Privacy Policy

This policy explains which data we process, why we process it, and how you can exercise your rights.

Last updated: 2026-08-14

Controller and Company Details

SIGNRACER GmbH
Gartenweg 24
CH-6343 Buonas
Switzerland

Demo Center
Calendariaweg 4
CH-6405 Immensee
Switzerland

Phone: +41 41 792 01 57
Email: info@signracer.ch
Data protection contact: info@signracer.ch
EU representative (Article 27 GDPR): details available on request where legally required.

Scope of this Privacy Policy

This policy describes how SIGNRACER GmbH processes personal data through this website for inquiry handling, security operations, limited consent-based analytics, and related communications. This website does not provide user accounts, a customer portal, or a self-service privacy dashboard.

Categories of Data

Depending on your interaction, we may process limited categories of personal data: technical access and security data (for example IP address, user agent, requested URLs, referrer, and timestamps), inquiry and correspondence data you send to us (for example name, company, email, phone, subject or topic, and message), consent preference data stored through the privacy module, anti-abuse verification data for the contact form (reCAPTCHA token and risk-check outcome), and analytics event data only when analytics consent is granted. For non-English inquiries, the form handler sends only the subject or topic and message to Google for automatic translation into English; the original text is retained and contact details are not included in that translation request. This website does not maintain a user account database or customer profile system.

Purposes and Legal Bases

We process personal data to operate and secure the website, prevent spam and abuse on forms (including reCAPTCHA verification), translate non-English inquiry text into English for internal review, respond to inquiries, handle pre-contract communication, and comply with legal obligations. Optional analytics processing is based on consent. Security, anti-abuse, inquiry handling, and core operational controls are based on legitimate interest. Automated translation assists staff review only and is not used for decisions with legal or similarly significant effects. reCAPTCHA risk scoring is used for security filtering only and not for such decisions.

Recipients and Service Providers

Data may be processed by approved service providers where required for website operation or communications. Key provider roles include Google Ireland Limited and Google LLC (Google Tag, reCAPTCHA, Gmail, and automatic translation of non-English inquiry subject or topic and message) and Hostpoint AG as hosting and server infrastructure provider. Inquiry-related data may also pass through email or communications providers when we receive or answer your request. We apply contractual and organizational controls appropriate to the processing risk profile.

International Transfers

When personal data is transferred outside Switzerland or the EEA (including to the United States), SIGNRACER GmbH relies on legally recognized safeguards under applicable law, such as adequacy decisions (including, where applicable, Swiss-US or EU-US Data Privacy Framework participation) or Standard Contractual Clauses with supplementary measures.

Retention

We apply retention by data type: (1) server and security logs available to us or our hosting provider are generally retained for up to 30 days unless needed for incident analysis, abuse prevention, or legal obligations; (2) contact and pre-sales inquiries, together with related correspondence, are generally retained for up to 24 months after the last relevant interaction unless contractual or legal obligations require longer; (3) consent preferences are stored in your browser local storage until changed, cleared, or refreshed by a policy-version change and are not kept in a server-side user profile; (4) analytics and reCAPTCHA provider-side data are retained under the applicable provider settings and policies.

Your Rights

You can request access, correction, deletion, restriction, portability, and objection in line with applicable law. You may also withdraw consent for consent-based processing at any time without affecting prior lawful processing.

How to Exercise Rights

Privacy requests are handled manually by SIGNRACER. To submit a request, contact info@signracer.ch or use the local data-rights page at /data-request/. This website does not provide a self-service export or deletion portal. Please include sufficient context to identify your records. We may request proportionate identity verification before disclosing, correcting, or deleting personal data. We aim to respond within one month for valid requests, subject to lawful extension where applicable.

Security Measures

SIGNRACER applies technical and organizational safeguards suitable for the context of industrial B2B website operations, including transport security, controlled access, and operational protection measures.

Google Tag and Analytics Processing

This website uses Google Tag and Google Analytics for analytics only when analytics consent is granted. In strict consent mode, analytics is denied by default and enabled only after consent. Tag configuration applies IP anonymization. When enabled, analytics providers may process pages viewed, interaction events, browser/device metadata, and approximate geolocation derived from IP. Typical analytics identifiers may include _ga and _ga_* (up to 2 years). Depending on provider infrastructure, data may be processed outside Switzerland or the EEA, including in the United States, with safeguards under applicable law.

Policy Updates

We may revise this policy when legal requirements or website processing operations change. The page always shows the latest update date.