1. Data Controller
ELK Media L.L.C.
30 N Gould St, Ste R
Sheridan, WY 82801
United States
Email: info@kmuseiten.ch
2. Scope
This privacy policy applies to the website kmuseiten.ch, any communication initiated through it, and all related digital services of ELK Media L.L.C.
3. Applicable Data Protection Law
Personal data is processed primarily in accordance with the Swiss Federal Act on Data Protection (DSG) and its ordinance. The European General Data Protection Regulation (GDPR) applies where its scope is applicable.
4. Categories of Personal Data
We process the following categories of personal data insofar as they arise from the use of our website and services:
- Identity and contact data (name, email address, phone number)
- Company-related data (company name, role, industry)
- Inquiry and communication content
- Contract and project data
- Technical connection data (IP address, browser, OS, access times)
- Log and security data
5. Data Sources
We receive personal data:
- Directly from the data subject (contact form, email, phone)
- From their employer or company in the course of project initiation
- Through technical access to the website (automatically collected connection data)
6. Processing Purposes
We process personal data for the following purposes:
- Operation and security of the website
- Responding to inquiries and correspondence
- Preparing quotes and contract negotiations
- Contract fulfillment and project delivery
- Client and project management
- Abuse and fraud prevention
- Compliance with legal obligations
- Accounting and archiving
7. Legal Basis
Under Swiss data protection law, processing occurs within the framework of legitimate business and contractual interests. Where the GDPR is applicable, we rely on:
- Contract performance or pre-contractual measures (Art. 6(1)(b) GDPR)
- Legitimate interests (Art. 6(1)(f) GDPR)
- Legal obligations (Art. 6(1)(c) GDPR)
- Consent, where obtained (Art. 6(1)(a) GDPR)
8. Website Hosting and Security Logs
Cloudflare, Inc.
This website is served via Cloudflare Workers. Cloudflare automatically processes technical connection data with each page request:
- IP address (anonymized or truncated per Cloudflare policies)
- Requested URL and HTTP method
- Browser and operating system information
- Access timestamp
- Data volume transferred
Purpose: website delivery, DDoS protection, network security. Cloudflare processes data on servers worldwide, including the USA. Legal basis: legitimate interest in a secure and available web presence. More information: cloudflare.com/privacypolicy.
Google Fonts
For displaying the DM Sans typeface, Google Fonts is loaded. This establishes a connection to Google servers on page load, transmitting the visitor's IP address to Google. Purpose: typographic rendering of the website. More information: policies.google.com/privacy.
9. Forms and Direct Communication
When you contact us via a contact form or email, we process the submitted data (name, email address, message content, and any additional information you provide) for the purpose of handling your inquiry.
Data is stored in our email system and not shared with third parties unless required for contract fulfillment. Inquiries that do not result in a contract are deleted after 12 months at the latest.
10. External Service Providers
Cloudflare, Inc.
Purpose: Website hosting, CDN, DDoS protection
Data categories: Technical connection data
Processing location: Global (including USA)
Safeguards: EU Standard Contractual Clauses, DPA
Technically necessary: Yes
Google LLC (Google Fonts)
Purpose: Web font delivery
Data categories: IP address, HTTP request data
Processing location: USA
Safeguards: EU Standard Contractual Clauses
Technically necessary: Yes (for correct display)
Google Ireland Limited (Google Analytics)
Purpose: Web analytics and reach measurement
Data categories: IP address (anonymized), usage data, device and browser information
Processing location: EU / USA
Safeguards: EU Standard Contractual Clauses, Adequacy Decision (EU-US Data Privacy Framework)
Technically necessary: No (consent-based only)
11. International Data Transfers
The controller is a US company. Technical service providers may process data outside Switzerland and the EEA, particularly in the USA.
Where no adequate level of data protection is recognized, we rely on:
- Standard Contractual Clauses recognized by the EU Commission
- Contractual and technical safeguards
- Encryption during transmission
12. Cookies and Storage Technologies
This website uses technically necessary storage technologies (e.g., for language preferences) and optional analytics cookies:
Technically Necessary Cookies
These are required for website operation and are set without consent. They serve language selection and session management.
Google Analytics
We use Google Analytics (Google Ireland Limited / Google LLC) to statistically evaluate website usage and improve our services. Google Analytics uses cookies that enable analysis of usage. The information generated is typically transferred to and stored on a Google server.
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Purpose: Reach measurement, usage analysis, website optimization
- Data categories: IP address (anonymized), page views, session duration, referral source, device and browser information
- Processing location: EU / USA
- Retention: Up to 14 months
- Legal basis: Consent (cookie banner)
Google Analytics is only activated after your explicit consent via the cookie banner. You may revoke your consent at any time through the cookie settings in the footer. More information: policies.google.com/privacy.
13. Retention
We retain personal data only as long as necessary for the respective purpose or as required by statutory retention obligations:
- Inquiries without contract: Up to 12 months
- Contract and project data: Duration of the contractual relationship plus statutory retention periods
- Invoices and accounting records: 10 years (per legal requirements)
- Technical logs: Maximum 90 days
- Communication after contract end: Up to 3 years (statute of limitations for contractual claims)
14. Data Security
We implement appropriate technical and organizational measures to protect your data, including encrypted transmission (TLS), access controls, and regular security reviews. Absolute security cannot be guaranteed due to inherent system limitations.
15. Your Rights
You have the following rights regarding your personal data:
- Right to information about stored data
- Right to correction of inaccurate data
- Right to deletion, unless a statutory retention obligation applies
- Right to restriction of processing
- Right to data portability in a common format
- Right to revoke consent
- Right to lodge a complaint with the competent supervisory authority
Direct inquiries to: info@kmuseiten.ch
Competent Swiss supervisory authority: Federal Data Protection and Information Commissioner (FDPIC).
16. Changes
This privacy policy may be updated when processing activities or the legal landscape change. The current version is always available on this page.
Last updated: August 1, 2026