Skip to content
Home

Legal

Privacy Policy

In accordance with the Swiss Federal Act on Data Protection (revFADP, in force since 1 September 2023) and the General Data Protection Regulation (GDPR, EU 2016/679)

Last updated: July 2026

The German version is legally binding. This English text is for convenience only.

1 · Controller

The controller responsible for data processing on this website is:

cloud services ag

Breitfeldstrasse 8

9015 St. Gallen, Switzerland

Email: datenschutz@cloud-services-ag.com

Phone: +41 58 590 99 33

Responsible person: Martin Auckenthaler (CEO)

2 · At a Glance

No tracking cookies

This website sets no analytics or tracking cookies. Only your own UI preferences are stored locally in your browser.

Self-hosted analytics

Plausible Analytics runs on our own Swiss infrastructure. No IP storage, no fingerprinting, no profiling.

Swiss hosting

Operated at the Eastern Switzerland Data Centre (RZO, Tier IV, ISO 27001). Contact enquiries are processed in our CRM Odoo.sh (Odoo SA, EU servers).

Self-hosted bot protection

Forms are protected by Altcha – a self-hosted proof-of-work mechanism that processes no personal data.

3 · Hosting & Server Logs

This website is operated on our own infrastructure at the Eastern Switzerland Data Centre (RZO) in Gais (Appenzell Ausserrhoden, Switzerland; Tier IV, ISO 27001).

With every page request, technically necessary connection data is recorded in server logs: IP address, time of access, requested URL, HTTP status, volume transferred, referrer URL, and user agent.

Purpose: secure operation, defence against attacks, fault analysis. Legal basis: Art. 31(2)(c) revFADP and Art. 6(1)(f) GDPR. Retention: a maximum of 30 days, then automated deletion.

4 · Web Analytics (Plausible, self-hosted)

We use Plausible Analytics, an open-source, privacy-friendly analytics solution. Our Plausible instance is self-hosted on our own Swiss infrastructure (analytics.bluematicag.ch). No data is transmitted to third parties.

Only aggregated, anonymous data is collected (page views, referrer, coarse device class, browser/OS, country of origin). The IP address is never stored; only a daily, salted hash is derived from it and deleted after 24 hours. No cookies, no cross-site tracking, no profiles.

Legal basis: Art. 31(2)(c) revFADP and Art. 6(1)(f) GDPR (legitimate interest in privacy-friendly reach measurement). As no personal data is processed, no consent is required.

5 · Form Bot Protection (Altcha, self-hosted)

Our forms (contact form, inquiry panel) are protected by Altcha – an open-source proof-of-work solution and privacy-friendly alternative to reCAPTCHA. Our Altcha instance is self-hosted on Swiss infrastructure. No data is transmitted to third parties.

The browser solves a cryptographic puzzle locally. Only the solution token and the challenge signature are transmitted – no biometric data, no device identifiers, no cookies. Tokens are used server-side only once for validation and are not stored persistently. Legal basis: Art. 31(2)(c) revFADP and Art. 6(1)(f) GDPR.

6 · Contact Form & CRM (Odoo)

The contact form and inquiry panel let you reach us. We collect the information you enter: first name, last name, email address, company (optional), phone (optional) and your message. Mandatory fields are marked.

Purpose: handling your enquiry and follow-up questions. Legal bases: consent under Art. 6(1)(a) GDPR and Art. 6(1)(b) GDPR (pre-contractual measures).

Our CRM is Odoo (Odoo SA, Chaussée de Namur 40, 1367 Grand-Rosière, Belgium), running on the managed Odoo.sh platform on EU servers (Google Cloud, Europe/Belgium region). Odoo SA is our processor under Art. 28 GDPR; a Data Processing Agreement (DPA) based on the EU Standard Contractual Clauses is in place. Switzerland recognises the EU/EEA as providing an adequate level of protection (Annex to the revFADP); no transfer to third countries outside the EU/EEA takes place.

Retention: data is retained for as long as necessary to handle your request, at most until you withdraw consent. If a business relationship arises, the commercial retention obligations under Art. 958f of the Swiss Code of Obligations (ten years) apply. Requests without follow-up are deleted after 24 months at the latest. Withdraw consent at any time by emailing datenschutz@cloud-services-ag.com.

7 · Online Appointment Booking (Kalenda)

For online appointment booking we use Kalenda, our own self-operated booking platform on Swiss infrastructure. Clicking «Book a meeting» embeds an iFrame of the Kalenda platform.

When booking, we process your name, email address, the selected appointment and optional notes. This data remains on our own Swiss infrastructure and is written to the relevant contact person's calendar for appointment management. Legal basis: Art. 6(1)(b) GDPR (pre-contractual) and Art. 6 revFADP. See the Kalenda privacy policy for details.

8 · Fonts (self-hosted)

This website uses the fonts «Outfit», «DM Sans», and «JetBrains Mono» (each licensed under the Open Font License 1.1). The font files are obtained from npm via the open-source packages @fontsource-variable/outfit, @fontsource-variable/dm-sans, and @fontsource-variable/jetbrains-mono, embedded into the website at build time, and served exclusively from our own infrastructure (RZO Gais). When you visit this website NO connection to fonts.googleapis.com, fonts.gstatic.com, or any other external font service is established. No personal data is transmitted to Google or any other third party — neither at build time nor at runtime.

9 · Local Storage (technically required)

Your browser's localStorage (not a cookie, no transmission to our server) holds only your own UI settings: selected language (DE/EN) and colour scheme (light/dark). This data never leaves your browser and can be cleared at any time in your browser settings.

10 · External Links

This website contains links to external websites. The respective operators are solely responsible for their content and privacy practices. By clicking an external link you leave our website; we have no influence over the data collected there.

11 · Your Rights as a Data Subject

Under the revFADP (Switzerland) and the GDPR (EU), you have the following rights:

  • Right of access (Art. 25 revFADP / Art. 15 GDPR)
  • Right to rectification of inaccurate data (Art. 32(1) revFADP / Art. 16 GDPR)
  • Right to erasure (Art. 32(2) revFADP / Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 28 revFADP / Art. 20 GDPR)
  • Right to object to processing based on legitimate interest (Art. 30(2) revFADP / Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)
  • Right to lodge a complaint with the competent supervisory authority (see Section 14)

12 · Automated Decision-Making

No automated decision-making within the meaning of Art. 21 revFADP or Art. 22 GDPR, including profiling, takes place.

13 · Contact for Privacy Requests

For requests regarding data processing, the exercise of your rights, or the withdrawal of consent, please contact:

cloud services ag · attn. Data Protection · datenschutz@cloud-services-ag.com

We will respond to requests within 30 days as required by law.

14 · Supervisory Authorities / Right to Lodge a Complaint

If you believe that the processing of your data infringes data-protection law, you may lodge a complaint with the competent supervisory authority:

  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC / EDÖB), Feldeggweg 1, 3003 Bern · edoeb.admin.ch
  • EU / EEA: The national data-protection authority of your country of residence · edpb.europa.eu

15 · Changes to This Policy

We reserve the right to amend this privacy policy to reflect changes in the law, technical developments, or changes to our data processing. The current version is always available at this URL.