Privacy policy

1. Who we are

DO Innovations SA is the controller for the personal data described here. We comply with the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).

DO Innovations SA
Chemin de Bon-Abri 26a
1007 Lausanne, Switzerland
Email: admin@do-innovations.ch

2. What we collect

  • Contact form. The service you select, the pricing package you clicked on if you came from our pricing page, your brand or company name, your message, your name, your email address, and your consent. There is no telephone or address field.
  • Client data. If you instruct us, the identification, contact, billing and matter data we need to act for you.
  • Server logs. Your IP address, the time, the page requested, the referring page, and your browser and operating system.
  • Analytics and advertising data — only if you accept cookies. See section 4.

Please do not put health data, information about criminal proceedings or other sensitive details into the contact form. Send those another way once we are in touch.

3. Why we process it, and on what basis

Under the GDPR, each purpose has the legal basis shown. Under the FADP, a private controller does not need a legal basis in the same sense; where a justification is required we rely on your consent, on the contract, or on an overriding private interest (Art. 31 FADP).

  • Answering your enquiry — your consent, and steps taken at your request before a contract (Art. 6(1)(a) and (b) GDPR).
  • Acting for you under an instruction, including filings and enforcement abroad — performance of the contract (Art. 6(1)(b) GDPR).
  • Accounting, tax and professional obligations — legal obligation (Art. 6(1)(c) GDPR).
  • Running the website securely, including logs and spam filtering — our legitimate interest (Art. 6(1)(f) GDPR).
  • Establishing or defending legal claims, including conflict checks — our legitimate interest (Art. 6(1)(f) GDPR).
  • Measuring traffic and advertising — your consent, withdrawable at any time (Art. 6(1)(a) GDPR).

4. Cookies, analytics and advertising

This website loads one third-party measurement script, Google's gtag.js, configured with two properties: Google Analytics 4 (G-F29E8W61J9), which measures how the site is used, and Google Ads (AW-18289814686), which measures our advertising and records a conversion when you send the contact form. No other analytics, advertising or tracking tool is loaded — no Meta, LinkedIn, TikTok or X pixel, and no session recording.

We use Google Consent Mode v2. Until you choose, all four consent signals are set to denied and no analytics or advertising cookies are set. A banner appears on your first visit with an Accept and a Decline button. Cookies are set only if you accept.

These are used on this site:

  • cookie_consent — not a cookie but a local-storage entry set by this site, recording your choice. Stays until you clear your browser storage. Set either way.
  • _ga and _ga_F29E8W61J9 — Google Analytics, distinguish visitors and hold session state. Typically 2 years. Only after you accept.
  • _gcl_au — Google Ads, attributes conversions. Typically 90 days. Only after you accept.

To change your mind, use the Cookie settings link in the footer of any page. It withdraws your consent, tells Google, deletes the cookies above and brings the banner back. You can also opt out of personalised advertising in Google Ads Settings or read Google's Privacy Policy.

Separately, most pages load fonts from Google Fonts. This sets no cookies, but your IP address is visible to Google when the font loads.

5. Who else sees your data

We do not sell personal data. We share it only with providers acting on our instructions under a contract, and with:

  • Formspree — receives contact-form submissions and forwards them to us by email.
  • Google — analytics, advertising measurement and web fonts, as described above.
  • Our hosting and email providers — they operate the server and carry our correspondence.

6. Data outside Switzerland and the EEA

Some of these providers are outside Switzerland and the EEA. Where that is the case we transfer data only if the country is recognised as providing adequate protection, or under the Standard Contractual Clauses, or because the transfer is necessary to perform our contract with you or to pursue a legal claim (Art. 16 and 17 FADP; Art. 45, 46 and 49 GDPR).

Google is certified under the EU-U.S. and Swiss-U.S. Data Privacy Frameworks, which the European Commission and the Swiss Federal Council recognise as providing adequate protection.

7. Your rights

Subject to the conditions in the applicable law, you may ask us to:

  • give you access to your data and a copy of it (Art. 25 FADP; Art. 15 GDPR);
  • correct it if it is wrong (Art. 32 FADP; Art. 16 GDPR);
  • delete it where we have no valid reason to keep it (Art. 32 FADP; Art. 17 GDPR);
  • restrict processing while a dispute about it is resolved (Art. 18 GDPR);
  • hand it over in a structured, machine-readable format, or send it to another controller where that is technically feasible (Art. 28 FADP; Art. 20 GDPR);
  • stop processing based on our legitimate interests, on grounds relating to your situation. For direct marketing we stop without needing a reason (Art. 30(2)(b) FADP; Art. 21 GDPR).

You can withdraw consent at any time without affecting what was done beforehand (Art. 7(3) GDPR); for cookies, use the Cookie settings link in the footer. We do not make automated decisions about you and do not profile you.

Write to admin@do-innovations.ch. We may need to confirm your identity first, and we answer within 30 days, or one month where the GDPR applies.

Complaints. You can complain to the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Berne, www.edoeb.admin.ch. In the EU or EEA you may instead go to the supervisory authority where you live, where you work, or where the problem occurred. You can also go to the civil courts.

8. Security

The site is served over HTTPS with HSTS, and we apply technical and organisational measures to protect personal data against loss, misuse and unauthorised access.

9. Changes

We may update this policy. The date at the top shows when it last changed.