Home

Legal

Privacy notice

This notice explains how we process personal data when you use VSME-PRO (the demo, the lead and trial forms, and the authenticated workspace). Two frameworks apply together: the Swiss Federal Act on Data Protection (FADP), which governs us as a company established in Switzerland, and EU Regulation 2016/679 (GDPR), which applies because we offer the service to people located in the European Union.

Data controller

F&D Sàrl, Swiss limited liability company (Sàrl)

Avenue de Tivoli 19b, 1007 Lausanne, Switzerland

Registration: IDE/UID CHE-115.235.245 — Commercial Register of the Canton of Vaud

Operator of the VSME-PRO platform. Contact: info@vsme-pro.app

No Data Protection Officer (DPO) has been designated.

Categories of data collected

Identification and contact data (name, work email, role, company and, for trial requests, the VAT number); ESG and company data voluntarily entered in the workspace or demo flows; billing and subscription data for paid plans (card details are handled directly by the payment provider and never pass through our systems); navigation and product-usage data (funnel analytics); technical logs (IP address, user agent, timestamps) required for operation and security.

Purposes and legal bases

Providing the platform and workspace and managing the account (performance of a contract, Art. 6(1)(b) GDPR); sending follow-up and marketing communications about VSME/ESG, subject to double opt-in consent (Art. 6(1)(a)); security, abuse prevention and product analytics to improve the service (legitimate interest, Art. 6(1)(f)); accounting, tax and legal obligations (legal obligation, Art. 6(1)(c)).

Payment and billing data

For paid plans we use Stripe as our payment provider. Card details are collected and processed directly by Stripe on its own infrastructure: they never pass through our systems and are not stored by us. We retain the customer and subscription reference held at the provider, billing details and accounting records. The legal bases are performance of a contract (Art. 6(1)(b) GDPR) and compliance with accounting and tax obligations (Art. 6(1)(c)).

Data processors

We rely on providers that process data on our behalf under an Art. 28 GDPR agreement: Supabase (database and authentication, hosted in the European Union – Ireland); Brevo (transactional and marketing email, European Union – France); Stripe (payments and billing for paid plans); Vercel (frontend hosting and CDN, USA); ImprovMX (inbound email forwarding, USA). In addition, when you provide a VAT number for a trial request, that number is checked against the European Commission's public VIES service. An up-to-date list of processors is available on request.

Controller's location and transfers

Data is primarily hosted in the European Union, while the controller is established in Switzerland: Switzerland benefits from a European Commission adequacy decision, so transfers to the controller require no additional safeguards. Some providers (for example Vercel and ImprovMX) are based in the United States: any transfers take place under the European Commission's Standard Contractual Clauses (SCC) and the related Data Processing Agreements (DPA), with appropriate supplementary measures.

Retention period

Unconfirmed leads (no double opt-in): deleted within 6 months. Leads and CRM notes of confirmed contacts: until consent is withdrawn or 24 months of inactivity. Account and workspace data: for the duration of the relationship and thereafter for the periods required by law. Accounting and invoicing records: 10 years, as required by tax law. Technical logs: typically up to 12 months. These are our retention criteria and may be refined in the validated version.

Security measures

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR): encryption of data in transit (HTTPS/TLS) and encryption of the database at rest at our provider; access to the reserved area through a one-time code sent by email (OTP), with no passwords stored by us; per-organisation data isolation through row-level access policies, so each customer only sees their own data; internal access limited to authorised personnel on a least-privilege basis; backups and monitoring handled by our infrastructure providers. No system is absolutely secure, but we review these measures periodically.

Personal data breaches

In the event of a personal data breach we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33 GDPR). Where the breach is likely to result in a high risk to your rights and freedoms, we will also inform you without undue delay (Art. 34 GDPR), describing the nature of the incident and the measures taken.

Automated decisions, AI and customer data

We do not carry out solely automated decision-making that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). The guidance and quality-check features support data entry through rule-based logic and suggestions: the assessment remains yours and your advisor's, and VSME-PRO does not issue certifications, ratings or assurance. The ESG and company data you enter remains yours: we do not use it to train artificial intelligence models, we do not sell it and we do not use it for purposes other than providing the service. We may use aggregated, anonymous statistics that cannot be traced back to you or your company in order to measure and improve the product.

Your rights

You may at any time exercise your rights of access, rectification, erasure, restriction, objection and portability, and withdraw any consent given (without affecting the lawfulness of processing before withdrawal). To exercise them, write to the controller's address above; we will respond within the statutory time limits.

Right to lodge a complaint

Without prejudice to any other remedy, if you believe the processing of your data infringes applicable law you may contact the competent supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC). If you are in the European Union you may contact the authority of your country of residence, place of work or of the alleged infringement: in Italy, the Garante per la protezione dei dati personali.

Cookies and analytics

We use only two categories of tools. (1) Technical and necessary: required for the site and the reserved area to work (login session, language preference, storing your cookie choice). These do not require consent. (2) Product analytics: navigation events that tell us which steps work and where people get stuck. They are collected only with your explicit consent: until you choose, or if you select "Necessary only", we send no events at all. Analytics are first-party and hosted on our European infrastructure: we use no third-party advertising or profiling tools and we do not sell personal data. You can change your mind at any time through the "Cookie preferences" link at the bottom of every page.

Changes to this notice

This notice may be updated over time. The date of the latest update is shown at the bottom of the page; material changes will be communicated by appropriate means.

Last updated: 2026-07-20