Privacy notice

How HICONIUM AG processes information for the public platform and invitation-only membership.

Controller
HICONIUM AG
Place
Zürich · Switzerland
Effective
1 September 2026
Contact
privacy@hiconium.com

What we collect

HICONIUM AG collects information you give us, operational information produced when you use the platform, and the limited measurement information described below. We do not buy data; we do not enrich your profile from third-party brokers; and we do not run programmatic advertising. The information below is the entire list of categories we touch.

Categories of personal data:

  1. Identity — your name, the legal name of your business, an authorised contact, the country and (where applicable) commercial-register number.
  2. Correspondence — the contents of any message you write to us at hello@, press@, privacy@, security@, or legal@hiconium.com.
  3. Application — for the Founding Garage cohort, the details you provide about your collection, marques, and notable vehicles.
  4. Subscription — for the Founders List, the email address you submit to be notified at launch.
  5. Operational metadata — server logs, the IP address used to reach the site, and the user agent of your browser, retained for 30 days for fraud and abuse prevention.
  6. Usage and consent-mode information — your statistics choice; pseudonymous visitor, session and, after consent, signed-in account identifiers; page types and sanitised routes; event names; approved low-cardinality event categories; and limited screen and language information. Before or without consent, Google Advanced Consent Mode receives only limited cookieless measurement and consent-status pings, with analytics storage and all advertising signals denied. Query parameters, external referrers, the original IP address and the raw browser user agent are hidden from Google by the Zaraz configuration.

No third-party data

We do not buy or enrich your profile from data brokers.

Purposes

We process these data only for the purposes below:

  1. To assess invitation-only membership requests and respond to them.
  2. To send requested platform communications.
  3. To respond to direct correspondence and keep a record of the exchange so we can pick up where we left off.
  4. To produce and distribute editorial work to which you have explicitly subscribed.
  5. To understand aggregate use, measure registration, sign-in, onboarding, garage and settings funnels, and find reliability or usability problems through first-party analytics and Google Analytics 4.
  6. To communicate and enforce your analytics choice through Google Consent Mode and produce aggregate measurement from limited cookieless signals when analytics storage is denied.
  7. To meet our legal obligations under Swiss and EU law (revFADP, GDPR), which sometimes require us to retain information beyond your consent.

We do not sell, lease, or rent personal data. We do not run profile-based advertising. We do not feed personal data into third-party AI models for training, fine-tuning, or evaluation.

No AI training

Personal data is never fed into third-party model training, fine-tuning, or evaluation.

Legal basis

Different categories sit on different legal bases. Founding Garage applications run on the contract we are negotiating with you (Art. 6(1)(b) GDPR; Art. 31 revFADP). The Founders List runs on consent (Art. 6(1)(a) GDPR; Art. 5(6) revFADP). Operational logs and security records run on legitimate interest (Art. 6(1)(f) GDPR; Art. 31(1)(c) revFADP). Where we are required to retain information by Swiss commercial law, we do so on legal obligation (Art. 6(1)(c) GDPR; Art. 31(1)(c) revFADP).

Browser statistics, session replay, Google Analytics storage and pseudonymous account-level measurement run only on your consent (Art. 6(1)(a) GDPR; Art. 5(6) revFADP). The daily-changing server-side visit count and the limited cookieless Google Consent Mode pings used for aggregate service measurement run on our legitimate interest in understanding and securing the platform (Art. 6(1)(f) GDPR; Art. 31(1)(c) revFADP). Those pings do not use analytics storage, an account identifier, advertising data, or information you entered. You may object to legitimate-interest processing and refuse or later withdraw statistics consent.

Your rights

You have the following rights at any time, free of charge:

  1. Access — ask us what we hold about you and receive a copy.
  2. Rectification — correct anything that has become inaccurate.
  3. Erasure — ask us to remove your data, subject only to legal retention obligations.
  4. Restriction — ask us to pause processing while we resolve a dispute.
  5. Objection — refuse processing where we are relying on legitimate interest.
  6. Portability — receive your data in a structured, machine-readable format.
  7. Withdraw consent — stop any processing that depends on your consent, with immediate effect for future processing.
  8. Lodge a complaint — with the Swiss Federal Data Protection Commissioner (FDPIC) or, in the EU, your local supervisory authority.

Write to privacy@hiconium.com or to HICONIUM AG, Privacy, Badenerstrasse 567, 8048 Zürich, Switzerland. We will acknowledge within five business days and resolve within thirty.

Processors & transfers

Hiconium is operated from Switzerland. Some of the technical infrastructure that keeps the platform running — hosting, content delivery, analytics tag delivery, Google Analytics and transactional email — is provided by partners with operations in the European Economic Area and, in limited cases, in the United States. Where that is the case, transfers happen under the European Commission's Standard Contractual Clauses, an applicable Data Privacy Framework certification, or the equivalent Swiss-issued addendum.

A list of our material data processors is published below and updated when it changes. If a processor is added that you would like to know about earlier than the next refresh, write to privacy@hiconium.com.

Hosting · edge delivery · application database · private file storage · analytics tag delivery (Zaraz)

Cloudflare Inc.

United States · Global

Google Analytics 4 · consent-mode measurement

Google Ireland Limited / Google LLC

Ireland · United States · Global

Authentication · account security

Clerk Inc.

United States

Transactional email

Resend

United States

Editorial-assist tooling

Anthropic

United States

Payments (post-launch)

Stripe Inc.

EEA · CH · US

Cookies & analytics

Hiconium uses first-party, strictly necessary browser storage for forms, security, sign-in, display preferences and your consent choice (hiconium:consent). We also count visits server-side without consent through a daily-changing anonymous hash of connection facts, with no cookie, stored IP address, or replay. With statistics consent, our first-party browser analytics use hiconium:analytics:vid for up to 13 months and hiconium:analytics:sid for the session. Session recordings capture navigation, clicks, scrolling, page structure and typed input except passwords, payment details and fields marked private; they remain on Cloudflare infrastructure operated for Hiconium.

We use Google Analytics 4 (measurement ID G-HRQHDWBRKM) through Cloudflare Zaraz in Advanced Consent Mode. Until you accept statistics — and whenever you refuse — analytics_storage is denied. Limited cookieless pings may still carry the consent state, a sanitised page route or type, an event name, an approved coarse event category, and limited screen or language information to Google for aggregate measurement. They contain no stored or reusable Google Analytics or Zaraz client identifier and no Hiconium account identifier. The Google component may generate fresh, ephemeral client and session values for an individual cookieless ping; the denied component cannot store or reuse those values. If you consent, the first-party Zaraz/GA4 storage may create pseudonymous visitor and session identifiers for up to two years and Google may receive pseudonymous page, event, session and signed-in account information. Query parameters, external referrers, the original IP address and the raw browser user agent are hidden from Google. ad_storage, ad_user_data and ad_personalization always remain denied: we do not use Google Ads or personalised advertising.

We never send Google names, email addresses, phone numbers, postal addresses, number plates, VINs, vehicle or garage record identifiers, document contents, typed input, search terms, query strings, share or invitation tokens, file names, or exact location. This restriction applies independently of your statistics choice. First-party analytics events are kept for 13 months, session recordings for 30 days and Google Analytics user-level event data for no longer than 14 months; aggregate reports may remain after identifiers expire. Recordings are accessible only to authorised staff. You can refuse or withdraw statistics consent at any time through the Cookies link in the footer; withdrawal stops future consent-based collection. Google describes how it processes partner-site data at policies.google.com/technologies/partner-sites.

Retention

How long we keep things:

  1. Founding Garage applications — for as long as the cohort is open, plus 24 months after the platform launches, after which they are deleted unless you become a Member.
  2. Founders List subscriptions — until you unsubscribe (a single click in any email we send, or a note to privacy@hiconium.com).
  3. Direct correspondence — for as long as the matter is open, plus 7 years where Swiss commercial-record law requires it.
  4. Server logs and operational metadata — 30 days, then deleted except where investigation is ongoing.
  5. Google Analytics user-level event data — no longer than 14 months; consented first-party Zaraz/GA4 identifiers may remain for up to 2 years. After withdrawal, the cookieless path cannot access them; clearing browser storage removes them from the browser.
  6. Anonymised, aggregated data — indefinitely, for product and editorial improvement; this data does not identify you.

Security

We treat security as part of the design, not an addition. Sensitive member content — title documents, identity papers, contracts, ownership and provenance records — will be encrypted on the member’s device with a passphrase only the member holds (Section 4.2 of the Terms of Service). Hiconium cannot read those documents in their decrypted form. Operational data sits behind authenticated APIs, transport-layer encryption, and access logs.

If you discover a vulnerability, write to security@hiconium.com. We acknowledge within one business day and resolve material issues as quickly as the nature of the issue allows. Responsible disclosure is welcome and credited unless you ask otherwise.

Disclosure

Material vulnerabilities → security@hiconium.com. Acknowledgement within 1 business day.

Contact

Three addresses, each routed to a small inbox we read:

  1. privacy@hiconium.com — anything to do with your data, your rights, or this notice.
  2. security@hiconium.com — vulnerabilities and incident reports.
  3. legal@hiconium.com — formal legal correspondence, court orders, regulator enquiries.

Postal

HICONIUM AG · Privacy · Badenerstrasse 567 · 8048 Zürich · Switzerland

Effective 1 September 2026. Questions about this notice or the information we process: privacy@hiconium.com.