Legal

Privacy policy

As of: 5 October 2026

This privacy policy explains which personal data Noxal’s processes when you visit this website, contact us, receive post from us or work with us, and what rights you have. It is governed by the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies in an individual case, for example to persons in the EU or EEA, its provisions also apply.

Controller

Noxal’s, sole proprietorship of Nando Goris
Seestrasse 116, 8805 Richterswil, Switzerland
Email: info@noxals.com

You can reach us at this address with any question about data protection and to exercise your rights. We have not appointed a data protection officer and are not required to.

Overview

WhenWhich dataWhat for
Visiting the websiteTechnical connection data such as IP address, time, page requestedSecure and stable operation
AI Mirror form, emailName, business, contact details, your answers and messageReply, AI Mirror, quote
Letter to your businessPublicly available business informationOne-off information by post
Working togetherContract, communication and billing dataProviding and invoicing our services

No cookies, no tracking. This website sets no cookies, uses no analytics or advertising services and embeds no social media plugins. Fonts and images are loaded from our own web server.

Visiting this website

This website is hosted by Netlify, Inc., San Francisco, USA. When pages are requested, Netlify processes technically necessary data in server log files: the IP address of your device, date and time of access, the page requested and amount of data transferred, and information about your browser and operating system. These data are used solely to deliver the website securely and reliably, are not combined with other data and are kept only as long as necessary for that purpose.

The legal basis under the GDPR is our legitimate interest in operating the website securely (Art. 6(1)(f) GDPR).

AI Mirror form and contact

When you complete the AI Mirror form or send us an email, we process your details: name, business, email address, your answers about your business and the content of your message. We use them to answer your request, prepare the AI Mirror for your business and, if you wish, make you an offer.

Form submissions are received by the form service of our hosting provider Netlify and forwarded to us. For email we use Google Workspace (Google Ireland Limited, Dublin; Google LLC, USA).

The legal basis under the GDPR is pre-contractual steps at your request (Art. 6(1)(b) GDPR) and our legitimate interest in answering enquiries (Art. 6(1)(f)).

Letters to businesses

We inform businesses once, by post, about how AI assistants currently present them. For this we use only publicly available business information: the name and business address, where applicable the name of the owner, public listings and reviews in directories and map services, and the answers AI assistants give to general customer questions. We do not send marketing emails to anyone who has not consented.

You may object at any time, without formality, to the use of your data for such information; a short email to info@noxals.com is enough. We record the objection and will not contact you again. Information on businesses that do not reply is deleted no later than twelve months after the letter was sent.

The legal basis under the GDPR is our legitimate interest in informing businesses about our services (Art. 6(1)(f) GDPR).

AI Mirror, engagements and sessions

For the AI Mirror we ask AI assistants the questions your customers ask and analyse their answers together with public information about your business. We use the services of the respective providers, such as OpenAI, Google, Anthropic, Perplexity and Microsoft. The questions contain general information such as industry and town, but no personal data of your customers.

We do not need access to your accounts and never ask for passwords. Implementation sessions take place by video call: you share your screen, we see only what you show, and nothing is recorded. We process personal data of your customers only where necessary in an individual case and agreed with you in writing.

The legal basis under the GDPR is the performance of the contract (Art. 6(1)(b) GDPR).

Contracts and accounting

For quotes, contracts and invoices we process your contact, contract and payment data. Payments are made by bank transfer with a QR-bill through our bank in Switzerland. Business records are retained in accordance with statutory obligations (Art. 6(1)(b) and (c) GDPR).

Recipients and processors

RecipientPurposeLocation
Netlify, Inc.Website hosting, form serviceUSA
Google Ireland Limited, Google LLCEmail and calendarIreland, USA
Providers of AI servicesMeasurements for the AI Mirror, without your customers’ personal dataUSA and other countries
Video conferencing providersImplementation sessions, not recordedDepending on provider
Bank in SwitzerlandPaymentsSwitzerland
AuthoritiesOnly where legally requiredSwitzerland

We do not sell personal data and do not pass it on to third parties for marketing purposes.

Transfers abroad

Some recipients are based in the USA or other countries. Where personal data is disclosed to a country whose data protection the Swiss Federal Council has not recognised as adequate, we ensure appropriate protection, in particular through standard contractual clauses approved by the European Commission and recognised by the FDPIC, or through the recipient’s certification under the Swiss-U.S. Data Privacy Framework.

Retention

DataPeriod
Server log filesAccording to the hosting provider’s retention periods, only as long as needed for security and operation
Enquiries without an engagementUp to 24 months after the last contact
Information on businesses we wrote toUp to 12 months after the letter; an objection is recorded for as long as needed to respect it
Contracts, invoices, accounting10 years, in accordance with Art. 958f of the Swiss Code of Obligations

Data security

We take appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access. The website is delivered exclusively in encrypted form via HTTPS, our accounts are protected with two-factor authentication, and access to data is limited to what is necessary.

Automated decisions

We do not make decisions based solely on automated processing that have legal effects on you or significantly affect you.

Your rights

Within the scope of applicable law, you have the right to access the personal data we process about you, to have inaccurate data corrected, to erasure, to restriction of processing, to receive or transfer your data, and to object to processing, in particular at any time to processing for marketing purposes. You may withdraw any consent given at any time with effect for the future.

To do so, contact info@noxals.com. We may ask you to verify your identity and usually reply within 30 days.

You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) and, where the GDPR applies, with the data protection authority in your country; in Liechtenstein, with the Data Protection Authority.

Changes

We update this privacy policy when our services or the legal situation change. The version published on this website applies.

This English version is provided for convenience. In case of discrepancies, the German version prevails.