Security & data

Trust is built
in every decision.

GE2studio is designed to give the right information to the right person, retain a record of useful actions and keep people at the centre of sensitive decisions.

Accès par rôle

Everyone accesses only what they need.

Trust starts with a simple rule: everyone sees what their role requires, and no more.

01

Manager

Overall visibility, management, configuration and approval of significant actions according to assigned permissions.

Overall management · approval
02

Coach

Access focused on their classes, participants, availability and the information needed for the session, without overall finances, member cohorts or individual departure risks by default.

Their classes · useful information
03

Member

Access to their profile, bookings, credits and personal information.

Their own data only
Principes de conception

Clear access and traceable actions.

01

Role-based permissions

Capabilities are limited to operational needs. Responsibilities and access levels are defined with the studio.

02

Auditability

Important operations are designed to be attributable, timestamped and reviewable.

03

Data hygiene

Proportionate collection, structured data, consistency checks and retention rules to formalise.

04

Confirmation humaine

A recommendation can inform a decision. It does not execute a sensitive action on its own.

Explain a recommendation. Show its assumptions. Leave the final decision to the responsible person.

Trois niveaux de lecture

Designed, required, contractually confirmed: keep them distinct.

This matrix describes the level expected for the pilot. It is neither a certification nor, by itself, a contractual guarantee.

Already integrated into the design

Responsibilities & human control

Separation of Manager, Coach and Member roles, access limited to operational need, intended traceability and human confirmation of sensitive actions structure the product.

Required before go-live

Technical controls tested

Two-factor authentication for sensitive profiles, session revocation, default-deny access, strict studio separation, encryption in transit, input validation, audit logging, recovery and incident procedures must be tested.

Contractually confirmed

Hosting, data & responsibilities

Hosting provider, location, subprocessors, backups, retention, support, incident notification and responsibilities are specified in the documents applicable to the deployment.

Data protection framework

The applicable framework is checked according to the studio's country: GDPR, the revised Swiss Federal Act on Data Protection or relevant local regulations. Minimisation and aggregation remain required.

Application exchanges

Separated secrets, validated inputs, abuse prevention and signed automated calls with replay protection must be technically verified.

AI & analytics

Instructions given to AI and scenarios use the minimum necessary data. No training on a studio's data without explicit agreement and provider documentation.

Transparence

Written, verifiable commitments.

Hosting, backup, retention, subprocessors and incident-management arrangements will be specified in the contractual documentation applicable to the deployment.

No security certification is claimed on this page.

Do you have a specific security requirement?

Review the documented responsibilities, controls and limitations before deployment.

Discuss security