Security & Data

Where your data lives, in plain terms.

Most agencies say they take data protection seriously and leave it there. This page says where your data is actually processed and which companies handle it, so you can check rather than trust.

Our Commitments

Four things we hold to.

Processed in the EU by default

Wherever a provider lets us choose a region, we choose one inside the EU or EEA. Contact form submissions are processed in Frankfurt rather than the platform default in the United States.

Swiss law applies

Alec'x Designs is based in Montreux and operates under the revised Swiss Federal Act on Data Protection (FADP). Where a client is subject to the GDPR, we work to that standard as well.

We name every subprocessor

The companies that touch client data are listed on this page. We would rather you be able to check the claim than take our word for it.

We collect only what a project needs

We do not sell data, we do not use client material to train models, and we do not enrich contact records from third-party sources.

Subprocessors

Every company that touches your data.

If this list changes, this page changes with it.

ProviderPurposeProcessed inPersonal data
VercelWebsite hosting and contact form processingFrankfurt, Germany (EU)Contact form submissions in transit
Google WorkspaceClient documents, email, and file storageEuropean Union (Workspace Data Regions)Client contact details, project documents
HostpointDomain registration for alecxdesigns.chSwitzerlandRegistrant contact details only
ResendDelivery of contact form notificationsUnited StatesName, email, and message content, in transit
GitHubSource code repositories and version historyUnited StatesNone — see note on source code below

Source code is kept separate from personal data

Project source code is hosted on GitHub in the United States. Code repositories hold the software we build — they do not hold client customer records, credentials, or personal data.

Secrets such as API keys are never committed to a repository. They are held in the deployment platform's encrypted environment configuration and are not visible in version history.

Cross-border transfers

Two subprocessors are United States companies. Under the FADP, transferring personal data abroad is permitted where adequate protection is in place; these transfers rely on the standard contractual clauses those providers offer, together with the Swiss–US Data Privacy Framework where the provider is certified.

Where a project requires that no personal data leaves Switzerland or the EU, tell us at the outset. That constraint is workable, but it changes which providers we can use, so it needs to be part of the initial scope rather than a later adjustment.

Access and retention

Access to client material is limited to the two founders. Accounts use multi-factor authentication, and access to a client's systems is removed when an engagement ends unless we have been retained for ongoing support.

Contact form submissions are kept as email correspondence and deleted on request. Project files are retained for the duration of the engagement and for as long as afterwards as we may need them to support the work.

Your rights

You can ask what personal data we hold about you, ask us to correct it, ask for a copy, or ask us to delete it. Write to alec@alecxdesigns.ch and we will respond within one business day.

If you believe we have handled your data improperly, you may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC).

Last reviewed

31 July 2026. Questions about any of this go to alec@alecxdesigns.ch.

Working with data you can't afford to get wrong?

Tell us the constraint at the start and we'll scope the project around it.

Start a projectNo commitment · Reply within one business day