One security program, two regulatory homes.
merlon operates in the United States and Switzerland, under one group security program with region-specific standards attached. This page lays out both regimes side by side — the applicable law, the standards we align to, where your data lives, who you contract with, how transatlantic transfers are handled, and which authority oversees each.
CH/EU vs US, compared
The canonical facts for each region, in one table. Both programs are live and equally supported — your applicable regime follows your contracting region.
| Switzerland & EU | United States | |
|---|---|---|
| Applicable law | Swiss nFADP; EU GDPR for EU customers | CCPA/CPRA and applicable US state privacy law |
| Standards | nFADP · GDPR · ISO 27001 (aligned) | SOC 2 Type II · HIPAA-ready · CCPA/CPRA |
| Data residency | Switzerland (ch-eu-1, Zürich) | United States (us-east-1) |
| Controlling entity | Wahlen Software GmbH (Zürich) | Wahlen Software Inc. (Delaware / New York) |
| Transfer mechanism | Swiss–US & EU–US DPF; SCCs as fallback | US Data Privacy Framework (DPF); SCCs as fallback |
| Supervisory authority | FDPIC (Switzerland); EU DPAs for EU data | FTC and applicable US state regulators |
Standards are described as aligned/mapped, not verified accreditations.
A closer look at each program
Switch regions to see the specifics of each regulatory home — the law, the entity, and the standards.
Built on the nFADP and GDPR
For Swiss and EU customers, merlon is operated by Wahlen Software GmbH in Zürich, with data stored exclusively in Switzerland. The program is built to comply with the revised Federal Act on Data Protection and, for EU customers, the GDPR — with controls aligned to ISO 27001.
- Data residency in Switzerland (ch-eu-1)
- FDPIC as supervisory authority
- Contracting entity: Wahlen Software GmbH
SOC 2-aligned, HIPAA-ready
For US customers, merlon is operated by Wahlen Software Inc., our Delaware C-Corp and global HQ, with data stored in a US region. The program aligns to SOC 2 Type II, supports HIPAA-ready workflows, and honours CCPA/CPRA rights, participating in the US Data Privacy Framework.
- Data residency in the US (us-east-1)
- FTC / state regulators oversight
- Contracting entity: Wahlen Software Inc.
How data moves — and doesn't — across the Atlantic
By default, your data stays in your region. Where a transfer is genuinely necessary, we rely on recognised transfer mechanisms with a fallback for resilience.
Swiss–US DPF
The Swiss–US Data Privacy Framework provides an adequacy-style mechanism for transfers of Swiss personal data to the United States.
EU–US DPF
The EU–US Data Privacy Framework provides the equivalent mechanism for transfers of EU personal data to the United States.
Standard Contractual Clauses
SCCs (with a Swiss addendum where relevant) serve as a contractual fallback so transfers remain lawful even if a framework changes.
Default: no transfer
Your documents and metadata stay in your region. The common case involves no transatlantic transfer at all.
If needed: DPF
For any necessary transfer, the applicable DPF provides the primary legal mechanism.
Fallback: SCCs
Standard Contractual Clauses back the arrangement so transfers remain lawful under changing conditions.
How we stay compliant
Compliance is a continuous operating discipline, not an annual scramble. Four practices keep both programs honest.
Map to controls
Every obligation in each regime is mapped to a concrete, owned technical or organisational control — not a policy PDF.
Validate continuously
Our Purple Team validates that the controls actually work, and the Blue Team monitors that they keep working.
Review & update
Records of processing, sub-processors, and transfer mechanisms are reviewed on a defined cadence and when the landscape shifts.
Common controls, mapped to both regimes
A single set of technical controls satisfies obligations across both regions. A representative mapping:
- Encryption (AES-256 / TLS 1.2+)
- nFADP privacy-by-design · GDPR Art. 32 · SOC 2 confidentiality · HIPAA safeguards
- Access control (RBAC · MFA)
- nFADP least-privilege · GDPR access limitation · SOC 2 logical access · HIPAA access management
- Audit logging
- nFADP records of processing · GDPR accountability · SOC 2 monitoring · HIPAA audit controls
- Breach response
- nFADP FDPIC notification · GDPR 72-hour rule · SOC 2 incident management
- Retention & deletion
- nFADP minimisation · GDPR storage limitation · CCPA/CPRA deletion rights
Rights we honour, in both regions
Whichever regime applies to you, individuals whose data we process can exercise their rights through defined, auditable procedures — via a single privacy contact for your region.
Access & portability
Individuals can request a copy of their personal data and, where applicable, receive it in a portable format. Recognised under nFADP, GDPR, and CCPA/CPRA.
Rectification
Inaccurate or incomplete personal data can be corrected through a defined request procedure.
Deletion / erasure
Subject to legal retention, individuals can request deletion — the GDPR right to erasure, CCPA/CPRA deletion right, and nFADP equivalents.
Objection / opt-out
Objection to certain processing and, under CCPA/CPRA, opt-out of sale/share — which we honour as a matter of policy.
Requests are handled by the controller for your region — Wahlen Software GmbH (CH/EU) or Wahlen Software Inc. (US). See the Privacy Policy.
Compliance questions
Two programs, equally supported
Neither region is an afterthought. Both run the same underlying security program with region-specific standards attached.