Legal

Privacy policy

How Point Break Security GmbH handles personal data, and the rights you have.

Last updated: 24 September 2026

1. Who is responsible

The controller responsible for processing personal data on this website and in our business is:

Point Break Security GmbH
Industriepark 11
8610 Uster
Switzerland
UID: CHE-483.160.092

For any question about data protection, or to exercise your rights, use our contact form or write to the postal address above.

2. Scope and applicable law

This policy explains how we process personal data when you visit pbsec.tech, contact us, subscribe to our security briefings, or work with us as a client or business partner.

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP, in German nDSG), in force since 1 September 2023, and its ordinance. Where the EU General Data Protection Regulation (GDPR) applies, for example because we offer our services to people in the European Union or the European Economic Area, we also comply with the GDPR, and the rights and legal bases it provides apply to you.

3. What we process and why

3.1 Visiting this website

When you visit pbsec.tech, our hosting provider automatically records technical information in server log files: your IP address, the date and time of the request, the page or file requested, the referring page, the amount of data transferred, and your browser and operating system as reported by your browser.

We need this data to deliver the website, keep it stable and protect it against attacks and misuse. We do not combine it with other data or use it to identify visitors. We only analyze log files if there are concrete indications of unlawful use, for example an attack on the website.

3.2 Contacting us

When you use the contact form or write to us, we process the details you provide, typically your name, organization, email address, areas of interest and your message, to answer your inquiry and, where relevant, to prepare an offer.

The contact form sends your details over an encrypted connection to a small program that our hosting provider runs for us in Frankfurt, Germany. It checks the message for spam and forwards it to us by email through Resend (USA); the website does not store the form data. To limit the number of messages per visitor, the program keeps a one-way (salted hash) value derived from your IP address in its memory for up to one hour; it does not store the IP address itself.

3.3 Security briefings

If you subscribe to our security briefings through the form on this website, we use your email address to send you occasional analysis of threats, regulation and technology relevant to cybersecurity. We send briefings only with your consent or, for existing clients, based on our client relationship. You can unsubscribe at any time by replying to any briefing or writing to us; we will then stop sending briefings. We do not pass subscriber addresses to third parties.

3.4 Clients and business partners

When you are a client, a prospective client or a business partner, or work for one, we process contact and business details, correspondence, offers and offer letters, contracts, invoices and payment information, project documentation, reports and deliverables, and the information needed to provide services such as threat-intelligence feeds. We use this data to prepare, perform and administer our services and to meet our legal obligations, for example accounting and tax requirements.

3.5 Data we process on behalf of clients

In security engagements, such as penetration tests, audits or incident readiness work, we may come into contact with personal data held in our clients' systems. In these cases we act as a processor on behalf of our client, only within the scope agreed in writing and under strict confidentiality. The client's own privacy notice applies to that data.

4. Cookies, analytics and third-party content

This website does not use cookies, local storage for tracking, web analytics, advertising pixels, social-media plugins or embedded third-party content. Fonts, images and scripts are served from our own domain, so visiting the site does not disclose your IP address to third parties such as font or analytics services. Because we do not track you, there is nothing to accept or decline in a cookie banner.

5. Legal bases

Under the Swiss FADP, we process personal data in line with its principles of lawfulness, good faith, proportionality, purpose limitation and transparency. Where the GDPR applies, we rely on the following legal bases:

ProcessingLegal basis (GDPR)
Delivering and securing the website (server logs)Legitimate interests in a secure, functioning website (Art. 6(1)(f))
Protecting the contact form against spam and abuseLegitimate interests in a secure, usable form (Art. 6(1)(f))
Answering inquiriesSteps prior to a contract (Art. 6(1)(b)) or legitimate interests in answering you (Art. 6(1)(f))
Security briefingsConsent (Art. 6(1)(a)), which you can withdraw at any time
Providing services to clientsPerformance of a contract (Art. 6(1)(b))
Accounting, tax and other statutory dutiesLegal obligation (Art. 6(1)(c))
Establishing or defending legal claimsLegitimate interests (Art. 6(1)(f))

6. Recipients and service providers

We share personal data only where necessary, and only with:

  • IT service providers acting as processors on our behalf, in particular Vercel Inc. (USA) for hosting this website and running its contact form, Resend (USA) for delivering contact-form messages to our mailbox, and an external email and IT service provider for email and business systems. They may use personal data only on our instructions and must keep it secure.
  • Professional advisors such as accountants, auditors and lawyers, who are bound by confidentiality.
  • Authorities and courts, where we are legally required to disclose data or need to establish or defend legal claims.

We do not sell personal data and do not share it with third parties for their own marketing.

7. Disclosure abroad

We process personal data primarily in Switzerland. Where a service provider processes data in another country, we disclose it only to countries that the Swiss Federal Council recognizes as providing an adequate level of data protection, which includes the member states of the EU and EEA, or we ensure adequate protection by other means, in particular the European Commission's Standard Contractual Clauses as recognized by the Federal Data Protection and Information Commissioner (FDPIC). You can request a copy of these safeguards from us.

Our hosting provider and the service that delivers contact-form messages are based in the USA. For them, we rely on the Swiss-U.S. Data Privacy Framework, which the Federal Council recognizes as providing adequate protection for certified companies, where the provider is certified under it, and otherwise on Standard Contractual Clauses.

8. How long we keep data

We keep personal data only as long as necessary for the purpose for which it was collected, or as long as the law requires:

DataRetention
Spam-protection data (salted hash of the IP address)No longer than one hour
Server log filesUsually no longer than 30 days, unless needed to investigate a security incident
Inquiries that do not lead to a business relationshipDeleted no later than 24 months after our last contact
Security briefingsUntil you unsubscribe
Client and contract dataFor the duration of the relationship, then as required by law; accounting records and vouchers for 10 years (Art. 958f of the Swiss Code of Obligations)
Data processed on behalf of clientsAs agreed with the client; returned or deleted at the end of the engagement

9. Data security

We protect personal data with appropriate technical and organizational measures, including encrypted connections (HTTPS), restricted and need-to-know access, and confidentiality obligations for everyone who works with us. This website loads no third-party code and applies a strict Content Security Policy. No transmission over the internet is completely secure, but we work to keep the risk as low as possible.

10. Your rights

Subject to the applicable law, you have the right to:

  • Access: learn whether we process personal data about you and receive a copy of it;
  • Rectification: have inaccurate or incomplete data corrected;
  • Erasure: have your data deleted, unless we must keep it by law;
  • Restriction and objection: restrict or object to certain processing, including processing based on legitimate interests;
  • Data portability: receive data you provided to us in a common electronic format, or have it transferred to another controller;
  • Withdraw consent at any time, with effect for the future.

To exercise your rights, send us a request through our contact form or by post to the address in section 1. We may ask you to verify your identity, to make sure we disclose data only to the right person. We respond within 30 days. Exercising your rights is generally free of charge.

11. Complaints

If you believe we are not processing your personal data lawfully, please contact us first so that we can resolve the matter. You also have the right to contact a data protection supervisory authority:

  • In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch.
  • In the EU and EEA: the supervisory authority in your country of residence, place of work or the place of the alleged infringement.

12. Automated decisions

We do not make decisions based solely on automated processing, including profiling, that produce legal effects for you or similarly significantly affect you.

14. Changes to this policy

We may update this policy when our services, this website or the law change. The version published on this page applies, and the date at the top shows when it was last updated. If we make material changes, we will highlight them here.