Privacy policy

Last updated 22 September 2026

This privacy policy explains how Ampersand Labs by Davide Morotti ("we", "us") processes personal data when you visit consent.ampersand.ch, create an account, or use Consent by Ampersand (the "Service"). We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

1. Controller and contact

Ampersand Labs by Davide Morotti, Einzelunternehmen
Flüelastrasse 10
8048 Zürich
Switzerland
Email: legal@ampersand.ch

2. Controller and processor roles

For the data described in sections 3 to 8 we are the controller. When our customers embed the Service on their own websites (consent banner, privacy request form, consent withdrawal, accessibility feedback, form consent API), we process the data of their visitors on their behalf as a processor under our data processing agreement. For that processing the respective website operator is the controller; please refer to their privacy policy and address requests to them.

3. Visiting our website

When you access our website, our server automatically records the IP address, date and time, requested URL, referrer, browser and operating system. We use this information to deliver the website, to keep it secure and to detect abuse. Server logs are deleted after 14 days at the latest, unless an incident requires us to keep them longer for its investigation.

Legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).

4. Cookies

We only use cookies that are strictly necessary to provide the Service: a session cookie that keeps you signed in, a security token that protects forms against cross-site request forgery, and, if you choose "remember me" when signing in, a cookie that keeps you signed in on that device. We do not use analytics, advertising or tracking cookies, and we do not load third-party fonts or scripts on our public pages.

5. Account and use of the Service

When you register, we process your name, email address and password (stored only as a hash), and, if you enable them, your two-factor authentication settings and passkeys. When you use the Service, we process the data you enter: team members and invitations, the websites you register, company details used for generated documents, your records (such as vendor registers, processing activities, breach and DPIA records) and an audit log of changes. Our scanner visits the websites you register to detect cookies, trackers and accessibility issues; it does not collect personal data of those sites' visitors.

Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR). We keep account data for as long as your account exists and delete it within 30 days after you close it, except where we are required to keep it longer (section 12).

6. Free website check and document generators

If you use the free website check, we store the address of the website you check, the results and your IP address, which we use to prevent abuse of the scanner. Anonymous checks are deleted automatically after 30 days. The free document generators process the details you enter only to produce the document in your browser session.

Legal basis: our legitimate interest in providing the free tools and protecting them from abuse (Art. 6(1)(f) GDPR).

7. Payments

Subscriptions and orders are paid through Stripe. Stripe processes your payment details directly; we never see or store full card numbers. We receive and keep the information needed for invoicing: your name, billing address, the payment method type, and your subscription and invoice history.

Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and our legal obligations to keep accounting records (Art. 6(1)(c) GDPR).

8. Legal partners, communication and applications

If you order a review from a law firm listed as a legal partner, we share the order, the documents you attach and your contact details with that law firm, which processes them as an independent controller under its professional secrecy. If you apply to become a legal partner, we process the details of your firm and your contact person to assess the application.

If you contact us by email, we process your message and contact details to answer it. We send you transactional emails that are part of the Service (for example sign-in, invitation, scan alert, deadline reminder and report emails); you can configure optional notifications in your settings.

Legal basis: performance of the contract or pre-contractual steps (Art. 6(1)(b) GDPR) and our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).

9. Recipients and sub-processors

We use the following service providers, who process personal data on our behalf and are bound by data processing agreements:

ProviderPurposeLocation
Hetzner Online GmbH Server hosting, database and backups Germany / Finland (EU)
Brevo (Sendinblue SAS) Transactional email delivery France (EU)
Stripe Payments Europe, Ltd. / Stripe, Inc. Payment processing, subscriptions and invoicing Ireland / USA (EU-US / Swiss-US Data Privacy Framework, SCCs)
Anthropic, PBC AI analysis of publicly available vendor terms and privacy policies; no customer or visitor personal data is sent USA (SCCs)

We do not sell personal data and do not share it with third parties for their own marketing. We disclose personal data to authorities only where we are legally required to do so.

10. Transfers abroad

We host the Service in Switzerland or the EU/EEA. Some providers listed above are based in the USA. Transfers to them take place on the basis of the EU-US and Swiss-US Data Privacy Framework where the provider is certified, and otherwise on the basis of the European Commission's standard contractual clauses, as recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC).

11. Security

We protect personal data with appropriate technical and organisational measures, including encryption in transit (TLS), hashed passwords, optional two-factor authentication and passkeys, role-based access within teams, separation of customer data, regular backups and restricted administrative access.

12. Retention

We keep personal data only for as long as needed for the purposes described above. Accounting records, including invoices, are kept for ten years as required by Swiss law (Art. 958f of the Swiss Code of Obligations). Data we process as a processor is deleted according to our data processing agreement and the retention settings of the customer.

13. Your rights

You have the right to request access to your personal data, and to have it corrected, deleted or its processing restricted. You may object to processing based on our legitimate interests, receive your data in a portable format, and withdraw any consent you have given with effect for the future. To exercise your rights, write to legal@ampersand.ch. We may ask you to verify your identity.

You also have the right to lodge a complaint with a supervisory authority: in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch), and in the EU/EEA with the supervisory authority of your place of residence or work.

14. Automated decisions

We do not make decisions based solely on automated processing that produce legal effects for you. Compliance scores, scan results and AI-assisted assessments of vendor terms are aids for you and do not constitute such decisions.

15. Changes

We may update this privacy policy when our Service or the law changes. The current version is always available on this page; we will notify account holders of material changes by email.