Privacy
This privacy policy describes how rechtundgesetz.ch processes personal data, which cookies and optional measurement functions are used and which choices are available. The functions actually activated on the website are decisive in each case.
rechtundgesetz.ch facilitates orientation, search and context for publicly accessible Swiss legal information.
Where technical recognition is required, application data is shortened, hashed or aggregated where possible instead of being kept as a plain-text profile.
Optional cookie and privacy settings can be adjusted at any time on the settings page.
Controller
Operator
Foxware Fluri
Marco Peter Fluri
Bahnhofstrasse 10
3800 Interlaken
Switzerland
Privacy contact
Privacy and security enquiries can be submitted using the contact options described in the Imprint . Please make requests as precise as possible so that they can be correctly assigned and answered.
rechtundgesetz.ch is primarily aimed at users in Switzerland. Applicable Swiss data protection law is observed; where additionally applicable in an individual case, requirements of European data protection law are also taken into account.
Data that is processed
Technical access data
When the website is accessed, technically necessary access data is generated, such as the requested URL, time, HTTP status, browser/device information, referrer and IP address. This data is required to deliver the website, detect abuse, analyse technical errors and ensure stable operation.
Where rechtundgesetz.ch processes its own usage, search, security or statistical data, the IP address is not stored as a plain-text profile. Where possible, it is processed technically only for a short period and then shortened, hashed or used in pseudonymised form. This allows repeated technical processes to be recognised without keeping a directly readable IP address in the application data.
Server and security logs of the hosting operation may separately contain technically necessary access data. This data is not used for public statistics, convenience functions or personal usage profiles.
Search, rate limits and retry logic
Search queries are processed to calculate results, limit abuse and ensure the technical stability of the search. Pseudonymised technical characteristics may be used for fair-use limits, retry logic, technical retries or abuse protection.
The application is designed not to store plain-text IP addresses for these purposes in statistical, convenience or search-history data. Search and security data is handled separately from public content and used only for as long as required for operation, stability, error analysis or abuse protection.
User account and community functions
When an account is created or a community function is used, data including email address, username, profile information, roles/rights, verification status, logins, ratings, comments, tags, links, moderation information and technical security evidence may be processed.
For public proposals, the normalised legal-content reference, submission and moderation status, publishable reasons for decisions, and the version and hash of the accepted community rules are also stored. Internal moderation notes are not public and are not shown to the submitting person.
Private tags, their names, symbols, sorting and assignments are account-bound organisational data. They are not returned in public tag or community queries and are not shared with team members.
Subscriptions, payments and invoices
For User+ and Team/Professional, data including product, subscription status, monthly contractual period, cancellation status, payment status, invoice references, amount, currency, tax status and technical provider references is processed. Payment instruments such as full card details are processed by the payment service used and are not stored in the application.
Provider events whose signatures have been verified are logged idempotently so that payments, failed attempts, refunds and disputes can be reliably assigned. Only the scope necessary for operation, support, fraud prevention, accounting and statutory retention is stored.
Teams and workspaces
For teams, the name, owner, memberships, roles, invitation status, ownership transfers, seat usage and security- and billing-relevant audit events are processed. Members generally see only the profile data required for collaboration and role management.
For unambiguous administration of active memberships, the current team owner is additionally shown the login/system email address stored in the user account for each active team member. This address is not visible to ordinary team members and is not made available to them through the individual display-name setting or the directory mode. It is used in particular to identify members reliably before removal or an ownership transfer.
Personal dossiers, favourites, histories and private tags remain assigned to the personal user account and are not transferred to the owner when joining or leaving a team. Team data is assigned to a separate team workspace. Active members can read and edit its team dossiers; only the owner can permanently delete them and export the complete workspace. By default, the owner has no access to personal content or individual quota usage; an enabled statistic can display numerical totals only.
When a transfer of a personal dossier is expressly confirmed, its workspace assignment together with its content and notes is atomically changed to the team and logged as an audit event. The dossier then remains team data even if the transferring person leaves the team. On final account deletion, personal creator and transfer references are removed from retained team data.
After a team subscription ends, the team workspace may remain available to the owner for 30 days in read/export mode and is then archived. Team memberships, invitations and audit data may, where necessary, be retained separately from the personal account.
Dossiers, templates and change monitoring
Dossiers and custom templates may contain names, descriptions, notes, sorting and references to legal content. Monitoring processes the monitored dossier item, the last checked legal status, detected version changes, check times and delivery records.
Optional digest emails are disabled by default. Eligible users can independently choose off, daily, monthly or yearly. The summary includes only undelivered events from personal workspaces or teams of which the person is currently a member; deliveries are deduplicated per event and user.
Deactivate or delete account
An account can be deactivated or permanently deleted. Deactivation blocks access and turns off the optional monitoring summary; personal account data is retained for possible reactivation.
On final account deletion, login data, email address, display name, 2FA data, tokens, favourites, personal history, personal dossiers, personal templates and personal monitoring settings are removed. Ratings may be retained without user attribution as anonymised content signals. Comments and personal community submissions are removed. Team dossiers remain with the team; references to the deleted person are removed from them. Usage and search data is separated from the account; aggregated or no-longer-personal signals may be retained to optimise the site.
Communication
When contact is made, the submitted information is processed so that the enquiry can be answered and documented in a traceable manner.
Supporter redirect and click counting
When an approved advertising material or an entry on the Supporters page is clicked, the click may be routed via an internal redirect from rechtundgesetz.ch to the supporter’s target page. For supporter reports, only aggregated daily values such as date, campaign, advertising material, slot or Supporters page, format, language and target host are counted.
For this supporter reporting, no plain-text IP addresses, user IDs or personal user profiles are provided to supporters or advertising customers. The evaluation is used to document the booked advertising presence and remains separate from personal community, account or search usage.
Public legal data
Legislation, ordinance, article and systematic-classification data comes from publicly accessible sources. This content is generally not personal data of users; it is processed for search, presentation, linking and classification.
Purposes of processing
- Operation, security and technical delivery of the website.
- Provision of search, navigation, language choice, user account and community functions.
- Protection against abuse, spam, attacks and unauthorised access.
- Improving the findability of important enactments, articles and thematic entry points.
- Communication, support, error analysis and further development of the platform.
- Compliance with legal obligations and protection of legitimate interests.
Cookies and consent
rechtundgesetz.ch distinguishes three main categories:
Technically necessary
Required for language, session, form protection, security and storage of the cookie choice. This category cannot be disabled.
Functional / first-party
Optional convenience functions and internal relevance measurement on our own infrastructure. These include, for example, recently read content, anonymous public-rating identifiers and aggregated usage signals to make frequently requested content more visible.
Some convenience functions can only be used with this consent. Fair use.
Third-party / analytics
Optional third-party analytics, in particular Google Analytics. This category is loaded only after consent and is separate from internal first-party measurement.
The current choice can be changed at any time on the Cookie and privacy settings page.
First-party relevance measurement
Internal relevance measurement is intended to make rechtundgesetz.ch easier to understand and more useful. For example, it can help make frequently read federal acts, articles or thematic entry points more visible.
- Tracking requests go to an API operated by rechtundgesetz.ch and are executed only if the “Functional / first-party” category has been allowed.
- Do Not Track is respected where the browser sends a corresponding signal.
- Bot and crawler requests are filtered where possible.
- No plain-text IP addresses are stored as user profiles for internal measurement and abuse protection.
- Recognition, fair-use logic and security checks use pseudonymised or hashed characteristics where technically necessary.
- Aggregated values may be retained for longer in order to identify trends and relevance over longer periods.
Technical events for internal measurement are currently designed for a retention period of 30 days and aggregated values for 730 days. Changes to the technical configuration remain possible provided that they are implemented in compliance with data protection requirements and described transparently.
Google Analytics
rechtundgesetz.ch may use Google Analytics 4 to better understand reach and use of the website. Google Analytics is activated only if the “Third-party / analytics” category has been allowed.
With Google Analytics 4, cookies such as _ga and _ga_<container-id> may in particular be set. Google describes these as first-party cookies used to distinguish individual users and store session status. According to Google, the default lifetime is up to two years.
According to Google, when data is collected in Google Analytics, IP addresses of users in the EU, Switzerland or the United Kingdom are not logged or stored; they are used to derive location data and are then deleted. Nevertheless, processing by Google takes place and data may be transmitted to companies of the Google group.
Further information is available in Google’s privacy policy and in Google Analytics Help on GA4 cookies.
Icons and locally hosted resources
rechtundgesetz.ch uses Font Awesome to display icons. The required CSS and font files are delivered locally from our own server.
Loading these icons does not establish a connection to Font Awesome, cdnjs, Cloudflare or other external CDN providers. This therefore does not trigger additional third-party requests, set FontAwesome or CDN cookies, or transmit access data to such providers because of icon display.
External scripts or third-party services are used only when technically provided for and when the required cookie or privacy setting permits them.
Hosting, security and recipients
Personal data may be processed by technical service providers used for hosting, security, maintenance, email delivery, analytics or similar operational purposes. Such providers may generally process data only within the scope of the respective purpose.
Server logs, security logs and hosting-provider logs are technically separate from first-party tracking, convenience functions and public statistics. They serve in particular delivery, error analysis, attack detection and operational stability.
Data may also be disclosed where required by law, necessary to enforce legitimate claims or necessary to defend against attacks, abuse or security incidents.
Retention
Personal data is retained only for as long as necessary for the relevant purpose, while legal obligations apply or where legitimate interests justify longer retention. Account data and community contributions may remain stored for as long as an account exists or traceability of discussions, moderation and security is required.
Technical logs, security data and measurement data are shortened, aggregated, pseudonymised or deleted where possible once they are no longer needed for error analysis, security and platform improvement.
Rights of data subjects
Data subjects may, within the scope of applicable law, request access, correction, deletion, restriction, data disclosure or object to processing. Where processing is based on consent, consent may be withdrawn for the future.
Requests should be made as precisely as possible so that they can be clearly assigned and reviewed. Appropriate proof of identity may be requested to prevent abuse.
Changes to this policy
This privacy policy may be adapted if legal requirements, technical functions or organisational processes change. The version published on rechtundgesetz.ch at the relevant time is authoritative.
Content last updated: