Switzerland has traded on its privacy reputation for more than a century. That reputation is worth nothing to you unless the laws behind it are real. So here they are — the articles, the adequacy decision, the gap in US law that most providers would rather not discuss, and the parts Switzerland gets wrong.

"Swiss hosting" has become a marketing sticker, and plenty of companies wear it while being owned somewhere else entirely. That matters, because ownership — not the postcode of a server rack — decides which government can compel your data. Mailpro has been built and run from Geneva by Maxony since 2001. This page sets out what that actually buys you, with the citations to check, and where the limits are.
Mailpro is developed and operated by Maxony, a Swiss company in Geneva. There is no US parent, no US subsidiary and no foreign holding structure above us. Our team, our leadership and the servers holding your contact database are all in Switzerland.
The distinction does real work. A company's jurisdiction follows where it is genuinely established and controlled, not where it happens to store one database. A provider incorporated in Delaware is still a Delaware company after it switches on an "EU data region" — and still answerable to the authorities of its home country. Where your data sleeps is a detail. Whose law the company answers to is the substance.
Read our commitment →
Switzerland is not a member of the Five Eyes intelligence-sharing alliance, nor of its Nine Eyes and Fourteen Eyes extensions. It is not in the European Union and not in NATO. Its armed neutrality is not a line from the tourist board — it is the reason the country stayed outside the post-war intelligence architecture that most Western states joined.
For a company holding other people's contact databases, that absence is worth something concrete: those arrangements normalise routine, bulk exchange of intelligence between partner agencies, and Switzerland sits outside those channels. It does not mean Switzerland conducts no surveillance of its own — we come back to that below.

Four provisions do most of the work. They are public, and you are welcome to check every one of them.
Switzerland protects private and family life, the home, and mail and telecommunications at constitutional level — together with an express right to protection against the misuse of personal data. In the United States, by contrast, there is no equivalent express constitutional privacy right; protection is inferred from other amendments.
Article 28 turns that principle into a private remedy: anyone whose personality rights are unlawfully infringed can go to a civil court against all those causing the infringement, with claims for damages and for handing over profits expressly reserved. Privacy in Switzerland is not only something the state owes you — it is something you can litigate yourself.
The totally revised Federal Act on Data Protection — often called the nFADP or nLPD — came into force on 1 September 2023, repealing the 1992 Act outright, with no general transition period. It aligns Switzerland closely with the GDPR: records of processing, privacy by design and by default, impact assessments, breach notification and stricter rules on transfers abroad.
Article 271 makes it a criminal offence to carry out on Swiss soil, without authorisation, acts reserved to a Swiss authority on behalf of a foreign state. Handing your data straight to a foreign agency that approached us directly could put us in the dock — the request is expected to travel through official Swiss channels instead. Strictly, the article defends Swiss sovereignty rather than your privacy. The protection you get is a side effect — but a real one.
Not "where are your servers?" but "which country's law governs your company?" The 2018 CLOUD Act made the second question the only one that really counts.
The CLOUD Act requires providers subject to US jurisdiction to produce data in their possession, custody or control — wherever in the world it is stored. It was passed precisely to settle the question of overseas servers. So a US-headquartered platform can hold your list in Frankfurt or Dublin and still be compelled through US process. The "EU data residency" toggle in the settings panel does not change which government can knock.
The CLOUD Act reaches companies subject to US jurisdiction. Maxony is Swiss, with no US parent and no US subsidiary — there is no US entity for that process to attach to. A US authority that wants your data has to go to the Swiss authorities and ask — through mutual legal assistance, on the record, with Swiss review. That is a slower and far more accountable path than a subpoena served in California, and it is a difference of structure rather than of promises.
Sitting outside the European Union would normally add friction to every transfer. It does not here. The European Commission has recognised Switzerland as providing an adequate level of protection since Decision 2000/518/EC, and in January 2024 it reviewed the pre-GDPR adequacy decisions and confirmed Switzerland's should be maintained — including on the question of government access to data.
In practice, sending your subscriber data to Mailpro from the EU or EEA needs no Standard Contractual Clauses, no Binding Corporate Rules and no transfer impact assessment. The Commission treats such transfers as equivalent to sending data within the Union — which is exactly the paperwork, and the data residency risk, that a US provider cannot spare you.
How Mailpro handles GDPR →
Every argument above has a limit. A vendor who hides them is telling you something about how they will behave later.
A valid order from a competent Swiss authority binds us, as it would bind any company anywhere. Swiss providers do receive and execute legal orders, in meaningful numbers, every year. Anyone promising that no government can ever reach your data is selling you a feeling, not a legal position. What Switzerland changes is who may ask and through which process — not whether anyone can.
The Intelligence Service Act, in force since 2017, permits radio and cable-based signals intelligence on international traffic. In November 2025 the Federal Administrative Court found that regime, as currently constituted, incompatible with the Federal Constitution and the European Convention on Human Rights, citing weak safeguards and inadequate remedies. Parliament has been given time to fix it. We would rather point you to that ruling than pretend the debate does not exist.
In January 2025 the Federal Council opened a consultation on extending identification and metadata-retention duties to more online services. The response from industry and civil society was overwhelmingly hostile, Parliament demanded a fundamental rework, and in February 2026 the Federal Council commissioned an impact assessment and announced a second consultation. The revision has been neither adopted nor abandoned. It is a live fight, and we are on the side of the people resisting it.
You will read that claim often. It is not true in enforcement terms: the Swiss regulator cannot levy GDPR-style administrative fines on companies, and the ceilings under Swiss law are far below the GDPR's. The revised Act is closely aligned with the GDPR in principle, and Switzerland is EU-adequate — but its real advantage is jurisdictional, not punitive. That is the honest version, and it is still a good reason to be here.
Choosing a Swiss processor settles where your data lives and whose law governs it. It does not settle your own obligations. You remain the data controller: lawful consent, purpose limitation, retention and subject access requests stay with you. We give you the tools, the data processing agreement and guidance on Swiss emailing law — but we cannot be your compliance department.
Start free and keep your contact database in Geneva — protected by the law described on this page, not by a checkbox in a settings panel.