The controller is SRC – Security & Resilience Counsel, Zug, Switzerland - info@src.guide. This policy applies to website visits, accounts, memberships, briefings, enquiries, Q&A formats and other SRC services. We process personal data under the Swiss FADP and, where applicable, the GDPR.
We use data to operate, protect and improve services; manage accounts and access; provide requested content; communicate; send subscribed briefings; administer billing; prevent misuse; enforce legal rights; and create aggregated statistics. Where GDPR applies, our bases may include performance of contract, consent, legitimate interests and legal obligations.
Necessary cookies support operation, security and storage of your choices. Non-essential analytics, marketing, tracking or profiling technologies are activated only after consent where required by law. You can amend your choice at any time through "Cookie Settings" in the footer. The current cookie list, purposes, providers and retention periods appear in the cookie preference centre.
We use processors for hosting, infrastructure, authentication, email, analytics, support, security and, where enabled, AI-supported processing. Active providers and countries: Vercel Inc. (USA): Hosting and technical infrastructure. Resend Labs Inc. (USA): Email delivery and communications. We use Stripe for payment processing. Stripe processes payment information under its own responsibility and/or applicable privacy documentation. We typically receive payment status, amount, currency, subscription/invoice reference and details necessary for administration. Personal data may be processed outside Switzerland. Where needed, we use appropriate safeguards, including recognised standard contractual clauses and supplementary measures.
SRC may use AI tools for research, structuring, classification and drafting. We do not use personal data to train general-purpose AI models unless we provide advance transparent notice and have a valid basis. Public sources and third-party material are evaluated only to the necessary and lawful extent for research, analysis and documentation. Indicative retention: security logs 90 days; account data until account deletion plus 30 days; newsletter data until unsubscribe plus 3 years to evidence consent; communications 24 months; accounting records for statutory periods.
We implement appropriate technical and organisational safeguards, including access controls, role-based permissions, encryption, secure transmission, logging and backups. Subject to applicable law, you may request access, correction, deletion, provision/portability, restriction or objection, and withdraw consent for the future. Contact info@src.guide. We may require proof of identity. Complaints may be submitted to the Swiss FDPIC or the competent EEA authority, where applicable.