Privacy
Policy
Information about the protection of your personal data
Data Controller
Responsible party under Swiss DSG and GDPR
Ritter Bildungs- und Digitalberatung
Owner: Lars Ritter, Studienflüsterer project
J. Schmidheinystrasse 24, CH-9436 Balgach, Switzerland
beratung(at)ritterconsult.ch
Our Privacy Principles
Transparency and protection of your privacy
Full Transparency
We openly inform you about all data collection and tracking measures on this website.
Data Minimization
We only collect data necessary for our service and website optimization.
Your Control
You have the right to access, delete, and object to the processing of your data at any time.
Cookies and Tracking
Which cookies are active, and how you control them
Currently set cookies
| Cookie name | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
| cc_cookie | This website | Stores your consent to cookie categories | 6 months | Necessary |
| tidycal_* | TidyCal Inc. | Appointment booking embed (loads only after consent) | Session | Marketing |
| sendfox_* | SendFox | Newsletter sign-up forms (load only after consent) | Session up to 12 months | Marketing |
| _fbp | Meta Platforms Ireland Ltd. | Meta Pixel, recognition for advertising and reach analysis (loads only after consent) | 3 months | Marketing |
| _fbc | Meta Platforms Ireland Ltd. | Meta Pixel, stores the click identifier if you arrive via a Meta ad (loads only after consent) | 3 months | Marketing |
Note: General reach is measured with Cloudflare Web Analytics, which works without cookies (details below). Google Analytics, Plausible and Matomo are not active, and neither is any advertising tag such as Google Ads. The Meta Pixel has been embedded since 16.08.2026, but it loads only after your consent to the marketing category (details below). The same applies to the marketing embeds (TidyCal appointment booking, SendFox newsletter forms). Hero videos are served directly from this domain, no third party. If further services are added in the future, they will only be activated based on your explicit consent via the cookie banner (Art. 6(1)(a) GDPR or Art. 31(1) revFADP). This privacy policy will be updated before activation.
You can change or revoke your cookie consent at any time via the link in the footer.
TidyCal (appointment booking)
Provider:
TidyCal Inc., AppSumo Inc., 1108 Lavaca St STE 110-489, Austin, TX 78701, USA
Purpose:
Online appointment booking for consulting sessions. The TidyCal embed on /en/book-appointment/ only loads if you have consented to the marketing cookie category. Without consent, you only see a placeholder with a notice and can book via the contact page instead.
Data transfer to third countries:
TidyCal processes data in the USA. There is a risk that US authorities may access this data. Privacy policy: tidycal.com/privacy-policy.
Legal basis:
Art. 6(1)(a) GDPR (consent) or Art. 31(1) revFADP (Swiss law).
SendFox (newsletter)
Provider:
SendFox, AppSumo Inc., 1108 Lavaca St STE 110-489, Austin, TX 78701, USA
Purpose:
Sending the newsletter and processing sign-up forms. On the newsletter page, your input (first name, email) is not sent directly to SendFox but to our own server function (Cloudflare Pages), where it is first checked against automated spam sign-ups using Cloudflare Turnstile and only then forwarded to SendFox. Your browser establishes no connection to SendFox on this page. In the 10-Minute Check, the Credit Check, the homepage footer, and for the webinar sign-up on the webinar page (separate webinar list), the SendFox JavaScript still loads only after consent to the marketing category. Without consent, a placeholder with a hint to the cookie settings is shown there.
Bot protection (Cloudflare Turnstile):
On the newsletter page, the sign-up form is protected by Cloudflare Turnstile, a service of Cloudflare, Inc. (USA). Turnstile serves solely to prevent automated spam sign-ups, activates when the form loads, and sets no cookies for advertising or reach-measurement purposes. Legal basis: Art. 6(1)(f) GDPR or Art. 31(1) revFADP (legitimate interest in spam prevention). More information: cloudflare.com/privacypolicy.
Third-country transfer:
SendFox is a US provider and processes data in the USA. There is a risk that US authorities can access this data. Privacy policy: sendfox.com/privacy.
Legal basis:
Art. 6(1)(a) GDPR (consent) / Art. 31(1) revFADP. Newsletter delivery additionally Art. 6(1)(a) GDPR (consent during sign-up, double-opt-in).
Zoom (webinars)
Provider:
Zoom Communications, Inc., 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. For users in the EEA and Switzerland, processing is carried out in accordance with the Zoom privacy policy.
Purpose:
Running the live webinars. If you sign up via the webinar page, you receive the Zoom join link by email. When you take part, Zoom processes the data involved (for example name, where applicable audio and video, email address, IP address, and device and connection data). No Zoom script is embedded on this website; you join exclusively via the link sent by email.
Third-country transfer:
Zoom is a US provider and also processes data in the USA. There is a risk that US authorities may access this data. Privacy policy: zoom.com/en/trust/privacy.
Legal basis:
Art. 6(1)(a) GDPR (consent given with the webinar sign-up) / Art. 31(1) revFADP. Sign-up to the webinar list runs via SendFox using a double-opt-in procedure.
Meta Pixel (Facebook and Instagram)
Provider:
Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Parent company: Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.
Purpose:
Measuring advertising on Facebook and Instagram. The Meta Pixel records which pages of this website are visited after a click on an ad, and makes it possible to show ads again to visitors of this website at a later point (remarketing) and to build similar audiences. On every page view an event is transmitted to Meta together with your IP address, information about your browser and device, and the address you accessed. The cookies set are _fbp and, if you arrive via an ad, _fbc.
Additional “Lead” event:
If you successfully submit the form in the Credit Check, a “Lead” event is reported to Meta in addition to the page view. This makes it possible to evaluate which ad led to an enquiry. Only the fact that such an event took place is transmitted, together with the information listed above. The content of the form, meaning your first name and email address, is not transmitted to Meta, not even in encrypted form. The event is triggered only if the submission was actually successful, and only if you have previously consented to the marketing category.
Only after consent:
The pixel is present in the page source but is executed by your browser only after you have consented to the marketing category in the cookie banner. As long as you do not, no connection to Meta is established, no cookies are set and no data is transmitted. If you revoke your consent via the , _fbp and _fbc are deleted and the pixel no longer loads on further page views. A counting pixel for visitors without JavaScript is deliberately omitted, because it could not technically be made dependent on consent.
Joint controllership and transfer to third countries:
For the collection and transmission of data by the pixel, joint controllership under Art. 26 GDPR exists between me and Meta Platforms Ireland. Any further processing by Meta is Meta's sole responsibility. Meta also processes data in the USA. There is a risk that US authorities may access this data. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework, and the EU Standard Contractual Clauses apply in addition. Privacy policy: facebook.com/privacy/policy. Information on the pixel: facebook.com/business/help. You can adjust your ad settings at Meta at facebook.com/settings.
Legal basis:
Art. 6(1)(a) GDPR (consent) / Art. 31(1) revFADP. Consent is voluntary and can be revoked at any time with effect for the future.
Reach measurement and advertising
Cookieless reach measurement:
Reach is measured with Cloudflare Web Analytics, a service provided by Cloudflare, Inc. (USA), which also delivers this website. Only aggregated information is collected, such as pages viewed, referring website, approximate region of origin, device type and loading times. Cloudflare Web Analytics sets no cookies, stores nothing on your device and does not build user profiles across websites. Conclusions about individual persons are therefore not possible. Legal basis: legitimate interest in privacy-friendly reach measurement (Art. 6(1)(f) GDPR, Art. 31(1) revFADP). Further information: cloudflare.com/privacypolicy. Beyond that, there is no Google Analytics, no Plausible, no Matomo and no comparable service. There is also no Google Ads conversion tracking.
Advertising:
To measure advertising on Facebook and Instagram, the Meta Pixel has been embedded since 16.08.2026. It loads only after your consent to the marketing category, and only then sets cookies and transmits data to Meta. The details are in the section “Meta Pixel (Facebook and Instagram)” above.
What is used for search visibility:
Search visibility is monitored exclusively via Google Search Console and Bing Webmaster Tools. Both only evaluate what search engines already know through their own systems (for example, how often a search result was shown and clicked). No code runs on this website for this purpose, and no visitor data is collected.
Data Processing When Contacting Us
When and what data we process
When do we process data?
Data processing only occurs when you actively contact us or use our services:
Email: beratung(at)studienfluesterer.com
WhatsApp message
LinkedIn message
Appointment booking (TidyCal)
Newsletter signup (SendFox)
Partnership inquiry (Formrobin)
What data do we process?
Processed Data:
Name, email address, phone number (if provided), message content
Legal Basis:
Art. 6(1)(a) GDPR (consent) or Art. 6(1)(b) GDPR (pre-contractual measures); for Swiss users additionally Art. 31 revFADP
Purpose:
Processing your inquiry and communication within the scope of study consulting
Email marketing to existing customers
Tips and guidance after a booking or mandate
What this means
If you book an appointment (e.g. via the online appointment booking) or start a consulting mandate, the Ritter Bildungs- und Digitalberatung is entitled under § 7 para. 3 UWG (Germany), § 107 para. 3 TKG (Austria) and Art. 3 lit. o UWG (Switzerland) to send you emails with tips and guidance on studies, credit transfer and career, even without a separate newsletter consent.
Conditions: It must concern its own similar services, you must have been informed at the time of first contact and reminded in every follow-up email, and you must not have objected. This practice is well-established and transparently regulated across the DACH region.
Your right to object: You may object to email marketing at any time, informally. Clicking the unsubscribe link in any email is sufficient. No costs arise apart from base-rate transmission costs.
Further Privacy Details
Storage, security, and external services
Data Storage and Deletion
Your data is not permanently stored. After processing your inquiry and completing communication, data is deleted unless statutory retention periods apply.
Disclosure to Third Parties
Your personal data is not disclosed to third parties, except to fulfill legal obligations.
Hosting and Server Log Files
This website is operated on Cloudflare Pages, a service of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Content is delivered via a global server network, which involves transferring data to the USA. Cloudflare is certified under the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework, and the EU Standard Contractual Clauses apply in addition. When the website is accessed, information is automatically collected and stored in so-called server log files:
- Anonymised IP address
- Date and time of access
- File requested and volume of data transferred
- Notification of successful retrieval
- Browser and operating system used (user agent)
- Referrer URL (the previously visited page)
This data is evaluated exclusively to ensure trouble-free operation and to defend against attacks, and it is not merged with other data sources. Legal basis: Art. 31(1) revFADP or Art. 6(1)(f) GDPR (legitimate interest). The data is deleted after a maximum of 30 days.
External Services and Third-Party Providers
This website uses the following external services. Their respective privacy policies apply when you use them:
Communication Tools
Note: These services are only activated when you use the corresponding functions (e.g. submitting a form, booking an appointment, subscribing to the newsletter). Simply viewing the website does not transmit data to these services.
SSL Encryption
This website uses SSL encryption for security purposes and to protect the transmission of confidential content.
Your Rights
Your rights under Swiss DSG and GDPR
You have the following rights regarding your personal data. EU users may invoke the GDPR; Swiss users may additionally invoke the revFADP (revised Federal Act on Data Protection):
Contact to exercise your rights: beratung(at)ritterconsult.ch
Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC): edoeb.admin.ch. Persons resident in the EU may also contact the competent national data protection authority.