Legal

Privacy Policy

Last updated: 9 September 2026

01About this policy

1.1What this policy covers

This Privacy Policy explains how we process personal data when you use the CoreFrame Advisory website, when you get in touch with us, and when we work together in an advisory mandate. The website is a set of pages to read and two forms to write to us; there is no account and no signed-in area. Most of what we know about a person, we learn in a mandate, and section 4 covers that part. Everything else in this Policy applies to it as well.

CoreFrame Advisory is a brand of Langer & Co, a Swiss company. Our processing is governed by the Swiss Federal Act on Data Protection (FADP) and supervised by the Federal Data Protection and Information Commissioner (FDPIC). Where we address people in the European Economic Area (EEA), the EU General Data Protection Regulation (GDPR) applies to them in addition. Section 6.1 sets out both frameworks in one place, so that the rest of this Policy can say plainly what we do.

1.2Who is responsible

The entity responsible for the processing described here is:

Langer & Co
Zürcherstrasse 2a
8852 Altendorf
Switzerland

Email: privacy@coreframeadvisory.com

1.3Why we process personal data

We process personal data in order to:

  • provide and secure this website
  • answer your enquiries and arrange a first conversation
  • prepare, deliver and document the advisory work you have engaged us for
  • understand how the website is used and improve it, where the privacy setting permits it
  • meet our legal and accounting obligations

1.4How this policy changes

We may revise this Policy as the website and our services change. The version published here is the one that applies, and the date it carries is the date of that version. We recommend reviewing this page from time to time.

02When you use our pages

2.1Technical data

This website is a set of prebuilt pages delivered by a content delivery network. To deliver a page, that network processes the technical data every web request carries: your IP address, the date and time, the page requested, the referrer, and your browser and operating system. It also derives the country you are visiting from, which we use for the privacy setting described in section 2.3.

We have not enabled access logging, so the delivery network keeps no record of your visits for us, and we do not combine technical data with any other source or use it to build a picture of individual visitors. The function that delivers our forms (section 3.1) writes a short technical log of each outcome, whether a message was sent or rejected, without the message, the sender or the address it came from; those entries are deleted after 30 days.

Type faces are served from our own servers, so simply displaying a page requests nothing from a third party and reveals your address to nobody.

2.2Cookies

Our privacy settings sort cookies into two categories, and this section uses the same names, so that the setting you see and what you read here are the same thing.

Essential. Three small cookies of our own, set without consent because your privacy choice cannot be honoured without them:

  • cf_consent holds your choice about statistics and the time you made it, for twelve months
  • cf_country holds the two-letter country the delivery network determined, for one day, so that the page can pick the setting described in section 2.3
  • cf_privacy_notice remembers for twelve months that a visitor in a notice-and-opt-out country has dismissed the short notice; it contains only the version of our country rules

None of them carries an identifier, nobody else reads them, and none is used for anything but the purpose named here.

Session storage. Where your visit begins with a link that names where it came from, a campaign parameter in the address or the site that linked to us, the page keeps that source and the page you arrived on in your browser's session storage, for as long as the tab is open and not longer, so that the contact form can carry it (section 3.1). It holds no identifier and is read by nothing but the form.

Statistics. Google Analytics 4, which measures how the pages are used (section 2.4). It sets the cookies _ga and _ga_ followed by the identifier of our property, each limited to twelve months from when it was first created. Whether this category needs your prior permission depends on where you are; section 2.3 explains.

We run no marketing or advertising category. We do not use cookies to build an advertising profile of you, and we pass no cookie data to advertising networks.

You manage your choice through the privacy settings on this website (section 2.3), and you can delete or block cookies in your browser at any time.

2.3Your privacy choice

Consent is asked for and recorded by privacy controls built into this website. No consent management provider is involved, and your choice is not sent to anyone: it lives in the cf_consent cookie in your browser and nowhere else.

In countries where prior permission is required, statistics stay off until you allow them. In the United States and Australia they are on unless you switch them off, and a short notice tells you so on your first visit. The country rules are a versioned allow-list: version 1 admits the notice-and-opt-out setting for the United States and Australia only. The country comes from our delivery network, which derives it from your IP address; an absent or unrecognised country always receives the stricter prior-permission setting. The country is never written into the choice itself.

You can review or change the setting at any time through "Privacy settings" in the footer of this website. Where we rely on your consent, this is how you withdraw it; where statistics are on by default, this is how you object, with immediate effect: the measurement script is removed and its cookies are deleted. If your browser sends the Global Privacy Control signal, statistics stay off regardless of your country and of any earlier choice. A new version of the country rules shows the notice again.

2.4Google Analytics 4

Where the privacy setting permits it, we use Google Analytics 4, a service of Google Ireland Limited, to understand how visitors use this website: which pages are visited and in what order, from which kind of device and browser, and where visits come from, including which campaign or platform brought a visitor here. We use it to see which pages and which campaigns work, not to build a profile of you or to show you advertising elsewhere. Google Signals, the feature that would link visits to Google accounts for advertising, is switched off.

Google Analytics 4 may process pages visited and time spent on them, clicks and interactions, device and browser information, the referring site or campaign, and an approximate location derived from your IP address. Google Analytics 4 does not log or store IP addresses. Google may process data on servers in the EU and in other countries; section 5.1 describes the safeguards.

The measurement script is loaded from Google directly, without a tag manager, and only once the setting allows it. Its browser identifiers expire no later than twelve months after they are first created and are not extended on each visit. Our property keeps user-level and event-level data for fourteen months, with reset on new activity switched off; Google's standard aggregated reports are not governed by that retention control. Turning statistics off or sending Global Privacy Control removes the script and its cookies. The privacy settings link to Google's Privacy Policy and to Google's explanation of how it uses information from sites that use its services.

Our pages may link to external platforms such as LinkedIn. These are ordinary links. They load nothing from those platforms, embed no plug-in, and transmit nothing about you until you click them. If you do, you leave our site and the external platform processes your data under its own privacy policy, over which we have no control.

03Talking to us

3.1Contact form and call requests

The contact page and the pages describing individual challenges carry a form for reaching us or requesting a first conversation. We process what you enter: your name, your email address, the topic you pick where the form offers one, and your message, together with the address of the page you sent it from, so that we know what you were looking at when you wrote. Where your visit began with a link that names where it came from (section 2.2), the message also carries that source and the page you arrived on, so that we learn which channels bring enquiries; it is used for nothing else. The form also carries a hidden field that people never see; a submission that fills it is treated as automated and is not delivered.

The submission is delivered to our mailbox by a small function of our own running at Amazon Web Services (AWS) in Frankfurt, which passes the message on as an email with your address as the reply address and keeps no copy of it. The function records only whether a message was sent or rejected (section 2.1). From there, your enquiry is handled like any other email (section 3.2).

We use what you send us to answer you and, if you ask for a call, to propose times. In preparing our reply and, where it comes to that, an offer, we may use the working tools described in section 4.3, including services with artificial intelligence, with the same safeguards. We do not add you to a mailing list, and we send no newsletters.

3.2Email, calendar and calls

Our email, calendar and video calls run on Google Workspace, a service of Google Ireland Limited, which processes that correspondence on our behalf. When we arrange a first conversation, we send you a calendar invitation carrying the time, the title and the joining details; accepting or declining it happens in your calendar. A call is not recorded unless we agree it with you beforehand.

Email you send us, and our replies, are kept for as long as the matter is open and for a limited period after (section 5.3). If the conversation turns into a mandate, the correspondence becomes part of the mandate file (section 4).

04Working with us

4.1What we learn about you

Advisory work means that you tell us about the decision in front of you, or about the area of life you want to run on a system. That can include the things that weigh most: your health, your family and relationships, your finances, your career, your plans and your doubts. Some of this is sensitive personal data in the sense of the law. We process it because the work cannot be done without it, and we process only what the work needs. You decide what you share, and you can leave anything out.

We keep working notes, the documents you give us and the material we produce for you: the diagnosis, the decision models, the systems we design, and the record of what was decided and done. This file is the substance of the mandate and the basis of anything we conclude. We process it as the party responsible for it, and we keep it in the way described in sections 4.3 and 5.3.

4.2Other people you mention

A decision rarely concerns one person alone. In describing your situation you will name others: a partner, children, an employer, colleagues, a counterparty. We record what is needed to understand your situation and nothing more, we do not contact those people, and we do not use what we hold about them for any purpose but your mandate. The law gives them the rights in section 6.2 towards us as well. We honour them as far as we can without breaking the confidence you placed in us: to anyone but you, we neither confirm nor deny that a mandate file mentions the person asking, and anything that would touch your file we do only with your agreement.

4.3Confidentiality and where your material is kept

Everything you tell us in a mandate is confidential. Within Langer & Co, your file is read by the person you work with and by nobody who does not need it for your mandate. Outside Langer & Co, it reaches only the providers that hold our systems (section 5.1), which process it on our instructions and for no purpose of their own. Anyone else, inside or outside Langer & Co, we involve only with your agreement, and we tell you beforehand who it is and what they will see. The same goes for any instrument we propose to use with you, such as a personality test: we say beforehand what it is, who runs it and what it receives.

Your material is kept in our own working files and on the devices we work on, which are encrypted. We use services with artificial intelligence as working tools, on business terms that bar the provider from training on what we submit or using it for any purpose of its own; they are among the providers in section 5.1. Before anything you told us reaches such a service, we replace names and other direct identifiers, and the key to them stays with us. If you would rather we did not use such services on your material, say so, and we will work without them on your mandate.

05Who receives your data, and for how long

5.1Service providers and where data is processed

Personal data reaches only the providers listed here, for the purpose named there:

  • Amazon Web Services EMEA SARL: hosting of the website and delivery of the forms. Storage and processing take place in the Frankfurt region (eu-central-1); pages are delivered through a worldwide network of edge locations. AWS acts as our processor under a data processing agreement including the EU Standard Contractual Clauses.
  • Google Ireland Limited: Google Workspace for email, calendar, video calls and document storage (sections 3.2 and 4.3), and Google Analytics 4 where the privacy setting permits it (section 2.4). Google acts as our processor under its data processing terms, which include the EU Standard Contractual Clauses.
  • Other IT providers that process data on our behalf, including the services with artificial intelligence described in section 4.3, with servers in Switzerland or the EU and, for individual providers, in the United States.

Some of these providers are established in, or transfer data to, other countries, in particular the United States. We disclose personal data abroad only where Swiss law permits it: to a country the Federal Council has listed as providing adequate protection, or under standard contractual clauses recognised by the FDPIC, or under the Swiss-US Data Privacy Framework where the recipient is certified. Where the same transfer is also subject to the GDPR, the corresponding EU mechanism applies alongside.

We do not sell personal data, and we do not share it with third parties for their own purposes. We disclose it to authorities only where the law obliges us to.

5.2Data security

Traffic to and from this website is encrypted in transit, and the site is delivered with strict transport security and a content security policy that limits what a page may load. The site has no server of its own to break into: it is a set of files, and the form function accepts one message at a time and holds nothing. Mandate material is held at providers with certified security controls and on encrypted devices, and it is read by nobody outside Langer & Co (section 4.3).

5.3How long we keep personal data

We keep personal data only for as long as it is needed for the purposes described here, or for as long as the law requires.

  • Form function logs: 30 days (section 2.1).
  • Your privacy choice: twelve months in your browser; the country cookie one day; the notice cookie twelve months (section 2.2).
  • Google Analytics browser identifiers: no later than twelve months after first creation. Analytics user-level and event-level data: fourteen months without reset on new activity (section 2.4).
  • Enquiries and correspondence that do not lead to a mandate: twelve months after the matter is closed.
  • Calendar entries for conversations with you, with the joining details they carry (section 3.2): twelve months after the appointment.
  • Mandate files, meaning the working notes, the documents you gave us and the material we produced for you: three years after the mandate ends, so that a decision can be revisited with its reasoning intact, or earlier at your request.
  • Offers, invoices and the correspondence that belongs to them: ten years, the retention period Swiss commercial law requires for accounting records.

When a period ends, the data is deleted or, where a record must survive for an independent reason, the person's identity is removed from it.

06Your rights and the law

Swiss law governs what we do. The FADP binds everything described above: processing must be lawful, in good faith, proportionate, recognisable to you and confined to the purpose stated when the data was collected (Art. 6 FADP). It must be protected by appropriate technical and organisational measures (Art. 8). Service providers may process data on our behalf only under contract, and only as far as we could process it ourselves (Art. 9). Data may be disclosed abroad only under the conditions of Art. 16, which is what section 5.1 describes. This Policy is the information we owe you when we collect your data (Art. 19). Sensitive personal data reaches us in a mandate because you choose to disclose it for that purpose; we process it for that purpose alone, and where the law requires your express consent to it, we ask for it in the mandate agreement. We take no decision about you by automated means. Your rights of access, data portability and correction or deletion follow from Art. 25, Art. 28 and Art. 32.

Swiss law does not require a private company to declare a legal basis for every ordinary processing operation. It requires the processing to respect the principles above, and that where it would infringe your personality it be justified by your consent, by an overriding private or public interest, or by law (Art. 30 and Art. 31 FADP).

EU law applies in addition where it reaches you. For people in the EEA the GDPR also applies, and it asks for a basis per purpose. For the processing described here these are:

  • answering your enquiry, arranging a first conversation, and preparing and delivering a mandate: performance of a contract with you, or steps taken at your request before entering into one, Art. 6(1)(b); for sensitive data in a mandate, your explicit consent, Art. 9(2)(a);
  • the technical data of delivering the website and the spam protection on our forms: our legitimate interest in a working and secure website, Art. 6(1)(f);
  • analytics and its choice record: your consent where prior permission is required, Art. 6(1)(a); in the versioned notice-and-opt-out allow-list, our legitimate interest in improving the public site, Art. 6(1)(f), subject to the immediate objection and Global Privacy Control described in section 2.3;
  • accounting and tax records: our legal obligations, Art. 6(1)(c).

Where we rely on a legitimate interest you may object, and where we rely on consent you may withdraw it at any time.

6.2Your rights

You may ask what personal data we hold about you and receive a copy, have inaccurate data corrected, ask for data to be deleted, ask us to stop a particular processing, and receive the data you gave us in a common electronic format. Where we rely on your consent, you can withdraw it at any time with effect for the future; withdrawing it does not make what happened before unlawful.

To exercise any of these, write to us as described in section 6.3. We may need to establish that the request really comes from you before we act on it. We may have to withhold something to protect another person's data or a confidence we owe. Where we do, we say so and why, as far as that is possible without revealing what we protect; whether a mandate file mentions a person who is not our client, we neither confirm nor deny (section 4.2).

If you are not satisfied with how we handle your data, you can report the matter to the FDPIC in Bern, the authority that supervises us. People in the EEA may instead approach the supervisory authority of their country of residence or workplace.

6.3Contact

For any question about this Policy or about how we handle personal data, write to privacy@coreframeadvisory.com, or use the postal address in section 1.2.