Privacy Policy
Last updated: June 2026
The German Datenschutzerklärung is authoritative under Swiss law (nDSG).
1. Controller
The controller responsible for processing personal data on this website is:
[LEGAL_NAME]
[STREET_AND_NUMBER]
[POSTAL_CODE] [CITY], Switzerland
Email: contact@pillar5.ch
Privacy contact: [PRIVACY_EMAIL]
2. Scope
This policy applies to pillar5.ch and personal data processed in connection with:
- Website visits (server logs, technical cookies)
- Storage of your language preference in the browser
- Use of the contact form and subsequent email correspondence
No analytics, marketing, or profiling services are used.
3. Legal bases (nDSG)
Processing is permitted where justified by an overriding private or public interest or by law (Arts. 30 and 31 nDSG). The specific bases for each activity are set out below.
4. Contact form
When you use the contact form, we process:
- Name, to handle your inquiry
- Email address, to reply
- Message content
Purpose: Receiving and responding to inquiries.
Legal basis: Art. 31 para. 2 lit. a nDSG (processing in direct connection with initiating or performing pre-contractual steps at your request).
Voluntary: Providing data is voluntary; without name, email, and message we cannot process your inquiry.
Retention: [DATA_RETENTION_CONTACT] (e.g. 12 months after correspondence ends), unless a longer statutory retention period applies.
5. Form processor (Web3Forms)
We use Web3Forms (operated by Web3Creative, India) as a processor under Art. 9 nDSG to transmit contact form submissions.
- Data: Name, email, message; IP address and email hash for spam filtering where applicable
- Purpose: Delivering form content to us
- Location: Amazon Web Services (AWS), US-East, USA
- Sub-processors: AWS; CleanTalk and Akismet (spam filtering, if active)
- Retention at Web3Forms: up to 30 days (free) or 1 year (Pro); server logs up to 2 months (per Web3Forms documentation)
We maintain a data processing agreement with Web3Forms where available.
6. Email correspondence
Replies to your inquiry by email are processed for communication with you. Legal basis: Art. 31 para. 2 lit. a nDSG. Retention as in section 4.
7. Hosting and server logs
When you visit the site, logs may include IP address, date/time, URL, browser type, referrer, and HTTP status.
Hosting: Cloudflare, Inc. (Cloudflare Pages / CDN)
Location: USA and global edge network
Purpose: Operation, security, and stability
Legal basis: Art. 31 para. 1 nDSG (overriding private interest)
Retention: [LOG_RETENTION_PERIOD] (e.g. generally up to 30 days for Cloudflare logs)
8. Browser storage (localStorage)
When you switch language, we store your choice under pillar5-lang (de, en, or fr) in localStorage so it persists on return visits. No tracking data is stored; nothing is sent to third parties.
Legal basis: Art. 31 para. 1 nDSG. You may delete the entry in your browser settings at any time.
9. Cookies
No analytics or marketing cookies are used.
Cloudflare may set technically necessary cookies (e.g. __cf_bm, cf_clearance) for security and delivery. These are not used for advertising or profiling.
Legal basis: Art. 31 para. 1 nDSG. No separate cookie consent banner is required for this configuration; information is provided here.
10. Fonts
Fonts (Instrument Serif, Source Sans 3) are self-hosted on pillar5.ch. No personal data is sent to Google Fonts or other third-party font CDNs.
11. Recipients
Recipients may include Cloudflare, Inc.; Web3Forms / Web3Creative; AWS (on Web3Forms’ behalf); CleanTalk / Akismet (spam filtering, if active). No sale of personal data or sharing for marketing.
12. International transfers
Data may be processed outside Switzerland, especially in the USA.
- Cloudflare: certified under the Swiss-US Data Privacy Framework (Art. 16 para. 1 nDSG).
- Web3Forms / AWS: safeguards under Art. 16 para. 2 lit. d nDSG (standard contractual clauses) and/or Art. 17 nDSG (pre-contractual steps to handle your inquiry).
13. Security
We apply appropriate technical and organisational measures under Art. 8 nDSG, including HTTPS, data minimisation, self-hosted fonts, and established hosting.
14. Automated decisions
We do not make automated individual decisions with legal or similarly significant effect under Art. 21 nDSG.
15. Your rights
Under nDSG you may request access (Art. 25), rectification (Art. 32 para. 1), deletion or restriction where applicable (Art. 32 para. 2), and data portability where Art. 28 applies. Contact [PRIVACY_EMAIL]. We generally respond within 30 days and may request proof of identity.
16. Supervisory authority
Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Feldeggweg 1, 3003 Bern, Switzerland
www.edoeb.admin.ch
17. Changes
We may update this policy when processing, services, or law change. The version published on this page with the date above applies.