Privacy
What personal data Publens collects, why, where it is processed and what you can ask us to do about it. Written under the Swiss Federal Act on Data Protection (FADP/revDSG) and, where it applies, the GDPR.
Who is responsible
The entity named in the Impressum is the controller for the personal data described here, within the meaning of the Swiss Federal Act on Data Protection (FADP/revDSG) and, where it applies, the EU General Data Protection Regulation (GDPR).
What we collect, and why
- Contact form
- The name, email address, company and message you submit. We use them to answer you. They are stored in our database and are not used for anything else.
- Account
- If you sign in, we receive your name, email address, profile picture and Google account identifier from Google. We use them to identify you, to control what your organisation can see, and to record who performed an action.
- Audits you run
- The URLs you submit and the reports produced from them, kept so that results can be compared over time. These may incidentally contain personal data present on the pages audited.
- Server logs
- Our hosting records the IP address, the time, the request and the user agent for each request. These are used to operate and secure the service, and to investigate faults.
No tracking
This website uses no analytics, no advertising and no tracking cookies. There is nothing to consent to and no banner to dismiss. If you sign in, a cookie is set to keep you signed in; that is the only cookie the site sets.
Typefaces are requested from Google Fonts, which means your IP address reaches Google when a page loads. We can serve them from our own domain instead; write to the address in the Impressum if that matters to you.
Where it is processed
The service runs on Google Cloud Platform. Our database, application servers and stored reports are located in the europe-west6 region (Zürich, Switzerland).
Sign-in uses Firebase Authentication, operated by Google. Authentication data is processed by Google LLC and may be transferred to the United States. Google is certified under the EU–US and Swiss–US Data Privacy Framework, and we rely in addition on the European Commission’s Standard Contractual Clauses as incorporated in Google’s data processing terms.
How long we keep it
Contact-form submissions are kept for as long as needed to deal with the enquiry and any follow-up, and are deleted on request. Account data is kept for as long as the account exists. Audit reports are kept for as long as your organisation keeps them, since their value is in the comparison over time. Server logs are kept for a limited period under the retention configured for our hosting.
Who else sees it
We do not sell personal data and we do not share it for anyone else’s marketing. It is disclosed only to the providers that operate the service on our behalf under a processing agreement — principally Google Cloud — and where we are legally obliged to disclose it.
Data belonging to one organisation is not made available to another. Access is scoped to the organisation a user belongs to.
Your rights
You may ask what personal data we hold about you and receive a copy of it; ask for it to be corrected or deleted; object to processing; and ask for data you provided to be handed over in a machine-readable form. Write to the address in the Impressum and we will respond.
If you believe your data is being handled unlawfully, you may raise it with the Federal Data Protection and Information Commissioner (FDPIC/EDÖB), Feldeggweg 1, 3003 Bern. If the GDPR applies to you, you may also complain to the supervisory authority where you live or work.
Changes
This notice is updated when the service changes. The version in force is the one published here.
Contact
Requests about your data go to the address in our Impressum.
Last updated 7 October 2026.
