Skip to main content

Privacy Policy

Last updated: 30 July 2026

This privacy policy explains which personal data we process, for what purpose, who receives it, and what rights you have under the revised Swiss Federal Act on Data Protection (revFADP). It applies to the alpeniq.ch website. It does not apply to our internal, login-only working tools on separate subdomains; anyone recorded there is informed separately. If you access this website from the EEA, the provisions of the GDPR apply in addition.

1. Controller

The controller for the processing of personal data on this website is:

Nasser Zafi
Sole proprietorship, business name «Zafi Design House»
Glasistrasse 9
8180 Bülach, Switzerland
Email: info@alpeniq.ch
Phone: +41 78 354 30 93

«ALPENIQ» is the business name of this sole proprietorship and not a legal entity in its own right. The controller within the meaning of Art. 5 let. j revFADP (and Art. 4 no. 7 GDPR) is therefore Nasser Zafi.

For access, rectification, deletion, withdrawal or a complaint you can reach us at info@alpeniq.ch.

We have not appointed a data protection advisor under Art. 10 revFADP. Such an appointment is voluntary for private controllers; there is no legal obligation.

2. Principles and legal bases

We process personal data in good faith, proportionately, and only for the purposes stated in this policy (Art. 6 revFADP).

The legal bases in detail:

• Your consent — for analytics and marketing cookies (Art. 6 revFADP; Art. 6 para. 1 let. a GDPR). You may withdraw it at any time with effect for the future.
• Formation or performance of a contract — for instance when you use the contact form (Art. 31 para. 2 let. a revFADP; Art. 6 para. 1 let. b GDPR).
• Our overriding legitimate interest — for security logs, spam protection, rate limiting and cookieless traffic measurement (Art. 31 para. 2 let. d revFADP; Art. 6 para. 1 let. f GDPR).
• A legal obligation — for instance commercial and tax retention periods (Art. 31 para. 2 let. c revFADP; Art. 6 para. 1 let. c GDPR).

3. Server logs and security data

When you visit our website, technical data is automatically processed by our hosting provider Vercel Inc. (see section 6): IP address, date and time, browser type, operating system, referrer URL and the requested page. This data is used solely to deliver the website, to defend against attacks and to maintain system stability.

The /api/contact endpoint additionally uses your IP address for an in-memory rate limit (max. 5 requests per IP per hour) and for CSRF protection (double-submit cookie). The IP address is not stored in any database or email and is discarded once the request is complete. Vercel edge logs are auto-purged after at most 30 days.

Legal basis: legitimate interest in IT security (Art. 31(2)(d) revFADP / Art. 6(1)(f) GDPR).

4. Contact form and email contact

When you use our multi-step contact form (/erstgespraech or /initial-consultation) or send us an email, we process the following data: name, role, email address, phone number (optional), company name, industry, company size, information about your existing website, the services you selected, your acquisition channels, revenue range, problem, timeline, source of awareness and your free-text message.

We also receive a hidden honeypot field from the form to filter automated spam submissions. Real input in this field is silently discarded.

Purpose: handling your enquiry and preparing a free strategy call.
Legal basis: pre-contractual measures at your request (Art. 31(2)(a) revFADP / Art. 6(1)(b) GDPR).
Recipients: the ALPENIQ mailbox info@alpeniq.ch, transmitted technically through Resend Inc. (see section 6).
Retention: up to 24 months after our last contact with you, then deletion or anonymisation. If a contract is concluded, statutory commercial and tax retention periods apply (Art. 958f Swiss Code of Obligations: 10 years).

5. Cookies and similar technologies

We use technically necessary cookies without which this website does not work: to store your cookie choice, your language, and to protect against cross-site request forgery. These are set without consent, based on Art. 45c let. b of the Swiss Telecommunications Act and our overriding legitimate interest.

All other cookies and comparable technologies are activated only after your express consent via the cookie banner. Until then all analytics and marketing categories are set to «denied» in Google Consent Mode, and the Microsoft Clarity code is not loaded at all.

You may withdraw your consent at any time with effect for the future: via the «Cookie settings» link in the footer or via the button further down this page. Withdrawal is as easy as giving consent and costs you nothing.

Your choice is stored locally in your browser (local storage, key «cookie-consent»), not on our server. It persists until you change it or clear your browser storage. If we change the services we use, we will ask again.

Overview of cookies and comparable storage items in use:

Necessary (always active):
• csrf_token (cookie, alpeniq.ch, 1 hour), protection against CSRF on the contact form.
• cookie-consent (local storage, alpeniq.ch, unlimited), stores your cookie preference.
• NEXT_LOCALE (cookie, alpeniq.ch, 1 year), stores your language choice (de/en).

Analytics (only with consent):
• _ga, _ga_<ID> (cookie.alpeniq.ch, 13 months, Google Analytics), recognises user sessions.
• _gid (cookie.alpeniq.ch, 24 hours, Google Analytics), distinguishes users.
• _clck, _clsk, CLID, MUID (cookie.clarity.ms / .alpeniq.ch, up to 12 months, Microsoft Clarity), session ID and recognition for heatmaps and session replays.
• alpeniq_generate_lead_fired, alpeniq_404_fired_* (local storage, alpeniq.ch, 30 days), prevents internal events from firing twice.

Marketing (only with consent):
• ALPENIQ currently does not set marketing cookies directly. If conversion tags are loaded through Google Tag Manager in the future, the corresponding cookies (e.g. _gcl_au) will only appear after your marketing consent.

6. Processors and recipients

To operate the website we engage specialised service providers as processors within the meaning of Art. 9 revFADP. We have concluded the required agreements (DPA) with all of them.

• Vercel Inc. (USA) — hosting and delivery via the European edge network, plus «Vercel Analytics», a cookieless traffic measurement without recognition across sessions. It runs on our legitimate interest and without consent because it neither stores nor reads data on your device. Transfer basis: Swiss-U.S. Data Privacy Framework (certified) and EU standard contractual clauses.
• Google Ireland Ltd. (IE) and Google LLC (USA) — Google Tag Manager and Google Analytics 4. Tags and cookies are loaded only after your analytics consent; Google Consent Mode v2 is active and IP anonymisation is standard in GA4. Transfer basis: Swiss-U.S. Data Privacy Framework (certified) and EU standard contractual clauses.
• Microsoft Ireland Operations Ltd. (IE) and Microsoft Corporation (USA) — Microsoft Clarity for heatmaps and session replays. The code is loaded only after your analytics consent. Input into form fields is masked before transmission. Transfer basis: Swiss-U.S. Data Privacy Framework (certified) and EU standard contractual clauses.
• Resend Inc. (USA) — delivery of contact form enquiries to info@alpeniq.ch. Only the form data you entered is transmitted, no tracking or browser data. Transfer basis: EU standard contractual clauses. Delivery logs are deleted after around 30 days.
• Cal.com, Inc. (USA, processing primarily in the EU) — booking of the strategy call via an embedded calendar widget. It loads only when you visit /erstgespraech or /initial-consultation. Transfer basis, where applicable: EU standard contractual clauses.

Beyond this we pass on personal data only where we are legally obliged to do so or where you have consented. We do not sell personal data or pass it on commercially to third parties.

Where we work for you as a client and process personal data on your behalf, for instance in operating your website or your IT, we act as processor and you are the controller. For this we conclude a data processing agreement; the basis is set out in section 10 of our General Terms and Conditions.

7. International transfers

Some of the processors listed in section 6 are established or host data in countries outside Switzerland and the EEA, in particular the USA.

Since the Swiss Federal Council recognised the Swiss-U.S. Data Privacy Framework as of 15 September 2024, the USA is considered to provide adequate protection for certified recipients (Art. 16(1) revFADP read with Annex 1 of the Data Protection Ordinance). For recipients not certified under the DPF we rely on EU Standard Contractual Clauses in their Swiss-adapted version (Art. 16(2)(d) revFADP) and on additional technical and organisational measures (encryption in transit, pseudonymisation, access controls).

You have the right to request a copy of these safeguards by writing to info@alpeniq.ch.

8. Retention

We only retain personal data for as long as necessary for the relevant purpose (Art. 6(4) revFADP, principle of storage limitation).

In detail:
• Server logs / edge logs: max. 30 days (Vercel auto-purge).
• Contact-form enquiries in the ALPENIQ mailbox: up to 24 months after the last contact; in case of a contract, up to 10 years after the end of the contract (Art. 958f Swiss Code of Obligations).
• Resend delivery logs: max. 30 days.
• Google Analytics 4: 14 months (property-level retention setting).
• Microsoft Clarity: 13 months from last activity (Microsoft default).
• Cookie consent (local storage): until you change it or your browser clears it.
• Accounting and tax records: 10 years (Art. 958f Swiss Code of Obligations).

9. Your rights

Under the revFADP and the GDPR you have in particular the following rights:

• Access to whether and which personal data we process about you (Art. 25 revFADP / Art. 15 GDPR)
• Rectification of inaccurate data (Art. 32 para. 1 revFADP / Art. 16 GDPR)
• Deletion or destruction (Art. 32 para. 2 revFADP / Art. 17 GDPR)
• Restriction of processing (Art. 32 para. 2 revFADP / Art. 18 GDPR)
• Release or transfer of your data in a common electronic format (Art. 28 revFADP / Art. 20 GDPR)
• Objection to processing we base on a legitimate interest (Art. 30 para. 2 let. b revFADP / Art. 21 GDPR)
• Withdrawal of consent given, at any time and with effect for the future (Art. 7 para. 3 GDPR; under the revFADP withdrawal follows from the requirement that consent be freely given, Art. 6 para. 6 revFADP)

We do not process personal data for automated individual decisions with legal effect or significant detriment within the meaning of Art. 21 revFADP or Art. 22 GDPR.

An informal email to info@alpeniq.ch is sufficient to exercise your rights. Access is generally free of charge (Art. 25 para. 6 revFADP). We respond within 30 days; where that is not possible we will tell you, with reasons (Art. 18 DPO).

10. Right to lodge a complaint

If you believe that we process your personal data unlawfully, you can lodge a complaint with the competent supervisory authority at any time:

In Switzerland: Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Feldeggweg 1, 3003 Bern
Website: https://www.edoeb.admin.ch

In the EEA/EU: the data-protection supervisory authority of your country of residence or work (Art. 77 GDPR).

11. Data security

We take appropriate technical and organisational measures to ensure the confidentiality, integrity and availability of your data (Art. 8 revFADP, Art. 32 GDPR). In particular: end-to-end encryption of transport (HTTPS / TLS 1.2+, HSTS with preload); strict Content Security Policy, X-Frame-Options, Cross-Origin-Opener-Policy and other security headers; CSRF protection and rate limiting on every write endpoint; input validation with a Zod schema and HTML escaping before every email is sent; honeypot field for spam defence; access to info@alpeniq.ch and to all third-party systems only via personal accounts with two-factor authentication.

A data protection impact assessment under Art. 22 revFADP is not required for our standard processing; we keep a voluntary record of processing activities.

12. Changes to this privacy policy

We update this privacy policy when our processing, the services we use, or the legal requirements change.

The current version is available at alpeniq.ch/en/privacy-policy. The date of the last update is shown at the top of this page.

If the cookies or services we use change, we will obtain your consent again rather than rely on an earlier one.