Privacy Policy

1. Controller and scope

The controller is SRC – Security & Resilience Counsel, Zug, Switzerland - info@src.guide. This policy applies to website visits, accounts, memberships, briefings, enquiries, Q&A formats and other SRC services. We process personal data under the Swiss FADP and, where applicable, the GDPR.

2. Data categories and purposes

  • Website and usage data: IP address, timestamps, pages visited, referrer, browser, device and technical log data, and cookie settings.
  • Account data: name, email address, password hash, language, access and membership status.
  • Communication, content and interaction data: enquiries, feedback, saved content, comments, annotations, Q&A contributions and preferences where offered.
  • Newsletter data: email address, subscription, consent/unsubscribe status, and technical delivery, opening and click data where enabled.
  • Payment and transaction data: status, plan, invoice and transaction references where paid memberships are offered. Stripe processes payment-card details; SRC does not store card numbers.

We use data to operate, protect and improve services; manage accounts and access; provide requested content; communicate; send subscribed briefings; administer billing; prevent misuse; enforce legal rights; and create aggregated statistics. Where GDPR applies, our bases may include performance of contract, consent, legitimate interests and legal obligations.

3. Cookies and analytics

Necessary cookies support operation, security and storage of your choices. Non-essential analytics, marketing, tracking or profiling technologies are activated only after consent where required by law. You can amend your choice at any time through "Cookie Settings" in the footer. The current cookie list, purposes, providers and retention periods appear in the cookie preference centre.

4. Service providers, Stripe and international transfers

We use processors for hosting, infrastructure, authentication, email, analytics, support, security and, where enabled, AI-supported processing. Active providers and countries: Vercel Inc. (USA): Hosting and technical infrastructure. Resend Labs Inc. (USA): Email delivery and communications. We use Stripe for payment processing. Stripe processes payment information under its own responsibility and/or applicable privacy documentation. We typically receive payment status, amount, currency, subscription/invoice reference and details necessary for administration. Personal data may be processed outside Switzerland. Where needed, we use appropriate safeguards, including recognised standard contractual clauses and supplementary measures.

5. AI, public sources and retention

SRC may use AI tools for research, structuring, classification and drafting. We do not use personal data to train general-purpose AI models unless we provide advance transparent notice and have a valid basis. Public sources and third-party material are evaluated only to the necessary and lawful extent for research, analysis and documentation. Indicative retention: security logs 90 days; account data until account deletion plus 30 days; newsletter data until unsubscribe plus 3 years to evidence consent; communications 24 months; accounting records for statutory periods.

6. Security and rights

We implement appropriate technical and organisational safeguards, including access controls, role-based permissions, encryption, secure transmission, logging and backups. Subject to applicable law, you may request access, correction, deletion, provision/portability, restriction or objection, and withdraw consent for the future. Contact info@src.guide. We may require proof of identity. Complaints may be submitted to the Swiss FDPIC or the competent EEA authority, where applicable.