Coiltech 2026 · Stand C29

Privacy and data protection

Privacy Policy

This page explains what personal data we collect when you visit cleversuite.ch, why we need it and how you can exercise your rights.

cleversuite.ch — Clever SuiteLast updated: July 29, 2026

No profiling

No advertising, profiling or retargeting cookies, tracking pixels or third-party ad tech.

Self-hosted analytics

Umami on our own servers: no cookies, no individual profiles, aggregate data only.

Data in Switzerland

Processed exclusively in the data centres of Infomaniak Network SA, in Switzerland.

FADP and GDPR

Compliant with Swiss law and, where applicable, the European data protection regulation.

Table of contents
  1. 01Data controller
  2. 02Scope
  3. 03Guiding principle: we collect the minimum
  4. 04Categories of data we process
  5. 05Cookies and similar technologies
  6. 06Recipients of data
  7. 07International data transfers
  8. 08Data security
  9. 09Automated decision-making
  10. 10Your rights
  11. 11Right to lodge a complaint
  12. 12Representatives
  13. 13Children
  14. 14Third-party links
  15. 15Changes to this policy
01

Data controller

The controller for personal data collected through cleversuite.ch is:

Intycode Sagl
Vicolo Concordia 1
6932 Breganzona (TI) — Switzerland
Company ID (UID): CHE-260.486.512

Intycode Sagl develops and distributes the Clever Suite product.

Data protection contact person

Dario Mastromarco
Address for data protection enquiries: compliance@intycode.com

You may use this address to exercise your rights or to ask any question about how we process your data.

02

Scope

This policy covers the personal data we collect through cleversuite.ch, how we use it and the choices available to you.

The website is accessible worldwide. Depending on where you are and on the processing involved, the following rules may apply:

  • the Swiss Federal Act on Data Protection (FADP) and its Ordinance (DPO), in force since 1 September 2023;
  • the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), where processing falls within its territorial scope under Art. 3 GDPR — that is, where we offer our products to individuals located in the European Economic Area;
  • other applicable data protection laws, where relevant.

References to the GDPR apply only where the GDPR actually governs the processing described.

03

Guiding principle: we collect the minimum

We follow a simple rule: collect only what is needed. In practice, the cleversuite.ch website:

  • uses no advertising, profiling or retargeting cookies, tracking pixels or third-party ad tech;
  • shares no data with advertising networks or data brokers;
  • never sells or otherwise monetises personal data;
  • relies solely on strictly necessary technologies plus a self-hosted, privacy-first analytics solution that measures traffic in aggregate form.
04

Categories of data we process

Technical connection data (server logs)

When you open a page, the server records some technical data needed to deliver it correctly and keep the site secure:

  • IP address (truncated or pseudonymised where technically feasible);
  • date and time of the request;
  • requested URL and HTTP response code;
  • browser and operating system type and version;
  • volume of data transferred.

Purpose: correct delivery of pages, IT security, prevention of abuse and attacks, error diagnostics.

Legal basis: our legitimate interest in operating a secure and stable website (Art. 6(1)(f) GDPR); overriding interest under Art. 31(1) FADP.

Retention: 6 months. This period is justified by the need to detect and reconstruct abuse, intrusion attempts and automated attacks, which often only come to light after some time. Where a security incident is documented, the relevant logs are retained until the analysis and any related proceedings are concluded.

Usage statistics (self-hosted analytics)

To see which pages are being visited we run Umami, an open-source analytics solution installed on our own servers hosted with Infomaniak SA in Switzerland. The data is not transmitted to any third party and remains solely under our control: we do not use the Umami cloud service, and no data leaves our infrastructure.

This solution:

  • sets no cookies and uses no other persistent identifiers on your device;
  • builds no individual profiles, does not track users across websites, and cannot recognise you on a later visit;
  • records a limited set of information: page viewed, landing page, referring site (referrer), device and browser type, language, and country at national level.

Your IP address is not stored. It is used for a few moments to compute a non-reversible hash serving as a pseudonymous session identifier. The cryptographic salt used in that computation is regenerated every 24 hours: after that point the identifier can no longer be linked to any device, and correlating visits across different days becomes technically impossible.

In the analytics interface, data is viewed solely in aggregate form (counts, trends, page and referrer rankings).

Purpose: aggregate audience measurement, improvement of site content and usability.

Legal basis: our legitimate interest in understanding how our website is used, by means of a low-privacy-impact tool (Art. 6(1)(f) GDPR); overriding interest under Art. 31(1) FADP.

Because the solution neither stores nor accesses information on your device, no consent is required under Directive 2002/58/EC (ePrivacy) or corresponding national cookie rules.

Retention: individual browsing events are retained for 26 months, a period allowing year-on-year comparison across two full seasonal cycles. Deletion is automated: a scheduled routine purges all records older than that threshold from the database each month, with no manual intervention required. The cryptographic salt used to count unique visitors is regenerated every 24 hours.

Contact forms and sales enquiries

When you contact us through a form, we receive the information you choose to provide, usually:

  • first and last name;
  • email address;
  • company and role (if provided);
  • telephone number (if provided);
  • content of your message;
  • date and time of submission and a record of the consent you gave.

Mandatory fields are marked as such on the form. Please do not include unnecessary personal data in free-text fields, in particular sensitive data (health information, political or religious opinions, biometric data, etc.).

Purposes and legal bases:

PurposeLegal basis (GDPR)Legal basis (FADP)
Responding to your enquiry and providing the information requestedPre-contractual measures (Art. 6(1)(b))Processing connected with a contractual or pre-contractual relationship (Art. 31(2)(a))
Contacting you again with commercial communications about Clever Suite (product updates, offers, invitations)Explicit consent given via the dedicated checkbox (Art. 6(1)(a))Consent (Art. 6(6) FADP)

Consent to further commercial contact is optional, separate and not pre-ticked: you will receive an answer to your enquiry whether or not you give it. You may withdraw it at any time, without formality, by writing to compliance@intycode.com or using the unsubscribe link included in every communication. Withdrawal does not affect the lawfulness of processing carried out before it.

Retention:

  • enquiry data: 36 months from the last meaningful contact, a period reflecting the typical length of a B2B software sales cycle and the need to document the exchange;
  • data used for consent-based commercial contact: until consent is withdrawn. Where you have not interacted with us for 36 consecutive months, we review whether the consent is still current and, unless you confirm it, delete or anonymise the data;
  • proof of consent: retained for the duration of processing and for 3 years thereafter, as evidence of compliance in the event of a dispute or supervisory authority review.

Software download area for licensed customers

If you hold a Clever Suite licence, accessing the download area involves processing of:

  • credentials or licence key linked to your account;
  • name, email address and company associated with the licence;
  • access and download logs (date, time, version downloaded, IP address).

Purpose: verifying licence ownership and validity, delivering the software and updates, preventing unauthorised use, providing technical support, meeting contractual and legal obligations.

Legal basis: performance of the licence agreement (Art. 6(1)(b) GDPR; Art. 31(2)(a) FADP); legitimate interest in protecting our software against misuse (Art. 6(1)(f) GDPR); compliance with legal obligations, in particular accounting and tax requirements (Art. 6(1)(c) GDPR).

Retention: for the term of the contractual relationship and thereafter for 10 years, in line with the business record retention obligation under Art. 958f of the Swiss Code of Obligations and with the ordinary limitation period for contractual claims (Art. 127 CO). Access and download logs are retained for 24 months, a period needed to detect use inconsistent with the licence and to reconstruct the history of installed versions for support purposes.

This policy covers the cleversuite.ch website. Processing that takes place within the Clever Suite application deployed at our customers is governed by the licence agreement and the associated data processing agreement (DPA), under which Intycode Sagl typically acts as a processor on the customer's behalf.

05

Cookies and similar technologies

cleversuite.ch uses strictly necessary cookies and technologies only, for example to:

  • secure the session and protect forms against CSRF attacks;
  • maintain authentication in the licensed download area;
  • store essential preferences such as your selected language.

These are indispensable to delivering the service you requested and therefore do not require your prior consent. We use no analytics, profiling or third-party advertising cookies.

You can configure your browser at any time to block or delete cookies; some site functions, in particular the download area, may then not work correctly.

06

Recipients of data

Personal data is accessible only to authorised Intycode Sagl personnel bound by confidentiality, and only to the extent required for their duties.

We also use a limited number of suppliers acting as processors, under agreements compliant with Art. 28 GDPR and Art. 9 FADP:

SupplierPurposeData location
Infomaniak Network SA, GenevaHosting of the website, the download area, our Umami instance and our email servicesSwitzerland (own data centres, powered by renewable energy)

Infomaniak Network SA is a Swiss company whose infrastructure is located entirely in Switzerland and which is subject to the Swiss FADP. We use no other suppliers with access to personal data collected through this website.

Website maintenance and development are carried out in-house by Intycode Sagl.

Beyond these cases, we disclose data to third parties only where required by law or by order of a competent authority, or where necessary to establish, exercise or defend legal claims.

07

International data transfers

Data is processed exclusively in Switzerland, in the data centres of Infomaniak Network SA.

Switzerland benefits from a European Commission adequacy decision: transferring personal data from the EU/EEA to Switzerland is therefore treated as equivalent to a transfer within the European Economic Area and requires no additional safeguards such as Standard Contractual Clauses.

We do not transfer data to third countries lacking an adequate level of protection. Should this become necessary in future, it will take place only on the basis of appropriate safeguards — in particular the European Commission's Standard Contractual Clauses (Decision 2021/914), which are also recognised by the Swiss FDPIC — supplemented where necessary by additional technical and organisational measures, and this policy will be updated accordingly.

08

Data security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure, including:

  • TLS/HTTPS encryption across all pages;
  • access control on a least-privilege basis;
  • strong authentication for administrative access;
  • regular backups with tested restore procedures;
  • systematic patching and updating of infrastructure;
  • access logging and monitoring of security-relevant events.

No system can guarantee absolute security. In the event of a data security breach posing a high risk to your rights, we will notify the competent authority and, where required, inform you, within the deadlines set by Art. 33 GDPR (72 hours) and Art. 24 FADP (as soon as possible).

09

Automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR; Art. 21 FADP).

10

Your rights

You may exercise the following rights in relation to your personal data:

RightContent
AccessObtain confirmation of processing and a copy of the data concerning you (Art. 15 GDPR; Art. 25 FADP)
RectificationHave inaccurate data corrected or incomplete data completed (Art. 16 GDPR; Art. 32(1) FADP)
ErasureHave your data deleted, within the limits set by law (Art. 17 GDPR; Art. 32(2) FADP)
RestrictionHave processing restricted in certain circumstances (Art. 18 GDPR)
PortabilityReceive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller (Art. 20 GDPR; Art. 28 FADP)
ObjectionObject at any time, on grounds relating to your particular situation, to processing based on our legitimate interest; for direct marketing, the objection is always unconditional (Art. 21 GDPR; Art. 30(2)(b) FADP)
Withdrawal of consentWithdraw consent at any time, with effect for the future (Art. 7(3) GDPR; Art. 6(6) FADP)

How to do this: write to compliance@intycode.com, or by post to Intycode Sagl, for the attention of Dario Mastromarco, Vicolo Concordia 1, 6932 Breganzona, Switzerland.

To protect you against unauthorised access, we may ask you to verify your identity in a proportionate manner. We respond within 30 days of receiving your request; for particularly complex requests the deadline may be extended, and we will explain why. Exercising your rights is free of charge, except for manifestly unfounded or excessive requests.

11

Right to lodge a complaint

If you believe our processing infringes applicable law, you may contact:

  • Switzerland — Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern — edoeb.admin.ch
  • EU/EEA — the supervisory authority of the Member State where you habitually reside, where you work, or where the alleged infringement occurred (Art. 77 GDPR).

We would appreciate the chance to address your concern first — in most cases we can resolve matters directly and quickly.

12

Representatives

EU representative (Art. 27 GDPR). Intycode Sagl has no establishment in the European Union. We consider that the processing described in this policy falls within the exception in Art. 27(2)(a) GDPR, being occasional, not involving large-scale processing of special categories of data, and unlikely to result in a risk to the rights and freedoms of natural persons. Should the volume or nature of our processing change, we will appoint an EU representative and publish their details here.

Controller's note

This assessment must be reviewed periodically. If cleversuite.ch begins collecting EU leads on a regular, structured basis — which is likely for software sold internationally — the Art. 27(2)(a) exception no longer applies, and a representative must be designated in writing in an EU Member State and identified here.

Swiss representative (Art. 14 FADP). Not applicable: the controller is established in Switzerland.

Data protection officer (DPO). We have not appointed a DPO. We carry out no regular and systematic monitoring of data subjects on a large scale, and we do not process special categories of data or criminal conviction data on a large scale, so none of the conditions triggering a mandatory appointment under Art. 37 GDPR applies. Nor have we made the optional appointment of a data protection adviser under Art. 10 FADP.

Responsibility for data protection rests directly with management, in the person of Dario Mastromarco, who acts as the point of contact for data subjects and authorities. Requests sent to compliance@intycode.com are handled by him.

13

Children

The website and Clever Suite are aimed at professionals and businesses and are not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it without delay.

15

Changes to this policy

We may update this policy to reflect legal, technical or organisational developments. The applicable version is the one published on this page, with its last-updated date. Where changes materially affect your rights, we will inform you in good time by notice on the website or by direct communication.

Questions about your data?

Write to us: we respond within 30 days of receiving your request, and exercising your rights is free of charge.

This policy is issued in Italian and English. In the event of divergence, the Italian version prevails.

Back to top