Contents
Who is responsible for your data?
The entity responsible for the collection and processing of personal data described in this policy is:
Identity card, Legal entity
CHE-362.077.556- Company name
- Avepto Sàrl
- Address
- Chemin de l’Epinglier 4 1242 Satigny, Switzerland
- Phone
- +41 22 552 96 70
Which laws apply?
This policy is issued in accordance with the Swiss Federal Act on Data Protection (FADP, RS 235.1, in force since 1 September 2023) and its implementing ordinance (DPO).
The General Data Protection Regulation (GDPR, EU Regulation 2016/679) applies additionally to visitors located in the European Economic Area.
What does this policy cover?
This policy concerns exclusively the personal data collected through the avepto.ch corporate website. The corporate website does not handle client data related to Avepto’s managed-service offerings.
Client data managed as part of our managed services is hosted, where possible, on infrastructure located in Switzerland and is governed by the service contracts and data-processing agreements entered into with each client.
Certain management and supervision tools used as part of these services may involve transfers to providers located outside Switzerland, in compliance with FADP requirements.
What data is collected?
Avepto distinguishes two categories of data collected through the corporate website, depending on whether you submit it actively or it is recorded by your browsing.
Data submitted voluntarily
When you use the contact form, the following data is collected:
- 01 First and last name
- 02 Professional email address
- 03 Phone number (optional)
- 04 Company and role (optional)
- 05 Subject of the request
- 06 Message content
- 07 Your briefing opt-in choice (unchecked by default)
- 08 IP address at the time of sending, kept with the request for security and evidence purposes (the same rule applies to job applications)
This data is sent by email to the Avepto team and stored in the website backend.
Audience measurement, anonymous tier
Before your consent, we collect anonymous technical data via our own analytics infrastructure, with no third-party measurement tool:
- 01 Approximate country and city, inferred from your connection by Cloudflare, and your truncated IP address (network, not machine)
- 02 Browser family and operating system, inferred from the User-Agent header
- 03 Pages viewed, date and time of visit
- 04 Traffic source (UTM parameters, referring page)
- 05 Anonymous per-tab session identifier (non-persistent)
Legal basis: legitimate interest (aggregate audience measurement). No browser fingerprint or third-party cookie at this stage.
Audience measurement, enriched tier
At the enriched tier, the same data is tied to a stable session identifier, which lets us reconstruct the path of a visit rather than isolated pages. This tier waits for your consent in the European Economic Area and the United Kingdom; elsewhere it is active by default and refusable at any time (see the cookie policy):
- 01 Browser technical fingerprint, transformed by HMAC-SHA256 cryptographic function before storage (the raw fingerprint is never retained)
- 02 Your full IP address, tied to each event
- 03 Two texts you type, absent from the anonymous tier: your site-search queries, kept with the event, and the command line typed in the 404 terminal, sent to Google Analytics with the event
Legal basis: your consent in the European Economic Area and the United Kingdom; elsewhere, the Swiss regime of article 45c of the Telecommunications Act, which requires that you be informed and allowed to refuse. In both cases refusing takes one click on the “Cookies” link in the footer. See the cookie policy for retention details.
Why is this data processed?
The data collected is processed for the following purposes:
- 01 Responding to requests sent via the contact form.
- 02 Preparing our reply to your contact request, job application, briefing subscription or meeting request, by summarising for the team the visit path that led to it (see the Automated processing section).
- 03 Improving the operation and content of the site (analytics).
- 04 Meeting applicable legal obligations.
Avepto sends an editorial briefing only to people who opted in. We do not use your data for any other unsolicited commercial purposes. One-click unsubscribe is in every email.
Are your requests analysed automatically?
Requests received through our forms (contact, application, briefing, appointment) may be pre-analysed by automated tools in order to speed up their handling, triage, and categorisation.
When you send a contact request, a job application, a briefing subscription or a meeting request, your request is tied to your browser’s analytics session identifier, the very one our audience measurement uses. From it we build a visit summary attached to the internal notification sent to the team: pages viewed and how often, notable actions, referring domain, campaign parameters (UTM), approximate city and country, browser and operating system. If you accepted enriched measurement, that summary also covers your earlier visits (how many there were, and your most-viewed pages); otherwise it is limited to the current visit.
The log of those events is also sent to Cloudflare Workers AI, a language model running at our hosting provider, which writes a short observational paragraph added to that same internal notification. This step is optional: if it fails, the notification goes out without that paragraph. The corresponding processing is described in Cloudflare’s documentation on Workers AI data usage.
That summary is preparation material, read by a member of the Avepto team who then handles your request. It may shape the way we reply to you, but no decision producing legal or similarly significant effects is taken solely on the basis of automated processing.
What is the legal basis for this processing?
Data processing relies on:
- 01 Your consent, for analytics cookies and certain optional fields of the contact form.
- 02 Avepto’s legitimate interest in responding to contact requests and improving its website, where this interest does not override your rights.
- 03 Compliance with applicable legal obligations.
You can withdraw your cookie consent at any time via the “Cookies” link in the footer, which opens the cookie policy and its management panel.
Who has access to your data?
Personal data is neither sold, rented, nor transmitted to third parties for commercial purposes. It may be shared with the following recipients:
| Recipient | Country | Role | Data scope |
|---|---|---|---|
| Recipient Cloudflare, Inc. | Country USA | Role Hosting, CDN, attack protection and protection against automated form submissions (Turnstile), and generation by the Workers AI service of the visit summary attached to our internal notifications | Data scope Browsing data, plus hosting of the data entered in the contact, application, newsletter and booking forms (D1 / R2 storage) |
| Recipient Google LLC | Country USA | Role Processor: receives analytics events via the Measurement Protocol API at both tiers (under a random per-tab identifier at the anonymous tier, under the transformed session identifier at the enriched tier) | Data scope Pseudonymised data, no IP address |
| Recipient Microsoft Corporation | Country USA / EU | Role Processor: Clarity session replay (with consent in the European Economic Area, active by default and refusable at any time elsewhere) and, for online appointments, creation of the invitation in Avepto’s Microsoft 365 calendars with a Teams link | Data scope Clarity: pseudonymised browsing interactions. Appointments: name, email and meeting subject |
| Recipient SMTP2GO Ltd | Country New Zealand / EU | Role Processor: delivery of the site’s transactional emails (confirmations, internal notifications, application files) | Data scope Form content sent by email, including application documents |
| Recipient Competent authorities | Country CH / EU | Role Disclosure where required by law | Data scope Strict minimum required by law |
Does your data leave Switzerland?
Hosting of the site by Cloudflare, Inc. involves a transfer of browsing data to the United States. Cloudflare adheres to the Swiss-U.S. Data Privacy Framework.
Audience measurement events are collected by our first-party infrastructure, operated on our hosting (see Cloudflare in the processor list above). A copy of the events, at both tiers, is transmitted to Google LLC via the Measurement Protocol API to feed our marketing dashboard, without any IP address. When you send one of our forms, the log of your events is also sent to Cloudflare’s Workers AI service, which writes the summary described in the Automated processing section. The enriched tier’s browser fingerprint is computed in your browser, sent to our server over an encrypted connection and transformed by the HMAC-SHA256 cryptographic function before any storage; only that transformed value is kept or passed to third parties.
The site’s internal search sends the text you type to Cloudflare, our hosting provider, in order to look up the content of our own pages. Without your consent to audience measurement, only the fact that a search took place is counted: the text you typed is not recorded in our visit statistics.
No client data related to managed-service offerings transits through the corporate website.
How long is your data kept?
Data is retained for the time strictly necessary for the purpose pursued, then deleted or archived in line with legal obligations.
| Data type | Retention period |
|---|---|
| Data type Contact-form data Name, email, phone, company, role, subject, message, briefing opt-in choice, IP address at sending | Retention period 12 months after the request has been handled, unless an active contractual relationship exists |
| Data type Audience measurement data Anonymous and enriched events, logged in our first-party infrastructure | Retention period About 90 days a rolling window that erases itself, with no older archive on our side. The identifier we keep is the fingerprint transformed by HMAC-SHA256, not the raw fingerprint; the IP address is truncated at the anonymous tier and full at the enriched tier; it is tied back to your identity only if you send one of our forms, in which case it is stored alongside your request (see the Automated processing section) |
| Data type Job application files CV, cover letter and attachments, applicant contact details, IP address at sending | Retention period 12 months after the application is received, unless it progresses towards a hire, as stated on the form |
| Data type Newsletter subscription Email address, consent state and truncated IP address at the time of subscription | Retention period Until you unsubscribe every email carries a one-click unsubscribe link |
| Data type Online appointments Name, email, phone, organisation, meeting subject, additional notes and hashed IP address at the time of booking | Retention period 24 months after the appointment, unless an ongoing contractual relationship exists |
| Data type Server logs Cloudflare | Retention period Third-party policy according to Cloudflare’s retention policy |
What rights do you have over your data?
In accordance with the FADP (art. 25 et seq.), you have the following rights regarding data concerning you:
- 01 Right of accessObtain confirmation that your data is being processed and receive a copy of it.
- 02 Right to rectificationRequest correction of inaccurate or incomplete data.
- 03 Right to erasureRequest the deletion of your data, subject to legal retention obligations.
- 04 Right to portabilityReceive your data in a structured and commonly used format.
- 05 Right to objectObject to the processing of your data on legitimate grounds.
To exercise these rights, contact Avepto Sàrl by email at or by post at Avepto Sàrl, Chemin de l’Epinglier 4, 1242 Satigny, Switzerland. Avepto undertakes to respond within 30 days.
In the event of a dispute, you may file a complaint with the Federal Data Protection and Information Commissioner (FDPIC).
How is your data protected?
Avepto puts in place appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction.
The public forms on this site are protected against automated submissions by Cloudflare Turnstile. The service analyses technical browser signals (IP address, TLS fingerprint, User-Agent header, sitekey and associated origin) to tell a human visitor from a bot; these signals are used solely for bot detection and neither to identify you nor for advertising profiling. The corresponding processing is described in Cloudflare, Inc.’s Turnstile Privacy Addendum.
How does this policy change over time?
Avepto reserves the right to amend this privacy policy at any time. The version in force is the one published on this site, with the last-updated date shown at the top of this page.
Who can you contact with questions?
For any question relating to data protection: by email at , by phone at +41 22 552 96 70, or by post at Avepto Sàrl, Chemin de l’Epinglier 4, 1242 Satigny, Switzerland.