Securely Attached

Privacy notice

DE·EN

As of 24 August 2026 · Swiss Data Protection Act (DSG)

This is a translation for your convenience. The legally binding version is the German one at securely-attached.ch/datenschutz.html. Where the two differ, the German text applies.

1. Responsible person

Responsible for processing the data is Lorin Both, Kirchlindach, Switzerland, under the name Securely Attached. The full address and the email are in the imprint. Questions about data protection go there too.

There is no obligation to appoint a data protection advisor, and none is appointed.

2. The self-test

The test runs entirely in your browser. The twelve answers and the two calculated values are not sent to the server, not stored in a database and not held in cookies or in the browser's local storage. They exist only while the page is open.

If you buy after the test, an order reference like sa-anx-a34v18-mfk2q1-s7f3a91c4e02b8d6 goes to Stripe. It contains the workbook chosen, the two rounded test values, a timestamp and the session token from section 3. The reference serves to match the payment to the right PDF and to see at which point on the site a purchase comes about. It contains no name, no address and nothing that makes you identifiable to third parties.

3. Counting the steps on this site

To see at which point visitors drop out, this website counts individual steps: that the homepage was loaded, which sections came into view, that the test was started, which of the twelve questions somebody stopped at, which of the four results came out, that the checkout card was opened or closed again, and that a download was clicked.

Not counted and not stored: the twelve individual answers, your IP address, your browser identifier, your email address. No cookie is set and nothing is placed in the browser's persistent storage. That is also why there is no consent banner.

The steps stay together through a sixteen-character token that your browser generates itself, for example 7f3a91c4e02b8d6a. It sits in the tab's session storage (sessionStorage) and is gone as soon as you close the tab. On your next visit a new token is created, and there is no way to connect the two visits. No link to your person arises from it.

Additionally stored are the class of your screen (phone, tablet or desktop), the language version you are reading, and the hostname of the page you came from, so for example google.com. Not the full address and not your search term.

The data sits in a file on the same server as the website, outside the publicly reachable area. It is passed to nobody, no third-party service is involved, and there is no connection to Google Analytics or any similar tool. Entries older than 180 days are deleted.

If your browser sends Do Not Track or Global Privacy Control, nothing is counted at all. Both can be switched on in the settings of most browsers.

4. Hosting

The website runs at Hostinger on servers in France. Apart from the counting of steps in section 3, we store nothing when the website is loaded: no cookies, no advertising identifiers, no IP addresses.

Technically unavoidable is that Hostinger's web server processes details such as IP address, time and requested file when delivering a page. We do not evaluate those details and do not combine them with anything. What Hostinger keeps of it and for how long is governed by Hostinger's own terms.

5. Purchase and payment

Payment is handled by Stripe Payments Europe Ltd., Dublin, Ireland, with other Stripe entities involved. In doing so, Stripe processes your email address, the payment details and technical data for fraud detection. You enter those details directly with Stripe; they do not pass through this website.

From Stripe we receive: email address, amount, time, payment method, the order reference and a session reference. We never receive card numbers.

Stripe also processes data in the USA. The basis for this is the standard contractual clauses together with additional safeguards. Details are in Stripe's privacy policy: stripe.com/ch/privacy.

6. Delivery of the PDF

Delivery works without sending mail. After the confirmed payment we store, against your Stripe session reference, a time-limited download link which the confirmation page picks up. Stored in the process are only the payment reference in encrypted form, the workbook purchased, the order reference and a timestamp. No address, no name.

The link is valid for seven days and allows up to eight retrievals. For that we keep a counter tied to the signature of the link.

If we send you the PDF by hand on request, we process the address the request comes from only for that purpose.

7. Retention

8. Cookies, statistics, advertising

This website sets no cookies, uses no third-party statistics tool and shows no advertising. That is why there is no consent banner. What is counted on our own server is described in section 3. The fonts also sit on our own server, so no connection to Google Fonts arises.

When you move to Stripe, Stripe's cookies apply there. That concerns the payment page only.

9. Your rights

You can request information about the data processed about you, have it corrected or deleted, and restrict the processing. A request to the address in the imprint is enough; we need evidence that the request comes from you.

For purchase records, deletion is not possible during the ten-year retention period. Afterwards we delete them.

You can complain to the Federal Data Protection and Information Commissioner: edoeb.admin.ch.

10. Data security

The website runs over HTTPS. The PDFs and the counted steps sit outside the publicly reachable area of the server. Download links are signed and time-limited.

11. Changes

This notice can be amended. The version that applies is the one published here.