Privacy Policy
Last updated: May 17, 2026 · Version 2.0
1. Preamble
This privacy policy describes how Practech collects, uses, retains and protects the personal data of visitors to its practech.ch website, of its prospects and of its clients. It applies to all services offered by Practech, whether intended for the Swiss, European or Gulf (GCC) markets.
Practech undertakes to process your data fairly, lawfully and transparently, in accordance with the Swiss Federal Act on Data Protection (FADP, SR 235.1, in force since 1 September 2023), the European Union General Data Protection Regulation (GDPR, EU 2016/679) and, where applicable, the provisions applicable in the United Arab Emirates (Federal PDPL, Decree-Law No. 45 of 2021). Swiss law applies to this policy.
2. Data Controller
Practech
Bern, Switzerland
Phone: 0445938553
Email: contact@practech.ch
Publication director: Youness Bitite
Practech is not required to appoint a Data Protection Officer (DPO) within the meaning of Article 37 GDPR. All questions concerning your data may be addressed directly to the controller at the email address above.
3. Data Collected
Practech only collects data strictly necessary for the provision of its services. The following categories of data may be collected:
- Identification data: first name, last name, business name, role.
- Contact data: postal address, email address, phone number.
- Project data: brief content, description of needs, files transmitted (texts, images, logo, PDF, archives), reference links.
- Billing data: amounts, payment method (anonymized token provided by Stripe or PayTabs, Practech never stores the card number), any VAT number.
- Account data: login credentials, hashed password (bcrypt), language preferences.
- Technical data: IP address, browser type, operating system, pages consulted, timestamp, error log.
- Cookies and trackers: see the dedicated cookie policy.
No sensitive data within the meaning of Article 5 FADP (religious or philosophical beliefs, political opinions, health, biometric data, etc.) is collected by Practech.
4. Processing Purposes and Legal Bases
Your data is processed for the following purposes, on the corresponding legal bases:
- Contract performance (Art. 6.1.b GDPR, Art. 31 FADP): design, development and delivery of the ordered website, provision of the customer area, technical support.
- Legal obligation (Art. 6.1.c GDPR): bookkeeping, issuing invoices, tax returns, 10-year archiving required by Article 958f Swiss CO.
- Legitimate interest (Art. 6.1.f GDPR): fraud prevention, site security, anonymized internal statistics, service improvement.
- Consent (Art. 6.1.a GDPR, Art. 6 FADP): sending commercial communications (newsletter, offers), placement of non-essential cookies. Consent is freely given, informed, specific and revocable at any time.
5. Recipients and Processors
Practech does not sell, rent or transfer your data to third parties for commercial purposes. Your data may however be communicated to the following technical processors, bound by a processing contract compliant with Article 28 GDPR and Article 9 FADP:
- Vercel Inc. (United States, with compute regions in Frankfurt and Paris) — website hosting and code execution. Transfer covered by the Standard Contractual Clauses (SCCs) of the European Commission and the EU-US Data Privacy Framework.
- Supabase Inc. (eu-central-1 region / Frankfurt, Germany) — main database (customer accounts, briefs, files, order history). Data stored in the EEA.
- Anthropic PBC (United States) — brief analysis and content generation by the Claude model. Briefs are transmitted for one-off processing and are not used for training purposes, in accordance with the Anthropic commercial agreement. Transfer covered by SCCs.
- Stripe Payments Europe Ltd (Ireland, with Stripe Inc. in the United States) — payment processing for Swiss and European clients.
- PayTabs (United Arab Emirates / Saudi Arabia) — payment processing for Gulf clients (deployment upcoming).
- Resend, Inc. (United States) — sending transactional emails. Transfer covered by SCCs.
- Cloudflare, Inc. (United States) — DNS, anti-DDoS protection, TLS termination.
- Hostpoint AG (Rapperswil-Jona, Switzerland) — hosting of the contact@practech.ch mailbox. Data stored in Switzerland.
Competent public authorities may also be recipients of your data in the event of a legal obligation.
6. Data Transfers Outside Switzerland / EEA
Some of the processors listed in the previous section are established in the United States or operate infrastructures outside Switzerland and the European Economic Area. These transfers are covered by the following safeguards:
- Standard Contractual Clauses (SCCs) of the European Commission dated 4 June 2021, supplemented by additional technical measures (end-to-end encryption, pseudonymization).
- Adherence to the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework by eligible US providers (Vercel, Stripe Inc.).
- Prior Transfer Impact Assessment for each processor outside the EEA.
You may obtain a copy of the applicable safeguards by writing to contact@practech.ch.
7. Retention Periods
Your data is retained for the duration strictly necessary for the purpose pursued, increased where applicable by legal retention periods:
- Invoices and accounting documents: 10 years from the end of the financial year (Art. 958f CO).
- Contractual data (briefs, exchanges, deliverables): for the entire duration of the contractual relationship, then archived for 5 years after the end of the contract for evidentiary purposes.
- Customer account data: for as long as the account is active, then deleted 12 months after inactivity or on request.
- Support tickets: 3 years after closure.
- Technical logs: 6 months, except in the event of a security incident (12 months maximum).
- Prospecting data: 3 years from the last contact, unless the data subject objects.
- Non-essential cookies: 13 months maximum (cf. cookie policy).
8. Your Rights
In accordance with the FADP and the GDPR, you have the following rights regarding your data at any time:
- Right of access: obtain confirmation that your data is being processed and receive a copy.
- Right of rectification: have any inaccurate or incomplete data corrected.
- Right to erasure ("right to be forgotten"): request the deletion of your data, subject to legal retention obligations.
- Right to restriction of processing.
- Right to data portability: receive your data in a structured, commonly used and machine-readable format.
- Right to object to processing based on legitimate interest or for prospecting purposes.
- Right to withdraw your consent at any time, without affecting the lawfulness of processing based on prior consent.
To exercise these rights, write to contact@practech.ch specifying the purpose of your request. A response will be sent to you within a maximum of 30 days. Proof of identity may be requested in case of reasonable doubt as to your identity.
If you consider that the processing of your data does not comply with regulations, you have the right to lodge a complaint with the competent supervisory authority:
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern — edoeb.admin.ch.
- European Union: supervisory authority of the Member State of your habitual residence, place of work, or place where the alleged infringement occurred.
- United Arab Emirates: UAE Data Office (Office of Data Protection) — uaedataoffice.ae.
9. Data Security
Practech implements appropriate technical and organizational measures to ensure the security of your data:
- Encryption of communications by TLS 1.3 (HTTPS) with automatically renewed certificates.
- Encryption at rest of the databases (AES-256) at Supabase and encryption of uploaded files.
- Hashing of passwords using the bcrypt algorithm.
- HTTP security headers (Content Security Policy, HSTS, X-Frame-Options, Referrer-Policy).
- Daily encrypted backups with a 30-day retention.
- Strictly limited access to authorized personnel, logging of administrative access.
- Two-factor authentication (2FA) for access to Vercel, Supabase and GitHub administration consoles.
- Documented procedure for notifying data breaches within 72 hours to the competent supervisory authority.
10. Protection of Minors
Practech's services are not intended for persons under the age of 16. Practech does not knowingly collect data concerning minors. If you believe that a child has transmitted personal data to us without valid parental consent, please let us know at contact@practech.ch so that we can proceed with their deletion as soon as possible.
11. Cookies and Trackers
The use of cookies and trackers on practech.ch is described in detail in our cookie policy. You may change your choices at any time via the consent banner present at the bottom of the page.
12. Changes to the Policy
Practech reserves the right to amend this policy in order to adapt it to the evolution of its services, legislation or recommendations of supervisory authorities. The applicable version is always the one published on this page, on the date indicated in the header. In the event of substantial modifications, active clients will be informed by email at least 30 days before the new provisions enter into force.
13. Contact
Any question relating to this policy or to your personal data may be addressed to:
Practech
Bern, Suisse
contact@practech.ch
0445938553
See also: legal notice · terms of service · cookie policy.