Privacy policy
Version 1.0, in force from 3 August 2026. Applies to the website cbisoftware.ch.
This notice covers this website only. It is written to be checked rather than believed, so every factual claim below is one a visitor, a client or an auditor can verify independently from their own browser. Where a statement cannot be verified from outside, it is marked as an internal control rather than presented as proof.
Our platform products and our client engagements are governed by separate contractual data-processing terms, because they process categories of data this website never touches. Nothing in this notice should be read as describing them.
1. Controller
CBI Software GmbHKlosbachstrasse 37
8032 Zürich, Switzerland
Commercial register: Canton of Zurich, no. CH-020.4.070.385-0
Company identification number (UID): CHE-287.787.509
Contact for all data-protection matters, including access, rectification, erasure, objection and any complaint: [email protected]
We are not required to appoint a data-protection officer under Art. 10 of the Swiss Federal Act on Data Protection or Art. 37 GDPR, and we have not appointed one. Requests sent to the address above reach the person responsible directly.
2. What this website does not do
Each of the following is a design decision, not a policy promise. The right-hand column states how to confirm it.
How to verify this yourself in about thirty seconds
Open your browser developer tools, press reload, and look at two panels. Under Network, every request should show cbisoftware.ch as the host and nothing else. Under Application or Storage, cookies, local storage and session storage should all be empty. If either check ever shows otherwise, this notice is wrong and we want to hear about it at [email protected].
The one script that does load
In the interest of stating this precisely rather than conveniently, the site loads exactly one script, served from our own domain. It is Cloudflare's email-address decoder. Its only function is to reassemble our contact address in the page, so that the address is not published in plain text where address-harvesting robots can scrape it. It sets no cookie, reads no storage and sends no data anywhere. Our content-security policy blocks scripts from any other origin, which is why the claim of no third-party requests above holds.
3. What is processed, and why
3.1 Server and edge log data
Delivering a web page technically requires your device to send a request to a server, and that request necessarily contains your IP address. Our hosting and content-delivery provider processes these requests to serve the page and to protect the site against attack and abuse. The data involved is the requesting IP address, the date and time, the page requested, the HTTP status returned, the referring page where your browser supplies one, and your browser and operating system identification string.
Purpose: delivering the site, ensuring its availability, and defending against
denial-of-service and other attacks.
Legal basis: our overriding legitimate interest in the secure and reliable operation of
our website, Art. 31 para. 1 of the Swiss Federal Act on Data Protection and Art. 6 para. 1
lit. f GDPR.
Our access: we do not receive, download, store or analyse raw request logs. The
aggregate figures available to us, such as total requests or countries of origin, contain no
personal data and cannot be resolved to an individual.
Retention: held by the provider for a short period under its own retention schedule and
then deleted. We hold no copy.
3.2 Email correspondence
If you write to us, we process your email address, your name where you give it, and the content of your message, together with the technical headers that email transmission requires.
Purpose: answering your enquiry and, where it leads to one, managing the resulting
business relationship.
Legal basis: Art. 31 para. 1 of the Swiss Federal Act on Data Protection, and Art. 6
para. 1 lit. b GDPR where your message concerns a contract or steps preparatory to one,
otherwise lit. f.
Retention: for as long as needed to deal with the matter and any relationship arising
from it. Where Swiss commercial law requires business records to be retained, the statutory
period of ten years applies under Art. 958f of the Swiss Code of Obligations. Correspondence
outside that scope is deleted when it is no longer needed.
Note on email in general: ordinary email is transported securely between well-configured
servers but is not end-to-end encrypted. Please do not send passport scans, financial records,
health information or other sensitive documents by unsolicited email. Ask us first and we will
provide a secure channel.
3.3 Domain registration
Our registrar processes the registration data for our domains as required by the registry. This concerns our own company data, not yours.
4. Processors and service providers
The complete list. There are no others, and no undisclosed sub-processors act on this website.
| Provider | Function | Processing location | Personal data involved |
|---|---|---|---|
| Cloudflare | Website hosting, DNS, content delivery, attack protection | Requests to this site are served from the Zurich edge location. The provider is US-incorporated with an EU entity, see section 5. | IP address and request metadata, transiently, for delivery and security |
| Infomaniak | Email hosting for our contact address | Switzerland, in the provider's own Swiss data centres | The content and metadata of correspondence you send us |
| Hostpoint | Domain registrar | Switzerland | None belonging to visitors, our own registration data only |
| GitHub | Private source-code repository for this website | United States | None. The repository holds page templates and styles, and no visitor data reaches it. |
| Google Search Console | Reports how this site appears in Google search results | United States | None collected from you. See the explanation below. |
Google Search Console deserves a plain explanation, because its name suggests more than it does. Ownership of the domain is verified through a DNS record, so no code, tag or script is added to any page. The reports we see are compiled by Google from its own search index and are aggregated, for example how often a page appeared in results. No data is collected from your visit to this site and nothing is transmitted from your browser to Google when you read these pages. Confirming this is the network check in section 2.
5. Transfers abroad
We name this openly rather than leaving it to be discovered. Our email, our domain and the edge location serving these pages are all in Switzerland. Two providers in the table above are nevertheless US-incorporated, and we treat that as a fact to disclose, not to obscure.
Cloudflare. Requests to this site are served from Switzerland and the company offers EU and Swiss contractual terms including the European Commission's standard contractual clauses with the recognised Swiss adaptations. Log data may in principle be processed outside Switzerland for security purposes. The exposure is limited to the transient request metadata in section 3.1, which is what a website visit unavoidably generates.
GitHub and Google Search Console. Neither receives personal data from visitors to this site, as set out above, so no transfer of your data arises.
Transfers where required are based on Art. 16 and 17 of the Swiss Federal Act on Data Protection and, where the GDPR applies, on Art. 46 para. 2 lit. c GDPR.
Why our website and our platform are architected differently
A public marketing website and a system holding client identity documents are not the same risk, and we do not defend them with the same measures. This website carries no client data, so a global content-delivery network is an appropriate and safer choice for it, because it absorbs attacks we would otherwise absorb ourselves. Our platform, which does process sensitive personal data, is built to a separate and stricter rule: the entire sensitive path, meaning compute, database and document storage, runs on Swiss infrastructure and is never proxied through a foreign network. The separation is deliberate, and stating it here is part of the point.
6. Your rights
Under Swiss data-protection law and, where it applies to you, under the GDPR, you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectification of data that is inaccurate or incomplete.
- Erasure of your data, subject to any statutory retention duty.
- Restriction of processing, and objection to processing based on legitimate interest.
- Data portability, meaning a copy in a common machine-readable format.
- Withdraw consent at any time where processing rests on consent, without affecting the lawfulness of what came before.
Write to [email protected]. We answer within thirty days, and free of charge. We may ask for information sufficient to establish your identity, but only what is necessary and only in order to avoid disclosing your data to someone else. In practice the data we hold on any website visitor is limited to correspondence you have sent us, since nothing else is collected.
Right to complain
You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, Switzerland. If you are in the European Economic Area, you may instead complain to the supervisory authority of your country of residence or workplace. We would prefer to hear from you first, but we do not treat that as a condition.
7. Security
Measures that can be verified from outside, using any public security-header or TLS testing service:
- TLS 1.3 encryption in transit, with HTTPS enforced across the entire site.
- HTTP Strict Transport Security for one year, including subdomains, so browsers refuse an unencrypted connection.
- Content Security Policy restricting all resources to our own origin, which structurally prevents third-party scripts and trackers.
- Clickjacking protection via X-Frame-Options DENY and a frame-ancestors directive, and MIME-type sniffing disabled.
- Referrer-Policy set to strict-origin-when-cross-origin, so full page addresses are not leaked to other sites.
- Permissions-Policy disabling geolocation, microphone and camera access, and disabling interest-based advertising cohorts.
- Authenticated email using SPF, DKIM and DMARC, which prevents third parties from sending mail that appears to come from our domain.
Organisational and internal measures, which by their nature you cannot verify from outside and which we therefore state as controls rather than as proof:
- Multi-factor authentication on every administrative account for our domain, DNS, hosting, source code and email.
- A statically generated site with no database, no user accounts and no server-side application logic, which removes the most common classes of web vulnerability entirely rather than defending against them.
- Encrypted, versioned backups of all site content, held in Switzerland, with restoration tested rather than assumed.
- The principle of data minimisation applied at the design stage, which is why the list in section 3 is as short as it is. Data never collected cannot be breached, misused or compelled.
8. Automated crawling and artificial intelligence
We permit reputable search and AI crawlers, including those operated by OpenAI, Anthropic and Google, to read the public pages of this site. This concerns published corporate information only. No personal data of visitors exists on these pages for a crawler to read, because none is collected.
9. Children
This website addresses businesses and public-sector bodies. It is not directed at children, and we do not knowingly process children's personal data through it.
10. Changes to this notice
We will amend this notice if our processing changes. Each version carries a version number and an effective date at the top of this page, so that any change is visible rather than silent. Should we ever introduce cookies, analytics or third-party scripts, we would state it here explicitly and, where the law requires, ask for your consent first.
11. Questions
Any question about this notice, or about how we handle data more generally, goes to [email protected]. If you believe any statement on this page is inaccurate, tell us and we will correct it or correct the practice.
See also our legal notice.