Kroemtech

OT security and industrial connectivity

Privacy Policy — www.kroemtech.ch

Version: 2.0

Last Updated: 20.08.2026

Only the English version of this Privacy Policy is legally binding.

1. Scope

This Privacy Policy explains how Kroemtech GmbH processes personal data in connection with the website www.kroemtech.ch.

It does not cover the dathaScy platform. Data processing in connection with the platform is governed by separate documentation provided to customers, including the platform Privacy Policy and the Data Processing Agreement.

2. Controller

The controller responsible for the processing described here is:

Kroemtech GmbH

Christoph Merian-Ring 11

CH-4153 Reinach/BL

Switzerland

info@kroemtech.com

3. Applicable Law

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies, we comply with it, and references to GDPR provisions include the corresponding provisions of the FADP. Section 10 contains additional information for visitors in Brazil.

4. What We Collect, Why, and on What Basis

4.1 Contact form

When you use the contact form we process the data you enter — typically your name, e-mail address, company, and the content of your message.

Your submission is transmitted directly from your browser to our own application interface hosted in Switzerland, and is then forwarded to our e-mail system. It is not processed by GitHub, the provider that hosts the pages of this website, and it is not handled by any third-party form service.

Purpose: to receive, assess, and respond to your enquiry, and to take steps at your request prior to entering into a contract.

Legal basis: pre-contractual steps and performance of a contract (Art. 6(1)(b) GDPR); our legitimate interest in responding to business enquiries (Art. 6(1)(f) GDPR).

Retention: if the enquiry does not lead to a business relationship, we delete it 12 months after our last correspondence with you. If a business relationship does arise, the correspondence becomes part of our business records and is retained for 10 years in accordance with Art. 958f of the Swiss Code of Obligations.

Providing this data is voluntary, but without it we cannot respond to your enquiry.

Please note: we ask that you do not send confidential or security-sensitive information — such as vulnerability details, network diagrams, or incident information — through the contact form. See Section 4 of the Terms of Use.

4.2 Website hosting

The pages of this website are hosted on GitHub Pages, a static hosting service operated by GitHub, Inc. and GitHub B.V. (see Section 6). When you load a page, GitHub automatically processes the technical data required to deliver it and to protect its infrastructure, including your IP address, device and browser information, and the date and time of your request. GitHub receives no data that you enter into the contact form.

Purpose: delivery of the website, and the security, stability, and abuse prevention of the hosting infrastructure.

Legal basis: our legitimate interest in making the website available securely and reliably (Art. 6(1)(f) GDPR).

Retention: this data is held by GitHub under its own retention practices. We do not receive access to these logs and cannot retrieve, analyse, or delete them. Further information is available in the GitHub Privacy Statement: https://docs.github.com/site-policy/privacy-policies/github-privacy-statement

4.3 Contact form infrastructure

Contact form submissions are received by our own application interface, which runs on infrastructure operated by Akenes SA (Exoscale) in Switzerland. In the course of receiving a submission, our interface records technical data including the IP address from which the request was sent and the date and time of the request.

Purpose: to receive and forward your enquiry, and to protect the interface against abuse, automated submissions, and attacks.

Legal basis: our legitimate interest in the secure operation of the interface (Art. 6(1)(f) GDPR).

Retention: 90 days.

4.4 No analytics or tracking

This website does not use Google Analytics or any other web analytics service. We do not track visitors across pages or across websites, we do not create visitor profiles, and we do not use advertising, remarketing, or social media tracking technologies.

5. Cookies

A cookie is a small text file stored on your device when you visit a website.

This website sets a single cookie, which records that you have acknowledged our privacy notice so that the notice is not displayed again on every page you visit. It is necessary for that function, contains no information that identifies you, and is not shared with anyone.

CookiePurposeDurationProvider
kroemtechGpdrRecords that the privacy notice has been acknowledged6 monthsKroemtech (first-party)

We set no analytics, advertising, profiling, or tracking cookies, and no third party sets cookies through this website.

You can configure your browser to block or delete cookies at any time. If you delete this cookie, the privacy notice will be displayed again on your next visit.

6. Recipients and International Transfers

We do not sell or rent personal data, and we do not share it for advertising purposes.

Personal data processed in connection with this website is accessible to the following recipients:

1. Website hosting — GitHub B.V., Prins Bernhardplein 200, 1097 JB Amsterdam, Netherlands, and GitHub, Inc., 88 Colin P. Kelly Jr. St., San Francisco, CA 94107, United States.

GitHub hosts the pages of this website and processes the technical data described in Section 4.2, in the United States and in other countries in which it operates infrastructure. GitHub does not receive contact form submissions. Transfers to the United States are covered by appropriate safeguards: GitHub has certified its compliance with the EU–U.S. Data Privacy Framework and its Swiss–U.S. extension, and additionally relies on the Standard Contractual Clauses published by the European Commission. GitHub’s Data Protection Agreement is available at https://github.com/customer-terms/github-data-protection-agreement

2. Application infrastructure — Akenes SA (trading as Exoscale), Boulevard de Grancy 19A, 1006 Lausanne, Switzerland.

Akenes SA operates the Swiss infrastructure on which our application interface runs, and processes contact form submissions and the technical data described in Section 4.3 on our instructions. Processing takes place in Switzerland; no transfer abroad occurs.

3. E-mail — Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Les Acacias (Geneva), Switzerland (UID CHE-103.167.648).

Infomaniak operates our e-mail system on our instructions and processes the enquiries forwarded to it from the contact form. Processing takes place in Switzerland; no transfer abroad occurs.

The content of contact form submissions is processed exclusively in Switzerland. It does not pass through GitHub or any third-party form service, and it is not transferred outside Switzerland at any point.

Beyond the above, personal data is disclosed only where required by law or a binding order of a court or authority.

7. Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, and destruction. This website, and the interface that receives contact form submissions, use TLS encryption, indicated by the “https://” prefix and the lock symbol in your browser.

8. Your Rights

You have the right to request confirmation as to whether we process personal data about you and, if so, to access that data. You may also request the correction of inaccurate data, the deletion of your data, and the restriction of processing, and you may receive data you provided in a structured, commonly used, machine-readable format. Where processing is based on consent, you may withdraw that consent at any time with effect for the future. Where processing is based on our legitimate interests, you may object to it on grounds relating to your particular situation.

To exercise any of these rights, contact us at info@kroemtech.com.

You also have the right to lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern. If the GDPR applies to you, you may complain to the supervisory authority of the EU Member State in which you reside or work.

9. External Links

This website may link to third-party websites. We are not responsible for their content or their data protection practices. Please review their privacy notices directly.

10. Information for Visitors in Brazil

If you are in Brazil, the Brazilian General Data Protection Law (Law No. 13.709/2018, “LGPD”) applies to our processing of your personal data. In addition to the rights described in Section 8, you have the rights set out in Article 18 LGPD, including confirmation of processing, access, correction, anonymisation or deletion, information about data sharing, and revocation of consent. Requests may be sent to info@kroemtech.com. You may also lodge a complaint with the Brazilian National Data Protection Authority (ANPD).

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The current version and its date appear at the top of this page. Please review it before submitting personal data through this website.

12. Contact

Questions about this Privacy Policy, or requests to exercise your rights:

Kroemtech GmbH

Christoph Merian-Ring 11

CH-4153 Reinach/BL, Switzerland

info@kroemtech.com