Privacy policy
Version: September 2026 · Edition: 3.2 · Applies to: ai-edu.ch
1. Controller
The controller within the meaning of the applicable data-protection laws, in particular the Swiss Data Protection Act (DSG) and the EU General Data Protection Regulation (GDPR), is:
Reto Lutz
Sole proprietorship "ai-edu"
Switzerland
Email: contact@ai-edu.ch
Phone: +41 77 289 52 45
You can contact me at any time with questions about data protection.
2. Principles of data processing
Based on Article 13 of the Swiss Federal Constitution and the data-protection provisions of Swiss federal law (DSG), every person has the right to privacy and to protection against misuse of their personal data.
I follow these principles:
- Lawfulness: I process data only on a lawful basis.
- Purpose limitation: Data is only collected for specified, explicit purposes.
- Data minimisation: I only collect the data I actually need.
- Accuracy: I keep your data up to date and correct.
- Storage limitation: Data is kept only as long as necessary.
- Integrity and confidentiality: I protect your data appropriately.
3. Data collection on this website
3.1 Server log files
Every time you access my website, information is automatically recorded and stored in server log files. This includes:
- Browser type and version
- Operating system
- Referrer URL (previously visited page)
- Hostname of the accessing computer
- Date and time of the server request
- IP address (anonymised)
This data cannot be assigned to specific persons and is used to ensure smooth operation and to improve my services.
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR).
3.2 Hosting
This website is hosted by Netlify, Inc. (USA). Servers are located in various data centres worldwide. Netlify processes data under the EU Standard Contractual Clauses.
5. Processing of company data
5.1 Training data
When delivering workshops and training, the following data may be collected:
- Names and email addresses of participants
- Internal example data (anonymised)
- Training outcomes and feedback
This data is used exclusively to deliver the agreed service and, after completion, is deleted or returned to the client according to the contractual arrangements.
5.2 Confidentiality
I treat all company data received in the course of training and advisory engagements as strictly confidential. The confidentiality obligation is contractually anchored in my Terms.
5.3 AI tools and company data
My training addresses the safe use of AI tools. I recommend that clients:
- Do not enter confidential company data into public AI systems
- Use Enterprise versions of AI tools with data-protection guarantees
- Establish internal guidelines for AI use
6. Contact form and enquiries
When you contact me via the contact form, email, or phone, your details are stored to process the enquiry.
6.1 Data collected
- Name
- Company name
- Email address
- Area of interest (optional)
- Message content
- Origin details: referring page, landing page and campaign parameters (
utm_*,gclid), where present
About the origin details: so that the route by which you reached this website
is still known when you submit, your browser stores these details on your
first visit under the key aiedu_herkunft in session storage. The
entry contains no identifier, applies only to that one browser tab, is never
sent automatically with any request, and serves solely to attribute your
enquiry to the right source. The switch in section 4.3 disables and clears it. For ChatGPT ads we ask for separate, optional permission before storing attribution. Without permission, campaign details are not added to the form or sent to Cal.com. The choice lasts for this browser tab. This ad attribution is unavailable when session storage is blocked.
6.2 Processing via Netlify Forms
With JavaScript enabled, the form sends your enquiry through a Netlify proxy to my own server and waits for confirmed receipt. Without JavaScript, Netlify Forms processes the enquiry and it is subsequently synchronised to my server. In that case Netlify stores the details on servers in the EU/USA.
6.3 Confirmed receipt on my own server
My server in Switzerland stores the enquiry, receipt date and contact ID. A random submission ID prevents duplicate submissions when you retry; it does not track your browsing. Enquiries and bookings with the same email address are combined for handling. I record business needs, qualification, conversations, quotes and orders.
The same details listed under 6.1 are transmitted, plus your IP address, browser identifier and the referring page. The transport path runs via Tailscale, which provides the encrypted connection to my server and only carries the content – see section 8.1. Storage takes place exclusively on hardware in Switzerland.
In addition, I send myself a notification about your enquiry to my own address. For this delivery I use Resend (USA) as a processor; the message contains the details listed under 6.1. The sole purpose is to ensure that an enquiry does not go unnoticed.
Legal basis: Pre-contractual steps (Art. 6(1)(b) GDPR).
6.4 Calendar bookings and ad attribution
Cal.com, Inc. provides the booking calendar. A connection is made only when you open it. Booking information includes name, email, company, enquiry and appointment details. With your optional ChatGPT attribution permission, the five standard UTM parameters are also passed to Cal.com. Confirmed bookings, their campaign origin and cancellations are synchronised to my server through the existing authenticated Cal.com API.
The limited ChatGPT ad test measures confirmed contacts, qualification and orders. Calendar loads, submit attempts and thank-you page visits are not confirmed contacts. No contact data is sent to OpenAI for this test, and no OpenAI pixel or automatic contact matching is installed. Use the switch in section 4.3 to withdraw permission for future transfers; for deletion of existing data, contact contact@ai-edu.ch. The retention periods in section 7 apply. See Cal.com's privacy policy.
7. Retention period
I retain your data only for as long as necessary for the respective purposes or as required by statutory retention obligations.
| Data category | Retention | Reason |
|---|---|---|
| Contact enquiries | 6 months | After enquiry is closed |
| Contract data | 10 years | Statutory retention |
| Invoice data | 10 years | Tax law obligations |
| Server logs | 30 days | Security analysis |
| Statistics data | Aggregated, no personal reference | Audience measurement (section 4.2) |
| Training materials | As agreed | Per contract |
9. Data security
I use technical and organisational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorised access.
9.1 SSL/TLS encryption
For security reasons this website uses SSL/TLS encryption. You can recognise an encrypted connection by the padlock icon in your browser and by the address starting with "https://".
9.2 Further measures
- Regular security updates
- Access restrictions to data
- Encrypted communication
10. Your rights
10.1 Exercising your rights
To exercise your rights, please contact me at contact@ai-edu.ch. I will process your request within 30 days.
10.2 Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your data violates data-protection law.
Competent authority in Switzerland:
Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Feldeggweg 1
3003 Berne
www.edoeb.admin.ch
11. Changes to this privacy policy
I may adjust this privacy policy at any time to reflect changed legal requirements or changes to my services. The current version published on my website applies.
I will notify you on the website of any material changes.
Questions about data protection?
Contact me any time - I am happy to help.
Email: contact@ai-edu.ch
Phone: +41 77 289 52 45