Privacy Policy
Effective date: 8 September 2026
SHIBULERU GmbH (Steinbrüchelstrasse 2, 8053 Zurich, Switzerland, CHE-345.482.915) is the controller of personal data collected through www.shibuleru.com under the Swiss revFADP, EU GDPR, and UK GDPR (as amended by the Data (Use and Access) Act 2025).
Contact: inquiries@shibuleru.com
What we collect and why
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, email, message content (via email or forms) | Respond to inquiries and prepare commissions | Contract preparation and legitimate interest | 2 years from last contact |
| IP (truncated), browser, pages viewed | Operate and secure the site | Legitimate interest | 24 months, aggregated |
| Cookie preferences | Honor your consent | Legal obligation | 12 months |
| Commission records | Perform the contract and meet accounting law | Contract and legal obligation | 10 years (Swiss CO Art. 958f) |
We do not collect sensitive data. We do not knowingly collect data from children under 16.
Cookies
Essential cookies are set automatically. Non-essential cookies (Squarespace first-party analytics) are set only if you accept them on the banner. Change your choice via Cookie Preferences in the footer. The site sets no advertising or third-party tracking cookies.
Recipients
- Squarespace, Inc. (US) — hosting and analytics. Covered by SCCs, UK IDTA, and Swiss-US and EU-US Data Privacy Framework certification.
- Swiss accountants, legal advisers, and tax authorities — as required by contract or law.
We do not sell your data.
Your rights
Email inquiries@shibuleru.com. We reply within 30 days.
- revFADP: access, correction, deletion, objection. Complaint: FDPIC (https://www.edoeb.admin.ch).
- GDPR: access, rectification, erasure, restriction, portability, objection, withdrawal of consent. Complaint: your local supervisory authority.
- UK GDPR: the same rights. Complaint: ICO (https://ico.org.uk).
Security and breaches
We apply technical and organizational measures appropriate to the risk. We notify affected individuals and the competent authority of a data breach as required by revFADP Art. 24 and GDPR Art. 33-34.
Governing law
Swiss law. Statutory rights under GDPR and UK GDPR are unaffected.