Privacy notice

Translation of the German version, checked against the source on 16 September 2026. German original.

This privacy notice informs you, under Article 19 of the revised Swiss Federal Act on Data Protection (FADP, called nDSG in the German original, in force since 1 September 2023), about the processing of your personal data on this website.

1. Controller

Responsible for data processing on this website:

Daniel Bidoli
Bidoli IT-Services
Feldeggweg 1
5033 Buchs AG, Switzerland

Email:
Phone: +41 76 753 37 86

2. Hosting and server location

This website is hosted by ALL-INKL.COM – Neue Medien Münnich in Germany. When you access this website, the web host automatically records the following data in server log files:

  • IP address of the requesting device
  • Date and time of access
  • Name and URL of the file requested
  • Browser, operating system and device
  • Referrer URL (previously visited page)

Purpose: ensuring operation, security and error analysis.
Legal basis: legitimate interests (Art. 31 FADP).
Retention period: generally 7–30 days, followed by automatic deletion.
Data processing: the data is processed exclusively on servers in Germany. Under Swiss data protection law, Germany is considered a country with an adequate level of data protection (binding list of countries established by the Federal Council in Annex 1 to the Data Protection Ordinance, DPO).

3. Contact form

When you send us a message using the contact form, we collect the following data:

  • First name and last name (last name optional)
  • Company (optional)
  • Email address
  • Phone number (optional)
  • Preferred contact method (optional)
  • Content of your enquiry

Purpose: processing and responding to your enquiry.
Legal basis: steps prior to entering into a contract / legitimate interests (Art. 31 FADP).
Retention period: your data is deleted once your enquiry has been fully dealt with and no statutory retention obligation applies (generally after 12 months).
Disclosure: no disclosure to third parties, with one exception: if you have consented to marketing measurement, we transmit the hashed contact details described in section 11 to Meta. Without this consent, the data is used exclusively to process your enquiry.
Transmission: the form is transmitted in encrypted form via HTTPS. Email is processed through our host’s SMTP server.

4. Fonts

This website uses the fonts “IBM Plex Sans” and “IBM Plex Mono”. They are served exclusively from our own server. No connection is made to Google Fonts or any other external provider, and no data is transmitted to third parties.

The IBM Plex fonts are licensed under the SIL Open Font License, which permits self-hosting.

Purpose: consistent and correct display of fonts.
Transmission to third parties: none.

5. Technical performance measurement (Web Vitals)

To improve this website’s loading speed and stability, your browser measures technical indicators during your visit (loading time of the largest visible element, response time to input and layout stability) and sends them to our own server. We store only the measured value, the page visited, the screen size category, the connection type and a timestamp rounded to the hour. The stored measurements contain no IP address or browser identifier; no cookies are set, no identifiers are stored in your browser and no data is passed to third parties.

Purpose: measuring and improving this website’s loading speed and stability.
Legal basis: legitimate interest in a functional and fast website (Art. 31(1) FADP; for visitors from the EEA, Art. 6(1)(f) GDPR).
Retention period: Measurements are stored in monthly files. When the first measurement of a new month is accepted, the endpoint removes older files; the intended retention covers the current and two previous months. Without new measurements, this cleanup is not triggered.
Note: independently of this, our host keeps the server log file described in section 2.

6. Cookies

This website does not set any cookies without your consent. Not even technically necessary ones: no session data is stored. On your first visit, a question appears at the bottom. Under Show purposes and choose individually, you can separately allow or reject two categories: Statistics and Marketing. Accept all allows both; Reject allows neither.

If you allow Statistics, Google Tag Manager and Google Analytics are loaded (see section 10). Google Analytics then sets these two cookies:

  • _ga: distinguishes visitors from one another. Lifetime: 2 years.
  • _ga_LSLXY8CH1X: links the history of a visit. Lifetime: 2 years.

If you allow Marketing, the Meta Pixel is also loaded (see section 11). It sets this cookie:

  • _fbp: recognises your browser across page views. Lifetime: 3 months.

The two categories are independent. Consenting only to statistics does not trigger a transmission to Meta, and vice versa.

Your choice is remembered in your browser’s local storage. We use localStorage instead of a cookie (keys cookie_zustimmung and marketing_zustimmung). This lets us respect your choice on subsequent page visits. We also send your decision to our own server to record it. The information stored for this purpose is described under Evidence of your consent.

Changing or withdrawing consent: you can reopen the question at any time through Cookie settings in the footer of every page. The checkboxes show your current choice. If you withdraw a category, its cookies are deleted and no new ones are set.

7. Links to social networks and external platforms

Depending on the profiles configured, this website contains simple links to Instagram and Facebook (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland), LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland) and WhatsApp (WhatsApp LLC, 1601 Willow Road, Menlo Park, CA 94025, USA). The contact page also links to our address on Google Maps (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland): a simple link, not an embedded map. No social media content or plugins are embedded directly in the website.

The About us page also links to the owner’s book on Amazon (Amazon Europe Core S.à r.l., 38 avenue John F. Kennedy, L-1855 Luxembourg, or the Amazon entity for the relevant country). To direct you to the Amazon shop for your country with the appropriate currency, a script evaluates your browser’s language and country settings. This evaluation takes place exclusively locally in your browser: nothing is stored or transmitted to us, Amazon or third parties. The link contains no advertising or affiliate identifier.

You are taken to the relevant platform only when you click one of these links. The privacy policies of the relevant platform then apply:

8. Your rights

Under the revised Swiss Federal Act on Data Protection (FADP), you have the following rights:

  • Right of access (Art. 25 FADP): you may request information at any time about the data stored about you.
  • Right to rectification (Art. 32 FADP): you may request that inaccurate data be corrected.
  • Right to erasure (Art. 32 FADP): you may request deletion of your data where no statutory retention obligation applies.
  • Right to data delivery (Art. 28 FADP): you may request that your data be provided in a commonly used electronic format.
  • Right to object: you may object to data processing insofar as it is based on legitimate interests.

Please send requests to:


We generally respond to access requests within 30 days (Art. 25 FADP). Access is free of charge.

9. Right to complain to the supervisory authority

You have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC):

FDPIC, Feldeggweg 1, 3003 Bern
www.edoeb.admin.ch

10. Google Tag Manager and Google Analytics

This website uses Google Tag Manager to manage analytics tags centrally and Google Analytics 4 to measure visitor numbers. Tag Manager also loads the Meta Pixel for the advertising measurement described in section 11. Statistics and marketing are enabled according to your separate choices. Providers: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

Tag Manager and Analytics are loaded only after your express consent. We use the basic version of Google Consent Mode v2. If you reject or do not respond, no Google script is requested, no consent signal is transmitted and no connection is made to Google.

Identifiers used: Tag Manager container GTM-MT6JLJT3 and Analytics measurement ID G-LSLXY8CH1X.

After your consent, we collect the pages visited, the time and duration of the visit, approximate location, device type, browser and the referring page. According to Google, IP addresses of visitors from the EU, Switzerland and the United Kingdom are used to derive an approximate location and then discarded without being logged or stored.

Purpose: identifying which content is read in order to improve the website.
Legal basis: your consent (Art. 6(6) FADP). For visitors from the EU: Art. 6(1)(a) GDPR.
Retention period: event data at Google: 14 months; cookies: 2 years.
Disclosure abroad: the data may be processed in the USA. The USA is considered a third country under data protection law. For disclosures of data from Switzerland, the Swiss-U.S. Data Privacy Framework applies to US companies certified under that framework. It has been in force since 15 September 2024 and exists separately from the EU-U.S. Data Privacy Framework.
Withdrawal: at any time through Cookie settings in the footer of every page. Withdrawal takes effect immediately; cookies already set are deleted.
Google privacy policy: policies.google.com/privacy

11. Meta Pixel (Facebook and Instagram)

We advertise on Facebook and Instagram. To determine whether an advertisement led to an enquiry, we use the Meta Pixel, a measurement tool provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland.

The Pixel is loaded only after your express consent. If you do not allow the Marketing category, no Meta script is requested, no cookie is set and no connection is made to Meta. Consent to statistics alone is not sufficient; the two categories require separate permission.

Data processed: pages visited and the time, submission of the contact form, clicks on our phone number and WhatsApp, plus device, browser and IP address. We do not transmit names, email addresses or the content of your message in this process.
Cookie: _fbp, lifetime: 3 months. If you arrived through an advertisement, also _fbc.
Purpose: measuring advertising effectiveness and targeting our advertisements.
Legal basis: your consent under Art. 6(6) FADP; for visitors from the EU, Art. 6(1)(a) GDPR.
Joint controllership: we and Meta are jointly responsible for collecting and transmitting the data; Meta alone is responsible for further processing.
Disclosure abroad: data is processed in the USA. The USA is considered a third country under data protection law. For disclosures of data from Switzerland, the Swiss-U.S. Data Privacy Framework applies to US companies certified under that framework. It has been in force since 15 September 2024 and exists separately from the EU-U.S. Data Privacy Framework.
Withdrawal: at any time through Cookie settings in the footer of every page. Withdrawal takes effect immediately; cookies already set are deleted.
Meta privacy policy: facebook.com/privacy/policy

Transmission from the server (Conversions API)

In addition to the Pixel in the browser, we transmit a submitted contact enquiry to Meta from our server (Conversions API). The reason is technical: ad blockers often prevent the Pixel from loading in the browser. Without the second transmission, the picture of which advertisement led to an enquiry would be incomplete.

This also takes place only with your consent. If you have not allowed the Marketing category, there is no server-side transmission. Your choice is sent with the form submission and evaluated there.

Data transmitted: your email address, phone number, first and last name and country code, each exclusively as a cryptographic hash (SHA-256), not in plain text. Meta can match these hashes against contact details it already knows and associate them with an account. The hashes must therefore not be equated with anonymous data. This is accompanied by your IP address, browser identifier, page visited and, where present, the Pixel cookies _fbp and _fbc.
The content of your message is not transmitted. What you write to us remains between you and us.
Timing: only after we have received your enquiry.
Purpose: measuring advertising effectiveness. The browser and server reports carry the same identifier so that an enquiry is not counted twice.
Legal basis, third country and withdrawal: as described above in this section.

Evidence of your consent

We must be able to demonstrate that consent was given. For every decision in the cookie banner, we therefore store the time, the categories selected, the version of the banner text and the page visited.

Your IP address is not stored in this record. Instead, we generate a pseudonymous verification value from the IP address, browser identifier and a secret random value. It can associate decisions with the same technical characteristics, but does not reliably identify a person or a device. IP address and browser identifier are not stored in plain text in this consent log. Independently of this, our host keeps the server log files described in section 2.

12. Connection to LinkedIn (the “Bidoli Social Publishing” app)

In addition to this website, we operate our own application called Bidoli Social Publishing. It connects to our own “Bidoli IT-Services” company page through LinkedIn’s programming interfaces (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland). This section concerns only that application; it does not apply simply to visiting this website.

Who uses the application: exclusively us, as the operators of the company page. The application is not available to third parties and does not access LinkedIn pages belonging to others.

What data is processed

  • Login details of the authorised person: the name and LinkedIn identifier of the account connecting the application to the company page. They serve solely to confirm that the connection comes from an authorised administrator.
  • Content of our own company page: posts we schedule or publish there, together with their publication status.
  • Feedback on these posts: comments and reactions to our own posts so that we can respond to them.
  • Page metrics: views, interactions and follower counts in the aggregated form provided by LinkedIn.

Not processed: profile data of visitors to our page, contact networks, private messages or data from pages we do not own.

Purpose and legal basis

The purpose is to manage our own company presence: schedule and publish posts, respond to comments and assess the impact of our own posts. The legal basis is our legitimate interest in organised external communications (Art. 31(1) FADP). We do not analyse the behaviour of individuals, create profiles, match this information with other data sources or use it to target advertisements.

Access token, storage and retention

For access, LinkedIn issues the application an access token valid for two months. This token is held exclusively on our own access-protected infrastructure in Switzerland and is not passed to anyone. Retrieved content and metrics are kept only as long as needed for ongoing editorial planning, for no more than twelve months; they are then deleted. We do not sell them or disclose them to third parties.

The redirect page www.bidoli-it.ch/oauth-rueckgabe only receives and displays the one-time authorisation code when the connection is established. It stores nothing, sets no cookies and is excluded from search engines. The same applies to the equivalent /threads-oauth redirect page for connecting to Threads (Meta).

Withdrawal

The connection can be ended at any time: either in LinkedIn’s settings under “Privacy → Permitted services”, in the company page administration, or by an informal message to info@bidoli-it.ch. Withdrawal invalidates the access token; we delete content and metrics already retrieved on request.

LinkedIn is responsible for processing on the platform itself; its privacy policy applies there. Where LinkedIn transfers data to the USA, it relies on the European Commission’s Standard Contractual Clauses and the EU-US Data Privacy Framework.

13. Data security

This website uses SSL/TLS encryption (indicated by the padlock symbol in the browser). All data submitted through forms is transmitted in encrypted form. We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss or misuse (Art. 8 FADP).

14. Changes to this privacy notice

We reserve the right to adapt this privacy notice as necessary, in particular following changes to the legal basis or the use of new services. The current version is always available on this page.

Last updated: September 2026 · Legal basis: FADP (SR 235.1), in force since 1 September 2023

Back to contact →