1. Data Controller

Farid Saïd
Email: hello@faridsaid.com
Website: faridsaid.com

2. Applicable Legal Framework

This privacy policy is drafted in accordance with the Swiss Federal Act on Data Protection (nFADP), effective since September 1, 2023, as well as the General Data Protection Regulation (GDPR – EU 2016/679) for visitors located in the European Economic Area.

3. Data Collected

3.1 Contact Form Data

When you use the contact form, the following data is collected:

  • Name
  • Email address
  • Message content

Legal basis: Consent (art. 6 para. 6 nFADP; art. 6(1)(a) GDPR) and legitimate interest in responding to your inquiries (art. 6(1)(f) GDPR).

Purpose: Processing your inquiry and establishing contact.

Retention period: Data is retained for the duration necessary to process your request, then deleted within 12 months, unless a legal retention obligation applies.

3.2 Technical Connection Data

When browsing the site, the hosting server may automatically collect technical data:

  • IP address (anonymized in logs)
  • Date and time of the request
  • Page visited
  • Browser and operating system

Legal basis: Legitimate interest in the proper functioning and security of the site (art. 6(1)(f) GDPR).

Retention period: Server logs are automatically deleted after 30 days.

3.3 Reading Statistics

Blog article pages use an internal statistics service to display reader counts. This service collects:

  • An anonymous digital fingerprint (SHA-256 hash of IP address and browser, with daily salt rotation)
  • The identifier of the article viewed
  • The date of first visit and last activity

No personally identifiable data is stored. The IP address is never stored in plain text. The hash salt is rotated daily, making fingerprints non-reversible after rotation. No cookies are set by this service.

Legal basis: Legitimate interest in measuring article readership (art. 6(1)(f) GDPR).

Retention period: Fingerprints are automatically deleted after 180 days.

3.4 Audience measurement and bot protection (Cloudflare)

The site is served through the Cloudflare network, which handles its delivery and security. Two Cloudflare features are enabled:

  • Cloudflare Web Analytics: aggregated traffic statistics (page views, referrer, browser type, approximate country). This service sets no cookie and builds no visitor profile.
  • Bot detection (Bot Fight Mode, JavaScript Detections): a script analyses technical characteristics of the browser to tell human visitors from malicious bots. For this purpose Cloudflare may set a security cookie (__cf_bm, 30 minutes, and cf_clearance if a check is required).

Legal basis: Legitimate interest in measuring the site's audience and protecting it against abuse (Art. 6(1)(f) GDPR).

Retention: According to Cloudflare's retention periods; security cookies expire after 30 minutes at most (__cf_bm) or a few hours (cf_clearance).

3.5 Browser local storage

The site stores in the browser's session storage (sessionStorage) your choice to enter with or without sound (fs-audio-enabled, fs-audio-gesture). This data stays on your device, is never sent to any server and is cleared when the tab is closed.

4. Subprocessors and Data Transfers

4.1 Contact Form

Data submitted through the contact form is transmitted via FormSubmit (formsubmit.co). This service acts as a technical subprocessor for message delivery. Data is not permanently stored by this service.

4.2 Cloudflare

The site is delivered and protected by Cloudflare, Inc. (United States), which in this capacity processes technical connection data, traffic statistics (Web Analytics) and the bot detection signals described in section 3.4. Cloudflare participates in the Data Privacy Framework (EU, Switzerland and United States) and commits to standard contractual clauses.

4.3 International Data Transfers

Some subprocessors may process data outside Switzerland or the EEA. In such cases, appropriate safeguards are in place (EU standard contractual clauses, Swiss Federal Council adequacy decisions, or explicit consent).

5. Your Rights

Under the nFADP and GDPR, you have the following rights:

  • Right of access: obtain confirmation of data processing and receive a copy.
  • Right to rectification: have inaccurate or incomplete data corrected.
  • Right to erasure: request deletion of your data, subject to legal retention obligations.
  • Right to restriction: restrict processing in certain circumstances.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interest.
  • Right to withdraw consent: withdraw your consent at any time, without affecting the lawfulness of prior processing.

To exercise these rights, contact us at: hello@faridsaid.com. We will respond within 30 days.

6. Data Security

Appropriate technical and organizational measures are implemented to protect your data against unauthorized access, modification, disclosure or destruction. The site uses HTTPS to encrypt communications between your browser and the server.

7. Cookies

The site itself sets no cookie. Only Cloudflare may set strictly necessary security cookies to protect the site against bots (__cf_bm, cf_clearance, see section 3.4). No advertising tracking cookie is used, and audience measurement (Cloudflare Web Analytics) works without cookies.

For more information, see the cookies section in the legal notice.

8. Supervisory Authority

If you believe that the processing of your data constitutes a violation of applicable law, you may file a complaint with:

  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch
  • EU: The competent supervisory authority in your country of residence.

9. Changes

This privacy policy may be modified at any time. The current version is the one published on this page with its last update date. In the event of a substantial change, a notice will be displayed on the site.