PRIVACY

Privacy.

How this site handles personal data. We are pre-GA and design-partner-focused, so we collect as little as possible. Last updated 2026-09-30.

Who is responsible

Attestree is the trading name of Marc Kevin Borer, a sole trader based in Switzerland. He is the controller of the personal data described on this page; "we" below means him.

Marc Kevin Borer, trading as Attestree
Hirzengarten 2
4226 Breitenbach
Switzerland
Switzerland
[email protected]

This notice covers this website, its forms and our mailboxes. It does not describe the Attestree software, which you host yourself.

The waitlist and early-access forms

The forms collect your email address (required) and, only if you choose to provide them, your name, role, fleet size, industry, which products interest you, and a note. With each submission we also record which page's form you used, the time you signed up and the time you last updated your entry. If you submit again with the same address, the new answers replace the old ones.

If you reached the site through one of our tagged links, we also record that link's campaign tags (utm_source, utm_medium, utm_campaign, for example "linkedin", "social", "2026-10-launch-week"), so we can tell which channel brought you here.

The short sign-up boxes on other pages only pass the address you typed to the waitlist page, in the page address. It is saved to the list only when you submit the form there. The list stores no IP address and no browser details.

Why. To contact you about design-partner and early access and, if you signed up from a research page, to send you new essays. We do not sell or share your contact information, and we do not use it for unrelated marketing.

Legal basis. Your consent, which you give by submitting the form (GDPR Art. 6(1)(a)). You can withdraw it at any time by emailing us, and we then delete your entry. For the page and campaign tags, our legitimate interest in knowing which channels reach the people the product is for (GDPR Art. 6(1)(f)).

How long. For 18 months from the day you first signed up, or until you ask us to delete your entry, whichever comes first. The 18-month limit is enforced by an automatic clean-up that runs each time the form is used.

Where. In a database at Cloudflare that is restricted to the EU by Cloudflare's EU jurisdiction setting, which fixes where the database runs and keeps its data — a binding restriction, not a best-effort region. We read it from Switzerland, through an access-controlled admin page. When a new address joins, the site sends us a notification email through Microsoft 365; it contains no personal data, only the source page, a running total and a link to that admin page.

Analytics

We use Cloudflare Web Analytics. A small script reports each page view to Cloudflare: the page path (without anything after a "?"), the referring site, page-load timings, and the country, browser, operating system and device type derived from the request. Cloudflare states that it uses no cookies or other storage in your browser for this and does not fingerprint visitors by IP address or browser. No advertising pixels, no cross-site tracking.

Why. To see which pages are read and whether the site loads properly. Legal basis. Our legitimate interest in that (GDPR Art. 6(1)(f)). How long. Cloudflare keeps the figures available to us for six months.

Hosting, security and logs

The site is served by Cloudflare. To deliver a page and to protect the site from attacks and automated abuse, Cloudflare processes the technical data every web request carries: your IP address, the address of the page, your browser's user-agent string and the time. If a connection to the site fails, your browser may also send Cloudflare a short error report. Every connection to the site is encrypted (HTTPS). We run no web server of our own and keep no access logs ourselves; Cloudflare keeps its own logs under its own retention rules.

The forms are protected by Cloudflare Turnstile, which checks that a submission comes from a person. It processes your IP address, browser user-agent and similar connection signals, and our server passes your IP address and the Turnstile result to Cloudflare to verify it. We store neither. Cloudflare also uses these signals, on its own responsibility, to improve its bot detection.

Legal basis. Our legitimate interest in a site that is delivered reliably, readable and protected from abuse (GDPR Art. 6(1)(f)).

Email

If you write to hello@, privacy@ or [email protected], we process your address, your name if you give it, and whatever your message contains. The mailboxes are hosted on Microsoft 365.

Why. To answer you, to act on privacy requests, and to handle security reports. Legal basis. Our legitimate interest in answering (GDPR Art. 6(1)(f)); steps at your request before a contract (Art. 6(1)(b)) where that is what you wrote about; a legal obligation (Art. 6(1)(c)) where we must act on a request about your data. How long. As long as the conversation needs, and afterwards only where we have a reason to keep a record or Swiss law requires it.

Swiss law

We are in Switzerland, so the Swiss Federal Act on Data Protection (FADP) applies to all of the above. The FADP does not require a separate legal basis for each of these activities; we follow its processing principles (FADP Art. 6), and where a justification is needed we rely on your consent or on an overriding private interest (FADP Art. 31). Where the GDPR applies to you, the legal bases named above apply.

Who receives it, and where it goes

Cloudflare, Inc. (United States) hosts the site and provides the waitlist database, the form handling, Turnstile, the analytics and the access control for our admin page. It acts as our processor. The waitlist database stays in the EU; page requests are handled by the Cloudflare data centre nearest to you and may be processed in other countries, including the United States.

Microsoft hosts our mailboxes (Microsoft 365) as our processor. Email may be processed outside Switzerland and the EU, including in the United States.

We do not share your data with anyone else. Switzerland and the EU each recognise the other's data-protection law as adequate. For the United States, Cloudflare and Microsoft each state that they are certified under the Swiss-U.S. and EU-U.S. Data Privacy Frameworks; Cloudflare states that it falls back on standard contractual clauses if a certification lapses.

Cookies and browser storage

The site itself sets no cookies. To carry campaign tags from the page you landed on to the form, it keeps the three values in your browser's session storage for that tab. It is not a cookie, holds nothing else, is cleared when you close the tab, and is only sent to us if you submit a form. If you arrive without a tagged link, nothing is stored.

Cloudflare's protection against automated traffic may set a short-lived cookie that is strictly necessary for that security check. It is not used for analytics or advertising.

Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to its use, or to hand it over in a common electronic format, and you can withdraw a consent at any time. These rights come from the FADP (Art. 25, 28 and 32) and, where it applies to you, the GDPR (Art. 15 to 21 and 7(3)). Email [email protected] and we will action it within 30 days.

The email address is the only field the waitlist needs; everything else is optional. We make no automated decisions about you and do no profiling.

If you think we handle your data wrongly, you can report it to the Swiss Federal Data Protection and Information Commissioner (FDPIC). If the GDPR applies to you, you can also lodge a complaint with the data-protection authority of the EU or EEA country where you live or work (list of authorities).

Changes

We will update this notice as the product and the waitlist go live. The date at the top reflects the current version. Questions: [email protected].