Capability
Security & data protection
Compliant with the revised Swiss Act and the GDPR in operation, not just on paper. Operation in Switzerland is possible.

Built in, not bolted on.
Consent as a state.
Per channel, with evidence, effective immediately and everywhere.
Traceable.
Changes, exports and approvals are logged.
Your location.
Switzerland, Europe or your own infrastructure.
Data protection is not a chapter in the manual. It is built into the system.
There are two ways to make a marketing system compliant. One is an operating instruction: never do X, always remember to check Y. The other is to build the system so the wrong action cannot happen in the first place.
Caymland M4 takes the second road.
Consent as a state, not a tick box
- Single and double opt-in with time, source and evidence. You know not only that someone consented, but when and through which form.
- Unsubscribes with a reason. Unsubscribed themselves, blocked manually, hard bounce, soft bounce, suppression list. The difference has legal and practical consequences, and the system knows it.
- Separated by channel. Unsubscribing from the newsletter does not automatically mean an appointment confirmation by SMS is unwelcome.
- A preference centre, where your contacts steer for themselves what they want to receive.
- Frequency rules, so nobody is overrun.
A block takes effect immediately and everywhere. There is no sequence that can get around it because it happens to be running.
Access, correction, deletion
In daily practice, data subject rights are above all a question of findability.
- Access: all data about a person sits in one profile, history included, and can be exported.
- Correction: changes are made in one place and take effect everywhere.
- Deletion: a contact can be removed completely. Suppression lists are untouched by that, so a deleted person is not written to again by the next import.
- Retention: retention periods are configurable for log data, so not everything simply piles up forever.
Traceability instead of trust
Who changed which field, and when? Who exported which contacts? Who published a campaign?
That is in the log, not in the memory of those involved. In a supervisory enquiry, an internal audit or an incident, that is the difference between an answer and a guess.
Access that matches your organisation
- Roles and permissions down to individual areas and actions. Viewing, editing, deleting and publishing can be granted separately.
- Distinguish your own data from other people's: field sales sees its contacts, management sees all of them.
- Two-factor authentication for additional security when signing in.
- Single sign-on through your company's identity management, so accounts are granted centrally and withdrawn centrally when someone leaves.
- Separate access for interfaces, with their own restricted permissions.
You decide where your data lives
Operation is possible in Switzerland or in Europe, and on request in your own infrastructure. For Swiss companies under the revised Data Protection Act and for European companies under the GDPR, that settles the decisive question before it is asked.
On top come the technical matters of course: encrypted transmission, encrypted storage of sensitive credentials, regular backups, controlled updates.
Tracking stays clean too
Behavioural data is valuable, but only when it was collected lawfully. Caymland M4 works with consent logic rather than with "it will probably be fine". Analysis and interest recognition are designed so they can be operated under the revised Swiss Act and the GDPR, instead of being an open flank.
What this looks like day to day
The access request. A customer wants to know what data you hold about her. Instead of searching three systems, you open one profile and export it.
The staff change. An employee leaves the company. Access is withdrawn centrally, her contacts pass to her successor, and the log keeps showing what she worked on.
The data protection audit. Instead of a presentation you show the system: consents with dates, unsubscribe reasons, the change log, the permission model.
Questions & answers
Frequently asked questions
Is Caymland M4 compliant with the revised Swiss Act and the GDPR?
The system brings the necessary capabilities: consent records, data subject rights, logging, a permission model, deletion options and data processing agreements. Compliance always arises from the system and how it is used together. We accompany you through the setup.
Can we host in Switzerland?
Yes. Operation in Switzerland, in Europe or in your own environment.
Do we get a data processing agreement?
Yes, as part of the hosting.
What about the security of accounts?
Two-factor authentication and single sign-on are available, and interface access can be granted separately and restricted.
The difference in one sentence




































