merlon
Log In
Pricing
Compliance & Regions

One security program, two regulatory homes.

merlon operates in the United States and Switzerland, under one group security program with region-specific standards attached. This page lays out both regimes side by side — the applicable law, the standards we align to, where your data lives, who you contract with, how transatlantic transfers are handled, and which authority oversees each.

nFADP · GDPR · ISO 27001 SOC 2 · HIPAA · CCPA · DPF
Region posture 2 programs · 1 control set
Switzerland & EU ch-eu-1
LawnFADP · GDPR
EntityWahlen GmbH
AuthorityFDPIC
United States us-east-1
LawCCPA/CPRA
EntityWahlen Inc.
AuthorityFTC · state
Default: no transfer · DPF + SCCs if needed
Side by side

CH/EU vs US, compared

The canonical facts for each region, in one table. Both programs are live and equally supported — your applicable regime follows your contracting region.

  Switzerland & EU United States
Applicable lawSwiss nFADP; EU GDPR for EU customersCCPA/CPRA and applicable US state privacy law
StandardsnFADP · GDPR · ISO 27001 (aligned)SOC 2 Type II · HIPAA-ready · CCPA/CPRA
Data residencySwitzerland (ch-eu-1, Zürich)United States (us-east-1)
Controlling entityWahlen Software GmbH (Zürich)Wahlen Software Inc. (Delaware / New York)
Transfer mechanismSwiss–US & EU–US DPF; SCCs as fallbackUS Data Privacy Framework (DPF); SCCs as fallback
Supervisory authorityFDPIC (Switzerland); EU DPAs for EU dataFTC and applicable US state regulators

Standards are described as aligned/mapped, not verified accreditations.

Per region

A closer look at each program

Switch regions to see the specifics of each regulatory home — the law, the entity, and the standards.

Swiss & European program

Built on the nFADP and GDPR

For Swiss and EU customers, merlon is operated by Wahlen Software GmbH in Zürich, with data stored exclusively in Switzerland. The program is built to comply with the revised Federal Act on Data Protection and, for EU customers, the GDPR — with controls aligned to ISO 27001.

  • Data residency in Switzerland (ch-eu-1)
  • FDPIC as supervisory authority
  • Contracting entity: Wahlen Software GmbH
nFADPGDPRISO 27001Swiss residency
nFADP
GDPR
ISO 27001
Swiss residency
United States program

SOC 2-aligned, HIPAA-ready

For US customers, merlon is operated by Wahlen Software Inc., our Delaware C-Corp and global HQ, with data stored in a US region. The program aligns to SOC 2 Type II, supports HIPAA-ready workflows, and honours CCPA/CPRA rights, participating in the US Data Privacy Framework.

  • Data residency in the US (us-east-1)
  • FTC / state regulators oversight
  • Contracting entity: Wahlen Software Inc.
SOC 2 Type IIHIPAA-readyCCPA/CPRAUS DPF
SOC 2 Type II
HIPAA-ready
CCPA / CPRA
US DPF
Transatlantic transfers

How data moves — and doesn't — across the Atlantic

By default, your data stays in your region. Where a transfer is genuinely necessary, we rely on recognised transfer mechanisms with a fallback for resilience.

Swiss–US DPF

The Swiss–US Data Privacy Framework provides an adequacy-style mechanism for transfers of Swiss personal data to the United States.

EU–US DPF

The EU–US Data Privacy Framework provides the equivalent mechanism for transfers of EU personal data to the United States.

Standard Contractual Clauses

SCCs (with a Swiss addendum where relevant) serve as a contractual fallback so transfers remain lawful even if a framework changes.

Default: no transfer

Your documents and metadata stay in your region. The common case involves no transatlantic transfer at all.

If needed: DPF

For any necessary transfer, the applicable DPF provides the primary legal mechanism.

Fallback: SCCs

Standard Contractual Clauses back the arrangement so transfers remain lawful under changing conditions.

Operating model

How we stay compliant

Compliance is a continuous operating discipline, not an annual scramble. Four practices keep both programs honest.

Map to controls

Every obligation in each regime is mapped to a concrete, owned technical or organisational control — not a policy PDF.

Validate continuously

Our Purple Team validates that the controls actually work, and the Blue Team monitors that they keep working.

Review & update

Records of processing, sub-processors, and transfer mechanisms are reviewed on a defined cadence and when the landscape shifts.

Controls mapping

Common controls, mapped to both regimes

A single set of technical controls satisfies obligations across both regions. A representative mapping:

Encryption (AES-256 / TLS 1.2+)
nFADP privacy-by-design · GDPR Art. 32 · SOC 2 confidentiality · HIPAA safeguards
Access control (RBAC · MFA)
nFADP least-privilege · GDPR access limitation · SOC 2 logical access · HIPAA access management
Audit logging
nFADP records of processing · GDPR accountability · SOC 2 monitoring · HIPAA audit controls
Breach response
nFADP FDPIC notification · GDPR 72-hour rule · SOC 2 incident management
Retention & deletion
nFADP minimisation · GDPR storage limitation · CCPA/CPRA deletion rights
Individual rights

Rights we honour, in both regions

Whichever regime applies to you, individuals whose data we process can exercise their rights through defined, auditable procedures — via a single privacy contact for your region.

Access & portability

Individuals can request a copy of their personal data and, where applicable, receive it in a portable format. Recognised under nFADP, GDPR, and CCPA/CPRA.

Rectification

Inaccurate or incomplete personal data can be corrected through a defined request procedure.

Deletion / erasure

Subject to legal retention, individuals can request deletion — the GDPR right to erasure, CCPA/CPRA deletion right, and nFADP equivalents.

Objection / opt-out

Objection to certain processing and, under CCPA/CPRA, opt-out of sale/share — which we honour as a matter of policy.

Requests are handled by the controller for your region — Wahlen Software GmbH (CH/EU) or Wahlen Software Inc. (US). See the Privacy Policy.

An honest word on certifications

We describe our controls as aligned with, designed to comply with, or mapped to the relevant standards and frameworks. Where a standard implies formal certification or accreditation, we do not claim to hold it unless we do. This page is informational and not legal advice; for contractual specifics, see your DPA and Privacy Policy.

Questions

Compliance questions

Which regime applies to me?
It follows your contracting region. Americas customers contract with Wahlen Software Inc. under the US program; EU/EFTA/Switzerland/RoW customers contract with Wahlen Software GmbH under the CH/EU program.
Do you transfer my data across the Atlantic?
Not by default — your data stays in your region. Where a transfer is necessary, we rely on the applicable Data Privacy Framework, with Standard Contractual Clauses as a fallback.
Are you actually ISO 27001 certified?
Our controls are aligned to ISO 27001. We describe standards as aligned/mapped rather than claiming accreditation we do not hold. See the disclaimer above.
Where do I get the DPA and privacy details?
In the Trust Center, along with the DPA (with regional annexes) and the Privacy Policy.
At a glance

Two programs, equally supported

Neither region is an afterthought. Both run the same underlying security program with region-specific standards attached.

2
Regulatory homes
US & CH/EU
2
Contracting entities
Inc. & GmbH
DPF
+ SCCs fallback
for transfers
1
Group security program
follow-the-sun SOC

Have a compliance question we didn't answer?

Our team can walk your legal and security stakeholders through either regional program in detail.

Talk to Sales

Keep your documents, vaults, and audit data secure with AES-256 encryption, immutable audit trail, and regional residency on every plan.Learn more