Privacy Policy

1. Introduction and Scope

With this privacy policy, I comprehensively inform you about the nature, scope, and purposes of the collection and use of your personal data by pro|cyber by Bühlmann (Einzelfirma).

This privacy policy applies to my website https://procyber.ch as well as all associated online offers, services, and communication channels.

I take the protection of your personal data very seriously and treat your personal data confidentially and in accordance with Swiss data protection law (revFADP) and the General Data Protection Regulation (GDPR) of the European Union.

The use of my website is generally possible without providing personal data. Insofar as personal data is collected on my pages, this is always done on a voluntary basis. These data will not be passed on to third parties without your explicit consent.

Special, supplementary, or further privacy policies as well as other legal documents such as General Terms and Conditions (GTC), terms of use, or conditions of participation may apply to individual or additional offers.

2. Controller

The controller responsible for data processing within the meaning of data protection legislation is:

pro|cyber by Bühlmann Einzelfirma

5306 Tegerfelden

Switzerland

Email:  [email protected]

Website: https://procyber.ch

Data Protection Officer: Sem Bühlmann

If you have any questions regarding data protection, you can contact me at any time.

3. Definitions

To make this privacy policy easy to understand, I use the following definitions:

Personal Data:
All information relating to an identified or identifiable natural person. This includes, for example, name, address, email address, telephone number, or IP address.
Processing:
Any handling of personal data, irrespective of the means and procedures applied, in particular the collection, storage, keeping, use, alteration, disclosure, archiving, deletion, or destruction of data.
Data Subject:
The natural person whose personal data is processed.
Controller:
The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processor:
A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
Consent:
Any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
Cookies:
Small text files stored on your device that can contain certain information. A distinction is made between session cookies (deleted after the browser session ends) and persistent cookies (stored for a defined period).

4. Legal Basis

I process personal data in accordance with Swiss data protection law, in particular the revised Federal Act on Data Protection (revFADP) of September 25, 2020, and the Data Protection Ordinance (DPO).

Under Swiss law, the processing of personal data is generally permitted provided that:

  • there is no statutory prohibition
  • the data subject has given their consent
  • there is an overriding private or public interest
  • the processing is necessary for the performance of a contract

Stricter requirements apply to the processing of particularly sensitive personal data or to high-risk profiling.

Insofar as the General Data Protection Regulation (GDPR) of the European Union is applicable (e.g., for offers to persons in the EU/EEA), I process personal data on the following legal bases in accordance with Art. 6(1) GDPR:

a) Consent (Art. 6(1)(a) GDPR)
The data subject has given consent to the processing of their personal data for one or more specific purposes. Consent can be revoked at any time with effect for the future.

b) Performance of a Contract (Art. 6(1)(b) GDPR)
Processing is necessary for the performance of a contract or to take steps prior to entering into a contract.

c) Legal Obligation (Art. 6(1)(c) GDPR)
Processing is necessary for compliance with a legal obligation to which I am subject.

d) Vital Interests (Art. 6(1)(d) GDPR)
Processing is necessary to protect the vital interests of the data subject or of another natural person.

e) Public Interest (Art. 6(1)(e) GDPR)
Processing is necessary for the performance of a task carried out in the public interest.

f) Legitimate Interests (Art. 6(1)(f) GDPR)
Processing is necessary for the purposes of my legitimate interests or those of a third party, except where such interests are overridden by the interests or fundamental rights of the data subject.

5. Types of Data Collected

I collect and process various categories of personal data. The specific data collected depends on the services and features you use.

Overview of data categories:

Master Data:
Examples: Name, first name, salutation, title
Basic personal information for identification purposes
Contact Data:
Examples: Email address, phone number, postal address
Information for contact and communication
Technical Data:
Examples: IP address, browser type and version, operating system, device type, screen resolution
Information automatically collected when using my website
Usage Data:
Examples: Visited pages, time spent, click paths, access times
Information about your usage behavior on my website
Content Data:
Examples: Text inputs in forms, message content, files
Information actively provided by you

Data Sources:

Data is collected in various ways:

  • Directly from you: by entering data in forms, emails, registration
  • Automatically: through technical logging during website visits
  • From third parties: e.g., through payment providers or advertising partners (if applicable)

6. Purposes of Data Processing

I process your personal data for the following purposes:

  • Provision and Operation of my Website
    To make my website and its functions available to you
    Legal basis: Legitimate interest
  • Ensuring IT Security
    Protecting my systems against misuse, attacks, and technical disruptions
    Legal basis: Legitimate interest
  • Processing Contact Requests
    To answer your inquiries and communicate with you
    Legal basis: Initiation of a contract / Legitimate interest
  • Fulfillment of Legal Obligations
    To comply with statutory retention and documentation obligations
    Legal basis: Legal obligation

7. General Data Processing

Contact Forms

When you contact me via a contact form, the data you provide (name, email address, phone number, message) will be processed and stored to handle your inquiry.

  • Processed data: Name, email address, optional phone number, message content
  • Legal basis: Performance of a contract or initiation of a contract (Art. 6(1)(b) GDPR / Art. 31(2)(a) revFADP) or legitimate interest (Art. 6(1)(f) GDPR / Art. 31(1) revFADP)
  • Retention period: The data will be deleted as soon as it is no longer required to achieve the purpose of its collection and there are no statutory retention obligations.

Server Log Files

Every time you access my website, technical data is automatically recorded in server log files. This is necessary for technical and security reasons.

  • Processed data: IP address, date and time of access, requested page/file, amount of data transferred, browser type and version, operating system used, referrer URL, hostname of the accessing computer
  • Legal basis: Legitimate interest (Art. 6(1)(f) GDPR / Art. 31(1) revFADP) – Ensuring system security and error analysis
  • Retention period: Log files are automatically deleted after 30 days unless longer retention is required for evidence purposes.

8. Detailed Data Processing (Third-Party Services)

I use third-party services to operate, analyze, and improve my website. Below I inform you in detail about the services used.

Email Transmission

Brevo (Sendinblue)
  • Provider: Sendinblue SAS
  • Location: France (European Union)
  • Purpose: Technical transmission of contact form requests to our own email address. No marketing, no newsletter, no mass mailing function in use — Brevo is used exclusively for the technical transmission of the notification when someone fills out the contact form.
  • Data categories: Name, email address, optional phone number, message content
  • Legal basis: Legitimate interest (Art. 6(1)(f) GDPR / Art. 31(1) revFADP) — Processing of contact requests
  • Privacy policy: https://www.brevo.com/legal/privacypolicy/

Hosting & Infrastructure

Cloudflare
  • Provider: Cloudflare Inc.
  • Location: USA
  • Purpose: CDN, DDoS protection, and performance optimization
  • Data categories: IP address, browser information, request data
  • Legal basis: Legitimate interest (Art. 6(1)(f) GDPR)
  • Privacy policy: https://www.cloudflare.com/privacypolicy/

Security

Cloudflare Turnstile
  • Provider: Cloudflare Inc.
  • Location: USA
  • Purpose: Privacy-friendly bot protection without CAPTCHAs
  • Data categories: IP address, browser information
  • Legal basis: Legitimate interest (Art. 6(1)(f) GDPR)
  • Privacy policy: https://www.cloudflare.com/privacypolicy/

9. International Data Transfer

Data Transfer to Third Countries

As part of my data processing, personal data is also transferred to recipients outside Switzerland and the European Economic Area (EEA). This particularly concerns the following countries:

USA

For these countries, there is no adequacy decision by the European Commission or the Federal Data Protection and Information Commissioner (FDPIC) confirming a level of data protection comparable to that of Switzerland or the EU.

Safeguards for Data Transfer

To ensure an adequate level of data protection, I rely on the following safeguards:

  • Standard Contractual Clauses (SCCs): I have concluded the Standard Contractual Clauses approved by the European Commission with the respective recipients, which contractually guarantee an adequate level of data protection.
  • Adequacy Assessment: Before any data transfer, I check whether the recipient country offers an adequate level of data protection or whether additional protective measures are required.
  • Additional Protective Measures: If necessary, I implement technical and organizational measures such as encryption, pseudonymization, or contractual agreements to ensure the protection of your data.

Note on US Transfers

Some of my service providers are based in the USA. The USA currently does not have a level of data protection equivalent to that in Switzerland or the EU. However, I have agreed to Standard Contractual Clauses with these providers and/or they have committed to complying with adequate data protection standards.

Please note that US authorities may have access to transferred data under certain circumstances. By using the corresponding services (after being informed and, if applicable, providing consent), you accept this residual risk.

Your Rights

You have the right to request a copy of the agreed Standard Contractual Clauses or information about the implemented protective measures.

10. Retention Periods

I only store your personal data for as long as is necessary to fulfill the purposes for which it was collected or as required by statutory retention obligations.

General Principles

The storage duration depends on:

  • the purpose of data processing
  • statutory retention obligations
  • legitimate interests (e.g., defense against legal claims)
  • the nature of the data and the risk to the data subjects

Specific Retention Periods

  • Contact inquiries: 12 months (purpose fulfillment / legitimate interest)
  • Server log files: 30 days (IT security)
  • Accounting records / invoices: 10 years (Art. 958f CO (Swiss law))
  • Contracts and business correspondence: 10 years after the end of the contract (Art. 958f CO / limitation periods)

Statutory Retention Obligations (Switzerland)

Under Swiss law, the following retention obligations apply in particular:

  • Art. 958f CO: Business books and accounting records as well as the annual report and the audit report must be kept for ten years.
  • Tax law regulations may provide for additional retention obligations.

After the respective periods expire, the data is routinely deleted unless it is still required for other purposes.

11. Data Security

I take appropriate technical and organizational security measures (TOMs) to protect your personal data against unauthorized access, loss, misuse, or destruction. The specific measures implemented are based on the current state of the art and are regularly reviewed and adapted.

My security measures may include in particular, depending on the risk and protection requirements:

  • Encrypted data transmission (e.g., TLS/SSL)
  • Access restrictions and authorization concepts
  • Protection of IT infrastructure through suitable security systems
  • Regular data backups
  • Maintenance and updating of my systems
  • Confidentiality obligations for employees
  • Careful selection and contractual binding of service providers
  • Processes for detecting and handling security incidents

Security in International Data Transfers

If personal data is transferred to recipients in countries without an adequate level of data protection, I ensure through appropriate safeguards that your data is adequately protected. This may include, in particular, Standard Contractual Clauses, contractual agreements, or technical protective measures such as encryption.

Limitation

Despite all precautions, no data transmission over the Internet can be guaranteed to be completely secure.

In the event of a data breach that is likely to result in a high risk to your rights and freedoms, I will inform you without undue delay and notify the competent authorities.

12. Rights of the Data Subject

As a data subject, you have various rights regarding your personal data. These rights arise from the Swiss Data Protection Act (revFADP) and, where applicable, from the General Data Protection Regulation (GDPR).

Right of Access
You have the right to request confirmation from me as to whether I process personal data concerning you. If this is the case, you have the right to access this data as well as further information such as processing purposes, categories of data, recipients, and planned storage duration.
Right to Rectification
You have the right to request the rectification of inaccurate or the completion of incomplete personal data.
Right to Erasure ("Right to be Forgotten")
You have the right to request the erasure of your personal data under certain conditions. This applies in particular if the data is no longer necessary for the purposes for which it was collected or if you revoke your consent.
Right to Restriction of Processing
You have the right to request the restriction of the processing of your data under certain conditions, e.g., if you contest the accuracy of the data or if the processing is unlawful.
Right to Data Portability
You have the right to receive the personal data concerning you, which you have provided to me, in a structured, commonly used, and machine-readable format and to transmit those data to another controller.
Right to Object (Art. 21 GDPR)
You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you, provided this is based on legitimate interests.
In the case of direct marketing, you can object at any time without giving reasons.
Right to Withdraw Consent
Insofar as the processing is based on consent, you have the right to withdraw it at any time with effect for the future. The lawfulness of the processing carried out up to the time of withdrawal remains unaffected.
Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law.

Competent Supervisory Authority in Switzerland:

Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
CH-3003 Bern
Tel.: +41 58 462 43 95
Website: www.edoeb.admin.ch

For offers to persons in the EU/EEA, you can also contact the data protection supervisory authority responsible for your country.

Exercising Your Rights

To exercise your rights, you can contact me at any time:

Email: [email protected]

To process your request, I require proof of identity to ensure that the request comes from the authorized person. I generally process your request within one month.

13. Updates and Contact

Updates to this Privacy Policy

I may adapt and update this privacy policy from time to time to take into account changes in my data processing practices, new legal requirements, or other developments.

Changes will be published on my website. In the event of material changes affecting your rights or the nature of the data processing, I will inform you separately – as far as possible and appropriate.

I recommend that you regularly review this privacy policy to stay informed about the current state of my data protection practices.

Contact for Questions

If you have any questions about this privacy policy or the processing of your personal data, you can contact me at any time:

pro|cyber by Bühlmann

Email: [email protected]