X-TECH
X-TECH|STUDIO
Skip to content

Privacy Policy

This Privacy Policy explains how X-Tech Studio AG (the “Company”, “we”, “us”) processes personal data in connection with our website (https://x-tech.studio) and our business relationships. It is drafted in accordance with the revised Swiss Federal Act on Data Protection (revFADP, SR 235.1), in particular Art. 19 revFADP (duty to inform), and the Data Protection Ordinance (DPO, SR 235.11). Where the EU General Data Protection Regulation (GDPR) additionally applies, we comply with it as well.

Effective date: [date] · Version: [v1.0] · Last updated: 17 June 2026

X-TECH Studio is in the process of incorporation. Fields shown as [pending] are not yet available and will be completed once the underlying fact exists — they are shown here rather than omitted or guessed at.

1. Controller Identity and Contact

The controller responsible for the processing of personal data described here is:

X-Tech Studio AG (in formation until entry in the Commercial Register)
Schaffhauserstrasse 500, 8052 Zürich, Switzerland
Email: info@x-tech.studio
Website: https://x-tech.studio
Represented by Ecda Erol, Founder & CEO

For all data-protection matters, including the exercise of your rights, you may contact our data-protection contact point:

Data-protection contact: [name / role — e.g. Data Protection Contact]
Email: [privacy@x-tech.studio — mailbox pending]
Postal address: as above

We are not legally required to appoint a Data Protection Officer / data-protection adviser under Swiss law for a company of our size and processing profile. We have [not / voluntarily] appointed one. [if a data-protection adviser is appointed and notified to the FDPIC under Art. 10 revFADP, insert their contact details here].

2. Categories of Personal Data We Process

Depending on how you interact with us, we process the following categories of personal data:

  • Website visitors (server logs): IP address, date/time of request, pages/URLs accessed, referrer URL, browser type and version, operating system, and similar technical data automatically transmitted by your device.
  • Cookies & analytics: Device/usage identifiers, interaction and reach-measurement data (see §6).
  • Contact forms / email enquiries: Name, email address, company, phone (if provided), message content, and any data you choose to include.
  • Customers & orders (B2B): Contact and company details of your representatives, billing and delivery addresses, order and product details, correspondence, and contract-performance data.
  • Payment data: Billing details and transaction data; full card/bank credentials are processed by our payment service provider, not stored by us (see §7).
  • Newsletter / marketing: Email address and, optionally, name and preferences, plus consent and dispatch/interaction logs.
  • Suppliers & partners: Contact details of your representatives and contract-related data.
  • Applicants (if applicable): Application documents and related correspondence.

We do not intentionally collect special categories of personal data through the website. Please do not submit such data via contact forms.

3. Purposes of Processing

We process personal data to:

  • operate, secure, and maintain the website and ensure its technical stability and IT security;
  • respond to enquiries and communicate with you;
  • conclude and perform contracts, including quotation, order processing, delivery, invoicing, payment, returns, and support for our AXIOM force/torque sensors and accessories;
  • manage our customer, supplier, and partner relationships (CRM);
  • send newsletters and information about our products where permitted;
  • comply with legal and regulatory obligations (e.g. bookkeeping and retention under the Swiss Code of Obligations, tax/VAT, export-control and product-compliance duties);
  • analyse and improve the website and our offering (reach measurement, statistics); and
  • protect, exercise, or defend legal claims and prevent misuse/fraud.

4. Legal Bases

Under Swiss law, the lawful processing of personal data does not generally require a specific legal “justification” unless a data subject's personality is unlawfully infringed; processing in good faith, proportionately, and for a recognisable purpose is permitted. Where a justification is relevant, we rely on one or more of the following:

PurposeBasis (Swiss / GDPR equivalent)
Contract performance & pre-contractual stepsContract / Art. 31(2)(a) revFADP · GDPR Art. 6(1)(b)
Legal/regulatory compliance (accounting, tax, export control)Legal obligation / Art. 31(2)(c) revFADP · GDPR Art. 6(1)(c)
Website operation, security, reach measurement, direct marketing to existing customersLegitimate/overriding interest · GDPR Art. 6(1)(f)
Newsletter to non-customers, non-essential cookies/analyticsConsent (revocable at any time with future effect) · GDPR Art. 6(1)(a)

5. Source of the Data

We obtain personal data primarily from you (directly, via the website, forms, email, or in the course of a business relationship) and from your device (technical/log data). Where lawful, we may also receive data from third parties such as business partners, public registers/sources, or credit/identity-check providers.

6. Cookies, Analytics, and Reach Measurement

Our website uses cookies and similar technologies. Strictly necessary cookies are required for the website to function and are set without consent. Non-essential cookies (e.g. analytics/reach measurement, preferences) are set only with your consent, which you can give or withdraw at any time via our [cookie banner / consent manager].

Account access: When you request access to a protected account area, your email address and technical access metadata are processed by Cloudflare, our access-control and infrastructure processor, solely to verify access and protect the account area. Cloudflare sets a strictly necessary authorization cookie for the duration defined by our access-security policy; it is not used for advertising or marketing.

Analytics: We use [analytics tooling not yet selected — e.g. a privacy-friendly, cookieless tool such as Plausible / Matomo / Fathom, provider, location, and IP-anonymisation status to be specified] to measure reach and improve the website.

Other tools: [list any additional tools — e.g. embedded maps, fonts CDN, video, tag manager — or state “none”].

A full, up-to-date list of cookies, providers, purposes, and storage durations is available in the [cookie settings / cookie policy]. You can also configure your browser to refuse or delete cookies; this may limit website functionality.

7. Recipients and Processors

We disclose personal data to the following categories of recipients only as necessary for the purposes above, and engage processors bound by written data-processing agreements that meet Art. 9 revFADP (and GDPR Art. 28 where applicable):

CategoryExamples / placeholderRole
Web hosting & infrastructure[hosting / cloud provider, location]Processor
ERP / CRMOdoo (Odoo S.A., SaaS — hosted in the EU)Processor (ERP/CRM — orders, customers, invoicing)
Email & communications[email/CRM/newsletter provider]Processor
Payment service provider(s)[e.g. Stripe / PostFinance / acquirer]Independent controller / processor
Shipping & logistics[carrier(s) — e.g. Swiss Post / DHL / freight forwarder]Recipient (delivery)
Professional advisers & auditorslawyers, tax advisers, [auditor if any]Recipient / processor
Authorities & courtstax/customs/data-protection authorities, courtsRecipient (where legally required)

We do not sell personal data. Disclosure to other third parties occurs only with your consent, where legally required, or to protect our legitimate interests / legal claims.

8. Cross-Border Transfers

Some recipients/processors named in §7 may be located outside Switzerland, including in the EU/EEA and potentially the USA or other countries.

  • Transfers to countries with an adequate level of data protection recognised by the Swiss Federal Council (Annex 1 DPO), including EU/EEA states, take place on that basis.
  • Transfers to countries without recognised adequacy (which may include the USA and others) take place only under appropriate safeguards, in particular the EU Standard Contractual Clauses (SCCs) adapted/recognised for Switzerland, and/or another legal mechanism under Art. 16–17 revFADP. [where a recipient is certified under the Swiss–U.S. Data Privacy Framework, note that here].

A copy of the relevant safeguards can be requested at info@x-tech.studio / [privacy@x-tech.studio — mailbox pending].

9. Retention

We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law. In particular, business and accounting records are retained for 10 years under Art. 958f CO. Server logs, contact-form data, and analytics data are retained for [specific retention periods to be set]. Newsletter data is retained until you unsubscribe. Thereafter, data is deleted or anonymised, unless longer retention is required to comply with legal obligations or to establish, exercise, or defend legal claims.

10. Your Rights

Subject to the conditions and exceptions of applicable law, you have the right to:

  • information / access to whether and which personal data we process about you (Art. 25 revFADP);
  • rectification of inaccurate data (Art. 32 revFADP);
  • erasure / destruction of your data;
  • object to processing, and to request that we stop processing or not disclose your data to third parties;
  • restriction of processing;
  • data portability — to receive personal data you provided in a structured, commonly used, machine-readable format, and (where technically feasible) have it transmitted to another controller (Art. 28 revFADP); and
  • withdraw consent at any time with future effect, where processing is based on consent.

To exercise these rights, contact us at info@x-tech.studio / [privacy@x-tech.studio — mailbox pending]. We may need to verify your identity. Exercising your rights is generally free of charge, subject to the statutory exceptions. We will respond within the statutory time limits.

11. Automated Individual Decision-Making and Profiling

We do not carry out automated individual decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 21 revFADP). If this changes, we will describe the logic involved and the consequences, and update this section.

12. Data Security

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, or alteration, in line with Art. 8 revFADP and Art. 1–6 DPO (e.g. access controls, encryption in transit, backups, least-privilege, and vendor due diligence). No transmission over the internet can be guaranteed to be fully secure. In the event of a data-security breach that is likely to result in a high risk to data subjects, we will notify the FDPIC and affected persons as required by Art. 24 revFADP.

13. Right to Lodge a Complaint

If you believe our processing of your personal data infringes data-protection law, you may contact us at any time and you have the right to lodge a complaint or report with the competent supervisory authority. In Switzerland this is the:

Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, 3003 Bern, Switzerland · https://www.edoeb.admin.ch

Where the GDPR applies, you may also contact the supervisory authority of your EU/EEA habitual residence, place of work, or place of the alleged infringement.

14. EU/CH Representative

A company without an establishment in the EU/EEA that is subject to the GDPR may be required to designate an EU representative (GDPR Art. 27); under Art. 14 revFADP, a controller domiciled abroad may, in certain cases, have to designate a representative in Switzerland. [assessment pending: based on our establishment in Switzerland and the scope of our processing, whether a representative is required, and if so their name and contact details].

15. Changes to This Privacy Policy

We may amend this Privacy Policy from time to time to reflect changes in our processing or the law. The current version is always available at https://x-tech.studio/privacy with its effective date. Material changes will be communicated as appropriate.