Data Protection

Privacy policy package

Tailored, compliant privacy policies for your website, app, recruitment and employees — delivered within 72 hours.

Compliant with EU-GDPR and Swiss data protection law
Privacy policies for websites, apps, recruitment & employees
Implementation within 72 hours after kick-off meeting
Transparent, all-inclusive pricing — from CHF 700 excl. VAT
Personalised advice from experienced CH and EU legal advisors
Trusted by 1000+ clients
Trusted by 1'500+ tech companies & investors
Thomas Kuster
"One of the main requirements under data protection law is the need to inform individuals of how you process their personal data. We take care of all data protection aspects of your company's information requirements — including cookies and similar tools you use in your operations. Book a call with me and my team."

Thomas Kuster · Partner @ LEXR  ·  Book your free call →

Trusted by businesses across Switzerland and beyond

Sandro Matter
Tapping into LEXR’s expertise and leveraging their advice was a great experience – as great as it can be when dealing with such an uncharming topic like data privacy. We kicked it off with an overall assessment. After that, a clear action plan with specific sub-task ownership and a pragmatic, hands-on approach were the key ingredients for successfully revamping our data privacy setup in view of the revised Data Protection Act.
Sandro Matter
Co-Founder & CFO, vlot

How we solve your challenges

From website and app policies to recruitment, employee and tailored notices — all your information obligations covered in one place.

Your website is often the first place prospective customers learn about your company. It is important to ensure your website is compliant with data protection laws and your visitors are informed of how their personal data is processed.

The data processing activities related to your app are different from those of your website or other services you provide. Moreover, app stores have specific data protection requirements that you need to comply with before offering it there. We help you create a policy specific to your app that fulfils all the necessary requirements.

As you execute your recruitment processes, you will collect information of applicants, such as CVs, education qualifications and previous work experience. You will need to inform how you process this personal data. Furthermore, if you use automatic decision-making systems in the recruitment process (e.g. application filtering software), there are legal requirements you have to fulfill in your privacy policy.

As you process personal data from your employees and staff, you will also need to inform them of the information you collect and for what purposes. This is especially critical in cases you store particularly sensitive information such as sick leave records or employees' religion.

Depending on your operations, you may need to create additional notices. LEXR's team can help you in creating tailored documents to your needs and information requirements, covering topics like AI and blockchain.

The LEXR approach

How we deliver Privacy Policy, AI-amplified

Step 01

Matter in

Brief us in plain language — we scope it and route it to the right specialist.

Intake < 4h
Step 02 AI · Privileged

AI does the heavy lifting

Our own AI stack drafts, reviews and cross-checks — inside privilege.

60% fewer draft cycles
Step 03

Senior lawyer signs off

The specialist who built the strategy reviews and signs every output.

Lars Fidan Maximilian Krähenbühl Christian Meisser
Step 04

Output delivered

On scope, on the quoted price — delivered into your workflow.

Scope and price are fixed in writing before we start — AI absorbs the lift, not your budget.

Our expert privacy policy services

One team for every data protection information requirement — from first analysis to published, compliant policy.

Website privacy policyApp privacy policyRecruitment privacy policyEmployee privacy policyCookie banner & consent textMultilingual policy draftingTailored AI & blockchain notices

Benefits of a LEXR privacy policy package

01

Consulting & best practices

Personalised advice from experienced CH and EU legal advisors who stay current on every update to Swiss data protection law and the EU-GDPR — so your policies reflect the latest requirements.

02

Full compliance, one stop-shop

All required privacy policies regarding the compliant disclosure of information to data subjects, meeting information requirements under the EU-GDPR and the Swiss Data Protection Act in a single engagement.

03

Efficient & cost-effective

Implementation within a maximum of 72 hours after the kick-off meeting at an attractive all-inclusive price — from CHF 700 excl. VAT per policy package, with no hidden billable hours.

Privacy policy FAQ

The questions businesses ask us most before we get started.

The requirements for a privacy policy are specified by the EU-GDPR and Swiss data protection law. For example, general information about data processing, such as the purpose, legal basis, duration of data processing, and any data transfers to third parties, must be provided. There must also be an indication of the rights of the data subject. The information must be precise, transparent and in plain language. You also have to inform users about the cookies or similar technologies that are installed or accessed on the user's end device — including tools such as Google Analytics 4, Google Ads, as well as embedded frames from other websites, such as YouTube and Vimeo videos.

A privacy policy is required whenever personal data is collected or processed. This includes not only names and e-mail addresses that are collected through a contact form, but also the IP address, which is often found in the server log files. This means that, for example, a website and an app almost always need a privacy policy.

The requirements in Switzerland are less strict than in the EU. However, if data of EU citizens is processed, it is quite possible that the requirements of the EU-GDPR also apply to Swiss companies. In addition, there are other legal requirements within the EU, such as the e-Privacy Directive. Simply put, under EU rules a cookie banner with opt-in functionality is required whenever the cookies and other technologies (e.g., pixels) used are not essential to the operation of the website. This includes tracking and analytics tools and the integration of social media plug-ins.

After the kick-off meeting where we gather all necessary information, we deliver your tailored privacy policy within 72 hours. The package includes one iteration round, and a 30-minute final meeting to address any remaining questions before you publish.

The base package starts from CHF 700 excl. VAT per policy package. If you need the policy in multiple languages, each additional language is available at CHF 300 excl. VAT.

Let's get started

Book your free call and become one of our 1'000+ happy clients.

Dive deeper into data protection

Data ProtectionAI Features in Your SaaS? What the EU AI Act Means for YouTeam LEXR · Mar 2026Read more →Data ProtectionYou Need to Fix These 5 Points in Your SaaS Agreements Now!Nadine Saalbach · Sep 2025Read more →Data ProtectionNavigating the EU AI Act: A Comprehensive Analysis and Compliance GuideTeam LEXR · May 2024Read more →Data ProtectionNew EU Regulations: A Blueprint for Growth in the Digital SectorTeam LEXR · May 2024Read more →Data ProtectionCybersecurity and data protection: keeping your company's data safeTeam LEXR · Apr 2024Read more →Data ProtectionFrom concept to compliance: Legal Bases for AI training explainedTeam LEXR · Mar 2024Read more →Data ProtectionData Processing Agreements: Navigating the Essentials for Data Protection Compliance (Part 2)Team LEXR · Feb 2024Read more →Data ProtectionData Processing Agreements: Navigating the Essentials for Data Protection Compliance (Part 1)Team LEXR · Jan 2024Read more →Data ProtectionPseudonymisation versus anonymisation: a practical privacy guideTeam LEXR · Dec 2023Read more →Data ProtectionHow to handle data breaches – a privacy best practice guideTeam LEXR · Sep 2023Read more →Data ProtectionNavigating AI tools and data protection: A guide for compliant company practicesTeam LEXR · Jul 2023Read more →Data ProtectionThe new Swiss Data Protection Act comes into force: What tech companies need to do nowTeam LEXR · Jun 2023Read more →Data ProtectionNavigating Privacy Rules for App Developers: App Store Compliance and Privacy RequirementsTeam LEXR · Apr 2023Read more →Data ProtectionKYC for FinTech companies: Data protection guide part 3 - Manage the dataTeam LEXR · Mar 2023Read more →Data ProtectionKYC for FinTech companies: Data protection guide part 2 - Follow the dataTeam LEXR · Feb 2023Read more →Data ProtectionKYC for FinTech companies - Guide to a data protection compliant implementationTeam LEXR · Feb 2023Read more →Data ProtectionChecklist: How to write a privacy policy for the new FADP and GDPR?Team LEXR · Jun 2021Read more →Data ProtectionData Processing Agreement I: Determine whether you are a Controller or a ProcessorTeam LEXR · Apr 2021Read more →Data ProtectionSchrems II impact on privacy shield & SCCsTeam LEXR · Jul 2020Read more →Data ProtectionGDPR impact on AdTech and Real-Time Bidding (RTB)Team LEXR · May 2020Read more →Data ProtectionConfidential Computing and GDPRTeam LEXR · Mar 2020Read more →Data ProtectionThe License to Kill and the right to be forgotten - Gaming in the Age of GDPRTeam LEXR · Mar 2020Read more →Data ProtectionEmployee awareness as the key to security and data privacyTeam LEXR · Feb 2020Read more →Data ProtectionThe Internet of Things in the GDPR eraTeam LEXR · Jan 2020Read more →Data ProtectionGDPR in Switzerland - What it means for businessesTeam LEXR · Dec 2018Read more →