Legal · Data protection

Privacy Notice

What personal data we process, why, on what legal basis, who receives it, and the rights you have over it.

Version 1.0 · Effective 4 August 2026 · Governing law: Switzerland
AI-assisted, human-reviewed. Editorial responsibility: Fabien Lopez.
In short. This is a brochure site. It has no login, no forms, no tracking cookies and no advertising pixels. We do not sell or share personal data. For most visitors the only personal data we hold is a server log entry; if you email us or subscribe to the newsletter, we hold what you send us. We self-host our fonts, so loading this site makes no connection to any third-party server.
On this page
  1. Who is responsible
  2. Which law applies
  3. What we process, why, and on what legal basis
  4. Who receives your data
  5. Transfers outside Switzerland
  6. How long we keep it
  7. Your rights
  8. Fonts, hosting and logs
  9. Artificial intelligence and automated decisions
  10. Security and breaches
  11. Children
  12. Changes to this notice

1. Who is responsible

The controller of the personal data described here is Living Scale Up Sàrl, Chemin de la Verrière 3, 1094 Paudex, Vaud, Switzerland — [email protected]. Full identification details are in the Legal Notice.

We have not appointed a data protection officer, and we are not required to. Data protection questions go to the address above.

Representative in the European Union

We have not appointed a representative in the European Union under Article 27 GDPR. We have assessed that obligation and recorded our reasoning: the volume of personal data we process is very low, we process no special-category data, we operate no tracking or profiling, and the only channels through which we receive personal data are an email address and an email-based newsletter. We keep that assessment dated and on file, and we review it whenever our processing changes — in particular if we add a web form, a customer-relationship system, analytics, or paid advertising directed at the EU. If you are in the EEA and wish to exercise a right or raise a concern, write to [email protected] and we will handle it directly and without routing you through an intermediary.

We have not appointed a representative in Switzerland and are not required to: Article 14 FADP applies only to controllers whose registered office is outside Switzerland.

2. Which law applies

We process personal data under the Swiss Federal Act on Data Protection (FADP, SR 235.1) and its Ordinance (DPO, SR 235.11), both in force since 1 September 2023.

Where we offer services to, or monitor the behaviour of, people in the European Union or the EEA, the General Data Protection Regulation (EU) 2016/679 (GDPR) also applies to that processing. This notice is written to the GDPR standard throughout, because it is the higher of the two; Swiss-specific points are marked where they differ.

The European Commission confirmed on 15 January 2024 that Switzerland provides an adequate level of data protection. Personal data may therefore flow from the EEA to us without additional safeguards.

3. What we process, why, and on what legal basis

3.1 Visiting the website

DataPurposeLegal basis
IP address, date and time, page requested, HTTP status, referrer, user agent — recorded in server and edge logsDelivering the site, security, abuse prevention, diagnosing faults, aggregate volume statisticsGDPR Art. 6(1)(f) legitimate interests — operating a secure and functioning website. FADP: overriding private interest, Art. 31
Security and bot-mitigation signals generated by our content delivery networkProtecting the site against attack, abusive crawling and denial of serviceGDPR Art. 6(1)(f). FADP Art. 31

We use no analytics cookies, advertising pixels, session recording, fingerprinting or cross-site tracking. See Cookies and Tracking for the full inventory.

3.2 Contacting us by email

DataPurposeLegal basis
Your name, email address, employer or venture, the content of your message, and our correspondence with youAnswering your enquiry, assessing a possible engagement, investment, partnership or role, and keeping a record of the exchangeGDPR Art. 6(1)(b) steps prior to a contract, and Art. 6(1)(f) legitimate interests in responding to business enquiries. FADP Arts. 6 and 31
Notes and assessments we make about a prospective venture, partner, investor or candidateEvaluating and progressing the opportunityGDPR Art. 6(1)(f). FADP Art. 31

Providing this data is voluntary, but we cannot answer an enquiry without a means of replying to you.

If you pitch us. Where your message contains a venture proposal, a business plan, a deck or comparable material, we hold it only to assess the opportunity and to conduct the conversation. We do not circulate it outside Living Scale Up without asking you first, we do not use it to train AI models, and we do not enter identifiable submissions into AI tools that are not on our approved list. You may ask us to delete it at any time — write to [email protected] and we will delete it and confirm, subject only to anything we must legally retain. What confidentiality does and does not apply, and how to get a non-disclosure agreement in place before you send anything sensitive, is set out in section 8 of the Terms of Use.

3.3 The studio newsletter

DataPurposeLegal basis
Your email address; the fact, date and time of your subscription requestSending you the newsletter, and being able to prove that you asked for itConsent — GDPR Art. 6(1)(a) and Art. 7; ePrivacy Directive Art. 13(1). In Switzerland, prior consent under UCA Art. 3(1)(o)
Your name, if you give itAddressing you properlyConsent, as above

Subscription is by email, so your request is itself your consent and your own record of it. You may withdraw consent at any time, as easily as you gave it, by using the unsubscribe link in any issue or by writing to [email protected]. Withdrawal does not affect the lawfulness of sending before it. We act on unsubscribe requests immediately and permanently, and keep a minimal suppression record so that we do not contact you again by mistake.

We do not track whether you open our emails or which links you click. We do not sell, rent or share our list, and we do not send third-party advertising. Every issue carries our registered company name, postal address and a working unsubscribe link.

3.4 Client, partner and portfolio relationships

Where we work with you under an engagement, investment or partnership agreement, we process the contact and contractual data needed to perform that agreement, to keep the accounts and records Swiss law requires, and to manage the relationship. Legal bases: GDPR Art. 6(1)(b), Art. 6(1)(c) and Art. 6(1)(f); FADP Arts. 6 and 31. Where an engagement involves personal data belonging to you, the terms of that engagement — including any data processing agreement — govern it in preference to this notice.

3.5 What we do not do

4. Who receives your data

We keep the number of processors deliberately small. As at the effective date of this notice they are:

RecipientRole and what it receivesLocation
Cloudflare, Inc.Hosting, content delivery and edge security for this website. Receives request metadata including your IP address.United States, with global edge processing
Google Workspace (Google Ireland Ltd / Google LLC)Business email and calendar. Receives the content of correspondence with us.European Union and United States
Professional advisers, auditors and, where legally required, authoritiesLegal, accounting and audit advice; compliance with legal obligationsPrincipally Switzerland

Each processor acts on our instructions under a written agreement meeting GDPR Art. 28 and FADP Art. 9, is bound to confidentiality and appropriate security, and may not engage further processors without authorisation. We do not disclose personal data to third parties for their own marketing purposes.

The AI tools we use in our own work are described in the AI Disclosure. We do not enter identifiable client or personal data into AI tools that are not approved and contractually bound not to train on our inputs.

5. Transfers outside Switzerland

Some recipients above are outside Switzerland, including in the United States and the European Economic Area.

Transfers to the EEA and to other states listed in Annex 1 to the Swiss DPO are permitted because the Federal Council has determined that those states provide adequate protection (FADP Art. 16(1)).

For the United States we rely on one or both of the following (FADP Art. 16(2); GDPR Arts. 45–46):

You may request a copy of the safeguards in place for a specific transfer. We keep the pending challenge to the EU–US Data Privacy Framework before the Court of Justice of the European Union in view, and will change our arrangements if its legal basis is disturbed.

6. How long we keep it

CategoryRetention
Server and edge logsup to 30 days at the edge, then aggregated
Enquiry correspondence that does not lead to a relationship24 months from the last exchange, then deleted
Venture proposals, decks and pitch material that do not lead to a relationship12 months from the last exchange, then deleted. Deleted sooner on request
Newsletter subscription and consent recordFor as long as you are subscribed, and 3 years after you unsubscribe, to evidence that the sending was lawful
Suppression list entry after unsubscribeIndefinitely, limited to the minimum needed to avoid contacting you again
Client, investor and partner contractual records10 years from the end of the financial year concerned, as Swiss accounting and record-keeping law requires (Art. 958f CO)
Records of a data breachAt least 2 years, as DPO Art. 15 requires

We delete or anonymise personal data once the purpose has been achieved and no legal retention obligation, and no need to bring or defend a legal claim, requires us to keep it.

7. Your rights

Subject to the conditions and exceptions in the applicable law, you may:

Ask what we hold about you
Access to your personal data and to the information needed to exercise your rights — FADP Art. 25, GDPR Art. 15. Free of charge; we normally answer within 30 days.
Have it corrected
Rectification of inaccurate or incomplete data — FADP Art. 32(1), GDPR Art. 16.
Have it deleted
Erasure where we no longer have a basis to hold it — FADP Art. 32(2), GDPR Art. 17.
Restrict or object to processing
Including an absolute right to object to direct marketing at any time — FADP Art. 30(2)(b) and Art. 32(2), GDPR Arts. 18 and 21.
Receive it in a portable form
Data you provided to us, in a common electronic format — FADP Art. 28, GDPR Art. 20.
Withdraw consent
At any time, as easily as you gave it, without affecting the lawfulness of earlier processing — GDPR Art. 7(3).
Not be subject to a decision based solely on automated processing
Including the right to state your position and to have a decision reviewed by a human being — FADP Art. 21, GDPR Art. 22. We take no such decisions.
Complain to a supervisory authority
In Switzerland, the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern — edoeb.admin.ch. In the EEA, the supervisory authority of your habitual residence, place of work or place of the alleged infringement — GDPR Art. 77. You may also seek a judicial remedy.

Write to [email protected]. We may need to verify your identity before acting, and we will not use identity documents for any other purpose. We will tell you if a statutory exception prevents us from complying in full, and why.

8. Fonts, hosting and logs

Fonts. We self-host the two typefaces this site uses. Loading a page makes no connection to any third-party server: no font service, no content delivery network other than our own host, no analytics endpoint. Nothing about your visit is disclosed to anyone other than us and our hosting provider.

Hosting and logs. The site is served by Cloudflare Pages. Cloudflare processes request metadata, including your IP address, in order to deliver the site and protect it against attack. Cloudflare acts as our processor under a data processing agreement.

9. Artificial intelligence and automated decisions

Living Scale Up uses artificial intelligence extensively in its own work. What that means, which tools we use, what we do not put into them, and who is accountable, is set out in the AI Disclosure and Editorial Standards. As it affects your personal data:

10. Security and breaches

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss and misuse, having regard to the risk — including transport encryption, access control on a need-to-know basis, multi-factor authentication on business accounts, a short list of vetted providers, and staff instruction. No internet transmission can be guaranteed absolutely secure. Ordinary email is not a secure channel: please do not send us confidential or sensitive information by unencrypted email, and tell us if you need a secure channel.

If a breach of data security is likely to result in a high risk to your personality or fundamental rights, we notify the FDPIC as quickly as possible (FADP Art. 24) and, where the GDPR applies, the competent supervisory authority within 72 hours (GDPR Art. 33). We inform affected individuals where necessary for their protection or where the authority requires it.

11. Children

This site addresses business audiences and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.

12. Changes to this notice

We will update this notice when our processing changes or the law does. The version number and effective date are at the top of this page, and we keep superseded versions on file. Where a change materially affects you we will draw attention to it — and where a change requires your consent, we will ask for it rather than assume it.