Privacy Policy
PREM SA | Last Updated: 05/18/26
This privacy policy explains how PREM SA (“PREM,” “we,” “us”) collects and processes personal data when you visit our website at premai.io. It applies to the corporate website only. For product-specific privacy information, see the applicable product privacy policy, available at the relevant product portal.
1. Controller
The controller responsible for processing personal data under this privacy policy is:
Data controller — PREM SA, Crocicchio Cortogna 6, 6900 Lugano, Switzerland.
EU Representative (GDPR Article 27) — PREM AI S.r.l., Via Giuseppe Verdi 6, 70017 Putignano (BA), Italy.
Data protection contact — privacy@premai.io.
Swiss supervisory authority — FDPIC, www.edoeb.admin.ch.
EU supervisory authority — your local EU data protection authority (GDPR Article 77).
2. Data We Collect
2.1 Data You Provide
(i) Contact form submissions (name, email, company, message) via Typeform.
(ii) Newsletter sign-up (email address).
(iii) Job applications submitted through Notion or linked career pages.
2.2 Data Collected Automatically
(i) Technical data: IP address, browser type and version, operating system, device type, screen resolution, referring URL.
(ii) Usage data: pages visited, time on page, click paths, scroll depth.
(iii) Cookies and similar technologies: see Section 7 below.
2.3 Data We Do Not Collect
This website does not collect special-category data (health data, biometric data, political opinions, etc.). The website does not process AI inference requests—product-level data processing is governed by the applicable product privacy policy.
3. Purposes and Legal Bases
We process personal data for the following purposes:
Responding to enquiries — performance of pre-contractual steps at your request under nDSG Art. 31(1) and GDPR Art. 6(1)(b).
Website analytics — consent under nDSG Art. 31(1) and GDPR Art. 6(1)(a), provided via our cookie consent banner. You can withdraw consent at any time through the cookie settings.
Security and fraud prevention — legitimate interest in protecting the website and detecting abuse under nDSG Art. 31(1) and GDPR Art. 6(1)(f).
Legal compliance — compliance with legal obligations under nDSG Art. 31(1) and GDPR Art. 6(1)(c).
Marketing communications — consent under nDSG Art. 31(1) and GDPR Art. 6(1)(a). You can withdraw consent at any time.
4. Recipients and Sub-processors
We share personal data only as necessary with the following service providers:
Framer — website hosting, based in the Netherlands/EU.
Typeform — contact form submissions, based in the EU.
Google Analytics — website analytics, based in the US. See Section 6 on international transfers. Google Analytics can be disabled through cookie settings.
Ghost — blog and newsletter services, based in the US.
We do not sell personal data. We do not share personal data with advertisers.
4.1 Google Workspace Integrations
If you elect to use any Google Workspace Integrations, the use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Retention
We retain personal data only for as long as necessary:
Contact form data — retained for the duration of correspondence, plus 12 months, then deleted.
Analytics data — retained for 26 months, in line with the Google Analytics default, then anonymized.
Security logs — retained for 90 days.
Newsletter subscribers — retained until you unsubscribe, plus 30 days.
6. International Transfers
Some sub-processors are based in the United States. Transfers from PREM SA to US-based processors are covered by:
(i) EU-US Data Privacy Framework (for self-certified US recipients).
(ii) Standard Contractual Clauses (SCCs, Commission Decision 2021/914) where the DPF does not apply.
(iii) Swiss-US Data Privacy Framework extension (for transfers from Switzerland).
A Transfer Impact Assessment has been conducted for each US-based sub-processor.
7. Cookies and Tracking Technologies
7.1 Cookie Categories
We use the following categories of cookies:
Strictly necessary — session cookies required for website functionality. No consent is required.
Analytics — Google Analytics cookies used to measure website traffic. These are set only with your consent.
Functional — cookies that remember your preferences, such as language and region. These are set only with your consent.
7.2 Cookie Consent
When you first visit premai.io, a cookie banner will ask for your consent before setting any non-essential cookies. You can change your preferences at any time by clicking the cookie settings link in the website footer. If you refuse analytics cookies, we will not set them and you can still use the website fully.
7.3 Do Not Track
We honor Do Not Track (DNT) browser signals. If your browser sends a DNT signal, no analytics cookies will be set.
8. Your Rights
Under the Swiss nDSG and the GDPR, you have the following rights:
(i) Right of access—to obtain confirmation of whether we process your personal data and to receive a copy (nDSG Art. 25 / GDPR Art. 15).
(ii) Right to rectification—to correct inaccurate data (nDSG Art. 32 / GDPR Art. 16).
(iii) Right to erasure—to request deletion of your data in specified circumstances (GDPR Art. 17).
(iv) Right to restriction—to restrict processing in specified circumstances (GDPR Art. 18).
(v) Right to data portability—to receive your data in a structured, machine-readable format (nDSG Art. 28 / GDPR Art. 20).
(vi) Right to object—to object to processing based on legitimate interests, including analytics (GDPR Art. 21).
(vii) Right to withdraw consent—at any time, without affecting the lawfulness of prior processing (GDPR Art. 7(3)).
To exercise any right, contact privacy@premai.io. We will respond within 30 days. You also have the right to lodge a complaint with the FDPIC or your local EU data protection authority.
To protect your privacy and security, we may take reasonable steps to verify your identity before fulfilling your request.
9. Children
This website is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data to us, please contact privacy@premai.io.
10. Changes to This Policy
We may update this policy from time to time. The “Last Updated” date at the top indicates the latest revision. Material changes will be communicated via a prominent notice on the website.
11. Contact
For any questions about this policy or to exercise your data protection rights:
Email: privacy@premai.io
Postal: PREM SA, Crocicchio Cortogna 6, 6900 Lugano, Switzerland
EU Representative: PREM AI S.r.l., Via Giuseppe Verdi 6, 70017 Putignano (BA), Italy