What this website does with personal data, in plain language. Written against the revised Swiss Federal Act on Data Protection (revDSG, in force since 1 September 2023) and — where it reaches us, because visitors are in the EU — the GDPR.
Last updated: 2026-08-25
Responsible for the processing of personal data on this website (the “controller”) is:
For any question about your data, write to that address. You do not need a particular form of words.
This website sets no cookies, runs no analytics, and contains no tracking pixels, advertising tags or social-media plugins. We do not profile visitors, and we do not sell or rent personal data to anyone, ever.
In fact your browser contacts no third party at all to display this site — even the typefaces are served from our own server. What remains is short, and each item has its own section below: the server log our host keeps, the contact form if you use it, and two small settings your browser stores locally.
Every visit to a web page is a request to a server, and the server records it. The log holds your IP address, the date and time, the page requested, the HTTP status, the amount of data transferred, and the browser and operating system your device reports (the “user agent”).
Why: to operate the site, keep it secure and diagnose faults. We have an overriding legitimate interest in this (revDSG art. 31 para. 1; GDPR art. 6(1)(f)). Log data is not merged with anything else and is not used to identify individuals.
How long: only as long as it is useful for those purposes — a log entry has no value to us once it is old, and the files rotate. We do not archive them.
If you use the form on the contact page, we receive what you typed: your name, your email address, the interests you selected, and your message. Along with it, the submission stores the IP address and user agent it arrived from.
Why the IP and user agent: solely to tell a real enquiry from automated spam. They are never used for anything else and are never sent to an external spam service — the check runs on our own systems.
Why the rest: to answer you, and to take the enquiry forward if it becomes a project. That is a pre-contractual step you asked for (revDSG art. 31 para. 2 lit. a; GDPR art. 6(1)(b)).
How long: as long as the enquiry is live, and afterwards only as long as we may need it to show what was discussed or agreed. Write to us and we will delete it sooner.
If you email us, we hold your message and your address for as long as it takes to deal with the matter and to keep a record of it. Ordinary email is not encrypted end-to-end and can in principle be read in transit — please do not send anything highly sensitive that way.
This site stores exactly two values in your browser's local storage: mk-lang (whether you chose German or English) and mk-mode (light or dark). They exist only so the site looks the way you left it.
These are not cookies: they are never sent to a server, they stay on your device, and they contain no identifier. Nothing about you can be recognised from them. Clearing your browser's site data removes them. Because they are strictly necessary for a function you asked for, no consent banner is required — which is why this site has none.
The typefaces are served from our own server, together with the rest of the page. Your browser contacts no font CDN and no third party to render this site.
We pass personal data on only where it is necessary to run the site and answer you. Everyone below acts as our processor, bound by contract to use the data only on our instructions.
Beyond that we disclose personal data only if we are legally obliged to, or to enforce our rights.
We are a Swiss company, but the servers are in Germany and Finland. That is a disclosure abroad under revDSG art. 16. Both are EU/EEA states that the Swiss Federal Council recognises as providing adequate data protection, so no additional safeguard is needed for them.
Email is the one path that may reach further: our provider operates in several regions, and where processing happens outside the EU/EEA it is covered by the contractual guarantees agreed with them. If you would rather not have your message travel at all, write to us on paper at the address in the imprint.
This site is served over HTTPS, so the connection between your browser and our server is encrypted. Access to submitted enquiries is restricted to the two of us. Backups are encrypted and kept for a limited number of runs, which means a deleted record may persist in a backup for a while after deletion — a normal consequence of having backups at all, and worth knowing.
No system is perfectly secure, and we do not claim otherwise.
Under the revDSG you may, at any time and free of charge:
If the GDPR applies to you, you additionally have the rights in its art. 15–22, including restriction of processing and — where processing rests on legitimate interest — objection on grounds relating to your situation.
Write to hello@murikual.com. We may need to check who you are before answering, so that we do not hand your data to somebody else.
You may also complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC/EDÖB), and in the EU your national data protection authority.
No. You can read every page of this site without giving us anything. The contact form is voluntary — but if you leave the name, email or message empty we cannot reply, so those fields are required to send it.
There is no automated decision-making and no profiling on this site.
We may update this notice when the website changes. The version published here is the one that applies; the date at the top tells you when it last changed.
Murikual is a small Swiss web & software company. We build the websites, tools, web apps and software that make your business simpler to run.
What we build
Studio
Get in touch