The short version
- No cookies of any kind, and no consent banner because there is nothing to consent to.
- No analytics, no tag manager, no tracking pixel, no advertising, no A/B testing.
- No fonts, scripts, images, maps or embeds loaded from other servers.
- No contact form, no newsletter, no account, no login, no payment on this website.
- No data of yours is uploaded by the free check — it never leaves your device.
-
The Azure admin agent is not reachable from this website and is not open to customers, so
nothing of yours reaches it either — see below.
-
The hosting provider that serves these pages records IP addresses and request metadata in
its server logs, as every web server does. That is described in full below.
-
If you write to contact@neopiq.ai or telephone us,
we process what you send in order to answer you.
Who is responsible
The controller for the processing described here — the party that decides why and how
it happens:
- Controller: Neopiq GmbH
- Address: c/o Ludwig Limbeck AG, Sinserstrasse 67, 6330 Cham, Switzerland
- UID: CHE-345.914.300
- Contact for data-protection questions: contact@neopiq.ai, or by telephone on 0041 78 223 6716
- Data protection officer: none is appointed. Swiss law makes a data protection
adviser voluntary for a private company (revFADP Art. 10), and the GDPR’s duty to
appoint one is not triggered by processing of this scale — nor, on the assessment
under which law applies, does the GDPR apply here at all.
Data-protection questions go to the contact address above and are answered by the
management directly.
- Representative in the EU under GDPR Art. 27: none is appointed, because on the
assessment under which law applies the GDPR does not apply to
this site. A Swiss controller needs no separate Swiss representative. If the company
ever starts offering its services to people in the EU, a representative will be
appointed and named here before that happens.
The same details, with the VAT position, are in the
imprint.
Which law applies
Neopiq GmbH is established in Switzerland, so the revised Swiss Federal Act on Data
Protection (revFADP) applies to the processing described here, and the competent
supervisory authority is the Swiss Federal Data Protection and Information Commissioner
(FDPIC) in Bern.
Whether the EU GDPR applies in addition turns on its Art. 3(2): it reaches
a company outside the EU only if that company offers goods or services to people in the EU,
or monitors their behaviour. Our assessment is that this site does neither, and that
the GDPR does not apply to it. The site is addressed to businesses that
run Microsoft Azure and Microsoft Dynamics 365 Supply Chain Management, not to
consumers; nothing on it can be bought, ordered or signed up for; the free check runs entirely in your browser and sends us nothing; and
there is no cookie, analytics or tracking of any kind, so no behaviour is monitored. A
website being reachable from the EU does not, by itself, bring it within Art. 3(2).
This notice is nevertheless written to the fuller GDPR field list throughout: the rights
below are stated in their broadest form, and legal bases are given for each processing
operation. That is deliberate — it costs nothing, and it means nothing on this page
becomes wrong if a court or authority ever reads Art. 3(2) more broadly than we do. The
assessment will be revisited, and this notice rewritten, before anything on this site is
offered to people in the EU rather than merely visible to them.
What this site does not collect
These are properties of how the site is built, not promises about how it is administered, so
you can verify them rather than trust them.
No cookies and no tracking
No cookie is set by these pages, and nothing is written to local storage or session
storage. There is no analytics service, no tag manager, no tracking pixel, no
advertising network, no social plug-in and no cross-site identifier. You are not
profiled, and no automated decision-making takes place.
No scripts
The marketing pages of this site contain no JavaScript at all — not a single
script element. A page that runs no code cannot quietly measure you. The
site’s own build check fails the build if a script is ever added.
No third-party requests
The only file these pages load is one stylesheet served from this same site. There is no
content delivery network, no remote web font, no remote image, no embedded video and no
map. Because nothing is requested from another server, no other company learns your IP
address from your visit here.
No forms and no accounts
There is no contact form, no sign-up, no newsletter subscription, no login and no
payment on this website. Nothing on these pages submits anything anywhere, so browsing
gives us no name, e-mail address or message to receive, store or lose.
There is a published e-mail address and telephone number, but they are ordinary
contact routes, not a form: nothing is collected unless you choose to write. See
writing to us.
You can confirm all of this in about a minute: open your browser’s network tab and load
any page here, or read the page source. What you will see is the document itself and one
stylesheet.
Hosting and server logs
This site is published with GitHub Pages, so GitHub’s servers deliver these pages to
your browser. Like every web server, they process the technical data that a request
necessarily contains in order to answer it, and record it in server logs. That typically
includes:
- the IP address the request came from;
- the date and time of the request;
- the address of the page or file requested, and the response status;
- the amount of data transferred;
- the browser and operating system reported by your browser (the user-agent string);
- the referring page, if your browser sends one.
This is the only processing of personal data that actually happens when you use this site,
and it is unavoidable: a server cannot send a page to an address it does not have. It is used
to deliver the site, to keep it available, and to detect and defend against attacks and
abuse. It is not used to identify you, to build a profile, or for marketing, and it is not
combined with anything else — there is nothing else.
Legal basis
Where the GDPR applies, the legal basis is Art. 6(1)(f) — the legitimate interest in
presenting a functioning, stable and secure website. Where Swiss law applies, the same
processing is justified by the overriding private interest in the secure operation of the
site. You can object to processing based on legitimate interests; see
your rights below.
Who processes it
GitHub acts as the hosting provider for this site and, in data-protection terms, as a
processor acting for the controller named above. The logs are generated and held by GitHub as
part of operating its platform. We do not receive these logs, do not have an interface to
query them, and cannot look up individual visitors.
The processor agreement for this is GitHub’s Data Protection
Agreement, which forms part of the service terms under which this site is hosted
and which GitHub publishes on its website. It commits GitHub to process personal data only
to provide the service, to keep it confidential and secure, and to the transfer safeguards
described in the next section. We have not negotiated anything beyond it, and nothing
beyond it is needed for a site that consists of static pages.
How long the logs are kept
The logs are kept by GitHub, not by us, on GitHub’s own schedule. GitHub’s
documentation states that visitor IP addresses of Pages sites are logged and stored for
security purposes; it does not publish a fixed number of days for these logs, and its
privacy statement limits retention to what the collection purpose requires. We hold no
copy at all, so there is nothing on our side to be kept or deleted.
Transfers outside your country
GitHub is a company established in the United States and operates a global network, so the
server-log data described above may be processed outside Switzerland and outside the European
Economic Area. There is no other recipient: nothing else on this site sends anything anywhere.
The safeguard for that transfer is the EU standard contractual clauses
(Commission Implementing Decision 2021/914), which Switzerland recognises for Swiss
transfers subject to the FDPIC’s adaptations, and which are incorporated into
GitHub’s Data Protection Agreement — the same published document named under
hosting above, obtainable from GitHub’s website. GitHub is in
addition certified under the Swiss–U.S. Data Privacy Framework. It is worth being
precise about what actually travels under these safeguards: the request logs and IP
addresses described above, and nothing more. No content of yours is transferred by this
site, because none is collected — the free check uploads nothing.
If you write to us
A contact route exists: the e-mail address and telephone number published in the
imprint. This section describes what happens if you use
one.
-
What is processed: whatever you put in your message or say on the call
— typically your name, your e-mail address or number, and the content of your
enquiry. Nothing else is collected, and nothing is required of you beyond the address we
need in order to reply.
-
Why: to read your message, answer it, and keep the thread coherent if
the exchange continues.
-
Legal basis: where the GDPR applies, Art. 6(1)(b) for enquiries that are
pre-contractual and Art. 6(1)(f) — the legitimate interest in answering people who
write to us — for everything else. Under Swiss law no separate justification is
needed to process data you send us for the purpose you sent it for.
-
What is not done with it: it is not used for marketing, not added to any
mailing list — there is none — and not passed to anyone outside the company.
Who carries it
E-mail to our contact address is carried and stored by a commercial e-mail hosting
provider acting as our processor, under its standard data-processing terms. The published
telephone number is a Swiss mobile number carried on a Swiss mobile network, and calls are
not recorded. Large e-mail providers routinely operate infrastructure outside Switzerland
and the EEA, including in the United States; for any correspondence processed there, we
use only providers whose terms include the EU standard contractual clauses, as recognised
by Switzerland with the FDPIC’s adaptations. We name the category rather than a
brand because the provider may change; the safeguard is the commitment, and it will not.
Ask at the contact address and we will tell you which provider holds your thread.
How long it is kept
Correspondence is kept while an exchange is open and then for up to 24
months after the last message, so that the thread is still there if you come back
to the same matter; after that it is deleted. The one exception is correspondence that
becomes part of a contract or matters for the books, which Swiss accounting law (OR
Art. 958f) requires us to keep for ten years.
The free check runs in your browser
Nothing is uploaded
Your CSV files never leave your device
The free planning check is a web page that reads the CSV files you choose, analyses them
and displays the findings — all inside your browser, on your own machine. It has no
network capability by construction: no upload, no background transmission, no telemetry, no
error reporting, no “optional” cloud step.
Your files are never sent to us, never sent to the hosting provider beyond the ordinary
request that fetched the page itself, and never stored by this site. Nothing is written to
cookies, local storage, session storage or any browser database. The analysis lives in the
page while the tab is open; closing the tab is the delete button.
Because your item master, vendor list and receipts are commercially sensitive, this is
deliberately verifiable rather than merely promised: open the browser’s network tab
while the check runs and nothing is requested, or disconnect from the network first and it
still works.
The same claim, with the technical reasoning behind it, is on the
how it works page.
Because the tool never transmits your data, we are not a controller or a processor of
anything it reads. Whatever is in those exports remains entirely under your own control, on
your own equipment, and under whatever obligations already apply to you as its controller.
The Azure admin agent, and why it is not part of this notice yet
This site also describes a second product:
ChatAdmin, a chat-based agent that signs in to
Azure, carries out administrative changes
after an explicit approval, and writes an audit trail of what was asked, what was approved
or declined, and what the platform did. That is a materially heavier processing story than
a local browser tool.
What is true today, and only this:
- It is not reachable from this website. No page here connects to it, and
its address is not published.
- There is no sign-in and no sign-up. You cannot create an account, join a
waiting list or be onboarded, so it holds no account, identity or contact data about you.
- It is not multi-tenant, and it runs today against
Neopiq’s own Azure subscription — not against yours. No
customer system, tenant or data is connected to it.
- It follows that no personal data of visitors or customers is processed by it,
and that nothing you do on this website causes anything to reach it.
This notice therefore covers the website, the free check and correspondence with us —
and nothing else. It will be rewritten before the admin agent opens to customers; see
changes to this notice.
Who receives your data
For your visit to this site: nobody, apart from the hosting provider described above. Your
data is not sold, rented, shared or disclosed. There is no advertising partner, no analytics
vendor and no customer relationship system involved in this site, because there is no
mechanism by which anything could reach them.
For correspondence: the mail and telephony providers that carry it, and nobody else —
see writing to us.
For authorities: we disclose personal data to a court or authority only against a legally
binding order that we are required to comply with. If we receive one, we check that it is
valid and within the issuer’s powers, disclose no more than it compels, and inform
the person concerned unless the order itself lawfully prevents that. In practice such an
order would rarely have anything to reach: the only visit data that exists sits in
GitHub’s logs, which we cannot query, so an authority wanting it would have to go to
GitHub, which publishes its own guidelines for handling government requests. What we could
actually be ordered to produce is correspondence you have sent us, and nothing else.
How long anything is kept
This website stores nothing itself: there is no database, no log of our own and no back end
behind these pages. Only two retention periods exist, and both are stated in full earlier
on this page:
-
Server logs — held by GitHub, not by us, on GitHub’s own
schedule. GitHub does not publish a fixed number of days for Pages logs; its privacy
statement limits retention to what the security purpose requires. We hold no copy. See
hosting and server logs.
-
Correspondence — deleted no later than 24 months after the last
message in an exchange, except where it becomes part of a contract or matters for the
books, in which case Swiss accounting law (OR Art. 958f) sets ten years. See
if you write to us.
Your rights
In respect of personal data relating to you, you can ask to exercise the following rights.
They are stated here in their broadest form, so that the answer does not depend on which
framework finally applies.
- Access — confirmation of whether data relating to you is processed, and a copy of it.
- Rectification — correction of inaccurate data, and completion of incomplete data.
- Erasure — deletion, where there is no overriding reason to keep it.
- Restriction — that processing be limited rather than continued, in the cases the law provides for.
- Objection — to processing based on legitimate interests, including the server logging described above, on grounds relating to your situation.
- Portability — a structured, commonly used, machine-readable copy of data you provided, where that right applies.
- Withdrawal of consent — at any time, where processing ever rests on consent. Nothing on this site currently does.
- Complaint — to a data protection supervisory authority.
In practice the honest answer to most access requests about this site is that we hold nothing
about you: the only record of your visit sits in the hosting provider’s logs, keyed to
an IP address we cannot query. A request would be forwarded to the provider to the extent it
can be. If you have written to us, the correspondence itself is the exception — that we
do hold, and it is what an access request would actually return.
-
To exercise a right, write to contact@neopiq.ai, or
to Neopiq GmbH, c/o Ludwig Limbeck AG, Sinserstrasse 67, 6330 Cham, Switzerland.
-
Competent supervisory authority in Switzerland: the Federal Data Protection and
Information Commissioner (FDPIC), Bern.
-
Competent supervisory authority in the EU: on the assessment under
which law applies, the GDPR does not apply to this site, so no
EU authority is competent and the FDPIC is the place to complain to. If you are in the
EU and read Art. 3(2) differently, nothing here stops you from raising the matter with
the data protection authority of your own member state — whether a complaint is
admissible is that authority’s call, not ours.
Is providing data required?
No. You are not asked for any data by this site, and there is nothing to withhold. The
technical data in the server logs is created by the act of requesting a page and cannot be
separated from it, which is true of every website; if you would rather not generate it, do
not open the page. If you write to us, you decide what to put in the message — we need
only enough of an address to reply.
Changes to this notice
This notice describes the site as it is built today. It will change when the site changes
— and in particular it must be rewritten before anything that collects data is added:
a contact form, an account, a newsletter, a payment step, an embedded video, the cloud
reporting step described on the pricing page as not yet open, or
customer onboarding for the Azure admin agent.
The current version is always the one published on this page. There is no mailing list to
announce changes through, because there is no mailing list.
This version is effective from 16 August 2026.