Privacy Policy
How we collect, process and use your data and what rights you have as a data subject.
/ Contents:
- 1. Introduction and Scope
- 2. Data Controller
- 3. Legal Basis for Data Processing
- 4. Collected Data and Purposes
- 5. Cookies and Tracking
- 6. Third Parties and International Transfer
- 7. Storage Duration
- 8. Your rights as a data subject
- 9. Data Security
- 10. Processors and recipients
- 11. Minors
- 12. Changes to this privacy policy
- Questions about Data Protection?
1. Introduction and Scope
This privacy policy informs you about the collection, processing and use of your personal data by Weblio and about your rights as a data subject. The privacy policy applies to all services of Weblio, including our website, customer portal and all related services.
3. Legal Basis for Data Processing
We process your data on the following legal bases:
- Consent (Art. 6 para. 1 lit. a GDPR): When you have given us your explicit consent
- Contract Performance (Art. 6 para. 1 lit. b GDPR): For the provision of our web design and hosting services
- Legitimate Interest (Art. 6 para. 1 lit. f GDPR): To improve our services and IT security
- Legal Obligation (Art. 6 para. 1 lit. c GDPR): To fulfill legal retention and reporting obligations
4. Collected Data and Purposes
4.1 Automatically Collected Data
The following data is automatically collected each time you visit our website:
- IP address
- Browser type and version
- Operating system
- Referrer URL
- Date and time of access
- Amount of data transferred
Purpose: IT security, error diagnosis, website performance optimisation, and automatic determination of the display currency relevant to you (CHF for visitors from Switzerland, EUR for the EU and other regions). No personal location tracking takes place; only the country is derived from the IP address.
4.2 Contact Form
When using our contact form, we collect:
- Name
- Email address
- Phone number (optional)
- Message content
Purpose: Processing your inquiries and communication
4.3 Customer Portal (Google OAuth)
When logging in via Google OAuth, we process:
- Google ID
- Name (provided by Google)
- Email address (provided by Google)
- Profile picture (if shared)
Purpose: Authentication, access to customer portal
4.4 Support System
In the support ticket system, we process:
- Ticket content and messages
- Ticket category and priority
- Processing history
- File attachments (if uploaded)
Purpose: Customer support, problem resolution, service improvement
4.5 Business Data
For our business relationship, we process:
- Project data and progress
- Invoice information
- Quote data
- Payment information
Purpose: Contract fulfillment, accounting, legal retention requirements
4.6 Website Analysis Tool
When you use our website analysis tool, we process:
- The website address (URL) you submit for analysis
- Your email address (only if you request the detailed report)
- A pseudonymised access identifier, used exclusively to prevent abuse
- A preview of the publicly accessible target page
- Your consent to receive optimisation tips (voluntary, revocable at any time)
Purpose: Generating and delivering the analysis report, providing individual offers exclusively for the submitted website (see Terms § 8a), and ensuring the proper operation of the service.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures at the request of the data subject) and Art. 6(1)(f) GDPR (legitimate interest in protecting against abuse). For newsletter emails: Art. 6(1)(a) GDPR (consent).
Retention: Analysis data and preview images are cached for a limited period on our own infrastructure and then deleted. Email addresses are stored until the processing purpose has been fulfilled or until you withdraw your consent. Access identifiers used for abuse prevention are deleted after a short period.
Disclosure: Analysis data and your email address are not disclosed to third parties for advertising purposes. Processing takes place on our own infrastructure.
5. Cookies and Tracking
This website sets no cookies for advertising or analytics and loads nothing from third-party servers: no external fonts, no maps, no embedded videos. That is why there is no consent banner here. Technically necessary cookies are only set in the customer portal, that is, after you log in. There is no visitor analytics on this website; Umami runs solely in the customer area on app.weblio.eu.
Cookies in the customer portal:
- Session Cookie: For your login to the customer portal
- Language Setting: To save your preferred language
- CSRF Token: For protection against Cross-Site-Request-Forgery
Stored in your browser (not a cookie):
- Colour scheme: Remembers whether you want the site light or dark. Stays on your device.
- Configurator state: Remembers your selection in the web design configurator so it is still there when you come back. Stays on your device.
Website Analytics:
- Umami Analytics (cookieless, self-hosted on analytics.weblio.eu, no personal data). Umami is embedded on app.weblio.eu, not on weblio.eu.
6. Third Parties and International Transfer
6.1 Google OAuth
For login we use Google OAuth. Data is transferred to Google LLC (USA). Google is certified under the EU-US Data Privacy Framework.
6.2 Stripe (Payment Processing)
We use Stripe, Inc. (USA) for payment processing. When making a purchase, payment data (credit card number, name, billing address) is transmitted directly to Stripe. We do not store payment data on our servers. Stripe is certified under the EU-US Data Privacy Framework and PCI DSS Level 1 compliant. Legal basis: Art. 6(1)(b) GDPR (contractual performance).
6.3 Chatwoot (Live Chat)
For live chat we use Chatwoot, self-hosted on our own server (support.weblio.eu). Messages and contact data are stored exclusively on our infrastructure in Germany. No data is transmitted to third parties.
6.4 Cloudflare Turnstile (Bot Protection)
To protect our forms from abuse we use Cloudflare Turnstile. Technical data (IP address, browser information) is transmitted to Cloudflare, Inc. (USA). Cloudflare is certified under the EU-US Data Privacy Framework. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protection against abuse).
6.5 Email Delivery
For sending emails (confirmations, notifications) we use our own mail-server infrastructure (Plesk/Postfix on our own VPS in Germany). Email addresses and message content are processed exclusively on our own servers within the EU. Legal basis: Art. 6(1)(b) GDPR (contractual performance) or Art. 6(1)(f) GDPR (legitimate interest).
6.6 Fonts
We use the Manrope and JetBrains Mono typefaces. Both are copied into our own delivery directory when the site is built and are served from our own server. Opening the page therefore creates no connection to a font provider, and no IP address is transmitted to third parties.
6.7 Hosting Partners
We work with various hosting providers but prefer Swiss and EU providers for maximum data protection. All partners are contractually obligated to comply with data protection regulations.
7. Storage Duration
- Contact inquiries: 2 years after last contact
- Customer portal data: Until account deletion
- Support tickets: 3 years after completion
- Invoice data: 10 years (legal retention requirement)
- Project data: 5 years after project completion
- Server logs: 90 days
8. Your rights as a data subject
As a data subject you have the following rights under Art. 15 to 22 GDPR and Art. 8 et seq. of the Swiss Federal Act on Data Protection (revDPA):
- Right of access: Art. 15 GDPR / Art. 25 revDPA: obtain information about the data we process, the purposes, categories, recipients and retention periods.
- Right to rectification: Art. 16 GDPR / Art. 32(1) revDPA: correction of inaccurate or incomplete personal data.
- Right to erasure: Art. 17 GDPR / Art. 32(2) revDPA: erasure of your data unless statutory retention obligations apply.
- Right to restriction: Art. 18 GDPR: restriction of processing while the merits of an objection are being assessed.
- Right to data portability: Art. 20 GDPR: receipt of your data in a structured, commonly used and machine-readable format.
- Right to object: Art. 21 GDPR: objection to processing based on legitimate interests.
- Right to withdraw consent: Art. 7(3) GDPR: withdrawal of a previously granted consent with effect for the future.
- No automated individual decision-making: Art. 22 GDPR: no solely automated decision-making with legal effects takes place.
Contact for data protection inquiries:
Email: info@weblio.eu
We respond to requests without undue delay and at the latest within one month.
Right to lodge a complaint:
You have the right to lodge a complaint with the competent data protection supervisory authority.
CH: For residents of Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch
EU: For residents of the EU: the competent supervisory authority in the Member State of your habitual residence.
9. Data Security
We implement technical and organizational measures to protect your data:
- SSL encryption for all data transfers
- Secure password policies
- Regular security updates
- Restricted access to personal data
- Regular encrypted backups
10. Processors and recipients
We engage carefully selected service providers who process personal data exclusively on our behalf and in accordance with our instructions. Where legally required, we have entered into data processing agreements under Art. 28 GDPR and, for transfers to third countries, we rely on appropriate safeguards under Art. 44 et seq. GDPR (e.g. Standard Contractual Clauses).
Sub-processors engaged (named):
- Stripe Inc. (US) - payment processing
- OpenAI L.L.C. (US) - AI features, where enabled
- Google LLC (US) - Analytics, OAuth login, Search Console, Places API, CrUX
- Cloudflare Inc. (US) - bot mitigation (Turnstile)
- IONOS SE (DE) - hosting infrastructure
- Plesk International GmbH (US) - hosting management
- Meta Platforms Inc. (US) - indirectly via WhatsApp bridge (WAHA) and social-media posting (Upload-Post)
Self-hosted components on our own infrastructure in Germany:
- Umami - privacy-friendly analytics
- Chatwoot - support and live-chat system
- Jitsi Meet - video conferencing
Transfers to third countries
Transfers to third countries (in particular the United States) take place on the basis of the EU Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR and, where applicable, the Swiss-U.S. Data Privacy Framework. A complete, up-to-date list of all sub-processors, including registered office, purpose and safeguards, is provided on request by email to info@weblio.eu.
Data Processing Agreement (DPA)
Business customers may download a standard Data Processing Agreement (DPA) at www.weblio.eu/api/dpa-template.php?locale=en or request it by email to info@weblio.eu.
Changes to the sub-processor list are communicated to active customers by email at least 30 days in advance.
11. Minors
Our services are intended for persons aged 16 or older. Persons under the age of 16 may not submit personal data to us without the consent of their legal guardians. If we become aware that we have inadvertently collected data from a minor without appropriate consent, we will delete it without delay.
12. Changes to this privacy policy
We update this privacy policy when our processing activities or the legal framework change. The current version is always available at www.weblio.eu/privacy-policy. For material changes we notify affected data subjects with an ongoing contractual relationship by email.
Questions about Data Protection?
If you have any questions or concerns about data protection, please contact us at any time:
Email: info@weblio.eu
