Privacy Policy
2. Data Controller and Data Protection Officer
3. Collection and Processing of Personal Data
3.1 Automatically when visiting the website
When you access our website, the following data is collected automatically:
| Data | Purpose | Legal basis |
|---|---|---|
| IP address | Technical provision of the website, security | Legitimate interest (Art. 13 FADP / Art. 6(1)(f) GDPR) |
| Browser type and version | Optimisation of display | Legitimate interest |
| Operating system | Optimisation of display | Legitimate interest |
| Referrer URL | Analysis of user behaviour | Legitimate interest |
| Date/time of request | Security, error analysis | Legitimate interest |
| Time zone difference | Correct time display | Legitimate interest |
| Requested page/content | Provision of requested information | Legitimate interest |
| HTTP status code | Error analysis | Legitimate interest |
| Volume of data transferred | Technical optimisation | Legitimate interest |
Retention period: Server log files are deleted after 30 days.
3.2 Contact by email
When you contact us by email (info@elvida.app), we collect:
Purpose: Processing your enquiry
Legal basis: Legitimate interest (Art. 13 FADP / Art. 6(1)(f) GDPR)
Retention period: 2 years after final processing
3.3 Newsletter subscription
To receive our newsletter we collect:
Purpose: Sending information about ELVIDA
Legal basis: Consent (Art. 13 FADP / Art. 6(1)(a) GDPR)
Retention period: Until unsubscription (revocable at any time)
4. Cookies and Tracking
4.1 Cookies used
We use the following cookie categories:
| Category | Purpose | Examples | Duration |
|---|---|---|---|
| Necessary | Technical functionality, security | Session cookies, CSRF token | Session up to 1 year |
| Analysis | Understanding of website usage | Google Analytics 4 | Up to 2 years |
Note: We currently do not use marketing cookies.
4.2 Google Analytics 4
We use Google Analytics 4 (GA4) to analyse website usage. Data is transmitted to Google LLC (USA).
- Provider
- Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- Purpose
- Analysis of user behaviour to optimise the website
- Legal basis
- Legitimate interest (Art. 6(1)(f) GDPR / Art. 13 FADP)
- Data transmitted
- IP address (truncated), browser information, usage data
- IP anonymisation
- Enabled – your IP address is truncated before transmission
Right to object:
Further information on data processing by Google: Google Privacy Policy / Google Analytics Privacy
5. International Data Transfers
We transfer personal data to countries outside Switzerland and the EEA:
| Recipient | Location | Purpose | Safeguards |
|---|---|---|---|
| Netlify, Inc. | USA | Website hosting | EU Commission Standard Contractual Clauses (SCC) |
| Google LLC | USA | Web analytics (Google Analytics 4) | EU Commission Standard Contractual Clauses (SCC) |
The USA does not have a level of data protection equivalent to Swiss or EU law. The transfer is based on standard contractual clauses providing adequate safeguards for the protection of your data pursuant to Art. 16 FADP and Art. 46 GDPR.
Further information on data processing by our service providers: Netlify Privacy Policy / Netlify DPA
6. Data Processors
We use the following service providers as data processors:
| Recipient | Activity | Contract |
|---|---|---|
| Netlify, Inc. | Website hosting | Data Processing Agreement (DPA) |
| Google LLC | Web analytics | Data Processing Agreement (DPA) |
All data processors are contractually obliged to comply with data protection requirements.
7. Automated Decision-Making
8. Retention Period
| Category | Duration | Legal basis |
|---|---|---|
| Server log files | 30 days | Technical necessity |
| Contact requests | 2 years after completion | Legitimate interest |
| Newsletter data | Until unsubscription | Consent |
| Cookie consents | 1 year | Proof obligation |
Note on cookie consents: After the 1-year retention period expires, you will be asked again for your consent via the cookie banner. Consent is not automatically renewed.
9. Your Rights
You have the following rights:
| Right | Description |
|---|---|
| Access | Information about your personal data stored with us |
| Rectification | Correction of incorrect or incomplete data |
| Erasure | Erasure of your data ("right to be forgotten") |
| Restriction | Restriction of processing |
| Objection | Objection to processing |
| Data portability | Receipt of your data in a standard format |
Exercise: Contact us at info@elvida.app
Complaint: You may lodge a complaint with the supervisory authority: Federal Data Protection and Information Commissioner (FDPIC)
10. Data Security
We implement the following technical and organisational measures to protect your data:
| Measure | Description |
|---|---|
| Encrypted data transmission | SSL/TLS encryption for all data transmissions |
| Access restrictions | Access only for authorised persons |
| Access logging | Log of access to personal data |
| Pseudonymisation | Data is processed in pseudonymised form where possible |
| Regular security updates | Updating of systems and software |
| Encrypted storage | Personal data is stored in encrypted form |