Legal

Privacy. What this site does with your data.

This website sets no cookies, runs no analytics, and makes no requests to any third party. You can verify every word of that in your browser’s developer tools before you take it on trust.

AlexSta sells cyber defense. It would be a poor advertisement to run a site that quietly leaked its visitors to an advertising network, so this one does not. This page describes, in plain terms, the small amount of data that does get processed when you read these pages or write to the firm, and what your rights are over it.

There is no cookie banner on this site. That is not an oversight. A banner exists to collect consent for non-essential cookies, and there are none here to consent to.

0 Cookies set when you visit
0 Third-party requests from any page
0 Trackers, pixels or analytics scripts
Switzerland Where the controller is established

What the site itself collects

Nothing, and it is checkable.

Most privacy notices ask you to trust a description of the site. This one can be tested. Open developer tools, load any page, and read the network and storage tabs.

Cookies None are set when you browse this site. No consent is sought because none is required. A cookie is set only if you log in to the site’s administration, which applies to the firm’s own staff and not to visitors.
Analytics There is no Google Analytics, no Meta pixel, no LinkedIn Insight tag and no product of that kind on any page. Nothing measures what you read here or how long you stay.
Third-party requests Every asset on every page, including the fonts, is served from this domain. Your browser contacts no one but this domain. Web fonts in particular are often loaded from a font provider’s servers, which discloses the reader’s IP address to that provider on every page view. The fonts here are self-hosted so that does not happen.
Forms There are none. The contact page gives you an email address and a telephone number. Nothing on this site collects what you type.
Embedded content No video embeds, no social widgets, no maps, no chat box. These are the usual routes by which a site that believes it tracks nobody is in fact tracking everybody.

What is unavoidable

Server logs.

A web server cannot answer a request without knowing where to send the answer. That is the one piece of data this site cannot avoid processing, and it is better explained than glossed over.

What is recorded The hosting provider records standard web server log entries: the IP address making the request, the date and time, the page or file requested, the status returned, and the browser user agent string. This is the ordinary operation of a web server and not something the firm switched on.
Why To operate the site, to diagnose faults, and to detect and defend against attacks on it. Under the GDPR this rests on legitimate interests, namely keeping the service running and secure.
What is not done with it Log data is not used to build a profile of you, is not combined with any other source, is not sold, and is not shared for advertising. It is not analyzed to study reader behavior.
Retention Logs are held for a limited period by the hosting provider and are then overwritten in the ordinary course. The firm keeps no archive of them.
Who hosts the site This website is hosted by HostGator, on servers in the United States. They act as the firm’s processor for the log data described above, and for nothing else. No other provider receives anything from this site.
Transfer outside Switzerland Because those servers are in the United States, the limited personal data in the logs, principally IP addresses, is processed outside Switzerland and the EEA. Under the GDPR that is a transfer to a third country, and it is governed by the data processing terms of the hosting agreement. It is stated here plainly rather than left for you to infer from a traceroute.

Note the boundary this draws. Nothing a visitor does on this site is sent anywhere by their browser. What leaves Switzerland is the server log entry created by the act of requesting a page, which no website can avoid producing.

When you get in touch

Email and telephone.

If you write or call, you are handing the firm information about yourself on purpose. Here is what happens to it.

What the firm holds Whatever you choose to send: your name, your email address, your telephone number, your employer, and the content of what you write. Nothing is asked for beyond what you volunteer.
Why To answer you, to scope an engagement, and to keep a record of what was discussed and agreed. That is either the performance of a contract or steps taken at your request before entering one.
Confidentiality People often contact the firm in the middle of an incident, which means the first email can be sensitive. Enquiries are treated as confidential, are not referenced to anyone outside the firm, and are never used as a marketing example. If you would prefer an encrypted channel before saying anything substantive, ask and one is arranged.
Retention Correspondence is kept while it is useful for the engagement or the relationship, and for as long afterwards as Swiss law requires business records to be retained. Ask, and you are told what is still held.

Engagement data

Client data is governed by the contract, not by this page.

This notice covers the website. It does not cover the evidence handled during an engagement.

During a compromise assessment, an incident response or a forensic investigation the firm necessarily processes data belonging to the client, and some of it is personal data about their staff. That processing is governed by the engagement contract and its data processing terms, which set out scope, location, retention and deletion before any collection begins. Those terms are agreed in writing first, and they are not replaced or modified by anything on this page.

Residency and classification constraints are treated as fixed inputs from the first call. If data cannot leave a jurisdiction or a network, that shapes the method rather than becoming a problem to negotiate later.

Your rights

What you can ask the firm to do.

If you are in the EU or the EEA the GDPR applies. If you are in Switzerland the revised Federal Act on Data Protection applies. The practical rights are close to identical.

Access Ask what personal data the firm holds about you and receive a copy of it.
Rectification Have anything inaccurate corrected.
Erasure Have it deleted, except where the firm is required to keep it.
Restriction and objection Object to processing based on legitimate interests, or ask the firm to restrict it while a question is resolved.
Portability Receive data you gave the firm in a structured, machine-readable form.
Complaint Raise the matter with a supervisory authority. In Switzerland that is the Federal Data Protection and Information Commissioner. In the EU it is the authority for your country.

Write to the address below to exercise any of these. No form is required and no fee is charged.

Who is responsible

Controller and contact.

Controller AlexSta CyberSecurity AG
Address Sinserstrasse 67, 6330 Cham, Canton of Zug, Switzerland
Company number CHE-349.360.783, registered in the Canton of Zug
Changes If this notice changes in a way that matters, the date below changes with it. There is no mailing list to notify, because the firm does not run one.

Last updated 11 September 2026.

NEXT / CAPABILITY

Solutions

The range of capabilities, and how engagements are built from it.

NEXT / SCOPING

Engage

Describe the situation. The call is with the consultant who would run the assessment, not a salesperson.