---
title: "Privacy policy: FADP, GDPR and your rights | Avepto"
canonical_url: "https://avepto.ch/en/privacy"
last_updated: "2026-09-13T23:45:23.093Z"
meta:
  description: "Avepto Sàrl privacy policy, aligned with the Swiss FADP and the EU GDPR: data collected, purposes, cookies, processors, retention periods, and your rights."
  "og:description": "Avepto Sàrl privacy policy, aligned with the Swiss FADP and the EU GDPR: data collected, purposes, cookies, processors, retention periods, and your rights."
  "og:title": "Privacy policy: FADP, GDPR and your rights"
  "twitter:description": "Avepto Sàrl privacy policy, aligned with the Swiss FADP and the EU GDPR: data collected, purposes, cookies, processors, retention periods, and your rights."
  "twitter:title": "Privacy policy: FADP, GDPR and your rights"
---

Data protection

# Privacy policy.

Which personal data Avepto Sàrl processes, for what purposes, for how long and with whom it is shared, as well as how you can exercise your rights at any time.

https://avepto.ch/en/privacy (AVP-LEG-PC-2026.09.5)

Summary

## In brief.

Thirty seconds to read. The full legal detail is in the numbered sections below.

<dl>

<dt>Last updated</dt>
<dd>September 11, 2026</dd>

<dt>Reference</dt>
<dd>AVP-LEG-PC-2026.09.5</dd>

</dl>

1. We collect the data needed to respond to your requests.
2. Analytics cookies wait for your consent in the European Economic Area and the UK; elsewhere they are active by default and refusable in one click.
3. We send an editorial briefing only to people who opted in. One-click unsubscribe.
4. We do not use your data for any other unsolicited commercial purposes.
5. We do not sell your data.
6. Some technical providers, notably Cloudflare and Google, may process data in the United States.
7. You can exercise your rights at any time, by email or by post.

01 Data controller

## Who is responsible for your data?

The entity responsible for the collection and processing of personal data described in this policy is:

### Identity card, Legal entity

CHE-362.077.556

<dl>

<dt>Company name</dt>
<dd>Avepto Sàrl</dd>

<dt>Address</dt>
<dd>Chemin de l’Epinglier 4 1242 Satigny, Switzerland</dd>

<dt>Email</dt>
<dd></dd>

<dt>Phone</dt>
<dd>[+41 22 552 96 70](tel:+41225529670)</dd>

</dl>

02 Legal framework

## Which laws apply?

This policy is issued in accordance with the **Swiss Federal Act on Data Protection** (FADP, RS 235.1, in force since 1 September 2023) and its implementing ordinance (DPO).

The **General Data Protection Regulation** (GDPR, EU Regulation 2016/679) applies additionally to visitors located in the European Economic Area.

03 Scope

## What does this policy cover?

This policy concerns **exclusively the personal data collected through the avepto.ch corporate website**. The corporate website does not handle client data related to Avepto’s managed-service offerings.

Client data managed as part of our managed services is hosted, where possible, on infrastructure located in Switzerland and is governed by the **service contracts and data-processing agreements** entered into with each client.

Certain management and supervision tools used as part of these services may involve transfers to providers located outside Switzerland, in compliance with FADP requirements.

04 Data collected

## What data is collected?

Avepto distinguishes two categories of data collected through the corporate website, depending on whether you submit it actively or it is recorded by your browsing.

### Data submitted voluntarily

When you use the contact form, the following data is collected:

1. First and last name
2. Professional email address
3. Phone number (optional)
4. Company and role (optional)
5. Subject of the request
6. Message content
7. Your briefing opt-in choice (unchecked by default)
8. IP address at the time of sending, kept with the request for security and evidence purposes (the same rule applies to job applications)

This data is sent by email to the Avepto team and stored in the website backend.

### Audience measurement, anonymous tier

Before your consent, we collect anonymous technical data via our own analytics infrastructure, with no third-party measurement tool:

1. Approximate country and city, inferred from your connection by Cloudflare, and your truncated IP address (network, not machine)
2. Browser family and operating system, inferred from the User-Agent header
3. Pages viewed, date and time of visit
4. Traffic source (UTM parameters, referring page)
5. Anonymous per-tab session identifier (non-persistent)

Legal basis: legitimate interest (aggregate audience measurement). No browser fingerprint or third-party cookie at this stage.

### Audience measurement, enriched tier

At the enriched tier, the same data is tied to a stable session identifier, which lets us reconstruct the path of a visit rather than isolated pages. This tier waits for your consent in the European Economic Area and the United Kingdom; elsewhere it is active by default and refusable at any time (see the cookie policy):

1. Browser technical fingerprint, transformed by HMAC-SHA256 cryptographic function before storage (the raw fingerprint is never retained)
2. Your full IP address, tied to each event
3. Two texts you type, absent from the anonymous tier: your site-search queries, kept with the event, and the command line typed in the 404 terminal, sent to Google Analytics with the event

Legal basis: your consent in the European Economic Area and the United Kingdom; elsewhere, the Swiss regime of article 45c of the Telecommunications Act, which requires that you be informed and allowed to refuse. In both cases refusing takes one click on the “Cookies” link in the footer. See the cookie policy for retention details.

05 Purposes

## Why is this data processed?

The data collected is processed for the following purposes:

1. Responding to requests sent via the contact form.
2. Preparing our reply to your contact request, job application, briefing subscription or meeting request, by summarising for the team the visit path that led to it (see the Automated processing section).
3. Improving the operation and content of the site (analytics).
4. Meeting applicable legal obligations.

Avepto sends an editorial briefing only to people who opted in. We do not use your data for any other unsolicited commercial purposes. One-click unsubscribe is in every email.

06 Automated processing

## Are your requests analysed automatically?

Requests received through our forms (contact, application, briefing, appointment) may be **pre-analysed by automated tools** in order to speed up their handling, triage, and categorisation.

When you send a contact request, a job application, a briefing subscription or a meeting request, your request is tied to your browser’s **analytics session identifier**, the very one our audience measurement uses. From it we build a visit summary attached to the internal notification sent to the team: pages viewed and how often, notable actions, referring domain, campaign parameters (UTM), approximate city and country, browser and operating system. If you accepted enriched measurement, that summary also covers your **earlier visits** (how many there were, and your most-viewed pages); otherwise it is limited to the current visit.

The log of those events is also sent to **Cloudflare Workers AI**, a language model running at our hosting provider, which writes a short observational paragraph added to that same internal notification. This step is optional: if it fails, the notification goes out without that paragraph. The corresponding processing is described in [Cloudflare’s documentation on Workers AI data usage](https://developers.cloudflare.com/workers-ai/platform/data-usage/).

That summary is preparation material, read by a member of the Avepto team who then handles your request. It may shape the way we reply to you, but **no decision producing legal or similarly significant effects is taken solely on the basis of automated processing.**

07 Legal basis and justification

## What is the legal basis for this processing?

Data processing relies on:

1. Your consent, for analytics cookies and certain optional fields of the contact form.
2. Avepto’s legitimate interest in responding to contact requests and improving its website, where this interest does not override your rights.
3. Compliance with applicable legal obligations.

You can withdraw your cookie consent at any time via the “Cookies” link in the footer, which opens the cookie policy and its management panel.

08 Recipients

## Who has access to your data?

Personal data is **neither sold, rented, nor transmitted to third parties for commercial purposes**. It may be shared with the following recipients:

Data recipients: name, country, role and scope.

| Recipient | Country | Role | Data scope |
| --- | --- | --- | --- |
| Cloudflare, Inc. | USA | Hosting, CDN, attack protection and protection against automated form submissions (Turnstile), and generation by the Workers AI service of the visit summary attached to our internal notifications | Browsing data, plus hosting of the data entered in the contact, application, newsletter and booking forms (D1 / R2 storage) |
| Google LLC | USA | Processor: receives analytics events via the Measurement Protocol API at both tiers (under a random per-tab identifier at the anonymous tier, under the transformed session identifier at the enriched tier) | Pseudonymised data, no IP address |
| Microsoft Corporation | USA / EU | Processor: Clarity session replay (with consent in the European Economic Area, active by default and refusable at any time elsewhere) and, for online appointments, creation of the invitation in Avepto’s Microsoft 365 calendars with a Teams link | Clarity: pseudonymised browsing interactions. Appointments: name, email and meeting subject |
| SMTP2GO Ltd | New Zealand / EU | Processor: delivery of the site’s transactional emails (confirmations, internal notifications, application files) | Form content sent by email, including application documents |
| Competent authorities | CH / EU | Disclosure where required by law | Strict minimum required by law |

09 International transfers

## Does your data leave Switzerland?

Hosting of the site by Cloudflare, Inc. involves a **transfer of browsing data to the United States**. Cloudflare adheres to the *Swiss-U.S. Data Privacy Framework*.

Audience measurement events are collected by our **first-party infrastructure**, operated on our hosting (see Cloudflare in the processor list above). A copy of the events, at both tiers, is transmitted to Google LLC via the Measurement Protocol API to feed our marketing dashboard, without any IP address. When you send one of our forms, the log of your events is also sent to Cloudflare’s Workers AI service, which writes the summary described in the Automated processing section. The enriched tier’s browser fingerprint is computed in your browser, sent to our server over an encrypted connection and transformed by the HMAC-SHA256 cryptographic function before any storage; only that transformed value is kept or passed to third parties.

The site’s internal search sends the text you type to **Cloudflare**, our hosting provider, in order to look up the content of our own pages. Without your consent to audience measurement, only the fact that a search took place is counted: the text you typed is not recorded in our visit statistics.

**No client data related to managed-service offerings transits through the corporate website.**

10 Retention

## How long is your data kept?

Data is retained for the time strictly necessary for the purpose pursued, then deleted or archived in line with legal obligations.

Retention periods: data type and duration.

| Data type | Retention period |
| --- | --- |
| Contact-form data Name, email, phone, company, role, subject, message, briefing opt-in choice, IP address at sending | 12 months after the request has been handled, unless an active contractual relationship exists |
| Audience measurement data Anonymous and enriched events, logged in our first-party infrastructure | About 90 days a rolling window that erases itself, with no older archive on our side. The identifier we keep is the fingerprint transformed by HMAC-SHA256, not the raw fingerprint; the IP address is truncated at the anonymous tier and full at the enriched tier; it is tied back to your identity only if you send one of our forms, in which case it is stored alongside your request (see the Automated processing section) |
| Job application files CV, cover letter and attachments, applicant contact details, IP address at sending | 12 months after the application is received, unless it progresses towards a hire, as stated on the form |
| Newsletter subscription Email address, consent state and truncated IP address at the time of subscription | Until you unsubscribe every email carries a one-click unsubscribe link |
| Online appointments Name, email, phone, organisation, meeting subject, additional notes and hashed IP address at the time of booking | 24 months after the appointment, unless an ongoing contractual relationship exists |
| Server logs Cloudflare | Third-party policy according to Cloudflare’s retention policy |

11 Rights

## What rights do you have over your data?

In accordance with the FADP (art. 25 et seq.), you have the following rights regarding data concerning you:

1. Right of access Obtain confirmation that your data is being processed and receive a copy of it.
2. Right to rectification Request correction of inaccurate or incomplete data.
3. Right to erasure Request the deletion of your data, subject to legal retention obligations.
4. Right to portability Receive your data in a structured and commonly used format.
5. Right to object Object to the processing of your data on legitimate grounds.

To exercise these rights, contact Avepto Sàrl by email at  or by post at *Avepto Sàrl, Chemin de l’Epinglier 4, 1242 Satigny, Switzerland*. Avepto undertakes to respond within **30 days**.

In the event of a dispute, you may file a complaint with the Federal Data Protection and Information Commissioner (FDPIC).

12 Security

## How is your data protected?

Avepto puts in place **appropriate technical and organisational measures** to protect personal data against unauthorised access, alteration, disclosure, or destruction.

The public forms on this site are protected against automated submissions by **Cloudflare Turnstile**. The service analyses technical browser signals (IP address, TLS fingerprint, User-Agent header, sitekey and associated origin) to tell a human visitor from a bot; these signals are used solely for bot detection and neither to identify you nor for advertising profiling. The corresponding processing is described in Cloudflare, Inc.’s [Turnstile Privacy Addendum](https://www.cloudflare.com/turnstile-privacy-policy/).

13 Changes

## How does this policy change over time?

Avepto reserves the right to amend this privacy policy at any time. The version in force is the one published on this site, with the last-updated date shown at the top of this page.

14 Contact

## Who can you contact with questions?

For any question relating to data protection: by email at , by phone at [+41 22 552 96 70](tel:+41225529670), or by post at *Avepto Sàrl, Chemin de l’Epinglier 4, 1242 Satigny, Switzerland*.

Related documents

[ Cookie policy 

Necessary cookies, audience measurement, consent management.](https://avepto.ch/en/cookies) [ Legal notice 

Site editor, host, intellectual property and liability.](https://avepto.ch/en/legal-notice)