Privacy Policy
Dr. Dusica Lehmann attaches importance to privacy and processes personal data responsibly, transparently and in accordance with applicable Swiss data-protection law. Where applicable, European data-protection rules may also apply.
Last updated: July 2026
Data controller
Switzerland
Main data collected
Main purposes
Privacy contact
Data controller
The data controller responsible for the processing described in this policy is:
Switzerland
Privacy enquiries: contact@dusica-lehmann.ch
Website: https://dusica-lehmann.ch/
Scope of this policy
This policy applies to personal data processed in connection with:
- visits to this website;
- use of the contact form;
- email or professional communications directed to Dr. Dusica Lehmann;
- advisory, speaking, research and collaboration enquiries;
- technical and security data generated by website infrastructure;
- optional analytics or other non-essential services, only when activated with the visitor’s explicit choice.
Principles applied
Personal data is processed in accordance with core data protection principles:
- Transparency: Visitors are informed about how their data is used.
- Purpose limitation: Data is collected for specific, legitimate professional purposes.
- Proportionality & Minimisation: Only data necessary for the stated purpose is requested and processed.
- Security: Appropriate technical measures protect data against unauthorised access.
- Limited retention: Data is kept only as long as necessary or legally required.
Categories of personal data
The following categories of personal data may be processed:
| Category | Examples |
|---|---|
| Identity & Contact data | Full name, email address, phone number (if provided). |
| Professional data | Organisation, job title, industry sector. |
| Enquiry content | Subject line, message body, context of the request. |
| Technical data | IP address, browser type, device information, connection logs. |
| Consent data | Cookie preferences, privacy consent timestamps. |
| Correspondence | Emails, meeting notes, professional exchanges. |
| Administrative data | Billing information, contractual details (if an engagement is accepted). |
Sources of personal data
Personal data may be collected from various sources:
- Directly from the visitor: When filling out a form or sending an email.
- From technical systems: Automatically generated when browsing the website.
- From public sources: Publicly available professional profiles or institutional directories, when relevant to an enquiry.
- From third parties: When an organisation or professional contact makes a direct introduction.
Website and technical data
When you visit the website, technical data is generated automatically. This may include your IP address, the date and time of your visit, the pages visited, the referrer URL, browser type, operating system, device type, approximate technical location (at network level), connection logs, and cookie consent information.
This data is used strictly to operate the website, ensure security, diagnose technical issues, and improve the overall infrastructure.
Contact form and professional enquiries
When you use the contact form, the following fields are collected: full name, organisation, email address, subject, message, and consent confirmation. Technical anti-spam and submission data may also be recorded to ensure the request is legitimate.
Visitors are advised to avoid sending highly confidential files, sensitive personal data, complete research datasets, or commercially sensitive documentation in the initial contact message.
Purposes of processing
Personal data is processed for the following practical purposes:
| Purpose | Data Categories Used |
|---|---|
| Responding to enquiries | Identity, Contact, Enquiry content |
| Assessing advisory, speaking or research opportunities | Identity, Professional, Enquiry content |
| Organising conversations and exchanges | Identity, Contact, Correspondence |
| Preparing proposals or discussions | Identity, Professional, Correspondence |
| Ensuring website security and preventing spam | Technical data |
| Maintaining technical functionality | Technical data, Consent data |
| Complying with legal obligations | Identity, Administrative data |
Basis for processing
Under applicable data protection law, personal data is processed where it is necessary:
- to respond to a specific request initiated by the visitor;
- to take steps prior to entering into an agreement;
- to perform an agreed professional engagement;
- to comply with mandatory legal obligations;
- to protect legitimate interests, such as ensuring website security and maintaining professional administration;
- on the basis of consent, where explicit consent is required (e.g., optional cookies).
European data protection rules (GDPR) may also apply, but only where their territorial scope is legally met.
No automatic engagement
Submitting a form, sending an email, or engaging in initial correspondence does not automatically create an advisory, consulting, or contractual relationship. An engagement exists only after an explicit written agreement is established.
No sale of personal data
Personal data is treated with strict confidentiality. It is neither sold nor rented to third parties under any circumstances.
Automated decisions and profiling
This website does not currently use automated decision-making processes that produce legal or similarly significant effects for visitors. Furthermore, no behavioural advertising profile is currently created through the use of this website.
Technical service providers
To operate the website securely and efficiently, certain technical service providers are utilised. These providers may access limited data only when technically necessary for maintenance, diagnostics, security, or support, and may not use it for their own independent purposes.
Climbee SA
Climbee SA provides website design, technical maintenance, support, optimisation, and development.
Climbee SARue du 31-Décembre 41, 1207 Geneva, Switzerland
UID: CHE-403.333.807 | climbee.ch
Infomaniak
Infomaniak provides domain-name registration and DNS-related services essential for the website's availability.
LeadConnector
LeadConnector provides parts of the website infrastructure, form processing capabilities, communications routing, and related technical functions to ensure enquiries are securely delivered.
Media-storage and CDN providers
Images, animations, and media assets may be stored or delivered using cloud-storage and content-delivery network (CDN) services. These providers process technical data (such as IP addresses) required to route and deliver the visual content to the visitor's browser.
Recipients and disclosures
Personal data may be disclosed only:
- to the technical providers listed above, strictly as necessary to operate the website;
- to professional advisers (e.g., legal or financial) where necessary and under confidentiality;
- to competent authorities where legally required;
- to contractual partners, only where necessary for an explicitly requested service;
- to protect legal rights, defend against claims, or ensure website security.
International processing
While the publisher is based in Switzerland, some technical providers or their subcontractors may process data outside Switzerland. Where data is transferred internationally, appropriate legal safeguards are used as required by applicable law. These safeguards may include recognised adequacy frameworks, standard contractual clauses, or other lawful transfer mechanisms.
Analytics and marketing
No optional analytics, advertising, or behavioural marketing technology is currently active on this website. Should such technologies be introduced in the future, they will not be activated without the visitor’s prior explicit choice where consent is required.
Retention
Personal data is retained only for as long as reasonably necessary for the purposes outlined.
| Data Category | Retention Criterion |
|---|---|
| Contact enquiries | Kept for as long as necessary to respond and manage the professional exchange. |
| Accepted engagements | Kept for the duration of the engagement and applicable administrative or legal retention periods (e.g., 10 years for accounting records in Switzerland). |
| Correspondence | Archived or deleted when the professional context concludes. |
| Technical logs | Retained only as long as reasonably necessary for security diagnostics. |
| Consent preferences | Retained for the period required to remember the visitor’s choice (typically 6 months). |
Security
Reasonable technical and organisational measures are implemented to protect personal data. These include HTTPS secure connections, access controls, restricted administrative access, technical monitoring, backups where available, maintenance and updates, and protection against spam and misuse.
However, no internet transmission or digital storage system can be guaranteed as completely risk-free.
Data breaches
In the event of a data security breach that creates a legally relevant risk to the rights and freedoms of individuals, appropriate assessment, mitigation, and notification measures will be taken in accordance with applicable data protection laws.
Individual rights
Depending on applicable law, individuals may have the right to request:
- Information and Access: To know what data is held about them.
- Correction: To rectify inaccurate or incomplete data.
- Deletion: To request erasure of data where it is no longer necessary.
- Restriction and Objection: To limit or object to certain processing activities.
- Portability: To receive data in a structured format, where applicable.
- Withdrawal of consent: To withdraw consent for future processing at any time.
Exercising rights
To exercise these rights, please contact:
Please note that reasonable identity verification may be requested before fulfilling a request to ensure data security.
Complaints
Individuals have the right to contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) if they believe that their data-protection rights have not been respected in relation to the processing of their personal data.
Children
This website is intended for professional and adult audiences. It is not designed to collect data knowingly from children.
External websites
This website may contain links to external websites. This Privacy Policy does not apply to those external resources, which are governed by their own privacy practices.
Policy updates
This Privacy Policy may be updated periodically to reflect changes in the website, professional services, technical providers, or applicable law. The "Last updated" date at the top of the page indicates the current version.
Contact
Questions concerning this Privacy Policy or the processing of personal data may be sent to:
