A reputation is not a guarantee

"Swiss hosting" has become a marketing sticker, and plenty of companies wear it while being owned somewhere else entirely. That matters, because ownership — not the postcode of a server rack — decides which government can compel your data. Mailpro has been built and run from Geneva by Maxony since 2001. This page sets out what that actually buys you, with the citations to check, and where the limits are.

Effective jurisdiction

Geneva is our home, not our mailbox

Mailpro is developed and operated by Maxony, a Swiss company in Geneva. There is no US parent, no US subsidiary and no foreign holding structure above us. Our team, our leadership and the servers holding your contact database are all in Switzerland.

The distinction does real work. A company's jurisdiction follows where it is genuinely established and controlled, not where it happens to store one database. A provider incorporated in Delaware is still a Delaware company after it switches on an "EU data region" — and still answerable to the authorities of its home country. Where your data sleeps is a detail. Whose law the company answers to is the substance.

Read our commitment
Swiss infrastructure operated from Geneva
Neutrality

The alliances Switzerland doesn't join

Switzerland is not a member of the Five Eyes intelligence-sharing alliance, nor of its Nine Eyes and Fourteen Eyes extensions. It is not in the European Union and not in NATO. Its armed neutrality is not a line from the tourist board — it is the reason the country stayed outside the post-war intelligence architecture that most Western states joined.

For a company holding other people's contact databases, that absence is worth something concrete: those arrangements normalise routine, bulk exchange of intelligence between partner agencies, and Switzerland sits outside those channels. It does not mean Switzerland conducts no surveillance of its own — we come back to that below.

Swiss neutrality and data protection
THE LAW ITSELF

What Swiss law actually says

Four provisions do most of the work. They are public, and you are welcome to check every one of them.

Federal Constitution · Art. 13

Privacy is a constitutional right

Switzerland protects private and family life, the home, and mail and telecommunications at constitutional level — together with an express right to protection against the misuse of personal data. In the United States, by contrast, there is no equivalent express constitutional privacy right; protection is inferred from other amendments.

Civil Code · Art. 28

And a right you can personally enforce

Article 28 turns that principle into a private remedy: anyone whose personality rights are unlawfully infringed can go to a civil court against all those causing the infringement, with claims for damages and for handing over profits expressly reserved. Privacy in Switzerland is not only something the state owes you — it is something you can litigate yourself.

Data Protection Act · SR 235.1

Data protection, rebuilt in 2023

The totally revised Federal Act on Data Protection — often called the nFADP or nLPD — came into force on 1 September 2023, repealing the 1992 Act outright, with no general transition period. It aligns Switzerland closely with the GDPR: records of processing, privacy by design and by default, impact assessments, breach notification and stricter rules on transfers abroad.

Criminal Code · Art. 271

Foreign authorities must use the front door

Article 271 makes it a criminal offence to carry out on Swiss soil, without authorisation, acts reserved to a Swiss authority on behalf of a foreign state. Handing your data straight to a foreign agency that approached us directly could put us in the dock — the request is expected to travel through official Swiss channels instead. Strictly, the article defends Swiss sovereignty rather than your privacy. The protection you get is a side effect — but a real one.

THE CLOUD ACT GAP

The question to ask any provider

Not "where are your servers?" but "which country's law governs your company?" The 2018 CLOUD Act made the second question the only one that really counts.

A US-owned provider

An EU region changes the address, not the jurisdiction

The CLOUD Act requires providers subject to US jurisdiction to produce data in their possession, custody or control — wherever in the world it is stored. It was passed precisely to settle the question of overseas servers. So a US-headquartered platform can hold your list in Frankfurt or Dublin and still be compelled through US process. The "EU data residency" toggle in the settings panel does not change which government can knock.

Mailpro

No US entity, so no US lever

The CLOUD Act reaches companies subject to US jurisdiction. Maxony is Swiss, with no US parent and no US subsidiary — there is no US entity for that process to attach to. A US authority that wants your data has to go to the Swiss authorities and ask — through mutual legal assistance, on the record, with Swiss review. That is a slower and far more accountable path than a subpoena served in California, and it is a difference of structure rather than of promises.

EU adequacy

Outside the EU, but not outside its trust

Sitting outside the European Union would normally add friction to every transfer. It does not here. The European Commission has recognised Switzerland as providing an adequate level of protection since Decision 2000/518/EC, and in January 2024 it reviewed the pre-GDPR adequacy decisions and confirmed Switzerland's should be maintained — including on the question of government access to data.

In practice, sending your subscriber data to Mailpro from the EU or EEA needs no Standard Contractual Clauses, no Binding Corporate Rules and no transfer impact assessment. The Commission treats such transfers as equivalent to sending data within the Union — which is exactly the paperwork, and the data residency risk, that a US provider cannot spare you.

How Mailpro handles GDPR
EU adequacy and Swiss data transfers
THE HONEST PART

What Switzerland is not

Every argument above has a limit. A vendor who hides them is telling you something about how they will behave later.

Switzerland is not a place beyond the law

A valid order from a competent Swiss authority binds us, as it would bind any company anywhere. Swiss providers do receive and execute legal orders, in meaningful numbers, every year. Anyone promising that no government can ever reach your data is selling you a feeling, not a legal position. What Switzerland changes is who may ask and through which process — not whether anyone can.

Switzerland is not free of state surveillance

The Intelligence Service Act, in force since 2017, permits radio and cable-based signals intelligence on international traffic. In November 2025 the Federal Administrative Court found that regime, as currently constituted, incompatible with the Federal Constitution and the European Convention on Human Rights, citing weak safeguards and inadequate remedies. Parliament has been given time to fix it. We would rather point you to that ruling than pretend the debate does not exist.

Swiss surveillance law is being fought over right now

In January 2025 the Federal Council opened a consultation on extending identification and metadata-retention duties to more online services. The response from industry and civil society was overwhelmingly hostile, Parliament demanded a fundamental rework, and in February 2026 the Federal Council commissioned an impact assessment and announced a second consultation. The revision has been neither adopted nor abandoned. It is a live fight, and we are on the side of the people resisting it.

Swiss law is not "stricter than the GDPR"

You will read that claim often. It is not true in enforcement terms: the Swiss regulator cannot levy GDPR-style administrative fines on companies, and the ceilings under Swiss law are far below the GDPR's. The revised Act is closely aligned with the GDPR in principle, and Switzerland is EU-adequate — but its real advantage is jurisdictional, not punitive. That is the honest version, and it is still a good reason to be here.

And Swiss hosting does not make you compliant

Choosing a Swiss processor settles where your data lives and whose law governs it. It does not settle your own obligations. You remain the data controller: lawful consent, purpose limitation, retention and subject access requests stay with you. We give you the tools, the data processing agreement and guidance on Swiss emailing law — but we cannot be your compliance department.

QUESTIONS

Frequently asked questions

Is Mailpro subject to the US CLOUD Act?
No. The CLOUD Act reaches providers subject to United States jurisdiction. Mailpro is operated by Maxony, a Swiss company in Geneva, with no US parent and no US subsidiary, so US authorities have no direct route to compel our customer data. This is a structural difference rather than a policy one: a US-headquartered provider cannot opt out of the CLOUD Act by storing data in Europe, because the law follows the company rather than the server. See our FAQ on email marketing data and US law.
Do I need Standard Contractual Clauses to send data to Mailpro from the EU?
No. The European Commission recognises Switzerland as providing an adequate level of data protection under Decision 2000/518/EC, and confirmed that finding in its January 2024 review of the pre-GDPR adequacy decisions. Personal data can flow from the EU and EEA to a Swiss processor without SCCs, Binding Corporate Rules or a transfer impact assessment. Adequacy is reviewed periodically rather than granted permanently — see also GDPR and companies outside Europe.
Where exactly is my data stored?
Your contact database, campaign content and statistics are stored in our Swiss data center. Mailpro is developed and operated from Geneva by Maxony, and has been since 2001. More detail in the security of your data.
Can Swiss authorities access my data?
Yes, through due process — and we would rather say so than imply otherwise. No jurisdiction places a company beyond the reach of its own courts, and any provider claiming otherwise is misleading you. A valid order from a competent Swiss authority is binding on us. The meaningful difference is procedural: requests pass through Swiss judicial channels with review and redress attached, and foreign authorities cannot serve us directly but must use mutual legal assistance.
Is Swiss data protection law stricter than the GDPR?
Not in enforcement terms. The revised Federal Act on Data Protection, in force since 1 September 2023, is closely aligned with the GDPR in its principles, but the Swiss regulator cannot impose GDPR-style administrative fines on companies. Switzerland's advantage is jurisdictional rather than punitive: it sits outside US legal process while remaining EU-adequate. Read why hosting location matters.
Does Swiss hosting cover my own GDPR obligations?
No, and this is a common and expensive misunderstanding. Swiss hosting addresses where your data lives and which law governs your processor. You remain the data controller: consent, purpose limitation, retention periods and honouring subject access requests are still yours. Mailpro provides the tools and the data processing agreement to support that — see our privacy policy — but it cannot assume your role.

Your subscribers, under Swiss law

Start free and keep your contact database in Geneva — protected by the law described on this page, not by a checkbox in a settings panel.