Privacy by design. VILEXI uses Google Consent Mode with analytics and advertising storage denied by default. Limited cookieless measurement signals may be sent before a choice; analytics identifiers and full optional analytics are enabled only after express consent. A job draft stays on the advertiser's device until the advertiser starts secure checkout.
01Controller and scope
The controller responsible for VILEXI is Sascha Gallinat Vilekzi, operating under the VILEXI brand, Hauptstrasse 21, 8280 Kreuzlingen, Switzerland. Contact: support@vilexi.com.
This policy applies to vilexi.com, paid job-listing services, direct application delivery and communications with VILEXI. It is based on the Swiss Federal Act on Data Protection. Where the EU or UK GDPR applies to a particular activity, VILEXI also respects the applicable requirements under those laws.
02Data we process
| CONTEXT | DATA |
|---|---|
| Website use | IP address, date and time, requested page, browser/device and request or security metadata. |
| Audience analytics | Before consent, limited cookieless signals may include consent state, timestamp, user agent, referrer, page information and a random number. After analytics consent, page and event data, approximate country, device/browser category, campaign parameters, session and conversion information may also be processed. |
| Advertiser draft | Job title, description, location, schedule, requirements, company name and business email. |
| Checkout and billing | Contact and billing details, selected product, payment status, transaction identifiers, tax information and fraud-prevention data. Stripe—not VILEXI—receives full card or bank-account details. |
| Direct applications | Name, role, company, business email, optional phone and website, country, proposed system, profile link, capabilities, fit and availability. |
| Support | Contact details, message, related order or application reference and information you choose to provide. |
| Public market consultations | Organisation type, consultation classification, publication and expiry dates, submitted questions, official answers, response records, change history and relevant timestamps. Pending questions are visible only to authorised users until answered and published. |
| Compliance evidence | Cryptographic hashes, immutable event records, evidence-package metadata, verification codes, archive retention dates and—where configured—third-party timestamp responses. Public verification reveals package metadata but not confidential package contents. |
Do not submit health information, identity documents, financial data, trade secrets or other sensitive personal data in a job description or application.
03Purposes and legal bases
VILEXI processes personal data to provide the website and requested services; prepare and perform contracts; deliver applications; manage checkout, billing, refunds and support; prevent misuse and fraud; comply with legal duties; and establish, exercise or defend legal claims.
Depending on the context, processing is based on performance of a contract or pre-contractual steps, your request or consent, compliance with legal obligations, and VILEXI's legitimate interests in operating a secure and reliable B2B service. Consent may be withdrawn for future processing at any time.
04Direct applications
No account is required. The application is first displayed for review in your browser. Nothing is transmitted until you select the forwarding checkbox and press the final send button.
VILEXI stores the complete application securely so the named advertiser can review it in its employer dashboard. VILEXI also uses Brevo to send the application directly to that advertiser and a separate copy to the applicant. VILEXI receives no hidden inbox copy. The advertiser is an independent controller for its assessment, communications and retention; its own privacy information applies.
VILEXI also processes a technical fingerprint, request identifier and delivery status to prevent duplicates and provide a reliable application record. The applicant's IP address is used temporarily for rate limiting, normally for no more than 10 minutes. Brevo may retain message and delivery metadata under its own retention rules.
05Stripe payments
VILEXI uses Stripe for hosted one-time checkout, signed payment confirmation, fraud prevention and refunds. When an advertiser starts checkout, VILEXI stores the selected package, job listing and business contact details so the order can be matched securely to Stripe's payment status. Stripe processes the information entered in Checkout and may set its own necessary cookies or similar technologies. VILEXI may prefill the advertiser's business email.
Stripe may act as an independent controller for parts of its payment, compliance and fraud-prevention services. VILEXI receives or can access customer, payment-status and transaction records, but not full card numbers or bank credentials. See Stripe's Privacy Policy.
Purchase confirmations and reminders about unused credits six months and 14 days before expiry are transactional service messages required to administer the purchased package. Optional monthly VILEXI marketing emails are sent only after a separate opt-in, always include an unsubscribe option, and can be stopped without affecting payment, account, application or expiry messages.
06Local storage and cookies
Where configured, VILEXI uses Cloudflare Web Analytics for privacy-oriented, cookieless audience measurement. This service provides aggregate information about visits, pages, approximate country, device category and website performance and is not used by VILEXI to identify individual visitors.
VILEXI uses Google Analytics 4 with advanced Consent Mode. The Google tag is present with analytics storage, advertising storage, advertising user data and advertising personalisation denied by default. In this denied state, Google may receive limited cookieless measurement and consent signals but VILEXI does not permit analytics cookies or identifiers. After the visitor expressly accepts analytics, Google Analytics may store or access analytics identifiers and measure page views, sessions, referrers, campaigns, interactions, funnel steps and conversions. Google Signals and advertising personalisation remain disabled. The choice is stored locally with its version and timestamp and may be changed at any time through “Privacy settings” in the footer.
VILEXI does not permit analytics tools to receive passwords, login codes, payment credentials, support messages, application text, unpublished consultation questions or other form contents. VILEXI does not use analytics data for cross-site advertising or sell it to third parties.
The advertiser flow uses local storage to save the job draft and selected plan on the device while the form is being prepared.
The locally stored draft is transmitted to VILEXI only when the advertiser actively starts secure checkout. VILEXI removes the local copy after confirmed payment; it can also be removed by starting over or clearing browser data. External services reached from VILEXI, including Stripe, apply their own cookie practices.
07Recipients and service providers
- Advertisers, when an applicant expressly requests direct delivery.
- Brevo, for transactional application emails and delivery metadata.
- Stripe, for checkout, billing, tax, fraud prevention and refunds.
- Cloudflare and VILEXI's hosting providers, for website delivery, security, operational logs and cookieless aggregate audience measurement.
- Google, for limited cookieless measurement signals before consent and Google Analytics 4 measurement after analytics consent.
- Professional advisers, authorities or courts where required by law or necessary to protect legal rights.
VILEXI does not sell personal data.
08International transfers
VILEXI is based in Switzerland and uses providers with operations and infrastructure in Switzerland, the EEA, the United Kingdom, the United States and other countries. Data may therefore be processed outside your country of residence.
Where a destination is not recognised as adequate, VILEXI or the relevant provider relies on recognised standard contractual clauses, contractual and technical safeguards, or another permitted transfer mechanism. Details may be requested from VILEXI.
09Retention
Personal data is retained only as long as needed for its purpose, disputes, agreements and legal obligations.
- Browser-stored drafts and the analytics-consent record remain under the user's control as described above.
- Analytics data is retained according to the configured provider retention period and is reviewed at least annually; VILEXI aims to select the shortest period compatible with meaningful trend analysis.
- Email marketing preferences and the date of consent or withdrawal are retained while needed to honour and demonstrate that choice.
- Unpaid checkout drafts marked pending, expired or failed are normally deleted by VILEXI after 30 days.
- When an advertiser deletes a listing, it is removed from public view immediately. The underlying purchase record, listing audit record and existing application records may be retained where required for contract performance, accounting, dispute handling, fraud prevention or legal obligations.
- Paid listing, contract, invoice and transaction records may be retained for ten years where required by Swiss accounting or tax law.
- Public-consultation evidence packages and their integrity metadata are assigned a ten-year retention date. Until a certified external archive is connected, this retention is enforced by VILEXI's application controls and must not be described as certified WORM storage.
- Applications and their delivery records are retained while needed for application management, support, fraud prevention and legal claims. Applicants may request deletion subject to legal obligations and legitimate retention needs.
- Short-lived rate-limit records in VILEXI's volatile memory normally expire within 10 minutes.
- Support correspondence is kept as long as needed to handle the request and protect legitimate interests.
Providers and advertisers apply their own retention periods. Backups or legal holds may delay final deletion where necessary.
10Your rights
Subject to applicable law, you may request information, access or a copy, correction, deletion, restriction, data portability, or object to certain processing. You may also withdraw consent for the future.
Send requests to support@vilexi.com. VILEXI may verify your identity and may retain information where permitted or required. You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where applicable, your local data-protection authority.
11Security
VILEXI uses reasonable technical and organisational safeguards, including encrypted transmission, input validation, same-origin controls, rate limiting, restricted secrets and data minimisation. No internet service can guarantee absolute security.
12Children and automated decisions
VILEXI is a business service and is not directed to children. VILEXI does not knowingly collect children's personal data and does not currently make decisions producing legal or similarly significant effects solely through automated processing.
13Changes to this policy
VILEXI may update this policy when the service, providers or legal requirements change. The effective date and version above identify the current text. Material changes will be communicated through the website or another appropriate channel.