Legal
Privacy policy
This policy describes which personal data is processed when you visit pahldigital.ch or send an enquiry – in accordance with the revised Swiss Federal Act on Data Protection (FADP) and, for visitors from the European Economic Area, the GDPR.
Pahl Digital Art Owner: Adrian Pahl Seestrasse 34 8802 Kilchberg ZH Switzerland Email: hallo@pahldigital.ch WhatsApp: +41 79 868 75 16 Web: pahldigital.chAt a glance
- No cookies, no tracking, no analytics or advertising tools.
- No resources from third-party servers: fonts, graphics and scripts come from our own server.
- A single value in your browser storage: your light/dark choice, which we cannot read.
- The contact form processes only what you enter yourself – in order to answer your enquiry.
- Servers in Switzerland, administered and hardened by us.
That is why there is no cookie banner here: there is nothing for which we would need your consent. The details follow in the next sections.
Controller
The controller within the meaning of Art. 5 let. j FADP and Art. 4 no. 7 GDPR for the processing of personal data on this website is the sole proprietorship Pahl Digital Art, owner Adrian Pahl, Seestrasse 34, 8802 Kilchberg ZH, Switzerland. For privacy enquiries, contact the owner via the email address given above with the subject “Privacy”.
Principles
We process as little personal data as possible, for as short a time as necessary and only for the purposes stated here (data minimisation, storage limitation, purpose limitation, good faith). Sensitive personal data within the meaning of Art. 5 let. c FADP is not processed on this website – please do not submit such information through the contact form either.
Technical connection and security data
When you visit, your browser transmits technically necessary details, in particular the IP address, the time, the requested path and browser and TLS connection data. Without these details the server cannot deliver the page. We do not use them for audience measurement, profiling or advertising.
The website is designed for data-minimising logging: the web server keeps no access logs containing personal data. The operating system, firewall, abuse protection and the hosting provider's infrastructure may nevertheless process error or connection data for availability and security. To protect the contact form against automated mass submissions, the sender's network address is counted briefly – for at most one hour – in the server's memory; it is neither stored nor linked to the enquiry.
Browser storage
This website sets no cookies. Exactly one value is kept in your browser's LocalStorage: “pda-theme-v1”, your choice between the light and dark colour scheme. It is only written when you use the toggle, contains no personal data, is never transmitted to our server and can be deleted at any time through your browser's storage settings.
Contact form, email and WhatsApp
When you use the contact form, we process the details you enter: name, company (optional), email address, project type and message. The enquiry is stored in a protected area on our server and additionally delivered by email to the Pahl Digital Art mailbox. The website server sends it over encrypted connections wherever the receiving mail server supports them.
We use these details exclusively to answer your enquiry and for any collaboration that may follow. If you write to us directly by email, we receive the details contained in your message; they too are used only to reply.
If you contact us via WhatsApp, the conversation runs through the service of WhatsApp Ireland Limited (Meta). WhatsApp processes your phone number, timestamps and other metadata under its own privacy policy; message contents are end-to-end encrypted. We use WhatsApp only for the conversation you start yourself, keep no contact lists and do not pass your number on. If you prefer not to use WhatsApp, the form and email reach us just as well.
Purposes and legal bases
- Providing the website and securing the infrastructure – Art. 31 para. 1 FADP (overriding private interest) and Art. 6 para. 1 let. f GDPR (legitimate interest).
- Answering enquiries and initiating an engagement – Art. 6 para. 1 let. b GDPR (pre-contractual measures); under the FADP the principles of Art. 6 FADP apply.
- Meeting statutory retention obligations, for instance under Art. 958f of the Swiss Code of Obligations – Art. 6 para. 1 let. c GDPR.
Processors and recipients
The website runs on a server operated by FireStorm ISP GmbH, Kirchenrainstrasse 27, 8632 Tann ZH, Switzerland. The hosting provider supplies the underlying infrastructure and therefore has technical access to the machine; to that extent it is a processor within the meaning of Art. 9 FADP. We are responsible for the operating system, web server and configuration ourselves. The domain and name servers of pahldigital.ch are also held with FireStorm ISP GmbH; the technical query data arising there is neither received nor evaluated by us.
The email notification for an enquiry is delivered to the Pahl Digital Art mailbox, where it is stored on our behalf by the mailbox's email provider. Personal data is not passed on to any other third parties unless we are legally obliged to do so.
Transfers abroad
We obtain hosting, domain and name resolution from a Swiss provider, and the website loads no resources from third-party servers. When you open an external link – such as the WhatsApp link – your browser connects to the respective provider. If you contact us via WhatsApp, data may reach Meta in the USA; Meta is certified under the Swiss-U.S. Data Privacy Framework. Where a provider's technical subcontractors transfer data to a country without an adequate level of data protection, the safeguards required under Art. 16 FADP and Art. 46 GDPR apply.
Retention
- Enquiries: until they have been dealt with conclusively and for at most twelve months thereafter, unless a business relationship arises. Business-relevant correspondence is retained for ten years in accordance with Art. 958f of the Swiss Code of Obligations.
- Technical operating and security data: only as long as required for operation, fault analysis or abuse protection.
- Browser storage: remains in your browser until you delete it.
Your rights
You have the right to information (Art. 25 FADP / Art. 15 GDPR), rectification (Art. 32 FADP / Art. 16 GDPR), erasure (Art. 32 FADP / Art. 17 GDPR) and data portability (Art. 28 FADP / Art. 20 GDPR) and – for data subjects in the European Economic Area – to restriction of processing and objection (Art. 18 and 21 GDPR). Please use the email address given above; we may request reasonable proof of identity (Art. 16 para. 5 DPO).
Complaints can be addressed to the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland. Data subjects residing in the EEA may additionally contact the supervisory authority of their country of residence.
Data security
All connections are encrypted with HTTPS (TLS 1.2 or newer) and enforced through HSTS. A strict Content Security Policy prevents third-party scripts from being loaded. The web service runs with minimal privileges in an isolated system environment; enquiries are stored in an area readable only by the service. We thereby take appropriate technical and organisational measures under Art. 8 FADP and Art. 32 GDPR.
No automated decisions
This website performs neither profiling nor automated individual decision-making within the meaning of Art. 21 FADP or Art. 22 GDPR. All visitors receive the same content.
Applicable law and changes
Swiss law applies. We update this privacy policy when the website or the legal requirements change; the version published here is authoritative.
Last updated: September 2026