Legal
Privacy policy
In short: we process only what your enquiry and our work require. No advertising profiles, no sale of data. What follows sets out in detail what happens with your data.
1 Data controller
Responsible for the processing of personal data in connection with this website:
beeVisto GmbH (clever hr is a brand of beeVisto GmbH)
Registered office: Weieracherstrasse 4, 8184 Bachenbülach
Business and contact address:
Münchhaldenstrasse 10
8008 Zurich, Switzerland
Email: office@clever-hr.ch
Telephone: +41 44 589 73 11
2 Principles
We process personal data under the revised Swiss Federal Act on Data Protection (Datenschutzgesetz, revFADP), in force since 1 September 2023. We follow the principles of transparency, purpose limitation and proportionality: we process only the data we need for the purpose in question, and only for as long as we need it. This website is aimed at clients in Switzerland.
3 Visiting the website (hosting)
Opening this website generates certain data for technical reasons: the IP address of your device, the date and time of access, the pages you open, and information about your browser and your device. We need this data to deliver the website and to keep it secure and stable. It is held briefly in server log files and is not combined with other data.
For the operation and delivery of the website we use Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare processes the technical data described above on our behalf and is certified under the Swiss-U.S. Data Privacy Framework (see section 9). Details: Cloudflare privacy policy.
Visitor counting. We count how often our pages are opened and how many people visit the website each day. The count runs on the server and works without cookies. So that several page views by the same person on the same day count as a single visit, we derive a pseudonymous HMAC check value from the IP address, browser identifier, date and a secret key. Without that key it cannot be used for a simple comparison, and it is deleted after 30 hours; your IP address itself is not stored for this purpose. We look at totals only: page views, number of visits, pages opened, referring website, advertising campaign, country and recognised referrals from AI services. We keep these totals for up to 400 days. No profiles are created, and we do not pass the figures on. Visits from known search engine and AI crawlers are left out of the count entirely. The data is held by Cloudflare in its role as processor described above.
4 Cookies and local storage
This website sets no tracking or advertising cookies of its own. The visitor count described in section 3 works without cookies and without any recognition beyond a single day. When you confirm our data protection notice, your browser remembers this locally on your device (localStorage), and no data reaches us in doing so. The embedded Calendly booking tool may set technically necessary cookies of its own (see section 6). You can restrict or refuse the storage of cookies in your browser settings at any time.
Fonts and other design elements are loaded from our own servers. No connection to Google Fonts or similar services is established when a page loads.
5 Getting in touch (form, email and telephone)
If you contact us by email or telephone, we process the details you send us (for example name, company, email address, telephone number and your request) solely in order to answer your enquiry and to prepare for any collaboration that follows. Processing takes place in our Google Workspace environment (see section 7). Section 6 applies to online appointment booking.
Enquiry form. On the contact page you can send us an enquiry through a form. The details you enter are transmitted: name, company, email address, telephone number, the topic you select and your message. Transmission is encrypted and runs through our own server-side function at Cloudflare (see section 3). After validation, your enquiry is accepted into durable Cloudflare storage for a maximum of 400 days. A monitored queue retries email delivery after a failed attempt; failures and permanently failed jobs are logged and alerted without message content. The form confirms acceptance only after durable storage. The enquiry and delivery metadata are then deleted automatically. To protect the form against automated submissions, we limit the number of enquiries per connection and hour. For this we store a secret-keyed HMAC check value for a maximum of one hour, and we do not store the IP address itself. The legal basis is our legitimate interest in answering your enquiry and in a form that works and stays free of abuse.
Checking for automated submissions (Cloudflare Turnstile). The form is protected by Cloudflare Turnstile. Turnstile checks in the background whether a person is submitting the form. To do so, Cloudflare processes technical details such as your IP address, browser and device information and interaction signals from your visit. Turnstile sets no advertising cookies and builds no profile across websites. We also check the content of your message automatically for common advertising patterns. Submissions that are flagged are rejected and kept for a maximum of 90 days as a record. The legal basis is our legitimate interest in a form that stays free of abuse. Details on Cloudflare are in section 3.
Calls from Google ads. With an ad that includes a call function, Google may temporarily display a Google forwarding number and route the call to our telephone number. To measure results, Google records details such as the start and duration of the call, whether it was answered, the call source, country code, area code and call type, together with the associated campaign, ad group and search term. Depending on availability, the caller's telephone number may also appear in the call report for calls longer than 15 seconds. We can see these details in Google Ads and use them solely to assess enquiries and the effectiveness of our ads. Calls of 60 seconds or more are counted there once as a conversion. The optional call recording stays switched off in Google Ads, and we do not record these conversations ourselves. Details are set out in the Google privacy policy.
6 Online appointment booking (Calendly)
You can book an intro call on our contact page through the booking tool of Calendly, LLC, 115 E Main St., Ste A1B, Buford, Georgia 30518, USA.
When the contact page is opened, your browser establishes a connection to Calendly's servers in order to load the booking calendar, and your IP address reaches Calendly at that point, even if you do not book an appointment. If you do book an appointment, Calendly additionally processes your name, your email address, the appointment details and technical information such as time zone and device information on our behalf.
Calendly stores this data in data centres in the USA. The transfer is safeguarded: Calendly is certified under the Swiss-U.S. Data Privacy Framework, and Calendly's data processing addendum with standard contractual clauses applies in addition. Details: Calendly privacy notice. If you prefer not to use the booking tool, you can reach us by email or telephone at any time.
7 Email and collaboration (Google Workspace)
For email, documents and internal collaboration we use Google Workspace. Our contracting party is Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. Google offers data regions for supported editions and covered services. The region that applies to specific engagement data depends on the current Workspace configuration and the service concerned. The processing is governed by Google's Cloud Data Processing Addendum. Details: Google privacy policy.
Data from client engagements, such as payroll and personnel data, is processed in this protected environment. Processing follows Swiss data protection law and is governed by contract with our clients.
8 Disclosure to third parties
We sell no personal data and pass it on only where this is necessary to provide our services (to the processors named in this policy), where you have given your consent, or where the law requires us to do so.
9 Disclosure abroad
Personal data may be disclosed to the following countries:
- EU/EEA (Ireland in particular): countries with a legally recognised, adequate level of data protection.
- USA: solely to providers certified under the Swiss-U.S. Data Privacy Framework (Calendly, Cloudflare, Google). The Swiss Federal Council (Bundesrat) has recognised an adequate level of data protection for such companies since 15 September 2024. Standard contractual clauses apply in addition where appropriate.
10 Retention
We keep personal data only for as long as the purpose in question requires or statutory retention obligations demand (ten years as a rule for business records). After that, the data is deleted or anonymised.
11 Data security
The connection to this website is encrypted (TLS). Access restrictions apply within our working environment: your data is accessed only by the people who need it to deal with your request.
12 Your rights
You have the right at any time to information about whether and which personal data we process about you (Art. 25 revFADP), to the correction of inaccurate data and to erasure (Art. 32 revFADP), and to the release of your data in a common electronic format (Art. 28 revFADP). You may object to processing. To do so, write to office@clever-hr.ch; we reply within 30 days. You may also contact the Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB).
13 Changes
We may amend this privacy policy, for example when we change service providers. The version published on this page at any given time is the one that applies.
Last updated: 24 August 2026
This page presents the German privacy policy in English for convenience. The German version at clever-hr.ch/datenschutz/ is the legally binding one.