Legal
Privacy policy
Last updated: 2 August 2026
1. Who is responsible
This website, dc01sk.com (the "site"), is operated by VG RE GmbH ("we", "us"), the controller responsible for the personal data processed through it.
VG RE GmbH
Baarerstrasse 137, 6302 Zug, Switzerland
Company identification number: CHE-331.611.017
Contact for data protection matters: Jakub Krampl, info@dc01sk.com
Because the site is offered to visitors in the European Union, we apply both the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).
Representative in the European Union
We have not designated a representative in the European Union. Our processing of EU visitors' data is occasional and limited to running the site and answering enquiries people choose to send us; it does not involve large-scale processing of special categories of data or of data relating to criminal convictions, and it is unlikely to result in a risk to the rights and freedoms of individuals. On that basis we rely on the exemption in Article 27(2)(a) GDPR. You can contact us directly at the address and email address above, and we will answer.
2. What data we collect, and why
Enquiries you send through the form
When you use the "Request more info" form, we process what you enter: your name and email address (both required), the option you select for "I'm interested as" (tenant, buyer or other), and, if you choose to give them, your company, your role and a message. We also record the page you submitted from, the date and time of the submission, and the IP address it was sent from. Your name and email address are what we need in order to reply; without them we cannot respond to you.
The form carries two hidden anti-abuse checks: a decoy field that a person never sees, and a check on how quickly the form was completed. Neither answer is kept alongside your enquiry. If either check stops your submission, we keep a copy of it, including these two answers, so that a submission stopped in error can be found and acted on rather than lost (section 5).
We also count submissions against the IP address they come from, so that one address cannot flood the form. There are two counters: one counts submission attempts, with a high ceiling aimed at automated abuse, and one counts the enquiries we accept, with a lower ceiling. Both are held against the current calendar day in Coordinated Universal Time (UTC) and are discarded when that day ends at 00:00 UTC, whatever time of day you write to us. Each holds a number and nothing else. The storage behind them is shared across locations and takes a short time to settle, so these ceilings work as a brake on repeated submissions rather than as an exact quota.
We use this data only to respond to your enquiry, to take steps at your request before any possible business relationship, and to keep the form from being abused.
Legal basis: the taking of pre-contractual steps at your request, and our legitimate interest in responding to business enquiries and preventing abuse of the form (GDPR Article 6(1)(b) and (f); the corresponding grounds under the FADP).
If you email us
If you write to info@dc01sk.com, we process your email address, your message and anything else you include in it, in order to reply and to keep a record of the correspondence.
Legal basis: pre-contractual steps at your request and our legitimate interest in handling correspondence (GDPR Article 6(1)(b) and (f)).
Technical data when you visit
The site is hosted and delivered by Cloudflare. To serve a page and keep the site secure, Cloudflare processes standard technical data, including your IP address, browser and device information, and the pages you request.
Legal basis: our legitimate interest in operating a secure, functioning website (GDPR Article 6(1)(f)).
The consent banner
Every page loads Cookiebot, the tool that asks whether you accept non-essential cookies and stores your answer. It is the only third-party service that runs before you have made a choice, because it is what puts the choice in front of you. Showing the banner means your IP address and browser information reach Cookiebot's provider on each page load. Your choice is then stored so that we do not ask again on every page.
Legal basis: our legitimate interest in operating a working consent mechanism, and in meeting our obligation to ask for consent before any non-essential cookie is set (GDPR Article 6(1)(f)).
The site location map
Two pages, the home page and the buyers page, offer a Google Maps view of the site location. It does not load on its own: nothing is requested from Google until you press "Load map", or, if you have accepted marketing cookies in the consent banner, until that choice is applied. When the map loads, your browser connects to Google, Google receives your IP address and technical request data, and Google may set its own cookies. In that context Google is not acting on our behalf: it decides for itself how it uses that data, under its own privacy policy, and we do not receive it. The separate "Open in Google Maps" link is an ordinary link and sends you to Google only if you follow it.
Legal basis: your consent, given either by loading the map or by accepting marketing cookies in the banner (GDPR Article 6(1)(a)).
Analytics and measurement
Three measurement tools run on this site: Google Analytics 4 and Microsoft Clarity, which sit in the statistics category of the consent banner, and Apollo, which sits in the marketing category. None of them starts until you have accepted that category. Until then their scripts are not fetched at all and nothing is sent to any of them. We do not leave that to the blocking alone: before any Google tag exists, the page already declares to Google that every kind of storage and every advertising signal is denied, so a Google tag that somehow did run would have nothing to store and nothing to report until your answer changes it. Advertising storage is never granted, whatever you accept. Refusing costs you nothing here. Every page reads and works the same either way.
Google Analytics 4. This measures how the site is used: which pages are opened and in what order, how visitors arrived, roughly which country or region they are in, and what device and browser they use. It works by giving your browser an identifier, held in cookies, so that a series of page views is counted as one visit rather than as a crowd of strangers. Your IP address reaches Google as part of it, and is used to work out that approximate location. Google acts as our processor for this, and here we can be specific rather than general: we have accepted Google's data processing terms for Google Analytics, with Switzerland as the contracting country, so Google handles this data on our instructions and not for its own purposes. Three settings decide what it does not do. Google signals is switched off, so your visit is not joined to a cross-device advertising identity and nothing here feeds ads personalisation. Collection of user-provided data is switched off, so we send Google no email address or other identifier of our own. Sharing of Analytics data with other Google products and services is switched off. Retention is 14 months, for event data and user data alike (section 5).
Microsoft Clarity. This is the most privacy-significant of the three, so it is worth stating plainly rather than in passing. Clarity records your session. It captures the movement of your pointer or finger, how far and how fast you scroll, what you click or tap, how long you spend on a page, and the order in which you move through the site, and it replays that to us as a session recording. It also aggregates those interactions with other visits into heatmaps showing where people look, scroll and click. Masking is set to Clarity's Balanced mode, which masks the text you type and the images on the page while leaving the text we ourselves published visible. In practice that means we can see that you filled in the enquiry form and how long you took over it, but not what you typed into it. The recording is reconstructed from our own page content plus your interactions with it; it is not a video of your screen and it does not reach anything outside this site. Microsoft acts as our processor for this.
Apollo. Apollo exists here to tell us which organisations are reading the site. When it runs, it looks up the network your visit comes from, principally the IP address, against its own database of company networks, and reports back an organisation where it finds a match, together with the pages that were viewed. We use that to see which firms are interested and to follow up with them. It is deliberately set to company level only: person-level identification, which Apollo also offers, is not enabled, so it is not used to work out who you are as an individual. The match is an inference drawn from network data, and it is often absent or simply wrong, particularly on home and mobile connections. Apollo acts as our processor for this.
None of the three receives your name or your email address. Google's collection of user-provided data is off, Clarity masks what you type, and we pass none of them the contents of an enquiry.
If your browser broadcasts a Global Privacy Control or Do Not Track signal, we treat that as a refusal and load none of these three tools, whatever is later clicked in the banner.
Legal basis: your consent, given in the banner (GDPR Article 6(1)(a); the corresponding ground under the FADP). You can withdraw it at any time through "Cookie settings" in the footer. When you do, Google's tags are put back into the denied state immediately and Clarity is told to stop recording; from your next page load, nothing is loaded at all. Withdrawal does not undo what was already collected while consent was in place.
We do not build individual profiles of visitors, we do not combine what these tools collect with the enquiries you send us, and we do not use your data for automated decision-making that produces legal or similarly significant effects.
3. Cookies
The only cookie the site itself depends on is the record of your consent choice, set by the consent banner so that we do not ask you on every page. It is strictly necessary and cannot be switched off. The measurement tools described above set cookies of their own, but only after you have accepted the matching category: Google Analytics and Microsoft Clarity on statistics consent, Apollo on marketing consent. If you load the site location map, Google may set its own cookies at that point. You can give, refuse or withdraw consent at any time through the banner or the "Cookie settings" link in the footer. The names, purposes and lifetimes of the individual cookies are set out in our cookie policy.
4. Who we share data with
We do not sell your personal data. Beyond the providers listed below, we disclose it only where we are required to by law.
- Cloudflare: hosting, content delivery and security for the site; storage of enquiries submitted through the form (including the IP address) as our backstop record; storage of submissions stopped by the anti-abuse checks (also including the IP address); storage of the anti-abuse counters and the technical failure records described in section 5; and the operational logs the platform keeps while it runs the site and the form for us.
- Notion Labs: our working record of enquiries, used to manage follow-up. It holds what you entered plus the page, date and interest you selected. It does not include your IP address.
- Usercentrics A/S (Cookiebot): the consent banner described above. Because the banner is served on every page, this provider receives your IP address and browser information on every page load, including before you have made a choice.
- Our email provider: delivery and storage of messages sent to and from info@dc01sk.com.
- Google: two different things, in two different roles. For Google Analytics, once you have accepted statistics cookies, Google measures how the site is used, on our behalf and on our instructions; it receives your IP address, your browser and device information and the pages you open. For the site location map, and only once that map loads, Google receives your IP address and request data as its own controller, for its own purposes. Neither receives the enquiries you submit through the form.
- Microsoft: session recordings and heatmaps through Clarity, once you have accepted statistics cookies. It receives your IP address, your browser and device information and your interactions with the pages, with the text you type masked.
- Apollo.io: the company-level identification described above, once you have accepted marketing cookies. It receives your IP address and the pages you viewed, and returns an organisation where its database matches the network.
Cloudflare, Notion Labs, Usercentrics, Microsoft, Apollo.io and our email provider process personal data on our behalf, to provide their service to us, and are not permitted to use it for their own purposes. For most of them that rests on the provider's standard terms of service, which include that provider's data processing terms, and which we have not separately negotiated. For Google Analytics we can put it more firmly: we have accepted Google's data processing terms for that service, with Switzerland as the contracting country, which places Google in the role of processor for the data it collects there. That firmer position covers Google Analytics only. Google's handling of the map embed is governed by Google's own terms and privacy policy, not by ours.
Cloudflare, Notion Labs, Google, Microsoft and Apollo.io are United States companies or part of United States groups; Usercentrics is established in the European Union. Where personal data is transferred outside Switzerland and the EU, we rely on the safeguards the provider has put in place. For transfers to the United States, that is the provider's certification under the Swiss-U.S. Data Privacy Framework, which is the framework that applies to us as a Swiss controller, together with the separate EU-U.S. Data Privacy Framework for data covered by the GDPR. Where a provider is not certified under those frameworks, the transfer rests instead on the European Commission's Standard Contractual Clauses, with the adjustments Swiss law requires. Write to us and we will point you to the terms that apply to a given provider.
5. How long we keep it
Form submissions. Each accepted submission is written to our hosting provider's storage as a backstop copy, including the IP address it was sent from. That copy expires automatically one year after it is written.
Anti-abuse counters. The two counters tied to your IP address, one for submission attempts and one for accepted enquiries, are recorded against the current calendar day in UTC and expire when that day ends at 00:00 UTC. They are not measured from your last submission: a counter first written in the evening lasts a few hours, one written just after midnight UTC lasts almost a full day. Very late in the day the storage applies its own short minimum, which can carry a counter a little past midnight. Nothing about the enquiry itself is stored in them.
Technical records of failures. If we cannot copy an enquiry into our working record, we write a short technical record to the same hosting-provider storage, so that the failure is visible to us and not buried in a log file. It holds diagnostic details only: a short reason code, the status code the other service returned, and a reference to the stored backstop copy. It is not a second copy of your enquiry, it does not contain your IP address, and the raw response from the other service is not kept in it. It expires automatically one year after it is written, on the same schedule as the backstop copy.
Submissions stopped by the anti-abuse checks. If the decoy field has been filled in, or the form was completed faster than a person plausibly could, the submission is not passed on to us as an enquiry. We still keep a record of it, in the same hosting-provider storage, because these checks are automatic and can be wrong: without the record, a genuine enquiry stopped by mistake would be lost with no way to recover it. That record is a full copy of what you submitted. It holds the same fields as an enquiry, the page you submitted from, the date and time, and the IP address it was sent from, together with which check stopped it. It expires automatically one year after it is written, on the same schedule as the backstop copy, and you can ask us to erase it sooner (see section 6).
Working record of your enquiry. We keep this for as long as we need it to handle your request and any business relationship that follows. It does not expire automatically: we delete it by hand when it is no longer needed, and in any case when you ask us to (see section 6). It does not contain your IP address.
Email. Correspondence stays in our mailbox for as long as we need it for the matter it concerns, or longer where the law requires us to keep records.
Measurement data. Google Analytics holds both event data and user data for 14 months from your visit and then deletes them. Aggregated reporting figures, which say nothing about any one visitor, outlive that. Microsoft Clarity gives us no retention control at all: session recordings and heatmaps stay available for as long as Microsoft keeps them for the service, and we can neither lengthen nor shorten that. The company-level visit records Apollo produces sit in our Apollo account until we delete them. The cookies these tools set expire on their own separate schedules, which are listed with their durations in the cookie policy; a cookie lifetime is not the same thing as a retention period. You can delete those cookies in your browser at any time, and withdrawing consent stops new ones being set.
Technical data. Hosting and security data is kept for the limited periods our hosting provider applies. Our hosting provider also keeps operational logs of requests to the site and of the code that handles the form, which we can read while investigating errors and abuse; those logs are held for the retention period the provider applies to that service, which it currently measures in days rather than months.
6. Your rights
Subject to the conditions in the GDPR and the FADP, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected, and incomplete data completed;
- have your data erased;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw any consent you have given, at any time, without affecting prior processing.
To exercise any of these rights, email info@dc01sk.com. We answer within one month. You also have the right to lodge a complaint with a supervisory authority: in the EU, your local data protection authority; in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
7. Data security
The site is served over encrypted connections, and we apply appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access. No method of transmission over the internet is completely secure, so we cannot guarantee absolute security.
8. Changes to this policy
We may update this policy to reflect changes to the site or to legal requirements. The date at the top shows when it was last revised.
9. Contact
For any question about this policy or your personal data, contact Jakub Krampl at info@dc01sk.com.