1. Who is responsible
Rixiss AG is responsible (the “controller”) for the personal data described in this notice. Our registered details, postal address and email address are shown on this page under “Issued by”. Write to that address with any question about your data or to exercise your rights.
This notice covers the Zezep website, its contact form, and the accounts of our business customers. When a customer sends messages through the Zezep platform, the recipients’ numbers and the message content are the customer’s data: we process them on the customer’s behalf, as its processor, and the customer’s own privacy notice applies to them.
2. What we collect, and why
When you send the contact form
We store what you enter, what your browser sends with it, and where your request stands while we answer it. The table names each item as our records store it, and whether it is part of the notice our staff receive when a request arrives (section 4).
| What we store | Stored as | In the notice to our staff |
|---|---|---|
| Your first name and last name | first_name, last_name |
no |
| Your business email address | email |
no |
| Your company | company |
no |
| Your telephone number | phone |
no |
| Your country | country |
no |
| The monthly volume you expect, as you chose it | monthly_volume |
yes |
| What you send, as you chose it | use_case |
yes |
| Your message | message |
no |
| Your confirmation that you have read this notice | privacy_notice_acknowledged |
no |
| The website you sent the request from | source_host |
yes |
| The page you sent it from | page_path |
yes |
| The language of that page | locale |
no |
| The campaign parameters in the page’s address: utm_source, utm_medium, utm_campaign, utm_term and utm_content | utm |
no |
| A one-way keyed hash of your IP address, never the address itself | ip_hash |
no |
| Your browser’s user agent, shortened | user_agent |
no |
| The time you sent it | created_at |
no |
| Where your request stands with us, the check that classified it as spam if one did, and our notes on it | status, spam_reason, note |
no |
We use this to answer your request and to prepare an offer (legal basis: steps you asked for before a contract, and our legitimate interest in answering business enquiries), and to keep the form free of abuse: automatic checks classify a request that looks automated as spam, and the hash lets us recognise repeated requests from one address without keeping the address (legal basis: our legitimate interest in the security of our website).
When you visit the website
Our web server records each request: the address it came from, the time, the page, your browser’s user agent and the page that linked to ours. We use these records to operate and secure the website (legal basis: our legitimate interest).
We count visits with web analytics that we host ourselves. They set no cookies and store nothing in your browser, keep no IP address, and do not follow you across other websites. They record the pages viewed (each page’s address with its query, which carries any campaign parameters, and its title), the linking page, the browser, operating system and device type, the screen size, the language, and the country, region and city the visit came from, looked up from the IP address at the moment of the visit. We use these counts to understand how the website is used (legal basis: our legitimate interest). The website sets no cookies at all; our cookie notice explains the cookies of the console.
When you are a customer
For an account we process the names, business email addresses and telephone numbers of your users, your company and billing details, the record of top-ups and charges, and the audit log of actions in the console. We use them to provide the service, to bill it and to keep it secure (legal bases: the performance of our contract with you, our legal obligations, for example in accounting, and our legitimate interest in security).
3. How long we keep it
- A contact form request: [retention period to be decided by the owner; until then a request is kept until we delete it].
- A request our checks classify as spam, or that we mark as spam: deleted automatically 30 days after it is classified.
- Web server records: [retention period to be confirmed].
- Customer account data: for the duration of the contract, and afterwards for as long as accounting and tax law requires.
4. Who receives it
Your data is processed by our own staff and on servers we operate. [To be confirmed by the owner: the location of the data centre.] When a request arrives, our staff receive a notice of it in our console, and may receive it through a messaging service we use internally. The notice carries only the items the table in section 2 marks for it: where the request came from and what you told us about your traffic, never who you are or how to reach you. We send our reply to you through our email provider. We do not sell personal data, and we do not share it with advertisers.
5. Transfers abroad
Rixiss AG is established in Switzerland. Where personal data is transferred to a country without an adequate level of protection, we protect it with the safeguards the law requires, such as standard contractual clauses. [To be completed with the legal review: the transfers that take place and their safeguards, and whether a representative in the European Union is required.]
6. Your rights
Under the Swiss Federal Act on Data Protection and, where it applies, the EU General Data Protection Regulation, you may ask for access to your data, its correction or deletion, the restriction of its processing, and a copy of it in a portable format. You may object at any time to processing based on our legitimate interest. You may also lodge a complaint with a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner, or the authority of the country in the European Economic Area where you live or work.
7. Changes to this notice
We may change this notice. We publish each version on this page with its date.