Legal

Data protection

Last updated: 9 September 2026 · This notice describes what happens to your data when you visit this website. It is deliberately short: it names only what actually takes place.

This is a translation for convenience. The German version of this notice is the binding one.

1. Controller

The controller within the meaning of the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP) is:

Digital Leadership AG
c/o Stefan F. Dieffenbacher
Hauptstraße 21a
8280 Kreuzlingen, Switzerland
Commercial register: CHE-394.760.290

Telephone: +41 (0) 44 562 42 24
Email: info@digitalleadership.com

2. For visitors from the European Union

We are established in Switzerland and also address this offering to people in the European Union. For them the GDPR therefore applies alongside Swiss law, and we treat enquiries from the EU no differently from those from Switzerland.

You exercise all the rights in section 4 directly with us — an email to info@digitalleadership.com or a letter to the address in section 1 is enough. We reply in German or English, within one month, and without your having to give a reason. There is no intermediary we will refer you to: your matter is ours to answer.

3. Data protection officer

We have not appointed a data protection officer and are not required to: monitoring the behaviour of individuals is not part of our core activity, and we do not process special categories of personal data on a large scale (Art. 37(1) GDPR).

Responsibility for data protection within our company rests with Stefan F. Dieffenbacher, CEO. Please address your enquiries to the address in section 1 or to info@digitalleadership.com; that reaches him directly.

4. Your rights

You have the following rights against us. An email to the address in section 1 is enough for all of them; we reply within one month. Exercising them is free of charge, and we do not ask you for a reason.

  • Access (Art. 15 GDPR) — which data we hold about you, where it came from, and to whom we pass it on.
  • Rectification (Art. 16 GDPR) — correct what is wrong, complete what is missing.
  • Erasure (Art. 17 GDPR) — unless a statutory retention obligation stands in the way.
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR) — your data in a common, machine-readable format.
  • Objection (Art. 21 GDPR) — against any processing we base on a legitimate interest. Section 6 says which those are.
  • Withdrawal of consent (Art. 7(3) GDPR) — at any time, and as easily as you gave it. For cookies and measurement a click on cookie settings is enough; the withdrawal takes effect immediately. It applies going forward; processing before it remains lawful.
  • Complaint to a supervisory authority (Art. 77 GDPR) — independently of any other remedy, and without having to come to us first. The choice is yours: the competent authority is the one of your habitual residence, your place of work, or the place where you believe the infringement took place (Art. 77(1) GDPR). The European Data Protection Board keeps a list of the authorities of all member states at edpb.europa.eu. In Switzerland the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, is competent.

5. What we do not do

Because it is hard to read out of a list of services, it is stated here explicitly:

  • We make no automated decisions within the meaning of Art. 22 GDPR and carry out no profiling with legal effect for you. The Capability Benchmark assessment (section 15) is a self-assessment you complete yourself, and only you receive the result.
  • We do not sell data and pass none to data brokers, list vendors or credit agencies.
  • We use no service that identifies anonymous visitors by name. One such service was in use until 09.09.2026 and has been switched off.
  • We use no captchas. Forms are protected against abuse without any third party (section 13).
  • Fonts are served entirely from our own server. There is no connection to Google Fonts or any other font service.
  • Your IP address is not stored permanently by us. Where we need it, sections 7 and 18 say so.

6. Legal bases at a glance

Every processing operation below names its basis. There are four:

  • Consent (Art. 6(1)(a) GDPR, § 25(1) German TDDDG) — measurement, advertising, embedded content, newsletter. Without your yes it does not happen.
  • Contract or steps prior to a contract (Art. 6(1)(b) GDPR) — enquiries, customer account, purchase, downloads.
  • Legitimate interest (Art. 6(1)(f) GDPR) — operating and securing the website, and the anonymous audience measurement in section 9. You may object to any of these (section 4).
  • Legal obligation (Art. 6(1)(c) GDPR) — retention of invoices and the record of your consent.

7. When you open the website

This website has two halves: the pages are served by Vercel Inc., the content is managed by an editorial system at Rocket.net. Both act for us as processors.

Every request transmits technically necessary data, which is recorded in server logs: IP address, date and time, the address requested, browser and operating system details, and the page you came from. Without these the page cannot be delivered.

Purpose: delivery, troubleshooting, defence against attacks. Basis: Art. 6(1)(f) GDPR. Recipients: Vercel Inc., Rocket.net (both USA — section 19). Retention: The logs are kept only as long as operating the site and defending it against attacks requires, and are then deleted automatically by our providers. We do not evaluate them by person and do not combine them with any other source.

The connection is encrypted with TLS throughout; you can see it from the padlock in the address bar.

8. Cookies, consent and withdrawal

On your first visit we ask what you allow. You have three equally ranked options: accept all, necessary only, or choose individually. Declining is exactly as easy as accepting and costs you no function other than the measurement itself.

Before you decide we set no cookies that would recognise you. We do not conceal what nevertheless happens in that time: the page contacts Google and Vercel and counts the visit anonymously — your IP address and browser details are transmitted, but no identifier is set that would make you recognisable across visits. Sections 9 and 10 give the detail.

We store your decision in the cookie dl_consent on your device — otherwise we would have to ask again on every visit. It holds the categories you chose, a timestamp, a random identifier, and the version of the request. Basis: Art. 6(1)(c) GDPR (the record required by Art. 7(1)). Retention: 182 days; after that we ask again. If we change the list of services, we ask again straight away.

Withdrawal: one click on cookie settings — in the footer, in this notice, anywhere. The dialogue opens with your current choice, and every change takes effect immediately.

Cookies and storage in detail

Necessary — no consent required, cannot be switched off

  • dl_consent — your consent decision, 182 days.
  • unite_session — your sign-in. Holds only an identifier and an expiry, encrypted, not readable by the browser. 8 hours.
  • unite_cart — your basket. Holds only item numbers and quantities. 30 days.
  • wordpress_logged_in_… — your sign-in to the editorial system, for the duration of the session.
  • Session storage for the intermediate state of the Capability Benchmark, so an accidental reload does not discard your answers. Discarded when you close the tab.
  • Local storage for a notice bar you dismissed — so it does not come back.

Statistics — only with your consent

  • _ga, _ga_<id> — Google Analytics, up to 2 years (section 10).

Marketing — only with your consent

  • _gcl_au — Google Ads, 90 days. test_cookie — 15 minutes (section 11).
  • Cookies set by YouTube and Calendly if you load that content (sections 12 and 14).
  • Campaign parameters from an advertising or newsletter link, so that a form you submit is attributed to the right campaign (section 11).

We maintain this list by hand, not with an automatic scanner. If you notice a cookie that is not listed here, tell us — we will look into it and correct the list.

9. Anonymous audience measurement (Vercel Web Analytics)

To know which pages are read and how quickly they load, we use Vercel Web Analytics from Vercel Inc. This measurement runs without your consent, and that is a decision we owe you a reason for:

  • It sets no cookie and writes nothing to your browser storage. There is no access to your device, so § 25 TDDDG does not apply.
  • It creates no persistent identifier. Instead a hash is formed from IP address, browser details and page identifier, and that hash changes daily. The next day you are a new visitor to this measurement.
  • Your IP address is processed but not stored — it goes into the hash and into a coarse country-level location, and is then discarded.

Collected are: page path, referring page, campaign parameters, device, browser, operating system, country, loading times. Added to that are events about your use — which button was pressed, which filter was set. These events contain no name, no email address and no user identifier. A search term you type is checked before transmission and replaced as soon as it looks like an email address, a longer sequence of digits, or anything else personal.

Purpose: to decide what to write and improve next. Basis: Art. 6(1)(f) GDPR. Recipient: Vercel Inc., USA (section 19). Retention: The hash changes daily; after that a visit can no longer be attributed to any person. What remains are aggregate figures with no personal reference. Objection: at any time by email to the address in section 1; we will switch the measurement off for you.

10. Google Analytics (only with consent)

With your consent we use Google Analytics 4 from Google Ireland Limited. It is loaded through Google Tag Manager, a tool from the same provider that serves only to administer the measurement technology and stores no data about you itself.

Collected are: page path, referring page, campaign parameters, device, browser, operating system, truncated IP address, coarse location, and the same usage events as in section 9 — likewise without names, email addresses or user identifiers. Google sets cookies in the process that make you recognisable across visits; that is precisely what we ask you about first.

If you do not consent, the measurement runs in a restricted mode: Google is told that a page was opened, together with your IP address and browser details, but sets no cookie and forms no identifier linking several visits. Advertising data is additionally redacted. We say so because “nothing happens without your consent” would not be true.

Purpose: audience measurement and improving our content. Basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG. Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; further processing by Google LLC, USA (section 19). Retention: The event data held by Google is deleted automatically after the period set in our account; it is at most 14 months. The cookies on your device expire after two years at the latest, and a withdrawal removes them straight away. Withdrawal: cookie settings.

Google Signals and the enrichment of conversions with your contact details are switched off.

11. Google Ads and remarketing (only with consent)

With your consent to the “marketing” category we use Google Ads from Google Ireland Limited. This has two effects, and the second concerns you beyond this website:

  • We learn which advertisement or campaign brought you here, and whether an enquiry came of it.
  • Remarketing: Google may show you our advertisements again on other websites and in Google services. Your browser is assigned to an audience for that purpose.

In addition we store campaign parameters from the link you arrived through in a cookie and carry them into a form you submit — so that an enquiry is attributed to the right campaign.

Basis: Art. 6(1)(a) GDPR, § 25(1) TDDDG. Recipient: Google Ireland Limited; further processing by Google LLC, USA (section 19). Retention: see the cookie lifetimes in section 8. Withdrawal: cookie settings. You can also switch off personalised advertising directly at Google under myadcenter.google.com.

12. YouTube videos (only with consent)

Some articles embed videos from YouTube, a service of Google Ireland Limited. Such a video is loaded only when you click it. Until then you see a preview image served from our own server, and there is no connection to Google — not even to fetch that image.

Under every preview image we say what the click sets off. That is deliberate: it is what makes the click a decision rather than merely a load button.

Once you start a video, Google learns your IP address, which page you are viewing and details about your device; YouTube sets its own cookies. If you are signed in to Google at the same time, Google can attribute the request to your account. We have no influence over that. The video is loaded via youtube-nocookie.com, where Google sets cookies only on playback rather than on embedding.

Basis: Art. 6(1)(a) GDPR — your click on the video is the consent. Recipient: Google Ireland Limited; Google LLC, USA (section 19). Google’s own privacy policy applies in addition.

13. Contact form and email

Through the contact form we collect your name, email address, company and your message, together with your express confirmation that we may reply. Every field except the company is needed for us to be able to answer at all.

Your message is delivered by email to the responsible mailbox; Resend Inc. handles delivery as a processor. You receive a confirmation yourself, so that you know the message arrived.

Against abuse we briefly count how many submissions come from one IP address. The IP address is held in memory only, for at most ten minutes, and is stored nowhere. The form also contains a field invisible to you that only machines fill in. We need no captcha for this.

Purpose: answering your enquiry. Basis: Art. 6(1)(b) GDPR, or Art. 6(1)(f) for a matter with no contractual context. Retention: six months after your matter is closed. If the enquiry turns into an engagement, the statutory periods for business correspondence apply instead.

14. Appointment booking (Calendly)

For arranging calls we use Calendly LLC. The calendar is loaded only once you agree: you click “Book a meeting”, we tell you in two sentences what loading means, and only your click on “Load the calendar” makes the connection. Until then Calendly learns nothing about you.

You can have that choice remembered so we do not ask again; that setting stays in your browser and never reaches us. And you do not have to agree: next to the load button there is a way to write to us — we will then arrange the appointment by hand.

If you book an appointment, Calendly processes the details you enter there — at least your name and email address, plus time zone and preferred time — as well as your IP address. Calendly sets its own cookies. Calendly’s privacy notice applies in addition.

Basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG for the loading — your click on “Load the calendar” is the consent; Art. 6(1)(b) for the booking itself. Recipient: Calendly LLC, USA (section 19).

15. Capability Benchmark, report and newsletter

The Capability Benchmark is a self-assessment of twelve questions. You can complete it entirely without giving us any data; only when you request the report do we collect your first and last name, email address, company and your role.

Double opt-in. After you submit, you receive an email with a confirmation link. Only when you click it do we produce the report and send it to you. Without your click nothing further happens, and the request deletes itself after seven days.

Processing in our customer management system. Your details are transmitted to ActiveCampaign, LLC and stored there, together with your twelve answers, the resulting score and the processing status. Until you confirm, the record is marked unconfirmed and receives no further messages.

The report text is produced by an AI model. To draft the report we transmit your first name, last name, role, company name and your twelve answers to a language model from Anthropic, which we reach through the service OpenRouter, Inc. Your email address is not transmitted. The model only produces text; it decides nothing about you, and your details are not used to train models.

Newsletter. Separately from this you may tick that you would like occasional notes on the UNITE method. That tick is voluntary and is not a condition for the report. You can unsubscribe from every message with one click; we then keep a record of your objection so that you receive no further message.

Basis: Art. 6(1)(a) GDPR for both report and newsletter. Recipients: ActiveCampaign LLC, OpenRouter Inc., Anthropic PBC, Resend Inc. (all USA — section 19). Retention: the finished report stays on our server for 30 days and is then deleted; the record in the customer management system remains until you withdraw. If you do not confirm, the record is deleted after 30 days. If you withdraw later, we delete it as well — except for the note that you no longer wish to receive messages, because without it we could write to you again.

16. Job applications

Through the forms on the role pages we collect your name, email address, your message, the role you are applying for and — if you upload it — your application documents as a file.

The documents are delivered by email to the mailbox responsible for applications; Resend Inc. handles delivery. They are made available only to the people involved in the process and are not passed to third parties.

Purpose: conducting the application process. Basis: Art. 6(1)(b) GDPR (steps prior to a contract); in Germany additionally § 26 BDSG. Retention: six months after the process closes; we then delete the documents. We keep them longer only if you expressly ask us to.

17. Customer account, purchase and downloads

Account. For a customer account we collect your first and last name, email address and a password, plus, optionally, country, industry, company size, your position and your interests. The password is stored only as a value that cannot be computed back; we do not know it. To confirm your address we send you a six-digit code.

Purchase. For an order we additionally process your billing and, where given, delivery address, the items purchased, prices, taxes and the payment status. This is managed in our own shop system.

Payment. Payment is handled by Stripe and — if you choose that route — PayPal. Your card details never reach our server: you enter them in a field supplied directly by the payment provider, and we receive only the confirmation together with a reference to the payment method. Stripe’s and PayPal’s privacy notices apply in addition.

Downloads. For each download we record which file you fetched and when. We need this because the number of downloads per month depends on your plan (one, five or twenty). Without that count we could not apply it.

Subscriptions. For a subscription we additionally process the term, the status and the charges.

Purpose: performing our contract with you. Basis: Art. 6(1)(b) GDPR; for the retention of invoices Art. 6(1)(c) together with commercial and tax law periods. Recipients: Stripe, PayPal, Rocket.net, and ActiveCampaign LLC, to which our shop system transmits customer and order data for customer care. Retention: account data until the account is deleted; invoice data for the statutory periods (ten years in Switzerland).

You can have your account deleted at any time — an email is enough. We then delete everything not covered by the retention obligation for invoices.

18. Reviews and security

Reviews. If you leave a review, we store the name or handle you choose, the text and the time, and for technical reasons your IP address. Only what you wrote yourself is published. Basis: Art. 6(1)(a) GDPR; you can have your review deleted at any time.

Protection against attacks. The editorial system is protected by Wordfence. It processes IP addresses, sign-in attempts and characteristics of detected attacks in order to block repeated attacks.

Throttling of sign-in attempts. When we count failed sign-ins, we do not store your IP address but only a hash of it, and only for 15 minutes. After a successful sign-in it is deleted immediately.

Basis: Art. 6(1)(f) GDPR — our interest in secure operation.

19. Transfers to the USA and other third countries

Several of the providers named above are established in the United States or process data there. This means US authorities may be able to access data without your knowing of it or having the same legal protection as in the EU or in Switzerland. We want to tell you that explicitly.

We transfer only on one of the following bases:

  • An adequacy decision (Art. 45 GDPR) for providers certified under the EU-US Data Privacy Framework. You can check whether a certification exists yourself at dataprivacyframework.gov.
  • Standard contractual clauses of the European Commission (Art. 46(2)(c) GDPR) with additional safeguards.
  • Your explicit consent (Art. 49(1)(a) GDPR), where a processing operation takes place only with consent in any case.

Data processing agreements under Art. 28 GDPR are in place with the providers that process personal data for us.

An overview of the recipients:

  • Vercel Inc. — serving the website, audience measurement (sections 7, 9)
  • Rocket.net — operating the editorial and shop system (sections 7, 17)
  • Google Ireland Limited / Google LLC — measurement, advertising, YouTube (sections 10, 11, 12)
  • ActiveCampaign, LLC — customer and prospect management (sections 15, 17)
  • Stripe and PayPal — payment processing (section 17)
  • Resend Inc. — delivery of our emails (sections 13, 15, 16)
  • Calendly LLC — appointment booking (section 14)
  • OpenRouter, Inc. and Anthropic PBC — drafting the report text (section 15)

20. How long we keep data

We keep personal data only as long as the purpose requires or the law prescribes. The periods are given with each processing operation above. In summary:

  • Consent decision: 182 days, then we ask again.
  • Sign-in session: 8 hours. Basket: 30 days.
  • Finished benchmark report: 30 days. Unconfirmed request: 7 days.
  • Account data: until the account is deleted.
  • Invoice data: for the statutory retention periods.
  • IP addresses for abuse prevention: 10 minutes in memory, or 15 minutes as a hash.
  • Server logs: only as long as operation and security require.
  • Google Analytics: at most 14 months.
  • Enquiries: six months after the matter closes. Applications: six months after the process closes.
  • Unconfirmed newsletter records: 30 days.

21. Changes to this notice

If what we process changes, we change this notice. The version published here applies in each case; the date is at the top. If a change affects processing you consented to, we ask you again rather than relying on the old consent.

The German version is the binding one. This English text is a translation; you can read the German original.

22. Questions

If there is something you want to know that is not written here, write to info@digitalleadership.com. If you notice a cookie or a transfer that does not appear in this notice, tell us — we will look into it and correct the text.

The Strategy-to-Outcome Platform

Talk to us.

The first meeting is a working session, not a pitch.

The calendar is provided by Calendly. Loading it gives Calendly your IP address, sets cookies, and shares the details you enter. More on this

Write to us instead