Legal

Privacy Policy

Last updated 15 September 2026.

This Privacy Policy explains how Neldore Technologies, Matteo Chirivi (“we”, “us”) processes personal data when you visit neldore.com (the “Site”), use its contact form or write to us. It is written for the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies to you, this policy also gives the information it requires.

Controller

The controller is Neldore Technologies, Matteo Chirivi, a sole proprietorship entered in the Swiss commercial register (CH-ID CH-036.1.108.938-6, UID CHE-497.132.446), represented by its owner, Matteo Chirivi. The postal address is given in the Legal Notice. For any question about your data: contact@neldore.com.

We have not appointed a data protection officer, as we are not required to.

What we process, and why

Visiting the Site

When you open a page, your browser sends technical data to our hosting provider: IP address, date and time, the page requested, the referring page, and browser and operating system. It is needed to deliver the pages and to protect the Site against attacks and abuse. Legal basis under the GDPR: our legitimate interest in a secure, working website (Art. 6(1)(f)).

Audience statistics

We count visits with Vercel Web Analytics, which measures the Site’s audience in aggregate: pages viewed, referring page, country or region, device type, browser and operating system. It sets no cookies and stores nothing on your device. A visitor is recognised only by a code calculated from the request, which is discarded after 24 hours, so visits cannot be linked to you or followed across other websites. Legal basis under the GDPR: our legitimate interest in understanding how the Site is used (Art. 6(1)(f)).

Contact form and email

When you use the contact form, we process your name, email address, company (optional), the subject and your message, together with the language of the page. When you write to us directly, we process your email address and what you send. We use this data only to reply to you and, where relevant, to prepare or carry out a collaboration. Legal basis under the GDPR: steps taken at your request before a contract, and our legitimate interest in answering (Art. 6(1)(b) and (f)).

To protect the form against automated spam, without a CAPTCHA and without cookies, we also use:

  • a single-use token issued by our server when you start filling in the form, and a short calculation your browser performs in the background;
  • your IP address, held only in the memory of our server for up to 10 minutes, to limit the number of messages sent from one address;
  • a fingerprint of the message text (a one-way hash, from which the text cannot be read back), kept for 24 hours to detect the same message being sent repeatedly.

This data serves no other purpose and is not linked to your identity.

Cookies and similar technologies

The Site sets no cookies and stores nothing in your browser. The fonts are served by our own server: no request is made to Google Fonts or any other font service. The Site contains no social media plugins and no advertising trackers.

Who receives the data

We do not sell personal data and do not share it for advertising. It is disclosed only to service providers who process it on our behalf and on our instructions, bound by data processing agreements:

  • Vercel Inc. (United States): hosting of the Site, security, audience statistics.
  • Resend (Plus Five Five, Inc., United States): delivery of the messages sent through the contact form to our mailbox.
  • Infomaniak Network SA (Switzerland): hosting of our mailbox.

We may also disclose data to authorities where the law requires it, and to professional advisers bound by confidentiality where needed to protect our rights.

Disclosure abroad

Vercel and Resend process data in the United States, and Vercel serves the Site through a network of servers in several countries. Transfers to the United States are protected as follows: Vercel is certified under the Swiss-U.S. and EU-U.S. Data Privacy Framework, which the Swiss Federal Council and the European Commission recognise as providing adequate protection; for Resend, the standard contractual clauses approved by the European Commission and recognised by the Federal Data Protection and Information Commissioner (FDPIC) apply, completed by its certification under the EU-U.S. Data Privacy Framework. You can ask us for a copy of the safeguards used.

How long we keep data

  • Messages and emails: as long as needed to handle your request, then no longer than two years after our last exchange. If a collaboration follows, business correspondence is kept for the ten years required by Swiss law.
  • Technical data of visits: kept by our hosting provider for a short period for security and delivery, as set by its own retention rules.
  • Anti-spam data: the IP address for up to 10 minutes, the message fingerprint for 24 hours, in server memory only.
  • Audience statistics: aggregated figures without personal data.

Your rights

Under the FADP you may ask us free of charge for information about the data we hold on you, have it corrected or deleted, object to its processing, and receive data you gave us in a common electronic format. Where the GDPR applies, you also have the rights of access, rectification, erasure, restriction, portability and objection, and you may withdraw any consent at any time.

To exercise these rights, write to contact@neldore.com. We may ask you to confirm your identity, and we reply within 30 days. You may also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Berne, Switzerland (edoeb.admin.ch) or, in the European Union, with the data protection authority of your country.

Automated decisions

We make no decisions based solely on automated processing that would have legal effects on you, and we do not use your data for profiling.

Security

The Site is served only over an encrypted connection (HTTPS). We protect data with technical and organisational measures appropriate to the risk, including restricted access to our accounts and to our mailbox.

The Site links to other websites, such as LinkedIn, Klixeo Agency and UpDash. When you follow a link, the operator of that site processes your data under its own privacy policy.

Changes

We update this policy when our practices or the law change. The date at the top of the page shows the latest version.