Privacy notice.
This page says what happens to personal data when you read coprod.co, join the early-access list, apply for a job, or order a module. It is written to meet Article 13 GDPR and Article 19 of the revised Swiss Data Protection Act, and to be legible to a person who is not a lawyer. Where the honest answer is uncomfortable, it is here anyway.
This notice is complete in substance but not in fact: the controller has not been identified yet. It must not be published in this state: an unnamed controller is itself a breach of Art. 13(1)(a) GDPR and Art. 19(2)(a) revDSG.
- Fill every {{PLACEHOLDER}} on this page: ten of them, in twelve places.
- Settle the entity question: the footer and the JSON-LD say coprod Inc.; confirm this matches the commercial-register entry. See the long HTML comment at the top of this file.
- Decide on a GDPR Art. 27 EU representative, and say so either way.
- Sign the processor agreements with Vercel, Upstash, Resend, Google and Shopify.
- Re-date the “Last updated” line above.
- Link this page from the footer of all nine templates and add
/privacytositemap.xml. - Delete this block.
- No cookies. There is no cookie banner on this site because there is nothing to consent to.
- No advertising, ever. No ad networks, no remarketing pixels, no data sold, rented or shared for marketing. Not now, and it is not a business model we are keeping in reserve.
- No visitor identifier at all: not a cookie, not a fingerprint, not a hashed IP address. We cannot tell whether two visits came from the same person, and we did not try. That is a design decision, and it is the expensive one.
- Location is country only. Never city, never region, never coordinates.
- Nothing loads from anyone else. No Google Fonts, no CDN scripts, no embedded video, no social buttons. Nobody but us sees that you were here.
- Raw measurement records are deleted after 35 days. What survives is counts.
- Do Not Track and Global Privacy Control are honoured. If your browser sends either one, this site measures nothing whatsoever.
Switch measurement off.
This is a real switch, not a promise. Flip it and this browser stops sending measurement beacons from coprod.co, on this page and every other page of the site, from the next page load onwards.
Right now: your visits are measured, in the anonymous way described below.
Turn the switch on to stop this browser sending measurement beacons. Global Privacy Control and Do Not Track do the same thing across the whole site, and we honour both.
Honest small print: an opt-out that survives you closing the tab has to be remembered somewhere, and we refuse to remember it about you. We have no way to recognise you, and we are not building one. So it is remembered on your side instead. Turning this on writes exactly one key, coprod-analytics-opt-out, with the value 1, into this browser's local storage for coprod.co. It is never transmitted to us, it is not readable by any other site, and turning the switch back off deletes it. Clearing your browser data clears it too, and measurement resumes. There is no way around that without giving you an identifier, which would be worse.
Who is responsible.
Controller
{{LEGAL_NAME}} {{LEGAL_FORM}}{{STREET_ADDRESS}}
{{POSTCODE_CITY}}
Switzerland
UID {{CHE_NUMBER}}
contact@coprod.ch
“coprod” is the brand. The entity named above is the one that decides what happens to your data and that you can hold to this notice.
Reaching us about data
Write to contact@coprod.ch with “privacy” in the subject line. A human reads it. We are a small team, so we answer within 30 days at the outside, usually within a few working days.
We have not appointed a data protection officer. Under Art. 37 GDPR and Art. 10 revDSG we are not required to: we do not monitor people systematically and at scale, and we do not process special-category data.
Representative in the EU (Art. 27 GDPR): {{EU_REPRESENTATIVE}}
Two laws apply at once here, and they mostly agree. Swiss law (the revised Federal Act on Data Protection, revDSG) applies because the controller is Swiss. EU law (the GDPR) applies on top, under Art. 3(2), because we offer goods and services to people in the EU. Where this notice cites a GDPR lawful basis, the same processing is permitted under Swiss law too, as processing carried out at your request, or necessary to perform a contract with you, or justified by an overriding private interest of the kind described in each case (Art. 30–31 revDSG). We cite the GDPR article because it is the more specific of the two, not because Swiss law is an afterthought.
What we process, and why.
One row per purpose. If a purpose is not in this table, we are not pursuing it.
| Purpose | What is processed | Lawful basis | How long | Who else sees it |
|---|---|---|---|---|
| Serving this website | Standard server log entries: your IP address, the date and time, the page requested, the referring URL, your browser and operating system string, the response status and size. | Art. 6(1)(f) GDPR: our legitimate interest in delivering the site to you at all, and in detecting and repelling abuse, scraping and attack. There is no way to serve a web page without processing the address it must be sent to. | Held by our hosting provider under its own log settings: {{LOG_RETENTION}}. We do not export them or keep a copy of our own. | Vercel (hosting). |
| Audience measurement | Page path; the domain that referred you; campaign tags carried in the link you followed; time actively engaged and total time on the page; how far you scrolled; which sections were on screen and for how long; whether you turned a 3D viewer or opened the simulator; a coarse device class (mobile, tablet, desktop); your country; a timestamp. Your IP address is not stored. There is no identifier of any kind. See section 03. | Art. 6(1)(f) GDPR: legitimate interest, set out in full in section 03, with a right to object that we would rather you knew about than not. | Raw records are deleted 35 days after the visit. What survives is aggregate counts, which are not personal data. | Upstash (the database, in Frankfurt). |
| Hosting analytics (Vercel) | Separately from our own system: Vercel Web Analytics records page views with referrer, browser and operating system string, device type, and an approximate location derived from your IP address, down to city level; Vercel Speed Insights records page performance figures (Core Web Vitals) with the same technical dimensions. Both are cookieless and store nothing on your device. See the exception box in section 03. | Art. 6(1)(f) GDPR: legitimate interest in knowing that the site is read and that it is fast, with the same right to object as our own measurement. | Vercel's retention schedule for our plan, not our 35-day rule. | Vercel (US company), as our processor. |
| Early-access list | The email address you type into the signup form, and the time you submitted it. Nothing else: no name, no company, no enrichment, no lookup of who you are. | Art. 6(1)(a) GDPR: your consent, given by submitting the form. You can withdraw it at any time, and withdrawing is as easy as one email. | Until you ask to come off, or until we abandon the list, whichever is first. | Resend (email delivery) and/or Upstash (the database), depending on which is switched on. |
| Job applications | Whatever you put in the application form: name, contact details, CV and links, and your answers. If you email us instead, whatever is in that email. | Art. 6(1)(b) GDPR: steps taken at your request before entering a contract of employment. | {{APPLICATION_RETENTION}} after we reach a decision. If we would like to keep your application on file for longer, we will ask you first. | Google (the form). See section 05, and the alternative if you would rather not use it. |
| The shop | Order and delivery details: name, delivery and billing address, email, phone if you give one, and what you ordered. Payment is handled by the payment provider. We never see full card numbers. | Art. 6(1)(b) GDPR: performing the purchase contract; and Art. 6(1)(c) for the parts we are obliged to keep, Swiss accounting law (Art. 958f CO) among them. | Accounting records: 10 years, because the law says so. Everything not needed for that is deleted or anonymised once the order is settled and the warranty period has run. | Shopify, the payment provider, the shipping carrier. See section 06. |
| Correspondence | If you write to us: your address, your message, and anything you chose to put in it. | Art. 6(1)(f) GDPR: answering a message someone deliberately sent us; or Art. 6(1)(b) where it concerns a contract. | {{MAIL_RETENTION}}, then deleted, unless it belongs to a contract or a legal obligation that outlives it. | {{EMAIL_HOST}} (our mail host). |
Nothing on this site is subject to automated decision-making or profiling that produces legal effects for you, in the sense of Art. 22 GDPR or Art. 21 revDSG. There is no scoring, no segmentation, no automated assessment of applicants, and no decision about anybody taken by a machine.
Audience measurement, in detail.
This is the part of a privacy notice that is usually vague. Here is the whole thing.
What it is
We wrote our own. It runs on our own servers, it talks to nobody else, and its entire output is a table of page views with timing on it. It exists so we can tell whether the pages we spend a week writing are read past the first screen. That is the whole ambition.
It is first-party: the beacon goes to coprod.co/api/measure and stops there. No third party is involved in collecting it, and no third party is sent it afterwards.
One exception, and it is not ours. Alongside the system described here, this site also runs Vercel Web Analytics, a product of our hosting provider. It is cookieless and stores nothing on your device, but it is a separate system with a wider appetite: it records page views, referrer, browser, operating system, device type, and an approximate location derived from your IP address that resolves to city level, not merely to country. Vercel Inc. is a US company and processes it as our processor, under its retention schedule rather than the 35 days described below. The switch at the top of this page does not turn it off; Do Not Track and Global Privacy Control do, and so does writing to us.
The same provider also runs Vercel Speed Insights on this site. It measures how fast the pages load rather than who reads them: for a sample of page views it records the page, the performance figures (Core Web Vitals), your browser and operating system string, device type and country. It is cookieless, stores nothing on your device and carries no identifier that survives the page view; Vercel processes it as our processor under its own retention schedule.
What it records
- The page path, and the domain that referred you: the domain, not the full URL.
- Campaign tags (
utm_sourceand friends) if the link you followed carried them. - Engaged time and total time on the page, in seconds.
- How far down you scrolled, to the nearest tenth of the page.
- Which sections were in the middle of your screen, and for how long.
- Named interactions: “turned the actuator viewer”, “opened the simulator”, “pressed pre-order”. The name of the thing, never where your cursor was.
- A device class (mobile, tablet or desktop) derived from the browser string.
- Your country, and the time.
What it never does
- No cookie is set or read. None.
- The measurement code writes nothing to local storage, session storage or IndexedDB, and reads exactly one thing from any of them: the opt-out key set by the switch on this page, which it has to read in order to obey it. Nothing else on your device is looked at, and that key is never transmitted. Section 08 names it.
- No fingerprinting signal is collected: no canvas or WebGL rendering, no font enumeration, no audio stack, no screen or window dimensions, no device memory, no CPU count, no battery, no timezone probe.
- No mouse positions, no click coordinates, no keystrokes, no form contents, no session recording or replay. We could not reconstruct your visit if we wanted to.
- No cross-site, cross-device or cross-session linking. There is nothing to link with.
- No advertising identifiers, no data broker, no enrichment, no selling, no sharing.
The two honest caveats
Your IP address does reach our server. It has to: it is the address the page is sent back to. It is never written to the measurement database, never used as a key to anything, and never leaves the request: our own code does not even hold it in memory, because the per-address rate limit counts a one-way digest that is discarded when the server process is recycled. The country stored on the row does not come from the address at all. Our hosting edge resolves it and hands us the two-letter code. Country, never city, never region.
Each page load gets a random number. It lives in the page's memory, it is thrown away when you close or leave the tab, and a reload mints a fresh one. It exists purely so that a page reporting “18 seconds” twice is not counted as 36. It is not a visitor id, it does not identify you, it does not survive anything, and it cannot be used to recognise you on your next visit, because there is no next-visit record to match it against.
Why we may do this without asking
The lawful basis is Art. 6(1)(f) GDPR, legitimate interest, and here is the actual interest rather than the word: we need to know which of our technical pages are read, and how far, so that we write fewer and better ones, and so that we can tell whether a launch landed without buying an analytics product that would learn far more about you than we want anyone to know.
We think that interest does not override your rights, because of what the system cannot do: it holds no identifier, so it cannot build a profile; it holds no IP or city, so it cannot locate you; it holds nothing that could be combined with another dataset to single you out; and it forgets the raw records in 35 days. The intrusion is close to the floor, and the alternative, a hosted analytics product with cookies and a US parent, would be a great deal worse for you. If you disagree, the box below is not decorative.
Signals we obey
If your browser sends Do Not Track (DNT: 1) or Global Privacy Control (Sec-GPC: 1), the measurement script does not run and does not send anything. Belt and braces: if a beacon reaches our server carrying either header anyway, the server discards it without writing a row.
GPC is a legally recognised opt-out signal in several jurisdictions and a plain statement of preference everywhere else. We treat both the same way, and we treat them as binding rather than advisory.
Automated traffic (crawlers, headless browsers, monitors) is filtered out. It is noise in the numbers, not a person to be respected.
You have the right to object at any time to the audience measurement described in this section, on grounds relating to your particular situation. Because this processing rests on legitimate interest, an objection is not a request we weigh: for measurement we will simply stop, since there is nothing here we could claim outweighs your say-so.
Two ways to exercise it, and you do not have to explain yourself: use the switch near the top of this page, which takes effect in this browser immediately, or turn on Global Privacy Control or Do Not Track in your browser, which we honour everywhere on this site. You may also write to contact@coprod.ch, though note that because the records contain no identifier, there is nothing in the database we could look up and remove on your behalf; the switch and the browser signal are the effective remedies, which is the trade we made by not identifying anyone.
The consent question, answered plainly
You will notice there is no cookie banner. That is not an oversight and it is not a loophole we are quietly hoping nobody tests.
The consent rule that produces cookie banners, Art. 5(3) of the ePrivacy Directive and the equivalent reasoning under Swiss law, is about storing information on, or gaining access to information stored in, your device. The measurement code stores nothing on your device at all. It gains access to exactly one thing, and only if you put it there: the opt-out key the switch above sets, which it has to read in order to obey you. Access that exists solely to give effect to your own objection, and that goes away entirely if you never touch the switch. Nothing else on your device is stored or read. The only thing it transmits is what your browser had to send us anyway in order to be given a page, plus how long you actually stayed. On that basis we take the position that consent is not required here, consistent with how European regulators have treated cookieless, first-party audience measurement that is not shared with third parties and is not used for advertising, the CNIL's exemption criteria being the clearest published example.
It is a position, not a certificate. It rests on the system staying exactly as narrow as it is described above. If we ever wanted it to do more (an identifier, a longer memory, a third party, anything that touches your device), that would be a legal decision before it is an engineering one, and the honest response would be to ask you first, not to rewrite this paragraph.
The early-access list.
What you are signing up to
The form at the bottom of most pages takes one thing: an email address. We store it with the time you submitted it. We do not ask for a name, we do not look up your company, and we do not append anything to it from anywhere else.
We use it for one purpose: to tell you when there is something real to see: a module shipping, a batch opening, a piece of the stack going public. It is not a newsletter with a schedule, and it is not sold, rented, swapped or shared with anyone.
Getting off it
Reply to any message we send, or write to contact@coprod.ch and say “remove me”. That is the whole procedure. We delete the address rather than flagging it as unsubscribed, unless we need to keep a suppression record to make sure we do not add you back by accident, in which case that record is the address and nothing else.
Withdrawing consent does not make what we sent before unlawful; it stops anything further.
The form has a hidden field that real people never see and never fill in. If it comes back filled, we assume a bot and drop the submission on the floor. It is spam control, not measurement, and it collects nothing about you.
Job applications.
The form is Google's
The “Apply” buttons on the careers page open a Google Form. That means your application reaches Google before it reaches us, and Google processes it on its own infrastructure under its own terms, which we did not write. We use it because it works and we are small; we are telling you because you should be able to decide with that in front of you rather than behind you.
If you would rather not use it, write to contact@coprod.ch instead. An application by email is not a lesser application, and it does not go through Google's form.
What happens to it
Your application is read by the founders and by whoever would work with you. It is not scored by a machine, ranked by a model, or fed to anything that makes a decision. We do not run background checks and we do not search your private accounts.
We keep it for {{APPLICATION_RETENTION}} after we decide, so that we can answer questions about the process and defend a decision if we have to. Then it is deleted. If we would like to keep your application on file beyond that in case something better fits later, we will ask you, and you can say no with no consequence.
The shop.
It is a different site
Pre-order links on the products page take you to shop.coprod.co, which is a Shopify storefront. It is ours, but it is not this site: it runs on Shopify's platform, it sets its own cookies for your cart and checkout, and it has its own privacy and refund policies, which govern what happens once you are there.
Read them at shop.coprod.co/policies/privacy-policy. Nothing on this page overrides them, and the cookieless claims above are about coprod.co, not about the shop.
What an order involves
To ship you a module we need a name, a delivery address, an email, and sometimes a phone number for the carrier. Billing details go to the payment provider; we see that a payment succeeded, not your card number.
Order records that count as accounting documents are kept for ten years under Art. 958f of the Swiss Code of Obligations. That is not our choice and we cannot delete them early, even on request, a point worth knowing before you order rather than after.
Who else sees any of this.
The complete list. Each acts on our instructions under a data processing agreement, and none of them may use your data for their own purposes.
- Vercel Inc. Hosting and delivery of coprod.co Serves every page and runs the two small API endpoints. Sees request data, including your IP address, in its logs. The site is served from Vercel's European edge, but Vercel is a US company and administrative access from the US cannot be ruled out. US company · EU edge
- below, so Vercel appears a second time in this list in its analytics role. 2. Uncomment the paragraph marked (B) further down in section 03, which corrects the "country only" and "we wrote our own" statements. 3. Add a row to the table in section 02 for it, with its own retention (Vercel's, not our 35 days) and its own basis. 4. Re-check the consent position in section 03. Vercel Web Analytics is cookieless, but it is a separate controller-side judgement and the paragraph as written is about OUR system.
- Vercel Inc. Vercel Web Analytics In addition to hosting, Vercel provides the Web Analytics product used on this site. It is cookieless and sets nothing on your device, but it is not the same system as the one described in section 03 and it collects more: page views, referrer, browser, operating system, device type, and approximate location derived from your IP address, down to city level, not merely the country. Vercel is a US company; the data is processed under its terms as our processor, and retention follows Vercel's own schedule for our plan rather than our 35-day rule. You cannot switch this one off with the toggle on this page: use Do Not Track or Global Privacy Control, which Vercel Web Analytics also honours, or write to us. US company · city-level
- Vercel Inc. Vercel Speed Insights Also from the hosting provider: performance measurement. For a sample of page views it records the page, the Core Web Vitals figures, your browser and operating system string, device type and country. Cookieless, nothing stored on your device, no identifier that survives the page view. Processed by Vercel as our processor, under its own retention schedule. US company · sampled
- Upstash The database behind measurement Holds the measurement rows, and the early-access addresses when that mode is configured. The database is in Frankfurt, Germany, and the data stays there. Upstash is US-incorporated, so administrative access from the US cannot be ruled out. Measurement rows and subscriber addresses are held in separate databases, deliberately, so that a visit can never be joined to an email address. Frankfurt · eu-central-1
- Resend Email delivery for the early-access list Where the signup endpoint is configured to forward, Resend transports the message carrying your address to our own mailbox. Used only if that mode is switched on; if it is not, the address goes to the database instead and Resend is not involved. US company
- Google The job application form Google Forms hosts the careers application. Everything you type into it is processed by Google before it reaches us. Applying by email avoids this entirely: see section 05. US company · EU entity
- Shopify The shop at shop.coprod.co Runs the storefront, the cart and the checkout, and passes payment details to the payment provider. Sets its own cookies on its own domain, under its own policy: see section 06. Canada · EU entity
- {{EMAIL_HOST}} Our mailbox Receives and stores mail sent to contact@coprod.ch, including anything you write to us about privacy. To be named
Transfers outside Switzerland and the EEA
Several of the providers above are US companies, so some data can be accessed from the United States even where it is stored in Europe. Those transfers rest on the EU–U.S. and Swiss–U.S. Data Privacy Frameworks where the recipient is certified under them, and otherwise on the European Commission's standard contractual clauses together with the Swiss addendum required by the FDPIC.
We will not pretend that paperwork makes US surveillance law disappear. What we can do is keep the amount of data that ends up in that position as close to nothing as possible, which is most of what this notice is about.
Nobody else
We do not sell, rent, trade or share personal data. There is no ad network, no data broker, no “marketing partner”, no affiliate tracking and no analytics reseller in this stack.
We would disclose data to a court or authority if we were legally compelled to, and where the law allows us to say so, we would tell you.
If the company is ever sold or merged, personal data could pass to the acquirer as part of the business. If that happens we will say so here before it takes effect.
Links from this site to Discord, GitHub, YouTube, X, LinkedIn and Instagram are plain links. Nothing from those platforms is embedded in any page here, so none of them learns that you visited coprod.co unless you click through, at which point you are on their site, under their rules.
What is stored on your device.
“We store nothing on your device” would be a nice sentence and it would not be true. Here is the accurate version.
- Measurement: nothing written. The measurement code sets no cookie and writes nothing to local storage, session storage or IndexedDB. It reads one thing, and one thing only: the opt-out key below, so that it knows to stay silent.
- The opt-out switch: one key. If, and only if, you turn on the switch in section “Switch measurement off” above, this browser stores
coprod-analytics-opt-out=1for coprod.co. It exists so your choice survives closing the tab. It is never sent to us, no other site can read it, and turning the switch off deletes it. If your browser refuses to let the measurement script read that key at all (private mode, blocked site storage), the script stops instead of guessing, so “unreadable” means not measured. - The simulator remembers whether you chose light or dark. The co:dodo simulator at coprod.co/simulator is a full application, and it keeps your appearance preference in local storage under keys beginning
mui-(mui-modeand its colour-scheme companions). That is a display setting, it stays in your browser, and it is never transmitted to us. - Your browser's ordinary cache. Fonts, images and scripts are cached the way every website's files are cached. That is how the web works rather than something we do to you, but it is storage on your device and it belongs on this list.
- The shop is different. shop.coprod.co is a Shopify site and it does set cookies: for your cart, your checkout session, and Shopify's own analytics. Its policy governs there, not this page.
Your rights.
Under the GDPR (Arts. 15–22) and the revDSG (Arts. 25, 32). Exercising any of them is free and costs you nothing else either. We will not treat you differently for asking.
Access
Ask what personal data we hold about you, why, for how long, and who else has seen it, and get a copy.
Correction
Have anything inaccurate fixed, and anything incomplete completed.
Erasure
Have your data deleted, where we have no legal obligation or overriding reason to keep it. The ten-year accounting rule is the main exception.
Restriction
Have processing frozen rather than deleted, for instance while a dispute about accuracy is being sorted out.
Portability
Receive the data you gave us in a structured, machine-readable format, or have it sent straight to someone else.
Objection
Object to anything we do on the basis of legitimate interest: audience measurement above all. See the box in section 03.
Withdraw consent
Take back consent you gave (the early-access list) at any time, with effect for the future.
No automated decisions
Nothing here decides anything about you automatically. Nothing to opt out of, but you have the right, and you should know it is unused.
How to exercise them
One email to contact@coprod.ch. No form, no portal, no account required. We answer within one month, and if a request is genuinely complicated we will tell you inside that month rather than going quiet.
If we cannot tell who is asking, we may need to ask a question or two to be sure. We would rather be slightly annoying than hand your data to somebody pretending to be you. We will not demand ID as a matter of routine.
One thing we genuinely cannot do
We cannot give you access to “your” measurement records, or delete them, because we cannot find them. They contain no identifier: no cookie, no IP, no account, nothing that connects a row to a person. There is no query we could run that would return your visits rather than somebody else's.
That is Art. 11 GDPR: where a controller cannot identify a data subject, the access and erasure rights do not apply to that data. We are not using it as a shield; it is the direct consequence of a choice made in your favour. Everything else we hold (an email address, an application, an order) is fully reachable, and those requests we can and do answer.
How to complain.
Please tell us first: most things are a misunderstanding we can fix in a day. But you never have to go through us, and both routes below are open regardless of what we say.
In Switzerland
Federal Data Protection and Information Commissioner (FDPIC)Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter
Feldeggweg 1
3003 Bern
Switzerland
www.edoeb.admin.ch
In the EU or EEA
You can complain to the supervisory authority of the country you live or work in, or where you think something went wrong. You do not have to come to Switzerland to do it.
The current list of national authorities, with contact details, is published by the European Data Protection Board: edpb.europa.eu · members.
You also have the right to a judicial remedy under Art. 79 GDPR, and in Switzerland to bring a civil action under the revDSG.
Security.
What we actually do
- Everything is served over HTTPS; there is no unencrypted route to this site.
- A strict Content-Security-Policy stops the pages loading scripts, styles, fonts or images from anywhere but our own origin, which is also why no third-party tracker could be injected without the page breaking loudly.
- Referrer policy is set so other sites are told the domain you came from, not the page.
- Camera, microphone, geolocation and payment APIs are switched off at the browser level for this site.
- Measurement rows and subscriber email addresses live in separate databases with separate credentials, so the two cannot be joined even by us, even by mistake.
- Access to the stores is limited to the founders, and the beacon endpoint accepts nothing but the small fixed set of fields described in section 03.
What we do not claim
No system is perfectly secure, and a company of our size that told you otherwise would be selling something. If a breach ever affects your data, we will notify the FDPIC and, where the risk to you warrants it, the relevant EU authority, and we will tell you directly, in plain language, rather than by quietly editing this page.
Found a hole? contact@coprod.ch. We will thank you properly and we will not send a lawyer.
Children, and changes to this notice.
Children
This site sells industrial robotics modules and hires engineers. It is not directed at children, and we do not knowingly collect data from them. The measurement system cannot tell anyone's age, because it cannot tell anything about anyone. If you believe a child has sent us personal data, write to contact@coprod.ch and we will delete it.
Changes
We will update this page when what we do changes, and the rule we are setting ourselves is that the page changes before the system does, not after.
The version and date are at the top. For a material change (a new purpose, a new processor, anything touching your device) we will do more than bump the date: we will say what changed and why, and where the change would need your consent, we will ask for it instead of announcing it.