SavianoSwitzerland
Security and compliance

Where this site runs, and who gets to see your data.

Our processors by name, what each of them actually sees, how long we keep what, and what we do on the day something leaks.

Last updated 11 September 2026

Most pages of this kind discuss processors without naming one, and hosting without giving a country. We take the opposite view, because that is the only version of any use to a compliance team filling in a register.

This page covers this website. The products we are preparing run on different infrastructure, and the section after the table explains why that difference is stated rather than hidden.

Processors

Four providers, and what each one sees.

The column that matters is not the provider's name, it is what the provider sees. A service that delivers a message reads its contents, and a content network that terminates encryption sees every request. Both are here.

ProviderRoleCountryWhat it sees
Cloudflare, Inc.Domain name zone, content delivery network and application firewallUnited StatesEvery request made to the site. Encryption terminates on their network, so IP address, requested page, browser headers and, on a form submission, the content sent.
Hetzner Online GmbHServer that runs the siteGermany, Nuremberg data centreServer logs, and the form content while the request is being handled. Nothing is written to a database: this site does not have one.
ResendDelivery of the contact form messageIreland, eu-west-1 regionThe content of the message, its sender and its recipients, for as long as delivery takes.
Hostpoint AGBusiness mailboxesSwitzerlandMessages once received, as any mail host does.
A difference we state

This site is not the infrastructure we sell.

You have just read that this brochure runs in Germany, behind an American network. On a site that argues for digital sovereignty the contradiction is obvious, and we would rather write it ourselves than let you find it.

This site holds nothing. No account, no database, no client file, no document. It serves public pages and forwards a contact form. Paying for Swiss compute here would protect no data, because there is none to protect.

The sovereign workspace and the products in the programme are built to receive case files, accounting records and correspondence under professional secrecy. Those run in Switzerland, under Swiss law, and that is what the promise covers. It is the proportionality principle Swiss law itself applies: the measure follows the risk, not the rhetoric.

The day this site holds anything more than pages, this page changes before it does.

What this site does not do

No cookies, no audience measurement, no advertising trackers, no third-party scripts. Typefaces are served from our own server rather than from an outside service.

There is therefore no consent banner, not through neglect, but because there would be nothing to consent to.

What we keep, and for how long

Server logs hold the IP address, the date, the resource requested and the response code. They serve diagnostics and security, and are deleted after thirty days.

The protection against repeated form submissions keeps a fingerprint of the requester's address in memory for ten minutes. It is never written to disk and disappears when the process restarts.

Enquiries received through the form live in our mailboxes. Those that lead to no business relationship are deleted after twelve months.

The day something leaks

The person responsible for content is told immediately, and leads the risk assessment.

Swiss data protection law requires notification to the Federal Commissioner, as soon as possible, of any breach likely to result in a high risk to the people concerned. Unlike the European regulation and its seventy-two hours, it sets no figure. We hold ourselves to the stricter of the two and aim for seventy-two hours.

The people concerned are informed where protection requires it or the Commissioner asks for it. The sequence of events is recorded as it happens rather than reconstructed afterwards.

Your rights, and how to exercise them

You have rights of access, rectification, erasure and objection under the Swiss Federal Act on Data Protection, and under the European General Data Protection Regulation where you live in the Union.

Write to [email protected], or use the contact form. We answer within thirty days, and we say no where we cannot grant a request rather than let the clock run out.

Frequent questions

Security and compliance

Why name your processors when nobody else does?

Because the person reading this page has a register of processing activities to fill in, and a register needs names and countries. A page that writes “a mail delivery provider” wastes their time and tells them nothing.

Does Cloudflare really see the content of my message?

Yes. Encryption terminates on their network before reaching our server, which is how a content delivery network works. Saying so is the only honest way to present the chain, and it is also why the products that will handle sensitive documents will not be built this way.

Will you sign a data processing agreement?

Yes, for any relationship in which we process data on your behalf. The agreement names the processors, the places of processing and the retention periods, and it restates the list above rather than pointing at a page that can change.