Legal Notice & Privacy Policy
Last updated: 16 June 2026
Legal Notice (Impressum)
This website (lazzaretti.me) is operated by:
Fabrizio Lazzaretti
Switzerland
Contact: fabrizio@lazzaretti.me
This is a privately operated website presenting personal and professional content (blog posts, talks, and publications). Any opinions expressed here are my own and do not necessarily reflect those of my employer.
Privacy Policy
This privacy policy explains what personal data is processed when you visit lazzaretti.me, for what purposes, and what rights you have. It is based on the Swiss Federal Act on Data Protection (FADP / revFADP, in force since 1 September 2023). If you are located in the EU or EEA, the EU General Data Protection Regulation (GDPR) may also apply.
1. Data Controller
The controller responsible for data processing on this website is Fabrizio Lazzaretti (contact details above). You can reach me for any data-protection matter at fabrizio@lazzaretti.me.
2. What Data Is Collected and Why
This is a static website. I do not run user accounts, a newsletter, a contact form, a comment system, or any payment processing. The following data is processed:
- Server and connection data. When you open a page, your browser transmits technical data (including your IP address, the requested URL, referrer, date and time, browser type, and operating system) to the hosting provider so the page can be delivered and the service kept secure and stable.
- Usage and analytics data. Aggregate, privacy-friendly statistics about which pages are visited, referrers, approximate country, device and browser type, and link clicks (see “Web Analytics” below).
- Data processed by embedded third parties. When a page loads external resources (scripts and icons from content delivery networks, or an embedded YouTube video), your IP address is transmitted to the respective provider so that content can be delivered (see sections 4, 9 and 10).
3. Legal Bases
Under the Swiss FADP, processing must be lawful, proportionate, carried out in good faith, and for a purpose recognizable to you; the FADP does not generally require naming a specific legal basis. Where the GDPR applies, the legal bases are:
- Legitimate interests (Art. 6(1)(f) GDPR) for operating, securing, and analyzing the website with privacy-friendly, aggregate statistics.
- Consent (Art. 6(1)(a) GDPR) where you actively start an embedded YouTube video or follow an external link, at which point the third party may process further data.
4. Recipients and Sub-Processors
To operate this website I use the following service providers, which process data on my behalf or as independent controllers:
- Hosting and CDN: Cloudflare, Inc. (Cloudflare Pages). Delivers the website and processes connection data (including IP) for delivery and security.
- Web analytics: Umami (Umami Software, Inc.; umami.is / cloud.umami.is). Privacy-focused, cookieless analytics. Events are sent through a same-domain endpoint on this site that forwards your IP address to Umami; the IP is used transiently to derive an approximate country and is not stored to identify you.
- Content delivery networks: jsDelivr (cdn.jsdelivr.net) on all pages, and Cloudflare cdnjs (cdnjs.cloudflare.com) and Tailwind CDN (cdn.tailwindcss.com) on certain link pages. These deliver scripts and styles and receive your IP address when doing so.
- Embedded videos: Google Ireland Limited (YouTube, in privacy-enhanced “youtube-nocookie” mode) on talk pages.
- Affiliate links: Amazon (see section 11).
5. International Data Transfers
Some of these providers are based in or transfer data to countries outside Switzerland and the EU or EEA, in particular the United States (Cloudflare, Google, Amazon, and possibly Umami). Such transfers are safeguarded by recognized mechanisms, in particular the EU and Swiss-US Data Privacy Framework (the Swiss-US DPF was recognized by the Swiss Federal Council in 2024) and the European Commission’s Standard Contractual Clauses. For providers in other third countries, comparable safeguards apply.
6. Retention
Personal data is kept only as long as necessary for the purposes above or as required by law. Server and security logs are retained for a short period and then deleted or anonymized. Analytics data is stored in aggregate form for statistical purposes. Where Swiss law requires longer retention (for example commercial or tax records, up to 10 years under the Swiss Code of Obligations), that data is retained accordingly.
7. Your Rights
Under the Swiss FADP (and, where applicable, the GDPR) you have the right to:
- request access to the personal data processed about you;
- request rectification of inaccurate data;
- request erasure or restriction of processing;
- object to processing;
- request data portability (receipt or transfer of data you provided, in a common electronic format).
To exercise these rights, contact fabrizio@lazzaretti.me. I will respond within the statutory timeframe (generally 30 days).
8. Cookies and Tracking
This website itself does not set any cookies, and the analytics is cookieless. Third-party services may set cookies on their own domains only after you actively interact with them, for example when you play an embedded YouTube video or follow an Amazon affiliate link.
9. Web Analytics (Umami)
I use Umami, a privacy-focused, cookieless web-analytics tool, to understand aggregate website usage. It records events such as page views, referrer, approximate country, device and browser type, and link clicks. Analytics requests are routed through a same-domain endpoint on this site, which forwards your IP address to Umami; the IP is used only transiently (for example to derive the country) and is not stored to identify you. No cross-site tracking and no advertising profiles are created.
10. Embedded Videos (YouTube)
Some pages embed YouTube videos using the privacy-enhanced domain youtube-nocookie.com (provider: Google Ireland Limited). In this mode, before you start a video, only the information needed to deliver the player (including your IP address and device and browser data) is transmitted to Google. Once you start a video, Google may process further data and set cookies in line with its own privacy policy: policies.google.com/privacy.
11. Affiliate Links (Amazon)
Some pages contain Amazon affiliate links (for example to the book “Crafting Great APIs with Domain-Driven Design”). If you click such a link and make a purchase, I may receive a commission. The link contains an identifier that lets Amazon attribute the purchase, and Amazon may set a cookie for this purpose. This does not change the price you pay.
As an Amazon Associate I earn from qualifying purchases.
12. Changes to This Policy
I may update this policy when the website or the underlying processing changes. The current version always applies and is dated at the top.
13. Contact and Right to Complain
For any data-protection matter, contact fabrizio@lazzaretti.me.
If you believe your data is being processed unlawfully, you have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC / EDOEB), edoeb.admin.ch. If the GDPR applies to you, you may also complain to your local supervisory authority.
