Last updated: 6 October 2026

Privacy policy

This privacy policy explains which personal data we process when you visit hierarchy.ch or use our services, why we do so and what rights you have. It follows the Swiss Federal Act on Data Protection (FADP) and, where it applies, takes the EU General Data Protection Regulation (GDPR) into account.


1. Controller

The controller responsible for the data processing on this website is:

Hierarchy
Wolframplatz 15

8045 Zurich

Switzerland

Email: info@hierarchy.ch

Your contacts for data protection questions are Tenzin Langdun and Martin Oswald. The easiest way to reach us is by email at info@hierarchy.ch.

2. What data we process and when

We only process the data we need for the respective purpose. In detail:

Visiting the website

Our website runs on Cloudflare infrastructure (Cloudflare Workers). Every request automatically processes technical data: IP address, date and time, the requested address (URL), the previously visited page (referrer) and information about your browser and device (user agent). This is necessary to deliver the website, keep it secure and stable, and fend off attacks or automated abuse. Cloudflare may set technically necessary cookies for this.

Contact form and email

When you write to us through the contact form, we process your name, your email address, optionally your company, and your message. The form is forwarded as an email to our inbox via the email service Resend. If you email us directly, we process the information you send. We use this data to answer your enquiry and, where relevant, to prepare an offer.

Checklists from our articles

If you request a checklist in an article, we process your email address together with the article, the language and the time of the request. We send you the checklist via Resend and receive a notification ourselves. We do not use your address for a newsletter.

Free AI visibility check

For the AI visibility check you provide your website address, your email address and optionally a question of your own. We store this together with the language, the page from which you started the check, the country derived from your IP address, a hashed value of your IP address (SHA-256, to prevent abuse; we do not store the IP address itself), and the results and finished report in a database at Cloudflare.

To build the report we fetch publicly accessible pages of the website you entered (home page, robots.txt, sitemap). The website address and excerpts of the public content (title, description, text sample) are sent to an AI service (DeepInfra, or OpenAI as a fallback if DeepInfra is unavailable), which classifies the offering and drafts typical customer questions. We put these questions, and your own question if you gave one, to the AI assistants of OpenAI (ChatGPT), Google (Gemini) and Anthropic (Claude). We do not pass your email address to these AI services. Please do not enter personal data in the field for your own question.

The report is converted to a PDF via Cloudflare and sent to your email address via Resend. We receive an internal notification with the website, email address, country, your question and the report. The check is free; you receive the report and nothing else, in particular no newsletter.

In addition, the form stores the checked website, your email address and the time in your browser's local storage (localStorage, key "hy-vis"). This lets the form show its status after a reload and limit repeated requests. This information stays on your device until you delete it in your browser settings.

Purchase of the AI visibility study

You buy the study through Stripe's checkout page. Stripe collects the data needed for the payment directly (for example email address, name, payment method and, where required, billing address). We do not receive full card or account details. From Stripe we receive your email address, the amount and the payment status. After payment we send the download links to this email address via Resend; Stripe sends the receipt and invoice. On every download we check with Stripe that the payment is confirmed. The PDF files are kept in non-public storage at Cloudflare.

Stripe is itself responsible for part of the processing, for example fraud prevention and compliance with its own legal obligations. Details are in Stripe's privacy policy.

Google Tag Manager and analytics

Our website uses Google Tag Manager, a service provided by Google. Tag Manager itself is a tool for managing other scripts. Through it we may use analytics services such as Google Analytics. These use cookies or similar technologies and collect usage data, for example pages visited, time and duration of the visit, browser and device information, approximate location and your IP address. This data is transmitted to Google and may also reach the USA. We use it to understand how our website is used and to improve it and our services.

We do not currently display a cookie banner; Tag Manager starts when the page loads. You can object to this processing by blocking or deleting cookies in your browser, using a script or tracking blocker, or installing the browser add-on to opt out of Google Analytics. More information is in Google's privacy policy.

Fonts and links

The fonts on this website are served from our own server. No connection to Google Fonts is made when the pages load.

Links to other websites, such as LinkedIn or academic publications, are plain links without embedded plugins. Only when you click such a link does the respective provider process data under its own rules.

3. Purposes

We process personal data for the following purposes:

  • Providing the website and keeping it secure and stable
  • Answering enquiries and preparing offers
  • Providing the services you request (checklist, AI visibility check, study)
  • Processing payments, bookkeeping and meeting legal obligations
  • Preventing abuse, for example by limiting repeated requests
  • Measuring reach and improving our website and services

We process personal data lawfully, in good faith and proportionately. Where the GDPR applies, we rely on the following legal bases: contract or pre-contractual measures (Art. 6(1)(b) GDPR) for enquiries, checklists, the AI check and the study purchase; our legitimate interests (Art. 6(1)(f) GDPR) in a secure website, protection against abuse and reach measurement; legal obligations (Art. 6(1)(c) GDPR) for retaining accounting records; and your consent (Art. 6(1)(a) GDPR) where we ask for it.

4. Recipients and processors

We do not sell personal data. We work with service providers that process data on our behalf or, where stated, are partly responsible themselves:

  • Cloudflare (USA, global network): hosting and delivery of the website, security, AI check database, PDF generation, storage of the study PDFs
  • Resend (USA): sending emails (contact form, checklists, reports, download links)
  • Google (USA, Ireland): Google Tag Manager and analytics services used through it, the Gemini AI assistant in the AI check, and the email inbox (Gmail) in which we receive enquiries and internal notifications
  • Stripe (Ireland, USA): payment processing, receipts and invoices
  • DeepInfra (USA): AI analysis of public website content in the AI check
  • OpenAI (USA): ChatGPT AI assistant in the AI check and fallback if DeepInfra is unavailable
  • Anthropic (USA): Claude AI assistant in the AI check

Beyond this, we only disclose personal data where we are legally required to, for example to authorities.

Disclosure abroad

Some of these recipients process data in the USA or in other countries whose data protection the Swiss Federal Council has not in every case recognised as adequate. In these cases we ensure appropriate protection: if a recipient is certified under the Swiss-US Data Privacy Framework (or, for data from the EU, the EU-US Data Privacy Framework), we rely on that. Otherwise we use the European Commission's standard contractual clauses as recognised by the FDPIC, or rely on a statutory exception, for example where the disclosure is directly connected with concluding or performing a contract with you. On request we will gladly tell you about the safeguards in place.

5. Retention

We keep personal data only as long as the respective purpose requires or the law demands:

  • Server log data: at Cloudflare only as long as needed for operation and security
  • Enquiries via the contact form, by email and checklist requests: until your enquiry is resolved and for as long as any resulting business relationship requires
  • AI visibility check: as long as we need the data to create, deliver and follow up on the report and to prevent abuse; we delete it at any time on request
  • Study purchase data: accounting records for the statutory retention period of ten years (Art. 958f Swiss Code of Obligations)
  • Information in your browser's local storage: on your device until you delete it

6. Data security

The connection to our website is encrypted (HTTPS). Only the people at Hierarchy who need access to personal data for their work have it. Payment data is processed exclusively by Stripe.

7. Your rights

Within the scope of applicable data protection law you have in particular the following rights:

  • Access: to know whether and which personal data we process about you
  • Rectification of inaccurate personal data
  • Erasure of your personal data
  • Objection to certain processing, in particular reach measurement
  • Release or transfer of the personal data you provided to us in a common electronic format
  • Withdrawal of consent you have given, with effect for the future

An email to info@hierarchy.ch is all it takes. To make sure we do not release your data to anyone else, we may ask you to prove your identity. These rights are not unlimited: statutory retention obligations, for example, may prevent erasure.

You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland (www.edoeb.admin.ch). If you are in the EU or EEA, you additionally have the rights under Art. 15 to 21 GDPR and may lodge a complaint with the data protection supervisory authority in your country.

8. Cookies and similar technologies

Our website's own code does not set cookies. However, cookies or similar technologies may be used by the following services:

  • Cloudflare: technically necessary cookies for security and bot protection
  • Google Tag Manager and analytics services used through it, such as Google Analytics: cookies for reach measurement (see section 2)
  • Stripe: cookies on Stripe's checkout page when you buy the study
  • AI visibility check: your browser's local storage (localStorage, see section 2)

You can block or delete cookies and locally stored data in your browser at any time. The website remains usable.

9. Changes

We may update this privacy policy when our website, our services or the legal requirements change. The current version published on this page applies.

Further information about the operator is in the imprint.