Data protection

Privacy policy

How AlpenAgent processes personal data under Swiss data protection law.

1. Controller

AlpenAgent – Tymofii Bondar, Künzistegstrasse 54, 3714 Frutigen, Schweiz. Privacy requests: [email protected].

2. Scope and principles

This policy covers alpenagent.ch, enquiries and the website chatbot. We process only data needed for a stated purpose, protect it appropriately and retain it no longer than necessary. Customer projects are governed additionally by project-specific roles and terms.

3. Technical data and hosting

When the site is used, IP address, time, requested URL, browser/device data and security events may be processed in server and CDN logs. Website and chatbot infrastructure is operated partly in Switzerland; Cloudflare may process delivery and security data through its international network. Purposes are secure delivery, troubleshooting and abuse prevention.

4. Enquiries

We may process name, company, email, telephone, message, language and technical submission evidence. Cloudflare Turnstile, Resend and Zoho support this process. Enquiries that do not become a customer relationship are normally deleted after 24 months unless legal retention or evidence needs apply.

5. AI chatbot

The chatbot is an AI system and may be wrong. Do not enter sensitive, confidential or third-party personal data. Message, session ID, page, language and browser data are processed. Content is sent to the OpenAI API to generate a response; API data is not used to train OpenAI models by default, although limited abuse-monitoring processing may occur. Chat history on our Swiss VPS is normally deleted automatically after 30 days. Contact us for binding information.

6. Cookies and consent

Necessary storage supports language, design, security, chat sessions and your consent choice. Google Analytics and external Calendly content load only after voluntary consent. You can reject, choose separately and change the choice at any time through “Privacy settings” in the footer.

7. Analytics and booking

Google Analytics and embedded Calendly content load only after your voluntary consent. Google Analytics processes usage, device and interaction data; according to Google, IP addresses of users in Switzerland, the EU and the United Kingdom are discarded before logging. Calendly processes booking details and technical usage data. You may withdraw consent at any time for the future through “Privacy settings” in the footer.

Further information: Google Analytics data and privacy and the Calendly Privacy Notice.

8. Recipients and international transfers

Only authorised persons and processors receive data for hosting, security, communication, booking or AI responses. Based on the current provider information, processing may occur in particular at these locations:

  • Infomaniak: Switzerland.
  • Zoho Mail (EU account): Netherlands and Ireland; secured remote access from India may occur in rare support cases.
  • Resend: United States for account, log and API data; email delivery may additionally use Ireland, Brazil or Japan depending on the selected region.
  • Calendly: mainly United States; certain subprocessors also process in the Netherlands, Israel and the United Kingdom.
  • Cloudflare: global network; subprocessors and group companies may operate in particular in Switzerland, the EEA, United Kingdom, United States, Canada, Japan, Australia, Singapore, United Arab Emirates, India, South Korea, Mexico and Malaysia.
  • OpenAI API: depending on technical delivery, in particular Switzerland, EEA states, United Kingdom, United States, Canada, Australia, Brazil, India, Indonesia, Japan, Mexico, Norway, Singapore, South Africa, South Korea and United Arab Emirates; support or moderation may additionally occur in the Philippines.
  • Google Analytics: collection for users in Switzerland, the EU or United Kingdom first occurs in those regions; further processing may occur in particular in the United States.

Providers and locations may change. The current Cloudflare, Resend, Zoho, Calendly and OpenAI provider lists remain authoritative.

For disclosures to countries without a recognised adequate level of protection, we use in particular recognised standard contractual clauses with Swiss adaptations and assess necessary supplementary measures; where applicable, a recognised data privacy framework or a statutory exception may apply.

9. Security and retention

Risk-appropriate measures include TLS, access controls, anti-abuse controls and security logging. Absolute security cannot be guaranteed. Chat content and related operational logs and technical backups are normally deleted within 30 days at the latest or reduced so that conversation content is no longer present. Business records are generally retained for up to ten years where legally required; other data is deleted or anonymised when no longer needed.

10. Rights

Subject to applicable law, individuals may request access, correction, delivery or portability, deletion, restriction or objection, and withdraw consent. Identity verification may be required. Complaints may be addressed to the Swiss Federal Data Protection and Information Commissioner (FDPIC).

11. Customer AI and telephone solutions

Providers, storage, recording, retention, notices and human escalation are defined per customer project. Calls are recorded only where agreed, lawful and appropriately disclosed. This website makes no solely automated decisions with legal or similarly significant effects.

12. Updates

This policy may change when services or law change. Last updated: 5 September 2026.

Imprint

Privacy & Cookies

We use cookies to improve your experience. By using the site you agree to our privacy policy.