Placeholders in [square brackets] must be filled in before the domain goes live. Have a lawyer read the whole page — it was drafted from what the website's code actually does (2026-09-11), not the other way round.
Who is responsible
Trilliome GmbH, 8049 Zürich, Switzerland ("we"). For anything in this notice, including your rights below: [privacy@trilliome.com].
This notice covers the website at trilliome.com. It is written to meet the Swiss Federal Act on Data Protection (nFADP) and, for visitors in the EU/EEA, the GDPR.
What we process when you visit
Delivering the pages. Our server receives your IP address in order to send you the page you asked for. It is not written to a log file. We use it once, on the server, to look up a country and city in a local copy of the GeoLite2 database (MaxMind), keep a count per country and city, and discard the address. No IP address is stored.
Usage statistics. To understand which pages and sections are read, we record the page path, how you arrived (the referring page or campaign parameter), which sections were on screen and for how long, which buttons were used, the colour theme shown to you, and which variant of a text you saw (see cookies). A random session identifier lives in your browser's sessionStorage for as long as the tab is open, so that the pages of one visit can be counted as one visit; it is deleted when the tab closes and is never sent to anyone else. There is no third-party analytics service, no advertising network and no tracking across websites. Legal basis: our legitimate interest in knowing how the site is used (nFADP art. 31; GDPR art. 6(1)(f)).
Cookies and browser storage. The site sets no tracking cookies and shows no cookie banner, because nothing it stores identifies you or follows you. What it does use: ab_ session cookies, which remember which of two versions of a text you were shown so that a visit is consistent — they are deleted when you close the browser; a theme preference in localStorage, only if you use the light/dark switch; and, for our own staff, a session cookie for the internal dashboard.
What we process when you write to us
Contact, partner and investor forms. Your name, e-mail address, organisation and message, so that we can answer you. Legal basis: taking steps at your request before a contract (GDPR art. 6(1)(b)) or our legitimate interest in responding to enquiries.
Subscribe. Your e-mail address, so that we can send you news when we start sending it. You can withdraw at any time; every mailing carries an unsubscribe link. Legal basis: your consent.
Tanya, the assistant on the landing page. Tanya asks three questions with tappable answers; those answers are stored without any identifier and only ever counted in aggregate. If you choose "Something else…" and type an answer, or leave your e-mail address at the end, that text and address are stored with the answers and used to follow up with you. Legal basis: your consent, given by typing it.
Who receives data, and where
- Hosting: [Infomaniak SA, Geneva, Switzerland]. All stored data sits on servers in Switzerland.
- Slack Technologies, LLC (USA): when a form is submitted or Tanya is answered, our team is notified in Slack with the content of the submission. Slack is certified under the Swiss–US and EU–US Data Privacy Framework.
- Resend, Inc. (USA): sends the sign-in codes for our internal dashboard to our own staff. Visitor data is not sent through it.
No other recipients. We do not sell data and we do not use it for advertising.
How long we keep it
Form submissions and Tanya conversations: 24 months from receipt, after which they are deleted automatically. Usage statistics are aggregate counts that contain no personal data and are kept for as long as they are useful. Subscribe addresses: until you unsubscribe.
Your rights
You can ask us for a copy of the personal data we hold about you, have it corrected or deleted, restrict or object to its processing, and receive it in a portable format. Write to [privacy@trilliome.com]. You may also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, in the EU/EEA, to the supervisory authority of your country.
Security
The site is served over HTTPS only, with a strict content-security policy. It collects as little as it can, stores it on Swiss servers, and limits access to the internal dashboard to named staff who sign in with a one-time code.
Changes
This notice was last updated on [date]. When we change what the site processes, we update it here.