Evidence

The compliance file, as the application produces it

The day someone asks for your evidence, there is nothing to write: one button in the Compliance space, and out comes a dated Word document. No AI touches it: it is built from the computer’s actual logs and configuration, so it cannot say anything other than what the software does.

The “Étude Exemple” (“Example Firm”) does not exist: its controller is a fictitious person and its register was made up for the example — three processing operations on an invented matter. The structure, the measures and the retention periods are exactly what the application writes for a real practice. The file itself is in French.

What it contains

Three excerpts, translated from the file

The register of activities (Art. 12 FADP)

One entry per purpose, aggregated from every processing operation: number of operations and period, categories of data and of data subjects, recipients, country, retention period. Never any content, never a file name.

Summary of a litigation file for the insurer
Number of operations: 2 (period: 24.08.2026 → 02.09.2026)
Categories of data: correspondence, contracts, invoices
Data subjects: clients (legal entities), opposing parties
Recipients (AI sub-processors): Infomaniak (Switzerland)
Country of processing: CH
Retention: 90 days, then automatic purge

The processing rules (Art. 5 DPO, the Swiss Data Protection Ordinance)

The technical and organisational measures, written from the configuration at the time of export. Three lines among those in the file:

“Every call to an AI model is routed to Infomaniak AI Services (Switzerland): the content is processed in Switzerland, is not retained by the sub-processor and is not used to train models.”

“Forbidden folders (red list): the folders locked by the practice are physically unreadable to the agents and to the conversational assistant. State at the time of export: 0 forbidden folder(s) across 0 protected workspace(s).”

“Editing, renaming or deleting a document the user has designated applies immediately. The safeguard is then not the wait but reversibility: the original is copied to a local recycle bin and the action recorded in an undo journal before the document is touched — if the backup fails, the write is refused.”

The forbidden-folder count is that of the fictitious computer: on yours, it shows your own red list.

Logging (Art. 4 DPO), sub-processors (Art. 9), breaches (Art. 24)

The logging summary — records, period, retention of at least 365 days, independent of the content purge — the table of sub-processors with their country and their safeguards, the breach log, and the data-subject operations (exports, erasures, purges, certificates).

Records: 3 (of which 3 under sovereign processing)
Period covered: 24.08.2026 → 02.09.2026
Retention: at least 365 days (Art. 4 para. 4 DPO)
Data security breaches: none documented to date

Limits

What this file does not do

  • It only covers processing done through LEMIA. It is attached to the practice’s data-protection records; it does not replace the register of processing carried out by other means.
  • It does not make a practice “compliant”. Our measures are best-efforts obligations: full compliance depends on the data-processing agreement and on your own situation, to be confirmed with your legal adviser.
  • It does not write the rest for you. The fields only the practice knows — the controller’s identity, the purposes when you have not filled them in — are marked “to be completed”, never guessed.