Privacy policy

Last updated: 8 October 2026

Translation. Only the German version is legally binding.

This privacy policy explains how Sharpsoft processes personal data when you visit sharpsoft.ch, are in contact with us or are a customer. It is based on the Federal Act on Data Protection (FADP).

Controller

Sharpsoft, Luc Baumann
Haselrain 2, 3186 Düdingen
luc@sharpsoft.ch

What data we process and why

Visiting the website.

  • What is stored: When you access sharpsoft.ch, our server and our service provider Cloudflare process technical data: IP address, time, page accessed, browser and operating system.
  • Why: We need this data to deliver the website, fend off attacks and find errors.
  • How long: We delete our logs after 30 days at the latest.
  • Cookies: The public website sets no cookies. The customer portal sets only a technically necessary session cookie for logging in.
  • What we do not use: Third-party analytics and advertising services, fonts, maps or videos.

Contact. If you write to us by email or via the contact form, we process your details to answer your enquiry. We store messages from the contact form on our server and receive a notification about them by email. We delete data from the contact form 12 months after the last message, unless a customer relationship has arisen from it (portal access, demo or contract).

Customers.

  • What we process:
    • contact details and contact persons
    • quotes, contracts and invoices
    • payments
    • correspondence
    • change requests, messages and files in the customer portal
    • when you log in to the portal: IP address, browser and time of login, for the security of your account
  • Why: to perform the contract and keep the accounts.
  • Where: The platform, customer portal and backups run on servers in Switzerland (Sharpsoft's own server) or in Germany (Hetzner Online GmbH).
  • AI agents: Change requests and questions in the customer portal are handled by AI agents from Anthropic (Claude). For this purpose, the content of your message, attached files and the code of your website are sent to Anthropic. The contracting party is Anthropic Ireland, Limited; processing may also take place in the USA. Anthropic does not use this data to train its AI; our accounts are configured accordingly. Anthropic keeps the data only for a limited period, usually up to 30 days, and deletes it afterwards. Please do not enter confidential data in the portal, such as passwords, trade secrets, data of your customers or health data.
    • With the option “AI with data processing agreement” (available in the quote), your data is routed exclusively through a business account with Anthropic. Anthropic then processes it on our behalf, based on a data processing agreement (DPA) with standard contractual clauses and a Swiss addendum.
    • Without this option, the agents may also run through another Anthropic account. Anthropic then processes the data in accordance with its own privacy policy (anthropic.com/legal/privacy).
  • No automated individual decisions: The agents quote prices from our catalogue and carry out your orders. Contracts, price adjustments and a switch-off due to late payment are always decided by a person; we do not make automated individual decisions within the meaning of Art. 21 FADP.
  • Interface (REST API, MCP): If you create API tokens, we log their use (time, action, token identifier) as evidence, in particular for accepted quotes. We store tokens only in hashed form.
  • Payments: You pay by QR-bill to our bank account. In doing so, we receive from the bank the amount, the time, the reference and the name of the person paying. If we offer further payment methods, we will supplement this policy beforehand.
  • How long: We keep business records for 10 years as required by law. We delete portal login data no later than 30 days after the end of the session.
  • When a quote is accepted online: In that case we additionally store the name given, the time and the IP address as evidence.

Businesses we approach.

  • Whom we approach: We approach businesses whose website we could improve.
  • What data we use: only publicly accessible business data:
    • company name, business address, industry, business email address and telephone number
    • the publicly accessible website and its technical characteristics
  • Where the data comes from:
    • OpenStreetMap
    • the business's website
    • public directories and the commercial register
  • Why:
    • to assess whether our offering is a good fit
    • to contact the business individually and personally
    • to show a draft of a new website, where appropriate
  • AI tools: To assess the website and draft our message, we use AI tools from Anthropic (see table). Only the public business data and the public website are processed in this context. The drafts are kept in Sharpsoft's email mailbox (see table). Luc Baumann personally reads and sends every message.
  • Website drafts (demo): They run on our own server in Switzerland, cannot be found publicly and are deleted no later than three months after being shown if no order results.
  • Objection: You can object to the processing at any time by sending a short message to luc@sharpsoft.ch. We will then no longer contact you. To keep it that way, we store only a blocking note.

Who else receives the data

We do not pass on personal data for advertising purposes and do not sell it. The following service providers process data for us:

Service providerPurposeLocation and basis for the transfer
Cloudflare, Inc.DNS, delivery and protection of sharpsoft.ch and the customer portal; sees IP addresses and requests in the processworldwide, USA; Swiss-U.S. Data Privacy Framework
Hetzner Online GmbHServers for the platform and customer portal, for websites with a backend or high traffic and for backupsGermany
Google Firebase Hosting (Google LLC or Google Cloud EMEA Limited, Ireland)Hosting of static customer websites; when a site is accessed, Google processes the visitors' IP addressesworldwide, USA, no fixed location; Swiss-U.S. Data Privacy Framework
GitHub, Inc.Source code of customer projects, one repository per customerUSA; Swiss-U.S. Data Privacy Framework
Anthropic Ireland, Limited (with Anthropic, PBC, USA)AI agents for enquiries and change requests in the customer portal; AI tools for assessing public websites and drafting messages when acquiring customers; no training with your dataIreland, USA; Anthropic is not certified under the Data Privacy Framework. With the option “AI with data processing agreement”: standard contractual clauses with a Swiss addendum. Without the option: in accordance with Anthropic's privacy policy, which bases transfers to the USA on standard contractual clauses
Google Workspace (Google Cloud EMEA Limited, Ireland, with Google LLC, USA)Email of luc@sharpsoft.ch, notifications from the portal, also the message drafts when acquiring customersIreland, USA; Swiss-U.S. Data Privacy Framework, otherwise standard contractual clauses with a Swiss addendum

For visitors to our customers' websites, the respective customer is the controller; we process this data on the customer's behalf. The customer's privacy policy names Google Firebase Hosting if the customer's website runs there.

Authorities receive data only if the law requires it.

Data security

We protect data with encrypted connections, access restrictions, up-to-date software and backups, which we keep for 30 days.

Your rights

You can at any time:

  • request information about your personal data,
  • have incorrect data corrected,
  • request deletion or object to the processing, provided there is no statutory retention obligation,
  • request the return of your data in a common format.

To do so, write to luc@sharpsoft.ch. We respond within 30 days. You may also contact the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch).

Changes

We adapt this privacy policy when our processing changes. The version published on sharpsoft.ch applies.