Where your data lives, in plain terms.
Most agencies say they take data protection seriously and leave it there. This page says where your data is actually processed and which companies handle it, so you can check rather than trust.
Four things we hold to.
Processed in the EU by default
Wherever a provider lets us choose a region, we choose one inside the EU or EEA. Contact form submissions are processed in Frankfurt rather than the platform default in the United States.
Swiss law applies
Alec'x Designs is based in Montreux and operates under the revised Swiss Federal Act on Data Protection (FADP). Where a client is subject to the GDPR, we work to that standard as well.
We name every subprocessor
The companies that touch client data are listed on this page. We would rather you be able to check the claim than take our word for it.
We collect only what a project needs
We do not sell data, we do not use client material to train models, and we do not enrich contact records from third-party sources.
Every company that touches your data.
If this list changes, this page changes with it.
| Provider | Purpose | Processed in | Personal data |
|---|---|---|---|
| Vercel | Website hosting and contact form processing | Frankfurt, Germany (EU) | Contact form submissions in transit |
| Google Workspace | Client documents, email, and file storage | European Union (Workspace Data Regions) | Client contact details, project documents |
| Hostpoint | Domain registration for alecxdesigns.ch | Switzerland | Registrant contact details only |
| Resend | Delivery of contact form notifications | United States | Name, email, and message content, in transit |
| GitHub | Source code repositories and version history | United States | None — see note on source code below |
Source code is kept separate from personal data
Project source code is hosted on GitHub in the United States. Code repositories hold the software we build — they do not hold client customer records, credentials, or personal data.
Secrets such as API keys are never committed to a repository. They are held in the deployment platform's encrypted environment configuration and are not visible in version history.
Cross-border transfers
Two subprocessors are United States companies. Under the FADP, transferring personal data abroad is permitted where adequate protection is in place; these transfers rely on the standard contractual clauses those providers offer, together with the Swiss–US Data Privacy Framework where the provider is certified.
Where a project requires that no personal data leaves Switzerland or the EU, tell us at the outset. That constraint is workable, but it changes which providers we can use, so it needs to be part of the initial scope rather than a later adjustment.
Access and retention
Access to client material is limited to the two founders. Accounts use multi-factor authentication, and access to a client's systems is removed when an engagement ends unless we have been retained for ongoing support.
Contact form submissions are kept as email correspondence and deleted on request. Project files are retained for the duration of the engagement and for as long as afterwards as we may need them to support the work.
Your rights
You can ask what personal data we hold about you, ask us to correct it, ask for a copy, or ask us to delete it. Write to alec@alecxdesigns.ch and we will respond within one business day.
If you believe we have handled your data improperly, you may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC).
31 July 2026. Questions about any of this go to alec@alecxdesigns.ch.
Working with data you can't afford to get wrong?
Tell us the constraint at the start and we'll scope the project around it.