Legal
Privacy Policy.
How this website handles the personal data it collects, who receives it, how long it is kept, and the rights you keep over it.
Draft: pending legal review
Dit document is in het Engels opgesteld. De Engelse versie is bindend.
Who is responsible
Reverz Group AG, Poststrasse 30, 6300 Zug, Switzerland (UID CHE-417.231.969), operates www.reverz.com and is responsible for the personal data processed through it. For any question about this statement or about your data, write to info@reverz.com.
This statement covers the website: its forms, the customer accounts and the online shop. It applies under the Swiss Federal Act on Data Protection (FADP) and, where you are in the European Union, under the General Data Protection Regulation (GDPR).
Requests through our forms
Consultation and contact form. Your name, work e-mail address, company, phone number and message, and the language of the page. We use them to answer your request: as a step before a possible contract (GDPR Art. 6(1)(b)) and in our legitimate interest in following up a business enquiry (Art. 6(1)(f)).
ITAD presentation. Your name, work e-mail address and company, and the language of the page. We use them to e-mail you the download link and to follow up on your interest (Art. 6(1)(f)). The request is recorded in our customer relationship management system (CRM).
Asset-list upload. Your company, contact person, work e-mail address, optional phone number and country; the number of sites, the service and the period you ask for; your message; whether you asked for a non-disclosure agreement; and the asset list you upload. We use them to prepare and discuss your quote (Art. 6(1)(b)). The request and the list are recorded in our CRM. An asset list normally describes equipment, not people: please leave out personal data the quote does not need.
CareOne request. Your company, contact person, work e-mail address and optional phone number; when your OEM support ends, the approximate number of systems and the service level you are considering; your message; and the OEM renewal quote or asset list you send, through the form or by e-mail. We use them to prepare your coverage check and TCO comparison (Art. 6(1)(b)). The request and the file are recorded in our CRM.
The fields a form marks as required are needed to answer you; without them we cannot handle the request.
Newsletter
Only if you tick the box on the presentation form do we add your e-mail address, name and company to our newsletter list, on the basis of your consent (Art. 6(1)(a)). Every newsletter carries an unsubscribe link, and you can withdraw your consent at any time by writing to us; withdrawal does not affect what happened before it.
How an uploaded file is handled
An asset list or renewal quote you upload travels over an encrypted connection straight into encrypted storage in Frankfurt, Germany. Before anyone at Reverz opens it, it is checked for its real file type and scanned for malware by a scanning service in the EU, which deletes the file once the scan is done. The file is then handed to our CRM and deleted from the website's storage. A file that cannot be handed over straight away stays in that storage for seven days at the most.
It is used only to prepare your quote or comparison. It is never shared with buyers or other third parties.
Customer accounts and orders
If you create an account, we store your e-mail address and a hash of your password (never the password itself), and then the addresses, shopping carts and orders you add to it, so that you can sign in, order and use the customer platform (Art. 6(1)(b)). Account e-mails, such as a confirmation link or a security code, are sent through our e-mail provider.
When you place an order in the marketplace, your order, payment and delivery details are processed by Shopify, which runs our shop, and by the payment provider you choose at checkout, to fulfil the order (Art. 6(1)(b)) and to keep the records the law requires (Art. 6(1)(c)).
Security and bot protection
Our hosting provider records technical data, such as your IP address, your browser and the page requested, to deliver the website and keep it secure (Art. 6(1)(f)). These logs are kept for a short period, at most 30 days.
Our forms are protected against automated abuse with Cloudflare Turnstile, which runs invisibly and may process limited technical data, such as your IP address, to tell people from bots. This processing is described in the Cloudflare Turnstile Privacy Addendum.
Data travels encrypted (TLS) and is stored encrypted. Access is limited to the people who need it for the purposes described here.
Analytics
This website measures how it is used, so we can see which pages are read and where visitors leave.
Vercel Web Analytics runs on every visit. It is cookieless and aggregate: it stores nothing on your device and does not follow you across sites.
Google Analytics 4 runs under Google Consent Mode. Until you accept, it stores and reads nothing on your device and reports only cookieless, aggregate measurements. If you accept, it sets two first-party cookies (_ga and _ga_ZHZ2E7J7MY) that let us recognise a returning browser (Art. 6(1)(a)). No advertising or personalisation signals are enabled, nothing is shared with advertisers, and there is no cross-site tracking.
You can change or withdraw your answer at any time through “Cookie Settings” in the footer. Declining also removes any analytics cookies already stored.
Who receives your data
We use the following service providers, each bound by a data processing agreement and each only for the task named.
Vercel hosts the website, on servers in Frankfurt, Germany. Supabase stores the customer accounts and, for a few days at most, uploaded files, in Frankfurt. Resend delivers our e-mails, from Ireland. Odoo hosts our CRM, in the EU. Cloudflare provides the bot protection on our forms. Google provides Google Analytics, as described above. Shopify runs the online shop. A malware-scanning service in the EU checks uploaded files.
Within the Reverz group, your request is shared only with the people who handle it. We do not sell personal data, and we do not share it for advertising.
Transfers abroad
Switzerland and the European Union recognise each other's level of data protection. Some of our providers are companies based in the United States (Vercel, Supabase, Resend, Cloudflare, Google) or in Canada (Shopify). Where your data reaches them, the transfer is covered by an adequacy decision (Canada), by the EU-U.S. and Swiss-U.S. Data Privacy Framework where the provider is certified, and otherwise by the European Commission's standard contractual clauses.
How long we keep your data
Requests through our forms are kept as long as needed to handle and follow them up, and no longer than 24 months after our last contact, unless a business relationship follows; the records of that relationship are then kept as long as the law requires (in Switzerland, ten years for business records).
Asset lists and renewal quotes stay on the website only until they reach our CRM, and seven days at the most. In the CRM they are deleted 24 months after the request, unless a contract follows.
Newsletter subscriptions are kept until you unsubscribe. Accounts are kept as long as they exist; when an account is deleted, only the order records the law requires us to keep remain. Google Analytics keeps event data for at most 14 months, and server logs are kept for at most 30 days.
Your rights
You can ask us for access to your data, for its correction or deletion, and for its processing to be restricted. You can object to processing based on our legitimate interest, receive the data you gave us in a portable format, and withdraw your consent at any time. Send your request to info@reverz.com; we answer within 30 days.
We do not make decisions about you based solely on automated processing.
Supervisory authority
You can lodge a complaint with a data protection authority: in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC), and in the European Union with the authority in the country where you live or work, for example the Dutch Autoriteit Persoonsgegevens or the Belgian Data Protection Authority.
Changes to this statement
We update this statement when what we do with your data changes. This version is dated 8 October 2026. The English text prevails over any translation.