Oprivia privacy policy
This Privacy Policy explains how Brander Consulting, operating under the Oprivia brand, processes personal data in connection with the public Oprivia website, contact and pilot forms and the web services used on the site.
Separate, versioned privacy information and, where applicable, a data processing agreement apply to the protected Oprivia platform, user accounts and activated identity, KYC, KYB, service, partner and governance functions.
Last updated: July 2026
Contents at a glance
Select the section for which you need further information.
Responsibility and scope
The controller responsible for processing personal data in connection with this website is:
Brander Consulting, operating under the Oprivia brand
Mellingerstrasse 1a
5608 Stetten
Switzerland
Email: info@oprivia.com
The complete legal information is available in the Legal Notice.
This Privacy Policy applies to the public Oprivia website and to the contact and pilot forms provided on it. Additional privacy information may apply to the protected platform, user accounts or future productive functions.
Data and purposes
The submission of a contact or pilot form serves to handle your inquiry and to prepare possible pre-contractual steps. This Privacy Notice informs you about the related processing of personal data. Consent is obtained only where it is required for an additional and separate processing activity.
Cookies and maps
The website uses technically necessary cookies and comparable technologies where they are required for the operation and security of the website. Optional services are used in accordance with the choices made in the cookie settings. Your selection may be stored so that it can be documented and taken into account during later visits.
Google Maps is embedded on the contact page. When the map is loaded or used, your IP address, browser and device information and interaction data may be transmitted to Google. Further information and your choices are available in the cookie settings.
Service providers and recipients
Oprivia uses carefully selected service providers to operate the website, process inquiries and provide digital communication functions. These include, in particular, providers of website hosting and forms, email communication, consent management, IT security, mapping services and the digital assistant.
The services currently used include Webflow for providing the website and processing form submissions, Cookiebot by Usercentrics for consent management, and Google Maps for displaying maps. Form submissions may also be transmitted to the responsible recipients through the configured email services.
For the digital assistant “Nico”, Oprivia uses the Boei service provided by Ruby Foundry B.V., Mulderstraat 35, 3581 GP Utrecht, the Netherlands. When the assistant is used, the data processed may include chat messages entered by the user, technical connection data such as the IP address, browser and device information, and contact details provided voluntarily. The processing is carried out to provide automated answers to general questions about Oprivia, handle contact inquiries, collect contact details where a follow-up has been expressly requested, and ensure the secure operation of the service.
According to the provider, Boei’s primary server, database and storage processing takes place within the European Economic Area. The service uses, in particular, Hetzner Online GmbH in Germany, Weaviate B.V. for the knowledge database, and Amazon Web Services EMEA SARL with storage located in Ireland. Mistral AI SAS, Paris, France, is currently configured to generate responses. With this configuration, the AI processing of responses remains within the European Economic Area according to Boei. Under the data processing agreement concluded with Boei, chat content is not used to train AI models by either Boei or the AI provider used.
Boei uses additional sub-processors for certain technical functions. These include Mailgun Technologies, Inc. for email delivery and notifications, Firecrawl or Mendable, Inc. for retrieving publicly accessible website content, and Cloudflare, Inc. for CDN, DNS, security and protection functions. These functions may involve processing in the United States or through a global infrastructure. A change of AI provider to OpenAI, Anthropic or Google may also result in message content being transferred to the United States.
Personal data is made available only to those internal functions and external service providers that require it for the relevant purpose. Service providers may process data only within the scope of their contractual responsibilities and the applicable data protection requirements.
Individual service providers may process personal data in Switzerland, the European Economic Area, the United States or other countries. Where a recipient country is not recognized as providing an adequate level of data protection, the safeguards prescribed by law are applied, in particular recognized standard contractual clauses, applicable adequacy mechanisms or other appropriate safeguards.
Retention and security
Personal data is retained only for as long as required for the relevant processing purpose, communication, documentation of an inquiry or compliance with legal obligations. Once the purpose no longer applies, the data is deleted or anonymized unless statutory retention obligations or overriding legitimate interests prevent this.
Form and communication data is generally retained for as long as necessary to process and appropriately follow up the inquiry. Data that becomes part of a business or contractual relationship may be retained for longer in accordance with the applicable documentation and retention obligations.
Oprivia and the service providers used take appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, disclosure or misuse. These measures are designed with regard to the processing purpose, the risk and the relevant state of the art.
Your rights
You may request information as to whether and which personal data concerning you is being processed. You may request the correction of inaccurate or incomplete information and, where the statutory requirements are met, request the deletion or restriction of processing.
Where applicable, you may also request the disclosure or transfer of certain personal data, object to processing or withdraw consent previously given with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
To exercise your rights, we may request appropriate proof of your identity. This helps protect personal data against unauthorized disclosure or alteration.
You also have the option of contacting the Swiss Federal Data Protection and Information Commissioner.
No solely automated individual decisions are made via the public website or the forms provided on it that have legal or similarly significant effects on you. Additional functions of a later protected platform will be described in separate privacy information where required.
Questions and updates
This Privacy Policy may be amended if the website, the services used or the legal requirements change. The version published on this page is authoritative.
For questions about the processing of your personal data or the exercise of your rights, please contact:
Brander Consulting
operating under the Oprivia brand
Email: info@oprivia.com
Where possible, please use the subject line “Privacy request”.