Legal information

Privacy notice

How WEBish processes, protects and deletes personal data on this website and in Accident Tool.

1. Controller

WEBish GmbH
Bärenweg 31
4153 Reinach BL
Switzerland

Email: Contact us via the form
Phone: +41 76 570 22 70

WEBish GmbH is responsible for this website. For customer-specific deployments of Accident Tool, data-protection roles may be allocated differently by contract, for example where WEBish processes data on behalf of an insurer or another organisation.

2. Scope

This privacy notice applies to the website webish.ch and to personal-data processing in connection with Accident Tool where WEBish is responsible for that processing.

Swiss data-protection law applies. Where the EU General Data Protection Regulation also applies in a specific case, its requirements are taken into account as well.

3. Data when visiting the website

When you visit this website, technically necessary connection and log data may be processed, such as IP address, access time, requested page, browser and device information and technical error data. These data are used to operate the website securely and reliably and to prevent misuse.

In the current website implementation, no analytics or advertising tracking services are used and no marketing profiles are created from website visits.

4. Contact form and email

If you contact us through the contact form or by email, we process the information you provide in order to handle your enquiry and communicate with you. This may include your name, company, contact details and the content of your message.

These data are retained for as long as necessary to handle the enquiry, maintain a business relationship or comply with statutory retention obligations.

5. QR codes and data exchange

QR codes for data exchange are created in three places, with different data processing:

In the app (“Share profile”): the code is generated on the device and scanned directly from the screen by the other party. No data is transmitted to WEBish.

On this website (QR-code generator): the entered data is processed locally in the browser and is not transmitted to WEBish.

Via the partner interface: insurers and brokers under contract can have QR codes generated for their insured customers, for example for printing on an insurance card. The partner sends policyholder and vehicle data to the WEBish server, which generates the code and returns it. These data are not stored; they exist only for the duration of the request. The respective partner is responsible for the lawfulness of this transmission.

6. Data Accident Tool may process

Depending on the claim, the following data may be processed:

  • personal and contact details of the parties
  • vehicle, registration and insurance data
  • policy and Green Card numbers
  • driving-licence data where recorded
  • drivers, occupants, witnesses and other involved persons
  • accident location, time, weather and light conditions
  • damage type, circumstances, point of first impact and remarks
  • photos, sketches and signatures
  • information about injuries where recorded for the claim
  • device location data to determine the accident location, if location permission has been granted
  • observations about an unknown other party, such as colour or parts of a registration plate in a hit-and-run
  • a contact address chosen by the reporting person for practice reports

Information about injuries may constitute sensitive personal data and is protected accordingly.

Weather data: The app can automatically determine weather and light conditions at the time of the accident. For this purpose, the accident location is transmitted to Apple’s WeatherKit service; Apple receives the coordinates, but no information about the accident or persons. Apple’s privacy provisions apply.

7. Why accident and personal data are sent to the server

The current app architecture requires temporary server processing to create and deliver the claim report. After confirmation in the app, the data recorded for the claim are transmitted to the Accident Tool server infrastructure.

The server creates the required reports and data formats, generates the PDF in the language of each recipient and transmits the intended information to connected interfaces or recipients.

8. Server processing period and deletion

The personal data recorded for a claim are stored on the server in encrypted form (AES-256-GCM). The key is held exclusively on the server; decryption takes place only when the report is generated, delivered or made available again in response to an authorised request.

The data are retained for 30 days from receipt of the report and then deleted automatically. This period is required so that connected insurers can retrieve the report via the interface, so that the app can recover a lost copy of the report, and so that a report is not delivered twice if the app sends it again. An insurer may agree a shorter period; a longer period is not possible.

Practice reports (test mode of the app) are deleted after 7 days.

Deletion removes the entire encrypted content of the report, including persons, vehicles, contact data, photos, sketches and signatures, as well as the recipient addresses used for delivery. Deletion is performed by a daily automated process; there may therefore be up to 24 hours between expiry of the retention period and actual deletion.

What remains after deletion is a record without personal reference: the report identifier, time, country, damage type, the insurers involved and the delivery routes with status. This record demonstrates that a report was received and delivered and is used to answer follow-up questions from recipients. It contains no information about persons.

The PDF generated by the server is returned to the app and stored in the archive on the device. The user is responsible for this copy; it is not subject to the server’s deletion period.

9. Statistical data without personal reference

Independently of the report, one statistical record without personal reference is stored permanently. It contains: time and location of the accident (coordinates, municipality, postcode, country), damage type and cause, vehicle types, insurers involved, number of parties, accident circumstances, point of impact, weather and light conditions, and whether a connected insurer was supplied.

It does not contain names, contact details, registration plates, policy numbers, driving-licence data, photos, sketches, signatures, remarks or any other information that directly identifies a person. Practice reports are not included in the statistics.

These data are used to analyse accident events and further develop the product.

9a. Interface usage statistics

WEBish counts access to Accident Tool interfaces by day, app version and operating system. Devices or persons are not identified and no device identifiers are stored. The count is used for operation and to decide when old interface versions can be discontinued.

9b. Practice reports

The app offers a practice mode. A practice report follows the same technical path as a real report, but is delivered exclusively to the email address provided by the reporting person. If the reporting person selects an insurer that is a WEBish contractual partner, the report is additionally made available in that insurer’s interface marked as a test so that the insurer can check its integration. Practice reports are never billed, are not included in statistics and are deleted after 7 days.

10. Recipients

For each party involved, the server determines exactly one responsible recipient in this order: a self-regulating broker, if specified; for an accident in the insurer’s country, that insurer’s claims service; for an accident abroad, the insurer’s representative in the country of the accident under the Green Card system; otherwise the national insurance bureau of the country of the accident. If the other party is unknown or uninsured, the reporting person receives the contact details of the responsible guarantee fund; no data are transmitted to the fund itself.

Delivery is made by email with the report as a PDF. Insurers and brokers under contract instead receive the report in structured form via an interface from which they can retrieve it within the 30-day period. Each recipient receives only the information intended for that recipient.

Repair shops receive no data; they are merely named in the report if the reporting person has specified one.

11. Data security

WEBish protects personal data through appropriate technical and organisational measures against unauthorised access, loss, misuse and unlawful alteration. Server processing is restricted to the systems and processes technically required.

Because no electronic transmission is completely risk-free, absolute security against every conceivable threat cannot be guaranteed despite strong safeguards.

Access to server administration is restricted to WEBish. Encrypted report content is not opened during administrative operation.

12. Service providers and processors

Specialised service providers may be used for operation, hosting, communications or technical infrastructure. Where they process personal data on behalf of WEBish, they are contractually required to process the data only for the defined purpose and with appropriate protection.

If data are processed outside Switzerland or the European Economic Area, WEBish ensures appropriate protection through the legally required safeguards where necessary.

The Accident Tool servers are operated by a hosting provider in the European Union. Personal data are stored there only in encrypted form and only for the period specified in section 8. The provider’s backups may contain the encrypted data for the duration of its backup cycle; without the key, which is held only on the server, they cannot be read.

The app obtains weather data from Apple (WeatherKit), see section 6.

13. External links and the App Store

This website contains links to external services, including the Apple App Store. When you open an external link, the privacy rules of that provider apply. WEBish has no control over the data processing of those external services.

14. Your rights

Under applicable data-protection law, you may in particular request information about personal data processed about you and ask for inaccurate data to be corrected. Depending on the applicable law and processing, you may also have rights to deletion, restriction, data access or portability and objection.

Requests may be sent to WEBish using the contact details above. Where the legal requirements are met, you may also lodge a complaint with the competent data-protection supervisory authority.

15. Changes to this privacy notice

WEBish may update this privacy notice if the technical processing, the product or legal requirements change. The version published on this website is the current version.

Last updated: 7 September 2026