Privacy Notice
What personal data we process, why, on what legal basis, who receives it, and the rights you have over it.
1. Who is responsible
The controller of the personal data described here is Living Scale Up Sàrl, Chemin de la Verrière 3, 1094 Paudex, Vaud, Switzerland — [email protected]. Full identification details are in the Legal Notice.
We have not appointed a data protection officer, and we are not required to. Data protection questions go to the address above.
Representative in the European Union
We have not appointed a representative in the European Union under Article 27 GDPR. We have assessed that obligation and recorded our reasoning: the volume of personal data we process is very low, we process no special-category data, we operate no tracking or profiling, and the only channels through which we receive personal data are an email address and an email-based newsletter. We keep that assessment dated and on file, and we review it whenever our processing changes — in particular if we add a web form, a customer-relationship system, analytics, or paid advertising directed at the EU. If you are in the EEA and wish to exercise a right or raise a concern, write to [email protected] and we will handle it directly and without routing you through an intermediary.
We have not appointed a representative in Switzerland and are not required to: Article 14 FADP applies only to controllers whose registered office is outside Switzerland.
2. Which law applies
We process personal data under the Swiss Federal Act on Data Protection (FADP, SR 235.1) and its Ordinance (DPO, SR 235.11), both in force since 1 September 2023.
Where we offer services to, or monitor the behaviour of, people in the European Union or the EEA, the General Data Protection Regulation (EU) 2016/679 (GDPR) also applies to that processing. This notice is written to the GDPR standard throughout, because it is the higher of the two; Swiss-specific points are marked where they differ.
The European Commission confirmed on 15 January 2024 that Switzerland provides an adequate level of data protection. Personal data may therefore flow from the EEA to us without additional safeguards.
3. What we process, why, and on what legal basis
3.1 Visiting the website
| Data | Purpose | Legal basis |
|---|---|---|
| IP address, date and time, page requested, HTTP status, referrer, user agent — recorded in server and edge logs | Delivering the site, security, abuse prevention, diagnosing faults, aggregate volume statistics | GDPR Art. 6(1)(f) legitimate interests — operating a secure and functioning website. FADP: overriding private interest, Art. 31 |
| Security and bot-mitigation signals generated by our content delivery network | Protecting the site against attack, abusive crawling and denial of service | GDPR Art. 6(1)(f). FADP Art. 31 |
We use no analytics cookies, advertising pixels, session recording, fingerprinting or cross-site tracking. See Cookies and Tracking for the full inventory.
3.2 Contacting us by email
| Data | Purpose | Legal basis |
|---|---|---|
| Your name, email address, employer or venture, the content of your message, and our correspondence with you | Answering your enquiry, assessing a possible engagement, investment, partnership or role, and keeping a record of the exchange | GDPR Art. 6(1)(b) steps prior to a contract, and Art. 6(1)(f) legitimate interests in responding to business enquiries. FADP Arts. 6 and 31 |
| Notes and assessments we make about a prospective venture, partner, investor or candidate | Evaluating and progressing the opportunity | GDPR Art. 6(1)(f). FADP Art. 31 |
Providing this data is voluntary, but we cannot answer an enquiry without a means of replying to you.
If you pitch us. Where your message contains a venture proposal, a business plan, a deck or comparable material, we hold it only to assess the opportunity and to conduct the conversation. We do not circulate it outside Living Scale Up without asking you first, we do not use it to train AI models, and we do not enter identifiable submissions into AI tools that are not on our approved list. You may ask us to delete it at any time — write to [email protected] and we will delete it and confirm, subject only to anything we must legally retain. What confidentiality does and does not apply, and how to get a non-disclosure agreement in place before you send anything sensitive, is set out in section 8 of the Terms of Use.
3.3 The studio newsletter
| Data | Purpose | Legal basis |
|---|---|---|
| Your email address; the fact, date and time of your subscription request | Sending you the newsletter, and being able to prove that you asked for it | Consent — GDPR Art. 6(1)(a) and Art. 7; ePrivacy Directive Art. 13(1). In Switzerland, prior consent under UCA Art. 3(1)(o) |
| Your name, if you give it | Addressing you properly | Consent, as above |
Subscription is by email, so your request is itself your consent and your own record of it. You may withdraw consent at any time, as easily as you gave it, by using the unsubscribe link in any issue or by writing to [email protected]. Withdrawal does not affect the lawfulness of sending before it. We act on unsubscribe requests immediately and permanently, and keep a minimal suppression record so that we do not contact you again by mistake.
We do not track whether you open our emails or which links you click. We do not sell, rent or share our list, and we do not send third-party advertising. Every issue carries our registered company name, postal address and a working unsubscribe link.
3.4 Client, partner and portfolio relationships
Where we work with you under an engagement, investment or partnership agreement, we process the contact and contractual data needed to perform that agreement, to keep the accounts and records Swiss law requires, and to manage the relationship. Legal bases: GDPR Art. 6(1)(b), Art. 6(1)(c) and Art. 6(1)(f); FADP Arts. 6 and 31. Where an engagement involves personal data belonging to you, the terms of that engagement — including any data processing agreement — govern it in preference to this notice.
3.5 What we do not do
- We do not process special categories of personal data (GDPR Art. 9) or sensitive personal data (FADP Art. 5(c)) through this website, and we ask you not to send any.
- We do not carry out advertising profiling, behavioural targeting, or automated decision-making that produces legal effects for you.
- We do not buy personal data from data brokers for outbound marketing.
4. Who receives your data
We keep the number of processors deliberately small. As at the effective date of this notice they are:
| Recipient | Role and what it receives | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, content delivery and edge security for this website. Receives request metadata including your IP address. | United States, with global edge processing |
| Google Workspace (Google Ireland Ltd / Google LLC) | Business email and calendar. Receives the content of correspondence with us. | European Union and United States |
| Professional advisers, auditors and, where legally required, authorities | Legal, accounting and audit advice; compliance with legal obligations | Principally Switzerland |
Each processor acts on our instructions under a written agreement meeting GDPR Art. 28 and FADP Art. 9, is bound to confidentiality and appropriate security, and may not engage further processors without authorisation. We do not disclose personal data to third parties for their own marketing purposes.
The AI tools we use in our own work are described in the AI Disclosure. We do not enter identifiable client or personal data into AI tools that are not approved and contractually bound not to train on our inputs.
5. Transfers outside Switzerland
Some recipients above are outside Switzerland, including in the United States and the European Economic Area.
Transfers to the EEA and to other states listed in Annex 1 to the Swiss DPO are permitted because the Federal Council has determined that those states provide adequate protection (FADP Art. 16(1)).
For the United States we rely on one or both of the following (FADP Art. 16(2); GDPR Arts. 45–46):
- the recipient's certification under the Swiss–US Data Privacy Framework (in force since 15 September 2024) and, for GDPR-governed transfers, the EU–US Data Privacy Framework; and/or
- standard contractual clauses — the European Commission's clauses as recognised by the Swiss FDPIC with the Swiss amendments — supported by a transfer impact assessment and, where appropriate, additional technical and organisational measures.
You may request a copy of the safeguards in place for a specific transfer. We keep the pending challenge to the EU–US Data Privacy Framework before the Court of Justice of the European Union in view, and will change our arrangements if its legal basis is disturbed.
6. How long we keep it
| Category | Retention |
|---|---|
| Server and edge logs | up to 30 days at the edge, then aggregated |
| Enquiry correspondence that does not lead to a relationship | 24 months from the last exchange, then deleted |
| Venture proposals, decks and pitch material that do not lead to a relationship | 12 months from the last exchange, then deleted. Deleted sooner on request |
| Newsletter subscription and consent record | For as long as you are subscribed, and 3 years after you unsubscribe, to evidence that the sending was lawful |
| Suppression list entry after unsubscribe | Indefinitely, limited to the minimum needed to avoid contacting you again |
| Client, investor and partner contractual records | 10 years from the end of the financial year concerned, as Swiss accounting and record-keeping law requires (Art. 958f CO) |
| Records of a data breach | At least 2 years, as DPO Art. 15 requires |
We delete or anonymise personal data once the purpose has been achieved and no legal retention obligation, and no need to bring or defend a legal claim, requires us to keep it.
7. Your rights
Subject to the conditions and exceptions in the applicable law, you may:
- Ask what we hold about you
- Access to your personal data and to the information needed to exercise your rights — FADP Art. 25, GDPR Art. 15. Free of charge; we normally answer within 30 days.
- Have it corrected
- Rectification of inaccurate or incomplete data — FADP Art. 32(1), GDPR Art. 16.
- Have it deleted
- Erasure where we no longer have a basis to hold it — FADP Art. 32(2), GDPR Art. 17.
- Restrict or object to processing
- Including an absolute right to object to direct marketing at any time — FADP Art. 30(2)(b) and Art. 32(2), GDPR Arts. 18 and 21.
- Receive it in a portable form
- Data you provided to us, in a common electronic format — FADP Art. 28, GDPR Art. 20.
- Withdraw consent
- At any time, as easily as you gave it, without affecting the lawfulness of earlier processing — GDPR Art. 7(3).
- Not be subject to a decision based solely on automated processing
- Including the right to state your position and to have a decision reviewed by a human being — FADP Art. 21, GDPR Art. 22. We take no such decisions.
- Complain to a supervisory authority
- In Switzerland, the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern — edoeb.admin.ch. In the EEA, the supervisory authority of your habitual residence, place of work or place of the alleged infringement — GDPR Art. 77. You may also seek a judicial remedy.
Write to [email protected]. We may need to verify your identity before acting, and we will not use identity documents for any other purpose. We will tell you if a statutory exception prevents us from complying in full, and why.
8. Fonts, hosting and logs
Fonts. We self-host the two typefaces this site uses. Loading a page makes no connection to any third-party server: no font service, no content delivery network other than our own host, no analytics endpoint. Nothing about your visit is disclosed to anyone other than us and our hosting provider.
Hosting and logs. The site is served by Cloudflare Pages. Cloudflare processes request metadata, including your IP address, in order to deliver the site and protect it against attack. Cloudflare acts as our processor under a data processing agreement.
9. Artificial intelligence and automated decisions
Living Scale Up uses artificial intelligence extensively in its own work. What that means, which tools we use, what we do not put into them, and who is accountable, is set out in the AI Disclosure and Editorial Standards. As it affects your personal data:
- We do not use AI to make automated decisions about you that have legal effect or otherwise significantly affect you. If that ever changes we will say so here and honour your right under FADP Art. 21 and GDPR Art. 22 to a human review.
- We do not enter personal data, or identifiable client or partner information, into AI tools that are not on our approved list and contractually bound not to train on our inputs.
- We do not use your personal data to train AI models, and we do not permit our providers to.
- Where you interact with an AI system operated by us or by one of our ventures, you will be told that you are dealing with a machine and not a person.
10. Security and breaches
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss and misuse, having regard to the risk — including transport encryption, access control on a need-to-know basis, multi-factor authentication on business accounts, a short list of vetted providers, and staff instruction. No internet transmission can be guaranteed absolutely secure. Ordinary email is not a secure channel: please do not send us confidential or sensitive information by unencrypted email, and tell us if you need a secure channel.
If a breach of data security is likely to result in a high risk to your personality or fundamental rights, we notify the FDPIC as quickly as possible (FADP Art. 24) and, where the GDPR applies, the competent supervisory authority within 72 hours (GDPR Art. 33). We inform affected individuals where necessary for their protection or where the authority requires it.
11. Children
This site addresses business audiences and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
12. Changes to this notice
We will update this notice when our processing changes or the law does. The version number and effective date are at the top of this page, and we keep superseded versions on file. Where a change materially affects you we will draw attention to it — and where a change requires your consent, we will ask for it rather than assume it.