Legal

Privacy notice.

Last updated 2 September 2026. This notice explains what personal data we collect on dfensio.com, why, and what your rights are.

1. Controller

The controller is Obsidian Technologies, Switzerland, operator of Dfensio. Contact for data protection matters: contact@dfensio.com. We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable to visitors in the European Economic Area and the United Kingdom, the GDPR and UK GDPR.

2. What we collect and why

ContextDataPurpose and legal basisRetention
Briefing request formName, work email, company (unless you choose the anonymous option), role, phone, countries and domains of interest, message, IP address, timestampAnswering your request and preparing a briefing proposal — pre-contractual steps and our legitimate interest in responding to enquiries24 months after our last exchange, or the duration of the contract plus statutory retention
Contact formName, work email, company, phone, subject, message, IP address, timestampAnswering your message — legitimate interest24 months after our last exchange
NewsletterEmail, company (optional), domains of interest, IP address, timestampSending the weekly dispatch and the quarterly report — your consent, withdrawable at any time via the unsubscribe linkUntil you unsubscribe, then a suppression record
Server logsIP address, user agent, requested pages, timestampsSecurity, abuse prevention, rate limiting — legitimate interest30 days
AnalyticsPseudonymous usage data (pages, device, approximate location with IP anonymisation)Measuring audience and improving the Site — legitimate interest; advertising storage is disabled by defaultPer provider settings, maximum 14 months

Form submissions are stored as records on our own servers hosted in the European Union and forwarded to our mailbox. We do not use form data for advertising, and we do not sell or rent personal data.

3. Anonymous requests

If you tick the anonymous option on the briefing form, we do not record your company name and we require a phone number to verify the request. The other data you supply is processed as described above.

4. Anti-automation measures

Our forms use a proof-of-work challenge executed in your browser, a hidden honeypot field and per-network rate limiting. These measures process technical data (challenge tokens, IP address) solely to detect automated abuse. No third-party CAPTCHA service is used.

5. Processors and recipients

  • Transactional email: Brevo (Sendinblue SAS, France) transmits form notifications and newsletters. Data is processed in the European Union.
  • Hosting: our servers are located in the European Union; DNS and mailbox services are provided by Infomaniak (Switzerland).
  • Analytics and advertising measurement: Google Analytics 4 and Google Ads conversion measurement (Google Ireland Ltd) may be enabled with IP anonymisation and advertising storage denied by default. Google may transfer data outside Switzerland and the EEA under standard contractual clauses.

We do not disclose the identity of subscribers or the content of requests to any other party, except where required by law.

6. Cookies

The Site sets a language preference cookie when you change language and, if analytics are enabled, the cookies used by Google Analytics. No advertising cookies are set without your consent. You can block cookies in your browser; the Site remains fully usable.

7. International transfers

Where data leaves Switzerland or the EEA (for example to Google), we rely on adequacy decisions or standard contractual clauses recognised by the Swiss Federal Data Protection and Information Commissioner and the European Commission.

8. Your rights

You may request access to, rectification or erasure of your personal data, restriction of or objection to its processing, and portability, and you may withdraw consent at any time. Write to contact@dfensio.com. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner or your local supervisory authority.

9. Security

Data is transmitted over TLS, stored on access-controlled servers, and handled only by personnel bound by confidentiality. Form records are kept in append-only files with restricted permissions and are not exposed through any web interface.

10. Changes

We may update this notice. The date at the top indicates the current version.