Privacy Policy
1. Introduction
ISC Executive Services GmbH takes the protection of your personal data seriously. This Privacy Policy explains which personal data we process in connection with our website isces.com and the services offered through it, the purposes for which such data is processed, and the rights available to you.
As a company based in Switzerland, ISC Executive Services GmbH is generally subject to the Swiss Federal Act on Data Protection (FADP). Where we specifically offer services to individuals in the European Union or the European Economic Area and the relevant legal requirements are met, the General Data Protection Regulation (GDPR) also applies.
Mandatory data protection provisions of other jurisdictions remain reserved to the extent that they are applicable to the specific processing activity.
2. Data Controller
ISC Executive Services GmbH
Jacob Burckhardtstrasse 20
4052 Basel, Schweiz
Email for data protection enquiries: info@isces.com
3. General Information / Personal Data We Process
We process, in particular, the following categories of personal data:
- Information you provide to us via the contact form or when booking an appointment (e.g. name, email address, message, preferred appointment time)
- Information relating to payments (e.g. billing details, transaction data)
- Information you provide when requesting free content or subscribing to newsletters (e.g. name and email address)
- Information and documents you provide to us after booking or in connection with our advisory services, including questionnaires and documents (e.g. information relating to relocation, residence, housing, employment and family circumstances), to the extent necessary for the requested service
- Technical data that is generated automatically when you visit the website, in particular server log files (e.g. IP address, date and time of access, pages accessed, browser used). This data is generated as part of operating the website, is used to ensure the security and stability of the website, and is not used to identify individual visitors.
4. Scope
This Privacy Policy describes the processing of personal data in connection with this website and the services offered through it, including enquiries, orders and registrations submitted via the website.
It does not cover processing activities that are unrelated to the website, in particular the processing of employees’ personal data.
5. Recipients of Personal Data
In addition to the service providers specifically mentioned elsewhere in this Privacy Policy (including hosting, appointment booking, payment processing, email delivery, accounting, security, file storage and internal collaboration), the following parties may have access to your personal data:
- Web agency / webmaster: Access in connection with the technical support, maintenance and operation of the website.
- Trustee / accounting provider: Access in connection with bookkeeping, invoicing and tax-related obligations.
These parties process personal data only to the extent necessary for the performance of their respective tasks.
6. Hosting / Website Operation
Our website is hosted and operated on the Vercel platform (USA), which provides the technical infrastructure and delivery of the website. In this context, technical data and server log files in particular may be processed.
Network Solutions (USA) is used as the domain registrar for isces.com. Network Solutions is not the hosting provider of the website; however, administrative and technical domain-related data may be processed in connection with domain management.
Where personal data is transferred to the United States in connection with Vercel or Network Solutions, such transfers are made on the basis of an applicable adequacy mechanism or appropriate safeguards, in particular Standard Contractual Clauses in accordance with Art. 16 para. 2 lit. d of the revised Swiss Federal Act on Data Protection (revFADP).
Despite such safeguards, access by US authorities cannot be completely excluded.
7. Purpose of Processing
We process personal data for the following purposes:
- Operation, security and functionality of the website
- Responding to contact enquiries
- Appointment booking and appointment management
- Processing payments
- Providing and delivering requested content, in particular our free Relocation Checklist
- Sending newsletters and marketing emails to individuals who have consented to receiving them
- Technical delivery of emails and other communications in connection with our website and services
- Accounting, invoicing and order administration
- Providing our advisory and support services and processing the questionnaires and documents submitted for these purposes
- Internal collaboration, file storage and email communication
- Protecting the website against misuse, bots and spam
Legal Bases under the GDPR, Where Applicable
Where the GDPR applies, we rely, depending on the relevant processing activity, in particular on the following legal bases:
- Contact enquiries: Art. 6(1)(b) GDPR where the enquiry relates to taking steps prior to entering into a contract or to the performance of a contract; otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to general enquiries)
- Appointment booking, service-related questionnaires and provision of our services: Art. 6(1)(b) GDPR
- Payment processing and invoicing: Art. 6(1)(b) GDPR
- Newsletters and marketing emails: Art. 6(1)(a) GDPR (consent)
- Legally required accounting and record-keeping obligations: Art. 6(1)(c) GDPR
- Operational security, hosting, IT infrastructure and internal collaboration: Art. 6(1)(f) GDPR (legitimate interest in maintaining secure, stable and functional business operations)
8. Cookies & Tracking
Our website uses technically necessary cookies and similar technologies as well as, where applicable, additional services that may require your consent.
Where consent is required, we obtain it through a cookie consent banner. Non-essential services are only activated after you have provided your consent. You can change or withdraw your choices at any time through the relevant cookie settings.
The choices you make in the cookie consent banner are stored as evidence of your consent or refusal. This information is stored within our Google Workspace environment, in particular in Google Drive.
Cal.com is used in connection with appointment booking. Where the specific technical integration uses cookies or comparable technologies that require consent, Cal.com will only be activated after the relevant consent has been given.
Cloudflare Turnstile is used to protect the website against bots and spam and is required for the secure operation of the website. This service may be used without consent to the extent that this is technically necessary and permitted under applicable data protection law.
Resend is used for the technical delivery of emails and communications and, where you have subscribed accordingly, for newsletters and marketing emails. Resend is not, in itself, a cookie or tracking service.
9. Services Used in Detail
Cal.com
Purpose: Appointment booking and appointment management. When you book an appointment through our website, your name, email address and preferred appointment time are transmitted to Cal.com.
Location of processing: Germany (EU) and the United States. The EU-related processing is based on the Swiss Federal Council’s list of countries (Annex 1 to the Data Protection Ordinance), according to which the European Union provides an adequate level of data protection. To the extent that personal data is also transferred to the United States, the transfer is based on the Swiss-U.S. Data Privacy Framework where Cal.com is certified under that framework; otherwise, Standard Contractual Clauses are used pursuant to Art. 16 para. 2 lit. d revFADP.
Cloudflare Turnstile
Purpose: Protection against bots and spam.
Provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.
Location of processing: United States. To the extent that Cloudflare is certified under the Swiss-U.S. Data Privacy Framework, transfers are based on that framework; otherwise, Standard Contractual Clauses are used pursuant to Art. 16 para. 2 lit. d revFADP. This service is technically necessary for the operation of the website and does not require consent.
Stripe
Purpose: Payment processing.
For customers outside North and South America, the contracting entity is Stripe Payments Europe, Limited, One Wilton Park, Dublin 2, Ireland (parent company: Stripe, Inc., USA).
As Stripe Payments Europe, Limited is established in Ireland, the Swiss Federal Council’s list of countries (Annex 1 to the Data Protection Ordinance) applies to the EU-related processing, according to which Ireland, as a Member State of the European Union, provides an adequate level of data protection.
For transfers to the United States, Stripe relies on the Swiss-U.S. Data Privacy Framework.
Resend
Purpose: Technical delivery of emails and communications in connection with our website and services, in particular for contact enquiries, the delivery of requested content and, where the relevant consent has been given, newsletters and marketing emails.
The provider is Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA.
In this context, in particular your name, email address and the content of the relevant communication may be processed. Resend generally processes customer data in the United States.
For transfers from Switzerland, Resend’s Data Processing Addendum provides for Standard Contractual Clauses with the amendments required for Switzerland. For data transfers from the European Union, the EU-U.S. Data Privacy Framework may additionally apply.
Consent to receive newsletters may be withdrawn at any time with effect for the future, in particular by using the unsubscribe link contained in the relevant marketing email.
Invoice2go
Purpose: Accounting, invoicing and order administration.
Location of processing: United States. To the extent that Invoice2go is certified under the Swiss-U.S. Data Privacy Framework, transfers are based on that framework; otherwise, Standard Contractual Clauses are used pursuant to Art. 16 para. 2 lit. d revFADP.
Google Workspace
Purpose: Collaboration, file storage, email communication and storage of operational data.
Data submitted through certain functions of our website may be stored in Google Drive via a technical service account.
For customers with a billing address in Europe, the Middle East and Africa, excluding France, Italy and Poland, the contracting entity is Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland. For the EU-related processing, the Swiss Federal Council’s list of countries (Annex 1 to the Data Protection Ordinance) applies.
Data may also be processed within the Google group of companies in the United States. To the extent that Google is certified under the Swiss-U.S. Data Privacy Framework, transfers to the United States are based on that framework; otherwise, Standard Contractual Clauses are used pursuant to Art. 16 para. 2 lit. d revFADP.
10. Processing Activities
Email Contact
If you contact us by email, we process the information you provide, in particular your email address, the content of your message and, where applicable, any additional information you voluntarily provide, in order to process and respond to your enquiry. Communication takes place via our Google Workspace infrastructure.
Download of the Free Checklist / Newsletter Subscription
If you request our free Relocation Checklist through our website, we process your first name and email address in order to send you the requested checklist.
Where you have additionally consented to receiving newsletters and marketing emails, we also use your email address for this purpose. Resend is used for the technical delivery of these communications.
The data generated in this context is stored within our Google Workspace environment and/or in Google Drive.
Questionnaires and Documents in Connection with Our Advisory Services
After a booking or during the course of an advisory engagement, we may send you questionnaires or ask you to provide documents that are necessary for the requested relocation, residence, housing, citizenship or other advisory service.
The information and documents you provide are processed for the preparation and provision of the commissioned service and may be stored within our Google Workspace environment, in particular in Google Drive.
Please only provide information and documents that are necessary for the relevant advisory service.
Appointment Booking
You can book an appointment with us directly via Cal.com. In this context, we process your name, email address and selected appointment time, as well as any additional information you may provide in the booking form.
This information can be accessed by the relevant persons at ISC Executive Services GmbH who are responsible for conducting the appointment.
Payment Processing
Payments are processed via Stripe. Payment details, such as card information, are processed directly by Stripe. We receive confirmation and transaction data required to process the transaction and to comply with our accounting obligations.
11. Rights of Data Subjects
Under the revFADP, you have, in particular, the following rights:
- The right to obtain information about the personal data we process concerning you (Art. 25 revFADP)
- The right to have inaccurate data corrected (Art. 32 para. 1 revFADP)
- The right to request the deletion or destruction of data
- The right to receive or have your data transferred in a commonly used electronic format (Art. 28 revFADP)
- The right to object to certain processing activities
- The right to request that disclosure to third parties be blocked or that a note of dispute be added to the relevant data (Art. 32 paras. 2 and 3 revFADP)
Where the GDPR applies, data subjects additionally have, in particular, the right to data portability (Art. 20 GDPR), the right to object (Art. 21 GDPR), the right to restriction of processing (Art. 18 GDPR), and the right to lodge a complaint with a competent data protection supervisory authority.
To exercise these rights, you may contact us at info@isces.com.
You may also contact the Federal Data Protection and Information Commissioner (FDPIC) at any time or submit a report to the FDPIC pursuant to Art. 49 revFADP:
Eidgenössischen Datenschutz- und Öffentlichkeitsbeauftragten (EDÖB), Feldeggweg 1, 3003 Bern, edoeb.admin.ch
12. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or unauthorised alteration. These measures include, in particular, the use of service providers with appropriate security standards, encrypted data transmission where technically supported, and appropriate access and authorisation controls.
According to their own information, the IT service providers we use, in particular Vercel, Google Workspace and Resend, implement technical security measures such as encryption during data transmission and, in some cases, encryption of stored data.
Despite appropriate security measures, absolute protection against all risks associated with electronic data transmission and storage cannot be guaranteed.
Where the GDPR applies, we notify the competent supervisory authority of personal data breaches where and to the extent required by law.
13. Retention / Storage Period
We generally retain personal data only for as long as necessary for the relevant processing purposes, as required by statutory retention obligations, or where legitimate business interests justify further retention.
Client files may be archived after completion of an engagement and retained for a longer period, particularly where the documents they contain may be relevant for future follow-up engagements, departure or return processes, evidence of services previously provided, or the establishment, exercise or defence of legal claims.
We retain only those data for which continued storage appears appropriate for these purposes. Archived data is not used on an ongoing basis, but is generally accessed again only in connection with a new engagement, a legitimate enquiry, or for legal or administrative reasons.
We retain accounting records and supporting documents in accordance with applicable statutory retention requirements.
Newsletter data is generally processed for as long as the subscription remains active. Following an unsubscribe request, such data will be deleted or blocked unless statutory obligations or legitimate grounds justify further retention.
We do not guarantee that historical client files will remain complete and available indefinitely. Long-term archiving does not create any entitlement to the permanent or complete availability of all historical documents.
14. Contakt / Data Protection Inquiries
If you have any questions about this Privacy Policy or the processing of your personal data, please contact:
ISC Executive Services GmbH
Jacob Burckhardtstrasse 20
4052 Basel, Schweiz
E-Mail: info@isces.com
15. Last Updated
This Privacy Policy was last updated on 26 August 2026.