Privacy Notice
Last updated: August 18, 2026
This notice describes the website configuration reviewed on July 23, 2026. It is not legal advice. Points marked for review should be confirmed by a qualified Swiss privacy or legal advisor.
1. Controller
The controller for personal data processed through the JCapRisk website is JCapRisk – Dr. Jasmin Šahbegović, Kreuzlingen, Switzerland. Privacy contact: info@jcaprisk.ch.
2. Categories of personal data
Website and server-log data may include IP address, date and time, requested page, referring page, browser type, operating system, device information, response status, and technical security information. Inquiry data may include name, institution, business email address, area of interest, deadline, message content, and information included in an email or attachment. Communication data may include email metadata, correspondence, meeting information, and follow-up records.
3. Processing purposes
Personal data may be processed to operate and secure the website, respond to inquiries, assess potential engagements, prepare discussions and proposals, maintain necessary business records, comply with legal obligations, and establish, exercise, or defend legal claims.
4. Website hosting and server logs
The website is hosted through Infomaniak Network SA. The hosting provider may process server-log and security data to deliver, maintain, and protect the service. The exact log fields, storage locations, access controls, and retention periods depend on the active hosting configuration and require technical verification.
5. Contact form and email processing
The current contact form does not submit information to a website backend. It validates required fields in the browser and prepares an email addressed to info@jcaprisk.ch. No inquiry data is sent by the website until the visitor sends the email from the visitor’s email application. After sending, the data is processed by the sender’s email provider, the JCapRisk email service, and infrastructure used to route the message.
6. Processors and recipient categories
Recipient categories may include the website and email hosting provider, authorized representatives of JCapRisk, professional advisers where necessary, approved service providers supporting a defined engagement, and public authorities where disclosure is legally required. Independent specialists receive client information only where their role, confidentiality terms, permitted access, and client approval have been established.
7. Storage location and retention
Website and domain-email services are currently managed through Infomaniak. Exact storage locations, email routing, backups, administrative access, and server-log retention require technical verification. Inquiry and correspondence data is retained only for as long as needed to respond, assess an engagement, maintain required records, comply with legal obligations, or establish, exercise, or defend legal claims. Retention is determined by purpose and applicable obligations rather than one fixed period.
8. International transfers
Email messages may transit through infrastructure outside Switzerland depending on the sender’s provider and message routing. The website currently loads Montserrat through Google Fonts. A font request may transmit technical data, including the visitor’s IP address and browser information, to Google. Destination countries and applicable safeguards depend on the current service configuration and provider terms. This requires legal verification. Self-hosting the approved font should be assessed to reduce third-party data transfers.
9. External services, fonts, analytics, tracking, cookies, and embedded content
The website code reviewed for this release loads Google Fonts. No analytics scripts, advertising tags, social-media pixels, or embedded third-party media were identified in the reviewed HTML files. The reviewed code does not intentionally set analytics or marketing cookies. Whether the hosting platform sets technically necessary cookies or similar storage requires technical verification. External links, including LinkedIn, are not embedded content. The external provider’s terms apply after a visitor follows the link.
10. Data-security principles
JCapRisk uses risk-appropriate organizational and technical measures intended to protect personal data against unauthorized access, loss, alteration, disclosure, or misuse. Specific engagement requirements for client-system access, confidentiality, encryption, handover, return, and deletion are defined in the relevant engagement terms. No certification or formal control framework is claimed on this website unless separately verified.
11. Data-subject rights
Subject to applicable law and exceptions, individuals may request information about personal data processed about them and may request correction, deletion, restriction, objection, or portability where applicable. Requests may be sent to info@jcaprisk.ch. Identity may need to be verified before a request is fulfilled. Individuals may also contact the Swiss Federal Data Protection and Information Commissioner.
12. Review points
Qualified Swiss privacy or legal review is required for international-transfer safeguards, Google Fonts, email routing, retention periods, processor terms, GDPR applicability, and any future analytics, tracking, cookies, embedded services, or backend form processing.
13. Changes to this notice
This notice should be updated when the legal entity name changes, fonts are self-hosted, the contact form is connected to a backend, analytics or tracking is added, or hosting, email, processors, transfer locations, or retention practices change.
