Privacy policy
This translation is provided for convenience; the German version is legally binding. Draft, to be legally reviewed before publication. The Swiss Federal Act on Data Protection (FADP) is authoritative. Where persons in the EU are affected, the GDPR applies in addition.
- Controller: Ivo Schönberner, Bärenweidstrasse 1, 8833 Samstagern, Switzerland. Contact for data protection matters: privacy@sacosi.ch.
- No cookies: This website sets no cookies and does not embed any third-party analytics or advertising services. Your choice in the role selector and your language choice are stored locally by your browser (localStorage, and sessionStorage for the note on the other language version); they are not transmitted to us.
- Server-side logging (Web-Signal): With every page request, we process technical request data: requested path, time, status code, a device class (desktop, mobile, tablet) or the name of a recognised crawler and, where transmitted by Cloudflare, the country, autonomous system (ASN) and organisation name of the requesting network. The IP address is not stored in the process, not even in truncated form. Instead, we form a one-way hash from the IP address, user agent and a daily changing date component, which only allows returning visitors to be distinguished within one day. Purpose: recognising search engine and AI crawlers, distinguishing company from private connections for a simple visitor situation picture, and protection against misuse. Legal basis: legitimate interest in operation, security and reach measurement (Art. 31 para. 2 let. a and g FADP; where the GDPR applies, Art. 6(1)(f) GDPR). Retention: 13 months, then automated deletion.
- Fonts and media: All fonts, images and videos are delivered by this website itself. No requests go to Google Fonts or other third-party providers.
- Hosting: The website is delivered via Cloudflare Pages (Cloudflare, Inc., USA). When the site is accessed, technically necessary connection data is processed. Purpose: delivery of the page, protection against misuse and attacks. Legal basis: legitimate interest in the reliable operation of the website (Art. 31 para. 2 let. a FADP or Art. 6(1)(f) GDPR).
- Contact form and appointment booking: If you fill in the contact form, write an email or book an appointment, we process your details (name, company, email address, phone number, message) to handle your enquiry. No IP address is stored with the contact form. Legal basis: pre-contractual steps or your consent by submitting (Art. 31 para. 2 let. b and c FADP or Art. 6(1)(b) and (a) GDPR). Appointment bookings and emails run via Microsoft 365. Form details are additionally stored in a self-hosted TwentyCRM instance of IT am Main GmbH. Retention: as long as the enquiry or business relationship requires and no statutory retention obligations stand in the way. Legal review pending: check the article references to Art. 31 FADP in this text (taken over from the Web-Signal module); confirm the location of the CRM instance; data processing agreement between Ivo Schönberner and IT am Main GmbH.
- Assistant on the FAQ page: If you ask the assistant on the FAQ page a question, your question, up to six previous messages of the conversation and matching excerpts from this website are sent via Cloudflare (Cloudflare, Inc., USA; encrypted tunnel) to a server operated by us in Switzerland. There, a language model running on our own hardware generates the answer; no external AI service is used. We store neither your questions nor the answers. To protect against misuse, we count questions per day: for this we form a non-reversible hash from your IP address, the date and a secret salt, valid only for that day; only this hash and a counter are stored, not the IP address. Hashes and counters of previous days are deleted automatically during later requests. Legal basis: legitimate interest in offering information and in protection against misuse (Art. 31 para. 2 FADP or Art. 6(1)(f) GDPR). Please do not enter personal data or confidential information in the chat. Legal review pending: transit via Cloudflare (USA) and safeguards under Art. 16 f. FADP; confirmation that the server in Switzerland does not log inputs; check the reference to Art. 31 FADP.
Regulatory Check
Draft, legal review pending. Purpose, legal basis and retention period are proposals and must be legally reviewed before going live.
- Without a request: The check calculates in your browser. Your inputs (role, industry, employees, markets, activities, role towards customers) are not transmitted to us and not stored.
- With a request for the detailed evaluation: If you request the evaluation, we store your name, email address, company, role, your inputs, the result (the applicable standards), the wording of your consent with time and page, and your IP address. The data is transferred to our CRM (TwentyCRM of IT am Main GmbH).
- Purpose: To send you the detailed evaluation, to contact you about it and to assign the request to a company. The IP address serves as evidence of consent, to assign the request and to protect against misuse.
- Legal basis: Your consent (Art. 31 para. 1 FADP; where the GDPR applies, Art. 6(1)(a) GDPR). You can withdraw your consent at any time by email to the address given above; processing carried out until then remains lawful.
- Retention period (proposal): Contact details, inputs and result until withdrawal, at most 24 months after the last contact (deletion not yet automated). The IP address is automatically removed from the website’s database after 180 days at the next processing run; the same period still has to be set up in the CRM.
- Recipients: Cloudflare (storage in the website’s database), Microsoft 365 (sending the evaluation by email), IT am Main GmbH (CRM).
- Disclosure abroad: Recipients outside Switzerland are Cloudflare, Inc. (USA, hosting, logging, form data) and Microsoft (USA/EU, email and appointment booking via Microsoft 365). Legal review pending: check the safeguards under Art. 16 f. FADP (or Art. 44 ff. GDPR) for Cloudflare and Microsoft contractually and name them here.
- Your rights: Access, rectification, erasure and withdrawal of consent under Art. 25 ff. FADP (or Art. 15 ff. GDPR, where applicable). Please contact privacy@sacosi.ch. Complaints can be sent to complaints@sacosi.ch; this does not affect your right to contact the Federal Data Protection and Information Commissioner (FDPIC).