Skip to content
Legal

Privacy Policy

Cyberdise AG · Last updated: 26 September 2026

This Privacy Policy explains how Cyberdise AG (“Cyberdise”, “we”, “us”) collects, uses, discloses and protects Personal Information when you visit our websites, communicate or interact directly with us, or otherwise engage with Cyberdise in circumstances where Cyberdise acts as an independent Data Controller.

Controller — Cyberdise AG, Poststrasse 26, 6300 Zug, Switzerland

Data Protection contact — dpo@cyberdise.io

Scope — Cyberdise websites and direct business interactions where Cyberdise determines the purposes and means of processing

Customer service data — Where Cyberdise processes Personal Data on behalf of a Customer as Data Processor, the DPA and the Customer’s instructions govern that processing rather than this Privacy Policy.

1. Scope

This Privacy Policy applies to websites on which it is linked, including Cyberdise web properties, and to direct interactions with Cyberdise such as sales inquiries, account administration, support communications, events, newsletters and business correspondence where Cyberdise acts as Controller.

This Privacy Policy does not govern Personal Data that Cyberdise processes solely on behalf of a Customer as Data Processor in connection with the Cyberdise Suite. That processing is governed by the applicable Customer agreement and DPA. It also does not govern employee or job-applicant processing covered by separate internal notices, or third-party services that operate under their own privacy policies.

2. Personal Information We Collect

Depending on how you interact with Cyberdise, we may collect the following categories of Personal Information:

  • identification and contact information, such as name, business email address, telephone number, postal or billing address and organization;
  • professional and business information, such as employer, job title, role, business relationship and communications with Cyberdise;
  • commercial and transaction information, such as product inquiries, purchases, subscription and billing information, event participation and support history;
  • internet, device and usage information, such as IP address, device and browser information, referring pages, pages viewed, timestamps, cookie identifiers and interaction logs;
  • communications content, such as emails, web-form submissions, support messages and, where lawfully recorded with appropriate notice, call or meeting recordings;
  • marketing preferences and information about engagement with newsletters, campaigns or events;
  • other information you choose to provide to Cyberdise.

We do not intentionally collect special-category or highly sensitive Personal Information through our public websites unless it is necessary for a specific interaction and permitted by law. Please do not submit such information through general website forms unless requested and appropriate.

3. How We Collect Personal Information

We collect Personal Information directly from you when you contact us, create or administer a business account, request information, register for an event, communicate with support or sales, subscribe to communications, or otherwise interact with Cyberdise.

We also collect certain information automatically through cookies, logs and similar technologies when you use our websites. We may receive limited business information from partners, event organizers, public business sources or social-media platforms where permitted by law and consistent with your settings on those services.

We process Personal Information for the following purposes, where supported by an applicable legal basis such as performance of a contract, legitimate interests, consent, or compliance with legal obligations:

  • to operate, secure, maintain and improve our websites and direct business services;
  • to respond to inquiries, provide quotations, administer contracts and customer relationships, process billing and maintain business records;
  • to provide account administration, support and service communications;
  • to detect, prevent and investigate fraud, abuse, security incidents and technical issues;
  • to analyze website performance and understand how our public web properties are used;
  • to send marketing communications, invitations, newsletters and product information where permitted by law and according to your preferences;
  • to comply with legal, regulatory, tax, accounting and law-enforcement obligations and to establish, exercise or defend legal claims;
  • to manage corporate transactions such as mergers, acquisitions, reorganizations or asset transfers.

5. Cookies and Similar Technologies

Our websites use cookies and similar technologies, such as local storage in your browser. Some are strictly necessary to deliver the website and keep it secure. Others, for statistics and marketing, are used only if you consent.

Your choice on cyberdise.io

When you first visit cyberdise.io, a banner asks for your choice. You can accept all, reject all, or choose per category. Until you decide, and whenever you reject, only necessary technologies are used. No analytics or marketing script is loaded, and no data is sent to Google or LinkedIn. Every visitor gets the same choice, regardless of country.

The categories are:

  • Necessary (always active): delivering the website, protecting our forms against spam and abuse, and remembering your choices on this device.
  • Statistics: Google Analytics 4, which tells us how the website is used (see section 6).
  • Marketing: Google Ads conversion tracking and the LinkedIn Insight Tag, which measure our advertising (see section 6).

Your choice is stored in your browser’s local storage, together with the date and the version of the banner. It is not sent to us. We ask again after 12 months, or earlier if we change the banner. You can change or withdraw your choice at any time via “Cookie settings” at the bottom of every page. A withdrawal takes effect for the future, and the page reloads. You can also delete cookies and local storage in your browser settings.

Cookies and storage used on cyberdise.io

Necessary

  • Your consent choice: local storage on cyberdise.io, 12 months.
  • cd-theme: your light or dark display preference, set only if you use the switch in the footer. Local storage on cyberdise.io, until you delete it.
  • Cloudflare Turnstile, once you start filling in one of our forms: checks technical signals to tell people from bots (see section 7).
  • If our hosting provider shows you a security check, it stores a technical session in your browser for about one hour.

Statistics: Google Analytics 4, set on cyberdise.io

  • _ga: distinguishes visitors. 2 years.
  • _ga_<ID>: keeps the state of your visit. 2 years.

Marketing: Google Ads and LinkedIn

  • _gcl_au: Google Ads, links ad clicks to conversions. 90 days, set on cyberdise.io.
  • _gcl_aw, _gcl_gs: Google Ads click information. 90 days, set on cyberdise.io.
  • li_fat_id: LinkedIn, member identifier for conversion tracking, retargeting and analytics. 30 days, set on cyberdise.io.
  • li_sugr (90 days), bcookie (1 year), lidc (24 hours), UserMatchHistory (30 days), AnalyticsSyncHistory (30 days), lms_ads (30 days), lms_analytics (30 days): set by LinkedIn on linkedin.com. LinkedIn lists every cookie it may use in its cookie table.

6. Analytics, Advertising and Social Media

Cyberdise may use third-party analytics, advertising and social-media services in connection with its public websites and marketing activities. Such providers may process identifiers, device information and usage data under their own privacy terms. Where required, Cyberdise uses consent controls and contractual safeguards for these services.

On cyberdise.io we use the following services, each only after you have consented to its category (see section 5). They run only on cyberdise.io.

Google Analytics 4 (Statistics)

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data may also be processed by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

What and why: Google Analytics records which pages you visit and when you successfully send one of our forms (contact, pricing request, newsletter sign-up). It also records device and browser information, an approximate location and a pseudonymous identifier, which is stored in the cookies listed in section 5. According to Google, Google Analytics does not log or store IP addresses of visitors from the EU, Switzerland or the UK. We use it to understand how our website is used and to improve it.

Legal basis: your consent (Statistics). You can withdraw it at any time via “Cookie settings”.

Retention: the cookies expire after 2 years at most. Google Analytics keeps user-level and event-level data for at most 14 months.

Transfer: Google LLC is certified under the EU-U.S. and the Swiss-U.S. Data Privacy Framework (see section 8).

Provider: Google Ireland Limited (address above). Data may also be processed by Google LLC, USA.

What and why: when you send our contact form, Google Ads records a “Demo Request” conversion. Through the cookies listed in section 5, it links the conversion to an earlier click on one of our Google ads. We use this to measure which ads lead to enquiries. Google also processes this data under its own privacy policy.

Legal basis: your consent (Marketing).

Retention: the cookies expire after 90 days.

Transfer: as for Google Analytics.

LinkedIn Insight Tag (Marketing)

Provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland. Data may also be processed by LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA.

What and why: the Insight Tag sends LinkedIn the address of the page you visit, the referring page, your IP address, device and browser characteristics, and the time. If you are a LinkedIn member, LinkedIn can link the visit to your account. We use it to measure whether our LinkedIn advertising leads to visits and enquiries. LinkedIn also processes this data under its own privacy policy.

Legal basis: your consent (Marketing).

Retention: according to LinkedIn, IP addresses are truncated or hashed, and members’ direct identifiers are removed within seven days. The remaining pseudonymized data is deleted within 180 days. The cookies expire as listed in section 5.

Transfer: LinkedIn Corporation is certified under the EU-U.S. and the Swiss-U.S. Data Privacy Framework (see section 8).

7. How We Share Personal Information

We may disclose Personal Information to:

  • service providers that support hosting, communications, analytics, customer relationship management, billing, security, professional services or other business operations;
  • Cyberdise affiliates and authorized personnel who need the information for the purposes described in this Policy;
  • business partners where necessary to respond to a joint inquiry, deliver an agreed service or manage a partner relationship;
  • professional advisers, auditors, insurers and financial institutions where reasonably necessary;
  • courts, regulators, law-enforcement bodies or other authorities where disclosure is required or permitted by law;
  • a purchaser, successor or transaction counterparty in connection with a merger, acquisition, financing, reorganization or sale of all or part of the business, subject to appropriate confidentiality protections.

Cyberdise does not sell Personal Information in exchange for monetary payment. Where applicable law uses broader definitions of “sale” or “sharing” for targeted advertising, Cyberdise will provide any required notices and opt-out mechanisms.

Service providers for this website

The following providers process data on our behalf to run cyberdise.io. They are always active, because the website cannot be delivered or protected without them.

Vercel (hosting and delivery): Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Vercel delivers the website to your browser. For each request it processes your IP address, the location derived from it, browser information and the requested page, and keeps them in request logs for up to 30 days. Legal basis: our legitimate interest in a secure, working website. Transfer: EU-U.S. and Swiss-U.S. Data Privacy Framework, with Standard Contractual Clauses in Vercel’s data processing agreement.

Sanity (content management and media delivery): Sanity AS, Trondheimsveien 2K, 0560 Oslo, Norway, and Sanity US Inc., 351 California Street, Suite 650, San Francisco, CA 94104, USA. We manage the content of this website in Sanity. Some media files, such as the videos on our webinars page, are delivered to your browser directly from Sanity’s content delivery network. For that, Sanity processes your IP address and browser information and may log the request. Nothing you enter in our forms is stored in Sanity. Legal basis: our legitimate interest in delivering the website. Transfer: Sanity is not certified under the Data Privacy Framework. Transfers to the USA are based on the EU Standard Contractual Clauses, with the Swiss adaptations in Sanity’s data processing agreement.

Cloudflare Turnstile (spam and bot protection): Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. When you start filling in one of our forms, Turnstile checks whether the request comes from a person. It processes technical signals such as your IP address, TLS fingerprint and browser (user agent). It does not read what you enter in the form. Legal basis: our legitimate interest in protecting our forms against spam and abuse. Transfer: EU-U.S. and Swiss-U.S. Data Privacy Framework.

Resend (delivery of form messages): Plus Five Five, Inc. (“Resend”), 2261 Market Street #5039, San Francisco, CA 94114, USA. When you send our contact or pricing form, Resend delivers your message by e-mail to our team. Resend stores the message and its delivery logs in the USA for 30 days. Legal basis: answering your request, including steps before a contract, and our legitimate interest in handling enquiries. Transfer: EU-U.S. Data Privacy Framework. For data from Switzerland, the Standard Contractual Clauses with Swiss adaptations in Resend’s data processing agreement apply, because Resend is not certified under the Swiss-U.S. framework.

SendPulse (newsletter): see section 12.

8. International Transfers

Cyberdise is based in Switzerland and may use service providers or business systems in Switzerland, the EEA, the United Kingdom, the United States or other jurisdictions. Where Personal Information is transferred to a jurisdiction that does not provide an adequate level of protection under applicable law, Cyberdise uses appropriate safeguards such as approved Standard Contractual Clauses, the required Swiss adaptations or addendum, the UK transfer addendum, or another lawful transfer mechanism.

For transfers to the United States, we rely on the EU-U.S. Data Privacy Framework and, for data from Switzerland, on the Swiss-U.S. Data Privacy Framework, where the recipient is certified. The Swiss Federal Council has recognized the latter as providing adequate protection since 15 September 2024. On the date of this policy, Google LLC, LinkedIn Corporation, Vercel Inc. and Cloudflare, Inc. are certified under both frameworks, and Resend under the EU-U.S. framework. For Sanity and SendPulse, which are not certified, and for Resend under Swiss law, we rely on Standard Contractual Clauses. You can check a company’s certification on the Data Privacy Framework list.

9. Security

Cyberdise uses reasonable administrative, technical and physical safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, loss or destruction. Measures may include access controls, encryption, secure authentication, logging, monitoring, backups, vulnerability management and staff confidentiality obligations, as appropriate to the processing.

No method of transmission or storage can be guaranteed to be completely secure. If you believe your interaction with Cyberdise is no longer secure, contact us promptly at dpo@cyberdise.io or support@cyberdise.io.

10. Data Retention

Cyberdise retains Personal Information only for as long as reasonably necessary for the purposes described in this Policy, including the duration of the relevant business relationship and any additional period required for legal, tax, accounting, security, dispute-resolution or recordkeeping obligations. Retention periods vary depending on the type of information and the reason for processing.

Where information is no longer required, Cyberdise deletes, anonymizes or securely disposes of it in accordance with applicable retention procedures, subject to lawful retention obligations and routine backup cycles.

11. Your Data Protection Rights

Depending on the law applicable to you, you may have rights to request access to Personal Information, correction of inaccurate information, deletion, restriction of processing, objection to certain processing, data portability, withdrawal of consent, or information about international transfer safeguards. You may also have the right to lodge a complaint with a competent data protection authority.

To exercise a right, contact dpo@cyberdise.io. We may need to verify your identity and may request information reasonably necessary to locate the relevant records. We will respond within the period required by applicable law.

12. Marketing Choices

You may unsubscribe from marketing emails using the unsubscribe mechanism in the message or by contacting Cyberdise. We may continue to send non-marketing communications that are necessary for an existing contractual or business relationship, such as service, security, billing or legal notices.

Newsletter: If you sign up for our newsletter on this website, we first send you an e-mail asking you to confirm your address, and add it to our mailing list only once you have confirmed. We use SendPulse (SendPulse Inc., 220 E 23rd St #401, New York, NY 10010, USA) to send this confirmation e-mail and the newsletter. SendPulse processes your e-mail address on our behalf, on servers in the United States and Germany. SendPulse is not certified under the Data Privacy Framework, so transfers are based on the Standard Contractual Clauses in SendPulse’s data processing agreement. Legal basis: your consent, which you give by confirming your address. You can unsubscribe at any time using the link in every newsletter.

13. Children

Cyberdise’s public websites and business services are not directed to children under 16, and Cyberdise does not knowingly collect Personal Information from children under 16 through its public websites. If you believe a child has provided Personal Information to us through a public site, contact dpo@cyberdise.io.

14. Third-Party Websites

Our websites may contain links to third-party websites or services. Cyberdise is not responsible for the privacy practices of third parties. Review the privacy notices of those services before providing Personal Information to them.

15. Changes to this Privacy Policy

Cyberdise may update this Privacy Policy to reflect changes in law, technology, business practices or the services. The current version will be published with an updated revision date. Where required by law, we will provide additional notice of material changes.

16. Contact and Complaints

Cyberdise AG, Poststrasse 26, 6300 Zug, Switzerland

Data Protection: dpo@cyberdise.io · Support: support@cyberdise.io · Website: www.cyberdise.io

You may also contact the competent data protection supervisory authority in your jurisdiction. In Switzerland, the competent federal authority is the Federal Data Protection and Information Commissioner (FDPIC).