← back

Privacy Policy

Last updated: 17 July 2026

This policy describes how personal data is handled on ninepeaks.dev. The site is operated by ninepeaks from Switzerland.

Scope

The portfolio pages do not require registration and do not use analytics or advertising trackers. Personal data is collected only when a visitor submits the contact form or continues an existing conversation through the ticket system.

Data collected

When the contact form is used, the following information may be processed: the name or handle provided, the email address given for replies, the message content, and any uploaded attachments. In addition, the server may record technical data required for operation and security, such as IP address, request time, and similar log entries.

Purpose of processing

Personal data is used to receive and process inquiries, send a confirmation that a request was received, maintain the related correspondence, and protect the service against misuse. Processing is carried out to respond to the request and, where relevant, to take steps prior to a possible contract, in accordance with the revised Swiss Federal Act on Data Protection (revFADP). Submitting the contact form constitutes agreement to this processing for the stated purpose.

Personal data is not sold and is not used to build advertising profiles.

Recipients and hosting

To operate the website and contact system, the following categories of service providers may receive personal data as processors or infrastructure providers:

Hosting. The website, ticket database, and uploaded files are stored on a virtual server located in Germany (European Union).

Brevo. Email delivery, confirmation messages, and routing of inbound replies are handled through Brevo.

Cloudflare. Where DNS and proxy services are enabled, connection metadata may be processed by Cloudflare during a visit to the site.

Cookies

The site uses a single functional cookie (np_csrf) to protect forms against cross-site request forgery. This cookie is not used for tracking or marketing purposes.

Retention

Open tickets are retained for the duration of the correspondence. After a ticket is closed, the related data and attachments are deleted within twenty-four months, unless earlier deletion is requested or a longer retention period is required by law. Server logs are rotated in the ordinary course of operation.

Rights of data subjects

Under applicable Swiss data protection law, you may request information about personal data held about you, correction of inaccurate data, and deletion where no legal obligation to retain the data applies. Requests should be sent through the contact form, using the same email address as in the original inquiry, so that the request can be verified.

You may also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).

Security

The site is accessed over HTTPS. Form submissions are protected by CSRF tokens and rate limiting. Access to stored tickets is restricted to the operator. Reasonable technical and organisational measures are applied; however, no method of transmission over the internet is completely secure.

Changes

This policy may be updated from time to time. The date at the top of the page indicates the current version.

Privacy · Legal notice