Legal
Privacy Notice
Last updated: 18 July 2026
This notice explains how Dr Michael Gerlich ("we", "us") processes personal data in connection with this website (thfmg.com). We aim to comply with the Swiss Federal Act on Data Protection (revFADP) and, where applicable, the EU General Data Protection Regulation (GDPR), and to respect the principles of the EU AI Act.
1. Controller
Dr Michael Gerlich, Walchwil-Zug, Switzerland, is the controller for personal data processed through this website.
Contact for privacy matters: michael.gerlich@THFMG.com
2. What data we collect ourselves
We only collect personal data that you actively submit to us through the contact form on this website. This includes:
- Your name
- Your email address
- Any organisation or subject line you choose to provide
- The content of your message
We do not use tracking cookies, we do not run our own web analytics, and we do not attempt to profile visitors.
3. Purposes and legal basis
- Responding to your enquiry — to read your message and reply. Legal basis: steps taken at your request prior to entering into a contract, and our legitimate interest in handling enquiries (GDPR Art. 6(1)(b) and (f); revFADP art. 31).
- Speaking, advisory and publication requests — to evaluate and administer possible engagements you initiate. Legal basis: pre-contractual steps and legitimate interest.
- Legal compliance — to comply with applicable accounting, tax and record-keeping obligations where a contract results. Legal basis: legal obligation (GDPR Art. 6(1)(c)).
4. Retention
- Contact form messages: kept for as long as needed to handle your enquiry and any follow-up, and deleted at the latest 24 months after the last contact.
- Records of contracted engagements (speaking, advisory, publications): kept for up to 10 years to meet Swiss bookkeeping obligations.
5. Recipients and processors
We do not sell personal data. We share it only with service providers that process data on our behalf, or where legally required:
- Lovable Cloud (Supabase) — hosts the database and edge functions used to receive contact form submissions, in the EU region.
- Resend — delivers contact form messages by email to us so we can reply to you.
- Lovable (hosting and publishing platform) — serves the website. Lovable and its infrastructure partner Cloudflare process standard technical request data (IP address, user agent, timestamp, requested URL, approximate country, performance metrics) for security, delivery and platform-level analytics. Retention and further details are governed by Lovable's and Cloudflare's own privacy policies.
- Google Fonts — web fonts are loaded from Google's servers, which receive your IP address when a page loads.
- GoDaddy — provides the domain registration and DNS for thfmg.com.
6. International transfers
Some of the processors above are based outside Switzerland and the EEA (in particular the United States). Where this is the case, transfers are covered by standard contractual clauses, the EU–US Data Privacy Framework or equivalent safeguards recognised under revFADP and GDPR.
7. Cookies and tracking
This website does not set any cookies for marketing, advertising or cross-site tracking. Any cookies or local identifiers that may be set are strictly technical (e.g. by Cloudflare for security purposes). No consent banner is displayed because we do not use non-essential cookies.
8. Your rights
Under revFADP and GDPR you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Request deletion of your data, subject to legal retention
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, in the EU, your local supervisory authority
To exercise these rights, contact michael.gerlich@THFMG.com.
9. AI Act principles
Consistent with the principles of the EU AI Act, we do not use your personal data to train AI systems, to profile you or to make automated decisions that produce legal or similarly significant effects.
10. Security
Data is stored on managed infrastructure with encryption in transit (HTTPS) and at rest. Access to contact form submissions is restricted to Dr Michael Gerlich.
11. Changes to this notice
We may update this notice to reflect changes in our practices or in applicable law. The "Last updated" date at the top of this page indicates when it was last revised.