Privacy
Privacy policy
Policy updated on 21 September 2026
This page explains how we handle the data of people who visit lumestudio.ch, write to us or work with us. If we change tools or providers, we update this policy before switching them on.
We collect little data, and for specific reasons: to answer the people who write to us, to run our clients’ projects, and to understand in aggregate how the site is used.
We do not sell your data, we do not pass it to third parties for advertising, and we do not profile you.
1. Who handles your data
For any question or request about your personal data, write to info@lumestudio.ch. A person answers, not an automated form.
- Controller
- FALKEM SWISS Sagl, operating under the trading name Lume Studio
- Registered office
- Piazza Indipendenza 3, CH-6830 Chiasso, Switzerland
- UID/VAT
- CHE-190.276.060 IVA
- Privacy email
- info@lumestudio.ch
2. Which law applies
The primary framework is the Swiss Federal Act on Data Protection (FADP).
The European GDPR applies when the territorial conditions in Article 3 are met, for example when we offer services to people located in the European Union. Where it applies, the rights described in section 9 apply in addition.
3. What data we collect
- When you write from the Contact form
- Your first and last name, your business, the kind of project you are looking for, your message, and the contact detail you choose yourself: email or phone. When you confirm, the form sends the enquiry directly to Lume Studio. We treat it as received only when the site confirms acceptance.
- When you write by email
- The sender address, the subject, the content of the message and any attachments.
- When you browse the site
- The technical data every website receives in order to work: IP address, date and time, page requested, browser and device type. It is used to deliver the pages and to protect the site from abuse.
- Your cookie choice
- It stays in your browser’s local memory under the key "lume-consent-v2". It is not a tracking cookie and it never leaves your device: it only applies your choices and saves us from asking again on every visit.
- Site statistics
- Basic statistics are collected by PostHog without cookies and without saving anything on your device: page views, traffic sources and the steps of the path to the form, with an identifier computed on the provider’s servers and renewed every day. If you switch on extended statistics, an identifier stays in your browser to link the pages of one visit. If you switch on session recording, we record how you use the pages with every field masked, never on the contact form and the confirmation page. We also collect the technical errors the pages produce in your browser, with the message and the point in the code that raised them, so that we notice faults; those too never on the contact form and the confirmation page.
- When you become a client
- Project and business details, written approvals, correspondence and billing data. The materials you hand over stay yours.
- When you pay
- When a website-package invoice is validly issued, it states the verified payment details and the payment method applicable to that invoice.
4. Why we process it
- Answering your request, understanding the project and preparing a quote.
- Running the project and our relationship with you: communication, approvals, delivery and support.
- Remembering the cookie choice you made, in your browser.
- Understanding in aggregate how the site is used, so we can improve it.
- Keeping the site running and protecting it from abuse.
- Issuing invoices and meeting Swiss accounting and tax obligations.
5. On what basis
Swiss law requires processing to be lawful, proportionate, transparent and secure, and the data to be accurate. We collect only what the purposes above require, and nothing beyond that.
Where the GDPR applies, the legal bases are these:
- pre-contractual steps and performance of the contract, for your request and for the project (Art. 6(1)(b));
- our legitimate interest in keeping the site running and secure (Art. 6(1)(f));
- our legitimate interest in understanding, in aggregate, how the site is used, for the cookieless basic statistics (Art. 6(1)(f)), which you can object to from the “Cookie preferences” panel;
- your consent, for extended statistics, session recording and any other non-essential tool, which you can withdraw at any time (Art. 6(1)(a));
- legal obligations, for invoices and accounting records (Art. 6(1)(c)).
6. How long we keep it
- Enquiries that do not become a project
- After confirmed delivery, the enquiry content remains in the D1 database for no more than 30 days. The related operational metadata remains for 90 days. Content for unresolved enquiries remains in D1 during delivery attempts and is deleted within 24 months after receipt. Your name, email, phone and project details stay in that database and are not copied anywhere else: the Lume admin application, which runs on a server of ours, reads only the enquiry identifier, the arrival time, the activity you stated and the language, and keeps that record of the arrival in its own contact register, where no contact detail appears.
- Clients
- Working files remain for the project and are returned or deleted from copies controlled by Lume within 90 days after handover, unless the client instructs otherwise or law requires retention. The order, approvals, changes, handover and minimum relationship evidence are kept for 10 years after the relationship ends.
- Invoices and accounting records
- 10 years, as the Swiss Code of Obligations requires.
- Your cookie choice
- It stays in your browser until you change it or clear the site data.
- Technical data and statistics
- Operational form metadata remains in D1 for 90 days. PostHog keeps statistics events for one year and session recordings for 30 days. We do not create a permanent local copy of those statistics.
7. Who we entrust your data to
We work with a small set of selected providers to run the site, communications and payments. The list below explains what data they receive and for what purpose. We do not sell your data and we do not use it for third-party advertising.
Beyond the providers listed below, your data reaches only our accounting adviser or a lawyer where needed, and the authorities where the law requires it.
- Cloudflare
- Delivery and hosting of the site and protection against attacks. Cloudflare receives the form enquiry through a site function, stores it in the EU-jurisdiction D1 database, and processes it with a queue and a dedicated process in the same account.
- PostHog
- Site statistics, on servers in the European Union in Frankfurt: the cookieless basic statistics and, only with your consent, extended statistics and session recording. It never receives your name, email, phone or the content of the form.
- Hostpoint
- Email for info@lumestudio.ch, so the messages you send us and our replies.
- GitHub
- Version control and website deployment automation. It may receive code, content and assets intended for the website; form enquiries, passwords and full payment details remain outside the code archive.
- Wise
- Receipt and reconciliation of website-project invoices, only when the invoice identifies a verified Wise account.
8. Transfers outside Switzerland
The Cloudflare D1 database used for the form has EU jurisdiction. The Lume admin application runs on a server we control and reads from that database only the enquiry identifier, the arrival time, the stated activity and the language.
For transfers to countries without a Swiss adequacy decision, the DPAs and other applicable standard contractual documents of Cloudflare and GitHub provide, depending on the processing, for the Swiss–US Data Privacy Framework for certified organizations in the United States and/or standard contractual clauses adapted to the FADP. Wise processes payment data under its privacy notice and applicable regulatory duties; providers may involve other countries listed in their current subprocessor lists.
PostHog keeps the statistics on servers in Germany, a country Switzerland recognises as providing adequate data protection.
9. Your rights
You can ask us whether we process data about you and obtain a copy, have it corrected or deleted where the conditions are met, withdraw at any time a consent you gave, for example for extended statistics or session recording, and object to the basic statistics from the “Cookie preferences” panel.
Where the conditions of Article 28 FADP are met, you can ask for your data to be handed over or transmitted in an electronic format. Where the GDPR applies, restriction, objection, portability and a complaint to the competent authority apply in addition.
Write to info@lumestudio.ch: we answer within 30 days. You may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC).
10. Security
We protect data with measures proportionate to the systems we control: encrypted connections, secrets kept separate from public code, collection limited to necessary fields and revocable access. For external services, we use the controls available in the relevant account and limit the data sent to the stated purpose.
No system is completely secure and we cannot guarantee provider continuity. Where a personal data breach is likely to result in a high risk to the personality or fundamental rights of affected persons, we notify the FDPIC as soon as possible. We also inform the affected person when this is necessary for their protection or required by the FDPIC.
11. Changes and contact
The date at the top of the page identifies the published version of this policy. If we add a tool, a provider or a new purpose, we update this policy before switching it on and, where consent is required, we ask you for it.
For any question: info@lumestudio.ch.