Where your data is
This is the question companies ask when they come to us, and it deserves a precise answer rather than a “Swiss hosting” badge. Here is the chain, including the points where it leaves Switzerland.
The hosting chain
There is no hidden intermediary between you and the hardware. There is no third-party capacity resold under our name.
What is in Switzerland
For D&D’s main infrastructure, without reservation.
Your virtual machines
They run on hardware owned by D&D, installed in the Crissier data centre.
Their storage
The disks of your machines and the data they hold are on D&D’s Swiss infrastructure.
Their backups
Daily backups are kept on D&D’s Swiss infrastructure.
Their replication, where applicable
Where replication is put in place, it targets another infrastructure or data centre located in Switzerland and meeting the same requirements.
Systems administration
Carried out by the D&D team, in Switzerland. No external administrative access to the hypervisors.
Support
Provided from Switzerland, by the people who operate the infrastructure.
What is not necessarily in Switzerland — and why we say so
Writing “no data ever leaves Switzerland” would sell better, and would be untrue. Certain peripheral services involve other parties, and you are entitled to know before you sign.
Email spam filtering. In its standard configuration, it may rely on a service located in Germany: incoming messages pass through it to be analysed. A fully Swiss filtering solution is available for clients who ask for it.
Domain names. Registering a domain necessarily involves the registry for the extension concerned and the corresponding infrastructure. That chain is not Swiss as a whole, whatever the extension. It has no bearing on the location of the data you host with us.
Email itself. A message has a sender and a recipient. As soon as it leaves your organisation, it travels through your correspondents’ servers, wherever those are. No hosting provider can promise otherwise.
Apart from these cases, which we list explicitly: for D&D’s main infrastructure, virtual machines, their storage, their backups and their replications are hosted in Switzerland.
Location, access, operations: three different questions
Many offerings answer the first while hoping you will not ask the other two.
Where is the data physically? In a data centre in Switzerland, on hardware owned by D&D.
Who can technically access it? The D&D team, from Switzerland. No external provider holds administrative access to our hypervisors or to the infrastructure carrying your machines.
Who operates the infrastructure? D&D. We do not resell a third party’s capacity under our own brand, and hosting our clients’ data relies on neither AWS, nor Azure, nor Google Cloud.
These three answers hold together. An offering can perfectly well store data in Switzerland while being administered from abroad, or run on a hyperscaler’s capacity installed in Switzerland. Those are legitimate choices, but they are not the same choices, and they do not have the same consequences for you.
Regulated sectors and sensitive data
Trustees, legal professionals, financial firms, organisations handling sensitive data: these sectors have precise constraints, and we deal with them regularly.
Let us be clear on one point: hosting with D&D does not make any company “compliant” with anything. Compliance — Swiss data protection law, GDPR, sector requirements, professional obligations — depends on your processing, your organisation, your documentation and your risk assessment. It cannot be bought with a hosting contract, and you should be wary of any provider who lets you believe otherwise.
What we can provide is more modest and more useful: the factual elements your assessment needs.
- Knowing where your hosted data physically sits
- Knowing who operates it, and who holds administrative access
- Knowing which parties are involved in the chain, including peripheral services
- Having someone who can answer an auditor’s technical question in writing
- Being able to put in place a data processing agreement setting out these points
Frequently asked questions
Do you use AWS, Azure or Google Cloud?
No, not for hosting our clients’ data. The hosting infrastructure is D&D’s own: our hardware, in a Swiss data centre, administered by our team.
Can an external provider access my machines?
No external administrative access to the hypervisors or to the infrastructure is granted to any third party.
The data centre operator has physical access to the building, as any site operator does; that is a matter of the data centre’s physical security and access control, not of access to the systems.
Do my backups leave Switzerland?
No. Backups are taken and kept on D&D’s Swiss infrastructure. Where replication is put in place, it also targets infrastructure located in Switzerland.
Why do you mention the German spam filter when your competitors do not?
Because it is true, and because staying silent would leave clients who chose a Swiss provider for that very reason believing something inaccurate.
A fully Swiss alternative exists for clients who ask for it. We would rather offer a choice than an approximation.
Can you sign a data processing agreement?
Yes; this is a routine request from companies subject to particular obligations. Contact us setting out your requirements.
See also
A specific question from your auditor or IT department?
We answer technical questions about location, operations and access in writing.