Privacy Policy
Last updated: May 2026
1. Data Controller
The entity responsible for data processing on this website is:
Syntix
Bahnhofstrasse 29
8154 Oberglatt ZH
Switzerland
Email: [email protected]
This privacy policy is based on the Swiss Federal Act on Data Protection (DSG/nDSG, in force since 1 September 2023). Where visitors from the European Union or EEA are concerned, the provisions of the EU General Data Protection Regulation (GDPR) apply in addition.
2. Your Rights
Right to Information, Rectification, and Erasure
You have the right at any time to request information about the personal data we hold about you, to have inaccurate data corrected, and to request erasure of your data, provided no legal retention obligations stand in the way. To exercise these rights, please contact us at [email protected].
Right to Object
You have the right to object at any time to the processing of your personal data where such processing is based on a legitimate interest. We will then no longer process your data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Right to Data Portability
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit it to another controller, where technically feasible.
Revocation of Consent
Where data processing is based on your consent, you may revoke that consent at any time with effect for the future. The lawfulness of processing carried out prior to revocation remains unaffected.
Right to Lodge a Complaint
You have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch. EU residents may also contact the supervisory authority in their Member State of habitual residence.
3. Hosting
This website is hosted on a dedicated server located in the European Union. The personal data collected on this website (e.g. IP addresses, form data, server log files) is stored on this server. Processing is carried out on the basis of a legitimate interest in the secure and efficient operation of this website (Art. 6(1)(f) GDPR; Art. 31 para. 2 lit. a nDSG).
4. Content Delivery & Bot Protection — Cloudflare
This website is fronted by Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA). Every request to syntix.co is routed through Cloudflare's global network before reaching our origin server. Cloudflare provides DNS resolution, TLS termination, content caching, DDoS mitigation, and bot-traffic filtering.
To perform these functions, Cloudflare processes the following data: IP address, request metadata (URL, method, referrer, user-agent), approximate geographic location at country level (via the CF-IPCountry header, which we also use to suggest the appropriate language version of the site), and TLS handshake fingerprints. Cloudflare may set strictly necessary technical cookies — see the Cookies section below.
Cloudflare is certified under the EU-US Data Privacy Framework and offers Standard Contractual Clauses for international transfers. The legal basis for this processing is our legitimate interest in operating a secure and performant website (Art. 6(1)(f) GDPR; Art. 31 para. 2 lit. a nDSG). For more information see Cloudflare's privacy policy at cloudflare.com/privacypolicy.
5. Data Collection on This Website
Server Log Files
When you visit this website, our server automatically records the following data: browser type and version, operating system, referrer URL, hostname, time of request, and IP address. This data is used solely for the technically error-free operation of the website and is not merged with other data sources or used to identify individuals. Log files are deleted after 7 days.
Contact Form and Email Enquiries
When you contact us via the contact form or by email, the data you provide (name, email address, and your message) is stored and used solely to process and respond to your enquiry. We do not share this data with third parties. Data is retained for as long as necessary to handle your enquiry and for up to 10 years thereafter for commercial correspondence retention purposes under Swiss law (Art. 958f OR).
Payment Data (Pricing Request Form)
When you submit a pricing request via our website, we collect your name, email address, company name (optional), phone number (optional), and your project description. This data is used exclusively to prepare and send you a quote. It is not shared with third parties and is retained for up to 10 years as business correspondence.
7. Analytics — Google Analytics 4
With your consent, this website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar tracking technologies to collect and analyse information about how visitors use this website.
The following data may be collected: pages visited, time spent on pages, approximate geographic location (country/city level), device and browser type, and traffic source. IP addresses are anonymised before processing. Data is transferred to Google's servers, which may be located in the United States. Google has committed to appropriate safeguards under the EU–US Data Privacy Framework.
Analytics is only activated after you have given your explicit consent via the cookie banner. You may withdraw consent at any time by clearing your browser's local storage (key: cookie-consent). The legal basis for processing is your consent (Art. 6(1)(a) GDPR; Art. 31 para. 1 nDSG).
For more information, see Google's privacy policy at https://policies.google.com/privacy.
8. Payment Processing — Stripe
Payments on this website are processed by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. When you make a payment, you are redirected to Stripe's secure checkout page. We do not store or have access to your full card details at any time.
Stripe processes your payment data (name, email address, card details, and billing information) in accordance with their own privacy policy, available at https://stripe.com/privacy. Processing is carried out on the basis of contract performance (Art. 6(1)(b) GDPR; Art. 31 para. 2 lit. a nDSG).
9. Transactional Emails — Resend
We use Resend (Resend Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) to send transactional emails, including contact form confirmations and payment confirmations. When you submit a form or make a payment, your email address and relevant form data are transmitted to Resend for the purpose of sending you the confirmation email. Data is processed on the basis of contract performance or our legitimate interest in reliable email delivery (Art. 6(1)(b) and (f) GDPR; Art. 31 nDSG).
10. Third-Party Data Processors — Summary
We use the following third-party services to operate this website. Each processor acts under a data processing agreement or equivalent safeguard and processes only the data necessary for its function:
- Cloudflare (Cloudflare, Inc., San Francisco, USA) — DNS, reverse proxy, TLS termination, content caching, DDoS mitigation, bot protection. See Section 4.
- Google Analytics 4 (Google Ireland Ltd., Dublin, Ireland) — website analytics, activated only with your consent. See Section 7.
- Stripe (Stripe Payments Europe Ltd., Dublin, Ireland) — payment processing and fraud detection. Stripe may load scripts on our checkout pages to assess fraud risk. Privacy policy: stripe.com/privacy.
- Resend (Resend Inc., San Francisco, USA) — transactional email delivery (contact confirmations, payment confirmations). Only your email address and relevant form data are transmitted.
We do not sell or rent your personal data to any third party.
11. SSL/TLS Encryption
This site uses SSL/TLS encryption for all data transmissions. You can recognise an encrypted connection by the https://prefix in your browser's address bar and the padlock icon. Encrypted connections prevent third parties from reading the data you transmit to us.