Privacy Policy
Obsidian Monitoring Advisory — a product of Obsidian Technologies SARL
Last updated: February 13, 2026
1. Introduction
Obsidian Technologies SARL ("Obsidian Technologies", "we", "us", or "our"), a company registered in Switzerland with its registered office in Lausanne, operates the Obsidian Monitoring Advisory platform accessible at obsidianvisory.com (the "Service").
This Privacy Policy describes how we collect, use, store, and protect your personal data when you access or use the Service. It applies to all users of Obsidian Monitoring Advisory, whether through a web browser, mobile device, or any other means.
By accessing or using Obsidian Monitoring Advisory, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Policy, please discontinue use of the Service.
2. Data Controller
The data controller responsible for processing your personal data is:
Obsidian Technologies SARL Lausanne, Switzerland
For any privacy-related inquiries, please contact us at: privacy@obsidianvisory.com
3. Data We Collect
3.1. Information You Provide Directly
When you create an account or use our Service, we may collect the following personal data:
- Account information: name, email address, phone number, job title, and company name.
- Authentication data: credentials used to sign in to your account (processed through Firebase Authentication).
- Communication data: any information you provide when contacting our support team or submitting feedback.
3.2. Information Collected Automatically
When you access the Service, we automatically collect certain technical data, including:
- Device and browser information: device type, operating system, browser type and version, screen resolution, and language preferences.
- Usage data: pages viewed, features used, click patterns, session duration, and frequency of visits.
- Network data: IP address, approximate geographic location (city/country level), Internet Service Provider (ISP), and referring/exit URLs.
- Cookies and similar technologies: we use cookies, local storage, and similar technologies to maintain session state, remember preferences, and collect analytics data (see Section 7 below).
3.3. Data Collected Through Third-Party Services
We use the following third-party analytics and service providers, which may collect data on our behalf:
- Google Analytics (Google LLC): collects anonymized usage statistics, including page views, session duration, user demographics, and traffic sources. Google Analytics uses cookies to identify returning users. For more information, see Google's Privacy Policy.
- Firebase Authentication (Google LLC): processes authentication tokens and user identity data necessary for secure login. For more information, see Firebase Privacy and Security.
- Algolia (Algolia SAS): processes search queries to deliver search functionality within the platform. For more information, see Algolia's Privacy Policy.
4. How We Use Your Data
We process your personal data for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Providing and maintaining the Service | Performance of the contract (Art. 6(1)(b) GDPR / Art. 13 nDSG) |
| User account management and authentication | Performance of the contract |
| Improving the Service and user experience | Legitimate interest (Art. 6(1)(f) GDPR / Art. 31 nDSG) |
| Sending service-related notifications and alerts | Performance of the contract |
| Analyzing usage patterns and platform performance | Legitimate interest |
| Ensuring security and preventing fraud | Legitimate interest |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c) GDPR / Art. 31 nDSG) |
We do not use your personal data for automated decision-making or profiling that produces legal effects.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to third parties.
We may share your data in the following limited circumstances:
- Service providers: we share data with trusted third-party service providers who assist us in operating the platform (e.g., hosting, analytics, authentication), subject to contractual obligations of confidentiality and data protection.
- Legal requirements: we may disclose personal data if required to do so by law, regulation, or legal process, or if we believe in good faith that such disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: in the event of a merger, acquisition, or asset sale, personal data may be transferred to the acquiring entity, subject to the same privacy protections described herein.
6. International Data Transfers
As a Swiss-based company, your data is primarily stored and processed in Switzerland and the European Economic Area (EEA).
Where data is transferred outside of Switzerland or the EEA (e.g., to Google LLC in the United States for analytics and authentication purposes), we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions by the Swiss Federal Data Protection and Information Commissioner (FDPIC).
- The EU-U.S. Data Privacy Framework, where applicable.
7. Cookies and Tracking Technologies
7.1. Types of Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Strictly Necessary | Session management, authentication, security | Session / 30 days |
| Analytics | Usage statistics via Google Analytics | Up to 2 years |
| Functional | User preferences and settings | Up to 1 year |
7.2. Google Analytics
We use Google Analytics to understand how users interact with the Service. Google Analytics collects data through cookies and transmits it to Google servers. We have implemented the following privacy measures:
- IP anonymization: your IP address is truncated before transmission to Google.
- Data retention: analytics data is retained for 14 months, after which it is automatically deleted.
- No advertising features: we do not use Google Analytics advertising features, remarketing, or demographics and interest reporting.
7.3. Managing Cookies
You can control or disable cookies through your browser settings. Please note that disabling strictly necessary cookies may impair the functionality of the Service. You may also opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Policy:
- Account data: retained for the duration of your active account, and for up to 12 months following account closure.
- Analytics data: retained in anonymized form for up to 14 months.
- Communication records: retained for up to 24 months.
- Legal and compliance data: retained as required by applicable law.
Upon expiration of the retention period, data is securely deleted or anonymized.
9. Data Security
We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:
- Encryption of data in transit (TLS/SSL) and at rest.
- Secure authentication mechanisms via Firebase Authentication.
- Regular security assessments and monitoring.
- Role-based access controls and the principle of least privilege.
While we take all reasonable precautions, no method of transmission over the Internet or electronic storage is entirely secure. We cannot guarantee absolute security of your data.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of access: obtain a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): request deletion of your personal data, subject to legal retention obligations.
- Right to restriction of processing: request limitation of how we process your data.
- Right to data portability: receive your data in a structured, commonly used, machine-readable format.
- Right to object: object to processing based on legitimate interest.
- Right to withdraw consent: where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at privacy@obsidianvisory.com. We will respond within 30 days of receiving your request.
10.1. Swiss-Specific Rights
Under the Swiss Federal Act on Data Protection (nDSG), Swiss residents have the right to request information about their data and to request correction or deletion. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).
10.2. EU/EEA-Specific Rights
Under the General Data Protection Regulation (GDPR), EU/EEA residents may lodge a complaint with their local data protection supervisory authority.
11. Children's Privacy
Obsidian Monitoring Advisory is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16, we will take steps to delete such data promptly.
12. Third-Party Links
The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal data.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Provide a notice within the Service where appropriate.
We encourage you to review this Privacy Policy periodically.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Obsidian Technologies SARL Lausanne, Switzerland Email: privacy@obsidianvisory.com
This Privacy Policy is governed by Swiss law. Any disputes arising from or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Lausanne, Switzerland.