DATA PROTECTION
Data protection policy
This page explains which personal data we process, why, with whom it is shared and what you can demand from us. It was drawn up on 20 August 2026 and carries version 1.0.
Who is responsible for your data
The law requires saying clearly who decides on the processing. With us, the answer fits in one line, and there is no intermediary.
The controller
LYVIA SNC, Kleinschönberg 10, 1700 Fribourg, Switzerland, IDE CHE-433.051.153, is the controller for the processing of personal data described in this policy, within the meaning of the Swiss Federal Act on Data Protection and, where it applies, of the European Union's General Data Protection Regulation. Any question about this policy may be sent to office@lyvia.swiss.
We have not appointed a data protection adviser
The appointment of a data protection adviser provided for in art. 10 FADP is optional for a private company. We have not appointed one. Requests are handled directly by LYVIA's management, at the address indicated above.
The record of processing activities
Art. 12 para. 5 FADP, specified by art. 24 of the Data Protection Ordinance, exempts private companies with fewer than two hundred and fifty employees from keeping a record of processing activities, provided their processing does not entail a high risk. We meet these conditions to date. This exemption does not exempt us from knowing what we process, and this page describes all the processing we carry out for our own account.
The data we process, channel by channel
Rather than a general list, we describe each situation in which data about you may reach us, with the purpose that justifies it.
Simply visiting the site
When you open a page of lyvia.swiss, our host technically records your IP address, the date and time of the request, the page requested, the server's response code, the volume transferred, and the browser and operating system type. These logs serve exclusively to keep the site running, diagnose a failure and detect an attempted abuse. We do not use them to compile audience statistics, to identify you, or to send you any message.
The contact form
The form sends us your name, your email address, your company's name, your phone number if you choose to give it, the size of your team, the tools you use and the description of your situation. This information lets us understand your request, reply to you and prepare a possible diagnostic. The description field is free text, and we recommend not including sensitive data or information covered by professional secrecy.
Exchanges by email and phone
When you write to us or call us, we keep the content of the exchange, your contact details and the notes we take, in order to follow up the relationship and keep a record of what was agreed. We do not record phone calls.
The contractual relationship
If a collaboration takes shape, we process the data needed for its performance and invoicing, in particular the identity and contact details of the contact persons, information about the services, invoicing and payment data, and the exchanges linked to the engagement. This processing is essential to performing the contract and keeping our accounts.
The company search
Our site offers a tool that queries the central Zefix index of company names. The query leaves from our server and not from your browser, which means your IP address is not communicated to the register's operator. We transmit only the term searched. The results displayed come from a public register and we do not keep them beyond the time of display, apart from the technical logs mentioned above.
Unsolicited applications
If you send us an application file, we process the data it contains for the sole purpose of assessing your profile. We keep the file for six months after the process closes, then delete it, unless you expressly authorise us to keep it longer.
The legal basis we rely on
Swiss law and European law do not approach this question the same way. We set out both, because our site can be consulted from the European Union.
Under Swiss law
The Federal Act on Data Protection does not require a prior legal basis for a private person to process personal data. It does, however, require compliance with the principles of art. 6 FADP, namely lawfulness, good faith, proportionality, recognisability, defined purpose and accuracy of the data. Our processing relates to the performance or preparation of a contract, and to our overriding interests in running our site and securing our infrastructure, within the meaning of art. 30 and 31 FADP.
Under the European regulation
For a visitor located in the European Union, the processing of form data and preliminary exchanges rests on art. 6 para. 1 let. b GDPR, which covers pre-contractual measures taken at the person's request, then on that same provision for the performance of the contract. The technical server logs rest on legitimate interest within the meaning of art. 6 para. 1 let. f GDPR, which consists in ensuring the site's availability and security. The retention of accounting documents rests on the legal obligation within the meaning of art. 6 para. 1 let. c GDPR combined with Swiss law.
Consent
We currently seek no consent, because none of our processing depends on it. If we one day activate a service that requires it, in particular audience measurement or the sending of commercial information, we will ask for it explicitly, separately and revocably, and we will update this page before activation.
Who else sees your data
We sell no data, we rent none and we exchange none for advertising purposes. Some data does, however, pass through providers we name here.
Infomaniak Network SA
The hosting of the site and of our mail is provided by Infomaniak Network SA, in Geneva. This company acts as a processor and processes the data on infrastructure located in Switzerland. It has access to the technical server logs and to the emails passing through its systems, strictly to the extent of operating the service.
The fonts
The fonts are served from our own server, in Switzerland, like the rest of the site. Your browser makes no connection to Google or to any other provider in order to download them, and no data concerning you is transmitted for that purpose.
The operator of the Zefix register
Company searches carried out on our site leave from our server. The search term is transmitted to the infrastructure operating the central index of company names, without your IP address and without any data identifying you.
Other recipients
We may communicate data to our fiduciary and to our professional advisers, bound to secrecy, to the extent necessary for keeping our accounts and defending our rights, and to the authorities when the law or a ruling obliges us to. No other communication takes place without your agreement.
A point we want to state honestly
We have not yet replaced the loading of Google fonts with local hosting, which would be the most protective solution. We have identified it and plan to do it. As long as it is not done, we write it here rather than keep quiet about it.
Transfers outside Switzerland
Communicating personal data abroad obeys precise rules, and we must tell you where your data may go.
The applicable principle
Under art. 16 FADP, personal data may be communicated abroad only if the state concerned ensures adequate protection, recognised by the Federal Council, or if one of the safeguards provided by law is in place. Art. 17 FADP further provides derogations, in particular when the communication is essential to the performance of a contract.
What concerns you concretely
The hosting of the site and of our mail takes place in Switzerland. The only structural transfer outside Switzerland results from loading the fonts from Google's servers, which connects your browser with infrastructure established in Ireland that may involve servers in the United States. The European Commission and the Federal Council have recognised adequate protection for the United States under the data protection framework applicable to certified companies, and Google additionally relies on standard contractual clauses.
When an engagement involves other countries
If performing an engagement requires using software or a provider established outside Switzerland, we inform the client before implementation, with the country concerned and the basis of the transfer. The decision to accept that configuration is theirs.
How long we keep your data
We delete what we no longer need. Here are the durations we apply.
The technical server logs
They are kept by our host for a short period, in the order of a few weeks, then erased automatically. They are consulted only in the event of an incident or suspected abuse.
Requests that led nowhere
Messages received through the form or by email that do not lead to any collaboration are kept for twenty-four months, so that the thread of a discussion resumed later can be found, then deleted.
Client files
Data linked to a contractual relationship is kept for the duration of the engagement, then for ten years after its end. This duration corresponds to the ordinary limitation period of art. 127 of the Swiss Code of Obligations and to the obligation to keep the books and accounting records provided by Swiss law.
The data we process for a client
When we access personal data located in a client's systems, we do not keep it beyond what the service requires. At the end of the engagement, this data is returned or destroyed according to the client's written instructions.
How we protect this data
Art. 8 FADP requires technical and organisational measures appropriate to the risk. We describe what we do, without claiming an absolute security no one can promise.
The measures in place
The site is served exclusively over an encrypted connection. Access to our business accounts is protected by two-factor authentication and by unique passwords kept in a dedicated manager. Access to our clients' systems is limited to what is necessary, nominative where possible, and revoked at the end of an engagement. Our workstations are encrypted and kept up to date.
In the event of a security breach
If a breach of data security entails a high risk for the persons concerned, we notify the Federal Data Protection and Information Commissioner as promptly as possible, in accordance with art. 24 FADP, and we inform the persons concerned when the law requires it or when it allows them to protect themselves. Where the GDPR applies, we comply with the deadlines and terms it provides.
What we cannot guarantee
No transmission over the Internet and no computer system can be held inviolable. We implement proportionate measures and review them, without being able to rule out that a breach occurs despite them.
Your rights and how to exercise them
The law gives you concrete rights over the data concerning you. We respond to them without requiring a reason and without charging anything in ordinary cases.
The right of access
Art. 25 FADP allows you to ask whether we process data concerning you and, if so, to obtain its communication as well as the information necessary to assert your rights. We reply in principle within thirty days. This right is free of charge, except in the exceptional cases provided by the ordinance.
Rectification, erasure and objection
You may demand that inaccurate data be corrected and, under the conditions of art. 30 to 32 FADP, that the processing cease, that the data be erased or destroyed, or that its communication to third parties be prohibited. We grant these requests when no justifying ground and no legal retention obligation stands in the way, and we then explain to you precisely which one does.
Release and transmission of your data
Art. 28 FADP allows you, under the conditions it sets, to obtain the data you have communicated to us in a common electronic format, or to ask for its transmission to a third party.
If the European regulation applies to you
You then have the rights of access, rectification, erasure, restriction, portability and objection provided in art. 15 to 21 GDPR, as well as the right to withdraw consent at any time without affecting the lawfulness of prior processing. You also have the right to lodge a complaint with a supervisory authority within the meaning of art. 77 GDPR.
How to reach us
Write to office@lyvia.swiss or to LYVIA SNC, Kleinschönberg 10, 1700 Fribourg, Switzerland, describing your request. We may ask for an element allowing us to verify your identity, only when necessary to avoid handing your data to someone else, and we do not keep that element beyond the verification.
Cookies, audience measurement and advertising
This section is short because the situation is simple, and we undertake to update it before it changes.
No tracking cookie to date
The lyvia.swiss site sets no tracking cookie, no advertising cookie and no audience-measurement cookie. It uses neither Google Analytics, nor social network pixels, nor profiling tools. That is why you meet no consent window when arriving on the site.
What the site may use
Only mechanisms strictly necessary for the site's operation may be used, for example to remember a display choice or to protect a form against automated submissions. These elements serve neither to identify you nor to follow you from one site to another.
Our commitment if this were to change
If we one day decide to activate audience measurement or any other processing subject to consent, we will put in place the required information and consent mechanism, and we will update this page before activation and not after.
The do-not-track signal
As we practise no tracking, the refusal signal emitted by some browsers has nothing to deactivate with us. We would respect it if we were one day to introduce such processing.
Supervisory authority, European visitors and updates
A few institutional details, including one many sites prefer to keep quiet.
The Swiss authority
The competent supervisory authority is the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern. Anyone who considers that we process their data unlawfully may refer the matter to him, independently of the step they take with us.
Visitors from the European Union
We are established in Switzerland and address our services to Swiss companies. The European regulation nevertheless applies to processing when the conditions of its art. 3 are met, in particular if we offer goods or services to persons located in the Union or monitor their behaviour. We do not target that market, we practise no behavioural monitoring, and we have therefore designated no representative in the Union.
Why we say it this way
We prefer to describe our real situation rather than display a conformity we could not demonstrate. Art. 27 para. 2 let. a GDPR exempts from designating a representative processing that is occasional, does not involve sensitive data on a large scale and presents no risk for the persons. We consider we meet these conditions. If our activity evolved towards an offering directed at the Union, we would make the required designation and state it here.
Changes to this policy
We adapt this page when our processing changes. The version in force is the one published on lyvia.swiss, with its date and version number. A substantial change is signalled visibly on the site, and we invite you to consult this page before sending us information if you have not done so for a long time.
Frequently asked questions
What we are asked
Do you use Google Analytics or another measurement tool?
No, none to date. We therefore do not know how many people visit our site nor where they come from, and that is a deliberate choice. If we change our mind, we will put in place proper consent and update this page before activation.
Why is there no cookie banner on your site?
Because there is nothing to consent to. We set no tracking, advertising or statistics cookie. A banner that serves no purpose informs no one; it annoys everyone.
Does my data leave Switzerland?
The hosting of the site and mail is in Switzerland, with Infomaniak in Geneva. The fonts are served from our own server: there is no structural flow abroad any more. Audience measurement loads only after your consent; as long as you have not given it, nothing goes to Google.
How do I obtain the list of data you hold about me?
Write to office@lyvia.swiss with an access request. We reply in principle within thirty days, free of charge, and state the data processed, its purposes, its retention period and any recipients. We may ask you to prove your identity if the doubt is real, so as not to hand your data to someone else.
May I write confidential information in the form?
We advise against it for a first contact. Describe your situation in general terms; that is amply sufficient to prepare an exchange. Sensitive information will find its place once the collaboration has begun, in a suitable channel we will agree with you.
Do you have a representative in the European Union?
No, and we write it rather than let the contrary be assumed. We are established in Switzerland, we do not direct our offering at the European market and we monitor no one's behaviour. Art. 27 para. 2 let. a GDPR exempts from this designation in such a situation. If our activity evolved, we would make the designation and mention it here.
A question about your data
An access request, a correction, a deletion or simple curiosity about a point on this page. Write to us; a human reads and replies, with no five-step form to fill in.
Write to usThe sources for this page
- Zefix, the central business name indexLYVIA SNC’s commercial register entry, freely consultable, checked on 25.08.2026
- Swiss Federal Act on Data ProtectionThe text in force, in the Classified Compilation of Federal Law, read on 25.08.2026