The essentials in three sentences

This site sets no cookies, uses no audience-measurement tool, and has no user accounts. Beyond the technical connection data logged by the host, a single page collects data you provide yourself: the contact form, described in detail below. Three tools also send a request to an external service, and we explain exactly what they transmit, and what they never transmit.

Who is responsible for the processing

The data controller within the meaning of the Federal Act on Data Protection (FADP) is:

Säfeli Sàrl
Route d'Englisberg 3, 1763 Granges-Paccot
Switzerland

For any question relating to data protection, use this site's contact page, or write directly using the details below.

Person in charge
Elio Schnarrenberger, for Säfeli Sàrl
E-mail: [email protected]
Phone: 079 737 37 93
Route d'Englisberg 3, 1763 Granges-Paccot, Switzerland

What data is processed

The site is entirely static: pages are prepared in advance and served as-is. There is no visitor database, no user account, no personal area. No data is stored on this site, including data from the contact form, which is transmitted by e-mail without being retained here.

In practice, browsing the site results in the processing of the technical data that any host logs to deliver a page and secure its infrastructure. Generally speaking, this includes:

Data Why it exists
IP address of your connection Technically necessary to return the requested page to you, and used by the host to detect abuse (attacks, bots, overload).
Date and time of the request Technical logging and incident diagnosis.
Page or file accessed Technical logging, error detection.
Browser and system type Sent automatically by your browser, used to serve the right format and filter automated traffic.

This data is processed by the host for the operation, availability and security of the service. It is not used to build a visitor profile, is not cross-referenced with other sources, and is not shared with third parties for advertising or commercial purposes.

What this site does not do

  • No cookie is set by this site, whether to recognise you or to remember preferences. You will therefore see no consent banner: there is nothing to consent to.
  • No audience-measurement tool. No Google Analytics, no equivalent tool, not even one billed as privacy-friendly. We do not know, from our own tools, how many people read a given page.
  • No tracker, no pixel, no social-network button loaded from a third-party service.
  • No newsletter, no account, no sign-up. The site has a contact form, and that is the only place your e-mail address is ever requested. It is used to reply to you, nothing else: it is never added to a mailing list or a prospecting file.
  • No advertising and no ad network.

The interactive tools, in detail

This is the most important part of this page. The site's tools ask questions or accept input. It is legitimate to want to know what leaves your browser. Here is the answer, tool by tool.

The tools that transmit nothing

The cyber check-up, the password strength test and the cyberattack cost simulator perform all of their calculations inside your browser, in JavaScript. Your answers, the password being tested and the figures you enter never leave your device and are sent to no server. Nothing is saved once the tab is closed.

The tools that send a domain name

E-mail verification (SPF, DKIM, DMARC) and public exposure need to query public records. To do so, they transmit the domain name you enter, for example your-company.ch, and nothing else. A company's domain name is public information, not personal data in itself. The answers obtained come from public registries, which anyone can consult.

The breach-checking tool, and what it never sees

The has your password already leaked? tool deserves a precise explanation, because the question comes up naturally: how do you check a password without sending it?

Your browser first computes a SHA-1 hash of the password. A hash is a string of characters computed from the password, from which the original word cannot be recovered. Then, and this is the decisive point, only the first five characters of that hash are sent to the service being queried. It returns the list of all known hashes that start with those five characters, and the final comparison happens in your browser.

What never leaves your browser

Your full password is never transmitted. The complete hash is never transmitted either. The service being queried receives five characters, which match thousands of different passwords: it cannot know which one you are testing, nor even whether any of them actually matches yours.

For these three tools, requests are not retained on our side: they are issued with the Cache-Control: no-store header, and we keep no application log of the domains or hashes submitted. The external services queried apply their own terms, which each tool page specifies.

The contact form

The contact page has a form. It is the only place on the site where you voluntarily send us personal data, and it therefore deserves a precise description.

Data Why it is requested
Name To know who we are addressing in our reply.
E-mail address The address the reply is sent to. Without it, the request cannot be answered.
Company (optional) To place the question in context. This field can be left blank.
Message The content of your request.
IP address Used only at the moment of sending, to limit the number of messages sent from the same origin and rule out automated submissions. It does not appear in the e-mail received and is not kept once the counter expires.
Date and country of origin The country is inferred from the connection by the host. Both of these appear in the e-mail received, to place a request in context and spot an obviously fraudulent submission.

What this data is used for

Solely to process your request and reply to it. It is not used for prospecting, is not added to any commercial file, is not resold, and does not serve to build any profile.

On what basis

The processing generally rests on the fact that you send us this data on your own initiative, in order to get a reply. You remain free not to use the form: direct contact details, e-mail and phone, appear on the same page.

How long it is kept

The site itself retains nothing: no database, no record of the message. The message then exists as an e-mail in Säfeli Sàrl's mailbox. We keep it for as long as it takes to handle the request and any exchange that follows, then, if the request did not lead to a contractual relationship, we delete it within twelve months. When an exchange leads to an engagement, the corresponding documents fall under the usual retention obligations that apply to a Swiss company.

Who is involved in delivery

Sending the e-mail is handled by Resend, an e-mail delivery service operated by a US company. Processing takes place in the Ireland (eu-west-1) region, i.e. on infrastructure located within the European Economic Area. Resend acts as a processor: it carries the message to our inbox and has no intention of using it for its own purposes. The applicable terms are those published by this provider.

In practice, the data you enter passes through this service for the duration of delivery. That is how any e-mail sending normally works, which always involves one or more technical intermediaries. We would rather say so explicitly than let you believe a message travels without passing through anyone.

What an e-mail does not guarantee

An e-mail is not an end-to-end confidential channel. Avoid including passwords, access credentials or the technical detail of an unpatched vulnerability in it. If your request concerns an ongoing incident, a phone call is preferable.

Why this data is processed

Technical connection data is used to run the site, keep it available, and protect it against abuse. Requests sent by the three tools are used solely to produce the result you asked for, at the moment you ask for it. Contact-form data is used solely to reply to your request.

None of this data is used for prospecting, profiling, or advertising targeting.

Retention period

We keep no visit data. Messages received through the contact form are the exception: their retention period is detailed in the section devoted to the form above. Technical logs are the host's, and their retention period is whatever it applies to its infrastructure. Generally speaking, such logs are kept for a limited period, the time needed for diagnosis and security, then deleted or aggregated. We do not reproduce a specific figure here that we do not control: the applicable terms are those published by Cloudflare.

Processors and recipients

The processor involved in the day-to-day operation of the site is Cloudflare, Inc., which hosts and distributes it via Cloudflare Pages. As such, Cloudflare technically processes IP addresses in its logs, as any host does to deliver a page and protect its network.

A second processor is involved only when you use the contact form: Resend, a US company responsible for e-mail delivery, with processing in the Ireland (eu-west-1) region. It receives the content of the form on that occasion, for the duration of delivery.

The external services queried by the three tools described above receive, depending on the case, a domain name or five characters of a hash, and nothing more.

No data is sold, rented or transferred to third parties.

Transfers abroad

Cloudflare is a US company that operates a global network of servers. Processing of technical connection data may therefore, generally speaking, involve infrastructure located outside Switzerland. The external services queried by the tools may also be operated from abroad.

Resend is also a US company. Processing of contact-form messages is, however, configured on its Ireland (eu-west-1) region, i.e. within the European Economic Area. We cannot rule out that a US provider is subject to obligations under its own national law, and we refrain from making any definitive statement on this point. That is also why direct contact details, e-mail and phone, remain available alongside the form.

These transfers concern technical connection data and, for the tools, elements deliberately reduced to the strict minimum. We invite you to consult the data-protection documents published by these providers to learn what safeguards they apply.

Security

The site is served exclusively over HTTPS, which encrypts the exchanges between your browser and the server. The site's static nature greatly reduces the attack surface: there is no visitor database to compromise, no login area to force.

Your rights

The FADP generally grants you a right to access data concerning you, as well as a right to request its rectification or erasure, or to object to its processing.

One honest clarification: since we keep no visitor register, simply browsing the site leaves us no data that could identify you. If you have written to us through the contact form, however, your message does exist in our mailbox, and your rights apply to it in full. We will respond to your request by telling you exactly what exists.

To exercise these rights, use the contact page or write to [email protected]. We will need to be able to reasonably verify your identity before acting on it.

Supervisory authority

If you believe that a processing of data concerning you is not compliant, you can contact the Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch/fr .

Data breaches

In the event of a data security breach, Art. 24 FADP provides for a notification to the FDPIC as soon as possible where the breach is likely to result in a high risk to the personality or fundamental rights of the persons concerned. Swiss law sets no fixed deadline. We would apply this rule if such a situation were to occur.

Changes to this policy

This policy may evolve, in particular if a new tool is added to the site. The date of the last update appears at the top of the page, and any substantial change will be reflected in the text above.

Scope of this page

This policy describes the operation of this site only. It does not cover processing carried out by Säfeli Sàrl as part of its services, nor that of third-party sites we link to. This is an informational document; it does not constitute legal advice applicable to your own company: to draft your own, rely on your actual situation.