Skip to main content
Data protection

Privacy
policy.

Which personal data Avepto Sàrl processes, for what purposes, for how long and with whom it is shared, as well as how you can exercise your rights at any time.

Summary

In brief.

Thirty seconds to read. The full legal detail is in the numbered sections below.

Last updated
September 11, 2026
Reference
AVP-LEG-PC-2026.09.5
  1. 01 We collect the data needed to respond to your requests.
  2. 02 Analytics cookies wait for your consent in the European Economic Area and the UK; elsewhere they are active by default and refusable in one click.
  3. 03 We send an editorial briefing only to people who opted in. One-click unsubscribe.
  4. 04 We do not use your data for any other unsolicited commercial purposes.
  5. 05 We do not sell your data.
  6. 06 Some technical providers, notably Cloudflare and Google, may process data in the United States.
  7. 07 You can exercise your rights at any time, by email or by post.
Contents
01 Data controller

Who is responsible for your data?

Identity card, Legal entity

CHE-362.077.556
Company name
Avepto Sàrl
Address
Chemin de l’Epinglier 4 1242 Satigny, Switzerland
Email
02 Legal framework

Which laws apply?

03 Scope

What does this policy cover?

04 Data collected

What data is collected?

Data submitted voluntarily

  1. 01 First and last name
  2. 02 Professional email address
  3. 03 Phone number (optional)
  4. 04 Company and role (optional)
  5. 05 Subject of the request
  6. 06 Message content
  7. 07 Your briefing opt-in choice (unchecked by default)
  8. 08 IP address at the time of sending, kept with the request for security and evidence purposes (the same rule applies to job applications)

Audience measurement, anonymous tier

  1. 01 Approximate country and city, inferred from your connection by Cloudflare, and your truncated IP address (network, not machine)
  2. 02 Browser family and operating system, inferred from the User-Agent header
  3. 03 Pages viewed, date and time of visit
  4. 04 Traffic source (UTM parameters, referring page)
  5. 05 Anonymous per-tab session identifier (non-persistent)

Audience measurement, enriched tier

  1. 01 Browser technical fingerprint, transformed by HMAC-SHA256 cryptographic function before storage (the raw fingerprint is never retained)
  2. 02 Your full IP address, tied to each event
  3. 03 Two texts you type, absent from the anonymous tier: your site-search queries, kept with the event, and the command line typed in the 404 terminal, sent to Google Analytics with the event
05 Purposes

Why is this data processed?

  1. 01 Responding to requests sent via the contact form.
  2. 02 Preparing our reply to your contact request, job application, briefing subscription or meeting request, by summarising for the team the visit path that led to it (see the Automated processing section).
  3. 03 Improving the operation and content of the site (analytics).
  4. 04 Meeting applicable legal obligations.
06 Automated processing

Are your requests analysed automatically?

07 Legal basis and justification

What is the legal basis for this processing?

  1. 01 Your consent, for analytics cookies and certain optional fields of the contact form.
  2. 02 Avepto’s legitimate interest in responding to contact requests and improving its website, where this interest does not override your rights.
  3. 03 Compliance with applicable legal obligations.
08 Recipients

Who has access to your data?

Data recipients: name, country, role and scope.
Recipient Cloudflare, Inc.Country USARole Hosting, CDN, attack protection and protection against automated form submissions (Turnstile), and generation by the Workers AI service of the visit summary attached to our internal notificationsData scope Browsing data, plus hosting of the data entered in the contact, application, newsletter and booking forms (D1 / R2 storage)
Recipient Google LLCCountry USARole Processor: receives analytics events via the Measurement Protocol API at both tiers (under a random per-tab identifier at the anonymous tier, under the transformed session identifier at the enriched tier)Data scope Pseudonymised data, no IP address
Recipient Microsoft CorporationCountry USA / EURole Processor: Clarity session replay (with consent in the European Economic Area, active by default and refusable at any time elsewhere) and, for online appointments, creation of the invitation in Avepto’s Microsoft 365 calendars with a Teams linkData scope Clarity: pseudonymised browsing interactions. Appointments: name, email and meeting subject
Recipient SMTP2GO LtdCountry New Zealand / EURole Processor: delivery of the site’s transactional emails (confirmations, internal notifications, application files)Data scope Form content sent by email, including application documents
Recipient Competent authoritiesCountry CH / EURole Disclosure where required by lawData scope Strict minimum required by law
09 International transfers

Does your data leave Switzerland?

10 Retention

How long is your data kept?

Retention periods: data type and duration.
Data type
Contact-form data
Name, email, phone, company, role, subject, message, briefing opt-in choice, IP address at sending
Retention period
12 months
after the request has been handled, unless an active contractual relationship exists
Data type
Audience measurement data
Anonymous and enriched events, logged in our first-party infrastructure
Retention period
About 90 days
a rolling window that erases itself, with no older archive on our side. The identifier we keep is the fingerprint transformed by HMAC-SHA256, not the raw fingerprint; the IP address is truncated at the anonymous tier and full at the enriched tier; it is tied back to your identity only if you send one of our forms, in which case it is stored alongside your request (see the Automated processing section)
Data type
Job application files
CV, cover letter and attachments, applicant contact details, IP address at sending
Retention period
12 months
after the application is received, unless it progresses towards a hire, as stated on the form
Data type
Newsletter subscription
Email address, consent state and truncated IP address at the time of subscription
Retention period
Until you unsubscribe
every email carries a one-click unsubscribe link
Data type
Online appointments
Name, email, phone, organisation, meeting subject, additional notes and hashed IP address at the time of booking
Retention period
24 months
after the appointment, unless an ongoing contractual relationship exists
Data type
Server logs
Cloudflare
Retention period
Third-party policy
according to Cloudflare’s retention policy
11 Rights

What rights do you have over your data?

  1. 01
    Right of access
    Obtain confirmation that your data is being processed and receive a copy of it.
  2. 02
    Right to rectification
    Request correction of inaccurate or incomplete data.
  3. 03
    Right to erasure
    Request the deletion of your data, subject to legal retention obligations.
  4. 04
    Right to portability
    Receive your data in a structured and commonly used format.
  5. 05
    Right to object
    Object to the processing of your data on legitimate grounds.
12 Security

How is your data protected?

13 Changes

How does this policy change over time?

14 Contact

Who can you contact with questions?

Related documents