Back to the homepage

Privacy policy

Version: 11 August 2026

1 · Controller

The controller responsible for data processing on this website is: AurPhi Moukrim, Marktstrasse 18, 8853 Lachen SZ, Switzerland. Email: hallo@aurphi.ch. The Swiss Federal Act on Data Protection (FADP) applies.

2 · The principle first

When you visit this website, your browser does not load any analytics services, advertising trackers or external fonts from third-party providers. Not a single cookie is set while you simply browse. Apart from these technically necessary connection data, we only process additional personal data when you take action yourself: through the contact form, the chat assistant or the client area.

3 · When you visit the website

So that the website can be delivered, our hosting infrastructure processes technically necessary data: IP address, date and time, the page accessed and browser information. This data is used to deliver the website, keep it secure and prevent abuse. The website is hosted by Render Services, Inc. (USA), including the content delivery network (CDN) that forms part of the hosting service. Render is certified under the Swiss-U.S. Data Privacy Framework. Server location: Frankfurt (Germany). The hosting provider retains the technical logs for 7 days.

4 · Contact form

If you write to us via the form, we process: your name, email address and message (required), as well as your phone number, company and industry (optional). Purpose: answering your enquiry and preparing a quote. Your enquiry is not stored in a database belonging to the website. It reaches us as an internal notification via the messaging service Telegram and also appears in our hosting provider's technical logs. We keep the notifications for as long as they are needed to handle the enquiry and for our internal analysis, and delete them as part of a regular review.

5 · The chat assistant

Our chat assistant is powered by artificial intelligence. Here is what happens:

  • Processing by AI Your chat messages are transmitted to OpenAI to generate the responses. The contracting party for customers in Switzerland is OpenAI Ireland Ltd (Dublin, Ireland); to provide the service, data may be transferred onward to affiliated companies outside Switzerland and the EEA, in particular in the USA, on the basis of standard contractual clauses under OpenAI's Data Processing Addendum. What is transmitted is the conversation history, not your IP address or other identifiers. If you choose to share contact details, they are prepared as an enquiry for us in a second automated step.
  • Retention by the AI provider In the standard configuration we use, the provider stores the application state of the interface (requests and responses) for up to 30 days; abuse-monitoring logs may also retain content for up to 30 days. According to OpenAI, API data is not used to train its models by default. OpenAI's Data Processing Addendum forms part of the applicable service agreement.
  • Storage in your browser The conversation remains stored in your own browser (localStorage) for 24 hours, under a random identifier that is not linked to you as a person. No cookie is set.
  • Review by AurPhi Once the conversation has ended, a copy is delivered to us via Telegram, even if you have not left any contact details. Authorised AurPhi personnel can view it. We use the conversations to answer enquiries, to understand common questions, interests and objections, to improve our services and to develop the assistant further (internal market analysis). We keep these copies for as long as they are needed for these purposes and delete them as part of a regular review.
  • Safeguards To prevent abuse, we work with pseudonymised identifiers rather than plain-text IP addresses. Please do not enter any particularly sensitive personal data in the chat (health data, for example).

6 · Client area

We set up client accounts for you personally; there is no self-registration. We process: email address, name, company and the data relating to your project. Your password is stored exclusively as a cryptographic hash. When you sign in, we set the website's only cookie: a session cookie (sp_session, 7 days, httpOnly, Secure). We keep account data for the duration of the client relationship; on request we delete it, provided no statutory retention obligations or legally relevant legitimate interests stand in the way.

7 · Email

Our mailbox hallo@aurphi.ch is hosted by the Swiss provider Infomaniak, which states that it hosts the data in Switzerland. We keep email correspondence for as long as it is needed for the client relationship.

8 · Recipients and transfers abroad

RecipientPurposeCountrySafeguard
Render Services, Inc. (hosting, incl. CDN)Operation of the website, technical logsUSA, server location Frankfurt (Germany)Swiss-U.S. Data Privacy Framework (certified)
OpenAI Ireland LtdChat assistant responsesIreland; onward transfer to affiliated companies in the USAStandard contractual clauses under the OpenAI DPA
TelegramInternal notifications and conversation copiesCloud service; Telegram lists group companies in the British Virgin Islands and Dubai, among other places; the exact storage location for Swiss accounts is not publicly specifiedTelegram cites intra-group standard contractual clauses for certain transfers
InfomaniakEmailSwitzerlandNo transfer abroad

9 · Your rights

You have the right to obtain information about your data, to have it corrected and to have it deleted, provided no statutory retention obligations or legally relevant legitimate interests stand in the way; where the statutory conditions are met, you also have the right to receive your data or have it transferred. To exercise these rights, write to hallo@aurphi.ch. You may also contact the Federal Data Protection and Information Commissioner (FDPIC).

10 · Security

Transmission between your browser and aurphi.ch is encrypted with TLS/HTTPS; HSTS ensures that connections run over HTTPS. Passwords are stored only as hashes, internal identifiers are pseudonymised, and only authorised personnel have access to enquiries and conversations. Further technical measures are in place, but for security reasons we do not describe them in detail.

11 · Changes

We amend this policy whenever the website or the legal situation changes. The version published here at any given time is the one that applies.