Legal · Data protection

Privacy Notice

What personal data we process, why, on what legal basis, who receives it, and the rights you have over it.

Version 1.2 · Effective 7 September 2026 · Governing law: Switzerland
AI-assisted, human-reviewed. Editorial responsibility: Fabien Lopez.
In short. This is primarily a brochure site with no login, tracking cookies or advertising pixels. We use tightly limited, cookieless PostHog analytics hosted in Germany to count visits and understand which pages are useful. We create no visitor profiles, record no sessions or form interactions, discard client IP data and strip URL query strings. The Invest page's Studio Letter request form sends only the information you choose to provide to Living Scale Up. We do not sell personal data.
On this page
  1. Who is responsible
  2. Which law applies
  3. What we process, why, and on what legal basis
  4. Who receives your data
  5. Transfers outside Switzerland
  6. How long we keep it
  7. Your rights
  8. Fonts, hosting and logs
  9. Artificial intelligence and automated decisions
  10. Security and breaches
  11. Children
  12. Changes to this notice

1. Who is responsible

The controller of the personal data described here is Living Scale Up Sàrl, Chemin de la Verrière 3, 1094 Paudex, Vaud, Switzerland — contact@livingscaleup.com. Full identification details are in the Legal Notice.

We have not appointed a data protection officer, and we are not required to. Data protection questions go to the address above.

Representative in the European Union

We have not appointed a representative in the European Union under Article 27 GDPR. We have assessed that obligation and recorded our reasoning: the volume and risk of personal data processing are low, we process no special-category data, and our audience measurement is cookieless and does not create person profiles. The channels through which we receive personal data are our contact email, the Studio Letter request form and an email-based newsletter. We review that assessment whenever our processing or EU activities change. If you are in the EEA and wish to exercise a right or raise a concern, write to contact@livingscaleup.com and we will handle it directly.

We have not appointed a representative in Switzerland and are not required to: Article 14 FADP applies only to controllers whose registered office is outside Switzerland.

2. Which law applies

We process personal data under the Swiss Federal Act on Data Protection (FADP, SR 235.1) and its Ordinance (DPO, SR 235.11), both in force since 1 September 2023.

Where we offer services to, or monitor the behaviour of, people in the European Union or the EEA, the General Data Protection Regulation (EU) 2016/679 (GDPR) also applies to that processing. This notice is written to the GDPR standard throughout, because it is the higher of the two; Swiss-specific points are marked where they differ.

The European Commission confirmed on 15 January 2024 that Switzerland provides an adequate level of data protection. Personal data may therefore flow from the EEA to us without additional safeguards.

3. What we process, why, and on what legal basis

3.1 Visiting the website

DataPurposeLegal basis
IP address, date and time, page requested, HTTP status, referrer, user agent — recorded in server and edge logsDelivering the site, security, abuse prevention, diagnosing faults, aggregate volume statisticsGDPR Art. 6(1)(f) legitimate interests — operating a secure and functioning website. FADP: overriding private interest, Art. 31
Security and bot-mitigation signals generated by our content delivery networkProtecting the site against attack, abusive crawling and denial of serviceGDPR Art. 6(1)(f). FADP Art. 31
Page path, page title, referring site, device and browser category, page-view time, page-leave timing, and a short-lived cookieless visit identifier. Query strings and URL fragments are stripped. The client IP is used transiently to produce the identifier and then discarded before storage.Aggregate audience measurement and improving the usefulness and performance of the public websiteGDPR Art. 6(1)(f) legitimate interests, balanced by data minimisation, no device storage, no person profile and an objection route. FADP Arts. 6 and 31

We use no analytics cookies, advertising pixels, session recording, heatmaps, form or click autocapture, person profiles or cross-site tracking. Supported browser Do Not Track signals are respected. See Cookies and Tracking for the full technical inventory.

3.2 Contacting us by email or requesting the Studio Letter

DataPurposeLegal basis
Your name, email address, employer or venture, the content of your message, and our correspondence with youAnswering your enquiry, assessing a possible engagement, investment, partnership or role, and keeping a record of the exchangeGDPR Art. 6(1)(b) steps prior to a contract, and Art. 6(1)(f) legitimate interests in responding to business enquiries. FADP Arts. 6 and 31
For a Studio Letter request: your name, email address, firm (if supplied), investor category, jurisdiction, what you requested, eligibility confirmations and any note you addAssessing whether we may provide the requested investor material, delivering and answering the request, and keeping a record of the exchangeGDPR Art. 6(1)(b) steps prior to a contract, and Art. 6(1)(f) legitimate interests in responding to qualified business enquiries and applying our published distribution restrictions. FADP Arts. 6 and 31
Notes and assessments we make about a prospective venture, partner, investor or candidateEvaluating and progressing the opportunityGDPR Art. 6(1)(f). FADP Art. 31

Providing this data is voluntary, but we cannot answer an enquiry or send the Studio Letter without a means of replying to you. A Studio Letter submission is processed by a same-origin Cloudflare Pages Function and delivered to our business email. The endpoint keeps no form database or delivery queue. If optional rate limiting is enabled, it keeps a truncated hash derived from the requesting IP address for up to one hour solely to limit automated abuse.

If you pitch us. Where your message contains a venture proposal, a business plan, a deck or comparable material, we hold it only to assess the opportunity and to conduct the conversation. We do not circulate it outside Living Scale Up without asking you first, we do not use it to train AI models, and we do not enter identifiable submissions into AI tools that are not on our approved list. You may ask us to delete it at any time — write to contact@livingscaleup.com and we will delete it and confirm, subject only to anything we must legally retain. What confidentiality does and does not apply, and how to get a non-disclosure agreement in place before you send anything sensitive, is set out in section 8 of the Terms of Use.

3.3 The studio newsletter

DataPurposeLegal basis
Your email address; the fact, date and time of your subscription requestSending you the newsletter, and being able to prove that you asked for itConsent — GDPR Art. 6(1)(a) and Art. 7; ePrivacy Directive Art. 13(1). In Switzerland, prior consent under UCA Art. 3(1)(o)
Your name, if you give itAddressing you properlyConsent, as above

Subscription is by email, so your request is itself your consent and your own record of it. You may withdraw consent at any time, as easily as you gave it, by using the unsubscribe link in any issue or by writing to contact@livingscaleup.com. Withdrawal does not affect the lawfulness of sending before it. We act on unsubscribe requests immediately and permanently, and keep a minimal suppression record so that we do not contact you again by mistake.

We do not track whether you open our emails or which links you click. We do not sell, rent or share our list, and we do not send third-party advertising. Every issue carries our registered company name, postal address and a working unsubscribe link.

3.4 Client, partner and portfolio relationships

Where we work with you under an engagement, investment or partnership agreement, we process the contact and contractual data needed to perform that agreement, to keep the accounts and records Swiss law requires, and to manage the relationship. Legal bases: GDPR Art. 6(1)(b), Art. 6(1)(c) and Art. 6(1)(f); FADP Arts. 6 and 31. Where an engagement involves personal data belonging to you, the terms of that engagement — including any data processing agreement — govern it in preference to this notice.

3.5 What we do not do

4. Who receives your data

We keep the number of processors deliberately small. As at the effective date of this notice they are:

RecipientRole and what it receivesLocation
Cloudflare, Inc.Hosting, content delivery and edge security for this website. Receives request metadata including your IP address.United States, with global edge processing
PostHog, Inc.Cookieless web analytics as our processor. Receives the limited event fields described in section 3.1; EU Cloud stores customer event data in Germany. Client IP storage and person profiles are disabled for this site.Germany (EU Cloud), with PostHog group and subprocessors subject to contractual safeguards
Google Workspace (Google Ireland Ltd / Google LLC)Business email and calendar. Receives the content of correspondence with us.European Union and United States
Professional advisers, auditors and, where legally required, authoritiesLegal, accounting and audit advice; compliance with legal obligationsPrincipally Switzerland

Each processor acts on our instructions under a written agreement meeting GDPR Art. 28 and FADP Art. 9, is bound to confidentiality and appropriate security, and may not engage further processors without authorisation. We do not disclose personal data to third parties for their own marketing purposes.

The AI tools we use in our own work are described in the AI Disclosure. We do not enter identifiable client or personal data into AI tools that are not approved and contractually bound not to train on our inputs.

5. Transfers outside Switzerland

Some recipients above are outside Switzerland, including in the United States and the European Economic Area.

Transfers to the EEA and to other states listed in Annex 1 to the Swiss DPO are permitted because the Federal Council has determined that those states provide adequate protection (FADP Art. 16(1)).

For the United States we rely on one or both of the following (FADP Art. 16(2); GDPR Arts. 45–46):

You may request a copy of the safeguards in place for a specific transfer. We keep the pending challenge to the EU–US Data Privacy Framework before the Court of Justice of the European Union in view, and will change our arrangements if its legal basis is disturbed.

6. How long we keep it

CategoryRetention
Server and edge logsup to 30 days at the edge, then aggregated
Cookieless web analytics eventsUp to 24 months for trend analysis, then deleted or irreversibly aggregated
Enquiry correspondence that does not lead to a relationship24 months from the last exchange, then deleted
Studio Letter rate-limit hash, if optional rate limiting is enabledUp to one hour
Venture proposals, decks and pitch material that do not lead to a relationship12 months from the last exchange, then deleted. Deleted sooner on request
Newsletter subscription and consent recordFor as long as you are subscribed, and 3 years after you unsubscribe, to evidence that the sending was lawful
Suppression list entry after unsubscribeIndefinitely, limited to the minimum needed to avoid contacting you again
Client, investor and partner contractual records10 years from the end of the financial year concerned, as Swiss accounting and record-keeping law requires (Art. 958f CO)
Records of a data breachAt least 2 years, as DPO Art. 15 requires

We delete or anonymise personal data once the purpose has been achieved and no legal retention obligation, and no need to bring or defend a legal claim, requires us to keep it.

7. Your rights

Subject to the conditions and exceptions in the applicable law, you may:

Ask what we hold about you
Access to your personal data and to the information needed to exercise your rights — FADP Art. 25, GDPR Art. 15. Free of charge; we normally answer within 30 days.
Have it corrected
Rectification of inaccurate or incomplete data — FADP Art. 32(1), GDPR Art. 16.
Have it deleted
Erasure where we no longer have a basis to hold it — FADP Art. 32(2), GDPR Art. 17.
Restrict or object to processing
Including an absolute right to object to direct marketing at any time — FADP Art. 30(2)(b) and Art. 32(2), GDPR Arts. 18 and 21.
Receive it in a portable form
Data you provided to us, in a common electronic format — FADP Art. 28, GDPR Art. 20.
Withdraw consent
At any time, as easily as you gave it, without affecting the lawfulness of earlier processing — GDPR Art. 7(3).
Not be subject to a decision based solely on automated processing
Including the right to state your position and to have a decision reviewed by a human being — FADP Art. 21, GDPR Art. 22. We take no such decisions.
Complain to a supervisory authority
In Switzerland, the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern — edoeb.admin.ch. In the EEA, the supervisory authority of your habitual residence, place of work or place of the alleged infringement — GDPR Art. 77. You may also seek a judicial remedy.

Write to contact@livingscaleup.com. We may need to verify your identity before acting, and we will not use identity documents for any other purpose. We will tell you if a statutory exception prevents us from complying in full, and why.

8. Fonts, hosting and logs

Fonts and analytics. We self-host the two typefaces this site uses. The only browser connections beyond our own host are to PostHog's EU asset and ingestion hosts for the limited cookieless analytics described above.

Hosting and logs. The site is served by Cloudflare Pages. Cloudflare processes request metadata, including your IP address, in order to deliver the site and protect it against attack. Cloudflare acts as our processor under a data processing agreement.

9. Artificial intelligence and automated decisions

Living Scale Up uses artificial intelligence extensively in its own work. What that means, which tools we use, what we do not put into them, and who is accountable, is set out in the AI Disclosure and Editorial Standards. As it affects your personal data:

10. Security and breaches

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss and misuse, having regard to the risk — including transport encryption, access control on a need-to-know basis, multi-factor authentication on business accounts, a short list of vetted providers, and staff instruction. No internet transmission can be guaranteed absolutely secure. Ordinary email is not a secure channel: please do not send us confidential or sensitive information by unencrypted email, and tell us if you need a secure channel.

If a breach of data security is likely to result in a high risk to your personality or fundamental rights, we notify the FDPIC as quickly as possible (FADP Art. 24) and, where the GDPR applies, the competent supervisory authority within 72 hours (GDPR Art. 33). We inform affected individuals where necessary for their protection or where the authority requires it.

11. Children

This site addresses business audiences and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.

12. Changes to this notice

We will update this notice when our processing changes or the law does. The version number and effective date are at the top of this page, and we keep superseded versions on file. Where a change materially affects you we will draw attention to it — and where a change requires your consent, we will ask for it rather than assume it.