Last updated: 17 July 2026
This privacy policy explains how we process personal data when you visit the ProAuth website or contact us through it. It applies to this website and its contact form, not to customer-operated ProAuth installations or other 4tecture services that provide their own privacy information.
At a glance
- We host the website and process contact requests with Microsoft Azure in European regions. Contact requests are also delivered to our Microsoft 365 email system.
- We use Plausible Analytics for aggregated website statistics. Plausible does not use cookies, local storage, or persistent identifiers for analytics.
- We do not use advertising trackers. The website currently does not set cookies. A local browser preference is stored only if you choose a light or dark theme.
- We do not sell personal data or use website data for automated decisions or profiling.
Controller and contact
The controller responsible for the processing described in this policy is:
4tecture GmbH
Industriestrasse 25
8604 Volketswil
Switzerland
info@4tecture.ch
+41 44 508 37 00
You may use this email address for privacy questions and to exercise your rights.
Applicable law and legal grounds
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP). Where its territorial requirements are met, the EU General Data Protection Regulation (GDPR) also applies, for example when we offer goods or services to people in the EU or monitor their behaviour there.
Where the GDPR applies, we rely on the following legal grounds:
- steps requested before entering into a contract or performance of a contract (Article 6(1)(b) GDPR), particularly for offer, trial, and demo requests;
- our legitimate interests (Article 6(1)(f) GDPR) in operating a secure website, preventing misuse, responding to general enquiries, and understanding aggregate website usage;
- compliance with legal obligations (Article 6(1)(c) GDPR), where applicable; and
- consent (Article 6(1)(a) GDPR) only where we expressly ask for it for a specific optional purpose.
Website delivery and security
When you access the website, your browser necessarily transmits technical data to our hosting infrastructure. This may include your IP address, request date and time, requested page, referrer, browser and operating-system information, and user-agent data. Microsoft Azure processes this information to deliver the website, maintain availability, diagnose faults, and protect the service against attacks and misuse.
Our website application and contact-data storage are deployed in European Azure regions. Internet delivery, security, support, and diagnostic services may nevertheless involve Microsoft Corporation in the United States or Microsoft subprocessors in the countries identified in Microsoft’s current contractual documentation. Where a disclosure to a country without an adequate level of data protection is necessary, we use the safeguards required by applicable law, such as recognised standard contractual clauses and supplementary measures. Microsoft’s current data-protection terms are available in its Products and Services Data Protection Addendum.
Contact form and email
The data processed depends on the type of request. It may include your name, email address, telephone number, company or website, company address, enquiry type, subject and message, requested licence and support options, custom scenario information, or a trial issuer URL. We also record the submission time and delivery status so that failed delivery can be identified and handled.
The contact form is processed by an Azure Function. The submission is stored temporarily in Azure Table Storage and sent via Microsoft Graph to our Microsoft 365 email system, where authorised 4tecture personnel handle it. We use the data to respond to your request, prepare offers, arrange trials or demonstrations, document the communication, and protect the form from abuse. Please do not submit sensitive personal data that is not necessary for your request.
For rate limiting, the Function processes the source IP address transiently and converts it into a keyed, one-way pseudonymous value before storage. The raw IP address and user-agent string are not stored with the contact record or included in the notification email. Azure’s hosting and security infrastructure may independently process technical request data as described under “Website delivery and security”.
Fields marked as required are needed so that we can process the selected request. If you do not provide them, the form cannot be submitted; you can instead contact us by email or telephone.
Plausible Analytics
We use Plausible Analytics to understand aggregate trends such as page views, referral sources, countries, devices, operating systems, and browsers. Plausible processes the page URL and referrer and derives limited device and approximate location information from request data.
Plausible does not use cookies, browser cache, or local storage, and does not create persistent identifiers. It uses the IP address and user agent only to calculate a daily identifier with a salt that changes every 24 hours; the raw IP address and full user agent are not stored. Analytics data is aggregated and, according to Plausible, processed and stored in the EU. Plausible Insights OÜ, Estonia, acts as our analytics service provider. More information is available in Plausible’s data policy.
Where the GDPR applies, our legal ground is our legitimate interest in measuring and improving the usefulness and performance of this website (Article 6(1)(f) GDPR). We have chosen a data-minimising, cookieless service for this purpose.
Cookies and browser storage
The website currently does not set cookies. Plausible does not use cookies or other persistent analytics identifiers. If you actively select a light or dark colour theme, the choice is stored locally in your browser under proauth-theme so that the website can remember the requested setting. This preference is not transmitted to us and can be removed through your browser settings.
Because the current website uses no non-essential cookies or comparable storage requiring prior consent, we do not display a cookie-consent banner. We will reassess this if we add services or technologies that require consent.
Recipients and processors
Access is limited to authorised 4tecture personnel and service providers that need the data for the purposes described above. The principal providers for this website are:
- Microsoft, for Azure hosting, Azure Functions, Azure Table Storage, Microsoft Graph, and Microsoft 365 email; and
- Plausible Insights OĂś, Estonia, for privacy-focused website analytics.
These providers may use approved subprocessors under their contractual and legal obligations. We may also disclose data where required by law, to protect legal claims, or to investigate misuse. We do not sell personal data.
Retention
We retain personal data only for as long as required for the relevant purpose. The following standard periods apply to the contact form:
- pseudonymous rate-limit identifiers and counters in Azure Table Storage are deleted after 48 hours;
- the temporary contact record in Azure Table Storage is deleted 30 days after successful email delivery, or 30 days after receipt if delivery fails;
- general enquiries and related correspondence in Microsoft 365 are normally deleted 12 months after the last meaningful contact; and
- offer, demo, and trial enquiries and related correspondence in Microsoft 365 are normally deleted 24 months after the last meaningful contact.
We may delete data earlier if it is no longer needed. If an enquiry leads to a contract, or a record is relevant to accounting, legal claims, or another statutory obligation, the relevant information may instead be retained for the applicable contractual or statutory period. Legal holds and technically necessary backup cycles may temporarily delay deletion. Technical hosting and security logs are retained according to the configured operational periods and only for as long as needed to protect and operate the service.
Plausible retains only the aggregated analytics data described in its data policy and does not allow us to identify individual visitors from its dashboard.
Your rights
Depending on the applicable law and circumstances, you may request access to your personal data, correction, deletion, restriction of processing, or data portability. You may object to processing based on legitimate interests. If processing is based on consent, you may withdraw that consent at any time for the future. Legal exceptions may apply to these rights.
To exercise a right, contact info@4tecture.ch. We may need to verify your identity. You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where the GDPR applies, with the competent EU/EEA supervisory authority.
Changes to this policy
We may update this policy when our processing or the legal requirements change. The current version and its update date are published on this page.