1. Where Data Lives by Default
Unplex's standard (SaaS) infrastructure is hosted in Switzerland. Uploaded documents, extracted text, and the search index built from them are stored within the firm's isolated account — they remain inside the hosting boundary and are never sent to an external AI provider as raw documents.
When a question is asked or an analysis is run, only the text needed to answer it is sent to an AI model, and that text is pseudonymized first (see Section 2).
2. Protection Before Reaching an AI Model
Before any text leaves the hosting boundary to reach an external AI model, it passes through Unplex's internal pseudonymization step (PII Guard). Names, account numbers, and other identifying details are replaced with placeholder tokens; the AI model sees only the tokenized version, never the real values.
The mapping needed to restore real values into the AI's response is held only within the Swiss-hosted environment, and re-identification happens there, after the model responds. No external party — including the AI providers themselves — holds that mapping or can reverse it.
Note: this is pseudonymization, a specific, legally defined technical measure — not anonymization. Because the data can be restored, it remains personal/protected data throughout, and both Unplex and the customer organization retain full responsibility for it under applicable data protection and, for Swiss financial institutions, banking secrecy law. What pseudonymization changes is who can access the data in cleartext, and where — the external model provider cannot.
3. AI Inference Location and Configuration
Default: AI processing is routed to top-tier models operated by Unplex's infrastructure partners in the EU/EWR — never outside Switzerland or the EU/EWR, and always on pseudonymized text only.
Swiss-only routing: where AI inference itself — including complex, multi-step reasoning, not only short tasks — must run entirely on Swiss-hosted infrastructure, Swiss-hosted model options can be configured as the account's primary model for accuracy-critical work, alongside a lighter Swiss-hosted option for quick, single-step tasks. The account team enables Swiss-only routing per workspace on request.
Fully self-hosted (on-premise): where the software itself must run entirely on infrastructure controlled by the customer, a fully self-hosted deployment is available under a separate contractual addendum. In this tier, the customer connects and operates its own AI models and APIs — Unplex supplies the interfaces and documentation but does not select, host, or operate the models. Because Unplex has no access to the installation, it does not act as data processor for data held in it. The account team scopes this individually.
See Deployment Options: Standard, Swiss-Only Routing, and Self-Hosted for the high-level comparison of these three tiers by regulatory segment, including the support model for on-premise installations.
4. Regulatory Framework
Unplex's data-handling design is built around the requirements applying specifically to AI use in Swiss financial services:
Cross-border data transfer (FADP Art. 16–17; GDPR Art. 44–49): sending data to an AI model hosted outside Switzerland/EU can breach data-protection law without adequate safeguards. This is addressed by defaulting all inference to Switzerland/EU-hosted providers, with Swiss-only routing available where required.
Banking and professional secrecy (Art. 47 Banking Act; Art. 69 Financial Institutions Act for independent asset managers, portfolio managers, and trustees; Art. 162 Criminal Code): secrecy-protected client data cannot be transmitted to a third party — including an AI provider — without a legal basis. For Swiss wealth management clients, this is often the more decisive constraint, ahead of general data-protection law. Regulatory guidance recognizes pseudonymization, together with encryption and access controls, as a valid technical and organizational measure; PII Guard is designed to satisfy this — the AI provider never receives client-identifying data in cleartext.
Pseudonymization of PII (FADP Art. 6; GDPR Art. 4(5), 5, 25): identifiable client data must be removed or tokenized before reaching a model. Handled automatically by PII Guard on every request; pseudonymized data legally remains personal data, which is why this step is never described as anonymization.
Provider contract / Data Processing Agreement (FADP Art. 9; GDPR Art. 28): a documented processing agreement — covering purposes, security, sub-processors, deletion, and audit rights — is a standard part of every Unplex contract, supported by ISO 27001:2022 certification. Note: this DPA applies to the Standard and Swiss-only tiers; it does not apply to data processed in a fully self-hosted installation, where Unplex has no access to customer data (see Section 3).
FINMA Guidance 08/2024 on AI governance: there is no Switzerland-specific AI law; existing governance and risk-management requirements apply on a technology-neutral basis, including for outsourced AI. The customer institution is expected to maintain its own inventory of AI tools in use, a risk classification, and clear internal accountability. Unplex's audit trail, human-approval steps, and Data Processing Agreement are designed to support that internal governance work, not replace it.
5. Controller and Processor Roles
Unplex acts as the data processor; the customer organization remains the data controller. Pseudonymization and Swiss-hosted routing reduce the risk associated with sending data to an AI provider — they do not remove the customer organization's own compliance obligations. A data protection or banking-secrecy lawyer should confirm this analysis fits the specific institution and use case before it is relied on for a regulatory filing or client-facing statement.
6. Frequently Asked Questions
Question | Answer |
Is the data anonymized? | No. It is pseudonymized — the technically and legally precise term. The data can be restored using a mapping held exclusively within the Swiss-hosted environment, so it remains protected personal/client data throughout, under both Unplex's and the customer organization's responsibility. |
Can AI processing itself be required to stay in Switzerland? | Yes, for both quick tasks and complex, multi-step reasoning. The account team enables Swiss-only model routing per workspace on request. |
Does this replace the organization's own compliance sign-off? | No. Unplex is the processor, not the controller. The Data Processing Agreement and this documentation support the institution's own AI governance and secrecy-law analysis; they do not substitute for it. |
Who selects and operates the AI model in a self-hosted installation? | The customer. In the fully self-hosted tier, the customer connects and operates its own AI models; Unplex is not a party to that processing. |
Related articles: Data Security and Privacy at Unplex · How Unplex Prevents AI Hallucinations · Deployment Options
