1. Controller and contact
For website, account, billing, sales, marketing and business-administration data, the controller is the AlpineLayer legal entity identified in the Legal Notice. Privacy requests may be sent to privacy@alpinelayer.ch.
2. Scope
This Privacy Policy covers AlpineLayer websites, customer portals, cloud and hosting services, sales, support, billing, domain services, security and abuse handling, communications and related business operations where AlpineLayer determines why personal data is processed.
3. Data we collect
- Account data such as name, organization, address, email and telephone.
- Billing, invoice, payment-status and transaction metadata.
- Service metadata including products, domains, IP addresses, resource identifiers and configuration history.
- Support tickets, emails, chat records and troubleshooting information.
- Authentication, IP address, device/browser, security, audit and abuse data.
- Domain-registration information required by registrars or registries.
- Website preference and consent data.
- Marketing preferences and campaign interactions where marketing is used lawfully.
4. Sources
Data may come directly from customers, authorized users, payment processors, registrars, registries, fraud/security providers, infrastructure vendors, public sources and automated service logs. Where data is obtained indirectly, AlpineLayer will provide information when applicable law requires it.
5. Purposes
- Create and administer accounts and contracts.
- Provision, operate, secure and support services.
- Process invoices, payments, tax and accounting records.
- Authenticate users and prevent fraud, abuse and unauthorized access.
- Send service notices and support communications.
- Register and administer domain names.
- Investigate abuse, security incidents and legal claims.
- Improve reliability and usability using data appropriate for that purpose.
- Send marketing where legally permitted and respect opt-out/consent choices.
- Comply with legal obligations and valid legal requests.
6. Legal bases where GDPR applies
Where the GDPR applies, AlpineLayer may rely on contract performance, pre-contract steps, legal obligations, legitimate interests, consent and vital interests. Legitimate interests may include infrastructure security, fraud prevention, customer support, network integrity and business administration, balanced against individual rights.
7. Customer-hosted personal data
For personal data submitted by customers to hosting or cloud services, AlpineLayer generally acts as processor or subprocessor and processes that data to provide, secure, support and terminate the service according to customer instructions and applicable law. The DPA provides additional terms.
8. Domain registration data
Domain services require collection and transmission of registration information to sponsoring registrars, registries, escrow providers and other parties required by applicable domain policies. The exact data, retention, publication and disclosure rules depend on the top-level domain and registrar. Customers must keep registrant information accurate.
9. Payments and fraud
Payment credentials may be collected directly by payment processors rather than stored by AlpineLayer. AlpineLayer receives transaction identifiers, payment status and information needed for billing, reconciliation and fraud prevention. Security and fraud signals may be used to request additional verification or delay provisioning.
10. Cookies and similar technologies
This static build enables only essential preference storage by default. Non-essential analytics and marketing are disabled. If those technologies are later introduced, they should remain technically blocked until any required consent or other legal basis is obtained. See the Cookie Policy.
11. Recipients and subprocessors
Data may be shared with infrastructure providers, payment processors, registrars and registries, licensing/software vendors, backup providers, email/support suppliers, fraud/security vendors, professional advisers, authorities where legally required and other suppliers necessary to deliver services. The current processor list should be maintained on the Subprocessor List.
12. International transfers
Processing may occur outside Switzerland depending on the selected service, support function or supplier. Where a destination does not provide the legally required level of protection, AlpineLayer will use appropriate safeguards or another lawful mechanism. Where GDPR applies, applicable adequacy decisions or standard contractual clauses may be used. Contractual data-residency commitments apply only where expressly stated for a product.
13. Retention
Data is retained only as long as reasonably necessary for service delivery, security, dispute handling and legal obligations. Accounting, domain, security and abuse records may have different retention periods. Service data and backups are deleted according to product lifecycle and backup schedules. See the Data Retention & Deletion Policy.
14. Security
AlpineLayer uses administrative, technical and organizational controls appropriate to the service, including access controls, authentication, network security, logging, backup practices and incident handling. No system can guarantee absolute security.
15. Your rights
Depending on applicable law, individuals may have rights of access, correction, deletion, restriction, portability, objection, withdrawal of consent and information about processing or transfers. Requests may be submitted to privacy@alpinelayer.ch. Identity may be verified before a response. If AlpineLayer acts only as processor, the request may be referred to the relevant customer.
16. Complaints
Individuals may first contact AlpineLayer. Where applicable, they may also complain to a competent data-protection authority, including the Swiss Federal Data Protection and Information Commissioner or an EU/EEA authority when GDPR applies.
17. Children
AlpineLayer infrastructure services are intended for businesses, professionals and users capable of entering service contracts. AlpineLayer does not intentionally target children with marketing.
18. Changes
This policy may be updated as products, suppliers, laws and processing activities evolve. Material changes will be communicated where required.
19. Privacy contact
Privacy: privacy@alpinelayer.ch. Legal: legal@alpinelayer.ch. The final legal entity and postal address must be added to the Legal Notice before launch.