDPR in operating a secure website. Log files are automatically deleted within 30 to 90 days unless required for security incident investigation.

4.2 Contact Form, Inquiries, and Demo Requests

When you contact us via contact forms, email, or schedule a product demonstration, we collect the information you voluntarily provide, which may include:

  • Name and title;
  • Work email address and phone number;
  • Company name and job role;
  • Message content, operational details, and scheduling preferences.

Purpose & Legal Basis: Processed solely to respond to your inquiry, schedule and conduct product demonstrations, provide technical information, and evaluate potential B2B engagements. Legal basis: Pre-contractual measures (FADP / Art. 6(1)(b) GDPR) and legitimate interest in managing business communications (FADP / Art. 6(1)(f) GDPR).

4.3 Cookies and Technical Storage

Our Website uses essential technical cookies and local storage items strictly necessary for website operation, basic security, and session handling. We do not employ intrusive third-party tracking cookies or behavioral advertising scripts.

4.4 B2B Client Administration and Accounting Records

For existing Clients and business partners, we process corporate contact details, contract records, invoices, and communication history to manage our commercial relationship, fulfill contractual duties, and process payments.

Purpose & Legal Basis: Performance of a contract (FADP / Art. 6(1)(b) GDPR) and compliance with legal statutory obligations, including the Swiss Code of Obligations (Art. 958f CO), which mandates a 10-year retention period for financial and accounting records.

5. AI Processing, Dedicated Environments, and Model Training Prohibition

5.1. Absolute Prohibition on Model Training: Layer Nine maintains a strict technical and legal commitment that Client Data, prompts, communications, and operational outputs are NEVER used to train, fine-tune, develop, or improve public, shared, or third-party artificial intelligence models.

5.2. Isolated Client Environments: All workflow processing and agent executions take place within dedicated or logically segregated client environments to prevent data commingling or cross-client exposure.

5.3. Human Approval Gates: Automated workflows executed by Layer Nine agents are subject to Human Approval Gates. High-impact actions (such as financial transactions, bulk database updates, or external communications) require explicit human review and authorization before execution.

6. Hosting, Subprocessors, and Third-Party Services

6.1. To deliver our Website and Services efficiently and securely, we engage trusted third-party service providers ("Subprocessors"). All Subprocessors are carefully selected and bound by data processing agreements meeting FADP and GDPR requirements.

6.2. Current Key Subprocessors:

Provider / Subprocessor Purpose & Service Processing Location Data Protection Safeguard
Hetzner Online GmbH Cloud compute, backend infrastructure, and primary data storage Germany (EU) EU/Swiss Adequacy Decision; ISO 27001 Certified; GDPR Compliant
OpenAI, L.L.C. Natural Language Processing / LLM API inference United States Enterprise Zero-Data Retention Policy; Swiss-adapted Standard Contractual Clauses (SCCs)
Anthropic PBC Complex reasoning & LLM API inference United States Enterprise Zero-Data Retention Policy; Swiss-adapted Standard Contractual Clauses (SCCs)
Notion Labs, Inc. Business workspace & CRM database hosting United States Standard Contractual Clauses (SCCs)

7. International Data Transfers

7.1. Primary processing and storage of personal data take place in Switzerland and Germany (EU/EEA). The European Commission and the Swiss Federal Council recognize Switzerland and EU Member States as offering an adequate level of data protection.

7.2. Where personal data is processed by Subprocessors located in third countries without an adequacy decision (such as the United States), Layer Nine ensures appropriate safeguards are in place, specifically by executing Swiss-adapted EU Standard Contractual Clauses (SCCs) and enforcing enterprise zero-retention API policies.

8. Technical and Organizational Security Measures (TOMs)

We implement robust technical and organizational security measures to protect your personal data against unauthorized access, loss, misuse, alteration, or destruction:

  • Encryption in Transit: All website traffic and API communications are encrypted using modern TLS 1.2 / TLS 1.3 protocols.
  • Encryption at Rest: Sensitive client data and backend storage are encrypted using AES-256 standard encryption.
  • Access Control: Strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) are enforced for all administrative access.
  • System Isolation: Each Client environment is logically separated to eliminate cross-tenant risks.
  • Audit Logging: Comprehensive, tamper-evident action and access logging for security and compliance audits.

9. Data Retention Schedule

We retain personal data only for as long as necessary to fulfill the specific purpose for which it was collected or to comply with statutory retention requirements:

  • Web Server Logs: 30 to 90 days.
  • Inquiries and Demo Data: Duration of active inquiry + 12 months.
  • B2B Client Operational Data: Duration of the active service contract + 60 days following termination (as specified in our Master DPA).
  • Financial, Tax, and Accounting Records: 10 years, pursuant to Swiss statutory law (Art. 958f Swiss Code of Obligations).

10. Data Subject Rights

Under the Swiss FADP and (where applicable) the EU GDPR, you possess the following rights regarding your personal data:

  1. Right to Information / Access (FADP Art. 25 / GDPR Art. 15): Request confirmation as to whether we process your personal data and receive a copy of that data.
  2. Right to Rectification (FADP Art. 28 / GDPR Art. 16): Request the correction or updating of inaccurate or incomplete personal data.
  3. Right to Erasure / Deletion (FADP Art. 29 / GDPR Art. 17): Request the deletion of your personal data, provided statutory retention obligations do not apply.
  4. Right to Restriction of Processing (FADP Art. 30 / GDPR Art. 18): Request the restriction of data processing under certain legal conditions.
  5. Right to Data Portability (FADP Art. 31 / GDPR Art. 20): Receive personal data provided to us in a structured, commonly used, and machine-readable format.
  6. Right to Object (FADP Art. 32 / GDPR Art. 21): Object to data processing based on legitimate interests.
  7. Right regarding Automated Individual Decisions (FADP Art. 12 / GDPR Art. 22): Right to express your point of view and request human review for automated decisions. (Note: Layer Nine's Human Approval Gates ensure meaningful human intervention on all critical automated workflows).

To exercise any of these rights, please contact our Data Protection Coordinator at privacy@layer-nine.ai.

11. Right to File a Complaint with Supervisory Authorities

If you believe that our processing of your personal data violates applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority:

Swiss Supervisory Authority:
Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Feldeggweg 1
CH-3003 Berne, Switzerland
Website: https://www.edoeb.admin.ch

EU/EEA Supervisory Authority:
In the EU/EEA, you may contact your local national data protection authority (for example, in Finland: Office of the Data Protection Ombudsman / Tietosuojavaltuutetun toimisto, https://tietosuoja.fi).

12. Updates to this Privacy Notice

We reserve the right to update this Privacy Notice from time to time to reflect changes in our legal obligations, technology, or business operations. The current version will always be published on our Website with the effective date indicated.

Contact for Privacy Inquiries:
Microfiche.app GmbH (trading as Layer Nine)
Attn: Data Protection
Via Giuvs 17
7013 Domat/Ems, Switzerland
Email: privacy@layer-nine.ai / luca@layer-nine.ai

Terms & Conditions Legal Notice / Imprint
Layer Nine

実務を動かすAIシステム。Helsinki · Chur · Tokyo。

利用規約 運営会社情報

layer-nine.ai