Privacy Policy
Last updated: 27 September 2026
This privacy policy explains which personal data we process, for what purpose, who receives it, and what rights you have under the revised Swiss Federal Act on Data Protection (revFADP). It applies to the alpeniq.ch website. It does not apply to our internal, login-only working tools on separate subdomains; anyone recorded there is informed separately. If you access this website from the EEA, the provisions of the GDPR apply in addition.
1. Controller
The controller for the processing of personal data on this website is:
Nasser Zafi
Sole proprietorship, business name «Zafi Design House», brand «ALPENIQ»
Glasistrasse 9
8180 Bülach, Switzerland
Email: info@alpeniq.ch
Phone: +41 78 354 30 93
«ALPENIQ» is the brand of this sole proprietorship and not a legal entity in its own right. The controller within the meaning of Art. 5 let. j revFADP (and Art. 4 no. 7 GDPR) is therefore Nasser Zafi.
For access, rectification, deletion, withdrawal or a complaint you can reach us at info@alpeniq.ch.
We have not appointed a data protection advisor under Art. 10 revFADP. Such an appointment is voluntary for private controllers; there is no legal obligation.
2. Principles and legal bases
We process personal data in good faith, proportionately, and only for the purposes stated in this policy (Art. 6 revFADP).
The legal bases in detail:
- Your consent – for analytics and marketing cookies (Art. 6 revFADP; Art. 6 para. 1 let. a GDPR). You may withdraw it at any time with effect for the future.
- Formation or performance of a contract – for instance when you use the contact form (Art. 31 para. 2 let. a revFADP; Art. 6 para. 1 let. b GDPR).
- Our overriding legitimate interest – for security logs, spam protection, rate limiting and cookieless traffic measurement (Art. 31 para. 2 let. d revFADP; Art. 6 para. 1 let. f GDPR).
- A legal obligation – for instance commercial and tax retention periods (Art. 31 para. 2 let. c revFADP; Art. 6 para. 1 let. c GDPR).
3. Server logs and security data
When you visit our website, technical data is automatically processed by our hosting provider Vercel Inc. (see section 6): IP address, date and time, browser type, operating system, referrer URL and the requested page. This data is used solely to deliver the website, to defend against attacks and to maintain system stability.
The /api/contact endpoint additionally uses your IP address for an in-memory rate limit (max. 5 requests per IP per hour) and for CSRF protection (double-submit cookie). The IP address is not stored in any database or email and is discarded once the request is complete. Vercel edge logs are auto-purged after at most 30 days.
Since 14 September 2026, a web application firewall at Vercel additionally protects the /api/advisor endpoint against automated overload. It counts requests per IP address and per TLS fingerprint (JA4) and rejects excessive requests with status 429. The TLS fingerprint describes the browser or program version in use, not the person; Vercel processes it as part of attack mitigation and we do not store it.
Legal basis: legitimate interest in IT security (Art. 31(2)(d) revFADP / Art. 6(1)(f) GDPR).
Answer feature (section 4): the /api/advisor endpoint also limits requests by IP address – at most ten questions per IP per hour, and at most sixty questions per hour in total. The counter lives in the server's working memory and is not stored.
When one of these limits is reached, we write a line to the server log. It does **not** contain your IP address but a non-reversible short identifier derived from it: eight characters of a hash, salted with a random value that is regenerated every time the server starts. It lets us tell „many requests from one sender“ from „from many senders“ – and nothing else. Beyond a single server start it can no longer be linked to anything, not even by us.
The text of your question appears in no log.
Purpose: mitigating automated overload and capping cost.
Legal basis: legitimate interest in IT security (Art. 31(2)(d) revFADP / Art. 6(1)(f) GDPR).
Retention: as for the other server logs, at most 30 days.
4. Contact form, appointment booking, email, newsletter, Academy, website check and answer feature
When you use our multi-step contact form (/erstgespraech or /initial-consultation) or send us an email, we process the following data: name, role, email address, phone number (optional), company name, industry, company size, information about your existing website, the services you selected, your acquisition channels, revenue range, problem, timeline, source of awareness and your free-text message.
We also receive a hidden honeypot field from the form to filter automated spam submissions. Real input in this field is silently discarded.
Purpose: handling your enquiry and preparing a free strategy call.
Legal basis: pre-contractual measures at your request (Art. 31(2)(a) revFADP / Art. 6(1)(b) GDPR).
Recipients: the ALPENIQ mailbox info@alpeniq.ch, transmitted technically through Resend Inc. (see section 6).
Retention: up to 24 months after our last contact with you, then deletion or anonymisation. If a contract is concluded, statutory commercial and tax retention periods apply (Art. 958f Swiss Code of Obligations: 10 years).
Appointment booking (Cal.com): When you book a strategy call through the embedded calendar widget, we pass Cal.com a hidden booking question containing your Google Analytics 4 client ID (from the «_ga» cookie) alongside your booking details, provided you have consented to analytics. If the call takes place, Cal.com notifies our server via webhook and we send the event «meeting_held» with that client ID to Google Analytics 4 (Measurement Protocol). This tells us which source leads to calls that actually happen. Without analytics consent there is no client ID and no event. Legal basis: your consent (Art. 31(1) revFADP / Art. 6(1)(a) GDPR), withdrawable at any time via the cookie settings.
Newsletter: When you sign up for the newsletter, we first send you a confirmation email (double opt-in). Your address counts as subscribed only once you open the link in it and confirm the subscription on the page behind it; before that we do not store it. We process your email address, language, the source of the sign-up and the time of sign-up and confirmation as proof of your consent. Purpose: delivering the newsletter, about one email a month, and documenting your consent. Legal basis: your consent (Art. 31(1) revFADP / Art. 6(1)(a) GDPR, Art. 3(1)(o) Swiss Unfair Competition Act). Recipient: the ALPENIQ mailbox, transmitted technically through Resend Inc. (section 6). We keep the list at Resend Inc. (section 6); it stores your email address and whether you are subscribed or unsubscribed. You can unsubscribe at any time via the link in every newsletter email or by writing to info@alpeniq.ch. Your address then stays marked as unsubscribed so that it receives no further email, and we keep the record of your earlier consent and of the unsubscribe for as long as it is needed to defend claims.
Academy downloads: When you request material from the ALPENIQ Academy that we release in exchange for an email address, we do not send the file straight away – we send a personal download link by email. Until you trigger the download through that link we store nothing, not even your address; it exists only inside the signed link. The download is what shows the address is yours, and only then is a record created on our side. We process: your email address, language, the material requested, the time of the request and of the download, and whether you additionally consented to the newsletter. Purpose: delivering the material you asked for and – only if you ticked the second box – adding you to the newsletter under the rules in the previous paragraph. The first box covers delivery and nothing else; without the second one we will not write to you. The second box only counts if you trigger the download within 48 hours of the request, and it does not override an earlier unsubscribe. Legal basis: your consent (Art. 31(1) revFADP / Art. 6(1)(a) GDPR, Art. 3(1)(o) Swiss Unfair Competition Act). Recipient: the ALPENIQ mailbox, transmitted technically through Resend Inc. (section 6). The download link stays valid; you can download the guide again from the same email at any time. Retention: up to 24 months after the download, then deletion or anonymisation.
Website check (/growth/website-check): if you enter a website address and your email address there, we fetch that page once, check it technically and send you the report by email. We process: the address checked, your email address, the language, the result and the time. The email address is mandatory – it is how the report reaches you and at the same time what stops anyone from pointing the fetch at third-party servers automatically. Our own mailboxes receive a note with the same content so that we can answer follow-up questions. The report itself sits behind a signed link; we do not keep a copy in a database.
Purpose: delivering the report you asked for and preparing a possible strategy call.
Legal basis: pre-contractual step at your request (Art. 31(2)(a) revFADP / Art. 6(1)(b) GDPR).
Recipients: the ALPENIQ mailboxes info@ and admin@alpeniq.ch, transmitted technically through Resend Inc. (section 6).
Retention: up to 24 months after our last contact with you.
Follow-up by phone: if you filled in the contact form, requested the website check or took an Academy resource, we may call you once – to ask whether you got further, and to offer you a free strategy call. The number comes either from you, through the contact form, or from a publicly available source of your company. In doing so we respect the entry in the Swiss telephone directory under Art. 3(1)(u) of the Unfair Competition Act, and we treat numbers with no directory entry the same as those carrying the note. Three attempts at most, then no more. A newsletter sign-up on its own never triggers a call.
Purpose: following up on your enquiry and offering a first conversation.
Legal basis: our overriding legitimate interest in initiating a business relationship with companies (Art. 31(2)(d) revFADP / Art. 6(1)(f) GDPR); for an enquiry through the contact form additionally the pre-contractual step at your request.
One word is enough and we stop calling: info@alpeniq.ch.
Answer feature (ALPENIQ Advisor): when you ask a question in the chat window at the bottom right, we send exactly two things to Anthropic PBC (see section 6): your question, and the passages from our own publicly available pages that match it. Nothing else travels with it – no IP address, no cookie, no identifier, no name, no email address, and none of your earlier questions.
We do not store your question anywhere permanently. Question and answer sit in the server's working memory for at most twelve hours, so that the same question is not paid for twice, and they are gone with the next deployment of the website. Our server log records only what the call cost, never the text of your question.
Purpose: answering your question from our own content and naming the page the answer comes from.
Legal basis: our overriding legitimate interest in giving a clear answer (Art. 31(1) revFADP / Art. 6(1)(f) GDPR).
Recipient: Anthropic PBC (USA), see sections 6 and 7.
Retention with us: at most twelve hours in working memory, no permanent storage.
The feature is voluntary, and loading the website does not trigger it – only submitting a question does. You can find the same content without any transfer to third parties through the search on alpeniq.ch.
Please do not enter personal data or confidential information in the input field. We do not need it to answer, and for a matter that does require personal data the contact form is the right route.
6. Processors and recipients
To operate the website we engage specialised service providers as processors within the meaning of Art. 9 revFADP. We have concluded the required agreements (DPA) with all of them.
- Vercel Inc. (USA) – hosting and delivery via the European edge network, plus «Vercel Analytics», a cookieless traffic measurement without recognition across sessions. It runs on our legitimate interest and without consent because it neither stores nor reads data on your device. Transfer basis: Swiss-U.S. Data Privacy Framework (certified) and EU standard contractual clauses.
- Google Ireland Ltd. (IE) and Google LLC (USA) – Google Tag Manager, Google Analytics 4, Google Ads conversion measurement and Google Ads remarketing. Remarketing means visitors of this website can be shown ALPENIQ ads again across the Google advertising network. The audience this requires is filled only with your marketing consent; without it your visit remains invisible to Google Ads. Analytics cookies are set only after your analytics consent, conversion cookies and the hashed email address for enhanced conversions only after your marketing consent; Google Consent Mode v2 is active and IP anonymisation is standard in GA4. Transfer basis: Swiss-U.S. Data Privacy Framework (certified) and EU standard contractual clauses.
- Microsoft Ireland Operations Ltd. (IE) and Microsoft Corporation (USA) – Microsoft Clarity for heatmaps and session replays. The code is loaded only after your analytics consent. Input into form fields is masked before transmission. Transfer basis: Swiss-U.S. Data Privacy Framework (certified) and EU standard contractual clauses.
- Resend Inc. (USA) – delivery of contact form enquiries to info@alpeniq.ch, of newsletter confirmation emails to you and of consent records to our mailbox. Resend also keeps the newsletter list: the email address and subscription status of everyone who signed up. Only the form data you entered is transmitted, no tracking or browser data. Transfer basis: EU standard contractual clauses. Delivery logs are deleted after around 30 days.
- Cal.com, Inc. (USA, processing primarily in the EU) – booking of the strategy call via an embedded calendar widget. It loads only when you visit /erstgespraech or /initial-consultation. When Cal.com confirms a booking, our site reports it like an enquiry to Google Analytics, Google Ads and, with your marketing consent, to Meta (see below); Cal.com only passes us the booking's identifier for this, not your details. Transfer basis, where applicable: EU standard contractual clauses.
- Klaviyo, Inc., 125 Summer Street, Floor 6, Boston, MA 02111, USA – email marketing. With your marketing consent we load the Klaviyo script. It stores a random identifier for your browser (section 5), looks up your country and continent from your IP address when it loads, and keeps track in your browser of where you came from and which of our pages you visit. As long as Klaviyo does not know you, that list stays in your browser. Klaviyo knows you once you enter your email address in a Klaviyo sign-up form on this website or arrive through a link that identifies you – for instance from an email we send via Klaviyo, or a link containing your email address. The script then transmits the pages you visited, including those kept in your browser, to Klaviyo – with referrer, browser, operating system, device type and the parameters in the link, such as campaign details – and links them to your profile in our Klaviyo account so that we can tailor our emails to your interests. Klaviyo processes the data as our processor and stores it in the USA. Transfer basis: Swiss-U.S. Data Privacy Framework (certified) and EU standard contractual clauses.
Meta Pixel and Conversions API (joint controllership): With your marketing consent we use the Meta Pixel of Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, D04 X2K5, Ireland. On every page view it reports to Meta the address of the page, the referring page, the time, your IP address, screen size, time zone and browser details, plus the identifier from «_fbp» and, where present, the click identifier from «_fbc» (section 5). If you are logged in to Facebook or Instagram, your browser also sends Meta's own cookies, and Meta can attribute the visit to your account.
After you submit the contact form, Meta is additionally told once about the event «Lead», i.e. that an enquiry was received, through two channels: by the pixel in your browser, without name, email address or content, and by our server via Meta's Conversions API. The server report contains the page address, your IP address, browser details, the identifiers from «_fbp» and «_fbc», and your email address, but only as a SHA-256 hash. Meta compares this hash with the addresses of its accounts in order to attribute the enquiry to an ad. Meta does not receive your name, your phone number or the content of your message. Both reports carry the same random identifier so that Meta counts the enquiry only once. Our server only reports if you had given marketing consent when you submitted the form. If you book a call directly in the calendar, only the pixel reports the same event «Lead», with the booking's identifier and without name, email address or content.
If you sign up for the newsletter, request an Academy guide or run the website check, the pixel reports the event «CompleteRegistration» to Meta, together with which of the three it was. Your email address, the website address checked, the result of the check and the title of the guide are not sent to Meta, and our server does not report these sign-ups.
We use both to show you our ads on Facebook and Instagram and to measure whether they work. Clicks, other form input and page content are not reported: automatic collection of clicks and page data is switched off in our code, automatic matching via form fields («Automatic Advanced Matching») in Meta's settings.
For the collection of this data and its transmission to Meta we are joint controllers with Meta Platforms Ireland Ltd. (Art. 5 let. j revFADP; Art. 26 GDPR). The agreement on this is part of Meta's Business Tools Terms («Controller Addendum», facebook.com/legal/controller_addendum). Meta alone is responsible for any further processing; how Meta processes the data and how you can exercise your rights there is set out in Meta's Privacy Policy (facebook.com/privacy/policy). You may also exercise your rights with us; we will forward your request to Meta. Meta may transfer data to Meta Platforms, Inc. in the USA; transfer basis: Swiss-U.S. Data Privacy Framework (Meta Platforms, Inc. is certified).
Beyond this we pass on personal data only where we are legally obliged to do so or where you have consented. We do not sell personal data or pass it on commercially to third parties.
On individual project pages we embed the client's website in a frame so you see the result live rather than as a screenshot. The frame loads as you scroll; in doing so your browser transmits technical connection data to that website's server, in particular your IP address – as with any visit to a third-party site. We pass on no data about you. This currently affects physio-arslanovic.de on its project page.
Where we work for you as a client and process personal data on your behalf, for instance in operating your website or your IT, we act as processor and you are the controller. For this we conclude a data processing agreement; the basis is set out in section 10 of our General Terms and Conditions.
Additionally, for the answer feature (section 4):
- Anthropic PBC (USA) – phrasing the answer from your question and matching passages of our own pages. Only these two items are transmitted, no tracking and no browser data. The provider is contractually barred from using this content to train its models. Transfer basis: EU Standard Contractual Clauses in their Swiss-adapted version. The service is only contacted when you submit a question in the chat window.
7. International transfers
Some of the processors listed in section 6 are established or host data in countries outside Switzerland and the EEA, in particular the USA.
Since the Swiss Federal Council recognised the Swiss-U.S. Data Privacy Framework as of 15 September 2024, the USA is considered to provide adequate protection for certified recipients (Art. 16(1) revFADP read with Annex 1 of the Data Protection Ordinance). For recipients not certified under the DPF we rely on EU Standard Contractual Clauses in their Swiss-adapted version (Art. 16(2)(d) revFADP) and on additional technical and organisational measures (encryption in transit, pseudonymisation, access controls).
You have the right to request a copy of these safeguards by writing to info@alpeniq.ch.
8. Retention
We only retain personal data for as long as necessary for the relevant purpose (Art. 6(4) revFADP, principle of storage limitation).
In detail:
• Server logs / edge logs: max. 30 days (Vercel auto-purge).
• Contact-form enquiries in the ALPENIQ mailbox: up to 24 months after the last contact; in case of a contract, up to 10 years after the end of the contract (Art. 958f Swiss Code of Obligations).
• Resend delivery logs: max. 30 days.
• Newsletter addresses: until you unsubscribe; afterwards the address stays marked as unsubscribed so that it receives no further email, and the consent record is kept for as long as it is needed to defend claims.
• Google Analytics 4: 14 months (property-level retention setting).
• Microsoft Clarity: 13 months from last activity (Microsoft default).
• Meta Pixel: «_fbp» and «_fbc» 90 days on your device, deleted immediately on withdrawal; how long Meta keeps the data it receives is determined by Meta (Meta's Privacy Policy).
• Klaviyo: «__kla_id» up to 2 years on your device, deleted immediately on withdrawal. Your profile in our Klaviyo account, with the page visits linked to it, until you unsubscribe; afterwards the address stays marked as unsubscribed so that it receives no further email. On request we delete the profile entirely (section 9).
• Cookie consent (local storage): until you change it or your browser clears it.
• Accounting and tax records: 10 years (Art. 958f Swiss Code of Obligations).
9. Your rights
Under the revFADP and the GDPR you have in particular the following rights:
- Access to whether and which personal data we process about you (Art. 25 revFADP / Art. 15 GDPR)
- Rectification of inaccurate data (Art. 32 para. 1 revFADP / Art. 16 GDPR)
- Deletion or destruction (Art. 32 para. 2 revFADP / Art. 17 GDPR)
- Restriction of processing (Art. 32 para. 2 revFADP / Art. 18 GDPR)
- Release or transfer of your data in a common electronic format (Art. 28 revFADP / Art. 20 GDPR)
- Objection to processing we base on a legitimate interest (Art. 30 para. 2 let. b revFADP / Art. 21 GDPR)
- Withdrawal of consent given, at any time and with effect for the future (Art. 7 para. 3 GDPR; under the revFADP withdrawal follows from the requirement that consent be freely given, Art. 6 para. 6 revFADP)
We do not process personal data for automated individual decisions with legal effect or significant detriment within the meaning of Art. 21 revFADP or Art. 22 GDPR.
An informal email to info@alpeniq.ch is sufficient to exercise your rights. Access is generally free of charge (Art. 25 para. 6 revFADP). We respond within 30 days; where that is not possible we will tell you, with reasons (Art. 18 DPO).
10. Right to lodge a complaint
If you believe that we process your personal data unlawfully, you can lodge a complaint with the competent supervisory authority at any time:
In Switzerland: Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Feldeggweg 1, 3003 Bern
Website: https://www.edoeb.admin.ch
In the EEA/EU: the data-protection supervisory authority of your country of residence or work (Art. 77 GDPR).
11. Data security
We take appropriate technical and organisational measures to ensure the confidentiality, integrity and availability of your data (Art. 8 revFADP, Art. 32 GDPR). In particular: end-to-end encryption of transport (HTTPS / TLS 1.2+, HSTS with preload); strict Content Security Policy, X-Frame-Options, Cross-Origin-Opener-Policy and other security headers; CSRF protection via double-submit cookie on every form you submit (contact, newsletter sign-up, Academy request), and rate limiting on every endpoint that triggers work; input validation with a Zod schema and HTML escaping before every email is sent; honeypot field for spam defence; access to info@alpeniq.ch and to all third-party systems only via personal accounts with two-factor authentication.
A data protection impact assessment under Art. 22 revFADP is not required for our standard processing; we keep a voluntary record of processing activities.
12. Changes to this privacy policy
We update this privacy policy when our processing, the services we use, or the legal requirements change.
The current version is available at alpeniq.ch/en/privacy-policy. The date of the last update is shown at the top of this page.
If the cookies or services we use change, we will obtain your consent again rather than rely on an earlier one.