Privacy Policy
This page explains what personal data we collect on visilay.com, why we process it, who else sees it and what you can ask us to do. Cookies and measurement tools have their own page: the cookie policy.
Who processes your data
Mirko Rotelli, sole proprietorship trading as Visilay
Via Odescalchi 14, 6830 Chiasso, Switzerland
UID: CHE-421.016.871
Email: [email protected]
Phone: +39 375 837 4005
We have not appointed a data protection officer, because our activity does not fall into the cases where that appointment is mandatory. Write to the address above for anything related to this notice.
Which rules apply
Visilay is based in Switzerland, so processing follows the Federal Act on Data Protection (FADP, SR 235.1) and its ordinance. The site also addresses companies and professionals in the European Union, so for anyone in the EU or the European Economic Area we apply Regulation (EU) 2016/679 (GDPR) as well. Where the two sets of rules ask for different things, we follow the stricter one.
What we collect and why
| When | Data | Why | Legal basis | How long |
|---|---|---|---|---|
| You open a page on the site | IP address, browser and device type, pages viewed, date and time, referring page | Serving the pages, keeping the site safe from abuse, tracing errors | Legitimate interest (Art. 6(1)(f) GDPR), Art. 31 FADP | Logs stay on the hosting provider's server for as long as security and diagnostics require |
| You fill in the contact form | Full name, business email, business phone number, company, text of your request | Replying and, where relevant, preparing a quote | Pre-contractual steps (Art. 6(1)(b) GDPR) | 24 months from the last exchange, unless a contract follows |
| You apply through the "Work with us" form | Full name, email, role you are applying for, cover letter | Assessing the application and getting back to you | Pre-contractual steps and consent | 12 months from submission, then deleted |
| You subscribe to the newsletter | Email address | Sending you what we publish | Consent (Art. 6(1)(a) GDPR) | Until you unsubscribe |
| You book a call from the calendar | Name, email, the slot you pick and whatever you write in the booking form | Setting the meeting and sending the invitation | Pre-contractual steps | 24 months from the last appointment |
| You open the WhatsApp chat from the site | Phone number, profile name, message content | Answering your request | Pre-contractual steps | 24 months from the last message |
| You set your choices in the cookie panel | Consent identifier, date, categories enabled, notice version, truncated IP address, user agent | Being able to show that consent was collected and how | Legal obligation (Art. 7(1) GDPR) | 24 months |
We do not use your data for automated decision-making, and we do no individual profiling beyond the advertising tools described in the cookie policy, which run only with your consent.
Who else sees the data
We share data only with the providers we need to run the site and the business, under a contract that binds them to process it on our behalf and for nothing else:
- Netsons S.r.l., Italy, for website hosting and email.
- Google Ireland Limited, for Google Analytics 4, Google Tag Manager, Google Ads and reCAPTCHA.
- Meta Platforms Ireland Limited, for the Meta Pixel and for conversations started on WhatsApp.
- LinkedIn Ireland Unlimited Company, for the Insight Tag.
- Microsoft Ireland Operations Limited, for Microsoft Clarity.
- Calendly LLC, United States, for call bookings.
Beyond those, data may be seen by consultants and collaborators working with us on a project, always within what the work requires, and by public authorities where a rule obliges us. We do not sell personal data and do not pass it to third parties for their own marketing.
Transfers outside Switzerland and the European Economic Area
Some providers belong to groups with US companies and may process data there. Those transfers rest on an adequacy decision of the European Commission or the Swiss Federal Council (including the EU-US Data Privacy Framework and the Swiss-US framework), or on standard contractual clauses together with the technical measures the provider documents. Ask [email protected] if you want a copy of the safeguards in place.
How we keep data safe
The site runs over HTTPS. Access to the admin area is limited to named accounts with passwords that are not reused elsewhere. Backups are encrypted and kept by the hosting provider. No measure removes risk entirely: if a breach occurs that is likely to result in a high risk to you, we will tell you and notify the competent authority within the applicable deadlines.
What you can ask for
At any time you can ask to:
- know what data we hold about you and get a copy of it;
- correct anything wrong or incomplete;
- have it deleted, when we have no reason to keep it;
- restrict processing or object to it, for instance to marketing use;
- receive it in a machine-readable format or have it sent to another controller;
- withdraw a consent you gave, without affecting what was lawful before.
Write to [email protected]. We answer within 30 days; if the request is complex we say so and explain how long it will take. For cookie choices there is no need to write: you can reopen the panel whenever you like.
If our answer does not satisfy you
You can contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern. If you are in the European Union you can lodge a complaint with the supervisory authority of your country: in Italy that is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome.
Minors
visilay.com addresses companies and professionals. We do not knowingly collect data from people under 16. If you notice that it happened, write to us and we will delete it.
Updates
When we change tools or purposes we update this page and the date at the top. If the change concerns processing based on your consent, we ask you again before going ahead.