Skip to Content
← Home

Privacy

How we protect data for visitors in vulnerable legal situations

🛡 Our promise to you: Many of our visitors live in legally vulnerable situations. We have designed this site, our checkout, and our database with that in mind. We collect the absolute minimum, we never share with immigration authorities, and you can ask us to delete everything at any time.

1 · Who is responsible

Verein KI|E|RO Solutions
Scherzligweg 10 · 3600 Thun · Schweiz
HR-Nr. CH-036.6.104.113-3 · UID CHE-449.056.305
support@kiero.ch

For data protection requests specifically: privacy@kiero.ch (GPG key available on request).

2 · What we collect — the bare minimum

WhenWhatWhy
BrowsingAnonymous traffic count, page view, country (city-level only)To know which articles help most
Buying the bookE-mail, payment metadata from Stripe/PayPal (no card numbers stored on our side)Deliver the PDF and customer support
Franchise signupName (or pseudonym), e-mail, payout method, country of residenceRun the affiliate program, pay commissions, comply with Swiss accounting law
Legal serviceFull identity documents (passport, birth certificate, etc.)Required to file applications with authorities. Stored encrypted, separate from marketing data.

What we DO NOT collect

  • No immigration-status field on any form.
  • No precise GPS or address — until you actively start a legal service.
  • No third-party advertising trackers (no Facebook Pixel, no Google Ads tag).
  • No fingerprinting or session replay.

3 · Lawful basis

  • Contract performance (Art. 6(1)(b) GDPR / Art. 31 revDSG): everything needed to deliver products and services you bought.
  • Legitimate interest (Art. 6(1)(f) GDPR / Art. 31 revDSG): security logs, fraud prevention, anonymous analytics.
  • Consent (Art. 6(1)(a) GDPR / Art. 6 revDSG): newsletter, optional analytics cookies, optional marketing.
  • Legal obligation: Swiss accounting law (10-year retention of invoices), anti-money-laundering law for large payouts.

4 · Where data is stored

Our primary databases are hosted on Swiss servers (Thun and Bern). Some processors (Stripe, PayPal, Odoo Cloud, transactional e-mail) are EU/EEA-based and bound by the EU SCC. Document storage for legal services uses encrypted Swiss-based storage with at-rest AES-256 and per-customer keys.

5 · Who we share with — and who we never share with

We share with: our payment processors (Stripe, PayPal), our partner lawyers (only if you actively engage their service and after explicit consent), and partner language schools (only after you enroll).

We never share with: immigration authorities of any country, employers, landlords, or any third party not strictly needed to deliver your purchase. We do not sell or trade data. Ever.

If a foreign government formally requests data, we resist disclosure to the extent legally possible under Swiss law. We will be compelled only by a Swiss court order — and we will notify you unless legally gagged.

6 · How long we keep data

  • Browsing analytics: 6 months, aggregated.
  • Book customer e-mail: as long as you want the lifetime updates, plus 10 years for Swiss accounting (anonymised invoice only).
  • Franchise commissions records: 10 years (Swiss accounting law).
  • Legal service documents: 10 years after case closes (immigration law evidence rules), then irreversibly deleted.

7 · Your rights — and how to use them

You have the right to:

  • Access all data we hold about you (we respond within 30 days).
  • Correct wrong information.
  • Delete everything — except records we are legally required to keep (Swiss accounting, ongoing legal cases). We will tell you exactly what stays and why.
  • Port your data in machine-readable format.
  • Object to any processing based on legitimate interest.
  • Withdraw consent any time, for any processing where consent is the basis.
  • Complain to the Swiss data protection authority EDÖB or, if you are in the EU, to your national authority.

Send any of these requests to privacy@kiero.ch. We do not require ID verification for simple book-customer deletions; we do require it for legal-service files.

8 · Server log files

Standard web server logs capture IP address, browser, OS, referrer and timestamp for security purposes. They are auto-deleted after 7 days unless an active security incident requires longer retention.

9 · Children

This service is for adults (18+). We do not knowingly collect data from minors. If you discover a minor has signed up, write to us at the privacy address and we will delete the data within 72 hours.

10 · Changes to this policy

We may update this policy. The version active at the time of your interaction governs that interaction. For franchisees and active service customers, material changes are e-mailed 30 days in advance.

Version 2.0 · June 2026 · This policy is jointly drafted under DSGVO and Swiss revDSG.