Legal
Privacy. What this site does with your data.
This website sets no cookies, runs no analytics, and makes no requests to any third party. You can verify every word of that in your browser’s developer tools before you take it on trust.
AlexSta sells cyber defense. It would be a poor advertisement to run a site that quietly leaked its visitors to an advertising network, so this one does not. This page describes, in plain terms, the small amount of data that does get processed when you read these pages or write to the firm, and what your rights are over it.
There is no cookie banner on this site. That is not an oversight. A banner exists to collect consent for non-essential cookies, and there are none here to consent to.
What the site itself collects
Nothing, and it is checkable.
Most privacy notices ask you to trust a description of the site. This one can be tested. Open developer tools, load any page, and read the network and storage tabs.
What is unavoidable
Server logs.
A web server cannot answer a request without knowing where to send the answer. That is the one piece of data this site cannot avoid processing, and it is better explained than glossed over.
Note the boundary this draws. Nothing a visitor does on this site is sent anywhere by their browser. What leaves Switzerland is the server log entry created by the act of requesting a page, which no website can avoid producing.
When you get in touch
Email and telephone.
If you write or call, you are handing the firm information about yourself on purpose. Here is what happens to it.
Engagement data
Client data is governed by the contract, not by this page.
This notice covers the website. It does not cover the evidence handled during an engagement.
During a compromise assessment, an incident response or a forensic investigation the firm necessarily processes data belonging to the client, and some of it is personal data about their staff. That processing is governed by the engagement contract and its data processing terms, which set out scope, location, retention and deletion before any collection begins. Those terms are agreed in writing first, and they are not replaced or modified by anything on this page.
Residency and classification constraints are treated as fixed inputs from the first call. If data cannot leave a jurisdiction or a network, that shapes the method rather than becoming a problem to negotiate later.
Your rights
What you can ask the firm to do.
If you are in the EU or the EEA the GDPR applies. If you are in Switzerland the revised Federal Act on Data Protection applies. The practical rights are close to identical.
Write to the address below to exercise any of these. No form is required and no fee is charged.
Who is responsible
Controller and contact.
Last updated 11 September 2026.