Skip to content
Datotheque

Privacy

Privacy policy

This policy explains what personal data Datotheque Sagl processes, on what legal basis, for how long, with whom it is shared, and how you can exercise your rights.

Last updated: 2 August 2026

Controller and contact

Controller and contact

The controller is Datotheque Sagl, a limited liability company with registered office in Lugano, Canton Ticino, Switzerland. The registered address, UID and VAT status are published in the legal notice.

Data protection enquiries, including rights requests, should be addressed to the contact email published on the contact page, marked for the attention of the data protection contact.

Legal framework

Legal framework

We process personal data in accordance with the revised Swiss Federal Act on Data Protection (nFADP/nLPD) and, where our activities fall within its territorial scope, Regulation (EU) 2016/679 (GDPR).

Where we process personal data on behalf of a client during an engagement, the client is the controller and we act as a processor under a written data processing agreement. This policy then describes only our own processing as controller.

Data we process and why

Data we process and why

Website visits: the hosting provider processes standard server request data, including IP address, requested resource, timestamp, referrer and user agent, to deliver the site and defend it against abuse. The legal basis is our legitimate interest in the secure operation of our website (GDPR Art. 6(1)(f); nFADP Art. 31).

Enquiries: when you use the contact form or write to us, we process your name, organisation, email address, subject and message to answer you and to document any resulting business relationship. The legal basis is the taking of steps at your request prior to entering into a contract, and performance of that contract (GDPR Art. 6(1)(b)), and our legitimate interest in documenting business correspondence.

Client and supplier administration: contact details of the individuals we deal with, contractual documents, and billing records, processed to perform the mandate and to comply with statutory accounting, tax and anti-money-laundering record-keeping duties (GDPR Art. 6(1)(b) and 6(1)(c)).

We do not use personal data for automated decision-making producing legal effects, and we do not profile visitors to this website.

Recipients and transfers

Recipients and transfers

Personal data is accessible only to the people within the company who need it for the stated purpose. We disclose data to third parties only where necessary: our hosting and email providers acting as processors under written agreement, our professional advisers, and public authorities where required by law.

We do not sell personal data and do not disclose it for third-party marketing.

Transfers outside Switzerland or the EEA take place only on the basis of an adequacy decision or appropriate safeguards, such as the EU Standard Contractual Clauses with the Swiss addendum, together with a transfer risk assessment. For client engagements, processing locations are agreed in writing before any data is transferred.

Security measures

Security measures

We apply technical and organisational measures appropriate to the risk: encryption in transit, access on a least-privilege and need-to-know basis, individual accounts with multi-factor authentication, logging of administrative access, segregation of client data, vetted subprocessors, and confidentiality undertakings for everyone working on an engagement.

Personal data breaches are assessed without undue delay and notified to the competent authority and to affected individuals or clients where the applicable thresholds are met.

Retention

Retention

We keep personal data only for as long as necessary for the purpose for which it was collected, or for as long as a statutory retention period requires. At the end of a mandate, client data is returned or deleted on the client's written instruction, subject to statutory retention duties.

Indicative retention periods

CategoryRetained for
Server request logsUp to 90 days
Contact form enquiries not leading to a mandate12 months
Business correspondence with clientsDuration of the relationship, then 10 years
Contracts, invoices and accounting records10 years (Swiss Code of Obligations Art. 958f)
Client data processed under a mandateReturned or deleted at the end of the mandate on written instruction

Your rights

Your rights

Subject to the conditions of the applicable law, you may request access to your personal data, its rectification or erasure, restriction of processing, and data portability, and you may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time with effect for the future.

We respond to requests within one month, and we may ask for information reasonably necessary to verify your identity. If you are not satisfied, you may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or with the supervisory authority of your habitual residence in the EU/EEA.

Changes to this policy

Changes to this policy

We review this policy periodically and update it when our processing changes. The date of the last review is shown above.