Privacy Policy
Last updated 8 August 2026
This policy explains what personal data Prospex processes, why, and what you can do about it. It is written under the Swiss Federal Act on Data Protection (FADP / revDSG). Where the GDPR applies — to visitors in the EU and to people in the EU who appear in the public register data we process — it applies in addition, and this policy is written to satisfy both.
Prospex is a business-to-business service. Almost all of the data it handles is about companies. Some of it is nonetheless personal data, because a company officer named in an official register is a person, and this policy is specific about that.
1. Who is responsible
The controller is:
Sidorenko Consulting
Semion Sidorenko
Chemin du Frêne 7
1004 Lausanne
Switzerland
For anything in this policy, write to [email protected]. We have not appointed an EU representative under GDPR art. 27.
2. If you have a Prospex account
We hold the following about our customers:
- Account — your email address, which is also your username, a hashed password (never the password itself), the date you signed up and the date you last signed in.
- Preferences — the description of what you sell, and the sectors, company sizes, cantons and customer audiences you filter on, plus the job role you selected during onboarding.
- Use of the service — the leads you have marked as reviewed, the searches you have saved, the feedback you have given on individual leads, the companies you follow, and your email digest settings.
- Billing — your Stripe customer and subscription identifiers, your subscription status and the end of the current period. No card data ever reaches Prospex; payment details are entered on Stripe's own pages and stay with Stripe.
- HubSpot — if, and only if, you connect your HubSpot account, we store the access tokens for that connection and records of what we have written to your CRM.
- Server logs — ordinary web-server and application logs, including IP addresses, kept for operations and security.
The purpose is providing the service you signed up for, and the legal basis is the contract between us (GDPR art. 6(1)(b) / FADP art. 31(2)(a)). Billing records are also kept to meet Swiss accounting obligations.
3. Company and register data about other people
This is the section that matters if you have never used Prospex but have found yourself in it.
Prospex collects publicly available information about Swiss companies and turns it into sales signals for its customers. Where the Swiss commercial register publishes them, that information includes the names, functions and signing authority of company officers — directors, managing directors, partners, and authorised signatories. These names come from official public notices, and they can appear in the signal headlines we show to our customers, for example "New managing director appointed".
All of it comes from publicly accessible sources, of the following kinds: the Swiss commercial and intellectual-property registers and the official gazettes that publish their notices, both federal and cantonal; publicly advertised job vacancies; public company websites and the public pages and posts companies publish about themselves on social and professional networks; and public business directories and startup listings. We do not buy personal data from data brokers, and we do not collect anything that requires signing in to see.
The legal basis is our legitimate interest, and our customers' legitimate interest, in commercial information about businesses (GDPR art. 6(1)(f) / FADP art. 31(1) and 31(2)(e)). We have weighed that against the interests of the people concerned. In our assessment it prevails because: the data has already been published officially, by law, precisely so that the public can rely on it; we process it only in a person's professional capacity, as an officer of a company; we do not build behavioural profiles of individuals, infer anything about their private life, or process any special categories of data; and the volume held about any one person is a name, a role and a date.
You can object to this processing at any time by writing to [email protected]. Tell us the name and the company and we will remove the entry from what our customers see. If you want to know which source a particular entry came from, ask us and we will tell you. Objections are handled manually today — see section 7 on retention for why the underlying source archive is treated differently.
We also use large language models, through the gateway named in section 5, to summarise and classify this material. They generate the wording of a signal; they do not make decisions with a legal or similarly significant effect on anyone.
4. Analytics
Every page of this site, including the public ones, loads PostHog (PostHog EU Cloud). Your browser sends this data to g.prospex.ch, a domain of ours that forwards it to PostHog's European infrastructure; the recipient is PostHog either way. It records page views and interactions and sets cookies in your browser. If you are signed in, we additionally send PostHog your user id, your email address and your username, so that product usage can be attributed to an account.
Our servers also send PostHog the steps of the signup and subscription process — that an account was created, that the subscription page was shown, that a checkout was started, and that a subscription started, renewed or changed status, with the amount invoiced. Your current subscription status is stored against your profile there. No card details ever reach PostHog; those are held only by Stripe (section 5).
We also run the Reddit advertising pixel and report conversions to Reddit from our servers. The pixel loads on every page, sets a first-party _rdt_uuid cookie in your browser and reports that a page was viewed. Separately, our servers tell Reddit that an account was created, that a checkout was started, and that a subscription started — the last with the amount invoiced — together with a hashed (SHA-256) form of your email address, a hashed account identifier, your IP address, your browser's user agent, and the Reddit click id from the ad you arrived through. Reddit never receives your email address in readable form, and never receives card details.
We run the Google Ads tag on the same terms. It loads on every page, and sets first-party cookies beginning _gcl that record the click id of the ad you arrived through — which is what lets a signup weeks later be attributed to it. When you create an account, start a checkout or start a subscription, the tag reports that event to Google, the last with the amount invoiced, along with a hashed (SHA-256) form of your email address. As with Reddit, Google never receives your address in readable form, and never receives card details. Unlike Reddit, nothing here is sent from our servers: if you decline marketing cookies the event is held unreported and deleted after 30 days.
The basis is legitimate interest in understanding how the product is used and which advertising works. Both categories are covered by the cookie banner you see on your first visit: under Swiss data protection law they start switched on and the banner is notice rather than a gate, so you can turn either Analytics (PostHog) or Marketing (Reddit Ads and Google Ads) off at any time and we will stop. Necessary cookies — signing in, your session, and the record of this choice — always run. Your choice is kept in a prospex_consent cookie for 180 days. . PostHog is also where our internal observability data about model calls is sent.
5. Who else processes the data
We use the following providers. They act on our instructions and are bound by data-processing terms.
| Provider | Purpose | Where |
|---|---|---|
| Hetzner | Server hosting | Finland (EU) |
| Cloudflare | DNS, CDN and web application firewall | Global |
| PostHog | Product analytics | EU |
| SparkPost (via Anymail) | Transactional email | EU |
| Stripe | Payments and subscription billing | EU / US |
| OpenRouter | LLM gateway, routing to Qwen, OpenAI, Google and Anthropic models | US |
| Bright Data | Public web data collection | Global |
| fastCRW | Web page fetching and extraction | Global |
| DataForSEO | Search-result data | Global |
| HubSpot | CRM sync — only if you connect it | EU / US |
| Reddit (Reddit Ads) | Advertising measurement | US |
| Google (Google Ads) | Advertising measurement | US |
Our database, search index and job scheduler run on our own server; they are not third parties. We do not sell personal data, and we do not share it with anyone outside this list except where the law requires it.
6. Transfers outside Switzerland and the EU
Hosting and the two EU-region services above keep data in Europe. Stripe, OpenRouter, Reddit and Google involve processing in the United States, and the collection providers operate globally. Those transfers rely on the European Commission's Standard Contractual Clauses, on the Swiss–US Data Privacy Framework where the recipient is certified, and on the corresponding recognition under Swiss law.
7. How long we keep things
Account data is kept for as long as you have an account, and afterwards only where a legal retention period requires it — invoicing records, for instance, for ten years under Swiss commercial law. Close your account and write to us and we will delete the rest.
Data collected from the public sources in section 3 is kept in an append-only archive: the raw documents we fetched and the records extracted from them are never rewritten, because reprocessing the original evidence is what lets us correct a mistake later. We would rather say that plainly than promise a deletion the pipeline cannot perform. What we can and do act on is the visible layer: on an objection or a correction request we remove or fix what our customers see.
8. Your rights
You have the right to:
- ask what personal data we hold about you, and get a copy
- have inaccurate data corrected
- have data deleted, within the limits described in section 7
- object to processing based on legitimate interest, including the register data in section 3
- receive data you gave us in a portable form
- withdraw any consent you have given, without affecting what was done before
Write to [email protected]. We respond within 30 days. Exercising these rights is free, and we will not treat you differently for it.
If you are not satisfied, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC, Feldeggweg 1, 3003 Bern), or to the supervisory authority of your EU member state.
9. Security
All traffic to the site is served over TLS. The origin server sits behind Cloudflare and accepts web traffic only from it; the database listens on the local interface only and is not reachable from the internet. Passwords are stored as salted hashes and are never recoverable, by us or by anyone else. Administrative access is limited to the owner.
We do not claim that stored data is encrypted at rest. No system is perfectly secure, and we say what we actually do rather than what sounds reassuring.
10. Changes
We will update this policy when the service changes. The date at the top is the version in force. Material changes affecting customers are announced by email.