Return to main page
Legal

Privacy Policy

Last updated: July 2026

This Privacy Policy explains how Dr. Christian Kober, trading as Dr. Christian Kober Advisory, processes personal data when you visit c-kober.com, use the contact form, or communicate in connection with an enquiry or engagement. The website follows a data minimisation approach. It does not use advertising trackers, analytics cookies, marketing cookies, social media plug-ins, or automated decision making.

1. Controller

Dr. Christian Kober
trading as
Dr. Christian Kober Advisory
c/o Bernet
Scherrstrasse 7
8006 Zürich, Switzerland
Email: [email protected]

2. Applicable law and legal grounds

Personal data is processed under the Swiss Federal Act on Data Protection (FADP). The EU General Data Protection Regulation (GDPR) applies only where its territorial scope is met. Where the GDPR applies, processing is based, as appropriate, on legitimate interests in operating, securing, improving, and understanding the use of this website and in communicating with interested persons, on steps requested before entering into a contract or on contract performance, on legal obligations, or on consent where consent is specifically requested.

3. Hosting, content delivery, and server logs

This website is hosted on Cloudflare Pages and delivered through the global network of Cloudflare, Inc. When the website is accessed, Cloudflare processes technical request and security data that may include:

This processing is necessary to deliver the website, maintain availability and security, diagnose errors, prevent misuse, and operate the contact-form function. The operator does not use server logs to create individual visitor profiles. Cloudflare may retain and process service data according to its service configuration, contractual obligations, and legal requirements.

4. Cloudflare Web Analytics

This website uses Cloudflare Web Analytics for aggregate audience and performance measurement. A lightweight JavaScript beacon records page views, visits, page paths, referring sites, approximate country, device type, browser, operating system, page-load information, and Core Web Vitals. It does not use cookies or local storage, and it is not used to fingerprint or identify individual visitors. Cloudflare states that Web Analytics does not collect or use visitors' personal data.

To the extent technical information is treated as personal data under applicable law while it is transmitted, the processing serves the legitimate interests of understanding which content is useful, assessing website performance, and improving the website. Cloudflare currently makes analytics data available for the preceding six months. No advertising, cross-site profiling, or marketing analytics are used.

5. Contact form and email

If you use the contact form, the following information is processed: title, first name, last name, email address, organisation, position or job title, enquiry type, message content, and the time of submission. Technical request data is also processed to deliver and protect the form. Cloudflare Turnstile is used to distinguish legitimate submissions from automated misuse and processes limited browser and request signals for this security purpose.

Providing this information is neither a statutory nor a contractual requirement, but without the mandatory fields the enquiry cannot be processed.

The form is validated and processed by a Cloudflare Pages Function. The resulting message is delivered as a plain-text email through Resend, an email-delivery service operated by Plus Five Five, Inc. in the United States. Resend is used only as the technical relay for contact-form messages. The information is used only to assess and respond to the enquiry, prepare or conduct an engagement, communicate with relevant stakeholders, and document correspondence. No open or click tracking is enabled for these messages. Direct emails are processed by the email providers used by the sender and recipient.

6. Client and business communication

If an enquiry leads to a business relationship, further data may be processed, including contact details, role and organisation, correspondence, contract and billing information, and project information voluntarily provided. This data is used for contract preparation and performance, project delivery, invoicing, accounting, and compliance with legal obligations.

7. Recipients and service providers

Personal data is disclosed only where necessary. Recipients may include:

Personal data is not sold and is not shared with advertisers.

8. International data transfers

Cloudflare and Resend are United States based providers and may process data in the United States, the European Economic Area, and other countries in which they or their documented subprocessors operate. Where a destination does not provide an adequate level of data protection, recognised safeguards are used where required, including data processing agreements, standard contractual clauses, and applicable data privacy framework certifications. Current provider documentation and subprocessor information should be consulted for the precise processing locations and safeguards.

9. Data retention

General enquiries that do not lead to a business relationship are ordinarily deleted within 24 months after the last substantive contact, unless a longer period is needed to establish, exercise, or defend legal claims. Contract, project, invoice, tax, and accounting records are retained for the periods required by law, generally up to ten years where Swiss accounting rules apply. Cloudflare Web Analytics is currently accessible for six months, with Cloudflare aggregating older beacon data as described in its documentation. Provider-side technical logs are retained according to the respective service settings and legal obligations.

10. Security

Appropriate technical and organisational measures are used to protect personal data, including encrypted transmission, access restrictions, and measures intended to limit misuse. No internet transmission or storage system can be guaranteed to be completely secure.

11. Your rights

Subject to applicable law, you may request information about the processing of your personal data, access to the data, correction of inaccurate data, deletion where legally possible, or restriction of processing. Where the GDPR applies, additional rights may include data portability, objection to processing based on legitimate interests, and withdrawal of consent where processing is based on consent.

Requests can be sent to [email protected]. You may also contact the competent supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC). Where the GDPR applies, you may contact the competent EU or EEA supervisory authority.

12. Cookies and similar technologies

This website does not use non-essential cookies or browser storage for analytics, advertising, or marketing. Cloudflare Web Analytics is described in section 4 and operates without cookies or local storage. Turnstile is used only for form security and may set strictly necessary security cookies when required to protect the website. If the technical setup changes, this Privacy Policy and any consent mechanism required by applicable law will be updated before the relevant processing is introduced.

13. Changes to this Privacy Policy

This Privacy Policy may be updated when the website, service providers, or legal requirements change. The version published on this page applies.