Legal
Privacy policy
In short: we process only what your inquiry and our work require. No advertising profiles, no sale of data. What follows sets out in detail what happens with your data.
1 Data controller
Responsible for the processing of personal data in connection with this website:
beeVisto GmbH (clever hr is a brand of beeVisto GmbH)
Registered office: Weieracherstrasse 4, 8184 Bachenbülach
Business and contact address:
Münchhaldenstrasse 10
8008 Zurich, Switzerland
Email: office@clever-hr.ch
Telephone: +41 44 589 73 11
2 Principles
We process personal data under the revised Swiss Federal Act on Data Protection (Datenschutzgesetz, revFADP), in force since 1 September 2023. We follow the principles of transparency, purpose limitation and proportionality: we process only the data we need for the purpose in question, and only for as long as we need it. This website is aimed at clients in Switzerland.
3 Visiting the website (hosting)
Opening this website generates certain data for technical reasons: the IP address of your device, the date and time of access, the pages you open, and information about your browser and your device. We need this data to deliver the website and to keep it secure and stable. It is held briefly in server log files and is not combined with other data.
For the operation and delivery of the website we use Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare processes the technical data described above on our behalf and is certified under the Swiss-U.S. Data Privacy Framework (see section 11). Details: Cloudflare privacy policy.
Visitor counting. We count how often our pages are opened and how many people visit the website each day. The count runs on the server and works without cookies. So that several page views by the same person on the same day count as a single visit, we derive a pseudonymous HMAC check value from the IP address, browser identifier, date and a secret key. Without that key it cannot be used for a simple comparison, and it is deleted after 30 hours; your IP address itself is not stored for this purpose. We look at totals only: page views, number of visits, pages opened, referring website, advertising campaign, country and recognized referrals from AI services. We keep these totals for up to 400 days. No profiles are created, and we do not pass the figures on. Visits from known search engine and AI crawlers are left out of the count entirely. The data is held by Cloudflare in its role as processor described above.
4 Cookies and local storage
The visitor count in section 3 works without cookies and without recognizing anyone beyond a single day.
Google Ads conversion tag. Every page loads tag AW-18387386707. The script comes from googletagmanager.com (Google). We use it to see whether someone who clicked one of our ads then opens a page, calls us, or uses the contact form or Calendly. Successfully submitted contact forms are recorded as conversions. The content of your inquiry is not sent to Google. We use the same tag in our booking shop at shop.clever-hr.ch. After a paid booking, it sends the order value and an order number to Google, without your name or email address. After that kind of ad click, Google may set the cookies it usually uses for this. Details are in the Google privacy policy (same link as in section 5).
When you confirm our data-protection note, your browser stores that locally (localStorage). Nothing is sent to us for that. The Calendly booking tool may set its own technically necessary cookies (see section 6). You can limit or refuse cookies in your browser settings at any time.
Fonts and other design files are loaded from our own servers. A page load does not connect to Google Fonts.
5 Getting in touch (form, email and telephone)
If you contact us by email or telephone, we process the details you send us (for example name, company, email address, telephone number and your request) solely in order to answer your inquiry and to prepare for any collaboration that follows. Processing takes place in our Google Workspace environment (see section 8). Section 6 applies to online appointment booking.
Inquiry form. On the contact page you can send us an inquiry through a form. The details you enter are transmitted: name, company, email address, telephone number, the topic you select and your message. Transmission is encrypted and runs through our own server-side function at Cloudflare (see section 3). After validation, your inquiry is accepted into durable Cloudflare storage for a maximum of 400 days. A monitored queue retries email delivery after a failed attempt; failures and permanently failed jobs are logged and alerted without message content. The form confirms acceptance only after durable storage. The inquiry and delivery metadata are then deleted automatically. To protect the form against automated submissions, we limit the number of inquiries per connection and hour. For this we store a secret-keyed HMAC check value for a maximum of one hour, and we do not store the IP address itself. The legal basis is our legitimate interest in answering your inquiry and in a form that works and stays free of abuse.
Checking for automated submissions (Cloudflare Turnstile). The form is protected by Cloudflare Turnstile. Turnstile checks in the background whether a person is submitting the form. To do so, Cloudflare processes technical details such as your IP address, browser and device information and interaction signals from your visit. Turnstile sets no advertising cookies and builds no profile across websites. We also check the content of your message automatically for common advertising patterns. Submissions that are flagged are rejected and kept for a maximum of 90 days as a record. The legal basis is our legitimate interest in a form that stays free of abuse. Details on Cloudflare are in section 3.
Calls from Google ads. With an ad that includes a call function, Google may temporarily display a Google forwarding number and route the call to our telephone number. To measure results, Google records details such as the start and duration of the call, whether it was answered, the call source, country code, area code and call type, together with the associated campaign, ad group and search term. Depending on availability, the caller's telephone number may also appear in the call report for calls longer than 15 seconds. We can see these details in Google Ads and use them solely to assess inquiries and the effectiveness of our ads. Calls of 60 seconds or more are counted there once as a conversion. The optional call recording stays switched off in Google Ads, and we do not record these conversations ourselves. Details are set out in the Google privacy policy.
6 Online appointment booking (Calendly)
You can book an intro call on our contact page through the booking tool of Calendly, LLC, 115 E Main St., Ste A1B, Buford, Georgia 30518, USA.
When the contact page is opened, your browser establishes a connection to Calendly's servers in order to load the booking calendar, and your IP address reaches Calendly at that point, even if you do not book an appointment. If you do book an appointment, Calendly additionally processes your name, your email address, the appointment details and technical information such as time zone and device information on our behalf.
Calendly stores this data in data centers in the USA. The transfer is safeguarded: Calendly is certified under the Swiss-U.S. Data Privacy Framework, and Calendly's data processing addendum with standard contractual clauses applies in addition. Details: Calendly privacy notice. If you prefer not to use the booking tool, you can reach us by email or telephone at any time.
7 Private shop: booking, payment and documents
If you book a package in the private shop as a private individual, we process your name, your email address, your billing address, the package you book, the price, the time and version of the accepted terms for private clients, and the payment status. We need this data to conclude and perform the contract, to email you confirmations, appointment links and the invoice, and to keep our accounts.
Payment by card or TWINT is handled by the payment service Stripe (the Stripe group; Stripe's privacy policy names the Stripe company that is responsible). You enter your card or bank account details directly with Stripe. We receive the invoice amount, currency, payment status and booking and invoice details. This information may also be processed by our internal AI assistant (section 9). Stripe also processes data on its own account, for example to prevent fraud and to meet legal duties, and may disclose it to the United Kingdom, the EU and the USA. Stripe, LLC is certified under the Swiss-U.S. Data Privacy Framework. Details: Stripe privacy policy.
You choose the times for the booked sessions through a personal link at Calendly (see section 6). You upload documents such as a CV or a job posting through a personal link that expires. We store them encrypted in our business system, which runs on servers in Austria (EU), and we use them only for the service you booked. If the upload fails, you can also send the documents by email to office@clever-hr.ch.
The server infrastructure of this business system is operated by netcup GmbH, Emmy-Noether-Strasse 10, 76131 Karlsruhe, Germany, as a processor. The data center is in Vienna (Austria). The purpose is hosting the database and documents. Processing is governed by netcup's data processing agreement.
We keep your documents, for example your CV, certificates, cover letter, salary details and all uploaded files, at most until the advice or the workshop is completed, and we delete them afterwards. If the service is not completed (for example because follow-up appointments are never booked), we delete them at the latest 90 days after the last appointment, the payment or the last upload. For longer we keep only what the law requires: the invoice and booking records for ten years (Art. 958f OR), and none of your documents.
Additional copies may exist in our email account. You can contact office@clever-hr.ch to request their deletion. We back up the data daily. We keep daily backups for seven days and one backup per week for up to 35 days. The backups are stored in the EU with Cloudflare R2.
7a clever hr portal and upload links for business clients
clever hr portal runs at netcup in Vienna (Austria). The Portal server country chosen in the Individual Contract does not change the location of this temporary upload intake. Backups are encrypted, stored in the European Union with Cloudflare R2, and kept for no more than 35 days after creation.
Each personal upload link is assigned to exactly one business client. Transfer is encrypted, files are scanned for viruses and stored temporarily directly in that client's file in the clever hr portal. We delete them from active storage no later than 30 days after receipt. Our team may deliberately move only a business document containing no personal data about employees or applicants into the client file's “Documents” section. Where the client provides its own system, clever hr portal serves as a temporary transfer route. The client remains the controller; clever hr processes the data on its behalf under the DPA.
The AI assistant in the clever hr portal receives only upload metadata: client, number of files, time of receipt and status. Upload contents and file names are not sent to external AI services.
8 Email and collaboration (Google Workspace)
For email, documents and internal collaboration we use Google Workspace. Our contracting party is Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. Google offers data regions for supported editions and covered services. The region that applies to specific engagement data depends on the current Workspace configuration and the service concerned. The processing is governed by Google's Cloud Data Processing Addendum. Details: Google privacy policy.
We process data from client engagements, such as payroll and personnel data, in this protected environment and, where the DPA permits it and our work requires it, with AI-assisted tools. This is covered by sections 6.1 and 6.2 of the terms for business clients. A person reviews the results before we pass them on. Section 9 covers our internal AI assistant.
9 AI assistance and AI-assisted maintenance
For drafts, summaries and filing suggestions we use an internal assistant in our business system on our own servers. The model responses come from Anthropic, PBC (the Claude service), based in the USA. Information from emails and client files may be sent to Anthropic: sender and recipient, subject, message, attachment notes, client names and addresses, and, for bookings, invoice amount, currency, payment status and invoice reference. Sending employee data from business client engagements to external AI services requires documented instructions and prior written approval under the DPA (terms for business clients, sections 6.1 and 6.2).
We send CVs and application documents from services for private clients to external AI only with the private individual's separate, voluntary consent. We may then analyze the documents and prepare recommendations and draft feedback. A person checks the results before we use them. Without consent there is no AI review of these private documents. Documents from business client engagements are governed by the instructions and approval required under the DPA. You may withdraw your consent at any time by emailing office@clever-hr.ch. The AI receives no card or bank account details from the payment process. Stripe handles payments (section 7).
We also use AI-assisted tools to maintain and develop our business system: Claude from Anthropic, Codex and ChatGPT from OpenAI, and Cursor from Anysphere, Inc. Coding assistants receive dedicated access, with activity logged. Inputs and necessary code context may reach these providers and the model providers used through Cursor. Models accessed through OpenRouter receive no access. Data processing and possible model training are governed by the terms of the service used and its account settings.
Disclosure to the USA rests on Art. 16 para. 2 let. d revFADP. Anthropic safeguards it through standard contractual clauses with an addendum for Switzerland in its data processing addendum (version of 24 February 2025). Details: Anthropic data processing addendum.
10 Disclosure to third parties
We sell no personal data and pass it on only where this is necessary to provide our services (to the processors named in this policy), where you have given your consent, or where the law requires us to do so. This includes netcup GmbH (Karlsruhe, Germany) as processor for hosting the database and documents of the business system in the data center in Vienna (Austria).
11 Disclosure abroad
Personal data may be disclosed to the following countries:
- EU/EEA (Ireland and Austria in particular) and the United Kingdom: countries with a legally recognized, adequate level of data protection.
- USA: to providers under the Swiss-U.S. Data Privacy Framework (Calendly, Stripe, Cloudflare, Google). The Swiss Federal Council (Bundesrat) has recognized an adequate level of data protection for such companies since 15 September 2024. Standard contractual clauses apply in addition where appropriate. For Anthropic, standard contractual clauses with an addendum for Switzerland apply (section 9, Art. 16 para. 2 let. d revFADP). The contractual terms for data access by OpenAI and Cursor during maintenance depend on the service and account used.
12 Retention
We keep personal data only for as long as the purpose in question requires or statutory retention obligations demand (ten years as a rule for business records). After that, the data is deleted or anonymized. The periods for documents from services for individual clients are set out in section 7. That section also covers email copies, backups, invoices and booking records.
13 Data security
The connection to this website is encrypted (TLS). Access restrictions apply within our working environment: your data is accessed only by the people who need it to deal with your request.
14 Your rights
You have the right at any time to information about whether and which personal data we process about you (Art. 25 revFADP), to the correction of inaccurate data and to erasure (Art. 32 revFADP), and to the release of your data in a common electronic format (Art. 28 revFADP). You may object to processing. To do so, write to office@clever-hr.ch; we reply within 30 days. You may also contact the Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB).
15 Changes
We may amend this privacy policy, for example when we change service providers. The version published on this page at any given time is the one that applies.
Last updated: October 10, 2026
This page presents the German privacy policy in English for convenience. The German version at clever-hr.ch/datenschutz/ is the legally binding one.