Data protection and security a firm can prove
Accounting and tax firms are liable for their work. The Nyteca® App, arriving in mid-November 2026, is built so that you can show at any time who did what and when – and so that evidence does not disappear.
- Swiss company
- Hosted in Switzerland
- FADP & GDPR
- Audit log
- PDF/A archive
Three rules that apply throughout the app
- 01
One firm, one sealed space
Every firm is a separate tenant of the platform. A login belongs to exactly one firm; there is no switching between firms and no firm identifier in the address bar.
- 02
Every action traceable
Create, review, approve, send, download, delete – with timestamp, person, event and resource in the audit log. Including uploads via the network drive and configuration changes.
- 03
Revocation instead of deletion
KYC uploads, consents and powers of attorney are evidence. They are revoked and kept separately, but never deleted. Rejected and blocked case files are also retained in full.
How the separation works technically
Not a statement of intent, but properties of the system.
Tenant separation in the code
The firm assignment comes from the signed-in employee, never from the request. Every read access checks membership, and every foreign ID from a form is checked against the firm’s own data before writing.
Signed sessions
Sessions are signed, time-limited and carry only identity and expiry – no profile data. Public journeys for clients (enquiry, KYC, consent, quote) run through dedicated, purpose-bound links.
Separate data storage
Structured data and documents are stored separately. Copies of identity documents are additionally held apart from the rest of the case file; every access to them is logged.
No third parties in the browser
This website serves its fonts and scripts itself. No data flows to font or script CDNs when you visit.
Audit log, PDF/A and versions
The basis for data-protection evidence and audits – without anyone having to document on the side.
| Time | Actor | Event | Resource |
|---|---|---|---|
| 09:12 | M. Huber | KYC approvedKYC | KYC |
| 09:14 | System | Document filedDocument | Document |
| 10:03 | S. Brunner | Document uploaded via Nyteca® DriveDocument | Document |
| 10:41 | S. Brunner | Email sentCase | Case |
| 11:20 | M. Huber | Configuration changedFirm | Firm |
Logged events
- Sign-in
- Created
- Updated
- Role changed
- Invited
- KYC link sent
- KYC step changed
- KYC approved
- KYC restarted
- Consent requested
- Consent signed
- Consent revoked
- Quote accepted
- Document uploaded
- Document uploaded via Nyteca® Drive
- Document filed
- Document downloaded
- Document deleted
- Email sent
- Email received
- Case closed
- Case reopened
- Configuration changed
PDF/A for powers of attorney
Powers of attorney are rendered from the firm’s Word template to PDF/A-2b – the format for long-term, unaltered archiving. Other generated documents are created as PDF from the firm’s templates and filed in the case file.
Versions instead of overwriting
Documents keep earlier versions. The risk rule set is only saved as a new version; the previous one stays readable, and every deviation from the delivered value requires a justification in the audit trail.
Identity copies kept apart
Copies of identity documents are held separately from the rest of the case file. Every access is logged – downloads included.
FADP and GDPR – in the application, not just in the contract
Consents, retention, roles and access are part of every firm’s data model.
Consents with revocation
Consents are recorded by type, signed digitally and tracked with a status: pending, granted, revoked. A revocation deletes nothing – the entry stays in the case file with date and reason.
- Data processing
- KYC check
- Email communication
- Document exchange
- Marketing
- Power of attorney
- Data processing agreement
Retention rules per firm
For each data type it is recorded how many months data is kept and from when the rule applies. The rules are master data of the firm – not hidden in the code.
- Data type, period in months, valid from
- Stored per firm
- Basis for data-protection information requests
Roles and groups
Permissions follow from two attributes on the employee, not from the group. Groups assign people organisationally and are filled via an invitation link; employees can be deactivated and reactivated – both in the audit log.
- Case handling
- Standard role without special attributes. Works on the clients, cases, documents and emails of their own firm.
- Compliance responsibility
- An attribute on the employee. Decides on KYC approvals, rejections and blocked case files.
- Management
- An attribute on the employee. Same decision-making authority as compliance, plus firm configuration and the rule set.
Swiss company, Swiss law
Nyteca® is a product of Tax AI AG, Sihlbruggstrasse 105, 6340 Baar, entered in the Handelsregisteramt des Kantons Zug (CH-170.3.052.501-0). Swiss data protection law (FADP) applies; for firms with clients in the EEA, the platform takes the requirements of the GDPR into account, in particular consent, right of access and data processing on behalf.
- Data processing agreement as its own consent type
- Hosting in Switzerland; data centre operator named in writing on request
- Technical and organisational measures documented on request
The AI suggests. A person confirms.
In the Nyteca® App, that is not a phrase for the website but the architecture: AI suggestions only take effect once a person accepts them.
Where is our data held?+
The Nyteca® App is operated by Tax AI AG, based in Baar, and hosted in Switzerland; we will name the operator of the data centre in writing on request. Enterprise clients receive a dedicated environment on request.
Who at Nyteca® can see our data?+
Running the platform requires no insight into firm data. Support access happens only at your request and for a defined purpose; scope and evidence are governed by the data processing agreement.
What happens on a revocation?+
The consent or power of attorney stays in the case file and is kept as revoked – with date and reason. Automated messages and client access end when a case file is blocked.
How long is data retained?+
In the Nyteca® App, retention periods are stored per firm and data type, in months and with a validity date – as master data, not in the code.
What does the AI in the Nyteca® App do with our data?+
AI features in the app only receive the context the respective place needs – in the app’s case chat, for example, case and mandate data including notes and the metadata of the documents, not their content. Every result is a suggestion that a person confirms. The case chat is a feature of the Nyteca® App and not the same as Nyteca® Chat.
Questions from your IT or auditors?
We answer technical questions about the Nyteca® App directly, even before its launch in mid-November 2026 – tenant separation, audit log, retention and hosting. If you wish, with your IT lead at the table.