Privacy Policy
Last updated: April 2026
Please read this privacy and cookie policy carefully before using the Acuna website operated by Abilene Group SA.
Introduction and Contact
By this declaration, we inform you how personal data is processed across our websites and services. Acuna GRC is subject to the Swiss Federal Act on Data Protection (FADP) and, where applicable, GDPR. Data protection contact: Henri Haenni (DPO), Acuna GRC, Rue de la Gare 39, 1110 Morges, Switzerland, privacy@abilene.ch.
What Data We Process
We may process identity data, contact details, billing records, correspondence, and technical data (such as IP, MAC, and timestamp). Retention periods depend on data type and legal basis, including contract, accounting, evidence, and security obligations.
Purposes and Legal Bases
Data is processed to deliver contractual services, respond to requests, maintain security, run compliance operations, improve services, and perform reporting and planning. Legal bases include contract necessity, legal obligations, legitimate interests, and consent where required (including withdrawal rights for consent-based processing).
Data Sharing
Personal data may be shared with contractual partners, processors, and authorities when legally required or necessary for service delivery and security. Processors are assessed for proportionality and safeguards, and additional restrictions are applied when needed.
Cookies
This site groups its cookies into three categories. Necessary cookies keep the site working, remember your language and pricing region, and, for Acuna staff, keep the sign-in session active; Analytics and Marketing are optional, and you choose whether to allow each one.
- Necessary (always on): Necessary cookies keep your cookie preferences remembered, remember your language, and determine the pricing region shown to you; they also keep the portal sign-in session active for Acuna staff. Cookies: acuna_consent, kept for 12 months; NEXT_LOCALE, which remembers your language for your browser session; acuna-region, kept for 1 hour, which determines the pricing region; and the Supabase authentication cookies used for that staff sign-in.
- Analytics (opt-in): When you allow Analytics, this enables Google Analytics 4 to measure how visitors use the site. Cookies: _ga and _ga_*.
- Marketing (opt-in): When you allow Marketing, this enables the LinkedIn Insight Tag and its enhanced matching feature, which power LinkedIn advertising attribution and retargeting; Google's Preferred Sources control, which lets you mark Acuna as a preferred source in Google Search; and the Lusha website visitor pixel, which identifies the company a visitor is browsing from so our sales team can follow up. Cookies: li_sugr, bcookie, lidc, and UserMatchHistory from LinkedIn. Enhanced matching also stores li_hem in your browser's local storage. Google's Preferred Sources library reads the __gads advertising cookie if present and writes its own keys to your browser's local and session storage. Lusha stores a visitor identifier named lid_lusha, both as a cookie kept for 30 days and as an entry in your browser's local storage.
Vercel Analytics and Speed Insights also measure page performance and traffic on every visit. They use a cookieless method, so they sit outside these categories.
When Marketing is allowed and you submit a form on this site with your email address, your browser hashes that address with SHA-256 before sending it to LinkedIn for enhanced matching. LinkedIn receives the hash, not the address itself; under GDPR, a hashed email address is still personal data.
You can change these choices at any time from the Cookie settings control in the site footer.
International Transfers and Retention
Data may be transferred to providers outside Switzerland where necessary for service delivery, with preference for EEA locations and jurisdictions offering adequate protection. Personal data is retained only as long as required for legal, contractual, and governance purposes, then deleted or de-identified.
Security Measures
Acuna GRC operates an ISO 27001:2022 Information Security Management System (ISMS) to protect confidentiality, integrity, and availability. Security controls include encryption, access management, monitoring, and incident response. Website traffic is protected using SSL/TLS.
Your Rights and Policy Updates
You may request access, correction, deletion, restriction, portability, and objection, and may revoke consent at any time for future processing. You may also contact the DPO or relevant authority for complaints. This notice may be updated periodically; the published website version is the current authoritative version.