Privacy Policy

This website is operated in accordance with the revised Swiss Federal Act on Data Protection (revFADP) and, in addition, the EU General Data Protection Regulation (GDPR). Website analytics is enabled only after explicit consent; all data is stored in Europe.

1. Controller

Controller within the meaning of Art. 5 lit. j revFADP and Art. 4 No. 7 GDPR:

Beat W. Meier Switzerland Email:

Technical operation of the website is carried out by Praxis Olga Meier GmbH, Switzerland, on behalf of the controller. A data-processing agreement under Art. 9 revFADP is in place.

2. Scope

This privacy policy describes how personal data is processed when visiting beat-w-meier.ch and all language versions (/, /en/). It does not apply to linked third-party services.

3. Principles of Data Processing

Personal data is processed exclusively in good faith, for specified purposes, in a proportionate manner and for as short a time as possible. Only data necessary for operating the website or for the relevant function (e.g. contact form, newsletter, optional analytics) is collected. No disclosure to third parties for advertising purposes takes place.

4. Server Log Files

When a page is loaded, technically necessary information is processed by the web server (Nginx) to deliver the page and to mitigate attacks:

  • truncated IP address (the last two octets are removed before storage)
  • date and time of the request
  • requested URL and HTTP status code
  • amount of data transferred
  • browser type, operating system and language (user agent)
  • referrer (if transmitted by the browser)

This log data is kept for a maximum of 14 days and is used exclusively for ensuring operation, error analysis and abuse prevention. No combination with other data sources takes place.

Legal basis: Art. 31 para. 1 and para. 2 lit. d revFADP (legitimate interest in secure operation); additionally Art. 6 (1) (f) GDPR.

5. Cookies and Comparable Technologies

This website uses only the storage mechanisms required for operation, and — after explicit consent — cookies for anonymised audience measurement. There is no tracking across sessions or websites.

Cookie / StoragePurposeCategoryRetention
cookie_consent (localStorage)Stores the consent decision for audience measurementstrictly necessarypersistent (until manually reset)
_pk_id.*, _pk_ses.*Statistics cookies of the self-hosted Matomo instance — only set after consentanalytics (consent)13 months / 30 min
social_token (sessionStorage)Session token of the social-publish tool — only inside the internal admin area (VPN), never set for public visitorsstrictly necessary (internal)session
bwm-podcast-pos-* (localStorage)Remembers your last listening position per podcast episode so you can resume seamlesslystrictly necessarypersistent (until manually cleared)

Cookies can be deleted or blocked at any time via the browser settings. Once given, consent can be withdrawn at any time via the cookie notice at the bottom of the page — the banner reappears as soon as the storage decision has been removed in the browser.

6. Audience Measurement (only after consent)

To improve the offering, self-hosted, privacy-friendly analytics software (Matomo, open source) is used. Data collection takes place only after explicit consent via the consent banner.

If analytics is enabled, the following anonymised usage data is collected:

  • pages visited and time spent
  • approximate region (country / city); the location lookup happens transiently on the full IP address at the moment of the page request — only the truncated IP is ever stored
  • device class, screen resolution and browser
  • referring website (referrer)

Safeguards:

  • the IP address is truncated by the last octet before storage — no direct identification of a person is possible
  • data is processed exclusively on our own server in Europe (see Section 9)
  • there is no disclosure to third parties, no profiling, no automated individual decision-making
  • individual records are deleted no later than 180 days; only anonymous aggregates may be kept longer
  • the software is self-hosted; there are no contractual relationships with third-party analytics providers
  • the reporting-API token never leaves the internal network

Legal basis: consent under Art. 6 para. 6 revFADP; additionally Art. 6 (1) (a) GDPR.

7. Embedded External Content (Click-to-Embed)

Video and audio content from YouTube/Google, Vimeo, Spotify or Apple Podcasts is not loaded automatically on individual blog pages. You initially see only a preview image hosted on our server. The content is loaded from the respective provider only after an explicit click — and only at that moment do these providers receive your IP address and may set their own cookies.

The platforms listed above may disclose data to countries outside Switzerland and the EU (in particular the USA). With the click-based consent you accept this disclosure under Art. 17 para. 1 lit. a revFADP. Privacy notices of the providers:

7.1 Podcast Player

The page /podcast/ presents the podcast «Billions in the Fog» using our own player. All content — episode information, cover images and audio files — is delivered exclusively via this website itself (beat-w-meier.ch, servers in Europe). Your browser never contacts a third-party domain; no third-party cookies are set. When you play an episode, playback is counted anonymously on the server side. No advertising tracking takes place.

8. Contact and Newsletter

8.1 Contact Form

If you use the contact form, the data you submit (name, email address, message content) is forwarded to us by email solely for the purpose of answering your enquiry. No database storage of the content takes place. The data is deleted once the matter is concluded, at the latest after 24 months, provided no statutory retention obligations apply.

Legal basis: Art. 31 para. 1 revFADP (legitimate interest), for contract initiation Art. 31 para. 2 lit. a revFADP; additionally Art. 6 (1) (f) GDPR.

8.2 Newsletter

If you sign up for the newsletter, we store your email address, the chosen language and your notification preferences (book / blog) in a protected database. Sign-up uses the double-opt-in procedure: you receive a confirmation email with a verification link, and only after clicking it are you actually added to the mailing list.

Every newsletter email contains a personal unsubscribe link at the bottom. Clicking it permanently removes your address from the mailing list (soft-delete for 14 days, then physical deletion).

Legal basis: your consent under Art. 6 para. 6 revFADP; additionally Art. 6 (1) (a) GDPR.

9. Hosting and Processing

The website is operated on a server at Hetzner Online GmbH (location: Germany). A data-processing agreement under Art. 9 revFADP and Art. 28 GDPR is in place with the hosting provider. Hetzner offers a data-protection level that is recognised as adequate under Annex 1 of the Swiss Data Protection Ordinance (DPO).

No special categories of personal data of third parties are processed on this website.

10. Disclosure to Other Countries

Personal data is disclosed abroad only in the following cases:

  • on active consent to external embeds (Section 7) to the respective platforms
  • for technically necessary services within the EU/EEA, provided an adequate level of data protection under Annex 1 DPO is given
  • when sending transactional emails (verification, unsubscribe) via the email provider Hostpoint AG (Switzerland)

Transfers to third countries without an adequate level of protection take place only if the requirements of Art. 16 or Art. 17 revFADP are met.

11. Data Security

Appropriate technical and organisational measures under Art. 8 revFADP are taken:

  • transport encryption (TLS 1.3) for all requests (HTTPS)
  • regular security updates of the server and the software in use
  • restrictive access rights and two-factor authentication for administrators
  • encrypted backups of configuration and content
  • separation of public and administrative access (VPN for all admin functions such as editor, newsletter management and statistics view)
  • Web Application Firewall (CrowdSec) and rate-limiting against brute-force and DDoS attacks
  • automatic detection of suspicious login attempts

12. Retention Period (overview)

Data categoryRetention
Server log files (truncated)max. 14 days
Consent decision in the browser (cookie_consent)until manually reset
Matomo statistics raw data (after consent)max. 180 days
Matomo aggregates (anonymous)indefinite
Contact enquiries (via email to the controller)until conclusion, max. 24 months
Newsletter subscriptionuntil unsubscribed; then soft-delete 14 days, then physical deletion

13. Your Rights as a Data Subject

Under the revFADP and additionally the GDPR you have, in particular, the following rights:

  • access to the data processed (Art. 25 revFADP / Art. 15 GDPR)
  • rectification of inaccurate data (Art. 32 para. 1 revFADP / Art. 16 GDPR)
  • erasure or blocking (Art. 32 para. 2 revFADP / Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • objection to processing based on legitimate interests (Art. 21 GDPR)
  • withdrawal of consent with effect for the future (Art. 6 para. 7 revFADP / Art. 7 (3) GDPR)
  • data portability in a common electronic format (Art. 28 revFADP / Art. 20 GDPR)
  • complaint to the competent supervisory authority

To exercise these rights please contact the address given under Section 1: . For security reasons, proof of identity may be requested.

14. Supervisory Authority

Switzerland: Federal Data Protection and Information Commissioner (FDPIC) Feldeggweg 1, 3003 Bern https://www.edoeb.admin.ch

Data subjects in the EU/EEA may additionally turn to the data protection authority in their respective country.

15. Automated Individual Decision-making and Profiling

There is no high-risk profiling and no automated individual decision-making within the meaning of Art. 21 revFADP or Art. 22 GDPR.

16. Changes to This Policy

This privacy policy may be amended to reflect changes in legal or technical conditions. The version published on this page is the authoritative one.

17. Disclaimer

17.1 Liability for Content

The content of this website is created with the greatest possible care. However, the controller assumes no liability whatsoever for the timeliness, correctness, completeness, quality, availability or suitability of the information provided for a specific purpose. All content represents only general information and does not replace individual professional, legal, medical or other advice.

Use of the website is at the user's own risk. Liability claims against the controller arising from the use or non-use of the information provided or from the use of incorrect or incomplete information are excluded in principle.

The controller expressly reserves the right to change, supplement or delete parts of the pages or the entire offering without separate notice, or to discontinue publication temporarily or permanently.

17.2 Liability for Links

References and links to third-party websites lie outside the controller's area of responsibility. Liability for the content of such websites is fully rejected. Access to and use of such websites is at the user's own risk. At the time of linking, the external content was checked for possible civil or criminal liability. Permanent content monitoring of linked pages is not reasonable without concrete evidence of a legal violation.

17.3 Liability for Data Transmission

Data transmission via the internet (e.g. communication by email or contact form) may, despite transport encryption (TLS), exhibit security gaps. Complete protection from third-party access is not possible. The controller assumes no liability for damages arising from unauthorised third-party access to transmitted data.

17.4 Copyright

All content published on this website (in particular texts, book excerpts, images, graphics, audio and video files and their arrangement) is protected by copyright. Any reproduction, modification, distribution or exploitation — including in part — is not permitted without the express written consent of the controller or the respective rights holders. Excerpts from third-party works are used under the Swiss copyright quotation rule (Art. 25 URG) with attribution.

Downloads and copies of this site are permitted only for private, non-commercial use.

17.5 Trademarks and Personality Rights

All trademarks, names and other distinguishing marks mentioned within the website and possibly protected by third parties are fully subject to the provisions of the applicable trademark law and the ownership rights of the respective registered owners. The mere mention of a trademark does not warrant the conclusion that it is not protected by third-party rights.

18. Severability Clause

Should individual provisions or wording in this privacy policy and disclaimer not, no longer or not fully comply with the applicable legal situation, the remaining parts shall remain unaffected in their content and validity. In place of an invalid or missing provision, the legally permissible regulation that comes economically closest to what was originally intended shall apply.

19. Applicable Law and Place of Jurisdiction

The use of this website and all legal relationships between the controller and users shall be governed exclusively by Swiss law, excluding conflict-of-law rules and excluding the United Nations Convention on Contracts for the International Sale of Goods (CISG).

The exclusive place of jurisdiction for all disputes arising from or in connection with the use of this website is Zug, Switzerland, unless mandatory statutory provisions provide for a different place of jurisdiction. The controller is also entitled to sue the user at the user's general place of jurisdiction.


Last updated: May 2026

New book, new blog post? Be the first to know!

Sign up and get notified when a new book, blog post or podcast episode is published.

Notify me about

Privacy Policy | Beat W. Meier