Privacy Policy
Version privacy-2026-09-27.1, last updated on 27 September 2026. Earlier versions are available from the privacy contact.
- Data Controller
- Ada StudioAdriana-Ramona AdafinoaieiRössligasse 35, 4125 Riehen, Switzerland
- GDPR scope and EU representative
- Ada Studio is established only in Switzerland. Our services are directed at organisations in Switzerland; we do not offer them to people in the EU, and we do not monitor the behaviour of people in the EU. On our assessment of 27 September 2026, the GDPR therefore does not apply to our processing (Article 3(2) GDPR), and for that reason we have not designated a representative in the EU under Article 27. If the GDPR nevertheless applies to the processing of your personal data, you can exercise the rights it grants directly with us at the privacy contact below, and you may lodge a complaint with an EU/EEA supervisory authority. If we begin to offer our services to people in the EU, we will designate a representative and name it here.
- Purposes of Processing
- We provide and protect this website, respond to enquiries and discuss potential services. The assessment tools create reports in your browser. When AI risk report sending is available, you may request a copy for your verified email address, a review by Ada Studio, or both. We process the report only after you verify your address and confirm sending. An email-only choice sends no copy to Ada Studio’s inbox. A review request permits assessment follow-up and does not subscribe you to marketing.
- Legal Basis
- We follow the Swiss Federal Act on Data Protection, including proportionality and purpose limitation. Where the GDPR applies, taking steps you request before entering into a contract with us, or performing a contract with you, relies on Article 6(1)(b); other enquiries and business contact correspondence rely on our legitimate interest in answering relevant requests under Article 6(1)(f). Hosting and abuse prevention also rely on our legitimate interest in providing a reliable, secure website under Article 6(1)(f). Article 6(1)(c) applies only where a specific legal obligation under EU or Member State law requires processing. If processing relies on consent, you may withdraw it. We do not make decisions about you with legal or similarly significant effects solely by automated means. Where the GDPR applies, the optional assessment-sharing step relies on your voluntary, specific consent under Article 6(1)(a) for the selected recipients and purposes. You can use the assessment without sharing and withdraw consent by contacting us; withdrawal cannot recall an email already delivered.
- Data Categories
- Hosting and security providers process technical request data such as IP addresses, request time, requested URL and browser information. Contact enquiries include your email address, message, optional details, language, a random enquiry ID and submission time. AI risk reports contain the version, date, questions, answers, unknowns, recommendations and supplied context. Email verification sends your email address and a cryptographic fingerprint of the frozen submission, without assessment answers; the code email contains no answers. After confirmation, the hosting and email providers process the report, recipient choices, purpose, notice version and submission time. Optional review fields include name, organisation and a message. Ada Studio’s inbox receives the report only if you select a review. Error records contain the time, page path, technical error details and error message text, as described under Error reports.
- Data Retention
- There is no website database or online history of assessment reports. Drafts you save in your browser, downloads and copies in your own mailbox stay under your control. The table shows how long we and our providers keep other records.
Exceptions apply only where records are needed for agreed client work, a specific legal obligation or a dispute, and are documented. Historical reports from the earlier delivery feature will be classified with their original purpose by 14 December 2026 before deletion is proposed; ending that feature did not delete them. Deleting an accessible copy does not immediately erase recovery or provider copies. Our enquiry retention policy was adopted on 15 September 2026. Contact us about a specific record or deletion request.Data Retention Record How long it is kept Email verification codes Expire after ten minutes. The code email stays in your mailbox. Confirmed risk report sending Can be retried for less than 23 hours from submission. Expiry does not delete emails already sent or provider records. Ordinary enquiries Deleted 12 calendar months after the enquiry is closed. Declined enquiries Deleted six calendar months after the decline. Enquiry attachments Unnecessary copies are removed promptly; others are deleted within 90 days after closure. Risk report review copies Deleted 90 days after the enquiry is closed. Error reports, if switched on Kept only as long as needed to find and fix the fault. No fixed deletion period has been set yet. Email content and delivery records at Resend 30 days, with backups kept for seven days. Earlier deletion of a specific email can be requested from Resend support. Deleted messages in our Microsoft 365 mailbox Recoverable for 14 days after deletion, under current settings. Runtime logs at Vercel One day on our current hosting plan. - Your Rights
- Depending on the applicable law and its conditions, you may request access, correction, erasure, restriction and data portability. Erasure is not limited to inaccurate data. Your right to object is set out separately below. You may withdraw consent without affecting processing that was lawful before withdrawal. Send a request to the privacy contact below; you do not need to complete an assessment or agree to marketing. You may contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) or lodge a complaint with the competent EU/EEA supervisory authority, particularly where you live, work or consider that an infringement occurred.
- Right to object
- Where the GDPR applies to the processing of your personal data, you may object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Article 6(1)(f)). We then stop, unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims (Article 21(1)). You may object at any time to processing for direct marketing, and we then no longer use your data for that purpose (Article 21(2) and (3)). Under the Swiss FADP, processing your personal data against your express objection breaches your personality rights unless it is justified, for example by an overriding interest or by law (Articles 30(2)(b) and 31(1) FADP). Send your objection to the privacy contact below.
- Privacy authorities
- Swiss FDPICEU/EEA supervisory authorities
- International Data Transfers
- Vercel hosts and protects the website; the functions that handle contact requests and optional risk report sending run in Frankfurt, Germany. Resend delivers form messages from an EU sending region but stores customer data, including email content and delivery records, in the United States. Contact enquiries and selected review copies arrive in Ada Studio’s Microsoft-hosted mailbox. The administrator’s data-location card checked on 15 September 2026 places Exchange Online data at rest in Switzerland. The current setting permits future regional storage within the EU Data Boundary, with no location change before 13 December 2026. This storage setting does not restrict all support or subprocessor processing to Switzerland. Email-only report copies go solely to the visitor’s selected mailbox; sending email yourself also involves your own provider. The overview below lists, for each provider, the data it receives, where it processes data and the safeguard for transfers outside Switzerland and the EU/EEA. Providers also use subprocessors; for each provider, the overview links its published subprocessor information, which names the countries concerned where the provider states them. These safeguards do not mean that all processing stays in Switzerland or the EU/EEA. You can ask the privacy contact for a copy of the relevant transfer terms.International transfers by provider, checked on 26 September 2026
- Vercel Inc., United States
- Role
- Hosting, page delivery and server functions (processor)
- Data
- Technical request data; enquiries, report sending and error reports while our functions handle them; runtime logs
- Where
- Functions in Frankfurt, Germany; pages from Vercel’s global network, usually the location nearest you; possible processing in the United States and in the countries of Vercel’s subprocessors
- Safeguard
- Certified under the Swiss-US and EU-US Data Privacy Framework; standard contractual clauses in the Vercel DPA
- Subprocessors
- Named with their countries in Vercel’s subprocessor list
- Plus Five Five, Inc. (Resend), United States
- Role
- Email delivery for enquiries, risk reports, verification codes and error reports (processor)
- Data
- Email addresses, message and report content, delivery records
- Where
- Sends from an EU region; stores customer data in the United States
- Safeguard
- Standard contractual clauses in the Resend DPA, adapted for transfers from Switzerland; certified under the EU-US Data Privacy Framework, not the Swiss-US framework
- Subprocessors
- Named in Resend’s subprocessor list, which places all of them in the United States
- Microsoft, Microsoft 365
- Role
- Ada Studio’s mailbox (processor)
- Data
- Enquiries, review copies, error reports and our correspondence
- Where
- Mailbox data at rest in Switzerland; under the Microsoft DPA, support and subprocessors may process data in the United States and in other countries where Microsoft or its subprocessors operate
- Safeguard
- Standard contractual clauses in the Microsoft DPA; Microsoft is also certified under the Swiss-US and EU-US Data Privacy Framework
- Subprocessors
- Named in Microsoft’s subprocessor list
- Cloudflare, Inc., United States
- Role
- Turnstile security check (processor); separate controller when improving bot detection
- Data
- IP address, TLS fingerprint, browser user agent, site key and origin
- Where
- Cloudflare’s global network; possible processing in the United States
- Safeguard
- Certified under the Swiss-US and EU-US Data Privacy Framework; if that certification lapses or is invalidated, the Cloudflare DPA applies standard contractual clauses, adapted for transfers from Switzerland
- Subprocessors
- Named with their countries in Cloudflare’s subprocessor list
- Vercel Inc., United States
- Cookies and browser storage
- The AI Readiness Check saves answers in this tab’s browser session storage so you can continue after reloading. Start over clears this saved assessment when browser permissions allow it. Browser session restoration may retain it; use your browser settings to clear site data if removal fails. Decision Lab also uses session storage to resume a fictional story. Neither feature creates an account or cloud backup, and people with access to the same browser session may see the saved state. The AI Risk Check also keeps your answers, any context you type and your current step in this tab’s session storage, so a reload or going back does not lose them; closing the tab or clearing site data removes them. If you select Save on this device, a draft also remains in this browser until you switch saving off, use Delete saved copy or clear site data. Neither copy contains your email address or verification codes. We remove accessible records left by the retired advertising feature when the site runs; browser restrictions can prevent cleanup. This does not remove records previously received by providers.
- Advertising measurement
- Google Ads measurement has been removed from this website. We do not load the Google tag, send conversion events or add advertising click identifiers to new enquiries. There is no advertising consent setting to enable. Removing website measurement does not delete historical records held by Google, email providers or Ada Studio; contact us about those records.
- Local fonts and downloads
- The website, public decks and downloadable worksheets use locally served fonts. PDF downloads load fonts from this website and generate the report in your browser; assessment answers are not sent for that download. Copying the report also happens locally.
- Analytics
- Aggregate tool measurement is not currently enabled. Assessment answers, report IDs, contact details and free text are not sent to an analytics service.
- Newsletter
- No newsletter sign-up is active on this website. Buttondown, the service prepared for a possible newsletter, receives no data while it is inactive, and the website does not permit connections to it.
- Local reports and optional sharing
- PDF downloads and copied text are created in your browser without an email address. Quick and Standard are initial assessments without a compliance verdict; Detailed retains its precise questions and sources. If available, the optional sending controls let you choose yourself, Ada Studio at contact@adastudio.ch, or both. Neither is preselected. Email is required only for sending; review name, organisation and message are optional. Before sending, you can inspect the recipients and the report. Verify your email with an eight-digit code valid for ten minutes, then confirm sending. Each chosen recipient receives a separate readable email and PDF. Changing the recipient choices or report requires fresh verification. Reading or downloading does not send answers. The manual email link opens a draft in your own email app with a subject and a one-line result summary, without your answers and without attaching or sending anything. Separately, choosing Share in the AI Readiness Check passes an overall category, short description and result link to your selected app or clipboard. It excludes your answers and priorities. Anyone opening that link sends its coarse result category to the hosting service as part of the page request, which may appear in hosting logs. The selected app handles what you share under its own terms.
- Contact enquiries
- Email and message are required to submit an enquiry and receive a reply; without them, the form cannot send. Name, organisation, subject, service and the preparation brief are optional. Only the reviewed message and contact fields are submitted, not separate brief answers or assessment reports. Resend delivers the enquiry to our Microsoft-hosted mailbox. We use it to respond and assess whether our services fit your request, without adding you to a marketing list. Our application does not write contact text to browser storage or deliberately to application logs. If an unexpected error occurs while an enquiry is handled, an error message that quotes submitted text could reach an error report or the runtime log, as described under Error reports. Provider delivery records and mailbox copies are separate.
- Error reports
- When an unexpected error occurs on our server, or your browser reports a crash to our error endpoint, we record it only to find and fix the fault. If error reporting is switched on, Resend delivers an email report to Ada Studio’s mailbox; it contains the time, the page path, technical error details and up to 500 characters of the error message, which can occasionally quote text you entered. For server errors, Next.js, the software the website runs on, also writes the full error message and technical details, such as where in the code the error occurred, to Vercel’s runtime log, whether or not an email is sent. If a report is not emailed, for example because reporting is switched off, an entry with the page path and up to 200 characters of the error message is written to the runtime log. Vercel keeps the runtime log for one day on our current hosting plan. Browser reports are limited per IP address; the address is held briefly in the server’s memory for that limit and is not included in the report. We rely on our legitimate interest in a reliable, secure website.
- Contact form security
- When sending is available, Cloudflare Turnstile loads before submission, once you start filling in the contact page form or the floating contact form. It processes your IP address, TLS connection fingerprint, browser user agent, and the website’s site key and origin to distinguish people from automated traffic. Our server verifies the challenge before sending your enquiry. Cloudflare acts as our processor for this protection and as a separate controller when using signals to improve bot detection, as explained in its Turnstile Privacy Addendum. We do not configure Turnstile to issue clearance cookies. If the check is unavailable, you can use the email link instead. For optional risk report sending, Turnstile loads only after you select a recipient option. The server checks it separately for code requests, code confirmation and report sending. Neither verification stage sends assessment answers.
- Decision Lab
- The Decision Lab story keeps your choices in your browser and sends none of them to us. Its own notice has the details: Decision Lab privacy notice.
- Provider information
- VercelResendMicrosoftCloudflare Turnstile
- Provider transfer terms
- VercelResendMicrosoftCloudflare
- Privacy contact
- contact@adastudio.ch