Privacy
Controller
nablaX GmbH
CHE-438.561.556
4125 Riehen, Switzerland
What is processed when you visit
This website is a set of static pages delivered by Amazon CloudFront, Amazon Web Services’ content delivery network. To deliver a page and protect the site against abuse, AWS processes technical connection data — your IP address and request metadata — transiently as our infrastructure provider. nablaX has not enabled access logging: we keep no logs of your visit, and we receive no information about who you are. The legal basis for this transient processing is our legitimate interest in serving and securing the website (GDPR Art. 6(1)(f); revFADP).
Cookies
This website sets no cookies. None. There is consequently no cookie banner, because there is nothing to consent to.
Third-party content
Nothing on this website loads from a third-party origin. Fonts are served from our own domain, and no tracking pixel, chat widget or embedded script of any kind is present.
If you email us
If you write to our contact address, we receive your email address and what you send. We use it to answer you and for nothing else; we do not add you to any list. Correspondence is retained as long as the conversation is live and then as business correspondence where Swiss law requires it.
Your rights
Under the revFADP and, where it applies, the GDPR, you can request information about personal data we hold about you, and its correction or deletion. Simply reading this website creates no such data, so a request will normally concern correspondence you have sent us, or a mailing-list sign-up if you have made one. Write to the contact address above; you also have the right to complain to your supervisory authority — in Switzerland the FDPIC, in the EU your national data protection authority.
The mailing list
You are on this list only if you asked to be, and only after confirming it from your own inbox.
What we store. Your email address, which of the three lists you chose, the exact consent sentence shown to you and its version, the time you asked and the time you confirmed, and — as evidence that the request was genuine — the IP address and browser user-agent the request came from. Nothing else. We do not know your name unless you tell us.
Why we may store it. Your consent (GDPR Art. 6(1)(a); revFADP). Consent is the only basis we rely on here, which is why nothing is sent until you confirm.
How the confirmation works. Signing up sends you one email with a single link. Until you open that link nothing is on any list, and the pending request is deleted automatically after seven days. If the sign-up was not yours, ignoring the email is enough — you do not have to do anything.
What we send. Occasional messages about the thing you signed up for, from nablaX, written by us. No newsletters bought from anyone, no advertising for third parties, and nothing you did not ask for.
What we do not do. The emails contain no tracking pixel and no rewritten links, so we do not know whether you opened one or what you clicked. We do not sell, rent or share the list, and it is not uploaded to an advertising platform or any third-party mailing service.
Unsubscribing. Every message has an unsubscribe link that works in one click without logging in. Your address is removed immediately; the record is kept for thirty days so we can show the removal happened, and is then deleted. You can also simply write to us.
Who else sees it. The list is stored in Amazon DynamoDB and the confirmation email is sent through Amazon SES, both in Amazon Web Services’ Frankfurt region (eu-central-1), under a data processing agreement. Server logs from the sign-up endpoint contain your IP address and are deleted after thirty days. Nobody outside nablaX and AWS has access.
Withdrawing consent. Unsubscribing withdraws it. That does not affect the lawfulness of anything sent before, and it does not require a reason.
Last updated: