Privacy policy
Last updated: 30 September 2026
We take the protection of your personal data seriously and process it in accordance with the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies, it applies as well. This page explains which data we process, when, why and for how long. The German version is authoritative.
1. Controller
web-wiiser — web design, hosting & domains
Switzerland
Contact: via the contact form
Contact us via the contact form (type “Other”) for any privacy question and to exercise your rights.
2. Scope
This policy applies to the website web-wiiser.ch, the customer area admin.web-wiiser.ch, the central login and study-wiiser (study.web-wiiser.ch or learn.web-wiiser.ch). Our customers are responsible for their own websites; their own privacy policies apply there.
3. Visiting the website
When you open our pages, the web server processes technically necessary information: IP address, date and time, the address requested, the amount of data transferred, browser and operating system (server log files). This serves secure operation, troubleshooting and defence against attacks. Log files are not combined with other data and are kept only as long as needed for these purposes.
Fonts, images and software libraries are hosted on our own servers in Switzerland. Currently, no third-party content is loaded when you visit, and we do not use any third-party analytics or advertising services.
4. Contact form and support
When you write to us via the form, we process the details you provide: type of request, name, email, optionally company, phone and domain, your message and the details for the chosen type (e.g. scope, budget, number of mailboxes). We use them solely to answer your request and prepare a quote.
- The request is sent by email to our team; you receive a confirmation with a reference number.
- Support requests are also recorded as a ticket in our customer system and reported to our support team.
- To prevent abuse we store an irreversible hash of your IP address for one hour (at most five requests per hour).
The legal basis is your request or the preparation of a contract. The same applies if you email us directly.
5. Domain check and portfolio
For the domain check we query the public DNS for the name you enter. The name is not stored; to prevent abuse we briefly count requests per IP address.
In the portfolio we show websites we have built as embedded previews. Your browser loads each website directly from its domain. The privacy policy of the respective operator applies there; we do not measure anything in the preview.
6. Customer area and login
For the customer area we process your account data (username, name, email, optionally phone, company, address, profile picture), the websites assigned to you, support tickets, documents, invoices and payments. This is necessary to perform the contract; accounting records are kept as long as the law requires.
When you log in we set a session cookie. The session is bound to your device (IP network and a hash of the browser identifier) so that a stolen link does not work on another device. Failed login attempts are stored for 15 minutes to slow down password guessing. Passwords are stored only as a secure hash.
7. study-wiiser
study-wiiser is a study planner with social features (currently BETA). With an account we process:
- Account data and optional profile details (school, studies, career, linked social profiles, profile picture) — visible depending on your “public” or “private” setting. Organisation profiles are always public.
- Semesters, subjects, tasks, notes and timetable, groups, posts, comments and chat messages. Group content is visible to group members, public posts to all logged-in users.
- If you choose, calendar or email accounts (e.g. iCloud, Google, Microsoft/Outlook) to import your timetable. Credentials and keys are stored encrypted and used only for syncing. Data is exchanged between our server and the respective provider; the provider’s privacy policy applies there.
- If you choose, email reminders about deadlines and exams.
- For organisations and for operating the service, aggregated usage figures (e.g. views of a post). Breakdowns by audience are shown only from five people upwards; individuals cannot be identified.
The legal basis is the use of the service you choose by registering, or your consent for optional details and connections. You can have your account deleted at any time via “Request support”.
8. Hosting and email for customers
For our customers’ websites and mailboxes we process data on their behalf (as a processor). The servers are located in Switzerland. We access content and mailboxes only as far as necessary for operation, support or on the customer’s instructions; access to another person’s mailbox is logged and reported to its owner. We may use third-party AI services for this (section 12).
9. Cookies
Currently, we only set cookies that are necessary for the service to work:
| Cookie | Purpose | Duration |
|---|---|---|
auth_token | Login to the customer area and study-wiiser | 30 minutes to 30 days (“stay logged in”) |
ww_msg | Shows a contact-form message when JavaScript is off | 2 minutes |
PHPSESSID | Technical session in the customer area (form protection) | until you close the browser |
ww_site_lang | Chosen language of the public pages (German/English) | 1 year |
ww_lang | Language of the customer area (German/English) | 1 year |
lc_pub, lc_next, lc_invite, lc_flash, lc_lang | study-wiiser: form protection, return after login, group invitation, notices after saving, language | a few minutes to 7 days, language 1 year |
10. Visitor statistics
To see which pages are visited and how often, we evaluate the server log files (section 3) on our own servers in Switzerland. No cookies are set, no script is loaded and nothing is passed on to third parties.
- No IP address is stored in the statistics. Visits are counted with a key formed from the IP address and browser together with a random value that changes daily; the random value is deleted after three days. Individuals cannot be identified from it.
- From the IP address we only derive the approximate country, region and town — using a database on our own server. If it is not available, we take the country from the browser’s language setting.
- Log files containing IP addresses are deleted after 14 days, the aggregated figures after about two years.
11. Sending email (Brevo)
We send outgoing emails — such as contact form confirmations, support tickets, login and confirmation links, study-wiiser reminders and emails from the customer area and from mailboxes on domains we manage — via the Brevo service of Sendinblue SAS, Paris (France).
- For this, Brevo receives the email itself (sender, recipient, subject, content and attachments) and technical delivery details (time, delivery status, error messages from the receiving server).
- Brevo processes this data on our behalf and only for sending. According to Brevo, the data is stored in the European Union, which Swiss law recognises as providing adequate data protection.
- Incoming emails and the mailboxes themselves remain on our servers in Switzerland.
More information: Brevo privacy policy.
12. Third-party artificial intelligence
We reserve the right to process data for our services using AI services from third parties. Data may be transmitted to these providers, including abroad. You can object to this processing at any time (section 16).
13. Sharing and transfers abroad
We do not sell data. We share it only where necessary for our services — for example with our domain provider and the registries (when you request a domain), payment or accounting service providers, services you connect (study-wiiser), or where required by law. Our servers are in Switzerland. Data leaves Switzerland when sending email via Brevo (EU, section 11), for third-party AI services (section 12) and for connections you choose.
14. Retention
We keep data only as long as necessary for the purpose or required by law. Requests that do not lead to an order are deleted once they are settled and no follow-up questions are expected; contract and accounting records are kept for the statutory periods (usually ten years).
15. Security
All connections are encrypted (HTTPS). Passwords are stored only as hashes, credentials for connected accounts are encrypted. We make regular backups and keep our systems up to date.
16. Your rights
You can request information about your data at any time, have it corrected or deleted, object to its processing, withdraw consent and receive your data in a common format. Write to us via the contact form. You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where the GDPR applies, with a supervisory authority in the EU.
17. Changes
We update this policy when our services or the law change — for example if we introduce advertising or other third-party services. We do so before the change takes effect and ask for your consent where required. The version published here applies.