Legal
Privacy notice.
Last updated 2 September 2026. This notice explains what personal data we collect on dfensio.com, why, and what your rights are.
1. Controller
The controller is Obsidian Technologies, Switzerland, operator of Dfensio. Contact for data protection matters: contact@dfensio.com. We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable to visitors in the European Economic Area and the United Kingdom, the GDPR and UK GDPR.
2. What we collect and why
| Context | Data | Purpose and legal basis | Retention |
|---|---|---|---|
| Briefing request form | Name, work email, company (unless you choose the anonymous option), role, phone, countries and domains of interest, message, IP address, timestamp | Answering your request and preparing a briefing proposal — pre-contractual steps and our legitimate interest in responding to enquiries | 24 months after our last exchange, or the duration of the contract plus statutory retention |
| Contact form | Name, work email, company, phone, subject, message, IP address, timestamp | Answering your message — legitimate interest | 24 months after our last exchange |
| Newsletter | Email, company (optional), domains of interest, IP address, timestamp | Sending the weekly dispatch and the quarterly report — your consent, withdrawable at any time via the unsubscribe link | Until you unsubscribe, then a suppression record |
| Server logs | IP address, user agent, requested pages, timestamps | Security, abuse prevention, rate limiting — legitimate interest | 30 days |
| Analytics | Pseudonymous usage data (pages, device, approximate location with IP anonymisation) | Measuring audience and improving the Site — legitimate interest; advertising storage is disabled by default | Per provider settings, maximum 14 months |
Form submissions are stored as records on our own servers hosted in the European Union and forwarded to our mailbox. We do not use form data for advertising, and we do not sell or rent personal data.
3. Anonymous requests
If you tick the anonymous option on the briefing form, we do not record your company name and we require a phone number to verify the request. The other data you supply is processed as described above.
4. Anti-automation measures
Our forms use a proof-of-work challenge executed in your browser, a hidden honeypot field and per-network rate limiting. These measures process technical data (challenge tokens, IP address) solely to detect automated abuse. No third-party CAPTCHA service is used.
5. Processors and recipients
- Transactional email: Brevo (Sendinblue SAS, France) transmits form notifications and newsletters. Data is processed in the European Union.
- Hosting: our servers are located in the European Union; DNS and mailbox services are provided by Infomaniak (Switzerland).
- Analytics and advertising measurement: Google Analytics 4 and Google Ads conversion measurement (Google Ireland Ltd) may be enabled with IP anonymisation and advertising storage denied by default. Google may transfer data outside Switzerland and the EEA under standard contractual clauses.
We do not disclose the identity of subscribers or the content of requests to any other party, except where required by law.
6. Cookies
The Site sets a language preference cookie when you change language and, if analytics are enabled, the cookies used by Google Analytics. No advertising cookies are set without your consent. You can block cookies in your browser; the Site remains fully usable.
7. International transfers
Where data leaves Switzerland or the EEA (for example to Google), we rely on adequacy decisions or standard contractual clauses recognised by the Swiss Federal Data Protection and Information Commissioner and the European Commission.
8. Your rights
You may request access to, rectification or erasure of your personal data, restriction of or objection to its processing, and portability, and you may withdraw consent at any time. Write to contact@dfensio.com. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner or your local supervisory authority.
9. Security
Data is transmitted over TLS, stored on access-controlled servers, and handled only by personnel bound by confidentiality. Form records are kept in append-only files with restricted permissions and are not exposed through any web interface.
10. Changes
We may update this notice. The date at the top indicates the current version.