Privacy policy
1. Controller
Controller within the meaning of the Swiss Federal Act on Data Protection (DSG) and the GDPR:
DIGITLZ Massold, owner Christian Massold
Dufourstrasse 49, 8008 Zurich, Switzerland
[email protected]
2. Data collected
- When you visit the site: a truncated IP address, the time, the address requested, the volume of data transferred, the status message, the browser identifier, the language setting, the referring page and the country of origin as supplied by Cloudflare.
- When you write by email: your address and the content of your message.
- When you book an appointment: name, email address, whatever you enter in the additional fields, and the slot you choose. Loading the reservation page also transmits your IP address, browser and device details, and the page you came from.
3. Purposes
- Secure operation and troubleshooting
- Answering your enquiries
- Arranging, confirming and reminding you of appointments
- Protecting the reservation page against abuse
- Initiating and performing a contract
- Audience measurement
4. Legal bases
- Consent – Art. 6(1)(a) GDPR, § 25(1) TDDDG: for loading the reservation page.
- Contract and pre-contractual steps – Art. 6(1)(b) GDPR: for enquiries relating to a contract and for handling appointments.
- Overriding legitimate interest – Art. 31(1) DSG, Art. 6(1)(f) GDPR: for secure operation and for enquiries unrelated to a contract.
- Legal obligation – Art. 6(1)(c) GDPR: for retaining business records.
5. Retention
- Server logs: 30 days.
- Audience measurement data: 90 days, deleted weekly. The reports calculated from it remain.
- Appointment data: until the appointment is dealt with, at most twelve months – provided no business relationship arises.
- Business records: ten years (Art. 958f OR, the Swiss Code of Obligations).
6. Recipients and disclosure
Data is not passed to third parties, apart from the service providers below and to authorities where the law requires it. Where data is disclosed abroad, the country and the safeguard must be named (Art. 19(4) DSG).
- Cloudflare, Inc., USA – delivery of the website and protection against overload; involved in every page view. Safeguard: standard contractual clauses with the Swiss addendum recognising the EDÖB, the Swiss Federal Data Protection and Information Commissioner, as supervisory authority, supplemented by the Swiss-U.S. Data Privacy Framework.
- Google Cloud EMEA Limited, Dublin, Ireland – email and appointment booking, as processor. Safeguard: adequacy decision for Ireland; for onward transfer to Google entities in the USA the standard contractual clauses (EU) 2021/914, processor-to-processor module, with Google as exporter.
- Google LLC, Mountain View, USA – operation of the reservation page and reCAPTCHA abuse protection, as an independent controller. Its own terms apply: policies.google.com/privacy.
7. Cookies and local storage
This website sets cookies of its own only where you have decided something yourself: for your choice of language, and for your objection to the audience measurement.
- The cookie “digitlz-sprache” records whether you want to read the site in German or in English. It is only created once you use the switch in the header, contains nothing but “de” or “en”, and expires after a year. It serves only the presentation you asked for and therefore needs no consent; you can delete it in your browser settings.
- Your browser's local storage holds your colour scheme, the currency you picked and, once you have loaded the appointment picker, your consent to it. None of that leaves your device.
- The Google Calendar reservation page on the contact page only loads once you explicitly ask for it – before that, no request goes to Google. Google then sets the cookie “NID” with a lifetime of around six months and loads its reCAPTCHA abuse protection.
- The cookie “digitlz-nicht-zaehlen” is only created if you object to the audience measurement. It contains a 1 and expires after a year.
- Your consent can be withdrawn at the bottom of this page. The Google cookie is one you delete in your browser settings.
8. Audience measurement
To see which pages get read, DIGITLZ analyses the access log of its own server. Nothing is stored on or read from your device, and no service provider is involved. The legal basis is the overriding and legitimate interest in a demonstrably better website (Art. 31(1) DSG, Art. 6(1)(f) GDPR).
Objection to the audience measurement
One click keeps your visits out of the analysis.
The switch needs JavaScript. The analysis equally respects “Do Not Track” and “Global Privacy Control” from your browser.
9. Your rights
You have the following rights; an email to [email protected] is enough.
- Access to the data held about you (Art. 25 DSG, Art. 15 GDPR)
- Rectification of inaccurate data
- Erasure of your data
- Release or transfer of your data
- Restriction of processing (Art. 18 GDPR)
- Objection to processing (Art. 21 GDPR)
- Withdrawal of a consent you have given
10. Right to complain
You may complain to the competent supervisory authority:
- Switzerland: Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), Feldeggweg 1, 3003 Bern – edoeb.admin.ch
- EU: the data protection authority where you live or work
11. Changes
This policy will be adjusted whenever the services used or the processing change.
Consent for the appointment picker
You have loaded the appointment picker on the contact page and thereby allowed the Google content; the details are in section 7. Your decision sits in your browser's local storage. Withdraw it here – the picker then stays blocked until you ask for it again.
This English text is a translation for information only. In case of any discrepancy, the German version at digitlz.ai/datenschutz/ prevails.
Last updated: 14 August 2026