Privacy Policy

Last updated: 7 May 2026. This page is a practical legal starter text for Onir/Fexor.

Sign up for Onir

This Privacy Policy explains how Timothee Lefebvre ("Fexor", "Onir", "we", "us", "our") collects and processes personal data in connection with onir.ch, related websites, communications, demo requests, account creation, and the use of the Onir platform.

If there is any conflict between this Privacy Policy and specific contractual terms agreed with a customer, the contractual terms prevail to the extent permitted by law.

1. Controller

Timothee Lefebvre
Hubackerweg 40
4153 Reinach BL
Switzerland
Email: timothee.lefebvre@fexor.ch

2. What data we collect

We may collect and process the following categories of personal data:

a. Website and contact data

  • name
  • company name
  • email address
  • phone number
  • message content
  • any personal data submitted through contact forms, email, or demo requests

b. Account and user data

  • login details
  • user profile information
  • business contact details
  • workspace and account settings
  • support requests and related correspondence

c. Technical and usage data

  • IP address
  • date and time of access
  • browser and device information
  • log data
  • pages visited
  • usage events within the platform

d. Customer-provided data

When customers use Onir, they may upload or connect business data to the platform. This data is primarily commercial and operational in nature. To the extent such data includes personal data, we process it on behalf of the customer in accordance with the applicable contract.

3. Purposes of processing

We process personal data for the following purposes:

  • to operate and provide the website and platform
  • to respond to contact requests and demo requests
  • to create and manage accounts
  • to provide customer support
  • to ensure security, stability, and performance
  • to improve the website, product, and user experience
  • to send service-related communications
  • to comply with legal obligations
  • to establish, exercise, or defend legal claims

If permitted by law, we may also use contact details for direct marketing related to our own services. Users may opt out of such communications at any time.

4. Legal basis

Where GDPR applies, we process personal data on one or more of the following bases:

  • performance of a contract
  • steps prior to entering into a contract
  • compliance with legal obligations
  • legitimate interests, in particular the secure and efficient operation and improvement of our services
  • consent, where required

5. Cookies and similar technologies

We may use cookies and similar technologies to operate the website, improve functionality, understand usage, and support security.

If non-essential cookies or similar technologies are used, users can manage their preferences through the cookie banner or settings tool made available on the website.

6. Analytics and third-party services

We may use third-party providers for hosting, analytics, authentication, payments, communications, customer support, and related infrastructure. At present, this may include Infomaniak for hosting and infrastructure, Clerk for authentication and user management, and Stripe for payments and billing-related operations.

Such providers may process personal data on our behalf or, where applicable, as independent controllers under their own privacy terms.

Examples may include:

  • hosting and infrastructure providers, including Infomaniak
  • authentication providers, including Clerk
  • payment providers, including Stripe
  • analytics providers
  • email and communications providers
  • customer support tools

A current list of significant service providers can be provided upon request or made available separately.

7. Customer data processed on behalf of customers

For account authentication and user management, we may use Clerk. For payments, subscriptions, checkout, invoicing support, and related billing operations, we may use Stripe. These providers process relevant personal data as part of delivering their respective services.

8. Customer data processed on behalf of customers

If a customer uploads or connects data to Onir and that dataset contains personal data, the customer is generally the controller and we act as processor or service provider, unless expressly agreed otherwise.

In that case, we process such data only for the purposes of providing the contracted services and in accordance with our agreement with the customer.

9. Data sharing

We may disclose personal data to the following recipients where necessary:

  • group companies or affiliated service providers, if applicable
  • technical service providers and sub-processors
  • professional advisers
  • authorities, courts, or regulators where required by law
  • counterparties in connection with corporate transactions, where legally permitted

We do not sell personal data.

10. International transfers

Personal data may be processed in Switzerland, the European Economic Area, or in other countries where our service providers operate.

Where personal data is transferred to countries that do not provide an adequate level of protection, we implement appropriate safeguards as required by applicable law.

11. Retention

We retain personal data only as long as necessary for the relevant purpose, including for the duration of the business relationship, for legal compliance, for documentation obligations, and for the establishment, exercise, or defense of legal claims.

Log data, contact requests, and support records may be retained for reasonable operational and legal periods.

12. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.

These measures may include access controls, encryption, logging, backup procedures, and internal confidentiality obligations.

13. Data subject rights

Depending on applicable law and specific circumstances, individuals may have the right to:

  • request information about their personal data
  • request correction of inaccurate data
  • request deletion of data
  • request restriction of processing
  • object to certain processing
  • receive data in portable form, where applicable
  • withdraw consent, where processing is based on consent

Requests may be sent to: timothee.lefebvre@fexor.ch

14. Obligation to provide data

If personal data is required to enter into or perform a contract, and such data is not provided, we may be unable to provide the requested service.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The version published on this website is the current version.

Privacy Policy | Onir