XARA Privacy Policy
This privacy policy explains which personal data afca. ag collects and processes within the Xara dialog trainer.
Xara consists of the XaraWeb web client, the XaraApp for Quest3, and the XaraAdmin administration tool. XaraWeb and the XaraApp for Quest3 each require an access token; no personal data is collected or processed during sign-in or operation of the dialog trainer.
Personal data means any information relating to an identified or identifiable person.
This privacy policy is designed to meet the requirements of the EU General Data Protection Regulation ("GDPR"), the Swiss Data Protection Act ("DPA") and the revised Swiss Data Protection Act ("revDPA"). Whether and to what extent these laws apply depends on the individual case.
Markus Brönnimann is responsible for the data processing described here. If you have data protection concerns, you can contact us at: afca. ag, Markus Brönnimann, Industriestrasse 35, 3052 Zollikofen, datenschutz@afca.ch
In order to use the XaraAdmin administration tool, a permission must be set up for the customer (tenant) on the afca. ag side. Before the customer can access XaraAdmin, they must accept the "Permissions Request" displayed by Microsoft Online.
The following permissions are granted:
XaraAdmin can access the name, email address and user ID (Object ID in Azure AD).
XaraAdmin can view information about the organization (company name and tenant ID with Microsoft Online).
Following the customer's consent, ongoing access to this data exists, so consent only needs to be given once. An administrator can grant consent for the permissions described above on behalf of an entire organization.
The collected data is used exclusively to verify access authorization in XaraAdmin. No personal data is stored, analyzed or forwarded by XaraAdmin, the Xara web client, or the Xara Quest3 app.
There is no linking or storage of user inputs, user interactions, or the bot's responses together with the data collected for access authorization.
Voice input in the Xara web client and the Xara Quest3 app is transcribed 100% client-side (JavaScript or Unity). This means there are no recordings of the user's voice within the system.
Our access provider, Microsoft Online, uses cookies and comparable techniques for authentication, which can identify your browser or device. A cookie is a small file that is sent to your computer and automatically stored by the browser you use on your computer or mobile device when you visit XaraAdmin.
When you access XaraAdmin again, Microsoft Online can recognize you and thereby implement single sign-on (SSO). Google Analytics is not implemented. There are no active social media plugins or trackers.
XaraAdmin does not store any personal data. As part of the access authorization check by Microsoft Online, the minimally necessary data (email address, password and the token) is sent to the Microsoft Cloud for verification.
The user can delete and thereby revoke the granted permission for the access control by Microsoft Online described above at any time. XaraAdmin thereby loses all previously granted permissions to the personal data described.
We take appropriate technical and organizational security precautions to protect all data we process against unauthorized access and misuse.
The data collected for access control by Microsoft Online falls within Microsoft's area of responsibility.
XaraAdmin, the Xara web client and the Xara Quest3 app do not use personal data for profiling or automated decision-making.
Within the scope of the data protection law applicable to you, and to the extent provided therein, you have the right to information, correction and deletion of the data we have collected.
The following statements apply to Microsoft Online's services (non-exhaustive): more information on Microsoft's standard contractual clauses is available at learn.microsoft.com. More about the data processed through the use of Microsoft can be found in the privacy statement at privacy.microsoft.com.
Every data subject also has the right to assert their claims in court or to lodge a complaint with the competent data protection authority. The competent data protection authority in Switzerland is the Federal Data Protection and Information Commissioner (www.edoeb.admin.ch).
Version 1.2 (21.11.2025): Updated Azure services and locations
Version 1.1 (05.11.2025): Updated Xara web client
Version 1.0 (25.11.2024): First publication