Legal

PRIVACY
POLICY

Version 1.0 Effective 1 January 2026

This policy explains what personal data Aylight collects through this website, why we collect it, and the rights you have over it.

It is written to satisfy both the Swiss Federal Act on Data Protection (FADP, SR 235.1, as revised with effect from 1 September 2023) and, where it applies to you, Regulation (EU) 2016/679 (GDPR).

1 — Who is responsible

The controller for the processing described here is:

  • Aylight AG
  • Berninastrasse 46, 8057 Zurich, Switzerland
  • CHE-344.336.487 (Swiss commercial register)
  • Data protection enquiries: hello@aylight.io

We have not appointed a Data Protection Officer. Art. 37(1) GDPR requires one only of public authorities, of controllers whose core activities are large-scale regular and systematic monitoring, and of those whose core activities are large-scale processing of special categories of data. None applies to us. Swiss law imposes no general obligation either; the data protection advisor under Art. 10 FADP is voluntary.

We have not appointed a representative in the European Union. We consider the derogation in Art. 27(2)(a) GDPR to apply, as our processing of EU residents' data is occasional, is not large-scale, does not involve special categories of data, and is unlikely to result in a risk to rights and freedoms. We re-assess this if the volume of our EU hiring changes.

2 — No cookies, no tracking, no analytics

This website sets no cookies and uses no analytics, advertising, fingerprinting or session-recording tools. We do not profile visitors and we make no automated decisions about you.

All fonts, images and scripts are served from our own domain. Loading a page on this site therefore triggers no request to any third party, and no data about your visit reaches anyone but our hosting provider. This is also why you see no cookie banner: there is nothing to consent to.

3 — Server log data

Our hosting provider records the technical data needed to deliver and secure the site: your IP address, the time of the request, the page requested, the referring page, and your browser and operating system identification.

  • Purpose — delivering the site, diagnosing faults, and defending against attack and abuse
  • Legal basis — our legitimate interest in a secure, functioning website (Art. 6(1)(f) GDPR; Art. 31(1) FADP)
  • Retention — Netlify does not publish a fixed retention period for raw request logs. Where we use its server-side traffic dashboard, the data available to us covers a rolling 30-day window
  • Processor — Netlify, Inc., United States — see section 7 on transfers

We do not combine log data with any other data, and we do not use it to identify individual visitors.

4 — Job applications

If you apply for a role, we collect what you submit through the application form: your name, email address, an optional link to your LinkedIn profile or website, an optional cover note, your CV, and the role you applied for.

  • Purpose — assessing your application and communicating with you about it
  • Legal basis — steps taken at your request prior to entering a contract (Art. 6(1)(b) GDPR); the processing is directly connected to the employment relationship you are seeking (Art. 31(2)(a) FADP)
  • Necessity — name, email and CV are required to assess an application. The remaining fields are optional
  • Retention — if we do not hire you, we delete your application six months after the process closes, unless you have asked us to keep it on file

If you ask us to keep your application on file for future roles, we do so on the basis of your consent (Art. 6(1)(a) GDPR; Art. 6(6) FADP) and you may withdraw that consent at any time by emailing us.

Please do not send us special categories of personal data. We do not need — and ask you not to include — information about your health, religion or philosophical beliefs, political opinions, trade union membership, ethnic origin, sex life or sexual orientation, or any criminal record. Under prevailing Swiss and EU recruitment practice a photograph and date of birth are also unnecessary; omit them if you prefer.

5 — Contacting us by email

If you email us, we process your address and the content of your message in order to answer it, on the basis of our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR), or to take pre-contractual steps where your message concerns a possible contract (Art. 6(1)(b) GDPR). We keep correspondence for as long as needed to handle the matter and to meet our record-keeping obligations.

6 — Who else sees your data

We do not sell personal data and we do not disclose it for anyone else's marketing. We share it only with service providers who process it on our instructions under a data processing agreement, and only as far as they need it:

  • Netlify, Inc. (United States) — hosts this website and processes the request logs described above
  • Formspree, Inc. (United States) — receives and forwards application form submissions, including your CV. Formspree stores submissions on Amazon Web Services infrastructure in the United States, encrypted at rest, and holds a SOC 2 Type II report. Its privacy policy, terms of service and security statement are published on its site
  • Microsoft Corporation — Microsoft 365, Exchange Online and OneDrive, where we store applications and correspondence. Under Microsoft’s EU Data Boundary, customer data for European customers is stored and processed within the EU and EFTA, of which Switzerland is a member

We may also disclose data where the law requires it, or to establish, exercise or defend legal claims.

7 — Transfers outside Switzerland and the EEA

All three of the providers above are US companies, so using this site can involve a transfer of data to the United States. The United States is not generally recognised as offering adequate protection; it is recognised only for organisations certified under the relevant Data Privacy Framework. Each provider rests on a different safeguard:

  • Netlify is certified under the EU–U.S. Data Privacy Framework and its Swiss–U.S. counterpart. Transfers of request-log data therefore rely on the European Commission's adequacy decision of 10 July 2023 and, for data originating in Switzerland, on the Federal Council's recognition of the Swiss–U.S. framework with effect from 15 September 2024
  • Formspree is not certified under either framework. It acts as our processor on the basis of the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914), which the FDPIC also recognises for transfers from Switzerland, together with the technical measures set out in its security statement
  • Microsoft keeps the bulk of our stored applications and correspondence inside the EU and EFTA under its EU Data Boundary. A limited set of service functions — among them spam and malware filtering and authentication — is still handled globally. Microsoft is certified under the EU–U.S. and Swiss–U.S. Data Privacy Frameworks and has accepted the FDPIC as the dispute resolution body for individuals in Switzerland

You may request a copy of the safeguards in place by writing to us. We re-check each provider's certification status whenever we review this policy.

If you would rather not have your data leave Switzerland or the EEA, email your application to hello@aylight.io instead of using the form.

8 — Your rights

Under the FADP and, where it applies, the GDPR, you may:

  • ask whether we process data about you, and obtain a copy of it (Art. 25 FADP; Art. 15 GDPR)
  • have inaccurate data corrected (Art. 32 FADP; Art. 16 GDPR)
  • have data deleted, or its processing restricted (Art. 32 FADP; Art. 17–18 GDPR)
  • receive the data you gave us in a machine-readable form, or have it sent to another controller (Art. 28 FADP; Art. 20 GDPR)
  • object to processing based on legitimate interests (Art. 30(2)(b) FADP; Art. 21 GDPR)
  • withdraw consent at any time, without affecting processing already carried out

Write to hello@aylight.io. We answer within 30 days and free of charge. We may ask you to identify yourself before we disclose data, so that we do not hand your information to someone else.

9 — Complaints

If you believe we have handled your data unlawfully, we would like the chance to put it right — but you are entitled to go straight to a regulator.

  • Switzerland — Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern
  • EEA — the supervisory authority of the country where you live, work, or where the alleged infringement occurred (Art. 77 GDPR)
10 — Security

This site is served exclusively over TLS. Access to applications and correspondence is restricted to the people involved in the relevant hiring decision, and protected by multi-factor authentication.

11 — Changes to this policy

We may update this policy as our processing changes. The version and effective date at the top of this page always reflect the current text.