Privacy policy

Version 1.0, in force from 3 August 2026. Applies to the website cbisoftware.ch.

This notice covers this website only. It is written to be checked rather than believed, so every factual claim below is one a visitor, a client or an auditor can verify independently from their own browser. Where a statement cannot be verified from outside, it is marked as an internal control rather than presented as proof.

Our platform products and our client engagements are governed by separate contractual data-processing terms, because they process categories of data this website never touches. Nothing in this notice should be read as describing them.

1. Controller

CBI Software GmbH
Klosbachstrasse 37
8032 Zürich, Switzerland

Commercial register: Canton of Zurich, no. CH-020.4.070.385-0
Company identification number (UID): CHE-287.787.509

Contact for all data-protection matters, including access, rectification, erasure, objection and any complaint: [email protected]

We are not required to appoint a data-protection officer under Art. 10 of the Swiss Federal Act on Data Protection or Art. 37 GDPR, and we have not appointed one. Requests sent to the address above reach the person responsible directly.

2. What this website does not do

Each of the following is a design decision, not a policy promise. The right-hand column states how to confirm it.

No cookiesThis site sets no cookie of any kind, first or third party. Confirm in your browser under storage or site data.
No analyticsNo Google Analytics, no tag manager, no server-side analytics product, no visitor counter. No analytics tag has ever been installed on this site.
No trackingNo tracking pixels, no advertising or remarketing tags, no fingerprinting, no cross-site identifiers, no social media plugins or embeds.
No third-party requestsEvery asset, including fonts, styles and images, is served from cbisoftware.ch. Your browser contacts no other host while loading this site. Confirm in the network panel of your browser tools.
No formsThere is no contact form, no newsletter, no login and no comment function, so no form data can be submitted. Contact is by email only, at an address you control.
No profilingNo automated individual decision-making and no profiling within the meaning of Art. 22 GDPR takes place through this website.
No sale of dataWe do not sell, rent or trade personal data, and we do not transfer it to advertising networks or data brokers.

How to verify this yourself in about thirty seconds

Open your browser developer tools, press reload, and look at two panels. Under Network, every request should show cbisoftware.ch as the host and nothing else. Under Application or Storage, cookies, local storage and session storage should all be empty. If either check ever shows otherwise, this notice is wrong and we want to hear about it at [email protected].

The one script that does load

In the interest of stating this precisely rather than conveniently, the site loads exactly one script, served from our own domain. It is Cloudflare's email-address decoder. Its only function is to reassemble our contact address in the page, so that the address is not published in plain text where address-harvesting robots can scrape it. It sets no cookie, reads no storage and sends no data anywhere. Our content-security policy blocks scripts from any other origin, which is why the claim of no third-party requests above holds.

3. What is processed, and why

3.1 Server and edge log data

Delivering a web page technically requires your device to send a request to a server, and that request necessarily contains your IP address. Our hosting and content-delivery provider processes these requests to serve the page and to protect the site against attack and abuse. The data involved is the requesting IP address, the date and time, the page requested, the HTTP status returned, the referring page where your browser supplies one, and your browser and operating system identification string.

Purpose: delivering the site, ensuring its availability, and defending against denial-of-service and other attacks.
Legal basis: our overriding legitimate interest in the secure and reliable operation of our website, Art. 31 para. 1 of the Swiss Federal Act on Data Protection and Art. 6 para. 1 lit. f GDPR.
Our access: we do not receive, download, store or analyse raw request logs. The aggregate figures available to us, such as total requests or countries of origin, contain no personal data and cannot be resolved to an individual.
Retention: held by the provider for a short period under its own retention schedule and then deleted. We hold no copy.

3.2 Email correspondence

If you write to us, we process your email address, your name where you give it, and the content of your message, together with the technical headers that email transmission requires.

Purpose: answering your enquiry and, where it leads to one, managing the resulting business relationship.
Legal basis: Art. 31 para. 1 of the Swiss Federal Act on Data Protection, and Art. 6 para. 1 lit. b GDPR where your message concerns a contract or steps preparatory to one, otherwise lit. f.
Retention: for as long as needed to deal with the matter and any relationship arising from it. Where Swiss commercial law requires business records to be retained, the statutory period of ten years applies under Art. 958f of the Swiss Code of Obligations. Correspondence outside that scope is deleted when it is no longer needed.
Note on email in general: ordinary email is transported securely between well-configured servers but is not end-to-end encrypted. Please do not send passport scans, financial records, health information or other sensitive documents by unsolicited email. Ask us first and we will provide a secure channel.

3.3 Domain registration

Our registrar processes the registration data for our domains as required by the registry. This concerns our own company data, not yours.

4. Processors and service providers

The complete list. There are no others, and no undisclosed sub-processors act on this website.

ProviderFunctionProcessing locationPersonal data involved
Cloudflare Website hosting, DNS, content delivery, attack protection Requests to this site are served from the Zurich edge location. The provider is US-incorporated with an EU entity, see section 5. IP address and request metadata, transiently, for delivery and security
Infomaniak Email hosting for our contact address Switzerland, in the provider's own Swiss data centres The content and metadata of correspondence you send us
Hostpoint Domain registrar Switzerland None belonging to visitors, our own registration data only
GitHub Private source-code repository for this website United States None. The repository holds page templates and styles, and no visitor data reaches it.
Google Search Console Reports how this site appears in Google search results United States None collected from you. See the explanation below.

Google Search Console deserves a plain explanation, because its name suggests more than it does. Ownership of the domain is verified through a DNS record, so no code, tag or script is added to any page. The reports we see are compiled by Google from its own search index and are aggregated, for example how often a page appeared in results. No data is collected from your visit to this site and nothing is transmitted from your browser to Google when you read these pages. Confirming this is the network check in section 2.

5. Transfers abroad

We name this openly rather than leaving it to be discovered. Our email, our domain and the edge location serving these pages are all in Switzerland. Two providers in the table above are nevertheless US-incorporated, and we treat that as a fact to disclose, not to obscure.

Cloudflare. Requests to this site are served from Switzerland and the company offers EU and Swiss contractual terms including the European Commission's standard contractual clauses with the recognised Swiss adaptations. Log data may in principle be processed outside Switzerland for security purposes. The exposure is limited to the transient request metadata in section 3.1, which is what a website visit unavoidably generates.

GitHub and Google Search Console. Neither receives personal data from visitors to this site, as set out above, so no transfer of your data arises.

Transfers where required are based on Art. 16 and 17 of the Swiss Federal Act on Data Protection and, where the GDPR applies, on Art. 46 para. 2 lit. c GDPR.

Why our website and our platform are architected differently

A public marketing website and a system holding client identity documents are not the same risk, and we do not defend them with the same measures. This website carries no client data, so a global content-delivery network is an appropriate and safer choice for it, because it absorbs attacks we would otherwise absorb ourselves. Our platform, which does process sensitive personal data, is built to a separate and stricter rule: the entire sensitive path, meaning compute, database and document storage, runs on Swiss infrastructure and is never proxied through a foreign network. The separation is deliberate, and stating it here is part of the point.

6. Your rights

Under Swiss data-protection law and, where it applies to you, under the GDPR, you have the right to:

Write to [email protected]. We answer within thirty days, and free of charge. We may ask for information sufficient to establish your identity, but only what is necessary and only in order to avoid disclosing your data to someone else. In practice the data we hold on any website visitor is limited to correspondence you have sent us, since nothing else is collected.

Right to complain

You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, Switzerland. If you are in the European Economic Area, you may instead complain to the supervisory authority of your country of residence or workplace. We would prefer to hear from you first, but we do not treat that as a condition.

7. Security

Measures that can be verified from outside, using any public security-header or TLS testing service:

Organisational and internal measures, which by their nature you cannot verify from outside and which we therefore state as controls rather than as proof:

8. Automated crawling and artificial intelligence

We permit reputable search and AI crawlers, including those operated by OpenAI, Anthropic and Google, to read the public pages of this site. This concerns published corporate information only. No personal data of visitors exists on these pages for a crawler to read, because none is collected.

9. Children

This website addresses businesses and public-sector bodies. It is not directed at children, and we do not knowingly process children's personal data through it.

10. Changes to this notice

We will amend this notice if our processing changes. Each version carries a version number and an effective date at the top of this page, so that any change is visible rather than silent. Should we ever introduce cookies, analytics or third-party scripts, we would state it here explicitly and, where the law requires, ask for your consent first.

11. Questions

Any question about this notice, or about how we handle data more generally, goes to [email protected]. If you believe any statement on this page is inaccurate, tell us and we will correct it or correct the practice.

See also our legal notice.