alpflo
EN
Create a brief

Privacy notice

How alpflo handles personal data, under the revised Swiss Federal Act on Data Protection (nDSG/revFADP).

Last updated 2026-08-13

The controller responsible for the personal data processed through alpflo is:

Nariman Maddah
Tödistrasse 56
8810 Horgen, CH
info@alpflo.ch
  • Property address submitted — to resolve the parcel and assemble your brief. A submitted address can itself be personal data where it is a person's residence.
  • Payment data — processed by Stripe; no card details are stored by the Provider.
  • IP address — your device's IP address is read on each request and used only for abuse prevention (rate-limiting search, address suggestions, and brief rendering). It is held in memory only and is not stored durably against your order.

alpflo uses no marketing analytics and no third-party trackers: there are no advertising trackers and no third-party cookies. Pages are server-rendered. alpflo sets the following functional first-party cookies — each one to run the Service, none for advertising:

  • alpflo_vid — an opaque, randomly generated visitor id for first-party product analytics: how a single visit moves from search to result. It carries no personal data itself and is never shared or used for advertising. As an analytics identifier it is not a paywall — it does not decide whether a brief is chargeable; it does also serve as the session key for a daily allowance of ungated brief views (abuse prevention), so clearing it resets that allowance.
  • alpflo_lang — the interface language you chose.
  • alpflo_assembly — a short-lived timestamp (three minutes) so the progress indicator advances correctly while a brief is being assembled.
  • alpflo_order_access — the access grant for a single order, scoped to that order's confirmation page. It is a genuine access factor: if you block cookies you will not open a purchased brief through that link, and recover access by confirming your email address again instead.
  • alpflo_account_claim — proof that you confirmed an email address during this session. It contains that email address in signed, readable-back form and lasts up to 8 hours, so you can view further briefs for other properties in the same session without confirming a new code each time. After that it expires.
  • alpflo_pending_order — the opaque identifier of an order whose payment you started but did not complete, so the landing page can offer you the way back to that order. It holds only that identifier — no address, no email address — lasts one day, and is deleted once the order is paid.

The email you confirm to view a brief is used for your orders — to deliver the brief, to process payment, and, for up to 8 hours, to release further briefs in the same session — and is never stored against the visitor cookie's id or pre-filled on a later visit.

On the app host (app.alpflo.ch), alpflo loads a self-hosted browser diagnostics SDK (Azure Application Insights) that reports page views, load timings, and JavaScript errors to the Provider's own Azure telemetry workspace. It is configured cookieless, is loaded from no third-party CDN, and serves operational diagnostics rather than advertising; query strings are stripped from URLs and known personal field names are redacted before anything is sent.

For the public marketing site (www.alpflo.ch), alpflo uses Google Search Console and Bing Webmaster Tools to diagnose organic search — index coverage and the search terms that lead people to alpflo. Both are verified by a DNS record, set no cookies and add no client-side tracker, and report only aggregate, server-observed search data. They apply to the marketing site, not to the Service itself.

  • Address — contractual necessity (to deliver the brief you ordered).
  • Payment — contractual necessity (to take payment for the brief).
  • Usage / analytics — legitimate interest (nDSG Art. 31): first-party product analytics via the functional visitor cookie, kept de-identified (an opaque visitor id, the public canton, and a keyed one-way hash of the building identifier, never the identifier itself — never your address or email) so alpflo can understand and improve how the Service is used. No advertising or profiling. Minimal operational server logs are also kept to run and secure the Service (see retention below).

Briefs are delivered as immutable, dated order records. The payment record for an order is kept for 10 years to meet Swiss accounting-retention duties (OR Art. 958f); it is held against a surrogate customer identifier, not your email, so it remains even after your personal data is deleted. Cached register lookups expire after a limited period.

The personal parts of an order — the property address you searched, your billing email, and the stored brief document (which contains the address and building identifier) — are pruned automatically one year after the order, leaving the payment record without them. You can also ask us to delete them sooner (see Your rights below).

Operational diagnostic logs and key-management audit logs are retained for 30 days. Product analytics are kept as one row per event rather than in aggregate; each row carries a pseudonymous customer reference and a visitor session id, neither your email nor the property address you searched. That reference is replaced with an anonymous marker on a verified erasure request, and in any case one year after the order. The functional visitor cookie expires after up to two years or when you clear it.

The Provider shares personal data only with the processors needed to run the Service, each acting on the Provider's instructions under a data-processing agreement:

  • Stripe Payments Europe, Ltd. — payment processing; may transfer data outside Switzerland under standard contractual clauses (nDSG Art. 16). See the Data Processing Agreement with Stripe.
  • Microsoft Azure — hosting, brief storage, and diagnostics, located in the Switzerland North region (in-country, not a cross-border transfer). This includes Azure Communication Services, which sends your order-confirmation email from within the same Swiss Azure tenant (Switzerland data location), so that email is not a cross-border transfer.
  • Infomaniak Network SA — DNS and inbound email routing, operated in Switzerland (not a cross-border transfer).
  • Cloudflare, Inc. — egress relay for ÖREB register lookups in French-speaking Switzerland (VD, GE, FR), whose cantonal services block requests from Swiss Azure data centres. Only the resolved parcel identifier and the public ÖREB extract travel through the relay — no contact and no payment data. Cloudflare is US-headquartered (see Cross-border transfers below).

The submitted address and the parcel identifier derived from it are additionally queried against official Swiss registers: swisstopo/GeoAdmin (geocoding and GWR building data), the cantonal ÖREB services (cadastre of public-law restrictions on landownership), and GEAK (building energy certificate). These are independent public bodies rather than processors acting on the Provider's instructions, and all are in Switzerland.

We do not sell your data.

Stripe is US-headquartered; transfers to it are protected by standard contractual clauses recognised under Swiss law. Cloudflare, Inc. is also US-headquartered: register lookups for French-speaking Switzerland are routed through its edge network, where the TLS connection terminates. Only public register data travels that path — the resolved parcel identifier and the ÖREB extract — and no contact or payment data. Microsoft Azure hosting and brief storage are in the Switzerland North region, and DNS and inbound email routing are handled by Infomaniak Network SA in Switzerland; those two are not cross-border transfers.

You have the right to access your personal data, to have it corrected, to have it deleted, and to object to its processing. To exercise a right, contact the Provider at info@alpflo.ch; we respond within 30 days.

We honour these requests with a real mechanism, not just a promise. On a verified access request we compile what we hold about your email — your orders, the briefs delivered to you, and your event counts. On a verified deletion request we irreversibly remove the personal parts — your order addresses, your billing email, your stored brief documents, and your search history — and strip the identifier from our de-identified usage records, keeping only the anonymised payment record the law requires us to retain (see Retention above).

You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch.