Ceresio Digital AI Privacy Policy
This policy explains which personal data we collect through ceresiodigital.com and in the course of our services, why we collect them and what your rights are.
Last updated: 30 September 2026
Data Controller
Ceresio Digital AI
Strada da Viarmes 4, 6922 Morcote, Switzerland
Controller’s email address: info@ceresiodigital.com
Types of data collected
The personal data collected through this Website and in the course of our services include:
- Contact data: first name, surname, company, email address, phone number;
- Content of communications: messages sent via the contact form, email, AI chatbot or WhatsApp;
- Booking data: date and time of the chosen appointment;
- Contract and billing data: address, billing details, project information;
- Usage Data: IP address, browser and device type, pages visited, date and time of the visit.
Personal data are provided freely by the User or, in the case of Usage Data, collected automatically while the Website is being used.
Unless otherwise specified, the data requested are necessary to provide the service: if the User refuses to provide them, it may be impossible to respond to the request or deliver the service. Data marked as optional may be omitted without any consequence. Users who are unsure which data are mandatory may contact the Controller.
The User is responsible for any third-party personal data obtained, published or shared through the Website.
Purposes of processing
The User’s data are collected for the following purposes:
- Responding to enquiries sent via the contact form, email, WhatsApp or AI chatbot, and preparing offers;
- Scheduling and managing appointments via the online calendar (Google Calendar);
- Providing contracted services, managing the client relationship and invoicing;
- Sending the newsletter and informational and commercial communications about our services, news and events;
- Ensuring the operation and security of the Website;
- Complying with legal obligations and defending the Controller’s rights in court.
Newsletter
When subscribing to the newsletter, the User’s email address and name are added to a contact list to which we periodically send communications about digital marketing, AI, services, offers and events of Ceresio Digital AI.
- Legal basis: the User’s consent. We may send existing clients communications about services similar to those already purchased, within the limits permitted by law, always offering the possibility to object.
- Unsubscribing: the User can unsubscribe at any time, free of charge, via the link in every email or by writing to info@ceresiodigital.com.
- Provider: emails are sent via an email marketing service that processes the data on behalf of the Controller.
- Retention: until the User unsubscribes or withdraws consent.
Methods and place of processing
Methods of processing
The Controller takes appropriate security measures to prevent unauthorised access, disclosure, modification or destruction of personal data.
Processing is carried out using IT and telematic tools, with organisational methods strictly related to the purposes indicated. In addition to the Controller, external parties processing data on its behalf (Processors) may have access to the data, in particular:
- Lovable: Website hosting and development, AI chatbot;
- Google (Google Calendar): appointment management;
- WhatsApp (Meta Platforms): chat communications;
- Email marketing service: sending the newsletter;
- Fiduciary and legal or tax advisers, to the extent necessary.
An up-to-date list of Processors may be requested from the Controller at any time.
Place
Data are processed in Switzerland by the Controller and in any other place where the parties involved in the processing are located. Some providers may process data in the EU/EEA or in the United States. In such cases, data are transferred to countries recognised as adequate by the Swiss Federal Council or the European Commission, or on the basis of appropriate safeguards such as standard contractual clauses or the provider’s certification under the Swiss-U.S./EU-U.S. Data Privacy Framework.
Retention period
Personal data are kept for as long as required by the purpose for which they were collected:
- Enquiries not followed by a contract and chatbot conversations: up to 12 months;
- Data collected to perform a contract: until the contract has been completed; accounting records for 10 years, as required by the Swiss Code of Obligations (CO, art. 958f);
- Data processed on the basis of legitimate interest: until that interest has been fulfilled;
- Data processed on the basis of consent (e.g. newsletter): until consent is withdrawn.
The Controller may be required to keep data for longer to comply with a legal obligation or by order of an authority. Once the retention period ends, the data are deleted: from that point on, the rights of access, erasure, rectification and data portability can no longer be exercised.
Cookies
The Website uses technical cookies, necessary for its operation, which do not require the User’s consent. Any statistics or marketing cookies are activated only with consent given through the cookie banner; the choice can be changed at any time via the “Cookie settings” link in the footer. For details, please see the Cookie Policy.
Legal basis and User rights
The Controller processes data in compliance with the Swiss Federal Act on Data Protection (FADP) and, for Users located in the European Union, Regulation (EU) 2016/679 (GDPR).
Legal basis for processing
The Controller processes the User’s personal data where one of the following applies:
- the User has given consent for one or more specific purposes (e.g. newsletter);
- processing is necessary for the performance of a contract with the User or for pre-contractual measures;
- processing is necessary for compliance with a legal obligation to which the Controller is subject;
- processing is necessary for the purposes of the legitimate interests of the Controller or of third parties.
The User may ask the Controller at any time to clarify the legal basis of each processing activity.
User rights
Within the limits provided by law, the User has the right to:
- withdraw consent at any time, without affecting processing already carried out;
- object to processing based on a legal basis other than consent;
- access their data and receive a copy;
- verify and request rectification of inaccurate data;
- obtain restriction of processing;
- obtain erasure of their data;
- receive their data or have them transferred to another controller, in a structured, machine-readable format;
- lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland or, for Users in the EU, with the competent supervisory authority (in Italy: the Italian Data Protection Authority (Garante)).
The User also has the right to obtain information on the legal basis for transfers of data abroad and on the security measures adopted.
Right to object to direct marketing
Where data are processed for direct marketing purposes, such as sending the newsletter, the User may object at any time, free of charge and without giving reasons. In that case, the data will no longer be processed for these purposes.
How to exercise your rights
Requests can be sent to info@ceresiodigital.com. Requests are free of charge and the Controller will respond as soon as possible, and in any event within 30 days. Any rectification, erasure or restriction will be communicated to the recipients to whom the data have been disclosed, unless this proves impossible or involves disproportionate effort.
Further information on processing
AI chatbot
The replies of the chatbot on the Website are generated automatically by an artificial intelligence system. We ask Users not to enter sensitive data (e.g. about health or finances). The chatbot does not make decisions with legal effects: it provides information and suggests appointments.
Legal defence
Personal data may be used by the Controller in court, or in the preparatory stages, to defend itself against misuse of the Website or services. The Controller may be required to disclose data by order of public authorities.
System logs and maintenance
For operation and maintenance purposes, the Website and the third-party services it uses may collect system logs, which may contain personal data such as the IP address.
Information not contained in this policy
Further information on data processing can be requested at any time from info@ceresiodigital.com.
Changes to this privacy policy
The Controller may change this policy at any time by giving notice on this page and, where possible, via the User’s contact details in its possession. We recommend checking this page regularly, referring to the date of last update shown at the top. If changes affect processing based on consent, the Controller will collect consent again where necessary.
Definitions and legal references
- Personal data (or Data): any information that, directly or indirectly, including in connection with other information, identifies or makes identifiable a natural person.
- Usage Data: information collected automatically through the Website, such as IP address, time of the request, browser and operating system characteristics, pages viewed and time spent.
- User: the person who uses the Website or the Controller’s services and who, unless otherwise stated, is the Data Subject.
- Data Subject: the natural person to whom the personal data refer.
- Processor: the natural or legal person who processes personal data on behalf of the Controller.
- Controller: Ceresio Digital AI, which determines the purposes and means of processing personal data.
- Website: ceresiodigital.com, through which Users’ data are collected and processed.
- European Union (EU): unless otherwise stated, any reference to the EU includes all EU Member States and the European Economic Area.
Legal references: Swiss Federal Act on Data Protection (FADP, SR 235.1) and the related Data Protection Ordinance (DPO); Regulation (EU) 2016/679 (GDPR). Unless otherwise stated, this policy applies exclusively to the Website and services of Ceresio Digital AI.