Privacy Policy
In accordance with the Swiss Federal Act on Data Protection (revFADP, in force since 1 September 2023) and the General Data Protection Regulation (GDPR, EU 2016/679)
1 · Data Controllers
This website is jointly operated by the entities listed below, acting as joint controllers within the meaning of Art. 26 GDPR. The operational data-protection contact point and primary point of contact is bluematic AG (contact details in Section 13).
The allocation of responsibilities between the joint controllers is set out in an internal arrangement pursuant to Art. 26(1) GDPR. Data subjects may exercise their rights against any of the controllers.
2 · At a Glance
This website sets no cookies whatsoever – neither technical nor analytics or tracking cookies.
Plausible Analytics runs on our own infrastructure in Switzerland (RZO Gais). No IP storage, no fingerprinting, no profiling.
There is no registration and no login. The website can be used entirely anonymously.
The source code of this website is publicly available on GitHub and can be audited at any time.
3 · Hosting & Server Logs
This website — including the server-side service that receives contact-form submissions — is operated at the RZO data centre in Gais (Appenzell Ausserrhoden, Switzerland). All operations take place exclusively on Swiss infrastructure. No transfer of web-server logs to third countries occurs.
With every page request, technically necessary connection data is recorded in server logs: the requester's IP address, the time of access, the requested URL, the HTTP status, the volume transferred, the referrer URL, and the user agent (browser and OS identifier).
Purpose: secure operation of the infrastructure, defence against attacks, fault analysis. Legal basis: Art. 31(2)(c) revFADP and Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the website). Retention period: a maximum of 30 days, followed by automated deletion. We do not merge log data with other sources nor carry out person-related evaluations.
4 · Web Analytics (Plausible, self-hosted)
We use Plausible Analytics (plausible.io), an open-source, privacy-friendly analytics solution. Our Plausible instance runs on our own infrastructure at RZO Gais. No data is transmitted to Plausible Insights OÜ (Estonia) or to any other third party.
The following aggregated data is collected: page views (URL), referrer (linking page), coarse device class (desktop/mobile/tablet), browser and OS identifier, and country of origin (derived offline from the IP via a geolocation database). The IP address itself is never stored; only a daily, salted hash is computed from it in order to recognise returning visits within the same day. The hash is deleted after 24 hours.
In addition, we record a few aggregated, anonymous interaction events (e.g. which solution detail was opened, which filter was used, or which external link was clicked) to improve the directory – always without any personal reference. No cookies are set, no cross-site tracking is performed, no fingerprinting is carried out, and no personal profiles are created. Legal basis: Art. 31(2)(c) revFADP and Art. 6(1)(f) GDPR (legitimate interest in privacy-friendly reach measurement). As no personal data is processed, consent under Art. 6(1)(a) GDPR is not required. Retention of aggregated statistics: 24 months.
5 · Form Bot Protection (Altcha, self-hosted)
The contact form is protected by Altcha – an open-source proof-of-work solution and privacy-friendly alternative to Google reCAPTCHA, Cloudflare Turnstile, etc. Our Altcha instance is self-hosted at RZO Gais (Switzerland). No data is transmitted to third parties.
The visitor's browser solves a cryptographic puzzle locally (HMAC-SHA-256 search). Only the computed solution token and the associated challenge signature are transmitted – no biometric data, no device identifiers, no cookies, no tracking. To defend against automated bulk requests we additionally apply an IP-based rate limit; for this purpose the IP address is held in the server's memory only briefly (at most 10 minutes) and is never stored persistently. Legal basis: Art. 31(2)(c) revFADP and Art. 6(1)(f) GDPR (legitimate interest in defending against automated requests). Tokens are used server-side only once for validation and are not stored persistently.
6 · Contact Form & CRM (Odoo)
The contact form on this site allows visitors to send us suggestions or correction notices about open-source solutions. We collect only the information you voluntarily enter into the form: name, email address, name of the suggested solution, and a free-text description. Mandatory fields are marked as such.
Purpose of processing: handling the request, follow-up questions, and adding the solution to the directory. Legal bases: consent under Art. 6(1)(a) GDPR (by actively confirming the privacy notice before submission) and Art. 6(1)(b) GDPR (pre-contractual / preparatory measures). Form data is transmitted to our CRM system for processing. After submitting, you will also receive an automatic confirmation email at the address you provided; it contains the details you submitted. The confirmation email is sent via mail servers operated by hosttech GmbH (Seestrasse 15a, 8805 Richterswil, Switzerland), acting as our processor within the meaning of Art. 28 GDPR; processing takes place exclusively in Switzerland.
Our CRM is Odoo (Odoo SA, Chaussée de Namur 40, 1367 Grand-Rosière, Belgium). It runs on the managed Odoo.sh platform on EU servers. Odoo SA is our processor within the meaning of Art. 28 GDPR; we have concluded a Data Processing Agreement (DPA) based on the EU Standard Contractual Clauses. No transfer to third countries outside the EU/EEA takes place. Further information on data protection at Odoo SA: odoo.com/privacy.
Retention period: form data is retained for as long as is necessary to process your request, but no longer than until your consent is withdrawn. If a business relationship arises from the request, the commercial retention obligations under Art. 958f of the Swiss Code of Obligations (ten years) apply. Requests without follow-up communication are deleted from the CRM after 24 months at the latest.
You may withdraw your consent at any time with effect for the future by sending an email to ping@bluematic.com. The lawfulness of the processing carried out on the basis of the consent prior to its withdrawal remains unaffected.
7 · Fonts (self-hosted)
This website uses the fonts «DM Sans» (Indian Type Foundry, Open Font License 1.1) and «Fira Code» (Mozilla / Nikita Prokopov, Open Font License 1.1). The font files are obtained from npm via the open-source packages @fontsource-variable/dm-sans and @fontsource-variable/fira-code, embedded into the website at build time, and served exclusively from our own infrastructure (RZO Gais). When you visit this website NO connection to fonts.googleapis.com, fonts.gstatic.com, or any other external font service is established. No personal data is transmitted to Google or any other third party — neither at build time nor at runtime.
8 · GitHub Star Counts (Build-Time, no third-country transfer)
On the solution cards we display the GitHub star count for the respective open-source project as a quality indicator. These figures are fetched server-side at build time in our CI pipeline (RZO Gais, Switzerland) from the public GitHub API and embedded into the static build. The visitor's browser does NOT establish any connection to api.github.com or to other GitHub services.
Consequently, no personal data is transmitted to GitHub Inc. (USA) – neither your IP address nor your user agent ever leave our Swiss infrastructure in the direction of GitHub. Star counts are refreshed on every deployment (typically daily). Legal basis: Art. 31(2)(c) revFADP and Art. 6(1)(f) GDPR (legitimate interest in providing a quality indicator for the listed projects).
9 · Local Storage (technically required)
Your browser's localStorage (not to be confused with cookies, since no data is transmitted to our server) holds only your own UI settings: selected language (DE/EN/FR/IT) and selected colour scheme (light/dark). This data never leaves your browser. You can clear it at any time in your browser settings.
10 · External Links
This website contains links to external websites, in particular the GitHub and GitLab repositories and the project websites of the listed open-source solutions. The respective operators are solely responsible for the content and privacy practices of those external sites. By clicking an external link you leave our website; we have no influence over the data collected there. We recommend consulting the privacy notices of the destination sites.
11 · Your Rights as a Data Subject
Under the revFADP (Switzerland) and the GDPR (EU), you have the following rights with respect to your personal data:
- Right of access — confirmation as to whether, and which, data concerning you is processed (Art. 25 revFADP / Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 32(1) revFADP / Art. 16 GDPR)
- Right to erasure (the «right to be forgotten», Art. 32(2) revFADP / Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability in a structured, commonly used format (Art. 28 revFADP / Art. 20 GDPR)
- Right to object to processing based on legitimate interest (Art. 30(2) revFADP / Art. 21 GDPR)
- Right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR)
- Right to lodge a complaint with the competent supervisory authority (see Section 14)
Because this website maintains no user accounts and stores no personal data persistently outside the contact form (Section 6), the practical relevance of these rights is limited to server logs (30 days, Section 3) and – if used – the data submitted through the contact form.
12 · Automated Decision-Making
No automated decision-making within the meaning of Art. 21 revFADP or Art. 22 GDPR, including profiling, takes place.
13 · Contact for Privacy Requests
For requests regarding data processing, the exercise of your rights, or the withdrawal of consent, please contact:
bluematic AG · attn. Data Protection
ping@bluematic.comWe will respond to requests within 30 days as required by law.
14 · Supervisory Authorities / Right to Lodge a Complaint
If you believe that the processing of your personal data infringes data-protection law, you may lodge a complaint with the competent supervisory authority:
15 · Changes to This Policy
We reserve the right to amend this privacy policy in order to reflect changes in the legal framework, technical developments, or changes to our data processing. The current version is always available at this URL. Material changes will be communicated on the homepage or by email to individuals with active form requests.
Last updated: June 2026
Legal Notice →