Privacy Statement

I take your privacy seriously. This statement explains what personal data this website collects, why, and how it is handled, in line with the EU General Data Protection Regulation (GDPR)and the Swiss Federal Act on Data Protection (FADP).

Who is responsible

The data controller for this website is:

Sanne Wendes, trading as Sanne Wendes Advisory

Geneva, Switzerland

Email: sanne@wendes.ch

Note: Sanne Wendes Advisory is a trading name. The legal controller is Sanne Wendes as a natural person, resident in Switzerland. This statement will be updated when the entity is formally registered.

What this website collects

Simply visiting this website does not require you to provide any personal data. There are no contact formsor user accounts.

Our hosting provider (Infomaniak Network AG, Switzerland) automatically logs basic technical information for security and stability purposes, including:

•    your IP address;

•    the date, time, and pages requested;

•    your browser and operating system.

This website does not currently use analytics tools or tracking cookies. If you contact me directly by email, I will hold your contact details and the content of your message for as long as there is a legitimate business purpose to do so.

If you would like your data removed at any point, simply let me know at sanne@wendes.ch.

Why we use it and on what basis

Server log data is used solely to keep the website available, secure, and running reliably. The legal basis under the GDPR is Art. 6(1)(f) — legitimate interest in the secure and stable operation of the site. Under the FADP, this processing is grounded in are cognisable and proportionate purpose (Art. 6 FADP), justified by an overriding private interest in site security (Art. 31(1) FADP).

I do not sell your data, share it with advertisers, or use it for profiling of any kind.

How long data is kept

Server logs are kept by Infomaniak for a limited period (typically up to 90 days) and then deleted,unless a specific security incident requires otherwise. (GDPR Art. 5(1)(e); FADP Art. 6(4).)

Email correspondence is retained for as long as there is a legitimate business purpose, including any ongoingclient relationship, and in line with applicable record-keeping obligations.Under Swiss law, business correspondence with contractual relevance is generally subject to a 10-year retention obligation (Swiss Code of Obligations,Art. 958f). Enquiries that do not lead to an engagement are deleted when no longer relevant.

Who has access

Server log data is accessible only to Infomaniak Network AG as hosting provider, acting under their own data protection obligations. Infomaniak is headquartered in Geneva, Switzerland, and stores data on servers in Switzerland. No transfer of personal data outside Switzerland or the EEA takes place in connection with website hosting.

Email correspondence sent to me is processed via Microsoft Outlook (Microsoft 365), provided by Microsoft Ireland Operations Limited, Ireland. Microsoft acts as a data processor under their Data Protection Agreement and applicable Standard Contractual Clauses.Microsoft’s privacy practices are described in their Privacy Statement.Data processed through Microsoft 365 may be stored within the EEA or transferred under appropriate safeguards in accordance with Chapter V GDPR and Art. 16 FADP.

Cookies

This website does not use tracking or analytics cookies. The only cookies that may be set are strictly necessary technical cookies placed by the hosting infrastructure. No consent is required for these under the EU ePrivacy Directive.

If analytics are added in future (for example, via Plausible Analytics), this statement will be updated accordingly before any such tools are activated.

Your rights

Under the GDPR (Arts. 15–21) and the FADP (Art. 25), you have the right to:

•    request access to personal data held about you;

•    ask for it to be corrected, restricted, or deleted;

•    object to processing based on legitimate interest;

•    request that data be transferred to another party (data portability).

To exercise any of these rights,contact me at sanne@wendes.ch. I will respond in a clear and timely manner, as required under GDPR Art. 12(1).

If you believe your data has not been handled correctly, you may lodge a complaint with a supervisory authority— in the EU with the authority in your country of residence, or in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch.

Changes to this statement

I may update this statement from time to time, for example when analytics are added to the site. The date at the top shows when it was last revised.