Skip to privacy notice
Judit Sardi · BusinessCreator Switzerland Back to website

Data protection

Privacy / GDPR / Swiss FADP

Last updated: 28 July 2026

This notice describes the limited personal-data processing connected with this website. The site is deliberately privacy-light: no contact form, audience analytics, advertising technology, social plug-ins, tracking pixels, third-party embeds, or remote web fonts.

1. Controller and privacy contact

BusinessCreator by JSárdi, Judit Sárdi, Bergstrasse 35, 9437 Marbach SG, Switzerland is responsible for the processing described here.

Privacy questions and requests: info@businesscreator.ch or +41 71 525 1083.

2. Laws and principles

Processing is governed by the Swiss Federal Act on Data Protection (FADP; German: Datenschutzgesetz, DSG). Where the EU General Data Protection Regulation (GDPR) applies, this notice also provides the information required by Articles 12–14 GDPR. Personal data are processed proportionately, for stated purposes, and with privacy by design and by default.

3. Website delivery and technical data

When a browser requests a page, internet delivery necessarily exposes limited technical data to the network and hosting infrastructure. This can include the IP address, date and time, requested file, response status, browser and operating-system information, and a referrer if the browser sends one.

Routine Nginx access logging is disabled for this temporary deployment. Security-critical error information may still be processed where necessary to protect the service, investigate abuse, or restore availability. Such information is not used for audience measurement, advertising, or visitor profiling and is retained only for the period reasonably required for the relevant security or reliability purpose.

Where the GDPR applies, the legal basis is Article 6(1)(f): the legitimate interests in securely and reliably delivering a requested website, preventing abuse, and diagnosing serious faults. The same purposes are compatible with the proportionality and security principles of the Swiss FADP.

4. Hosting, recipients, and international transfers

This temporary website deployment is hosted on infrastructure provided by Vultr in California, United States. Vultr acts as an infrastructure processor for data handled through the hosting service. An independent technical administrator in Canada maintains the temporary deployment under the controller’s instructions. These providers receive only the information technically necessary for their role.

Technical data may therefore be processed in the United States and Canada. Where required, cross-border processing is to be protected through an applicable adequacy framework and/or recognised standard contractual clauses, together with appropriate technical and organisational safeguards. Information about the applicable transfer safeguard can be requested from the controller.

If the site moves to judit-sardi.com or another hosting provider, this section will be updated before the new production deployment is promoted.

5. Cookies and similar technologies

The website does not set analytics, advertising, personalisation, or third-party cookies. It does not load scripts or media from social networks, map providers, video platforms, advertising networks, or analytics providers.

After a visitor chooses “Deny optional cookies,” the privacy manager stores one first-party browser value named businesscreator_privacy_choice_v1 in local storage for up to 12 months. It records only the choice version, “essential only” status, and save/expiry times. It contains no name, email address, IP address, or cross-site identifier. This storage is necessary to remember the visitor’s privacy instruction and avoid repeating the notice.

Visitors can reopen the manager through “Privacy choices” in the footer. Clearing browser site data also removes the preference. Because no optional services are installed, the manager does not ask for consent to analytics or marketing.

6. Direct contact

The website provides email, telephone, and LinkedIn links but no web form. If a visitor chooses to contact the controller, the controller processes the information the visitor supplies to answer the enquiry, take requested pre-contractual steps, conduct a professional relationship, or protect legal interests.

Where the GDPR applies, the basis is Article 6(1)(b) for requested pre-contractual or contractual steps, Article 6(1)(f) for ordinary professional correspondence and legal interests, and Article 6(1)(c) where retention or disclosure is legally required. Email, telecommunications, or social-network providers used by the visitor or controller process communications under their own terms and privacy notices.

7. Retention

  • The essential browser preference expires after no more than 12 months.
  • Routine website access logs are disabled for this deployment.
  • Enquiries that do not lead to a mandate are normally deleted or anonymised within 12 months after the last substantive contact, unless a longer period is needed for a documented legal or security reason.
  • Contract, accounting, and business records are retained only for the applicable contractual and statutory periods.

8. Disclosures

Personal data are not sold. They may be disclosed to hosting and technical-administration providers, professional advisers bound by confidentiality, communications providers, contractual counterparties where necessary, and competent authorities where disclosure is legally required. Providers may use approved subprocessors for infrastructure operations.

9. Security

Measures include HTTPS in transit, a restrictive content security policy, no third-party scripts or embeds, disabled routine access logging for this deployment, least-necessary collection, and server access controls. No internet transmission or storage system can be guaranteed absolutely secure.

10. Individual rights

Subject to the conditions and limits of applicable law, a person may request access, correction, deletion, restriction, or delivery of personal data; object to processing based on legitimate interests; and withdraw consent for future processing where consent is the basis. This website currently performs no automated decision-making or profiling.

Requests can be sent to info@businesscreator.ch. Identity may need to be verified proportionately before a request is fulfilled.

11. Complaints

In Switzerland, concerns may be raised with the Federal Data Protection and Information Commissioner (FDPIC). Where the GDPR applies, a person may also complain to the competent supervisory authority in the EU or EEA country connected with the processing.

12. External links and changes

External websites receive data only after a visitor chooses to follow a link. They operate independently. This notice may be revised when the site, hosting, service providers, or legal requirements change. The date at the top identifies the current version.

Website · Imprint ·