Privacy

Controller

The controller responsible for data processing within the meaning of the Swiss Federal Act on Data Protection (FADP/revDSG) is:

SchäferSoft GmbH
UID: CHE-352.307.571
Contact: info@schaefersoft.ch

Applicable law

This privacy policy is governed primarily by the revised Swiss Federal Act on Data Protection (FADP/revDSG), which has been in force since 1 September 2023. Insofar as individuals from the European Economic Area are affected, the EU General Data Protection Regulation (GDPR) applies in addition. In the information on the legal basis below, Swiss law is therefore stated first and – where relevant – the GDPR is named in addition.

Collection and processing of personal data

We process personal data only to the extent necessary for the operation, use and security of our services. This includes in particular:

  • Contact details (name, e‑mail address, address)
  • Contract and billing data
  • Payment data in connection with payment processing
  • Usage and log data (e.g. login times, technical server log files)

Provision of the data required to perform the contract is a prerequisite for using our software.

Purpose of processing

Processing is carried out to provide and improve our software, to perform contracts, for billing, to ensure technical security and availability, and to communicate with users.

Hosting and server log files

Our application is operated on servers in Switzerland (Swiss data storage). When you visit our website, the server automatically creates and processes log files. These include in particular the IP address, the date and time of access, the browser used (user agent) and the URL requested.

This data serves the secure and stable operation of the website as well as the detection and prevention of misuse. The legal basis is our legitimate interest in secure operation (revDSG; Art. 6(1)(f) GDPR).

Third-party services used

For the operation, security and analysis of our website we use the following services. Where data is transferred abroad, you will find details of the safeguards in the section “Data processing abroad”.

  • Hosting – servers in Switzerland – Purpose: operation and provision of the website and application; Data: server log files (IP address, timestamp, user agent, URL requested); Legal basis: legitimate interest in secure and stable operation.
  • Cloudflare CDN & reverse proxy (Cloudflare, Inc., USA) – Purpose: delivery of the entire website via a content delivery network, caching of content, and protection against attacks (web application firewall, DDoS mitigation); Data: visitors’ IP address and request metadata; Legal basis: legitimate interest in security, availability and performance.
  • Cloudflare Turnstile (Cloudflare, Inc., USA) – Purpose: protection of the contact form against bots and spam (CAPTCHA alternative); a script is loaded from challenges.cloudflare.com for this purpose; Data: IP address as well as browser and interaction signals; Legal basis: legitimate interest in protection against misuse.
  • Cloudflare Web Analytics (Cloudflare, Inc., USA) – Purpose: privacy-friendly, aggregated audience measurement without cookies and without cross-site tracking; Data: aggregated, anonymous access data; Legal basis: legitimate interest in analysing website use.
  • Google Analytics 4 (Google Ireland Ltd., Ireland; Google LLC, USA) – Purpose: audience and usage analysis; loaded exclusively after your express consent via the cookie banner, with IP anonymisation (anonymize_ip) active; Data: truncated IP address, usage data, cookies (_ga, _ga_<ID>, _gid, _gat); Legal basis: consent (revDSG; Art. 6(1)(a) GDPR), revocable at any time via the cookie settings.
  • Stripe (Stripe Payments Europe Ltd., Ireland; Stripe, Inc., USA) – Purpose: processing of payments and subscriptions for paid plans; Data: billing and payment data (name, address, payment method, transaction data); card data is processed exclusively and directly by Stripe (PCI-DSS); Legal basis: performance of the contract.
  • E-mail dispatch via our own mail server – Purpose: sending account and transactional e-mails as well as replies to contact enquiries; no external e-mail service provider is used; Data: e-mail address and content of the message; Legal basis: performance of the contract or legitimate interest in communication.
  • Fonts – no external providers – Only locally hosted or system fonts are used. No fonts are loaded from external providers (e.g. Google Fonts or Adobe Fonts); accordingly, no personal data (in particular no IP address) is transmitted to a font CDN.

Cookies and consent

We use cookies and comparable technologies, in part mandatorily for operation and in part only with your consent.

Technically necessary cookies are required for the operation of the website and are set without consent. These include in particular the session cookie, the CSRF protection cookie (XSRF-TOKEN) and the cookie that stores your selection in the cookie banner.

Cookie banner and consent: Via a banner you decide whether non-essential services may be loaded. Your choice is stored in a cookie and can be changed or revoked at any time via the cookie settings.

Google Analytics is loaded exclusively after your express consent and sets cookies (including _ga, _ga_<ID>, _gid, _gat) only thereafter.

Cloudflare Web Analytics, by contrast, operates entirely without cookies and without cross-site tracking and therefore does not require consent.

Disclosure of data

Data is disclosed to third parties only where this is necessary for operation – in particular to the providers named in the section “Third-party services used”, for example for hosting, security, analysis and payment processing – or where there is a legal obligation to do so. Data processing agreements as required by data protection law are in place with all processors.

Data processing abroad

Some of the services we use process data outside Switzerland and the EEA, in particular in the USA. This concerns notably Cloudflare, Inc. (CDN/reverse proxy, Turnstile, Web Analytics), Google LLC (Google Analytics) and Stripe, Inc. (payment processing).

These transfers take place on the basis of appropriate safeguards: the providers named are certified under the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework respectively; in addition, the Standard Contractual Clauses of the EU Commission apply.

Storage and security

Personal data is stored on servers in Switzerland and retained only for as long as necessary for the stated purposes or as required by statutory retention periods. We implement appropriate technical and organisational measures (e.g. encrypted transmission, access controls) to protect data against loss, unauthorised access and misuse.

Rights of data subjects

Within the scope of applicable law, you have in particular the right to information, rectification, erasure, restriction of processing, data release or data portability, as well as the right to withdraw any consent given at any time with effect for the future. You also have the right to lodge a complaint with the competent supervisory authority (in Switzerland: the Federal Data Protection and Information Commissioner, FDPIC). Please address requests to info@schaefersoft.ch.

Changes to this privacy policy

We reserve the right to amend this privacy policy at any time. The current version published on our website is always authoritative.

Last updated: 27.06.2026