L1PRIVACY POLICY

Privacy Policy.

Last updated: 25 April 2026

Arden Cole Group attaches the highest importance to the protection of personal data. This policy describes the nature of the data processed, the purposes of the processing, the legal bases and the rights you have. It complies with the General Data Protection Regulation (GDPR, EU 2016/679) and the revised Federal Act on Data Protection (nFADP, Switzerland, in force since 1 September 2023).

01

Data controller

Arden Cole Group, a Swiss legal entity, acts as data controller within the meaning of Article 4 of the GDPR and Article 5 of the nFADP. For any question regarding the protection of your data, you may contact us via the form available on the contact page.

02

Data collected

When you interact with our site, we collect only the following data:

Contact form data: name, organisation, professional email address, subject of the request, content of the message, interface language. This data is provided voluntarily by you when you submit the contact form.

Technical browsing data: IP address (anonymised for statistics), browser type, pages consulted, visit duration, referral source. This data is collected via our analytics solution Plausible Analytics, GDPR-compliant by design and using no tracking cookies.

Visiting company identification data: via our business intelligence solution Leadfeeder, we identify companies (and not individuals) visiting our site, by cross-referencing the IP address with a database of public company registers. This practice constitutes a legitimate processing in accordance with Article 6(1)(f) of the GDPR.

03

Purposes of processing

Your data is processed exclusively for the following purposes:

Responding to your contact or strategic brief request; improving the quality of our site and our services; identifying organisations potentially interested in our services in a commercial approach compliant with the deontological rules of the profession; complying with our legal and regulatory obligations.

Your data is never used for unsolicited automated prospecting purposes, individual profiling, or transferred to commercial third parties.

04

Legal bases

The processing of your data is based on the following legal bases:

Consent (Art. 6(1)(a) GDPR): for the voluntary submission of your request via the contact form, validated by the explicit consent checkbox.

Legitimate interest (Art. 6(1)(f) GDPR): for the anonymised statistical analysis of our site traffic, the identification of visiting companies in a B2B commercial approach compliant with the deontological framework of the profession, and the security of our technical infrastructure.

Legal obligation (Art. 6(1)(c) GDPR): for the retention of certain data to comply with our accounting and tax obligations.

05

Retention period

Your data is retained for the periods strictly necessary for the purposes pursued:

Contact form data: three years from the last exchange, unless subsequent contractual commitment.

Analytics data: retained in aggregated and anonymised form, without time limit for aggregated statistics; raw data is deleted after twelve months.

Visiting company data: retained for the duration of commercial account activity, and deleted upon request in accordance with your right to erasure.

06

Data recipients

Your data is only accessible to authorised persons within the firm and to our technical subcontractors bound by contractual confidentiality commitments:

Vercel Inc. (hosting and CDN, data stored in Europe); Resend Inc. (transactional email sending); Supabase Inc. (database, EU instance — Stockholm); Plausible Analytics (statistical analysis, EU hosting); Leadfeeder Oy (visiting company identification, EU hosting).

All data processed by these subcontractors remains within the European Economic Area or in countries benefiting from an adequacy decision from the European Commission.

07

Your rights

In accordance with the GDPR and the nFADP, you have the following rights regarding your personal data:

Right of access: to obtain confirmation that data concerning you is being processed and to obtain a copy.

Right of rectification: to request the correction of inaccurate or incomplete data.

Right to erasure ("right to be forgotten"): to request the deletion of your data in cases provided by law.

Right to restriction of processing: to request that processing be suspended in certain circumstances.

Right to portability: to receive your data in a structured and machine-readable format.

Right to object: to object to processing based on legitimate interest.

Right to withdraw your consent at any time, without affecting the lawfulness of prior processing.

To exercise these rights, send us your request via the contact form specifying the nature of your request. We will respond within the one-month period provided by the GDPR, or the thirty-day period provided by the nFADP.

08

Right to lodge a complaint

If you consider that the processing of your data does not comply with the regulations, you have a right to lodge a complaint with the competent supervisory authority:

In Switzerland: Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch.

In the European Union: data protection authority of your country of residence (CNIL in France, BfDI in Germany, DPC in Ireland, etc.).

09

Data security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure or destruction. Our infrastructure relies on European hosting, encryption of communications in transit (TLS 1.3), HTTP security headers compliant with institutional standards, strict role-based access controls, and a periodic rotation policy for authentication secrets. As no security measure can guarantee absolute protection, we undertake to inform you as soon as possible in the event of a breach likely to present a risk to your rights and freedoms.

10

Policy modifications

We reserve the right to modify this policy to reflect changes in our activity or applicable regulations. Any substantial modification will be announced on this page with an update of the date indicated in the header. We invite you to consult this policy regularly.