1. Name and contact details of the controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states, as well as other data protection regulations, is:
Data Protection Officer
A Data Protection Officer (DPO) is only legally required under Art. 37 GDPR / § 38 BDSG if certain thresholds are met (e.g. core activities requiring regular, systematic monitoring of data subjects on a large scale, or at least 20 people constantly engaged in automated personal data processing). If Accessibilia does not currently meet these thresholds, this section can state that no DPO has been appointed and name a contact person for data protection matters instead.
2. Overview of processing on this website
This section summarises, at a glance, which categories of personal data Accessibilia processes and for what purpose. Full detail on each item follows in the sections below.
| Activity | Data processed | Purpose |
|---|---|---|
| Visiting the site | IP address, timestamp, browser/OS, referrer, requested page | Technical delivery, server stability, security (server log files) |
| Cookie consent | Consent status, timestamp, consent-tool ID | Recording that consent was given/refused (legal obligation) |
| Web analytics | Pseudonymous usage data via cookies/client ID (Google Analytics) | Understanding how the site is used, improving content, only with consent |
| Contact form | Name, email, company, enquiry topic, message | Responding to your enquiry (submitted via an embedded Brevo form) |
| Waitlist sign-up | First name, email, role ("I am a…") | Notifying you when enrolment opens (submitted via an embedded Brevo form) |
3. Legal bases for processing
Depending on the activity, Accessibilia relies on one or more of the following legal bases under Art. 6(1) GDPR:
- Art. 6(1)(a) GDPR — you have given consent, e.g. for non-essential cookies, Google Analytics, and marketing emails from the waitlist.
- Art. 6(1)(b) GDPR — processing is necessary to respond to your enquiry or to take steps prior to entering into a contract with you (e.g. the contact form, waitlist sign-up).
- Art. 6(1)(c) GDPR — processing is necessary to comply with a legal obligation (e.g. retaining certain business correspondence under German commercial and tax law, § 257 HGB, § 147 AO).
- Art. 6(1)(f) GDPR — processing is necessary for a legitimate interest, e.g. ensuring the security and stability of this website through server log files, and preventing misuse.
Where processing is based on consent, you may withdraw that consent at any time with effect for the future, as described in Section 5.
4. Hosting and server log files
This website is hosted by Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Geneva, Switzerland. Infomaniak processes data on our behalf under an Art. 28 GDPR (and, given its location outside the EU/EEA, Art. 44 et seq. GDPR) data processing agreement. Infomaniak operates its own data centres in Switzerland, which benefits from a European Commission adequacy decision confirming that Swiss data protection law provides an adequate level of protection for transfers from the EU/EEA — so no additional safeguards such as Standard Contractual Clauses are required for this transfer.
Each time this website is accessed, our hosting provider's servers automatically collect and store information in server log files, which your browser transmits automatically. This includes:
- IP address of the requesting device
- Date and time of access
- Name and URL of the file retrieved
- Website from which access is made (referrer URL)
- Browser type and version, operating system used
This data is not merged with other data sources. It is processed under Art. 6(1)(f) GDPR on the basis of our legitimate interest in the technically error-free presentation and optimisation of our website, and in ensuring the security of our IT systems. Log files are typically deleted after [e.g. 7–30 days], unless retention is required for evidentiary purposes following a specific security incident.
5. Cookies and the cookie consent banner
This website uses cookies and similar technologies (such as local storage). A cookie is a small file stored on your device that allows certain information to flow between your browser and our server.
Some cookies are strictly necessary for the website to function (e.g. remembering your cookie preferences) and are set without requiring consent, under § 25(2) TTDSG (Telecommunications-Telemedia Data Protection Act) and Art. 6(1)(f) GDPR. All other cookies — including Google Analytics, described below — are only set once you have given active, informed consent via our cookie banner, in accordance with § 25(1) TTDSG and Art. 6(1)(a) GDPR.
We use Cookiebot, a consent management platform provided by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark, to obtain, record, and manage this consent. Cookiebot itself sets a strictly necessary cookie to store your preferences (see the cookie table below). When you first visit the site, the banner presents the available categories of cookies and lets you accept all, reject all (except strictly necessary cookies), or make a granular selection.
Withdrawing consent
You can change or withdraw your consent at any time, with effect for the future, by reopening the Cookiebot banner via the floating Cookiebot icon on the bottom right side. You can also control or delete cookies at any time through your browser settings; please note that doing so may limit some functionality of the site.
Cookie table
| Name | Provider | Purpose | Duration |
|---|---|---|---|
| CookieConsent | Cookiebot (Usercentrics) | Stores your cookie consent choices | 12 months |
| _cfuvid | Cloudflare, Inc. | Distinguishes individual visitors sharing the same IP address, to apply security rate-limiting | Session (up to 24 hours) |
| _ga, _ga_* | Google Analytics | Distinguishes users for statistical analysis | 2 years |
| _ga_TX93BSLK1H | Google Analytics (GA4) | Distinguishes users, persists session state | 2 years |
| _GRECAPTCHA | Google reCAPTCHA | Distinguishes human visitors from bots on the contact form, for spam/abuse prevention | 6 months |
6. Web analytics — Google Analytics
Subject to your consent given via the cookie banner described in Section 5, this website uses Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Google Analytics uses cookies and similar technologies that enable an analysis of your use of the website. The information generated by these technologies (including a shortened/truncated IP address, which prevents direct identification of you) is transmitted to and stored on Google's servers. On our behalf, Google uses this information to evaluate your use of the website, compile reports on website activity, and provide other services relating to website and internet use to us.
We have entered into a data processing agreement with Google in accordance with Art. 28 GDPR. IP anonymisation ("IP masking") is [enabled/not applicable to the Analytics version in use — GA4 truncates IP addresses by default], so your full IP address is not stored by Google.
This processing takes place only where you have actively consented via the cookie banner. The legal basis is Art. 6(1)(a) GDPR. You may withdraw your consent at any time as described in Section 5, or by installing the Google Analytics opt-out browser add-on.
Further information on Google's data processing can be found in Google's privacy policy at policies.google.com/privacy and in Google's information on Analytics-specific data safeguards.
7. Contact form
The contact form on this website is an embedded form provided by Brevo (Sendinblue SAS), 7 rue de Madrid, 75008 Paris, France. When you submit the form, we process the data you enter: first name, last name (optional), work email, company or organisation (optional), the topic of your enquiry, and your message. This data is submitted directly to, and stored on, Brevo's infrastructure on our behalf.
This data is used solely to process and respond to your enquiry, and for any follow-up questions arising from it. The legal basis is Art. 6(1)(b) GDPR, where your enquiry is directed at entering into or performing a contract (e.g. a question about enrolling in Barrier Slayer, or a request for corporate training), or Art. 6(1)(f) GDPR (our legitimate interest in responding to enquiries directed at us) for all other enquiries.
We have entered into a data processing agreement with Brevo under Art. 28 GDPR; see Section 9 for further detail on this processor and Section 10 on the resulting transfer of data. We do not pass your data on to any other third party without your consent. Data submitted via the contact form is deleted once your enquiry has been conclusively resolved and no statutory retention obligation applies, unless you have consented to further storage (e.g. because you also joined the waitlist).
8. Waitlist sign-up
The waitlist sign-up on this website is also an embedded Brevo form. If you join the waitlist for the Barrier Slayer programme, we collect your first name, your email address, and your selected role ("I am a…"), which is submitted directly to Brevo and stored in our Brevo contact list. This data is used to send you a single message when enrolment opens, as stated at the point of sign-up.
The legal basis is Art. 6(1)(a) GDPR (your consent, given by submitting the form) and, to the extent the message relates to steps you have requested prior to entering into a contract for the programme, Art. 6(1)(b) GDPR.
You can withdraw your consent and unsubscribe at any time via the unsubscribe link in any email we send you, or by contacting us using the details in Section 1. Withdrawal does not affect the lawfulness of processing carried out before it. As stated on the site, we do not send promotional emails beyond the single enrolment notification.
9. Recipients and data processors
We only share personal data with third parties where necessary for the purposes listed above, where you have consented, or where we are legally obliged to do so. Where a third party processes personal data on our behalf and under our instruction, we have entered into a data processing agreement with them in accordance with Art. 28 GDPR.
| Recipient | Purpose | Location |
|---|---|---|
| Infomaniak Network SA | Website hosting, server log files | Switzerland |
| Google Ireland Limited | Google Analytics | EU (Ireland), with data flows to Google LLC (USA) |
| Usercentrics A/S (Cookiebot) | Recording and managing cookie consent | Denmark (EU) |
| Brevo (Sendinblue SAS) | Contact form and waitlist forms and emails | France (EU), data hosted in the EU |
10. International data transfers
Infomaniak is based in Switzerland. Transfers of personal data to Switzerland are covered by the European Commission's adequacy decision for Switzerland, so no additional safeguards are required for this transfer.
Google, as described in Section 6, is based in the EU (Ireland) but may transfer data to its US parent, Google LLC. Where personal data is transferred to a country outside the European Economic Area (a "third country") that has not been recognised by the European Commission as providing an adequate level of data protection (Art. 45 GDPR), we ensure an adequate level of protection through appropriate safeguards under Art. 46 GDPR — in particular the EU Standard Contractual Clauses, and, where applicable to the recipient, certification under the EU-U.S. Data Privacy Framework.
Brevo and Usercentrics (Cookiebot) are both based in the EU; to the best of our knowledge, personal data processed through these services is hosted within the EU and is not transferred to a third country. You may request a copy of the relevant safeguards for any of the above by contacting us using the details in Section 1.
11. Storage duration
Unless a more specific retention period has been stated in the sections above, we store personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by statutory retention obligations under German commercial and tax law (e.g. six to ten years for certain business records under § 257 HGB and § 147 AO), after which it is routinely deleted.
12. Your rights as a data subject
Under the GDPR, you have the following rights in relation to your personal data. To exercise any of them, contact us using the details in Section 1.
- Right of access (Art. 15 GDPR) — confirmation of whether we process your data, and access to that data and related information.
- Right to rectification (Art. 16 GDPR) — correction of inaccurate or incomplete data.
- Right to erasure (Art. 17 GDPR) — deletion of your data, subject to statutory retention obligations.
- Right to restriction of processing (Art. 18 GDPR) — limiting how we use your data in certain circumstances.
- Right to data portability (Art. 20 GDPR) — receiving data you provided to us in a structured, commonly used, machine-readable format, and transmitting it to another controller.
- Right to object (Art. 21 GDPR) — see Section 14.
- Right to withdraw consent (Art. 7(3) GDPR) — at any time, with effect for the future, without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR) — in particular in the EU member state of your residence, place of work, or the place of the alleged infringement. The supervisory authority responsible for us is: [e.g. Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg].
13. Right to object to processing based on legitimate interests
Where we process your personal data on the basis of legitimate interests under Art. 6(1)(f) GDPR (e.g. server log files described in Section 4), you have the right, under Art. 21 GDPR, to object at any time to such processing on grounds relating to your particular situation. We will then cease processing your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.
14. Data security (SSL/TLS encryption)
This website uses SSL/TLS encryption for all pages where personal data is transmitted, such as the contact form and waitlist sign-up. You can recognise an encrypted connection by the padlock symbol in your browser's address bar and by the address beginning with https:// rather than http://. When encryption is active, data you submit to us cannot be read by third parties in transit.
15. Automated decision-making and profiling
We do not use fully automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
16. Changes to this privacy policy
We may update this privacy policy from time to time to reflect changes to our data processing practices, the tools we use, or legal requirements. The version published on this page is always the current, applicable version. We recommend checking back periodically.