Privacy Policy
Last updated: 10 July 2026
This privacy policy explains what personal data is processed when you visit this website, use the contact form, or use the Octbase web application (including the public demo), for what purposes and what rights you have. As the controller is based in Switzerland, we process personal data primarily in accordance with the revised Swiss Federal Act on Data Protection (revFADP, in force since 1 September 2023) and its Data Protection Ordinance (DPO). Where the EU General Data Protection Regulation (GDPR) additionally applies — in particular to visitors in the EU/EEA — we also comply with it; the GDPR legal bases cited below apply only where the GDPR is applicable. Unlike the GDPR, the revFADP does not require a separate statutory basis for each processing activity by a private controller, but binds it to the principles of lawfulness, good faith, proportionality, purpose limitation, transparency and data security (Art. 6 revFADP).
1. Controller
Lars Frasseck
Renggerstrasse 49
8038 Zürich
Switzerland
For all privacy-related requests, contact:
2. Scope
This policy covers the website ocete.ch, the public demo at demo.ocete.ch, and Octbase instances we host and operate for clients. Where an Octbase instance is operated for a client organization, that organization is the controller for the data its users enter, and we act as a processor on its behalf.
3. Visiting the website (server logs)
When you access this website, the web server technically requires and temporarily processes connection data: your IP address, date and time of the request, the requested resource, the HTTP status, and the browser identifier (user agent). This data is used solely to deliver the website reliably, to defend against abuse (e.g. rate limiting), and to diagnose technical faults. We process this connection data on the basis of our overriding interest in the secure and stable operation of the service (Art. 31(1) revFADP; where the GDPR applies, Art. 6(1)(f) GDPR).
Log data is not merged with other data sources, is not used to build profiles, and is deleted automatically after a short period. This website uses no analytics, tracking or advertising services, and loads no resources from third-party servers.
4. Contact form
If you use the contact form, we process the details you enter (name, email address, and optionally company, team size, and your message) exclusively to handle your inquiry. This data is transmitted to us by email and is not stored in a database on the web server. We process it to take steps at your request prior to entering into a contract and on the basis of our legitimate interest in answering your inquiry (where the GDPR applies, Art. 6(1)(b) and (f) GDPR).
You receive an automatic confirmation email to the address you provided. To prevent abuse, form submissions are rate-limited per IP address; the IP address is held in memory only for this purpose and is not stored permanently. Correspondence is kept for as long as needed to handle your inquiry and any resulting business relationship, and is then deleted.
5. Using the Octbase application
If you sign in to an Octbase instance (including the demo), the following data is processed to provide the service under our contract with you or your organization and — for the security audit log — on the basis of our overriding interest in the traceability of security-relevant events (where the GDPR applies, Art. 6(1)(b) and 6(1)(f) GDPR):
- User account: email address, display name, password (stored only as a salted hash, never in plain text), role, account status, and last login time.
- Work content: projects, tasks, comments, pages and attachments you create, linked to your account.
- Security audit log: administrative actions and sign-ins, recorded with IP address and browser identifier.
- Activity feed: project-level actions (e.g. "task moved") together with your user ID, for team transparency.
- Email delivery: your email address is used to send invitations and notifications.
The public demo instance is reset regularly; do not enter real personal data there. Client instances are operated separately, one instance per client, and are not shared between customers.
6. Cookies and local storage
This website itself sets no cookies. The Octbase application uses only strictly necessary cookies and local browser storage:
- refresh_token (HttpOnly cookie): keeps your session alive and expires automatically. Strictly necessary.
- refresh_present (cookie): records only that a session exists, without any content. Strictly necessary.
- localStorage: language, color scheme and view preferences. This stays on your device and is never transmitted to us.
Because only strictly necessary cookies are used, no consent banner is required.
7. Recipients and hosting
Personal data is never sold and is not shared with third parties for advertising purposes. Data is disclosed to third parties only where this is necessary to operate the service or where we are legally obliged to do so.
The website and the Octbase instances are hosted on servers in Switzerland. Emails (contact-form delivery, confirmations, application notifications) are delivered via the same hosting provider, located in Switzerland, acting as our processor under a data processing agreement.
8. Retention periods
- Account data: until the account is deleted.
- Security audit log and activity feed: 365 days by default, then purged automatically.
- Expired sessions and unaccepted invitations: removed automatically.
- Server logs and contact correspondence: deleted as soon as they are no longer required for the purposes described above.
9. Your rights
Under the revFADP you have the right to information about whether and how we process your personal data (Art. 25 revFADP), to have inaccurate data corrected (Art. 32 revFADP), to request that data be deleted or its processing restricted, to object to a processing, and to receive personal data you have provided in a common electronic format (data portability, Art. 28 revFADP). Where the GDPR applies, you additionally have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), and — where processing rests on consent — to withdraw it at any time with effect for the future. To exercise these rights, contact the address given in section 1.
You also have the right to lodge a complaint with a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in the EU the data protection authority of your member state.
When an Octbase account is deleted, all personal details are erased or anonymized; work content the user created remains available to their organization, attributed to "Deleted user".
10. Data security
All connections to the website and the application are encrypted with TLS. Passwords are stored only as salted hashes. Access to production systems is restricted and security-relevant actions are logged. These technical and organizational measures follow the data-security requirements of Art. 8 revFADP and its Ordinance (and Art. 32 GDPR where applicable).
11. Changes to this policy
We may update this privacy policy when the service or the legal situation changes. The version published here is the current one; the date at the top indicates the last revision.