1. Controller
The controller responsible for processing personal data is Roberto De Simone, Karl Jauslin-Strasse 12, 4132 Muttenz, Switzerland, email: roberto@de-simone.me, UID: CHE-329.775.690.
There is no legal requirement to appoint a data protection officer. Privacy enquiries may be sent directly to the email address above.
2. Principles and legal bases
This website is primarily intended for individuals and businesses in Switzerland. The Swiss Federal Act on Data Protection (FADP) applies. Where it applies in a particular case, I also observe the European Union General Data Protection Regulation (GDPR).
I process personal data only for the purposes described and only for as long as necessary. Where the GDPR applies, processing is based, depending on the circumstances, on your consent, steps taken before or during a contract, a legal obligation, or my legitimate interests in secure website operation and traceable business communication.
3. Website operation and technical logs
Technical access data is generated automatically when you visit the website. It can include the IP address, time, requested path, HTTP method and status, transferred data volume, browser and device information, referrer, and technical request or diagnostic identifiers.
This data is needed to deliver the website, investigate errors, prevent attacks and abuse, and maintain reliable operation. Cloud Run automatically generates request logs for these purposes. The application does not write form contents or reCAPTCHA tokens to those logs.
The website currently runs on Google Cloud Run in the europe-west1 region (Belgium). The default retention period in the Cloud Logging bucket is 30 days unless a shorter or different retention period is configured.
4. Contact enquiries and business contacts
When you use the contact form, I process company, salutation, first and last name, email address, telephone number, message, language, and technical information required for security and evidence. Fields marked optional may be left empty.
The information is used solely to process your enquiry, reply personally and document any resulting business relationship. The contact form does not verify the email address through a separate confirmation message. If your address was used without your involvement, you may contact me and request correction or deletion.
Data relating to existing business contacts may also originate from previous direct correspondence. I use such information to maintain the existing business relationship and, where legally permitted, for occasional relevant business updates. Every newsletter provides a straightforward way to unsubscribe.
Please do not use the free-text message field to send sensitive or confidential information that is not necessary for your enquiry.
6. Protecting forms with reCAPTCHA Enterprise
The contact and newsletter forms are protected by Google reCAPTCHA Enterprise against automated submissions, spam and abuse. The reCAPTCHA script is loaded only when you submit one of these forms.
For the security assessment, Google can process technical session, browser, device and application data and the IP address, and can set the _grecaptcha cookie required by reCAPTCHA. The application then sends the short-lived security token, public site key and expected form action to Google Cloud and receives a risk assessment.
Google processes reCAPTCHA customer data as a processor solely for operation, security and the prevention of fraud and abuse, not for personalised advertising. No automated decision with legal or similarly significant effects takes place. If the security check fails, you can still contact me directly by email.
7. Cookies, local storage and analytics
This website currently uses no analytics tools, Google Tag Manager, advertising networks or technologies for cross-site profiling. No non-essential tracking cookies are used.
If you enter an email address in the footer, it is stored temporarily in your browser's sessionStorage so that the newsletter form can be prefilled on the following page. The information remains on your device, is removed when read, and is sent to the server only when you submit the complete newsletter form.
The reCAPTCHA cookie described in section 6 is used only in connection with a form submission for security purposes. External links to LinkedIn, X or other websites transfer data to their operators only when you open the relevant link.
If server-side tagging, audience measurement or another non-essential analysis capability is introduced later, this statement will be updated before activation and an appropriate choice or consent mechanism will be provided where required.
8. Processors, recipients and providers
I do not sell, rent or provide contact or newsletter data to third parties for their own advertising. As a rule, only I have access. Data is disclosed only where necessary for the operation described here or where required by law.
- Google Cloud for hosting, the planned API and database, logging and reCAPTCHA Enterprise. The current website runs in Belgium; the Google Cloud Zurich region is intended for the API and PostgreSQL database and will be verified before the forms are activated.
- Amazon Web Services for SES and SNS in the Zurich region, and the recipients' respective mail providers for email delivery.
- Public authorities or other recipients only where legally required or necessary to establish, exercise or defend legal claims.
9. Processing outside Switzerland
The primary regions I select are in Switzerland or the European Union. Google, AWS and their contractually bound subprocessors can also process data in other countries for support, security and operation, particularly in Switzerland, EU or EEA countries, and the United States.
Where the destination country is not recognised as providing adequate data protection, the transfer is based on the providers' contractual safeguards, particularly applicable standard contractual clauses and Swiss supplements, or another legally permitted safeguard.
10. Retention and deletion
I review stored data regularly and delete or anonymise it as soon as it is no longer required for its purpose and no statutory or overriding legitimate reason requires further retention.
- Technical Cloud Run and application logs are generally retained for 30 days.
- Contact enquiries that do not result in a continuing business relationship are normally deleted no later than 24 months after the last exchange.
- Business contact details and correspondence are retained for the duration of the relationship and afterwards in accordance with statutory documentation and limitation periods.
- Active newsletter data is processed until you unsubscribe. A minimal unsubscribe or suppression record is then retained for as long as needed to prevent further unwanted delivery.
- Evidence of signup, confirmation, delivery and unsubscribe events is retained for as long as needed for accountability, security or legal claims; raw events that are no longer needed are deleted.
11. Your rights
Subject to applicable data protection law, you may request access to, correction or deletion of your personal data, restriction of processing, delivery or transfer of certain data, and object to processing. You may withdraw consent at any time with effect for the future.
To exercise your rights, email roberto@de-simone.me. To prevent unauthorised disclosure, I may ask for reasonable proof of identity. You may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where the GDPR applies, the competent European supervisory authority.
12. Security and changes
I use appropriate technical and organisational safeguards, including encrypted transmission, restricted access, separate public and administrative interfaces, abuse protection and secured credentials. Despite careful safeguards, no transmission or storage system can be guaranteed to be entirely risk-free.
I update this privacy statement when the website, providers or legal requirements change. The current version is always available on this page; material changes will be identified by a new date and version identifier.