Privacy policy
Last updated: 28 August 2026
This policy sets out what personal data we process when you use aeternum.so,
why we process it, and what rights you have. It follows the revised Swiss Federal
Act on Data Protection (revDSG), in force since 1 September 2023.
1. Who is responsible
Nino Meier and Leonardo Ciccone are jointly the controllers within the meaning of Art. 5(j) revDSG. Contact details are in the legal notice. For anything to do with data protection, an email to hello@aeternum.so is enough.
We have not appointed a data protection advisor under Art. 10 revDSG. For a business of this size and this volume of processing that is voluntary and not required.
2. The short version
We collect as little as we can. This website uses no analytics or tracking, builds no profiles and sets no tracking or advertising cookies. Fonts are bundled at build time and served from our own domain.
The one exception is the contact form: to protect it against spam and abuse we
embed Cloudflare Turnstile. Turnstile loads a script from Cloudflare and may
set a short-lived security cookie (cf_clearance) that serves neither
advertising nor tracking (section 4.1). That is also why there is still no
cookie banner here: there is nothing to consent to.
3. Server logs
The site is hosted by Vercel Inc. Every request causes Vercel to process technically necessary connection data:
- the IP address of the requesting device
- the date and time of the request
- the URL requested and the HTTP status code
- the volume of data transferred
- the user agent (browser and operating system identifier)
- the referrer URL, where the browser sends one
Purpose: serving the site, operational security, abuse prevention and debugging. This processing is technically unavoidable in operating a website and rests on our overriding interest in a secure, working service (Art. 31(1) revDSG).
Retention: we do not systematically evaluate these logs and do not combine them with other data. Vercel deletes them according to its own retention periods; we keep no copy of our own.
4. The contact form
When you submit the contact form, we process what you type into it:
- name
- email address (required — without it we cannot reply)
- agency or company
- your project description in the free-text field
- the language you filled the form out in
Purpose: to answer your enquiry and, if it turns into a project, to prepare the engagement. The basis is processing carried out at your own initiative with a view to a possible contract.
Transmission: delivery runs through Resend. The message arrives as an email in our inbox, with your address set as the reply-to.
Retention: enquiries stay in our inbox for as long as they are commercially relevant. Enquiries that do not lead to a project are deleted no later than twelve months after the last contact. Where a contract results, the ten-year commercial retention period applies (Art. 958f OR).
4.1 Spam protection
Three checks run alongside the form to keep bots out. We disclose them here because they process data too:
- Rate limiting. Your IP address is held in the serverless function’s memory for 60 seconds in order to reject more than five submissions per minute. It is never written to disk, never stored with your message, and expires when the window closes or the function next restarts.
- Timing check. We measure how long passes between the page rendering and the form being submitted. A submission faster than a human could type is discarded.
- Honeypot. The form contains a field that is invisible to you. If it comes back filled in, the submission is discarded.
- Bot check (Cloudflare Turnstile). When the form is submitted, Cloudflare
Turnstile runs a check. Your browser loads a script from Cloudflare, and
Cloudflare processes technical data — IP address, browser and device
information — to tell humans from bots. Once the check is passed, a
short-lived security cookie (
cf_clearance) may be set. This data serves abuse protection only and is never used for advertising. The provider is Cloudflare Inc. (section 5). Cloudflare requires a reference to the Turnstile Privacy Addendum for use in invisible mode.
These checks build no profile and serve only to block automated abuse.
5. Processors and transfers abroad
We pass personal data only to the service providers below, and only as far as operating the site requires. All process data on our behalf and are contractually bound by our instructions (Art. 9 revDSG).
| Service | Purpose | Location |
|---|---|---|
| Vercel Inc. | Hosting, delivery, server logs | USA, served via European edge locations |
| Resend | Delivery of contact-form email | USA |
| Cloudflare Inc. | Bot protection for the form (Turnstile) | USA |
All three providers are based in the United States. The transfer rests on the recognition of the USA as providing adequate protection for organisations certified under the Swiss-U.S. Data Privacy Framework, and additionally on standard contractual clauses under Art. 16(2)(d) revDSG. We do not sell data and do not disclose it to third parties for any other purpose. We disclose data to authorities only where legally obliged to.
6. Security
The site is served over TLS only; unencrypted requests are redirected. Form input is capped at plausible lengths before it is processed. Service credentials live in environment variables, not in the source code.
Even so, transmission over the internet can never be entirely secure. Please do not send us sensitive personal data (Art. 5(c) revDSG) or any credentials through the form.
7. Your rights
Under the revDSG you have the right to:
- access — whether and what personal data we process about you (Art. 25)
- rectification of inaccurate data (Art. 32(1))
- erasure or destruction of your data (Art. 32(2)(c))
- data portability — release or transfer in a common electronic format (Art. 28)
- object to processing that rests on our own interest
An email to hello@aeternum.so is enough. We reply free of charge, normally within 30 days. To protect your data we may ask you to prove your identity before we disclose anything.
If you are not satisfied with our response, you can contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland.
8. Visitors from the EEA and the United Kingdom
Where the GDPR applies to a processing operation, we rely on Art. 6(1)(f) GDPR for the server logs, spam protection and the Turnstile check (legitimate interest in a secure, working service) and on Art. 6(1)(b) GDPR for the contact form (pre-contractual steps taken at your request). In that case you additionally have the right to restriction of processing (Art. 18 GDPR) and the right to lodge a complaint with a supervisory authority where you are located.
We do not direct our services at people in the EEA and do not offer goods or services in an EEA currency. The German-language version of this site is aimed at German-speaking Switzerland.
9. Changes
We update this policy when our processing or the law changes. The version published on this page is the one that applies. The date of the last change is shown above.
This is a translation. In case of any discrepancy, the German version of this document prevails.