Last updated: June 18, 2026
1. Data Controller
The controller responsible for processing personal data is:
Demircan Core Operations
DEMCO.ai
Yilmaz Demircan
Gitschenstrasse 1
6460 Altdorf UR
Switzerland
Email: info@demco.ai
Phone: +41 76 700 02 01
Website: www.demco.ai
2. What This Privacy Policy Covers
This Privacy Policy explains which personal data Demircan Core Operations processes in connection with the website www.demco.ai, communications, appointment bookings, advisory services, Recruiting Advisory, organizational diagnostics, Events, Digital Transformation projects, and other business relationships.
Personal data is any information relating to an identified or identifiable natural person. Examples include names, email addresses, phone numbers, IP addresses, professional details, communication content, appointment details, contract data, application data, candidate data, organizational assessment data, and technical usage data.
We process personal data carefully, for specified purposes, proportionately, and in accordance with applicable Swiss data protection law.
If foreign data protection law, particularly the EU General Data Protection Regulation (GDPR), also applies in an individual case, we take it into account in that context.
3. Data Processing Principles
We process personal data only to the extent necessary, appropriate, and permissible for the relevant purpose.
We pay particular attention to:
- Transparency
- Purpose limitation
- Proportionality
- Data accuracy
- Appropriate data security
- Limited retention
- Careful selection of service providers
- Protection of confidential information
- Human responsibility for evaluations and decisions
4. Personal Data We Process
Depending on the contact, website use, engagement, or business relationship, we may process the following personal data in particular:
Contact data:
Last name, first name, company, role, address, email address, phone number, and other contact details.
Communication data:
Messages, emails, contact form content, conversation notes, appointment details, WhatsApp messages, follow-up questions, responses, and other correspondence.
Technical data:
IP address, date and time of access, browser type, operating system, device type, referrer URL, pages visited, log data, cookie information, and similar technical information.
Appointment and booking data:
Requested appointment, service booked, inquiry, time zone, contact details, reminders, confirmations, cancellations, and other information provided voluntarily.
Business and contract data:
Proposals, orders, service descriptions, contracts, invoice data, payment information, accounting data, project information, and supplier and partner data.
Consulting and project data:
Information about the organization, roles, processes, leadership, culture, collaboration, goals, KPIs, roadmaps, decision-making materials, and project progress.
Recruiting Advisory and hiring process data:
Information about roles, contributions to organizational impact, requirements profiles, competency models, interview guides, scorecards, selection criteria, communication standards, candidate experience, hiring processes, recruiting metrics, and decision-making processes.
Application, candidate, interview, and scorecard data:
Where DEMCO.ai receives access to specific application, candidate, interview, feedback, or evaluation documents as part of a Recruiting Advisory engagement, personal information about applicants or candidates may also be processed. This may include, in particular, professional details, resumes, qualifications, interview notes, scorecard ratings, availability, expectations, communication data, and process-related evaluations.
Organizational diagnostics, assessment, and survey data:
Responses, analyses, profiles, competency, motivation, behavior, or personality indicators, team profiles, results reports, and feedback data.
Event and workshop data:
Participant data, registrations, attendance, interests, feedback, organizational details, and, where applicable, photo, video, or audio recordings, provided such recordings are announced or agreed.
Sensitive personal data is processed only if this is necessary for the specific purpose, an appropriate basis exists, consent has been given, or another permissible justification applies.
5. Purposes of Data Processing
We process personal data for the following purposes in particular:
- Operating, securing, maintaining, and optimizing the website
- Handling inquiries
- Scheduling and conducting initial consultations
- Preparing, entering into, performing, and completing engagements
- Providing consulting, analysis, Recruiting Advisory, organizational assessment, event, and transformation services
- Structuring, professionalizing, and developing recruiting processes
- Developing role profiles, interview guides, scorecards, communication standards, hiring metrics, and decision-making materials
- Enabling internal hiring teams
- Improving the candidate experience
- Communicating with clients, prospective clients, applicants, candidates, partners, service providers, and authorities
- Preparing proposals, concepts, analyses, roadmaps, presentations, reports, invoices, and contract documents
- Conducting organizational diagnostics, assessments, surveys, workshops, and events
- Internal organization, quality assurance, business management, and documentation
- Improving services, processes, and the user experience
- Protecting against spam, misuse, attacks, and unauthorized access
- Fulfilling legal, tax, accounting, and regulatory obligations
- Enforcing, asserting, or defending legal claims
6. Bases for Processing
We process personal data in particular when:
- Processing is necessary to perform a contract or take pre-contractual measures
- The individual concerned provides data voluntarily
- Consent has been given
- Legal obligations must be fulfilled
- Overriding private or public interests exist
- Processing is necessary to provide our services securely, efficiently, and professionally
Consent may generally be withdrawn with effect for the future, provided no statutory, contractual, or legitimate grounds for retention prevent this.
7. Website, Hosting, and Server Log Data
Technical data is processed automatically when you visit our website. This may include your IP address, date and time of access, browser type, operating system, device type, pages accessed, referrer URL, and similar log data.
This data is used to provide the website, ensure stability and security, analyze errors, prevent misuse, and improve usability.
Hosting, domain, website builder, security, and IT service providers may be used for the website's technical operation. These providers process data as part of their respective technical functions and, where necessary, on the basis of contractual data protection provisions.
8. Contact Form, Email, and Phone
If you contact us using a contact form, by email, or by phone, we process the information you provide. This includes, in particular, your name, email address, phone number, company, message, time of contact, and any other information you provide voluntarily.
We use this data to handle your inquiry, communicate with you, and, where applicable, prepare or carry out a contractual relationship.
Please do not provide particularly confidential or sensitive information through the contact form, by email, or by phone unless expressly agreed.
9. Technical Form and Spam Protection
The contact form uses technical safeguards such as session-based CSRF protection, an invisible control field, a minimum completion time, and a simple rate limit on repeated submissions.
When you access the contact form, a technically necessary session cookie may be set for this purpose, remaining valid until the end of the browser session. It is used solely for form security, not for analytics or advertising.
Google reCAPTCHA and other external spam protection services are not loaded in the current production build.
10. Communication via WhatsApp Business
If you communicate with us via WhatsApp Business, we process, in particular, your phone number, name, message content, timestamps, communication metadata, and other information you send through WhatsApp.
WhatsApp is a service of the Meta group. When you use it, WhatsApp or Meta may also process data outside Switzerland. We do not have full control over data processing by WhatsApp or Meta.
Please use WhatsApp only for general inquiries and appointment coordination. Confidential, sensitive, or business-critical information should be sent through suitable secure communication channels only after prior agreement.
11. External Appointment Booking
The website currently links to the external service SumUp Bookings for appointment bookings. The service opens in a new browser tab and is not embedded in this website.
If you book an appointment through such a third-party platform, the following data in particular may be processed:
- Name and contact details
- Email address and phone number
- Requested appointment
- Service booked
- Time zone
- Optional message or inquiry
- Confirmation, reminder, and cancellation data
- Payment or booking data, where applicable
Providers may process this data to provide and manage appointment bookings, send confirmations and reminders, operate the service technically, and, where applicable, process payments.
The provider's privacy policy and terms of use also apply to data processing by SumUp Bookings. Where the provider independently determines the purposes and means of its data processing, it is responsible for that processing.
12. Payment and Invoice Processing
Where services are chargeable or payments are processed through third parties, payment, invoice, and transaction data may be processed. This includes, in particular, billing address, service, amount, payment status, payment method, posting date, and payment references.
Banks, payment service providers, and accounting or fiduciary service providers may be used for payment processing. They process data for payment processing, accounting, statutory retention obligations, and record-keeping obligations.
13. Cookies and Similar Technologies
DEMCO.ai does not use preference, analytics, marketing, or tracking cookies in the current production build.
A technically necessary session cookie may be set when you access the contact form. It supports CSRF protection, is configured with HttpOnly and SameSite=Strict, and generally expires at the end of the browser session.
External services may use their own cookies or similar technologies after you deliberately open an external link. The respective provider's privacy information applies.
You can block or delete cookies in your browser settings. Blocking the technically necessary session cookie may prevent secure use of the contact form.
If non-essential analytics or marketing technologies are added in the future, they will be activated only after the required technical and legal review and, where applicable, valid consent.
14. Analytics and Marketing Services
No analytics, advertising, or marketing services are integrated into the current production build. No corresponding third-party scripts are loaded.
Before such services are activated in the future, this Privacy Policy, the technical consent mechanisms, and information about the providers involved must be updated accordingly.
Personal data is not shared or sold for advertising purposes.
15. Social Media and External Links
Our website may contain links to social media profiles, messaging services, booking platforms, or other external websites. Clicking these links takes you away from our website. The respective operator is responsible for data processing on external websites.
We do not have full control over which data external providers process when you visit their services. Please refer to the respective providers' privacy information.
16. Advisory Services, Consulting, Recruiting Advisory, and Digital Transformation
As part of advisory, Consulting, Recruiting Advisory, and Digital Transformation engagements, information about organizations, roles, processes, leadership, culture, collaboration, HR and recruiting processes, candidate experience, KPIs, roadmaps, tool environments, and project progress may be processed, depending on the assignment.
Where such information relates to individuals, we process it only within the agreed engagement, for the necessary preparation, delivery, documentation, and quality assurance, and to fulfill legal or contractual obligations.
17. Recruiting Advisory and Hiring Process Data
Through Recruiting Advisory, Demircan Core Operations helps companies make their recruiting processes clearer, more structured, and more measurable.
Recruiting Advisory means, in particular, helping companies establish professional recruiting processes and develop them with clear purpose. Together with the client company, we clarify the impact a position should have within the company, the competencies that matter most, and how to structure selection decisions.
Depending on the assignment, the following data and information in particular may be processed:
- Role and requirements profiles
- Contributions made by positions to organizational impact
- Competency models
- Interview guides
- Scorecards and evaluation frameworks
- Communication standards
- Candidate experience information
- Hiring process data
- Recruiting metrics
- Materials informing processes, roles, and decisions
- Training, workshop, and feedback materials
- Details of participating hiring managers, HR leads, and people involved in interviews
Where Demircan Core Operations | DEMCO.ai receives access to specific application, candidate, interview, feedback, or evaluation documents as part of an engagement, personal information about applicants or candidates may also be processed. This may include, in particular, contact details, professional details, resumes, qualifications, interview notes, scorecard ratings, availability, expectations, communication data, and process-related evaluations.
Such data is processed only to the extent necessary, appropriate, and permissible for the relevant engagement.
Through Recruiting Advisory, DEMCO.ai supports, in particular, the structuring, professionalization, and enablement of internal hiring processes. The respective client company makes selection, hiring, contractual, and compensation decisions on its own responsibility.
DEMCO.ai does not make decisions about applicants or candidates based solely on automated processing. Digital or AI-assisted tools may support structuring, analysis, or documentation, but do not replace human judgment and responsibility.
Active candidate sourcing, direct candidate outreach, personnel placement, temporary staffing, or sharing candidate profiles with clients is not part of Recruiting Advisory unless expressly agreed separately in writing.
18. Organizational Diagnostics, Assessments, and Surveys
Organizational diagnostics, assessments, surveys, feedback, or development formats may generate responses, analyses, and competency, motivation, behavior, personality, or team profiles.
Such data may be sensitive and is treated with particular care. The specific processing depends on the assignment, the method used, the group of individuals concerned, the purpose of the analysis, and the agreed confidentiality rules.
Depending on the agreement, results may be analyzed individually, in aggregate, or in anonymized form. Access to results reports is defined in the respective assignment or procedure.
Organizational diagnostics and assessment results are not used in isolation or on a solely automated basis to make decisions. They support structured reflection, development, selection, or organizational analysis and are evaluated in the context of other information.
19. Events, Workshops, Photos, and Videos
For events, workshops, offsites, or similar formats, participant data, registration data, organizational information, feedback, and, where applicable, photo, video, or audio recordings may be processed.
If photo, video, or audio recordings are made, we inform the individuals concerned appropriately. For publication for marketing or reference purposes, we obtain consent where required or rely on another permissible basis.
20. Use of Artificial Intelligence
Demircan Core Operations may use artificial intelligence and digital working tools to produce research, analyses, structured materials, documents, concepts, processes, project documents, or decision-making materials more efficiently.
Where personal data is processed in this context, it is processed for specified purposes, proportionately, and with due regard to appropriate technical and organizational safeguards.
Confidential client data, application, candidate, interview, scorecard, or organizational assessment data, and sensitive personal data will not be entered into external AI systems without an appropriate basis, a security review, and contractual safeguards.
Automated individual decisions that have legal effects or similarly significant adverse effects are not made unless expressly stated otherwise in an individual case.
Final responsibility for evaluations, recommendations, and decisions remains with people.
21. Disclosure of Personal Data to Third Parties
We may disclose personal data to third parties where necessary to provide our services, communicate, perform contracts, provide technical services, fulfill legal obligations, or safeguard legitimate interests.
Recipients may include, in particular:
- IT, hosting, domain, website, and security service providers
- Email, calendar, appointment booking, and communication tools
- Payment, accounting, fiduciary, and banking service providers
- Organizational diagnostics, assessment, or survey providers
- AI, cloud, office, and productivity tools, where permissible and appropriate
- Client companies, HR leads, hiring teams, applicants, candidates, or project participants within specific Recruiting Advisory, consulting, or organizational assessment engagements
- Legal advisers, insurers, authorities, or courts
- Subcontractors or project partners, where necessary for an engagement
Personal data is not shared for advertising purposes or sold.
22. Data Processors and Service Providers
When we have service providers process personal data, we select them with reasonable care and ensure appropriate contractual, technical, and organizational safeguards.
Where necessary, we enter into data processing agreements or comparable data protection agreements.
23. International Data Transfers
Personal data may be processed in Switzerland, the European Economic Area, the United Kingdom, the United States, or other countries, particularly when third-party providers, cloud services, communication services, appointment booking services, AI systems, or IT service providers are used.
If personal data is transferred to countries without an adequate level of data protection, we implement appropriate safeguards to the extent required by law. These may include, in particular, standard contractual clauses, contractual guarantees, technical safeguards, encryption, access restrictions, or other permissible mechanisms.
In individual cases, a transfer may also be based on a statutory exception, such as consent, performance of a contract, enforcement of legal rights, or overriding interests.
24. Retention Periods
We retain personal data only for as long as necessary for the relevant purposes, consent remains in place, statutory retention obligations apply, or legitimate interests exist.
Contact and communication data:
Generally for as long as necessary to handle the inquiry, maintain the business relationship, keep records, or defend or enforce claims.
Appointment booking data:
For as long as necessary for appointment management, follow-up, documentation, and any subsequent communication.
Contract, invoice, and accounting data:
In accordance with statutory retention obligations, generally for ten years.
Recruiting Advisory and hiring process data:
For the duration of the relevant consulting, workshop, analysis, or optimization engagement, and thereafter only for as long as necessary for documentation, quality assurance, follow-up communication, contractual obligations, statutory retention obligations, or legitimate interests.
Application, candidate, interview, and scorecard data:
Where specific application, candidate, interview, or scorecard data is processed as part of an engagement, retention is governed by the respective assignment, agreed purposes, confidentiality rules, and legal requirements.
Organizational diagnostics, assessment, and survey data:
In accordance with the respective assignment, agreed purposes, confidentiality rules, and legal requirements.
Event data:
For as long as necessary for organization, delivery, follow-up, billing, documentation, or legitimate interests.
Data is deleted, anonymized, or blocked as soon as its purpose no longer applies and no statutory, contractual, or legitimate grounds for retention prevent this.
25. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.
Depending on the context, these include access restrictions, password protection, encryption, careful selection of service providers, contractual data protection provisions, secure communication channels, internal confidentiality rules, and regular reviews of relevant processes.
Despite careful measures, absolute security cannot be guaranteed, particularly when communicating over the internet, by email, or through messaging services.
26. Rights of Data Subjects
Under applicable data protection law, individuals concerned may assert the following rights in particular:
- Access to information about personal data being processed
- Rectification of inaccurate personal data
- Deletion or destruction of personal data, provided no statutory or legitimate grounds for retention prevent this
- Restriction of or objection to certain processing, where provided for by law
- Release or transfer of personal data, where provided for by law
- Withdrawal of consent with effect for the future
- Exercise of other rights under applicable data protection law
Requests may be sent to info@demco.ai. Proof of identity may be required to process requests.
Individuals concerned may also contact the Federal Data Protection and Information Commissioner (FDPIC).
27. Information for Individuals in the EEA or the United Kingdom
If the EU GDPR or comparable foreign data protection regulations apply in an individual case, the individuals concerned may have additional rights. These may include, in particular, rights of access, rectification, erasure, restriction, data portability, objection, and complaint to a competent data protection supervisory authority.
This information does not establish the general applicability of foreign data protection law to all data processing by Demircan Core Operations.
28. Changes to This Privacy Policy
We may amend this Privacy Policy at any time, particularly when the website, services used, our data processing, or legal requirements change.
The current version published on this website applies.