Legal
Privacy policy
How Point Break Security GmbH handles personal data, and the rights you have.
Last updated: 24 September 2026
1. Who is responsible
The controller responsible for processing personal data on this website and in our business is:
Point Break Security GmbH
Industriepark 11
8610 Uster
Switzerland
UID: CHE-483.160.092
For any question about data protection, or to exercise your rights, use our contact form or write to the postal address above.
2. Scope and applicable law
This policy explains how we process personal data when you visit pbsec.tech, contact us, subscribe to our security briefings, or work with us as a client or business partner.
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP, in German nDSG), in force since 1 September 2023, and its ordinance. Where the EU General Data Protection Regulation (GDPR) applies, for example because we offer our services to people in the European Union or the European Economic Area, we also comply with the GDPR, and the rights and legal bases it provides apply to you.
3. What we process and why
3.1 Visiting this website
When you visit pbsec.tech, our hosting provider automatically records technical information in server log files: your IP address, the date and time of the request, the page or file requested, the referring page, the amount of data transferred, and your browser and operating system as reported by your browser.
We need this data to deliver the website, keep it stable and protect it against attacks and misuse. We do not combine it with other data or use it to identify visitors. We only analyze log files if there are concrete indications of unlawful use, for example an attack on the website.
3.2 Contacting us
When you use the contact form or write to us, we process the details you provide, typically your name, organization, email address, areas of interest and your message, to answer your inquiry and, where relevant, to prepare an offer.
The contact form sends your details over an encrypted connection to a small program that our hosting provider runs for us in Frankfurt, Germany. It checks the message for spam and forwards it to us by email through Resend (USA); the website does not store the form data. To limit the number of messages per visitor, the program keeps a one-way (salted hash) value derived from your IP address in its memory for up to one hour; it does not store the IP address itself.
3.3 Security briefings
If you subscribe to our security briefings through the form on this website, we use your email address to send you occasional analysis of threats, regulation and technology relevant to cybersecurity. We send briefings only with your consent or, for existing clients, based on our client relationship. You can unsubscribe at any time by replying to any briefing or writing to us; we will then stop sending briefings. We do not pass subscriber addresses to third parties.
3.4 Clients and business partners
When you are a client, a prospective client or a business partner, or work for one, we process contact and business details, correspondence, offers and offer letters, contracts, invoices and payment information, project documentation, reports and deliverables, and the information needed to provide services such as threat-intelligence feeds. We use this data to prepare, perform and administer our services and to meet our legal obligations, for example accounting and tax requirements.
3.5 Data we process on behalf of clients
In security engagements, such as penetration tests, audits or incident readiness work, we may come into contact with personal data held in our clients' systems. In these cases we act as a processor on behalf of our client, only within the scope agreed in writing and under strict confidentiality. The client's own privacy notice applies to that data.
5. Legal bases
Under the Swiss FADP, we process personal data in line with its principles of lawfulness, good faith, proportionality, purpose limitation and transparency. Where the GDPR applies, we rely on the following legal bases:
| Processing | Legal basis (GDPR) |
|---|---|
| Delivering and securing the website (server logs) | Legitimate interests in a secure, functioning website (Art. 6(1)(f)) |
| Protecting the contact form against spam and abuse | Legitimate interests in a secure, usable form (Art. 6(1)(f)) |
| Answering inquiries | Steps prior to a contract (Art. 6(1)(b)) or legitimate interests in answering you (Art. 6(1)(f)) |
| Security briefings | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Providing services to clients | Performance of a contract (Art. 6(1)(b)) |
| Accounting, tax and other statutory duties | Legal obligation (Art. 6(1)(c)) |
| Establishing or defending legal claims | Legitimate interests (Art. 6(1)(f)) |
6. Recipients and service providers
We share personal data only where necessary, and only with:
- IT service providers acting as processors on our behalf, in particular Vercel Inc. (USA) for hosting this website and running its contact form, Resend (USA) for delivering contact-form messages to our mailbox, and an external email and IT service provider for email and business systems. They may use personal data only on our instructions and must keep it secure.
- Professional advisors such as accountants, auditors and lawyers, who are bound by confidentiality.
- Authorities and courts, where we are legally required to disclose data or need to establish or defend legal claims.
We do not sell personal data and do not share it with third parties for their own marketing.
7. Disclosure abroad
We process personal data primarily in Switzerland. Where a service provider processes data in another country, we disclose it only to countries that the Swiss Federal Council recognizes as providing an adequate level of data protection, which includes the member states of the EU and EEA, or we ensure adequate protection by other means, in particular the European Commission's Standard Contractual Clauses as recognized by the Federal Data Protection and Information Commissioner (FDPIC). You can request a copy of these safeguards from us.
Our hosting provider and the service that delivers contact-form messages are based in the USA. For them, we rely on the Swiss-U.S. Data Privacy Framework, which the Federal Council recognizes as providing adequate protection for certified companies, where the provider is certified under it, and otherwise on Standard Contractual Clauses.
8. How long we keep data
We keep personal data only as long as necessary for the purpose for which it was collected, or as long as the law requires:
| Data | Retention |
|---|---|
| Spam-protection data (salted hash of the IP address) | No longer than one hour |
| Server log files | Usually no longer than 30 days, unless needed to investigate a security incident |
| Inquiries that do not lead to a business relationship | Deleted no later than 24 months after our last contact |
| Security briefings | Until you unsubscribe |
| Client and contract data | For the duration of the relationship, then as required by law; accounting records and vouchers for 10 years (Art. 958f of the Swiss Code of Obligations) |
| Data processed on behalf of clients | As agreed with the client; returned or deleted at the end of the engagement |
9. Data security
We protect personal data with appropriate technical and organizational measures, including encrypted connections (HTTPS), restricted and need-to-know access, and confidentiality obligations for everyone who works with us. This website loads no third-party code and applies a strict Content Security Policy. No transmission over the internet is completely secure, but we work to keep the risk as low as possible.
10. Your rights
Subject to the applicable law, you have the right to:
- Access: learn whether we process personal data about you and receive a copy of it;
- Rectification: have inaccurate or incomplete data corrected;
- Erasure: have your data deleted, unless we must keep it by law;
- Restriction and objection: restrict or object to certain processing, including processing based on legitimate interests;
- Data portability: receive data you provided to us in a common electronic format, or have it transferred to another controller;
- Withdraw consent at any time, with effect for the future.
To exercise your rights, send us a request through our contact form or by post to the address in section 1. We may ask you to verify your identity, to make sure we disclose data only to the right person. We respond within 30 days. Exercising your rights is generally free of charge.
11. Complaints
If you believe we are not processing your personal data lawfully, please contact us first so that we can resolve the matter. You also have the right to contact a data protection supervisory authority:
- In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch.
- In the EU and EEA: the supervisory authority in your country of residence, place of work or the place of the alleged infringement.
12. Automated decisions
We do not make decisions based solely on automated processing, including profiling, that produce legal effects for you or similarly significantly affect you.
13. Links to other websites
This website contains links to external websites, such as the publishers of the reports we cite. When you follow such a link, the operator of that website is responsible for processing your data. Please read their privacy policies before providing personal information.
14. Changes to this policy
We may update this policy when our services, this website or the law change. The version published on this page applies, and the date at the top shows when it was last updated. If we make material changes, we will highlight them here.