Privacy notice
Last updated: 2026-09-10. A practical, plain-language notice for visitors to this website — not legal advice about your own processing.
Who is responsible
Privacy Design® · Stefan Keller, Basel, Switzerland. Contact: info@privacydesign.ch
What this site is
privacydesign.ch is a static, informational knowledge base. It sets no cookies, uses no tracking or analytics, and makes no third-party or external requests — a Content-Security-Policy restricts the site to its own origin, so nothing loads from advertising, analytics, or social networks.
What is (and isn’t) processed
- No cookies, no advertising or analytics identifiers, no profiling.
- Theme preference: the light/dark toggle stores a single value in your browser’s
localStorage. It stays on your device, is never transmitted, and we never receive it. - Search: the in-page search loads a same-origin file (
/index.json) and runs in your browser. Your search terms are not sent to us or to any third party. - Server access logs: the site is self-hosted on infrastructure located in Switzerland. The web server may keep short-lived, standard access logs (IP address, timestamp, requested URL, browser user-agent) for operation, stability and security. They are kept for at most 30 days and then deleted, and are not used to profile or identify visitors.
- External links: the knowledge base links to third-party sources (regulators, standards bodies, publications). Following such a link takes you to sites governed by their own privacy practices.
Legal framework and your rights
Processing is governed by the Swiss revised Federal Act on Data Protection (revFADP / nFADP). The controller and hosting are in Switzerland.
To the extent any personal data (e.g. server-log data) is processed, you may request information/access, rectification, erasure, or object to processing — contact info@privacydesign.ch. You may also lodge a complaint with the Swiss supervisory authority, the Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch.
Identifying you. This site holds only minimal data — chiefly short-lived server logs keyed to an IP address — and has no user accounts. We generally cannot link that data to a named individual, and we do not collect extra information solely to identify visitors (data minimisation). Where we cannot identify you from the data we hold, we may be unable to act on an access or erasure request unless you provide information that lets us locate the relevant data; and we may ask for reasonable proof that a request genuinely concerns you before disclosing or deleting anything, to avoid revealing data to the wrong person. Given the ≤30-day log retention, most such data will in any case already have been deleted.
No automated decision-making
This site performs no automated decision-making or profiling with legal or similarly significant effects.
Changes
This notice may be updated as the site evolves; the “last updated” date above reflects the current version.