Skip to content
XLG SWISS
Bright corridor in a plant administration building with filing cabinets

Legal

Privacy Policy

1. Controller

The controller responsible for processing your personal data in connection with this website and our services is:

XLG SWISS GmbH Seestrasse 46 8598 Bottighofen Switzerland

Email: info@xlgswiss.com Telephone: +41 77 507 84 39 UID: [UID to follow after entry in the commercial register]

If you have any questions about data protection, please contact us at the email address above.

2. Scope and applicable law

This privacy policy explains which personal data we process, for what purposes, and what rights you have. It applies to visits to our website www.xlgswiss.com and to our work with clients, prospective clients and business partners.

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP). Where the General Data Protection Regulation of the European Union (GDPR) applies, in particular because we also offer our services to companies and individuals in the EU, we additionally comply with its requirements.

3. Hosting and server log files

When you access our website, the server automatically records information transmitted by your browser: IP address, date and time of access, page requested, previously visited page (referrer), browser type and version, and operating system.

We need this data to deliver the website technically, to ensure its security and stability, and to detect misuse. The data is not combined with other data sources. The legal basis under the GDPR is our legitimate interest in a secure and functioning website (Art. 6(1)(f) GDPR). Log files are deleted after 30 days at the latest, unless they are needed for longer to investigate a security incident.

Our website is delivered and protected against attacks via the content delivery network (CDN) of Cloudflare. The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Delivery takes place via data centres in the EU. Cloudflare processes the data on our behalf and is certified under the Swiss-U.S. Data Privacy Framework and the EU-U.S. Data Privacy Framework; the standard contractual clauses apply in addition. Further information: www.cloudflare.com/privacypolicy/

5. Web analytics

To improve our website, we use the following analytics tools with your consent. The legal basis in each case is your consent (Art. 6(1)(a) GDPR), which you give via the cookie banner and can withdraw at any time via "Cookie settings" in the footer. No analytics data is collected without consent.

PostHog: We use PostHog, a product of PostHog Inc., 2261 Market Street, San Francisco, CA 94114, USA. The data is stored exclusively on servers in the EU (Frankfurt am Main, Germany). Information about your use of the website is collected, such as pages visited, time spent, approximate location, device type and interactions with the page (clicks, scrolling behaviour). Further information: posthog.com/privacy

Google Analytics 4: We use Google Analytics 4 provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Your IP address is truncated before storage. Google Analytics is operated in Consent Mode: without your consent, no cookies are set and no usage data is transmitted. A transfer to Google LLC in the USA cannot be ruled out; Google is certified under the EU-U.S. Data Privacy Framework and the standard contractual clauses apply in addition. Further information: policies.google.com/privacy

We retain analytics data only for as long as necessary for evaluation, and for no longer than 14 months. It is then deleted or anonymised.

6. Company identification (lead.box)

We use the lead.box service on our website. Based on the IP address of your network, it evaluates whether the visit originates from a company network. If so, publicly available information about that company (such as company name, industry, location and website) and the pages viewed on our website are evaluated. Individual persons are not identified, and no profiles of natural persons are created.

The purpose is to understand which companies are interested in our services and to tailor our website and offering accordingly. The legal basis is our legitimate interest in aligning our offering with business clients (Art. 6(1)(f) GDPR). You may object to this evaluation at any time by sending a message to info@xlgswiss.com.

7. Protection against misuse (Cloudflare Turnstile)

To protect our forms against automated submissions and spam, we use Cloudflare Turnstile provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Turnstile uses technical characteristics to check whether a submission originates from a human or from an automated program. Information such as IP address, browser type and behaviour on the page is transmitted to Cloudflare for this purpose. No tracking cookies are set and no user profiles are created for advertising purposes.

The legal basis is our legitimate interest in the security of our website and in protection against misuse (Art. 6(1)(f) GDPR). Further information: www.cloudflare.com/privacypolicy/

8. Contacting us

If you contact us via the contact form, by email or by telephone, we process the information you provide, usually your name, company, email address, telephone number and the content of your enquiry. We use this data solely to respond to your enquiry and, where applicable, to prepare a proposal.

The legal basis is the performance of pre-contractual measures (Art. 6(1)(b) GDPR) or our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR). Providing this information is voluntary; however, we cannot respond to your enquiry without contact details. We delete the data once your enquiry has been fully dealt with and no statutory retention obligations apply.

Contact form: Messages from the contact form are delivered to us via the email service Resend. The provider is Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. We use the EU region of the service (Ireland); Resend processes the data on our behalf. Further information: resend.com/legal/privacy-policy

WhatsApp: Our website includes a button that allows you to contact us via WhatsApp. Its use is voluntary. Only when you click the button does WhatsApp open and data is transmitted to WhatsApp. For users in Switzerland and the EU, the provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland. The WhatsApp privacy policy applies (www.whatsapp.com/legal/privacy-policy-eea). If you do not wish to transmit data to WhatsApp, please use the contact form, email or telephone.

9. Appointment booking and online meetings

To arrange appointments, in particular the free initial consultation, we use the booking tool Cal.com provided by Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. When you book, your name, email address, the selected appointment and, where applicable, your message are transmitted to the provider, which processes the data on our behalf. Protection of data transferred to the USA is ensured by the standard contractual clauses of the European Commission. Further information: cal.com/privacy

We hold online meetings via Microsoft Teams provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. The data required for participation is processed, such as name, email address, and video and audio data during the meeting. We only record meetings by prior agreement with all participants. Further information: privacy.microsoft.com

The legal basis is the performance of pre-contractual measures or the performance of a contract (Art. 6(1)(b) GDPR).

10. Clients and business partners

In the course of our consulting, coaching, training and audit engagements, we process data relating to our clients and their contact persons, for example name, role, contact details, contract and invoicing data, and information made available to us in the course of an engagement, for instance in conversations, workshops or surveys. We treat this information confidentially.

We process this data to perform the contract (Art. 6(1)(b) GDPR), to comply with legal obligations such as bookkeeping (Art. 6(1)(c) GDPR), and to maintain the business relationship (Art. 6(1)(f) GDPR).

11. Fonts

The fonts used on our website are stored on our own server or delivered via our CDN. No connection is established to servers of Google or other font providers when you access the website, and no data is transmitted to third parties.

13. Disclosure to third parties

We disclose personal data only where this is necessary to perform a contract, where we are legally obliged to do so, where you have consented, or where we have a legitimate interest. Recipients may include: IT and hosting service providers, our fiduciary for bookkeeping and tax matters, partners from our network where they are involved in an engagement with the client's consent, and authorities and courts where we are legally obliged.

Service providers that process data on our behalf are contractually obliged to process the data only in accordance with our instructions and in compliance with data protection law. We do not sell personal data.

In connection with this website, we currently use the following service providers:

  • Cloudflare, Inc., USA – hosting, content delivery network, security, bot protection (Turnstile)
  • PostHog Inc., USA (servers in Frankfurt, Germany) – web analytics, only with consent
  • Google Ireland Limited, Ireland – Google Analytics 4, only with consent
  • lead.box – identification of companies based on publicly available company data
  • Resend, Inc., USA (EU region Ireland) – delivery of contact form messages
  • Cal.com, Inc., USA – appointment booking
  • Microsoft Ireland Operations Limited, Ireland – online meetings (Microsoft Teams)
  • Meta Platforms Ireland Limited, Ireland – WhatsApp, only when you voluntarily use the button

14. Data processing abroad

As a rule, we process personal data in Switzerland and in the European Economic Area (EEA). Switzerland and the EU mutually recognise an adequate level of data protection.

Where data is transferred to a country without an adequate level of data protection, for example because a service provider operates servers in the USA, we ensure protection through appropriate safeguards, in particular the standard contractual clauses of the European Commission in the version recognised by Switzerland, or certification of the provider under the Swiss-U.S. or EU-U.S. Data Privacy Framework, or we rely on a statutory exception. This currently concerns the USA (Cloudflare, Inc.; Cal.com, Inc.; Resend, Inc. as a provider with an EU region; PostHog Inc. as a provider with EU servers) and possible transfers to Google LLC in the context of Google Analytics.

15. Retention period

We retain personal data only for as long as necessary for the purposes stated. Business records such as contracts, correspondence and invoices are retained for ten years in accordance with statutory obligations (Art. 958f of the Swiss Code of Obligations). The data is then deleted or anonymised.

16. Data security

We take appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access. Data transmitted via our website is encrypted (SSL/TLS).

17. Your rights

Within the scope of applicable law, you have the following rights:

  • Information on whether and which data we process about you
  • Rectification of inaccurate data
  • Erasure of your data
  • Restriction of processing
  • Receipt or transfer of your data in a commonly used electronic format (data portability)
  • Objection to processing based on our legitimate interest
  • Withdrawal of consent with effect for the future; for cookies and web analytics at any time via "Cookie settings" in the footer of the website

18. Exercising your rights and complaints

To exercise your rights, an informal message to info@xlgswiss.com is sufficient. To protect your data, we may ask for proof of identity.

You also have the right to lodge a complaint with a data protection supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC, Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch). If you are located in the EU, you may contact the supervisory authority of your place of residence, place of work or the place of the alleged infringement.

19. No automated decision-making

We do not make automated individual decisions and do not carry out profiling.

20. Changes

We may amend this privacy policy at any time, for example when new website functions are introduced or legal requirements change. The version published on our website at the time applies.

This is a translation for convenience. In the event of any discrepancy, the German version prevails.

Last updated: September 2026