Privacy Notice
What personal data we process, why, on what legal basis, who receives it, and the rights you have over it.
1. Who is responsible
The controller of the personal data described here is Living Scale Up Sàrl, Chemin de la Verrière 3, 1094 Paudex, Vaud, Switzerland — contact@livingscaleup.com. Full identification details are in the Legal Notice.
We have not appointed a data protection officer, and we are not required to. Data protection questions go to the address above.
Representative in the European Union
We have not appointed a representative in the European Union under Article 27 GDPR. We have assessed that obligation and recorded our reasoning: the volume and risk of personal data processing are low, we process no special-category data, and our audience measurement is cookieless and does not create person profiles. The channels through which we receive personal data are our contact email, the Studio Letter request form and an email-based newsletter. We review that assessment whenever our processing or EU activities change. If you are in the EEA and wish to exercise a right or raise a concern, write to contact@livingscaleup.com and we will handle it directly.
We have not appointed a representative in Switzerland and are not required to: Article 14 FADP applies only to controllers whose registered office is outside Switzerland.
2. Which law applies
We process personal data under the Swiss Federal Act on Data Protection (FADP, SR 235.1) and its Ordinance (DPO, SR 235.11), both in force since 1 September 2023.
Where we offer services to, or monitor the behaviour of, people in the European Union or the EEA, the General Data Protection Regulation (EU) 2016/679 (GDPR) also applies to that processing. This notice is written to the GDPR standard throughout, because it is the higher of the two; Swiss-specific points are marked where they differ.
The European Commission confirmed on 15 January 2024 that Switzerland provides an adequate level of data protection. Personal data may therefore flow from the EEA to us without additional safeguards.
3. What we process, why, and on what legal basis
3.1 Visiting the website
| Data | Purpose | Legal basis |
|---|---|---|
| IP address, date and time, page requested, HTTP status, referrer, user agent — recorded in server and edge logs | Delivering the site, security, abuse prevention, diagnosing faults, aggregate volume statistics | GDPR Art. 6(1)(f) legitimate interests — operating a secure and functioning website. FADP: overriding private interest, Art. 31 |
| Security and bot-mitigation signals generated by our content delivery network | Protecting the site against attack, abusive crawling and denial of service | GDPR Art. 6(1)(f). FADP Art. 31 |
| Page path, page title, referring site, device and browser category, page-view time, page-leave timing, and a short-lived cookieless visit identifier. Query strings and URL fragments are stripped. The client IP is used transiently to produce the identifier and then discarded before storage. | Aggregate audience measurement and improving the usefulness and performance of the public website | GDPR Art. 6(1)(f) legitimate interests, balanced by data minimisation, no device storage, no person profile and an objection route. FADP Arts. 6 and 31 |
We use no analytics cookies, advertising pixels, session recording, heatmaps, form or click autocapture, person profiles or cross-site tracking. Supported browser Do Not Track signals are respected. See Cookies and Tracking for the full technical inventory.
3.2 Contacting us by email or requesting the Studio Letter
| Data | Purpose | Legal basis |
|---|---|---|
| Your name, email address, employer or venture, the content of your message, and our correspondence with you | Answering your enquiry, assessing a possible engagement, investment, partnership or role, and keeping a record of the exchange | GDPR Art. 6(1)(b) steps prior to a contract, and Art. 6(1)(f) legitimate interests in responding to business enquiries. FADP Arts. 6 and 31 |
| For a Studio Letter request: your name, email address, firm (if supplied), investor category, jurisdiction, what you requested, eligibility confirmations and any note you add | Assessing whether we may provide the requested investor material, delivering and answering the request, and keeping a record of the exchange | GDPR Art. 6(1)(b) steps prior to a contract, and Art. 6(1)(f) legitimate interests in responding to qualified business enquiries and applying our published distribution restrictions. FADP Arts. 6 and 31 |
| Notes and assessments we make about a prospective venture, partner, investor or candidate | Evaluating and progressing the opportunity | GDPR Art. 6(1)(f). FADP Art. 31 |
Providing this data is voluntary, but we cannot answer an enquiry or send the Studio Letter without a means of replying to you. A Studio Letter submission is processed by a same-origin Cloudflare Pages Function and delivered to our business email. The endpoint keeps no form database or delivery queue. If optional rate limiting is enabled, it keeps a truncated hash derived from the requesting IP address for up to one hour solely to limit automated abuse.
If you pitch us. Where your message contains a venture proposal, a business plan, a deck or comparable material, we hold it only to assess the opportunity and to conduct the conversation. We do not circulate it outside Living Scale Up without asking you first, we do not use it to train AI models, and we do not enter identifiable submissions into AI tools that are not on our approved list. You may ask us to delete it at any time — write to contact@livingscaleup.com and we will delete it and confirm, subject only to anything we must legally retain. What confidentiality does and does not apply, and how to get a non-disclosure agreement in place before you send anything sensitive, is set out in section 8 of the Terms of Use.
3.3 The studio newsletter
| Data | Purpose | Legal basis |
|---|---|---|
| Your email address; the fact, date and time of your subscription request | Sending you the newsletter, and being able to prove that you asked for it | Consent — GDPR Art. 6(1)(a) and Art. 7; ePrivacy Directive Art. 13(1). In Switzerland, prior consent under UCA Art. 3(1)(o) |
| Your name, if you give it | Addressing you properly | Consent, as above |
Subscription is by email, so your request is itself your consent and your own record of it. You may withdraw consent at any time, as easily as you gave it, by using the unsubscribe link in any issue or by writing to contact@livingscaleup.com. Withdrawal does not affect the lawfulness of sending before it. We act on unsubscribe requests immediately and permanently, and keep a minimal suppression record so that we do not contact you again by mistake.
We do not track whether you open our emails or which links you click. We do not sell, rent or share our list, and we do not send third-party advertising. Every issue carries our registered company name, postal address and a working unsubscribe link.
3.4 Client, partner and portfolio relationships
Where we work with you under an engagement, investment or partnership agreement, we process the contact and contractual data needed to perform that agreement, to keep the accounts and records Swiss law requires, and to manage the relationship. Legal bases: GDPR Art. 6(1)(b), Art. 6(1)(c) and Art. 6(1)(f); FADP Arts. 6 and 31. Where an engagement involves personal data belonging to you, the terms of that engagement — including any data processing agreement — govern it in preference to this notice.
3.5 What we do not do
- We do not process special categories of personal data (GDPR Art. 9) or sensitive personal data (FADP Art. 5(c)) through this website, and we ask you not to send any.
- We do not carry out advertising profiling, behavioural targeting, or automated decision-making that produces legal effects for you.
- We do not buy personal data from data brokers for outbound marketing.
4. Who receives your data
We keep the number of processors deliberately small. As at the effective date of this notice they are:
| Recipient | Role and what it receives | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, content delivery and edge security for this website. Receives request metadata including your IP address. | United States, with global edge processing |
| PostHog, Inc. | Cookieless web analytics as our processor. Receives the limited event fields described in section 3.1; EU Cloud stores customer event data in Germany. Client IP storage and person profiles are disabled for this site. | Germany (EU Cloud), with PostHog group and subprocessors subject to contractual safeguards |
| Google Workspace (Google Ireland Ltd / Google LLC) | Business email and calendar. Receives the content of correspondence with us. | European Union and United States |
| Professional advisers, auditors and, where legally required, authorities | Legal, accounting and audit advice; compliance with legal obligations | Principally Switzerland |
Each processor acts on our instructions under a written agreement meeting GDPR Art. 28 and FADP Art. 9, is bound to confidentiality and appropriate security, and may not engage further processors without authorisation. We do not disclose personal data to third parties for their own marketing purposes.
The AI tools we use in our own work are described in the AI Disclosure. We do not enter identifiable client or personal data into AI tools that are not approved and contractually bound not to train on our inputs.
5. Transfers outside Switzerland
Some recipients above are outside Switzerland, including in the United States and the European Economic Area.
Transfers to the EEA and to other states listed in Annex 1 to the Swiss DPO are permitted because the Federal Council has determined that those states provide adequate protection (FADP Art. 16(1)).
For the United States we rely on one or both of the following (FADP Art. 16(2); GDPR Arts. 45–46):
- the recipient's certification under the Swiss–US Data Privacy Framework (in force since 15 September 2024) and, for GDPR-governed transfers, the EU–US Data Privacy Framework; and/or
- standard contractual clauses — the European Commission's clauses as recognised by the Swiss FDPIC with the Swiss amendments — supported by a transfer impact assessment and, where appropriate, additional technical and organisational measures.
You may request a copy of the safeguards in place for a specific transfer. We keep the pending challenge to the EU–US Data Privacy Framework before the Court of Justice of the European Union in view, and will change our arrangements if its legal basis is disturbed.
6. How long we keep it
| Category | Retention |
|---|---|
| Server and edge logs | up to 30 days at the edge, then aggregated |
| Cookieless web analytics events | Up to 24 months for trend analysis, then deleted or irreversibly aggregated |
| Enquiry correspondence that does not lead to a relationship | 24 months from the last exchange, then deleted |
| Studio Letter rate-limit hash, if optional rate limiting is enabled | Up to one hour |
| Venture proposals, decks and pitch material that do not lead to a relationship | 12 months from the last exchange, then deleted. Deleted sooner on request |
| Newsletter subscription and consent record | For as long as you are subscribed, and 3 years after you unsubscribe, to evidence that the sending was lawful |
| Suppression list entry after unsubscribe | Indefinitely, limited to the minimum needed to avoid contacting you again |
| Client, investor and partner contractual records | 10 years from the end of the financial year concerned, as Swiss accounting and record-keeping law requires (Art. 958f CO) |
| Records of a data breach | At least 2 years, as DPO Art. 15 requires |
We delete or anonymise personal data once the purpose has been achieved and no legal retention obligation, and no need to bring or defend a legal claim, requires us to keep it.
7. Your rights
Subject to the conditions and exceptions in the applicable law, you may:
- Ask what we hold about you
- Access to your personal data and to the information needed to exercise your rights — FADP Art. 25, GDPR Art. 15. Free of charge; we normally answer within 30 days.
- Have it corrected
- Rectification of inaccurate or incomplete data — FADP Art. 32(1), GDPR Art. 16.
- Have it deleted
- Erasure where we no longer have a basis to hold it — FADP Art. 32(2), GDPR Art. 17.
- Restrict or object to processing
- Including an absolute right to object to direct marketing at any time — FADP Art. 30(2)(b) and Art. 32(2), GDPR Arts. 18 and 21.
- Receive it in a portable form
- Data you provided to us, in a common electronic format — FADP Art. 28, GDPR Art. 20.
- Withdraw consent
- At any time, as easily as you gave it, without affecting the lawfulness of earlier processing — GDPR Art. 7(3).
- Not be subject to a decision based solely on automated processing
- Including the right to state your position and to have a decision reviewed by a human being — FADP Art. 21, GDPR Art. 22. We take no such decisions.
- Complain to a supervisory authority
- In Switzerland, the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern — edoeb.admin.ch. In the EEA, the supervisory authority of your habitual residence, place of work or place of the alleged infringement — GDPR Art. 77. You may also seek a judicial remedy.
Write to contact@livingscaleup.com. We may need to verify your identity before acting, and we will not use identity documents for any other purpose. We will tell you if a statutory exception prevents us from complying in full, and why.
8. Fonts, hosting and logs
Fonts and analytics. We self-host the two typefaces this site uses. The only browser connections beyond our own host are to PostHog's EU asset and ingestion hosts for the limited cookieless analytics described above.
Hosting and logs. The site is served by Cloudflare Pages. Cloudflare processes request metadata, including your IP address, in order to deliver the site and protect it against attack. Cloudflare acts as our processor under a data processing agreement.
9. Artificial intelligence and automated decisions
Living Scale Up uses artificial intelligence extensively in its own work. What that means, which tools we use, what we do not put into them, and who is accountable, is set out in the AI Disclosure and Editorial Standards. As it affects your personal data:
- We do not use AI to make automated decisions about you that have legal effect or otherwise significantly affect you. If that ever changes we will say so here and honour your right under FADP Art. 21 and GDPR Art. 22 to a human review.
- We do not enter personal data, or identifiable client or partner information, into AI tools that are not on our approved list and contractually bound not to train on our inputs.
- We do not use your personal data to train AI models, and we do not permit our providers to.
- Where you interact with an AI system operated by us or by one of our ventures, you will be told that you are dealing with a machine and not a person.
10. Security and breaches
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss and misuse, having regard to the risk — including transport encryption, access control on a need-to-know basis, multi-factor authentication on business accounts, a short list of vetted providers, and staff instruction. No internet transmission can be guaranteed absolutely secure. Ordinary email is not a secure channel: please do not send us confidential or sensitive information by unencrypted email, and tell us if you need a secure channel.
If a breach of data security is likely to result in a high risk to your personality or fundamental rights, we notify the FDPIC as quickly as possible (FADP Art. 24) and, where the GDPR applies, the competent supervisory authority within 72 hours (GDPR Art. 33). We inform affected individuals where necessary for their protection or where the authority requires it.
11. Children
This site addresses business audiences and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
12. Changes to this notice
We will update this notice when our processing changes or the law does. The version number and effective date are at the top of this page, and we keep superseded versions on file. Where a change materially affects you we will draw attention to it — and where a change requires your consent, we will ask for it rather than assume it.