Data processing for our clients
This page summarises annex 3 of the service agreement, which governs the processing of personal data on behalf of our clients. The signed annex is what binds; this page exists so you know what you are agreeing to before signing.
Roles
The client is the controller. They decide what data is collected on their site and why. Hallebardier is the processor and handles that data only on documented instructions, for the purposes of the contract alone. This split is not cosmetic: the client answers to the supervisory authority, and Hallebardier answers to the client.
Data processed
Name, email, phone and message from people filling in the client's contact form, kept two years after the last exchange. IP address and timestamp in server logs, thirty days. Aggregated analytics, six months. Business contact details published on the site, for the duration of the contract.
No sensitive data is processed in the standard scope. If the client's site were to collect any, this annex must be revised before launch.
Security measures
| Subprocessor | Role | Location | Transfer |
|---|---|---|---|
| Cloudflare, Inc. | Hébergement, CDN, sécurité, sauvegardes chiffrées | UE et réseau mondial | CCT |
| Google Ireland Ltd | Messagerie, agenda | UE | — |
| Resend, Inc. | Acheminement des formulaires | États-Unis | CCT |
| Infomaniak Network SA | Serveur du CRM | Suisse | — |
| Bexio AG | Facturation | Suisse | — |
| Skribble AG | Signature électronique | Suisse | — |
| Proton AG | Gestion des identifiants | Suisse | — |
| Better Stack | Surveillance de disponibilité | UE | — |
TLS 1.3 on all traffic, with HSTS. Backups encrypted before leaving the server, with a key that is not on it. Two-factor authentication, SSH keys only, root login disabled. Deny-by-default firewall, database not exposed. Access logs kept ninety days. Automatic security updates. Each client's data is kept separate.
Deletion and backups
At the end of the contract, active data is returned or deleted within thirty days, at the client's choice.
Backups cannot be selectively purged. They are encrypted and rotate on thirty days. An erasure request is therefore fully effective at most thirty days after the active data has been handled. That is a real technical limit, stated here rather than discovered during a deletion request.
Security breach
Hallebardier notifies the client without delay and at most twenty-four hours after becoming aware of a breach, with its nature, the categories and approximate number of people and records affected, the likely consequences and the measures taken. It falls to the client, as controller, to notify the supervisory authority.
Audit
Once per calendar year and with thirty days' notice, the client may request the information demonstrating compliance with this annex. An on-site audit is possible at their expense, during business hours.
Swiss law, exclusive jurisdiction in Fribourg. Last updated: August 2026.