Privacy Policy
Privacy Policy Controller
Elibo Health GmbH
Schauenburgerstrasse 26
4052 Basel, Switzerland
Email: elisabeth(at)elibohealth.com
Phone: +41 61 311 6660 
Elibo Health GmbH (hereinafter "we", "us") operates the website elibohealth.com (the "Website"). We are the controller for processing personal data via the Website. This Privacy Policy explains how we collect, use, and protect your data in compliance with the Swiss Federal Act on Data Protection (nFADP/DSG) and—where applicable to EU/EEA users—the EU General Data Protection Regulation (GDPR/DSGVO). Swiss law applies primarily; GDPR terms are used for clarity where processing involves EU/EEA individuals. 
Data Collection via the Website 
We collect personal data only as necessary for our services in health economics and outcomes research, health technology assessment and market access consulting. Our website is hosted by Switzerland’s Infomaniak. Infomaniak’s confidentiality policy can be viewed here: Infomaniak Data confidentiality policy Its cookie policy can be viewed here: Policy on the use of cookies | Infomaniak
Contact Form 
The Infomaniak contact form collects full name, email address, and free-text message for handling enquiries (e.g., service requests). Data is emailed directly to elisabeth(at)elibohealth.com. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR; Art. 31 nFADP) to initiate or perform contracts; contract initiation where applicable (Art. 6(1)(b) GDPR). ·       
Server Logs and Analytics
Infomaniak hosting automatically logs IP address, browser type, device info, and pages visited for security, optimization, and error diagnosis (provider defaults, potentially including Infomaniak Web Analytics or Google Analytics). Legal basis: Legitimate interests (website security and functionality). ·       
No Other Collections
No newsletter signup, login areas, comments, event registration, cookies requiring consent beyond essentials (handled by Infomaniak's standard cookie banner), or social media links. No sensitive personal data (e.g., health data) is processed via the Website. 
Purposes and Legal Bases 
We process data solely for: 
·       Responding to enquiries and discussing potential consulting mandates (e.g., scheduling calls). 
·       Website security, stability, and improvement.
No marketing beyond service-related follow-up; no consent-based processing (no newsletter etc.). All rely on legitimate interests or contract performance, proportionate for our SME. 
Recipients and Transfers 
Data is shared minimally: ·       
Hosting/Email
Infomaniak (Switzerland; DPA in place via service terms). ·       
Collaboration Tools
(post-enquiry): Microsoft 365/OneDrive (EU servers for Swiss clients; adequacy decision/SCCs for any third-country access) and Infomaniak kDrive (Switzerland). ·       
Other
Adobe Acrobat (for PDFs; privacy policy at adobe.com/privacy). No processors outside CH/EU/EEA without safeguards. No automated transfers to third countries via the Website. 
Retention Periods
Enquiries/emails: As required by law (e.g., 5-10 years for potential contracts); deleted sooner if no mandate pursued.      
Enquiries/emails: As required by law (e.g., 5-10 years for potential contracts); deleted sooner if no mandate pursued.
Project files: Duration of project + 10 years (commercial/documentation obligations). 
Server logs: Infomaniak defaults (typically 6-12 months). Data is securely deleted or anonymized thereafter. 
Your Rights 
Under nFADP/GDPR, you have rights to access, rectification, erasure, restriction, portability (where applicable), and objection to processing. To exercise these, contact us at elisabeth(at)elibohealth.com. We respond within 30 days (extendable if complex). Complaints: Swiss Federal Data Protection and Information Commissioner (FDPIC/edoeb.admin.ch) or EU supervisory authority in your country. 
Security Measures 
As a low-risk controller, we implement proportionate technical/organizational measures (TOMs): MFA on all accounts, encrypted email/storage available on request (Infomaniak options), no shared accounts, device encryption, regular updates, and access limited to the owner. Breaches are reported to FDPIC if high-risk. 
Last Updated
February 2026. We review annually or on material changes.  

Search