1. Data controller
The controller of the personal data collected through this website is Atenek SAGL, Via Penate 4, 6850 Mendrisio (Canton of Ticino), Switzerland — CHE-248.446.111 VAT — e-mail: [email protected].
Atenek SAGL determines the purposes and means of the processing and is the "data controller" within the meaning of Art. 5 lit. j nLPD and Art. 4 no. 7 GDPR.
Atenek SAGL has not appointed a Data Protection Officer (DPO), as there is no obligation to do so pursuant to Art. 37 GDPR or Art. 10 nLPD. For any matter relating to personal data you may write to [email protected].
As Atenek is not established in the European Union, it is not required to appoint an EU representative pursuant to Art. 27 GDPR, since the processing is occasional, does not include special categories of data on a large scale and is unlikely to present a risk to the rights of data subjects.
2. Categories of data processed
We process exclusively the data you voluntarily provide to us or that are generated technically by ordinary browsing:
a) Data voluntarily provided through the contact form:
- First and last name
- Business e-mail address
- Company name
- Content of the message (and any personal data you choose to include in it)
b) Contact data via e-mail or WhatsApp: the data you communicate to us if you write directly to [email protected] or through the WhatsApp button (see sec. 6).
c) Technical browsing data: when you visit the site, the servers and network infrastructure necessarily process, solely for the operation and security of the service, technical data such as the IP address, the browser and device type, and the date and time of the request. These data are processed by our hosting/CDN provider (see sec. 6) in the system logs and are not used by Atenek to profile visitors.
We do not process special categories of data (sensitive data under Art. 9 GDPR / Art. 5 lit. c nLPD) through the site. We invite you not to enter sensitive data in the message field of the form.
3. Purposes of the processing
| # | Purpose | Data concerned |
|---|---|---|
| 1 | Respond to requests sent through the form, e-mail or WhatsApp and carry out any preliminary activities requested (e.g. quotes, introductory calls) | Form / contact data |
| 2 | Ensure the security of the site and prevent abuse and spam (honeypot, filters) | Form data / technical data |
| 3 | Deliver and keep the website technically functioning and secure | Technical browsing data |
| 4 | Comply with any applicable legal obligations | Contact data |
We do not use your data for marketing, newsletters or profiling. We do not build mailing lists from the form data without your separate and specific consent.
4. Legal bases of the processing
Under the GDPR (for data subjects in the EU), the legal bases are:
- Art. 6.1.b GDPR (performance of pre-contractual measures taken at the request of the data subject) — for purpose 1: it is you who contact us and handling your request is necessary to follow up on it.
- Art. 6.1.f GDPR (legitimate interest) — for purposes 2 and 3: our legitimate interest in keeping the site secure, functioning and protected from abuse. We have assessed that such interest does not override your rights and freedoms, as it involves minimal data and processing that is expected by the user.
- Art. 6.1.c GDPR (legal obligation) — for purpose 4, where applicable.
Under the nLPD (for data subjects in Switzerland), the processing is lawful in that it complies with the principles of lawfulness, good faith and proportionality (Art. 6 nLPD) and can be traced back to a justifying ground within the meaning of Art. 31 nLPD, namely the existence of a (pre)contractual relationship and Atenek's overriding interest in managing requests and in the security of the site. The nLPD does not require an exhaustive legal basis for the processing carried out by private persons, but rather compliance with the principles and fulfilment of the duty to inform (Art. 19 nLPD), which is discharged through this information notice.
5. Provision of data and consequences of refusal
The provision of the form data is optional, but failure to provide the data marked as mandatory (name, e-mail, message) makes it impossible to process the request. The technical browsing data, on the other hand, are intrinsic to the operation of the site.
6. Recipients and data processors
Your data are processed by the authorized staff of Atenek SAGL and by the following providers, which act as data processors (Art. 28 GDPR / Art. 9 nLPD) on the basis of compliant agreements:
| Recipient | Role / Service | Data location |
|---|---|---|
| Cloudflare, Inc. | Static site hosting and CDN/security network | Global edge network with PoPs in the EU; company based in the USA |
| Atenek's own server infrastructure (VPS) and self-hosted N8N | Reception and processing of the data sent by the form (via internal webhook) | European Union (Germany) |
| Umami (self-hosted by Atenek) | Anonymous and aggregated visit statistics, without cookies and without identification of the user | European Union (Germany) |
| Business e-mail provider | Reception and management of e-mail communications | EU/CH |
| Meta Platforms Ireland Ltd. / WhatsApp | Only if you choose to contact us via the WhatsApp button | EU/USA |
WhatsApp: the site displays a button that opens a conversation on WhatsApp. If you use it, the communication takes place through the WhatsApp app, operated by Meta Platforms Ireland Ltd., in accordance with the terms and privacy policy of WhatsApp/Meta, over which Atenek has no control. We invite you not to share confidential or sensitive data on WhatsApp. The use of WhatsApp is your free choice: alternatively, you can always contact us by e-mail or through the form.
The site's fonts are hosted directly on our own infrastructure (self-hosted): their display does not involve any transfer of data to third-party providers (e.g. Google Fonts).
We do not sell or transfer your data to third parties for marketing purposes.
7. Transfer of data abroad
Most of the processing takes place in Switzerland and in the European Union. However, transfers to third countries, in particular the United States, may occur in relation to the following providers:
- Cloudflare, Inc. (USA) — for the delivery of the site and of the network/security services. Although the content is also served by nodes located in the EU, the company is US-based and may access technical data (e.g. IP address).
- Meta / WhatsApp (USA/Ireland) — only if you contact us via WhatsApp.
Safeguards adopted:
- For transfers subject to the GDPR, where the provider adheres to it, we rely on the adequacy decision relating to the EU-U.S. Data Privacy Framework and/or on the Standard Contractual Clauses (SCC) approved by the European Commission pursuant to Art. 46 GDPR.
- For transfers subject to the nLPD, Switzerland does not automatically recognize the adequacy of the United States through the DPF: we therefore rely on the Standard Contractual Clauses recognized by the FDPIC (Art. 16 nLPD) and, where available, on the "Swiss-U.S. Data Privacy Framework" extension.
A copy of the safeguards may be requested at [email protected].
8. Retention periods
| Data | Retention |
|---|---|
| Form data / contact requests | For the time necessary to handle the request and the resulting commercial contacts; deleted or anonymized at the latest within 24 months from the last contact, unless a contractual relationship develops or legal obligations apply |
| E-mail / WhatsApp communications | For the duration of the relationship and up to 24 months from the last contact |
| Technical system logs (on the hosting/CDN side) | For the technical security periods defined by the provider, as a rule no longer than a few months |
| Data relating to legal obligations (e.g. tax) | For the applicable legal terms (in Switzerland, as a rule 10 years for accounting documentation) |
Upon expiry, the data are irreversibly deleted or anonymized.
9. Rights of the data subject
As a data subject you have the right, within the limits and under the conditions provided for by the applicable legislation, to exercise the following rights.
Rights recognized by both regulations (GDPR + nLPD):
- Access/information (Art. 15 GDPR; Art. 25 nLPD): to know whether we process your data and to obtain a copy/information thereof.
- Rectification of inaccurate data (Art. 16 GDPR; Art. 32 nLPD).
- Erasure/destruction of the data (Art. 17 GDPR; Art. 32 nLPD).
- Objection to the processing (Art. 21 GDPR; Art. 30 nLPD), in particular to those based on legitimate interest.
Rights specific to the GDPR (for EU data subjects):
- Restriction of the processing (Art. 18 GDPR).
- Portability of the data you have provided to us, in a structured and machine-readable format, where technically possible (Art. 20 GDPR).
- Withdrawal of consent at any time, where a processing is (exceptionally) based on consent, without affecting the lawfulness of the processing carried out before the withdrawal (Art. 7.3 GDPR). The ordinary processing operations of the site are not based on consent; this right is relevant only for any specific consents given separately (e.g. subscription to a future newsletter).
Right specific to the nLPD (for CH data subjects):
- Right to the handing over or transmission of data (Art. 28 nLPD), analogous to GDPR portability.
To exercise your rights, write to [email protected]. We will respond without undue delay and in any case within 30 days (GDPR, extendable by a further 60 days in complex cases, with notice); under the nLPD, as a rule, within 30 days. We may ask you to verify your identity before following up on the request.
10. Automated decision-making and profiling
Atenek does not carry out any automated decision-making, including profiling, that produces legal effects or similarly significantly affects you (Art. 22 GDPR; Art. 21 nLPD). The site does not profile visitors.
11. Data security
We adopt adequate technical and organizational measures (Art. 32 GDPR; Art. 8 nLPD and its ordinance) to protect the data from unauthorized access, loss or unlawful processing: encrypted HTTPS/TLS transmission, controlled self-hosted infrastructure, access limited to authorized staff, anti-spam systems (honeypot).
12. Complaint to the supervisory authority
If you believe that the processing of your data violates the legislation, you may contact the competent authority:
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC/PFPDT) — Feldeggweg 1, 3003 Bern — www.edoeb.admin.ch
- Italy: Garante per la protezione dei dati personali — Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it
- In other EU States: the supervisory authority of your State of residence.
13. Cookies
For information on cookies and consent management, consult the Cookie Policy. You can change your preferences at any time through the "Manage consent" link in the footer.
14. Changes to this information notice
We may update this notice to adapt it to regulatory changes or to our services. The current version is always published on this page, with an indication of the update date and version number. We invite you to consult it periodically.