Skip to content

Privacy Policy

Last updated: July 16, 2026

1. Controller

The controller responsible for data processing on this website is:

Apesec GmbH
c/o Manuel Füllemann
Hubelweg 6
5723 Teufenthal
Switzerland
Email: info@apesec.ch
Phone: +41 56 520 60 67
UID: CHE-196.727.747

2. Scope and Legal Basis

This privacy policy applies to the website apesec.ch and informs you about the nature, scope, and purpose of the collection and use of personal data.

Personal data is processed in accordance with the Swiss Federal Act on Data Protection (FADP/DSG) and, where applicable, the European General Data Protection Regulation (GDPR). Depending on the processing activity, we rely on the following legal bases:

  • Consent (Art. 6(6) FADP / Art. 6(1)(a) GDPR), e.g. appointment bookings
  • Contract performance or pre-contractual measures (Art. 6(1)(b) GDPR), e.g. contact inquiries
  • Legitimate interest (Art. 6(1)(f) GDPR), e.g. website analytics and ensuring operations

3. Categories of Personal Data Collected

Depending on how you use our website, the following categories of personal data may be collected:

  • Technical data: IP address, browser type, operating system, referrer URL, timestamp (when the website is delivered)
  • Contact data: Name, email address, message content (via the contact form or by email)
  • Booking data: Name, email address, selected time slot (via Cal.com)
  • Usage data: Page URL, referrer, device type, country, and anonymous interaction events (via Umami)

4. Data Collection on Our Website

4.1 Hosting (AWS S3 + CloudFront)

This website is hosted by Amazon Web Services (AWS). Content and data are stored in the Swiss AWS region (Zurich, eu-central-2). Delivery uses AWS CloudFront (Content Delivery Network) with globally distributed edge locations. CloudFront processes technical data (IP address, browser type, timestamp) at the location nearest to you, safeguarded by the AWS Data Processing Addendum with Standard Contractual Clauses. Server access logs are currently not stored permanently. AWS holds certifications (ISO 27001, SOC 2) ensuring compliance with data security standards.

Legal basis: Legitimate interest in the secure provision of the website.

4.2 Contact Form

If you send us inquiries via the contact form, your details (name, email, message) are processed via AWS API Gateway and AWS Lambda, and delivered as an email to our mailbox (see Section 4.3) through AWS Simple Email Service (SES). All these services run in the Swiss AWS region (Zurich, eu-central-2). Your data is used exclusively to process your inquiry and will not be shared with third parties without your consent.

Legal basis: Pre-contractual measures / legitimate interest.

4.3 Email Communication (Google Workspace)

If you contact us directly by email, your details (email address, message content) are processed in our email system. We use Google Workspace (Google Ireland Limited) for this. Processing may take place on servers in the USA. Google LLC is certified under the Swiss-U.S. Data Privacy Framework. Your data is used exclusively to process your inquiry.

Legal basis: Pre-contractual measures / legitimate interest.
Further information: policies.google.com/privacy

4.4 Appointment Booking (Cal.com)

We use the service Cal.com (Cal.com Inc.) for scheduling appointments. If you book an appointment via our website, the data entered (name, email, time slot) will be transferred to Cal.com and processed on servers in the EU.

Legal basis: Consent / pre-contractual measures.
Further information: cal.com/privacy

4.5 Web Analytics (Umami)

We use Umami (Umami Software Inc.) to analyze website usage. Umami is a privacy-friendly analytics solution that does not collect personal data, does not use cookies, and does not track users across websites. All collected data (page URL, referrer, device type, country, and anonymous interaction events such as button clicks) is anonymized. Processing takes place on servers in the EU.

Legal basis: Legitimate interest in improving our web presence.

4.6 Cookies, LocalStorage and External Resources

This website sets no cookies and stores no data in your browser's LocalStorage. All fonts and libraries are served from our own servers. No external CDNs or font services (e.g. Google Fonts) are used. The only exception is the Cal.com booking calendar on the contact page: it loads its code from app.cal.eu and may set technically necessary cookies in its own context (see Section 4.4).

5. International Data Transfers

In connection with the processing activities described in Section 4, personal data may be transferred to the following countries:

  • Switzerland (AWS Zurich: S3, API Gateway, Lambda, SES): Data stored and processed in Switzerland
  • EU / EEA (Cal.com, Umami): Adequate level of data protection as determined by the Swiss Federal Council
  • USA (Google Workspace): Transfer based on the Swiss-U.S. Data Privacy Framework
  • Worldwide (AWS CloudFront edge locations): Technical delivery data, safeguarded by Standard Contractual Clauses (AWS Data Processing Addendum)

We ensure that an adequate level of data protection is guaranteed for any transfer to third countries, whether through adequacy decisions, Standard Contractual Clauses, or other appropriate safeguards.

6. Data Retention

We store personal data only for as long as necessary for the respective purpose or as required by statutory retention obligations:

  • Contact inquiries (form and email): Duration of the business relationship, then according to statutory retention periods (up to 10 years)
  • Server logs: No access logs are currently stored permanently
  • Appointment bookings (Cal.com): According to Cal.com's retention policies
  • Web analytics (Umami): Anonymized data, no personal reference

7. Data Security

We employ appropriate technical and organizational measures to protect your data against unauthorized access, loss, misuse, or destruction. These include:

  • Encrypted transmission via TLS/SSL (HTTPS)
  • Access controls and authorization concepts
  • Regular review of security measures

Despite these measures, absolute security cannot be guaranteed. We recommend that you also take protective measures yourself (e.g., strong passwords, up-to-date software).

8. Your Rights

You have the following rights regarding your personal data:

  • Right of access: You may request information about your data stored with us free of charge at any time.
  • Right to rectification: You may request the correction of inaccurate data.
  • Right to erasure: You may request the deletion of your data, provided no statutory retention obligations apply.
  • Right to restriction: You may request the restriction of processing.
  • Right to data portability: You may request that we provide your data in a commonly used format.
  • Right to object: You may object to the processing of your data.
  • Withdrawal of consent: You may withdraw consent at any time without affecting the lawfulness of processing carried out prior to the withdrawal.

To exercise your rights, please contact us by email at info@apesec.ch. We will process your request within 30 days.

9. Supervisory Authority

You may contact the competent supervisory authority at any time:

Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
3003 Bern
Switzerland
www.edoeb.admin.ch

Where the GDPR applies, you also have the right to lodge a complaint with a supervisory authority in the EU / EEA.

10. Changes to this Privacy Policy

We reserve the right to amend this privacy policy at any time to reflect changes in legal requirements, new technologies, or changes to our services. The current version is published on this website. We recommend that you visit this page regularly.