Privacy Policy for setted.com
Status & Publication: Bern, March 1, 2026
Introduction and Scope
This privacy policy informs you about the processing of your personal data when using our website (https://www.setted.com). We process personal data in accordance with applicable data protection laws, in particular the following regulations:
- Swiss Federal Act on Data Protection (FADP/nFADP)
- General Data Protection Regulation (GDPR; for processing data of data subjects in the EU/EEA)
- California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA; for processing data of California residents)
- Other applicable laws
The website https://www.setted.com is accessible worldwide, which is why we adhere to the strictest standards to ensure maximum data protection for all website visitors.
Responsibility
setted is a brand of Hari Services & Products (CHE-169.542.079), a sole proprietorship based in Baar, Switzerland. If you have any questions regarding data protection, you can connect with us via the following channels:
- Email: dataprotection@setted.com
- Website: https://www.setted.com
General Information on Data Processing
We collect and process personal data only to the extent necessary to provide the website and our services or if you have given your consent. Automatically collected data (e.g., IP address, browser information) serve security and functionality purposes.
Legal bases:
- Consent (Art. 6 Para. 1 lit. a GDPR / Art. 31 Para. 1 FADP)
- Legitimate interest (Art. 6 Para. 1 lit. f GDPR / Art. 31 Para. 2 FADP)
- Fulfillment of legal obligations (Art. 6 Para. 1 lit. c GDPR / Art. 31 Para. 1 FADP)
Data Security and SSL/TLS Encryption
For security reasons and to protect the transmission of confidential content, such as inquiries you send to us, our website uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the browser's address line changes from "http://" to "https://" and by the lock symbol in your browser line. If encryption is activated, the data you transmit to us cannot be read by third parties.
Use of Data Processors (DPA)
We use external service providers to operate our website and provide our services (e.g., for web hosting and web analytics). Where legally required, we have concluded data processing agreements (DPA) with these service providers. These contracts ensure that the service providers only process your personal data according to our instructions and in compliance with applicable data protection laws.
Contact by Email
If you contact us by email, your details (email address, name, and the content of your message) will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. The legal basis is our legitimate interest in processing your request (Art. 6 Para. 1 lit. f GDPR / Art. 31 Para. 2 FADP). We do not pass on this data without your consent. We will delete this data once the inquiry has been conclusively resolved and provided there are no statutory retention obligations to the contrary.
Cookies and Similar Technologies
We use cookies to make the website functional and to analyze its usage. Technically necessary cookies are set without consent. For analytics cookies (e.g., Google Analytics), we obtain your consent (where required, e.g., under GDPR or CCPA for sharing for advertising purposes). You can reject cookies in your browser settings or use a consent tool. For California users: We honor Global Privacy Control (GPC) signals as an opt-out for the sale or sharing of personal data.
Google Analytics
We use Google Analytics 4 (GA4) provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; "Google"), with possible data transfer to Google LLC (USA).
Privacy Configuration:
- IP anonymization activated
- No transmission of personaly identifiable information
- Advertising features disabled
- Data retention limited to a maximum of 14 months
Purpose: Analysis of website usage for optimization (e.g. troubleshooting, user experience).
Legal bases:
- Consent (Art. 6 Para. 1 lit. a GDPR / Art. 31 Para. 1 FADP)
- Legitimate interest (Art. 6 Para. 1 lit. f GDPR / Art. 31 Para. 2 FADP)
- CCPA/CPRA: No "selling" or "sharing" of personal data for advertising purposes.
International Transfer: Data may be transferred to the USA. Google uses the EU-U.S. Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs) as safeguards.
Opt-out/Revocation:
- Browser-Add-on: https://tools.google.com/dlpage/gaoptout
- Adjust consent settings.
- For CCPA: GPC signal or direct request to us.
Further information: Google’s Privacy Policy: https://policies.google.com/privacy
Server Log Files
Hostpoint is a Swiss service provider. All data is stored on servers in Switzerland. Hostpoint automatically collects log data (such as IP address, browser, access time, etc.) for security purposes. These are not linked to other data and are deleted periodically.
Categories of Personal Data and Purposes (CCPA/CPRA Specific)
We collect the following categories of personal data:
- Identifiers (e.g., IP address)
- Internet activity (e.g., browsing behavior via Analytics)
Purposes: Operation of the website, analysis, security. We do not sell or share personal data for cross-context behavioral advertising. We only store personal data for as long as is necessary to fulfill the above-mentioned purposes or as stipulated by statutory retention periods (e.g., commercial and tax law obligations). Once the purpose no longer applies or the periods have expired, the data is routinely deleted or anonymized.
Rights of Website Visitors
Different rights apply depending on your place of residence (see Introduction). We align ourselves with the maximum extent of these rights:
- Access to stored data
- Rectification of incorrect data
- Erasure of personal data
- Revocation of granted consents (e.g., changing profile settings)
- Data portability (export of your data)
- Right to restriction of processing
- Right to lodge a complaint with the supervisory authority (e.g., FDPIC)
- Right to object to the processing of your personal data based on our legitimate interest (Art. 6 Para. 1 lit. f GDPR / Art. 31 Para. 2 FADP)
- Opt-out of sale/sharing
Email for privacy inquiries: dataprotection@setted.com.
Protection of Minors
Our website is directed at an adult audience. We do not knowingly collect personal data from children under the age of 16 (GDPR) or under the age of 13 (USA/COPPA). Should we learn that we have inadvertently collected data from minors without appropriate parental consent, we will delete this data immediately.
Do not Sell or Share My Personal Information
We do not sell or share any personal data.
Changes to this Policy
The privacy policy of https://setted.com will be revised as necessary. The current version will always be displayed at https://setted.com/privacypolicy.