Privacy Policy
Privacy Policy
Last updated: [DATE]
1. Controller
The controller responsible for the processing of personal data on this website (https://consulting.evrtng.cloud) is:
[COMPANY LEGAL NAME]
[STREET ADDRESS]
[CITY ZIP] [SWITZERLAND]
Email: [EMAIL]
Phone: [PHONE]
You can contact us at any time using the details above for any questions regarding the processing of your personal data or to exercise your data protection rights.
2. Scope and applicable law
2.1 This Privacy Policy describes how [COMPANY LEGAL NAME] (“EVRTNG Consulting”, “we”, or “us”) collects, uses, and discloses personal data when you visit this website or contact us through the contact form.
2.2 We process personal data in accordance with the revised Swiss Federal Act on Data Protection (FADP) of 25 September 2020, in force since 1 September 2023, and the accompanying Data Protection Ordinance. Where we provide services to clients or data subjects in the European Union, we also comply with the General Data Protection Regulation (GDPR) to the extent it applies.
2.3 This Privacy Policy does not cover the processing of personal data in the context of individual consulting engagements, which is governed by the engagement letter and applicable data processing agreements.
3. Data we collect
3.1 Contact form data. When you submit the contact form on this website, we collect the following personal data:
- Your name
- Your email address
- The content of your message
- The date and time of submission
- The IP address from which the form was submitted (collected automatically by the web server and the form plugin)
3.2 Correspondence data. When you contact us by email or through LinkedIn, we collect the personal data you choose to provide, including your name, contact details, and the content of your communication.
3.3 Technical data. When you visit this website, our web server automatically collects certain technical data, including:
- IP address
- Date and time of access
- The website from which you accessed us (referer URL)
- The pages visited on this website
- Browser type and version, and operating system
3.4 We do not operate an online shop, we do not offer user accounts (other than internal WordPress administration), and we do not run a newsletter. We do not collect payment data through this website.
4. Purposes and legal basis
4.1 We process personal data only for specific, legitimate purposes, in accordance with the principles of Articles 6 and 8 of the FADP.
4.2 Contact form and correspondence. We process the data you submit through the contact form or in correspondence in order to respond to your enquiry, to prepare a potential consulting engagement, and to maintain a record of our communication. The legal basis is our overriding legitimate interest in responding to enquiries and conducting business, in accordance with Article 31 paragraph 2 of the FADP. We retain this data for the duration of the enquiry and for a reasonable period thereafter to document the contact.
4.3 Technical data. We process technical data for the security and stability of the website, for the detection and prevention of misuse, and for the technical operation of the service. The legal basis is our overriding legitimate interest in operating a secure and functional website. We retain this data for a limited period, typically up to 30 days for IP addresses in the access logs.
4.4 Legal obligations. Where we are required by law to retain or disclose personal data, for example for accounting or tax purposes, we do so on the basis of the relevant legal provisions.
5. Recipients of personal data
5.1 We do not sell personal data and do not use it for advertising purposes.
5.2 We disclose personal data to the following categories of recipients:
(a) Hosting providers that host this website and process data on our behalf, located in Switzerland or the European Economic Area.
(b) Service providers we use to operate the website, including the WordPress content management system and the WPForms plugin used for the contact form.
(c) LinkedIn Corporation, where you contact us through LinkedIn. LinkedIn processes data on its own platform under its own terms. We have no influence on LinkedIn’s data processing.
(d) Authorities and courts, where we are required by law to disclose personal data.
5.3 Our processors act on our behalf and under our instructions. They are bound by written agreements that impose appropriate data protection obligations.
6. International data transfers
6.1 Personal data is processed primarily in Switzerland. Where data is transferred to service providers located outside Switzerland, this is done in accordance with the FADP and, where applicable, the GDPR.
6.2 Transfers to the European Economic Area are permitted on the basis of an adequate level of data protection, in accordance with Article 16 of the FADP.
6.3 For transfers to other countries, we rely on appropriate safeguards such as Standard Contractual Clauses, or on exceptions permitted by law. A list of countries to which personal data may be transferred includes Switzerland, the member states of the European Economic Area, and the United States of America, where our service providers operate.
7. Data security
7.1 We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure, in accordance with Article 7 of the FADP. These measures include encrypted transmission (TLS), access controls, regular updates of the website software, and restricted access to personal data within our organisation.
7.2 Despite our efforts, no method of transmission over the internet or electronic storage is fully secure. We cannot guarantee absolute security.
8. Your data protection rights
8.1 Under the FADP, you have the following rights regarding your personal data:
(a) Right of access. You may request information about whether we process personal data concerning you and, if so, what data is processed, the purposes, the recipients, and the retention period. We provide this information free of charge, normally within 30 days.
(b) Right to correction. You may request the correction of inaccurate or incomplete personal data.
(c) Right to deletion. You may request the deletion of your personal data, unless we are required to retain it by law or have an overriding legitimate interest.
(d) Right to restriction. You may request that we restrict the processing of your personal data while a dispute is resolved.
(e) Right to object. You may object to the processing of your personal data at any time for reasons relating to your particular situation, unless we have an overriding legitimate interest or a legal obligation to continue processing.
(f) Right to data portability. Where we process your personal data by automated means on the basis of consent or a contract, you may receive your data in a structured, commonly used, and machine-readable format.
8.2 To exercise any of these rights, please contact us at [EMAIL]. We may ask for additional information to verify your identity.
8.3 If you believe that we have not respected your rights, you may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch, or with the competent supervisory authority in your country of residence.
9. Cookies
9.1 This website uses only technically necessary cookies. No analytics, marketing, or tracking cookies are set without your prior consent.
9.2 Detailed information about the cookies used is set out in our Cookie Policy, available at https://consulting.evrtng.cloud/cookie-policy.
10. Retention
10.1 We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, to comply with legal obligations, or to defend against legal claims.
10.2 Contact form submissions are typically retained for up to 24 months. Email correspondence is retained for the duration of the business relationship and for a reasonable period thereafter, subject to statutory retention obligations.
11. Children
This website is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us so that we can delete it.
12. Changes to this Privacy Policy
12.1 We may update this Privacy Policy from time to time to reflect changes in our practices, the law, or the website. The current version is the one published on this page. We recommend checking this page periodically.
12.2 Material changes will be indicated by updating the “Last updated” date at the top of this page.
13. Contact
If you have any questions about this Privacy Policy or the way we process your personal data, please contact:
[COMPANY LEGAL NAME]
[STREET ADDRESS]
[CITY ZIP] [SWITZERLAND]
Email: [EMAIL]
Phone: [PHONE]
That’s about 1300 words. Good.
Now the Cookie Policy.