Privacy policy

This site is static HTML and CSS. It sets no cookies, runs no scripts, loads nothing from anywhere else and has no form to submit. The only personal data processed when you visit is the server-log record that any web server keeps when it serves a page. This notice covers the website and the free check; it also says, further down, what the admin agent for Microsoft Azure does and does not do today.

The short version

  • No cookies of any kind, and no consent banner because there is nothing to consent to.
  • No analytics, no tag manager, no tracking pixel, no advertising, no A/B testing.
  • No fonts, scripts, images, maps or embeds loaded from other servers.
  • No contact form, no newsletter, no account, no login, no payment on this website.
  • No data of yours is uploaded by the free check — it never leaves your device.
  • The Azure admin agent is not reachable from this website and is not open to customers, so nothing of yours reaches it either — see below.
  • The hosting provider that serves these pages records IP addresses and request metadata in its server logs, as every web server does. That is described in full below.
  • If you write to contact@neopiq.ai or telephone us, we process what you send in order to answer you.

Who is responsible

The controller for the processing described here — the party that decides why and how it happens:

  • Controller: Neopiq GmbH
  • Address: c/o Ludwig Limbeck AG, Sinserstrasse 67, 6330 Cham, Switzerland
  • UID: CHE-345.914.300
  • Contact for data-protection questions: contact@neopiq.ai, or by telephone on 0041 78 223 6716
  • Data protection officer: none is appointed. Swiss law makes a data protection adviser voluntary for a private company (revFADP Art. 10), and the GDPR’s duty to appoint one is not triggered by processing of this scale — nor, on the assessment under which law applies, does the GDPR apply here at all. Data-protection questions go to the contact address above and are answered by the management directly.
  • Representative in the EU under GDPR Art. 27: none is appointed, because on the assessment under which law applies the GDPR does not apply to this site. A Swiss controller needs no separate Swiss representative. If the company ever starts offering its services to people in the EU, a representative will be appointed and named here before that happens.

The same details, with the VAT position, are in the imprint.

Which law applies

Neopiq GmbH is established in Switzerland, so the revised Swiss Federal Act on Data Protection (revFADP) applies to the processing described here, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC) in Bern.

Whether the EU GDPR applies in addition turns on its Art. 3(2): it reaches a company outside the EU only if that company offers goods or services to people in the EU, or monitors their behaviour. Our assessment is that this site does neither, and that the GDPR does not apply to it. The site is addressed to businesses that run Microsoft Azure and Microsoft Dynamics 365 Supply Chain Management, not to consumers; nothing on it can be bought, ordered or signed up for; the free check runs entirely in your browser and sends us nothing; and there is no cookie, analytics or tracking of any kind, so no behaviour is monitored. A website being reachable from the EU does not, by itself, bring it within Art. 3(2).

This notice is nevertheless written to the fuller GDPR field list throughout: the rights below are stated in their broadest form, and legal bases are given for each processing operation. That is deliberate — it costs nothing, and it means nothing on this page becomes wrong if a court or authority ever reads Art. 3(2) more broadly than we do. The assessment will be revisited, and this notice rewritten, before anything on this site is offered to people in the EU rather than merely visible to them.

What this site does not collect

These are properties of how the site is built, not promises about how it is administered, so you can verify them rather than trust them.

No cookies and no tracking

No cookie is set by these pages, and nothing is written to local storage or session storage. There is no analytics service, no tag manager, no tracking pixel, no advertising network, no social plug-in and no cross-site identifier. You are not profiled, and no automated decision-making takes place.

No scripts

The marketing pages of this site contain no JavaScript at all — not a single script element. A page that runs no code cannot quietly measure you. The site’s own build check fails the build if a script is ever added.

No third-party requests

The only file these pages load is one stylesheet served from this same site. There is no content delivery network, no remote web font, no remote image, no embedded video and no map. Because nothing is requested from another server, no other company learns your IP address from your visit here.

No forms and no accounts

There is no contact form, no sign-up, no newsletter subscription, no login and no payment on this website. Nothing on these pages submits anything anywhere, so browsing gives us no name, e-mail address or message to receive, store or lose.

There is a published e-mail address and telephone number, but they are ordinary contact routes, not a form: nothing is collected unless you choose to write. See writing to us.

You can confirm all of this in about a minute: open your browser’s network tab and load any page here, or read the page source. What you will see is the document itself and one stylesheet.

Hosting and server logs

This site is published with GitHub Pages, so GitHub’s servers deliver these pages to your browser. Like every web server, they process the technical data that a request necessarily contains in order to answer it, and record it in server logs. That typically includes:

  • the IP address the request came from;
  • the date and time of the request;
  • the address of the page or file requested, and the response status;
  • the amount of data transferred;
  • the browser and operating system reported by your browser (the user-agent string);
  • the referring page, if your browser sends one.

This is the only processing of personal data that actually happens when you use this site, and it is unavoidable: a server cannot send a page to an address it does not have. It is used to deliver the site, to keep it available, and to detect and defend against attacks and abuse. It is not used to identify you, to build a profile, or for marketing, and it is not combined with anything else — there is nothing else.

Legal basis

Where the GDPR applies, the legal basis is Art. 6(1)(f) — the legitimate interest in presenting a functioning, stable and secure website. Where Swiss law applies, the same processing is justified by the overriding private interest in the secure operation of the site. You can object to processing based on legitimate interests; see your rights below.

Who processes it

GitHub acts as the hosting provider for this site and, in data-protection terms, as a processor acting for the controller named above. The logs are generated and held by GitHub as part of operating its platform. We do not receive these logs, do not have an interface to query them, and cannot look up individual visitors.

The processor agreement for this is GitHub’s Data Protection Agreement, which forms part of the service terms under which this site is hosted and which GitHub publishes on its website. It commits GitHub to process personal data only to provide the service, to keep it confidential and secure, and to the transfer safeguards described in the next section. We have not negotiated anything beyond it, and nothing beyond it is needed for a site that consists of static pages.

How long the logs are kept

The logs are kept by GitHub, not by us, on GitHub’s own schedule. GitHub’s documentation states that visitor IP addresses of Pages sites are logged and stored for security purposes; it does not publish a fixed number of days for these logs, and its privacy statement limits retention to what the collection purpose requires. We hold no copy at all, so there is nothing on our side to be kept or deleted.

Transfers outside your country

GitHub is a company established in the United States and operates a global network, so the server-log data described above may be processed outside Switzerland and outside the European Economic Area. There is no other recipient: nothing else on this site sends anything anywhere.

The safeguard for that transfer is the EU standard contractual clauses (Commission Implementing Decision 2021/914), which Switzerland recognises for Swiss transfers subject to the FDPIC’s adaptations, and which are incorporated into GitHub’s Data Protection Agreement — the same published document named under hosting above, obtainable from GitHub’s website. GitHub is in addition certified under the Swiss–U.S. Data Privacy Framework. It is worth being precise about what actually travels under these safeguards: the request logs and IP addresses described above, and nothing more. No content of yours is transferred by this site, because none is collected — the free check uploads nothing.

If you write to us

A contact route exists: the e-mail address and telephone number published in the imprint. This section describes what happens if you use one.

  • What is processed: whatever you put in your message or say on the call — typically your name, your e-mail address or number, and the content of your enquiry. Nothing else is collected, and nothing is required of you beyond the address we need in order to reply.
  • Why: to read your message, answer it, and keep the thread coherent if the exchange continues.
  • Legal basis: where the GDPR applies, Art. 6(1)(b) for enquiries that are pre-contractual and Art. 6(1)(f) — the legitimate interest in answering people who write to us — for everything else. Under Swiss law no separate justification is needed to process data you send us for the purpose you sent it for.
  • What is not done with it: it is not used for marketing, not added to any mailing list — there is none — and not passed to anyone outside the company.

Who carries it

E-mail to our contact address is carried and stored by a commercial e-mail hosting provider acting as our processor, under its standard data-processing terms. The published telephone number is a Swiss mobile number carried on a Swiss mobile network, and calls are not recorded. Large e-mail providers routinely operate infrastructure outside Switzerland and the EEA, including in the United States; for any correspondence processed there, we use only providers whose terms include the EU standard contractual clauses, as recognised by Switzerland with the FDPIC’s adaptations. We name the category rather than a brand because the provider may change; the safeguard is the commitment, and it will not. Ask at the contact address and we will tell you which provider holds your thread.

How long it is kept

Correspondence is kept while an exchange is open and then for up to 24 months after the last message, so that the thread is still there if you come back to the same matter; after that it is deleted. The one exception is correspondence that becomes part of a contract or matters for the books, which Swiss accounting law (OR Art. 958f) requires us to keep for ten years.

The free check runs in your browser

Nothing is uploaded

Your CSV files never leave your device

The free planning check is a web page that reads the CSV files you choose, analyses them and displays the findings — all inside your browser, on your own machine. It has no network capability by construction: no upload, no background transmission, no telemetry, no error reporting, no “optional” cloud step.

Your files are never sent to us, never sent to the hosting provider beyond the ordinary request that fetched the page itself, and never stored by this site. Nothing is written to cookies, local storage, session storage or any browser database. The analysis lives in the page while the tab is open; closing the tab is the delete button.

Because your item master, vendor list and receipts are commercially sensitive, this is deliberately verifiable rather than merely promised: open the browser’s network tab while the check runs and nothing is requested, or disconnect from the network first and it still works.

The same claim, with the technical reasoning behind it, is on the how it works page.

Because the tool never transmits your data, we are not a controller or a processor of anything it reads. Whatever is in those exports remains entirely under your own control, on your own equipment, and under whatever obligations already apply to you as its controller.

The Azure admin agent, and why it is not part of this notice yet

This site also describes a second product: ChatAdmin, a chat-based agent that signs in to Azure, carries out administrative changes after an explicit approval, and writes an audit trail of what was asked, what was approved or declined, and what the platform did. That is a materially heavier processing story than a local browser tool.

What is true today, and only this:

  • It is not reachable from this website. No page here connects to it, and its address is not published.
  • There is no sign-in and no sign-up. You cannot create an account, join a waiting list or be onboarded, so it holds no account, identity or contact data about you.
  • It is not multi-tenant, and it runs today against Neopiq’s own Azure subscription — not against yours. No customer system, tenant or data is connected to it.
  • It follows that no personal data of visitors or customers is processed by it, and that nothing you do on this website causes anything to reach it.

This notice therefore covers the website, the free check and correspondence with us — and nothing else. It will be rewritten before the admin agent opens to customers; see changes to this notice.

Who receives your data

For your visit to this site: nobody, apart from the hosting provider described above. Your data is not sold, rented, shared or disclosed. There is no advertising partner, no analytics vendor and no customer relationship system involved in this site, because there is no mechanism by which anything could reach them.

For correspondence: the mail and telephony providers that carry it, and nobody else — see writing to us.

For authorities: we disclose personal data to a court or authority only against a legally binding order that we are required to comply with. If we receive one, we check that it is valid and within the issuer’s powers, disclose no more than it compels, and inform the person concerned unless the order itself lawfully prevents that. In practice such an order would rarely have anything to reach: the only visit data that exists sits in GitHub’s logs, which we cannot query, so an authority wanting it would have to go to GitHub, which publishes its own guidelines for handling government requests. What we could actually be ordered to produce is correspondence you have sent us, and nothing else.

How long anything is kept

This website stores nothing itself: there is no database, no log of our own and no back end behind these pages. Only two retention periods exist, and both are stated in full earlier on this page:

  • Server logs — held by GitHub, not by us, on GitHub’s own schedule. GitHub does not publish a fixed number of days for Pages logs; its privacy statement limits retention to what the security purpose requires. We hold no copy. See hosting and server logs.
  • Correspondence — deleted no later than 24 months after the last message in an exchange, except where it becomes part of a contract or matters for the books, in which case Swiss accounting law (OR Art. 958f) sets ten years. See if you write to us.

Your rights

In respect of personal data relating to you, you can ask to exercise the following rights. They are stated here in their broadest form, so that the answer does not depend on which framework finally applies.

  • Access — confirmation of whether data relating to you is processed, and a copy of it.
  • Rectification — correction of inaccurate data, and completion of incomplete data.
  • Erasure — deletion, where there is no overriding reason to keep it.
  • Restriction — that processing be limited rather than continued, in the cases the law provides for.
  • Objection — to processing based on legitimate interests, including the server logging described above, on grounds relating to your situation.
  • Portability — a structured, commonly used, machine-readable copy of data you provided, where that right applies.
  • Withdrawal of consent — at any time, where processing ever rests on consent. Nothing on this site currently does.
  • Complaint — to a data protection supervisory authority.

In practice the honest answer to most access requests about this site is that we hold nothing about you: the only record of your visit sits in the hosting provider’s logs, keyed to an IP address we cannot query. A request would be forwarded to the provider to the extent it can be. If you have written to us, the correspondence itself is the exception — that we do hold, and it is what an access request would actually return.

  • To exercise a right, write to contact@neopiq.ai, or to Neopiq GmbH, c/o Ludwig Limbeck AG, Sinserstrasse 67, 6330 Cham, Switzerland.
  • Competent supervisory authority in Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), Bern.
  • Competent supervisory authority in the EU: on the assessment under which law applies, the GDPR does not apply to this site, so no EU authority is competent and the FDPIC is the place to complain to. If you are in the EU and read Art. 3(2) differently, nothing here stops you from raising the matter with the data protection authority of your own member state — whether a complaint is admissible is that authority’s call, not ours.

Is providing data required?

No. You are not asked for any data by this site, and there is nothing to withhold. The technical data in the server logs is created by the act of requesting a page and cannot be separated from it, which is true of every website; if you would rather not generate it, do not open the page. If you write to us, you decide what to put in the message — we need only enough of an address to reply.

Changes to this notice

This notice describes the site as it is built today. It will change when the site changes — and in particular it must be rewritten before anything that collects data is added: a contact form, an account, a newsletter, a payment step, an embedded video, the cloud reporting step described on the pricing page as not yet open, or customer onboarding for the Azure admin agent.

The current version is always the one published on this page. There is no mailing list to announce changes through, because there is no mailing list.

This version is effective from 16 August 2026.

Related pages