Privacy Policy

Version effective as of April 9, 2026

With this Privacy Policy we, Datanalytico Feye (hereinafter "Datanalytico", "we" or "us"), describe how we collect and further process personal data. This Privacy Policy is aligned with the EU General Data Protection Regulation (GDPR), the Swiss Data Protection Act (DPA) and the revised Swiss Data Protection Act (revDPA). However, the application of these laws depends on each individual case.

1. Controller

The controller of data processing as described in this Privacy Policy is:

Datanalytico Feye
Langegasse 117
4104 Oberwil
Switzerland

Phone: +41 76 757 64 23
Email: [email protected]
Website: https://datanalytico.com/

You can notify us of any data protection related concerns using the contact details above.

2. Collection and Processing of Personal Data

We primarily process personal data that we obtain from our users and customers in the context of our business relationships, or that we collect when operating our website and applications. The categories of data we process include:

  • Account data: name, email address, password (encrypted)
  • Usage data: IP address, browser type, device information, date and time of access, pages viewed
  • Payment data: processed by Stripe (we do not store credit card numbers)
  • Scan data: URLs submitted for analysis, scan results, AISO Score dimensions
  • Monitoring data: brand domains, monitoring configurations, alert preferences
  • Communication data: email correspondence, support requests

3. Purpose of Data Processing and Legal Grounds

We primarily use collected data in order to provide our AISO Score, AI Monitoring, and AI Optimizer services. In addition, we process your personal data for the following purposes:

  • Providing and developing our products, services and website
  • Processing your service requests and delivering scan results
  • Managing your account and subscriptions
  • Sending transactional emails (scan results, monitoring alerts)
  • Ensuring the security and stability of our systems
  • Compliance with legal obligations
  • Analytics and improvement of our services (with your consent)

If you have given us your consent to process your personal data for certain purposes (for example when accepting analytics cookies), we process your personal data based on this consent. Consent given can be withdrawn at any time, but this does not affect data processed prior to withdrawal.

4. Cookies and Tracking

We use cookies and similar technologies on our website. A cookie is a small text file that is sent to your computer and automatically saved by your web browser. You may configure your browser settings to reject cookies, only save them for one session, or delete them prematurely.

Strictly necessary cookies

These cookies are essential for the website to function and cannot be disabled:

NameProviderDurationPurpose
cookie_consentDatanalytico1 yearStores your cookie consent preference
next-auth.session-tokenDatanalyticoSessionAuthentication session for logged-in users
NEXT_LOCALEDatanalytico1 yearStores your language preference (EN/DE)

Analytics cookies (with consent only)

We use Google Analytics 4 (GA4) with Google Consent Mode v2 to measure and evaluate the use of our website. These cookies are only set after you give your explicit consent via our cookie consent banner.

NameProviderDurationPurpose
_ga, _ga_*Google2 yearsGoogle Analytics 4 — audience measurement and usage analysis

Google Analytics 4 uses IP anonymization by default. Further information about data protection at Google can be found at: https://policies.google.com/privacy

5. Data Transfer and Transfer Abroad

In the context of our business activities, we may transfer data to third parties insofar as such a transfer is permitted and appropriate. The following categories of recipients may be concerned:

  • Google Cloud Platform (hosting, EU region europe-west6, Zurich) — database and application hosting
  • Stripe, Inc. (USA) — payment processing for subscriptions
  • Resend, Inc. (USA) — transactional email delivery (scan results, monitoring alerts)
  • Google Ireland Ltd. / Google LLC (Ireland/USA) — website analytics via Google Analytics 4
  • Cloudflare, Inc. (USA) — CDN, DNS and DDoS protection

If a recipient is located in a country without adequate statutory data protection, we require the recipient to comply with data protection by means of the European Commission's standard contractual clauses or other legally accepted mechanisms.

6. Retention Periods

We process and retain your personal data as long as required for the performance of our contractual obligations and compliance with legal obligations. In particular:

  • Account data: retained for the duration of your account, deleted upon account deletion
  • Scan results: retained for 12 months
  • Monitoring snapshots: retained for 90 days, then automatically deleted
  • Server logs: retained for a maximum of 30 days
  • Payment records: retained as required by Swiss commercial law (up to 10 years)

As soon as your personal data are no longer required for the above-mentioned purposes, they will be deleted or anonymized to the extent possible.

7. Data Security

We have taken appropriate technical and organizational security measures to protect your personal data from unauthorized access and misuse, including: encrypted data transmission (TLS/SSL), encrypted password storage, access controls and restrictions, regular security updates, and data processing within Google Cloud's certified infrastructure.

8. Your Rights

In accordance with applicable law, you have the following rights:

  • The right to access your personal data and receive information about our processing
  • The right to rectification of inaccurate personal data
  • The right to erasure of your personal data
  • The right to restriction of processing
  • The right to data portability (receive your data in a machine-readable format)
  • The right to object to our data processing, in particular for direct marketing purposes

Please note that we reserve the right to enforce statutory restrictions on our part, for example if we are obliged to retain certain data or have an overriding interest.

In order to assert these rights, please contact us at [email protected].

In addition, you have the right to lodge a complaint with the competent data protection authority. The competent data protection authority of Switzerland is the Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch

9. Amendments

We may amend this Privacy Policy at any time without prior notice. The current version published on our website shall apply.