Elchi Studios is a brand of Krauss Software, the sole proprietorship of Samuel Krauss, Oberägeri ZG, Switzerland. The counterparty is Krauss Software, owned by Samuel Krauss.
Elchi Studios | Krauss Software, Samuel Krauss | legal@elchi.dev
1. Definitions and Scope
This Privacy Policy applies to the websites https://elchi.dev, https://websites.elchi.dev, https://legal.elchi.dev, https://docs.elchi.dev, https://devs.elchi.dev and https://status.elchi.dev, and to the enquiries and support messages you send us. What we store for your own Elchi account at EAuth and in the Console, for how long and how to delete it, is set out at https://legal.elchi.dev/en/your-data; for that we are the controller. The data of the users of our customers' applications and the mailboxes at EMX we process as a processor for our customers; the EAuth and EMX terms, with their data processing agreements, apply to that.
The terms used are based on the Swiss Federal Act on Data Protection (FADP, revised version, in force since 1 September 2023) and, where applicable, the EU General Data Protection Regulation (GDPR). The GDPR applies when services are offered to individuals residing in the EU.
Definitions:
- Personal Data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation performed on personal data, regardless of the means applied.
- Controller: The natural or legal person who determines the purposes and means of data processing.
- Hosting Provider: External providers from which we rent servers and storage to operate the website (Section 4).
- Processor: Third parties processing personal data on behalf of the controller.
2. Controller
Krauss Software, owned by Samuel Krauss (brand Elchi Studios)
Im Ländli 18
6315 Oberägeri
Switzerland
Email: legal@elchi.dev
3. Data We Process
3.1 Technical Access Data (Automatic)
When you visit our websites, our servers automatically collect the following technical data:
- IP address (anonymised after processing)
- Date and time of access
- URL / page accessed
- HTTP status code
- Data volume transferred
- Referrer URL
- Browser type and version
- Operating system
- Device category
Purpose: Ensuring technical operation, error detection, abuse prevention.
Legal basis (FADP): Art. 6 FADP (legitimate interest) | GDPR: Art. 6(1)(f) GDPR.
Retention: Technical logs are deleted or anonymised after a maximum of 90 days.
3.2 No Usage Analytics
Our websites use no analytics system. There are no cookies for tracking purposes, no third-party analytics services such as Google Analytics, and no analysis of your usage beyond the technical access data in section 3.1.
The cookie-free visitor statistics we offer our clients are built for their website as part of the respective contract. Should we later use such statistics on elchi.dev as well, we will update this notice beforehand.
3.3 Contact Enquiries
When you contact us by email or via the contact form, we process:
- Name and email address
- Company, phone number and budget, if you provide them
- Your choices in the configurator, if the enquiry comes from there
- Content of the message
- Language and the page from which you send the enquiry
- The country the enquiry comes from, derived from the IP address; the IP address itself is not stored with the enquiry
- Time of contact
We are notified of an enquiry from the contact form by email; for this and for replies to it we use Resend (section 4.2).
Purpose: Processing your enquiry, initiating a business relationship.
Legal basis (FADP): Art. 6 FADP | GDPR: Art. 6(1)(b) GDPR (pre-contractual measures).
Retention: 12 months after it was last handled; then our servers delete the enquiry by themselves. If a contract comes of the enquiry, it becomes part of the business records and is kept for 10 years after it was last handled (Art. 958f CO), then it is deleted too.
Deletion: Enter your address at https://legal.elchi.dev/en/your-data; once you confirm through the link we send you, we delete your enquiries at once, except those a contract came of.
3.4 Support Messages
When you write to us through support in the Console, we process your address, your name and the course of the messages. You also receive support's replies by email.
Purpose: Answering your question.
Legal basis (FADP): Art. 6 FADP | GDPR: Art. 6(1)(b) GDPR for customers, to perform the contract, otherwise Art. 6(1)(f) GDPR.
Retention: 24 months after the matter is resolved; then our servers delete the messages by themselves. They also go with your account, and before that you delete them as you would an enquiry (section 3.3).
3.5 Deletion Requests
When you ask for deletion at https://legal.elchi.dev/en/your-data and we hold something for your address, we record the request: your address, the language, a one-way checksum of the confirmation link (not the link itself), when it was made, until when the link is valid, when it was used and how many entries were deleted. The link is valid for 24 hours and once. Our servers delete the request itself 7 days after it was used or expired. The page does not reveal whether we hold anything for an address.
Purpose: Proof that the deletion was asked for by the holder of the address.
Legal basis (FADP): Art. 6 FADP | GDPR: Art. 6(1)(c) GDPR (Art. 17 GDPR).
3.6 Client Data in the Context of Commissions (B2B)
In the course of service contracts (software, websites, hosting), we process data from contact persons at companies:
- Contact details of the respective contact persons
- Communication relating to contract execution
- Technical access data (e.g. server credentials, stored exclusively in encrypted form)
This data is used exclusively for the fulfilment of the contract and is not processed for any other purpose.
4. Hosting, Recipients and Disclosure Abroad
4.1 Servers and Hosting Providers
Since 3 October 2026 we operate our websites and the client projects we host on our own servers, which we rent from the following hosting providers; ClouDNS answers the DNS queries for our domains:
| Provider | Role | Country (location) |
|---|---|---|
| Infomaniak Network SA | Servers, object storage for pictures | Switzerland (Geneva) |
| Hetzner Online GmbH | Servers, copy of the database | Germany (Falkenstein, Nuremberg) |
| Tavuru | Server of the primary database | Germany (Frankfurt) |
| UpCloud Oy | Servers | Netherlands (Amsterdam) |
| Scaleway SAS | Servers, copy of the database, nightly copy of the pictures | Netherlands (Amsterdam), France (Paris) |
| ClouDNS Ltd. | DNS queries for our domains; sees DNS queries only, no content | Bulgaria (Sofia) |
These providers process personal data only on our behalf. They are carefully selected and, where they process personal data, contractually obligated to comply with data protection law (Data Processing Agreement / DPA).
Where a client project is hosted with another provider at the client's request, the respective contract names that provider. Where that provider is outside Switzerland or the EEA, an adequate level of protection is ensured (e.g. through EU Standard Contractual Clauses).
4.2 Sending Email
Notifications of enquiries from the contact form, support's replies (section 3.4) and the links that confirm a deletion (section 3.5) are sent through Resend, Inc., a company based in the USA. Resend sends these emails from its region in the EU, but stores their data (sender, recipient, subject and content, and with it the details of your enquiry or support message) in the USA.
4.3 DNS
Cloudflare, Inc. (USA) holds the DNS zones of our domains and receives no content of your requests to the website. ClouDNS answers the DNS queries on our behalf (section 4.1), likewise without receiving the content of your requests. Name lookups usually reach ClouDNS from your DNS resolver, not from your device.
4.4 Disclosure Abroad
Personal data is disclosed to the following countries:
- Germany, Netherlands, France, Bulgaria (providers under section 4.1): Under Annex 1 of the Swiss Data Protection Ordinance (DPO), these countries ensure an adequate level of data protection (Art. 16 para. 1 FADP). For data subject to the GDPR, these countries belong to the EEA, and an adequacy decision of the European Commission exists for Switzerland (Art. 45 GDPR).
- USA (Resend under section 4.2): For data from Switzerland, disclosure to Resend is based on the European Commission's Standard Contractual Clauses with the adaptations required by Swiss law, which form part of Resend's data processing agreement (Art. 16 para. 2 let. d FADP). For data subject to the GDPR, Resend is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR); the same Standard Contractual Clauses apply in addition (Art. 46(2)(c) GDPR).
You can request a copy of the Standard Contractual Clauses at legal@elchi.dev.
5. Disclosure to Third Parties
Personal data is not sold or rented to third parties. Disclosure occurs only:
- to the providers named in Section 4 as processors
- to comply with legal obligations (e.g. on official orders)
- with the explicit consent of the data subject
Important note for clients: Where third-party services (e.g. payment providers, external APIs, social media plugins) are used in the context of a client project, the privacy policies of those third parties apply. In such cases, Elchi Studios acts solely as a technical service provider and assumes no responsibility for the data protection practices of third-party services chosen by the client.
6. Your Rights
6.1 Rights under the Swiss FADP
You have the right to:
- Access (Art. 25 FADP): Information about data processed about you
- Rectification (Art. 32 FADP): Have inaccurate data corrected
- Erasure (Art. 32 FADP): Have data deleted under certain conditions
- Restriction of processing (Art. 32 FADP)
- Data portability (Art. 28 FADP)
- Object to certain types of processing
6.2 Additional Rights under the GDPR (for persons residing in the EU)
In addition to the above:
- Right to object to processing based on legitimate interests (Art. 21 GDPR)
- Right to lodge a complaint with a data protection supervisory authority in your EU member state
6.3 Exercising Your Rights
What we store about you, for how long, and how to export and delete it, is set out for every product at https://legal.elchi.dev/en/your-data. You delete your enquiries and support messages there yourself. With an Elchi account, you delete it on your account page, and with it, after 30 days, everything that is only the account's. What is deleted also leaves the backups, within 60 days at the latest.
For anything else, please contact: legal@elchi.dev
We will respond to your request within 30 days. In complex cases, this period may be extended to 90 days; we will inform you in advance if this is necessary.
7. Data Security
Elchi Studios implements appropriate technical and organisational measures to protect your data, in particular:
- Encrypted data transmission via HTTPS (TLS)
- Encrypted storage of sensitive access credentials
- Access controls and access logs
- Regular security updates of systems in use
8. Cookies
Elchi Studios does not use tracking cookies or third-party advertising cookies on its websites. Where technically necessary cookies are used (e.g. for session management), this is done on the basis of Art. 6(1)(f) GDPR / Art. 6 FADP (legitimate interest in operating the website).
When you choose a language, a colour scheme or whether anything on the page may move, we store your choice in a cookie so the next page knows it, for a year at most; it contains nothing but that choice.
No cookie consent is required for strictly necessary cookies.
9. External Links
This website may contain links to third-party websites. This Privacy Policy does not apply to those external websites. We recommend reading the privacy policies of any external websites you visit.
10. Changes to this Privacy Policy
Elchi Studios reserves the right to update this Privacy Policy at any time, in particular in response to changes in the legal framework or technologies used. The version in effect and every earlier one are available at https://legal.elchi.dev/en/privacy, each with the day it applied from.
11. Supervisory Authorities
Switzerland: Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1, 3003 Bern | www.edoeb.admin.ch
EU (for complaints by EU residents): Competent data protection authority in the respective EU member state.
Last updated: 9 October 2026 | Version 1.6