Location and subcontracting

Where your data is

This is the question companies ask when they come to us, and it deserves a precise answer rather than a “Swiss hosting” badge. Here is the chain, including the points where it leaves Switzerland.

The hosting chain

There is no hidden intermediary between you and the hardware. There is no third-party capacity resold under our name.

D&D hosting chain The client deals with D&D. D&D operates its own hardware, housed in a data centre located in Switzerland. Backups are also kept on D&D’s Swiss infrastructure. D&D, its hardware, the data centre and the backups are all located in Switzerland. Switzerland You or your integrator D&D your point of contact systems administration D&D hardware servers, storage, network owned by D&D Data centre Crissier (VD) building and power Backups daily, kept in Switzerland

What is in Switzerland

For D&D’s main infrastructure, without reservation.

Your virtual machines

They run on hardware owned by D&D, installed in the Crissier data centre.

Their storage

The disks of your machines and the data they hold are on D&D’s Swiss infrastructure.

Their backups

Daily backups are kept on D&D’s Swiss infrastructure.

Their replication, where applicable

Where replication is put in place, it targets another infrastructure or data centre located in Switzerland and meeting the same requirements.

Systems administration

Carried out by the D&D team, in Switzerland. No external administrative access to the hypervisors.

Support

Provided from Switzerland, by the people who operate the infrastructure.

What is not necessarily in Switzerland — and why we say so

Writing “no data ever leaves Switzerland” would sell better, and would be untrue. Certain peripheral services involve other parties, and you are entitled to know before you sign.

Email spam filtering. In its standard configuration, it may rely on a service located in Germany: incoming messages pass through it to be analysed. A fully Swiss filtering solution is available for clients who ask for it.

Domain names. Registering a domain necessarily involves the registry for the extension concerned and the corresponding infrastructure. That chain is not Swiss as a whole, whatever the extension. It has no bearing on the location of the data you host with us.

Email itself. A message has a sender and a recipient. As soon as it leaves your organisation, it travels through your correspondents’ servers, wherever those are. No hosting provider can promise otherwise.

Apart from these cases, which we list explicitly: for D&D’s main infrastructure, virtual machines, their storage, their backups and their replications are hosted in Switzerland.

Location, access, operations: three different questions

Many offerings answer the first while hoping you will not ask the other two.

Where is the data physically? In a data centre in Switzerland, on hardware owned by D&D.

Who can technically access it? The D&D team, from Switzerland. No external provider holds administrative access to our hypervisors or to the infrastructure carrying your machines.

Who operates the infrastructure? D&D. We do not resell a third party’s capacity under our own brand, and hosting our clients’ data relies on neither AWS, nor Azure, nor Google Cloud.

These three answers hold together. An offering can perfectly well store data in Switzerland while being administered from abroad, or run on a hyperscaler’s capacity installed in Switzerland. Those are legitimate choices, but they are not the same choices, and they do not have the same consequences for you.

Regulated sectors and sensitive data

Trustees, legal professionals, financial firms, organisations handling sensitive data: these sectors have precise constraints, and we deal with them regularly.

Let us be clear on one point: hosting with D&D does not make any company “compliant” with anything. Compliance — Swiss data protection law, GDPR, sector requirements, professional obligations — depends on your processing, your organisation, your documentation and your risk assessment. It cannot be bought with a hosting contract, and you should be wary of any provider who lets you believe otherwise.

What we can provide is more modest and more useful: the factual elements your assessment needs.

  • Knowing where your hosted data physically sits
  • Knowing who operates it, and who holds administrative access
  • Knowing which parties are involved in the chain, including peripheral services
  • Having someone who can answer an auditor’s technical question in writing
  • Being able to put in place a data processing agreement setting out these points

Frequently asked questions

Do you use AWS, Azure or Google Cloud?

No, not for hosting our clients’ data. The hosting infrastructure is D&D’s own: our hardware, in a Swiss data centre, administered by our team.

Can an external provider access my machines?

No external administrative access to the hypervisors or to the infrastructure is granted to any third party.

The data centre operator has physical access to the building, as any site operator does; that is a matter of the data centre’s physical security and access control, not of access to the systems.

Do my backups leave Switzerland?

No. Backups are taken and kept on D&D’s Swiss infrastructure. Where replication is put in place, it also targets infrastructure located in Switzerland.

Why do you mention the German spam filter when your competitors do not?

Because it is true, and because staying silent would leave clients who chose a Swiss provider for that very reason believing something inaccurate.

A fully Swiss alternative exists for clients who ask for it. We would rather offer a choice than an approximation.

Can you sign a data processing agreement?

Yes; this is a routine request from companies subject to particular obligations. Contact us setting out your requirements.

A specific question from your auditor or IT department?

We answer technical questions about location, operations and access in writing.