01
Scope and data roles
This notice applies to people who visit the site, contact Svperior, are introduced to Svperior, request consideration for a private briefing, attend an event, represent a client or supplier, receive professional communications, or otherwise interact with the office.
Svperior GmbH is the controller for the public website, general inquiries, event consideration, relationship administration, and its own legal and security obligations. Within a client mandate, Svperior may act as an independent controller, joint controller, or processor depending on who determines the purpose and means of processing. The engagement letter, data-processing agreement, or mandate-specific notice identifies that role and prevails for the relevant processing.
02
Personal data we collect
- Website and security data
- IP address, request time, requested path, referrer where supplied, browser and device information, response status, error information, and security signals may be processed by the site and infrastructure providers to deliver, diagnose, and protect the service.
- Browser preference
- A local-storage value records a manual day or night choice and its expiry at Zug’s next sunrise or sunset. It contains no name, account, or behavioural profile and is removed sooner if the visitor returns to the scheduled presentation or clears local storage.
- General inquiries
- The inquiry form collects name, email, optional principal or organization, introducer or existing Svperior relationship, selected discipline, the context supplied by the sender, and ordinary transmission metadata. The submission is delivered through configured SMTP to an authorized Svperior mailbox and is not intentionally written to the site database, CMS, browser storage, or website analytics.
- Private briefing requests
- Name, email, organization, role, optional introducer, explanation of why the briefing is relevant, acknowledgement of the invitation condition, event identifier, and ordinary transmission metadata. The form does not request social handles, identity documents, breach data, or OSINT scope.
- Professional and relationship data
- Role, organization, contact details, introductions, correspondence, meeting details, attendance, instructions, decisions, relationship history, and information needed for conflicts, sanctions, independence, fraud, or client-acceptance checks.
- Mandate information
- Where required by an accepted mandate, this may include legal, corporate, fiduciary, financial, technical, security, operational, communications, identity, location, access, device, account, family, employee, counterparty, or other information connected to the client’s stated objective.
- Research and exposure information
- Publicly available, commercially licensed, client-provided, or otherwise lawfully obtained information may be used for approved diligence, exposure, OSINT, threat-intelligence, or investigative work. Personal OSINT or dark-web work for an event participant is scoped and authorized separately after selection; it is not initiated from a public form alone.
03
Where the data comes from
- Directly from the person, including through inquiry and event forms, email, meetings, instructions, and materials supplied for a mandate.
- From an introducer, client, employer, family office, adviser, counterparty, event partner, supplier, or other person who represents that they are authorized to provide it.
- From public registers, court or regulatory records, media, websites, technical sources, sanctions and compliance sources, commercial databases, threat-intelligence sources, and other lawful research channels where relevant to an approved purpose.
- From the site, hosting, email, CMS, security, and communications infrastructure used to deliver and protect Svperior’s operations.
04
Purposes and legal grounds
Under Swiss law, Svperior processes personal data in accordance with the principles of lawfulness, good faith, transparency, proportionality, purpose limitation, accuracy, security, and privacy by design and default.
- Operate and secure the site
- To deliver pages, remember the chosen theme, diagnose errors, prevent abuse, preserve availability, investigate incidents, and maintain evidence. Where the GDPR or UK GDPR applies, the basis is Svperior’s legitimate interest in operating and protecting its public service and, where relevant, compliance with legal obligations.
- Review inquiries and establish a mandate
- To identify the request, route it to the appropriate discipline, communicate, conduct acceptance and conflict checks, prepare scope and commercial terms, and take steps requested before entering a contract. The applicable bases include steps at the person’s request, legitimate interests, and legal obligations.
- Select and administer private briefings
- To assess relevance to a limited room, coordinate with a confirmed event partner where necessary, issue invitations, prepare the session, manage attendance, protect the event, and follow up. The applicable bases include the requested pre-event steps and legitimate interests in curating and securing the briefing.
- Perform and administer accepted work
- To provide legal, cyber, and engineering services; communicate; manage access; produce and deliver work; invoice; keep records; protect people, systems, and rights; and meet professional, contractual, regulatory, and legal obligations. The basis may be contract, legitimate interests, legal obligation, an overriding private or public interest, or consent where law requires it.
- Maintain professional relationships
- To keep appropriate business contacts, remember introductions and prior discussions, invite suitable contacts to relevant briefings, and send direct professional communications. Svperior does not use purchased consumer-marketing lists. Consent or an opt-out is used where required by communications law.
- Protect legal and security interests
- To establish, exercise, or defend legal claims; prevent fraud and misuse; conduct sanctions or risk checks; respond to lawful process; investigate vulnerabilities; protect confidentiality; and comply with authorities. The basis is legal obligation and legitimate or overriding interests, as applicable.
05
Sensitive data and public-form limits
Svperior may need sensitive personal data, privileged material, alleged-offence information, financial information, credentials, precise location, health information, biometric information, or high-risk profiling inputs for a specifically accepted legal, cyber, diligence, or engineering mandate. Such data is not requested through general public forms and is processed only where necessary, proportionate, authorized, and supported by an applicable legal basis and mandate controls.
Do not place passwords, private keys, recovery codes, identity documents, vulnerability evidence, breach datasets, medical records, account data, or other restricted material in a general inquiry or event application. Ask Svperior to establish an appropriate intake route first.
06
Who may receive personal data
Svperior does not sell or rent personal data and does not disclose it for cross-context behavioural advertising. A supplier is not permitted to use client confidential information for its own unrelated purpose merely because it provides infrastructure to Svperior.
- Svperior personnel and partners
- Founding partners, personnel, and approved specialists receive only what is relevant to their role, discipline, acceptance review, or mandate.
- Infrastructure and service providers
- Providers supporting website hosting, content management, cloud infrastructure, email and SMTP delivery, security, communications, document handling, accounting, and professional administration may process data under contractual and confidentiality controls.
- Professional and implementation parties
- Implementing or local counsel, technical specialists, forensic providers, insurers, auditors, accountants, fiduciaries, and other advisers may receive data where the client authorizes it, the mandate requires it, or another lawful basis applies.
- Event partners
- A confirmed presenting, supporting, or sponsoring partner may receive limited applicant or attendee information only where needed to review, secure, or administer the relevant briefing and where the relationship is identified or otherwise appropriately communicated. No attendee list is published.
- Authorities and protected transactions
- Courts, regulators, law-enforcement bodies, tax authorities, or counterparties to a reorganization, financing, acquisition, or transfer may receive data where lawfully required and subject to appropriate confidentiality and necessity controls.
07
International processing and transfers
Svperior is established in Switzerland and serves cross-border clients. Depending on the selected infrastructure, participants, advisers, and mandate, personal data may be processed in Switzerland, countries within the European Economic Area, the United Kingdom, the United States, and another country directly connected to the accepted work.
Where data is disclosed to a country without a recognized adequate level of protection, Svperior uses an available lawful mechanism appropriate to the transfer, which may include recognized standard contractual clauses adapted for Swiss law, EU Standard Contractual Clauses, a UK transfer addendum or agreement, contractual protections, and supplementary technical or organizational measures. An exception is used only where the applicable law permits it. Mandate-specific destination states and safeguards are identified where the nature of the work requires more detail.
08
Retention and deletion
Svperior retains personal data for the shortest period consistent with the purpose, the mandate, defensible security, and applicable legal or professional requirements.
Deletion from active systems may not remove data immediately from encrypted backups or immutable security records. Those copies remain protected, are not restored for ordinary use, and expire through the applicable backup or retention cycle unless preservation is legally required.
- Public-site and security logs
- Retention is governed by the relevant infrastructure configuration and is ordinarily limited to the period needed for delivery, diagnosis, abuse prevention, and security review—generally no more than 90 days unless an incident, investigation, legal hold, or provider requirement justifies longer retention.
- Theme preference
- A manual day or night preference remains in the visitor’s browser only until Zug’s next sunrise or sunset. It is cleared sooner if the visitor returns to the scheduled theme or clears local storage. Svperior does not receive a user profile from that preference.
- Inquiries and unaccepted matters
- Correspondence and acceptance records are ordinarily retained for up to 24 months after the last substantive contact, then deleted or minimized unless a relationship continues or legal, conflict, sanctions, security, or claim requirements justify retention.
- Event consideration
- Applications that do not lead to an invitation or continuing relationship are ordinarily deleted within 12 months after the briefing. The application is delivered to an authorized mailbox and is not intentionally stored in the site database, CMS, browser storage, or analytics. Invited-participant and relationship records follow the relevant event or professional-contact schedule.
- Accepted mandates
- The engagement terms and mandate schedule control. Working material may be removed earlier when no longer needed. Records subject to Swiss accounting, professional, evidentiary, or other retention duties may be retained for the applicable statutory period, which can be ten years for certain business and financial records.
- Security reports and disputes
- Responsible-disclosure reports and investigation records are ordinarily retained for up to 24 months after closure. Relevant material may be retained longer where needed to establish facts, prevent recurrence, comply with law, preserve privilege, enforce rights, or manage an active or reasonably anticipated claim.
09
Cookies, local storage, analytics, and external links
The public site uses Google Analytics and Google Consent Mode to measure page views, engagement time, navigation, scroll and article depth, outbound and contact-link selections, and inquiry or event-application progress. Analytics storage is enabled so Google may distinguish visits and produce aggregated reports. Advertising storage, advertising user-data use, and advertising personalization remain denied.
Form values, names, email addresses, free-text submissions, and other form contents are not sent to analytics. A separate local-storage value records the temporary manual day or night choice.
External links open only when selected; no third-party map, media player, or social widget is embedded solely to display public information. External sites then process data under their own terms. Public fonts and brand assets are delivered as site assets rather than through an embedded advertising network.
Svperior uses the resulting reports to understand audience engagement, improve content and journeys, measure successful inquiries and event applications, and evaluate campaigns. Google is an infrastructure recipient for this processing and may process data internationally under its applicable data-protection terms and transfer safeguards. Visitors can use their browser controls to restrict or clear analytics storage.
10
Security and confidentiality
Svperior applies technical and organizational measures selected for the sensitivity, purpose, volume, location, and risk of the processing. Measures may include data minimization, access restriction, multi-factor authentication, encryption, separated workspaces, logging, secure transfer, vendor controls, retention schedules, and incident procedures. The Data Handling and Security Posture statements describe the public operating standard in more detail.
No internet transmission, mailbox, cloud platform, or storage system can be guaranteed absolutely secure. A person who believes personal data or a Svperior-controlled system has been exposed should contact inquire@svperior.com with the subject Security and avoid placing sensitive evidence in the first message.
11
Your rights and how to exercise them
Subject to applicable law and its exceptions, a person may request confirmation of whether Svperior processes personal data about them; access to that data and the required processing information; correction of inaccurate data; deletion or destruction; restriction or cessation of particular processing; objection to processing; delivery or transfer of data in a portable format where that right applies; or withdrawal of consent for future processing where consent is the basis.
Send a request to inquire@svperior.com with the subject Privacy. Identify the relationship or communication involved and the right being exercised. Svperior may request proportionate proof of identity and authority before disclosing or changing data. Requests are ordinarily handled without charge and within the period required by applicable law; under Swiss access rules this is generally 30 days. A request may be restricted, deferred, or refused where law permits, including to protect privilege, confidentiality, security, evidence, legal obligations, or the rights of another person. Reasons will be provided where required.
A person may raise a concern with the Swiss Federal Data Protection and Information Commissioner. Where the GDPR or UK GDPR applies, the person may also complain to the competent supervisory authority in their place of residence, work, or the alleged infringement.
12
Automated decisions and AI
The public website and event consideration process do not make solely automated individual decisions that produce legal or similarly significant effects. Eligibility, mandate acceptance, and invitations remain subject to human judgment.
Svperior does not use client confidential information, inquiry content, event applications, or restricted mandate data to train a public or shared general-purpose AI model without express written authorization. Any AI-enabled processing of client information is governed by the accepted mandate, approved tools, defined access and retention controls, and applicable law.
13
Children
The public site and services are directed to institutions, professionals, and adult private clients. Svperior does not knowingly solicit personal data from a child through the public site. Information about a child is processed only where relevant to an authorized mandate, supplied through an appropriate adult or lawful source, and subject to the safeguards required by the circumstances and applicable law.
14
Changes and contact
Svperior may update this notice when processing, providers, services, or law changes. A material change will be identified through the effective date and, where required, communicated through a proportionate additional notice. The version in effect when data is processed governs the public disclosure, while an engagement-specific privacy or data-processing agreement may provide additional or controlling terms for a mandate.
Privacy requests and questions should be sent to inquire@svperior.com with the subject Privacy or by post to Svperior GmbH, Hinterbergstrasse 49, 6312 Steinhausen, Switzerland.
