Privacy notice
How Helvetic Fidelity handles the personal data you give us when you join the waitlist.
Who is responsible
TODO legal: controller name (Helvetic Fidelity AG), registered address, UID, and privacy contact email.
What we collect
TODO legal: confirm wording. Facts: email address; where you live (Switzerland / United Kingdom / elsewhere); optional, only if you answer the two questions shown after you confirm: how you earn and which phone you use; the site language; the privacy-notice version you saw; sign-up, confirmation and last-email times, and how many confirmation emails we sent you in the last 24 hours (to stop abuse). For abuse protection only: a keyed hash of your IP address, kept about 20 minutes. If you choose Continue on the entry notice, your browser stores that choice (and nothing about you) for 30 days. No tracking cookies, no analytics. Website analytics (no cookies, nothing stored on your device, no third parties): when you use the home page we record which sections you scroll to, which buttons and questions you open, how far you get in the waitlist form, page-speed measurements, your language, a screen-size category (phone, tablet or desktop) and how you reached us (the campaign tags in the link and the referring website’s name — never the full address). These events are tied only to a random number made for that one page view and kept in your browser’s memory, not to you, your email or your IP address. If your browser sends Global Privacy Control or Do Not Track, none of this is recorded. With your sign-up we also keep how you first reached us (for example “LinkedIn, social, 2026-10-launch”), so we can tell which channels bring people who join.
Why we collect it
TODO legal: legal basis. Facts: to invite you to open an account when we launch, and to decide which features to build first. Double opt-in: nothing is used until you confirm by email. Analytics: to see which channels bring people who join, where the page or form is hard to use, and what visitors want to know, so we can improve the site and spend wisely.
Who receives it
TODO legal: confirm wording and safeguards. Facts: Cloudflare, Inc. hosts the site and stores the waitlist in a Cloudflare D1 database restricted to the EU jurisdiction. Cloudflare also runs the Turnstile bot check, which loads from challenges.cloudflare.com only when you reach the waitlist form and processes technical browser signals and your IP address. Emails are sent by Resend (Resend, Inc., USA) from its EU sending region (Ireland); Resend receives your email address and the email’s content to deliver it. Because Resend is a US company, this is a cross-border disclosure that needs a safeguard (to confirm: Swiss-US Data Privacy Framework certification or standard contractual clauses). Open and click tracking are switched off. Analytics events are stored in the same Cloudflare D1 database (EU jurisdiction) and are not shared with anyone else; no advertising or analytics companies receive data.
How long we keep it
TODO legal: confirm, and fill in the backup window for our Cloudflare plan and the mail provider's log period. Facts: unconfirmed sign-ups are deleted 7 days after sign-up (an hourly job checks); confirmed sign-ups are kept until we launch or you unsubscribe; unsubscribing (link in every email) deletes your data immediately from the live database. The database's point-in-time backups (Cloudflare D1 Time Travel) keep deleted data restorable for up to 30 days (7 days on Cloudflare's free plan) before it is gone for good; we only restore backups to recover from incidents. Resend keeps its own sending logs for a period set by that provider. Website analytics events are deleted after about 13 months (the same hourly job).
Your rights
TODO legal: access, correction, deletion, data portability and objection under the Swiss Federal Act on Data Protection (FADP), and how to exercise them ([email protected]).
Changes to this notice
TODO legal: how changes are announced and the effective date. The version shown at sign-up is stored with each entry (CONSENT_VERSION).