The protection of your data is important to us. We process personal data only on a legally compliant basis and take our duty to protect that data seriously. This Privacy Policy explains what data we collect, why, and what rights you have — under both the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (revised, in force since 1 September 2023, "FADP"), as applicable to your relationship with us.
Table of Contents
1. Controller and scope
2. Principles of data processing
3. What data we process and why
4. Legal basis for processing
5. Server log files
6. Cookies and similar technologies
7. Google advertising services
8. Third-party content and services
9. International data transfers
10. Data retention
11. Your rights
12. Right to lodge a complaint
13. Automated decision-making and profiling
14. Data security
15. Changes to this Privacy Policy
1. Controller and scope
This Privacy Policy explains the nature, scope and purpose of the processing of personal data (collection, processing and use) within our online offering and related websites, features and content (collectively, the "Website"). It applies regardless of the domains, systems, platforms and devices used to access the Website.
The controller responsible for data processing under this policy is:
Gramont GmbH
Churerstrasse 158, 8808 Pfäffikon, Switzerland
Commercial register / UID no.: CHE-115.396.629
Contact for data protection matters: contact@gramont.ch
A Data Protection Officer has been formally appointed pursuant to Art. 37 GDPR / Art. 10 FADP:
Sascha Wenske, dpo@gramont.ch
References in this policy to "provider", "we", "us" mean Gramont GmbH. "User" means any visitor or customer of the Website.
2. Principles of data processing
We process personal data in compliance with applicable data protection law, in particular the principles of lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality and accountability (Art. 5 GDPR; corresponding principles under Art. 6 FADP). This means personal data is processed only where a legal basis exists, where necessary to perform a contract, or where you have given consent.
We apply organizational, contractual and technical measures appropriate to the state of the art to protect personal data against unauthorized access, loss, destruction or manipulation. Where required, we conduct data protection impact assessments for processing likely to result in high risk.
3. What data we process and why
In addition to the specific uses described in this policy, we process personal data for the following purposes, based on statutory permission, contract performance, or your consent:
● Provision, operation, maintenance, optimization and security of our services and the Website;
● Responding to inquiries and providing customer service and technical support;
● Compliance with legal obligations, including record-keeping requirements.
Where we contact you (e.g. via a contact form or email), we store your details to process your request and any follow-up questions. Personal data is deleted once it is no longer needed for these purposes and no statutory retention obligation applies.
Confirmed by inspection of network requests and response headers (31 Aug 2026): our contact form is a native Squarespace form block. Submissions are sent to Squarespace’s own API (server response header confirms "Squarespace") via our connected custom domain, gramont.consulting, rather than a squarespace.com subdomain — this is expected behavior for a Squarespace site on a connected custom domain, not a separate third-party system. Submissions are therefore processed and stored by Squarespace as our processor (see Section 9). The form is also protected by Google reCAPTCHA (see Section 8).
Where data is transferred to third parties to fulfill a legal requirement, perform a contract, or on the basis of your explicit consent, we ensure this is done securely and in accordance with applicable data protection law.
We also engage processors (e.g. our website hosting provider) to process personal data on our behalf and under our instructions, bound by data processing agreements meeting the requirements of Art. 28 GDPR and Art. 9 FADP. Engaging a processor does not constitute a disclosure to an independent third party.
4. Legal basis for processing
Under the GDPR, we rely on the following legal bases as applicable:
● Consent (Art. 6(1)(a) GDPR);
● Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR);
● Compliance with a legal obligation (Art. 6(1)(c) GDPR);
● Protection of vital interests (Art. 6(1)(d) GDPR);
● Legitimate interests, provided these do not override your rights and freedoms (Art. 6(1)(f) GDPR).
Under the Swiss FADP, processing is permitted provided the general principles of lawfulness, good faith and proportionality are observed (Art. 6 FADP), and — where required, e.g. for sensitive personal data or high-risk profiling — with your consent, a legal basis, or an overriding private or public interest (Art. 30–31 FADP).
5. Server log files
We collect data on each access to the server hosting the Website (server log files), including: the page or file retrieved, date and time, data volume transferred, retrieval status, browser type and version, operating system, referrer URL, IP address, and requesting provider.
This data is used, without linking it to an identified individual, for statistical evaluation, operation, security and optimization of the Website. We reserve the right to review log data retrospectively where there is concrete evidence of unlawful use.
Server log files are generated and retained at the infrastructure level by our hosting provider, Squarespace, Inc. (see Section 9), acting as our processor under its own data processing agreement, rather than on infrastructure we operate ourselves.
6. Cookies and similar technologies
Cookies are small files stored on your device by our web server or third-party servers for later retrieval. We use both strictly necessary cookies (required for core Website functionality) and optional cookies (e.g. analytics, marketing) as described in this policy.
Where cookies are not strictly necessary for the Website to function, we obtain your prior, informed and freely given consent before they are set, via a cookie consent tool on the Website (currently provided by CookieYes, a third-party consent management platform). Non-essential categories (e.g. functional, analytics, performance, advertisement) are switched off by default and are only activated if you actively opt in. You can withdraw or change your consent at any time via the "Preferences" / cookie settings link in the consent banner, or by adjusting your browser settings, which may also delete previously stored cookies. Blocking cookies may limit some Website functionality.
Some third parties also allow you to manage online advertising cookies directly via www.aboutads.info/choices (US) or
www.youronlinechoices.com (EU).
7. Google advertising services
We use advertising and remarketing services provided by Google Ireland Limited ("Google Ads", including services previously marketed as "AdWords", "DoubleClick" and "AdSense", now largely operated under the Google Marketing Platform). These services allow us to show ads on our Website and on other websites based on users' interests, including remarketing (showing ads for products a user previously viewed).
These services use cookies or comparable technologies to record which pages a user visited, what content they engaged with, and technical information about their browser, device and visit. Data is generally pseudonymized — Google does not, in this context, process a name or email address directly, but associates data with a cookie or device identifier. This does not apply where a user has separately given Google explicit permission to process their data without pseudonymization.
These services are activated only after you have given consent via our cookie consent tool.
Overview of Google's advertising technologies: Google Ads – How ads are personalized
Google's Privacy Policy: policies.google.com/privacy
Manage your ad settings with Google: adssettings.google.com
8. Third-party content and services
Our Website may include content or services from third-party providers, such as fonts, maps or video. Including such content generally requires the third-party provider to receive the user's IP address, since content cannot otherwise be delivered to the browser. Third-party providers may also set their own cookies and process data for their own purposes, potentially including profiling. We select third-party providers with care and, where feasible, minimize data shared with them.
● Fonts. Confirmed by inspection of network requests (31 Aug 2026): this Website does not load Google Fonts. Fonts are served from Squarespace's own content delivery network (file.squarespace-cdn.com) and from Adobe Fonts / Typekit (use.typekit.net, operated by Adobe Inc. and its Irish entity Adobe Systems Software Ireland Limited). Loading Adobe Fonts transmits the visitor's IP address to Adobe's servers in order to deliver the correct font files; Adobe does not set cookies for this purpose. Adobe Inc. is currently a self-certified, active participant in the EU-U.S. and Swiss-U.S. Data Privacy Frameworks per Adobe's published cross-border transfer information — re-verify on dataprivacyframework.gov immediately before publishing, consistent with the other vendors in Section 9.
● CookieYes (cookie consent management platform). Used to display the cookie banner described in Section 6, record and store users' consent choices, and enforce blocking of non-essential cookies until consent is given. Consent records are stored by the provider under its own data processing agreement.
● Google Maps (Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland). Loaded only after consent via our cookie consent tool where technically feasible; otherwise a click-to-load placeholder is used. Privacy Policy: policies.google.com/privacy
● YouTube (Google Ireland Limited). Embedded videos are loaded in privacy-enhanced mode where available, and/or only after consent via our cookie consent tool. Privacy Policy: policies.google.com/privacy
● Google reCAPTCHA (Google Ireland Limited). Used on our contact form to protect against spam and automated abuse. reCAPTCHA analyzes visitor interactions and technical/device data, and transmits this to Google, which may set cookies and process data on servers in the United States. Loaded only where technically required for form protection; further information: policies.google.com/privacy
9. International data transfers
Our Website is hosted on the platform of Squarespace, Inc., 225 Varick Street, New York, NY 10014, USA ("Squarespace"), which acts as our processor/sub-processor for hosting, contact form submissions (via our connected custom domain, gramont.consulting — see Section 3) and cookie consent management (see Section 6). Squarespace, together with Google, Adobe (Adobe Fonts/Typekit, see Section 8) and the other third-party providers named in this policy, is based in, or transfers data to, the United States. Where personal data is transferred outside the EU/EEA or Switzerland, we rely on an applicable safeguard, in particular:
● An adequacy decision (the EU-US Data Privacy Framework, in force since July 2023, and the Swiss-US Data Privacy Framework, in force since September 2024), where the receiving party is self-certified under the relevant framework. As of the last verification of this policy, Google LLC, Squarespace, Inc. and Adobe Inc. are all listed as active, self-certified participants in the EU-U.S. and Swiss-U.S. Data Privacy Frameworks (and the UK Extension) on the U.S. Department of Commerce's Data Privacy Framework registry; or
● EU Standard Contractual Clauses (and, for transfers from Switzerland, the FDPIC-recognized Swiss addendum), together with supplementary measures where required — applied by both vendors as a fallback if a Data Privacy Framework certification is invalidated or lapses.
10. Data retention
We retain personal data only for as long as necessary for the purposes described in this policy, or as required by applicable statutory retention obligations (e.g. commercial and tax record-keeping periods under Swiss law). Once these purposes and obligations no longer apply, the data is deleted or anonymized. Specifically:
● Contact form inquiries not leading to a business relationship: deleted 6 months after the inquiry is resolved.
● Contact form inquiries and correspondence that lead to a business relationship or are otherwise commercially relevant: retained for 10 years, pursuant to the statutory retention obligation for business records and correspondence under Swiss law (Art. 958f of the Swiss Code of Obligations).
● Server log files: retained according to our hosting provider Squarespace's own infrastructure-level retention practice (see Sections 5 and 9) rather than a period set by us directly.
● Cookie consent records (CookieYes): retained for 6-12 months, after which renewed consent is requested.
11. Your rights
Subject to the conditions set out in the GDPR and/or FADP, you have the right to:
● Request confirmation of and access to the personal data we hold about you;
● Request correction of inaccurate or incomplete data;
● Request erasure of your data, where applicable;
● Request restriction of processing, where applicable;
● Object to processing based on legitimate interests, including direct marketing;
● Receive a copy of your data in a structured, machine-readable format and have it transmitted to another controller (data portability), where processing is based on consent or contract and carried out by automated means;
● Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights, contact us using the details in Section 1.
12. Right to lodge a complaint
If you believe our processing of your personal data infringes applicable law, you have the right to lodge a complaint with a supervisory authority:
● In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch;
● In the EU/EEA: the data protection authority of your habitual residence, place of work, or the place of the alleged infringement.
13. Automated decision-making and profiling
We do not use fully automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR / Art. 21 FADP. Where cookie-based advertising involves limited profiling (see Sections 6–7), this does not involve automated decisions with legal or similarly significant effect.
14. Data security
We implement technical and organizational measures appropriate to the risk to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.
15. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in legal requirements or in our services and data processing. Where your consent is required, or where this policy forms part of a contractual relationship with you, changes affecting those elements will only be made with your consent. We encourage you to review this policy periodically.
Status: [09.09.2026]