Legal
Privacy policy.
How we process personal data when you visit this website or contact us — under the Liechtenstein Data Protection Act and the EU General Data Protection Regulation (GDPR).
Controller
The controller for data processing on this website is:
- Company
- Anstalt für Zellforschung
- Address
- Zollstrasse 34, 9490 Vaduz, Liechtenstein
- info@zellforschung.li
- Telephone
- +423 232 26 17
Data protection enquiries go to the controller at the address above.
Data we process
We process the following categories of personal data:
- Server log data — IP address, browser type and version, operating system, referring page, date and time of access. Processed by our hosting provider to operate and secure the website.
- Enquiry data — Your enquiry type, product and market details, name, company, email address and message. The form sends these data to an AFZ endpoint hosted by Vercel; Resend then delivers the enquiry to the AFZ business mailbox.
- Analytics data — After you allow analytics, Google Analytics 4 receives page paths, page titles and a small set of interaction events, together with technical data such as device and browser information. Form values, names, email addresses, company names and message text are not sent to analytics.
- Consent records — Your Necessary or Analytics choice, stored locally in your browser under afz_consent_v2. The preference is not submitted with the enquiry form.
Fonts and normal website assets are served from our own domain. The Google tag is the only optional third-party browser resource and is not requested before analytics consent. Do not include patient records, diagnoses or other special-category health data in the enquiry form.
Purposes and legal bases
- Website operation & security
- Art. 6(1)(f) GDPR — legitimate interest in a functional, secure website
- Answering enquiries
- Art. 6(1)(b) GDPR — pre-contractual measures; Art. 6(1)(f) for general correspondence
- Website analytics
- Art. 6(1)(a) GDPR — your consent
- Legal retention duties
- Art. 6(1)(c) GDPR — compliance with commercial and tax law
Retention
Server log data is retained by our hosting provider only for as long as needed to operate and secure the service, and is then deleted or anonymised.
The website does not maintain a separate enquiry database. Enquiries are retained in AFZ business mailboxes for as long as needed to handle the request and thereafter where commercial, tax or legal retention duties apply.
Google Analytics event retention is controlled through the AFZ GA4 property settings. First-party analytics cookies can remain for up to two years unless you withdraw consent or delete them earlier.
Your cookie decision remains in your own browser until you clear it or change your choice.
Recipients and transfers
Within AFZ, enquiry data is accessed only by people who need it to assess and answer the request.
Vercel processes technical and enquiry data to host the website and execute the enquiry function. Resend processes the enquiry to deliver it by email. Google processes analytics data only after you allow Analytics.
Where these providers process data outside the EEA, the transfer is covered by an applicable adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses. Provider and transfer details should be reviewed as part of the final legal launch check.
Your rights
Under the GDPR you have the right to:
- Request access to the personal data we hold about you (Art. 15).
- Request rectification of inaccurate data (Art. 16) or erasure (Art. 17).
- Request restriction of processing (Art. 18) and data portability (Art. 20).
- Object to processing based on legitimate interest (Art. 21).
- Withdraw consent at any time with effect for the future (Art. 7(3)).
To exercise these rights, write to info@zellforschung.li. You also have the right to lodge a complaint with the Liechtenstein Data Protection Authority (Datenschutzstelle), Städtle 38, 9490 Vaduz, or with the supervisory authority of your habitual residence.
Security
This website is served exclusively over TLS-encrypted connections. We maintain technical and organisational measures appropriate to the risk, including access control, logging and regular review.
Changes to this policy
We update this policy when our processing or the legal framework changes. The version published here applies, with the date of last update stated alongside.