Privacy Policy

Last updated: April 2026

1. Controller

Thurn is operated from Switzerland. Operator identity (legal name, registered address, commercial register entry) is published on the imprint page. For data protection inquiries: @EMAIL@.

2. What data we collect

3. Why we process your data — legal bases

4. Data processors (sub-processors)

We share data only with the processors below, each bound by a data-processing agreement:

5. Data retention

6. Your rights

You have the right to access, correct, and delete your personal data. The fastest paths are self-service: request a copy of your data or request deletion. Both pages take your email and send a confirmation link. You can also email @EMAIL@ from the address on file. You can unsubscribe from non-transactional emails at any time — every such email carries a one-click unsubscribe link.

You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or with your local EU supervisory authority if you consider that our processing of your data infringes applicable data-protection law.

7. Cookies & analytics

We use only strictly necessary session state (language preference, theme preference) stored client-side. We do not use advertising cookies, cross-site tracking, or consent-banner cookies.

When the operator has configured an analytics endpoint, aggregate traffic analytics are provided by Plausible Analytics — cookieless, no personal identifiers, no cross-site profiling. If analytics are not configured, no analytics requests are sent at all.

8. International data transfers

Most processing occurs within the EEA or Switzerland. Processors based outside the EEA (Stripe Inc. — US; smtp2go — Australia; Cloudflare Inc. — US) rely on Standard Contractual Clauses and, where applicable, supplementary measures to meet Swiss and EU adequacy requirements.

9. Changes

We may update this policy. Material changes will be noted on this page with a new "last updated" date.