Privacy
This is a convenience translation. Only the German version is legally binding: German version of the privacy policy.
This policy describes which personal data is processed when you visit this website, for what purposes this is done and which rights you have.
In short: in normal operation the website itself sets no cookies, loads no tracking script and embeds no external fonts, videos, maps or social media plugins. Aggregated visitor figures come from the host’s data, without any script.
Controller
The controller for the processing of your personal data on this website is Denis Rastoder, Linthblick 14, 8725 Ernetschwil, Switzerland.
Email: de.rastoder@hotmail.com, WhatsApp: +41 76 341 17 90. You can also reach him through these channels with questions about data protection.
What this policy covers
This policy provides information on the processing of personal data when you visit this website, when you contact the operator and when public App Store reviews are used for this website. The apps have their own policies: Privacy of the Amanah app and Privacy of the AmanahKids app.
The Swiss Federal Act on Data Protection (FADP, DSG) applies. Amanah is also offered to people in Germany and Austria. Some of the processing described here concerns people located in the EU. Where it is connected with this offer, the EU General Data Protection Regulation (GDPR) also applies.
Visiting the website and hosting
The website is hosted by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (Cloudflare Pages). When you open a page, Cloudflare processes technically necessary data: your IP address, date and time, the address requested, details about your browser and other connection data.
The purpose is to deliver the website, operate it reliably and protect it against attacks and misuse.
Cloudflare processes, in particular, the log data made available to the operator and the content transmitted or stored through the service as a processor. According to its own statements, Cloudflare processes certain network, security and abuse data that it generates itself under its own responsibility.
Cloudflare processes some data on behalf of the operator. For this data, the contract limits retention to the end of the contract or, if earlier, to the point at which the processing is no longer necessary. For data processed under its own responsibility, Cloudflare itself determines the duration according to purpose and legal requirements, see the Cloudflare privacy policy (opens in a new window).
To see how the website is used, the operator and JNL IT Solutions see aggregated traffic figures in the website’s Cloudflare account: number of requests, data volume, individual visitors and countries. Cloudflare calculates these figures from its log data. For this, the website loads no script and sets no cookie. The operator receives no information on individual visits and creates no profiles.
Recipients and service providers
The operator uses Cloudflare for hosting, delivery and security. JNL IT Solutions, Horgen, provides technical support for the website as a processor (Art. 9 FADP). Microsoft is involved in emails, and WhatsApp in WhatsApp messages.
Apple and Instagram receive no data from the operator through your visit to the website. A connection to the respective provider is only established once you open a link to them.
Disclosure abroad
According to its own statements, Cloudflare processes the data in data centres in the USA and in Europe. Switzerland recognises an adequate level of data protection for the states of the EU and the EEA (Annex 1 of the Data Protection Ordinance).
For disclosures to Cloudflare, Inc. in the USA that are covered by the certification, the operator relies on the Swiss-U.S. Data Privacy Framework (Art. 16(1) FADP and Annex 1 No. 44 of the Data Protection Ordinance). Where the GDPR applies, the transfer is based on the adequacy decision on the EU-U.S. Data Privacy Framework. In each case a valid certification covering the transfer is required.
If this basis lapses, Cloudflare’s data processing agreement provides for standard contractual clauses (Art. 16(2)(d) FADP, Art. 46(2)(c) GDPR), with the necessary adaptations for Swiss data. The operator then checks whether these still permit the transfer and, if necessary, takes additional measures or suspends the transfer. You can obtain a copy of the relevant safeguards at de.rastoder@hotmail.com.
For disclosure in the case of email and WhatsApp, see the section “Contact via WhatsApp or email”.
Cookies and browser storage
In normal operation the website itself sets no cookies and uses no local browser storage (localStorage) or comparable storage. Fonts, images and programs are held on this website’s server.
The type test, the game “Make your choice” and the sample view “Your day with Amanah” process your input only in your browser. The website does not store it permanently and does not send it to the operator. The result card of the type test is also created in your browser and leaves your device only if you share it yourself.
Cloudflare may carry out a security check to protect the website. In that case the cookie “cf_clearance” may store that your browser has passed the check. You can block or delete cookies in your browser. Checks may then become necessary again or access may be impaired.
Contact via WhatsApp or email
If you write via WhatsApp or email, the operator processes your details in order to reply to you. These are, for example, your name, your telephone number or email address and the content of your message.
The operator deletes messages from his actively used records as soon as the request is completed and no follow-up questions remain open. Individual details are kept longer only to the extent that they are necessary for statutory retention obligations or specific legal claims. The communication providers' own rules apply to their own processing.
For emails the operator uses Outlook.com (Hotmail). According to Microsoft, the entity responsible for Switzerland is Microsoft Ireland Operations Limited. Microsoft may also store and process data in the USA and other countries. For the USA, Microsoft states that it relies on the Swiss-U.S. Data Privacy Framework and, where the GDPR applies, on the EU-U.S. Data Privacy Framework.
The WhatsApp button opens a chat with a prepared sentence. A connection to WhatsApp is only established when it is opened. Which WhatsApp company provides the service depends on the terms that apply to you. For the European Region, these generally name WhatsApp Ireland Limited. According to its own statements, WhatsApp also passes data on to the USA and other countries. The bases WhatsApp cites for this are set out in WhatsApp’s privacy policy.
Links to the App Store and Instagram
The buttons to the App Store and the link to Instagram are simple links. The website loads nothing from Apple or Meta. Only when you open a link do you connect to the respective provider, and its privacy policy applies.
If you share a link or a result, your device’s share menu opens or the link is copied to the clipboard. What you share, and with whom, is your own decision there.
App notice in Safari
Most pages contain a notice that allows Safari on iPhone and iPad to show a banner for the app in the App Store (Apple’s Smart App Banner). The website itself transmits no visitor data to Apple for this. Any connection between Safari and Apple originates from the browser and is subject to Apple’s privacy terms.
Reviews from the App Store
When the website is built, the operator retrieves publicly available reviews from Apple’s App Store, not when you visit. The website shows only stars, number, date and a summary of topics from them, without names and without verbatim quotations.
A dated reference copy is kept internally. For each review it contains the identification number at Apple, the country, the stars, the title, the text, the app version and the date, but no display names. It is not published and serves to substantiate the review figures shown on this website. The operator deletes it as soon as the figures it substantiates have been removed from the website or replaced by newer ones, unless individual details are needed for a specific legal dispute.
The source is the public App Store. The authors are not notified personally, because the operator holds no contact details for them and doing so would only be possible with disproportionate effort. This information is therefore made publicly available here. Where reviews contain religious beliefs that the authors themselves have made public, the processing is additionally based on Art. 9(2)(e) GDPR.
Legal bases under the GDPR
Where the GDPR applies, the technical provision and securing of the website and the aggregated traffic statistics are based on Art. 6(1)(f) GDPR. The legitimate interest is a secure, stable website free of misuse, and seeing how it is used.
The operator processes contact requests on the basis of Art. 6(1)(b) GDPR, to the extent that this is necessary for the performance of a contract with you or for pre-contractual measures that you have requested. He processes other requests on the basis of Art. 6(1)(f) GDPR. His legitimate interest is answering your request.
The internal reference copy of the App Store reviews is based on Art. 6(1)(f) GDPR. The legitimate interest is being able to substantiate the review figures stated on the website.
Necessity of the data
You are under no statutory or contractual obligation to use this website or to contact the operator. Without the connection data transmitted automatically when a page is opened, the website cannot be delivered. When you get in touch, the operator needs the details necessary to answer. If they are missing, he may be unable to answer your request.
No automated individual decision-making and no profiling with legal or similarly significant effect takes place.
Your rights
You can request information on whether and which personal data about you is processed (Art. 25 FADP). The information is generally free of charge and is, as a rule, provided within 30 days.
You can request the correction of inaccurate data (Art. 32(1) FADP) and expressly object to processing (Art. 30(2)(b) FADP, subject to a justification under Art. 31 FADP). In the case of unlawful processing you can in particular demand that the processing be prohibited or that your data be deleted or destroyed (Art. 32(2)(a) and (c) FADP). Under the conditions of Art. 28 FADP you can request the handover or transfer of your data in a common electronic format.
To do so, contact the operator by email. Where necessary, he will ask for reasonable proof of your identity, and for requests under the GDPR only where there are justified doubts.
If you do not agree with a response, you can contact the Federal Data Protection and Information Commissioner (FDPIC, EDÖB): FDPIC, Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch (opens in a new window).
Where the GDPR applies, you have, under the statutory conditions, the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15 to 21 GDPR). The operator answers requests under the GDPR generally within one month and informs you within that month of any permitted extension and its reasons. The processing described here is not based on consent, so withdrawal of consent is therefore not provided for. You can lodge a complaint with a supervisory authority in the EU, in particular at the place of your habitual residence, your place of work or the place of the alleged infringement (Art. 77(1) GDPR).
Your right to object under the GDPR
If the operator processes your personal data on the basis of a legitimate interest, you can object at any time on grounds relating to your particular situation (Art. 21(1) GDPR). To do so, write to de.rastoder@hotmail.com. He will then no longer process the data concerned, unless he demonstrates compelling legitimate grounds that override your interests, rights and freedoms, or he needs the data for the establishment, exercise or defence of legal claims.
Security
The website is delivered encrypted via HTTPS. It has no forms that send data, no login and no payment function. The operator and his processors take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration and misuse.
Changes
The operator amends this policy if the website or the processing of data changes. In the case of significant changes he also informs you in a suitable manner. The current version is published here.
Last updated: 7 October 2026
