BE BRAVE operates its offers on its own servers in Switzerland. Customer data, documents, chats, logs and backups are stored and processed in Switzerland.
Customer content is never used for training, fine-tuning or model improvement by BE BRAVE or model providers.
If a customer activates an external connector, selected data may be transmitted to that provider; that provider’s terms and processing locations then apply.
This English version is provided for convenience. The German version is legally binding.
1. What this privacy policy covers
This privacy policy explains how BE BRAVE AG processes personal data when you visit our website, contact us, subscribe to a newsletter, request a consultation, demo or workshop, express interest in our solutions or use the investor area.
Our website is operated on BE BRAVE AG’s own servers in Switzerland and delivered through Cloudflare’s content delivery network. Website enquiries are generally stored on our systems in Switzerland; on their way there, however, they pass through Cloudflare and may also be processed outside Switzerland, in particular in the USA (sections 5 and 15). The messages in our email mailboxes at Microsoft 365, including [email protected] and [email protected], and the entries in our calendar at Microsoft 365 are an exception (sections 7 and 14); they are stored in the EU or the EEA (section 15). A further exception is formed by the analytics and marketing services of Google, Meta and LinkedIn, which you may activate voluntarily: without your consent, these services remain fully deactivated. If you consent, the providers concerned may also process data outside Switzerland, in particular in the USA.
The Swiss Federal Act on Data Protection (DSG/FADP) applies first and foremost. Where it applies to a specific processing activity, we additionally take into account the General Data Protection Regulation of the European Union (GDPR/DSGVO) and, for persons in Brazil, the Lei Geral de Proteção de Dados Pessoais (LGPD).
2. Controller
The following company is solely responsible for all language versions of this website:
BE BRAVE AG
Blegi 3
6343 Rotkreuz
Switzerland
Email for data protection enquiries: [email protected]
Telephone: +41 41 244 64 64
BE BRAVE Brazil Ltda. is not the controller of this website.
3. What data we process
Depending on how you use the website, we process in particular:
technical usage data such as IP address, date and time, page accessed, referrer, browser, operating system, device type, language, volume of data transferred and status of the request;
details you enter into forms, in particular name, business contact details, company, role, area of interest, subject and message;
details of consultation, demo, workshop, product or investor enquiries and of appointment bookings (name, email address, telephone number, company, topic, remarks and the chosen appointment);
newsletter data such as email address, language, time of sign-up and confirmation, and proof of consent;
preferences and consents, in particular your cookie choice together with the time and version of the notice displayed;
campaign and origin data such as UTM parameters and referrer;
where consent has been given, analytics and marketing data such as page views, interactions, conversion events and pseudonymous browser and device identifiers.
Please do not submit any sensitive personal data requiring special protection via free-text website forms.
The details a form requires are marked there, either with an asterisk (*) or by labelling the other fields as optional. Without these details we cannot process your enquiry, booking or subscription; all other details are voluntary.
4. Purposes and legal bases
We process personal data in order to:
provide the website securely, stably and in a user-friendly manner;
detect and defend against attacks, misuse, fraud and technical faults;
answer enquiries and carry out pre-contractual measures;
manage customer, product, workshop and investor enquiries in our CRM;
initiate, conclude and perform contracts;
send newsletters and company information on request;
with your consent, measure the use of the website, campaigns and conversions and build audiences for advertising;
fulfil legal obligations and establish, exercise or defend legal claims.
Where the GDPR applies, we base the processing, depending on the purpose, on your consent, pre-contractual measures or performance of a contract, legal obligations and our legitimate interests in secure, efficient and economical website and business operations. Under the Swiss DSG/FADP we process personal data in compliance with the statutory processing principles; we obtain consent in particular where it is required due to the nature or intensity of the processing. Under the LGPD, depending on the circumstances, consent, performance of a contract, compliance with legal obligations and legitimate interests come into consideration in particular. We do not base the bot check before a subscription is submitted (Cloudflare Turnstile, section 8) on consent, but on our legitimate interest in preventing automated submissions and misuse and on the performance of pre-contractual measures.
5. Hosting, delivery and security logs
The website and the services connected with it (such as forms, appointment booking and newsletter sign-up) run on BE BRAVE AG’s own servers in Switzerland. Delivery takes place via the content delivery network and tunnel service of Cloudflare (Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, with offices in Europe). Your requests first reach Cloudflare and are passed on from there to our server through an encrypted tunnel that our server itself establishes to Cloudflare. Cloudflare thus processes the entire connection to our website, including the content you submit via our forms (for example contact enquiries, appointment bookings, newsletter sign-ups and subscriptions including the signature). The encryption between your browser and Cloudflare (TLS) ends at Cloudflare: the request is decrypted there in order to be forwarded and is then transmitted to our server in encrypted form through the tunnel. Cloudflare also processes technical connection data (in particular IP address, time, URL accessed, browser and device identifiers) in order to deliver the content, protect against attacks (DDoS, bots) and analyse errors. As a processor, Cloudflare is contractually bound by our instructions. Processing may also take place on servers outside Switzerland, in particular in the USA; the transfer is based on the EU Standard Contractual Clauses and on the EU-US and Swiss-US Data Privacy Framework, under which Cloudflare states it is certified. Further information: https://www.cloudflare.com/privacypolicy/
When the website is accessed, technical server logs are generated on our server. This data is required to deliver content, ensure technical security, analyse errors and prevent misuse.
Security and access logs are generally stored for 90 days. In the event of a specific security incident, a legal obligation or the enforcement of claims, the log data concerned may be retained for longer. Customer data, operational logs and backups of BE BRAVE systems are stored on our own servers in Switzerland; form and connection data, however, pass through Cloudflare on their way there and may also be processed outside Switzerland (see above).
6. Contact, consultation, demo and workshop enquiries
If you submit a form or contact us by email or telephone, we process the details you provide in order to answer your enquiry, arrange an appointment and, where applicable, prepare or perform a contract. If you tick the box for news and invitations in the contact form, we additionally sign your email address up for the newsletter: you receive a confirmation email, and the subscription only becomes active once you confirm it via the link it contains (section 9).
Submitted website enquiries are delivered by email to the responsible team ([email protected] or, for investor enquiries, [email protected]) and stored for processing; we use our CRM system Odoo for follow-up. In addition to the visible form fields, the language, originating page, type of enquiry, campaign parameters, referrer, time and consent status may be stored, as well as the IP address and the browser identifier (user agent); we delete these two items after 90 days. The content of form fields that were not submitted is not transmitted to BE BRAVE and is not stored for sales purposes.
We delete enquiries stored on our server 24 months after receipt. We keep copies in our email mailboxes and in our CRM system for as long as they are required to process the enquiry, for a resulting business relationship or to safeguard our rights; we then delete them. If a contract is concluded or statutory documentation or retention obligations exist, the corresponding longer periods apply. Business records and accounting documents are generally retained for ten years.
7. Appointment booking
You can book consultation appointments online via the website. For this we use BE BRAVE’s own booking tool, which runs on our own servers in Switzerland. When you make a booking, we process your name, email address, telephone number, company, the topic of the consultation, any remarks and the chosen appointment. We transfer the name, company and topic of your appointment, together with its time and language, to our calendar at Microsoft 365 (Outlook), whose content is stored in the EU or the EEA (sections 14 and 15).
You receive a confirmation email with a calendar entry and a personal management link through which you can reschedule or cancel the appointment; in the event of changes you receive a corresponding notification. We use the booking data to conduct and follow up the appointment and store it for up to 12 months after the appointment, unless a business relationship or legal obligations require longer retention.
8. Investor enquiries
Enquiries from the investor area are delivered by email to [email protected] and stored for processing; we use our CRM system Odoo for follow-up. We process the details in order to answer the enquiry, assess the interest, provide approved documents, communicate about possible investments and fulfil obligations under company, financial market, tax and anti-money-laundering law, where applicable.
Contacting us via the investor area does not in itself constitute a subscription or the conclusion of an investment transaction. Data relating to an actual or prospective investment may be stored for longer in accordance with statutory record-keeping, due diligence and retention obligations.
Subscription for participation certificates
Subscriptions for participation certificates are made via the online subscription form on the investor page of this website. Subscriptions made previously via the former subscription service of BE BRAVE AG (zeichnung.be-brave.ch) or by other means (for example on paper or via another subscription platform) are recorded in the same register together with the details collected at the time. BE BRAVE AG is the controller for the associated processing of personal data (see section 2).
When you subscribe, we process the following details:
first name, surname, company (optional), date of birth, address, telephone number and email address;
optionally the bank and the number of your securities account; if you provide these details, your participation certificates are booked into that account once they have been issued, otherwise we record them in the company’s register of uncertificated securities;
currency and amount of the subscription, together with the number of participation certificates and the issue price calculated from them;
place and time of signing, the signature as an image – drawn by hand or generated from the name you entered in a handwriting style of your choice – stating the type of signature, the style and the name entered, the version of the subscription terms, your consent to the subscription terms and to signing electronically, and the language used;
where you subscribe on paper, the scans of the signed subscription form that Investor Relations files with your subscription (PDF, JPG or PNG, several per subscription possible) and which contain your handwritten signature; these files are held on our own server, can be retrieved only after logging in, are not delivered publicly and are retained for as long as the other subscription details;
as evidence of the conclusion of the contract (audit trail): your full IP address, the country estimated from it by Cloudflare (see section 5), the identifier of your request at Cloudflare, the browser identifier (user agent), the languages set in your browser, the time of receipt, the time at which the subscription terms were delivered, checksums of the contract text displayed, the declarations of consent, the signature image and your details, and the result of the bot check (provider, result, and the time and hostname reported by Cloudflare);
also as evidence, details provided by your browser (time zone and time on your device, interface language, window size and pixel density, amount displayed in the form) and the times of the individual steps (opening the form, completing each step, display of the terms up to their end, consent, adoption of the signature, submission); these details are transmitted only when you submit;
a checksum of the subscription form generated, the result of sending the email to you and the copy to Investor Relations (recipient address, message identifier) and, each time the subscription form or the associated QR bill is downloaded or the same subscription is submitted again, the time, the IP address and the browser identifier – even if the download was not initiated by you;
the payment status together with the date and amount of the payment received, notes made by Investor Relations (for example the reason for a cancellation) and a log of the events relating to your subscription (recording, sending the subscription form to your email address, payment, cancellation, lapse), stating the time and the initiating party for changes of status.
We process these details to carry out the capital increase, to issue and register the participation certificates, to allocate your payment and to fulfil legal obligations, in particular to keep the register of participants and to retain business records. Where the GDPR or the LGPD applies, we base this processing on the performance of a contract and on compliance with legal obligations; we base the processing for evidence of the conclusion of the contract (audit trail, including the full IP address) and the logging of downloads of the subscription form and of changes of status on our legitimate interest in preserving evidence and preventing misuse.
Before a subscription is submitted, we carry out a security check (bot check) using Cloudflare Turnstile (Cloudflare, Inc., USA) in order to protect the online subscription form against automated submissions and misuse. Turnstile is loaded only in the last step of the online subscription form and asks you for a confirmation only if Cloudflare considers this necessary. In doing so, Cloudflare processes your IP address, the TLS fingerprint of your connection, the browser identifier (user agent) and the sitekey of our form together with its associated origin (website address). Cloudflare acts as our processor and also uses this information under its own responsibility to improve Turnstile. Turnstile does not set a cookie; it stores an entry in your browser’s local storage only in Cloudflare’s own area (challenges.cloudflare.com) (see section 10). We store only the result of the check (provider, result, and the time and hostname reported by Cloudflare), never the token generated by Turnstile. We do not ask for your consent for this (legal basis: section 4). If you cannot or do not wish to load the check, you can subscribe on paper (next paragraph). Further information: https://www.cloudflare.com/turnstile-privacy-policy/
On request, Investor Relations will send you a subscription form pre-filled with your details but without a signature, for you to sign by hand. For the template itself, we store neither names nor contact details, only the template number, date of creation, language, currency, number of participation certificates, issue price, amount and version of the subscription terms (retained for ten years). Investor Relations records the signed subscription form in the register; for such subscriptions there is neither a bot check nor any information from your browser.
After you have signed, the subscription form is generated as a PDF and sent to you by email, with a copy to Investor Relations ([email protected]). Emails are sent via the email service provider of this website (cyon AG, Basel, Switzerland); the copy is placed in the Investor Relations email mailbox at Microsoft (Microsoft 365), whose messages are stored in the EU or the EEA (see sections 14 and 15). If the subscription was signed via the online subscription form on this website and the amount has not been recorded as received 30 days after the subscription form was first sent to you by email, the subscription lapses; if the subscription form could not be sent to you, this period is suspended and the subscription lapses at the latest 60 days after signing. For subscriptions that were signed via the former subscription service and transferred into this register, the period of 30 days begins when we switched over to the online subscription form on this website, but no earlier than the signature. We record this in the log and report lapsed subscriptions to Investor Relations, stating the name, number of participation certificates, amount, date of signing and, where applicable, the date of sending.
We retain the subscription details for the duration of the investment and thereafter for the statutory retention periods for business records and register documents, as a rule ten years after the investment ends. Lapsed or cancelled subscriptions are retained for ten years after they lapse or are cancelled, as evidence relating to the capital increase and to defend against claims. We retain the audit trail for as long as the other subscription details; its entries are neither altered nor deleted during the retention period. If, exceptionally, an email is not sent but stored on our server instead, we delete the stored copy after 90 days.
The recipient of the details is BE BRAVE AG. The form data is transmitted via Cloudflare to our own servers in Switzerland (see section 5); for the bot check, email delivery and the Investor Relations email mailbox, we use the service providers named in section 14. To the extent required to carry out the capital increase, the notary who certifies the capital increase, our statutory auditor and the commercial register office also receive the necessary details. If the register of participants is handed over to a registrar or a custodian, they receive the details required to keep the register.
9. Newsletter
If you subscribe to the newsletter – via the sign-up field on the website or by ticking the box in the contact form (section 6) – we use your email address and, where applicable, your language and name to send you information about BE BRAVE, products, events, company developments and relevant specialist topics. Sign-up uses a double opt-in procedure: after you enter your email address, we send you a confirmation email with a link that is valid for 72 hours. The subscription is only activated once you click this link; unconfirmed sign-ups do not receive any mailings. As proof of consent, we log the time of sign-up and confirmation as well as the chosen language. Every newsletter email contains an unsubscribe link.
You can unsubscribe at any time via the unsubscribe link in any message or by email to [email protected]. The lawfulness of mailings sent before withdrawal remains unaffected. We store sign-ups on our own servers in Switzerland. We delete unconfirmed sign-ups after 30 days. After you unsubscribe, we keep proof of sign-up, consent and unsubscription for 24 months in order to meet our obligations of proof and to prevent further mailings; we then delete it. If we engage a service provider to send the newsletter, we will name it in this privacy policy before it receives your details.
10. Cookies and similar technologies
We use cookies, pixels, tags, local storage technologies and comparable methods. Technically necessary technologies enable basic functions such as security, language selection and storing your privacy preferences. They cannot be deactivated via the cookie settings because the website would not work as intended without them.
Analytics and marketing technologies are only loaded once you have actively consented via the cookie banner. The buttons “Accept all” and “Reject all” are equally accessible. You can select individual categories and change or withdraw your decision at any time via “Cookie settings” in the footer. Withdrawal takes effect for the future. Google Analytics 4, Google Ads, the Meta Pixel and the LinkedIn Insight Tag are loaded together via Google Tag Manager, and only if you consent to “Marketing”. Google Analytics 4 is therefore only active together with “Marketing”; consent to “Analytics” alone does not load any of these services. If you consent to “Marketing” but not to “Analytics”, Google Analytics 4 does not set any cookies but may send counting signals without cookies to Google (section 11).
We currently use the following cookies and storage technologies (name – provider – purpose – storage period):
Necessary (always active)
bebrave.consent – BE BRAVE AG – stores your cookie choice together with the time and version of the notice – local storage (localStorage), until you delete it;
bebrave.lang – BE BRAVE AG – remembers the chosen language – local storage, until you delete it;
bebrave.settings.*, bebrave.integrations, bebrave.orbit.* – BE BRAVE AG – technical cache for website settings without personal reference – local storage;
bebrave.nav.* – BE BRAVE AG – cache of the menu structure per language (navigation state) without personal reference – local storage, until you delete it;
__bb_chunk_reload_at, react-router-scroll-positions – BE BRAVE AG – technical entries without personal reference (reloading after a loading error, scroll position when navigating back) – session storage (sessionStorage), until you close the tab;
cf.turnstile.u – Cloudflare, Inc. (Turnstile) – protection of the online subscription form against automated submissions, loaded only in the last step of a subscription – local storage in the challenges.cloudflare.com area, until you delete it.
Analytics (only with your consent to “Analytics” and “Marketing”)
_ga, _ga_* – Google Analytics 4 – distinguishing visitors and sessions – 2 years.
Marketing (only with your consent)
_gcl_au, _gcl_* – Google Ads – conversion measurement and attribution of ad clicks – 3 months;
IDE – Google Ads (doubleclick.net) – advertising measurement and remarketing – 13 months;
_fbp – Meta – reach and conversion measurement – 3 months;
lidc, UserMatchHistory, bcookie, li_sugr – LinkedIn – Insight Tag, campaign measurement and retargeting – lidc 1 day, UserMatchHistory 30 days, bcookie and li_sugr up to 12 months;
further identifiers of the same providers in cookies or local storage, whose names and lifetimes are set by the providers – Google, Meta, LinkedIn – purposes as above – storage period as stated by the provider.
As providers may change cookies and lifetimes, we review this list regularly and update it when changes occur. You can view and change your choice at any time via “Cookie settings” in the footer.
11. Google Tag Manager, Google Analytics 4 and Google Ads
With your consent, we use Google services, in particular Google Tag Manager, Google Analytics 4 and Google Ads conversion tracking and remarketing. For users in Switzerland and the European Economic Area, the provider is generally Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; other Google companies, in particular Google LLC in the USA, may be involved in the processing.
Google Analytics helps us understand how the website is used. Google Ads helps us measure the success of campaigns, attribute conversions and – only with the corresponding consent – display relevant advertising. In particular, IP address, browser and device information, pages visited, referrer, times, interactions, campaign parameters, cookie or device identifiers and defined conversion events may be transmitted to Google.
Without your consent to “Marketing”, no Google tags are loaded and no data is sent to Google. Using Google Consent Mode, we pass your choice on to the loaded tags: if you have consented to “Marketing” but not to “Analytics”, Google Analytics 4 does not set any cookies but may send counting signals without cookies (so-called cookieless pings) to Google. How long Google Analytics retains user-level data depends on the setting chosen in the service. If enhanced conversions are switched on in the Google Ads account or user-provided data collection is switched on in Google Analytics, the Google tags may also transmit details you enter into forms, such as your email address, to Google in hashed form.
Google may process data in Ireland, the USA and other countries. According to its own statements, Google bases international transfers, depending on the situation, on recognised data protection frameworks and standard contractual clauses. Further information: https://policies.google.com/privacy and https://business.safety.google/adsdatatransfers/
12. Meta Pixel
With your consent, we use the Meta Pixel for reach measurement, conversion attribution, campaign optimisation and building audiences for advertising on Facebook and Instagram. For persons in Switzerland and the European Economic Area, Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, is generally responsible; data may also be processed by Meta Platforms, Inc. in the USA and other Meta companies.
The pixel may in particular capture URL, referrer, time, IP address, browser and device information, cookie or device identifiers and defined interactions and conversions. Which interactions and conversions are sent to Meta as events is determined by the settings in Google Tag Manager and in the advertising account. If advanced matching is switched on in the advertising account, the pixel may also transmit email addresses or telephone numbers that you enter into forms to Meta in hashed form.
Under its own terms, Meta may also process the data received for measurement, security, integrity and the provision or improvement of advertising services and transfer information across borders, including to the USA. Further information: https://www.facebook.com/privacy/policy/ and https://www.facebook.com/privacy/policies/cookies/
13. LinkedIn Insight Tag
With your consent, we use the LinkedIn Insight Tag to measure campaigns, statistically evaluate website usage and for website retargeting. For persons in Switzerland and the European Economic Area, LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, is responsible; further processing may be carried out by LinkedIn Corporation in the USA.
The tag may capture URL, referrer, IP address, timestamp and device and browser characteristics. LinkedIn states that it removes direct identifiers within seven days and deletes the remaining pseudonymised data within 180 days. If advanced matching or the automatic capture of form details is switched on in the campaign account, the tag may also transmit details you enter into forms, such as your email address, to LinkedIn. BE BRAVE receives only aggregated reports and audience information, without individual LinkedIn members being identified.
Further information: https://www.linkedin.com/legal/privacy-policy and https://www.linkedin.com/help/lms/answer/a420839
14. Recipients and processors
Within BE BRAVE, only persons who need access to perform their duties are granted it. We operate the website and its services on our own servers in Switzerland (section 5). We may also pass personal data on to carefully selected service providers, for example for the delivery and protection of the website (Cloudflare, Inc., USA – see section 5), email delivery (cyon AG, Basel, Switzerland – SMTP), email mailboxes and calendars, including the mailboxes [email protected] and [email protected] (Microsoft as the provider of Microsoft 365, storage location EU or EEA), the bot check of the online subscription form (Cloudflare, Inc., USA – Cloudflare Turnstile, see section 8), CRM (Odoo, in Switzerland), security, translation, consulting and legally required audits. These providers process data in accordance with contractual requirements or under their own legal responsibility; Cloudflare also uses the information from the bot check under its own responsibility to improve Turnstile (section 8).
We disclose data to authorities, courts or other third parties where we are legally obliged or entitled to do so, where this is necessary to protect rights and security, or where you have consented.
15. Data transfers abroad
Operational website and form data is generally stored on our own servers in Switzerland. However, form data and technical connection data pass through Cloudflare on their way to our server and may also be processed outside Switzerland, in particular in the USA (section 5). Messages in our email mailboxes and entries in our calendar are held at Microsoft 365 (section 14) and are stored in the EU or the EEA; this applies to the mailboxes [email protected] and [email protected], including copies of subscription forms and notifications about subscriptions, and to appointments from the booking tool (section 7). For the bot check of the online subscription form (Cloudflare Turnstile, section 8), Cloudflare may likewise process information from your browser and connection outside Switzerland, in particular in the USA. Where you have activated marketing and analytics services, data may be transferred to Google, Meta and LinkedIn and their affiliated companies in the EU, the USA and other countries. A different level of data protection may apply in such countries, and foreign authorities may demand access under local law.
Where necessary, we base such transfers on an adequacy decision, a recognised data protection framework (in particular the EU-US and Swiss-US Data Privacy Framework), standard contractual clauses or another legally permissible safeguard. Transfers by the tracking services mentioned take place only with your consent. You can obtain a copy of the safeguards on request from [email protected].
16. Data security
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure. These include in particular access restrictions, encryption in transit, logging, backup and recovery procedures and organisational security processes within the framework of our information security management system.
Despite all protective measures, data transmission over the internet may involve security risks. Please therefore send particularly confidential information only via a secure channel agreed with us in advance.
17. Retention and deletion
We store personal data only for as long as is necessary for the respective purpose, for statutory retention obligations, to document consents, for IT security or to assert and defend claims. Thereafter, data is deleted or anonymised. Backups are overwritten in accordance with the defined rotation cycle, unless a legal obligation to preserve them exists.
18. Your rights
Depending on the applicable law, you have in particular the right:
to request information about the processing of your personal data;
to have inaccurate or incomplete data corrected;
to request the release or transfer of certain data in a commonly used electronic format;
to request the deletion or restriction of a processing activity;
to object to processing on overriding personal grounds or to direct marketing;
to withdraw consent at any time with effect for the future;
to have an automated individual decision reviewed, where such a decision is used;
to lodge a complaint with a competent data protection supervisory authority.
These rights may be subject to statutory conditions, exceptions or restrictions. To exercise your rights, please write to [email protected]. We may request reasonable information to verify your identity.
The competent Swiss supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC/EDÖB): https://www.edoeb.admin.ch/
Persons in the European Economic Area may also contact the data protection authority of their place of residence or work. Persons in Brazil may contact the Autoridade Nacional de Proteção de Dados (ANPD): https://www.gov.br/anpd/
19. No solely automated decisions
We do not make decisions about website enquiries that are based solely on automated processing and that have legal or similarly significant effects on you. Should this change, we will inform you in advance in accordance with the legal requirements.
20. Changes to this privacy policy
We may amend this privacy policy if the website, our processing activities or the legal situation change. The version published on this website at the time applies. We will draw attention to material changes in an appropriate manner.
Last updated: 3 October 2026