Privacy Policy
Last updated: 26.08.2026
This policy describes how CloudCan GmbH processes personal data in connection with its website, customer area, Genesis and customer relationships.
1) Controller
CloudCan GmbH
For any data-protection question or request, use the CloudCan contact form.
2) Legal framework
We process data in accordance with the Swiss Federal Act on Data Protection (FADP).
The GDPR is taken into account where it actually applies to a specific processing activity.
3) Data processed
a) Contact, account, order and support
Depending on your relationship with CloudCan, we process in particular:
- business identity, company, role and contact details;
- email address, authentication data, language preference and login logs;
- ordered service and configuration, price, currency, status, billing details and proof of acceptance;
- invoices, payment status and transaction references, without full card data processed by the payment provider;
- requests, communications, submitted documents and support history.
Do not submit unnecessary sensitive data in free-text fields.
b) Technical data
For operation and security, we may process:
- IP address, date, time, device, browser and language;
- pages viewed and technical or campaign events;
- login, security, diagnostic and abuse-prevention logs.
Campaign identifiers are pseudonymous and do not directly contain the recipient’s name or email address.
4) Purposes and grounds
We process the data necessary to:
- respond to enquiries and prepare an offer;
- create accounts, conclude and perform contracts, provide Genesis, invoice and collect payment;
- secure services, prevent abuse, provide support and manage our rights;
- measure traffic, campaign effectiveness and improve services.
These activities are based on requested pre-contractual measures, performance of the contract, our legal obligations, our legitimate interests or, where required, your consent, which you may withdraw for the future.
5) Audience measurement and campaigns
CloudCan uses Umami, a self-hosted audience measurement solution.
a) Privacy-friendly configuration
Umami is configured without cookies, local storage, fingerprinting or cross-site tracking to measure website traffic.
b) Campaign attribution
UTM parameters measure campaign effectiveness. Links may include a pseudonymous identifier that attributes a click or conversion to a communication; it does not directly contain the recipient’s name or email address.
c) Data and hosting
Analytics data is hosted by CloudCan and used only for audience measurement, campaign attribution and website improvement.
If this configuration changes or applicable law requires it, CloudCan will request consent before the relevant processing.
6) Cookies
The website uses only the following functional cookie:
| Cookie | Use |
|---|---|
| i18n_redirected | Stores the display language. |
Umami does not set tracking cookies.
7) Anti-spam protection
Forms may use technical checks to prevent automated submissions and abuse.
The related data is processed only to protect the forms and service.
8) Recipients and providers
CloudCan does not sell your personal data. Where necessary, it may disclose data to authorised staff and hosting, infrastructure, security, messaging, payment, billing, maintenance or support providers, and to authorities or advisers where required by law or to defend rights.
9) International transfers
Data required for payments is disclosed to Stripe and may be processed in the United States and other countries listed in its current service-provider list. Data entrusted to PlanetHoster may be processed in Switzerland, France or Canada depending on the service used. Where a country does not provide adequate protection, the transfer relies on a safeguard recognised under Swiss law, including the Swiss–US Data Privacy Framework or appropriate contractual clauses. See Stripe’s current service-provider list.
10) Retention
We retain data only for as long as required for the stated purposes and legal obligations:
- enquiries without a contract: 24 months after the last exchange;
- account data: while active, then generally 24 months after closure, subject to data linked to the contract;
- orders, contracts, acceptance records, invoices, payment references that form part of accounting records, and other accounting records: 10 years after the end of the relevant financial year or relationship, according to the applicable obligation;
- technical and security logs: generally 90 days, except where an incident, abuse or evidence requires longer retention;
- support requests: generally 5 years after closure, or retained with the contractual file where they establish a right or obligation;
- analytics and campaign data: as long as needed for measurement and analysis, then deleted or aggregated.
11) Security
CloudCan applies appropriate technical and organisational measures to protect data against unauthorised access, loss, alteration or disclosure.
12) Your rights
Subject to legal conditions, you may exercise the following rights:
- access to your personal data;
- correction of inaccurate data;
- deletion where the conditions are met;
- withdrawal of consent for the future;
- delivery or transmission of data in the cases provided by law.
Exercise your rights through the contact form by selecting “Data protection”. We may request information necessary to verify your identity.
Authorities
You may contact the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Where the GDPR applies, you may also contact the competent supervisory authority.
13) Changes
We may update this policy. The version and date displayed on this page identify the applicable text.
