Cookie Policy
Last updated: 14 September 2026
This page explains which cookies videodesign.com sets and how you change your consent.
Contents
1. Who is responsible
The controller is Videodesign.ch GmbH, Pilatusstrasse 18, 6003 Lucerne, Switzerland. Contact: [email protected]. The privacy policy describes all other processing of personal data.
This cookie policy supplements the privacy policy. It covers only what the website videodesign.com stores in or reads from your device's browser, which third-party services are loaded in the process, and how you decide about them. Everything else – the contact form, e-mail, job applications, server log files, your rights in detail – is governed by the privacy policy. Where the privacy policy describes cookies in general terms, this policy is the more specific and more current statement.
Our data protection representative in the European Economic Area under Art. 27 GDPR is VGS Datenschutzpartner GmbH, Hamburg; contact details are in section 1.2 of the privacy policy.
This policy applies to the German and the English edition of the website.
2. What cookies and similar technologies are
Cookies are small text files that a website places in your device's browser. The browser sends them back with every further request to the same domain. This lets a website recognise you, remember a choice or operate a service. Cookies set by our own domain videodesign.com are "first-party cookies". Cookies set by an embedded third-party service – a video player, for example – under its own domain are "third-party cookies"; we have no technical access to them and can neither read nor delete them.
A cookie either has a fixed lifetime (persistent cookie) or is deleted when you close the browser (session cookie). The lifetimes given in this policy are maximums; you can delete any cookie earlier at any time.
Besides cookies, this website uses your browser's local storage ("localStorage"). Unlike a cookie, a localStorage entry is never sent to a server; it stays on your device until you delete it or reset the setting. We use it for a single setting that you make yourself: the appearance, light or dark (see section 4.1). This policy treats cookies and localStorage entries alike: the same categories and the same consent logic apply.
We do not use tracking pixels, browser fingerprinting or similar techniques. We use sessionStorage only for the three entries listed below; they are limited to the open browser tab and are deleted when the tab closes at the latest.
3. How consent works
3.1 Four categories
Consent covers four categories. They correspond exactly to the four switches in the cookie settings:
- Necessary: theme and the consent record itself. These cookies are always on because the site does not work without them. The switch is visible but cannot be turned off.
- Analytics: usage and advertising-conversion measurement, only after consent.
- Marketing: advertising audiences and remarketing via Google Ads and the LinkedIn Insight Tag, only after consent.
- Embeds: Google Maps, Calendly, Vimeo and YouTube after consent.
If you choose “Accept content” on a blocked item, you give your consent for the entire “Embeds” category.
3.2 What "necessary" means and why you cannot decline it
We classify as necessary only what records your own decision or action: the cookie holding your cookie choice, the setting for the appearance and the three short-lived sessionStorage entries listed in section 4.1. Apart from the newsletter entry, none of these entries contains information about you as a person; none is used for analytics or advertising. With the exception of the consent cookie, they are only ever written when you do something yourself: operate a switch, submit the contact form or pause the photo gallery. They do not require consent (Art. 45c lit. b of the Swiss Telecommunications Act (FMG); Art. 6(1)(f) GDPR; Art. 5(3), second sentence, of Directive 2002/58/EC). That is why the category cannot be deselected in the settings.
You can nevertheless delete or block these entries in your browser at any time. The website remains readable; it can then no longer remember your cookie decision, shows the cookie prompt on every visit and keeps embedded content blocked.
3.3 Reject and accept carry equal weight
Reject and accept have the same visual weight in the banner. The cookie prompt appears at the bottom left on your first visit, does not block the page and offers three equal paths: "Accept all", "Reject" and "Settings". "Reject" is a single click and declines all optional categories – exactly as fast as "Accept all". In the settings you choose analytics, marketing and embeds individually and confirm with "Save selection". Optional categories are never pre-ticked: as long as you have not chosen, everything optional counts as declined (opt-in). Until you decide, no optional cookie is set and no third-party server is contacted.
3.4 Where your decision is stored
Consent is stored on this device in the cookie cc_cookie: consentId, timestamps, categories, services and revision. The revision is 3. There is no server-side log that identifies you by a persistent user identifier.
In detail, the cookie contains: the accepted categories ("categories"), the revision of this policy ("revision", currently 3), the time of your first and of your latest decision ("consentTimestamp", "lastConsentTimestamp"), a randomly generated identifier ("consentId"), the services accepted per category ("services"), the language of the prompt ("languageCode"), the expiry date ("expirationTime") and an empty data field ("data"). The identifier is generated in your browser at your first click, exists only in this cookie and is neither stored by us nor linked to other data. Its purpose is that your browser recognises your decision – not that we recognise you.
The cookie is written on each of the three buttons, including "Reject". It is valid for 182 days from your latest decision; after that the website asks again. It is a first-party cookie for videodesign.com (SameSite=Lax, Secure). Like any cookie it is technically transmitted to our hosting provider with page requests; we do not evaluate it there and keep no consent log. The proof of your consent is this cookie itself.
4. Which cookies and storage entries we use
The following overview is complete for everything videodesign.com sets itself. For third-party services we list what the provider documents; which cookies its server actually sets in a given case also depends on your browser, your region and any account you hold with the provider.
4.1 Necessary
These entries are set exclusively by videodesign.com. Apart from the newsletter entry, none contains information about you as a person.
| Name | Provider | Purpose | Category | Duration | Legal basis |
|---|---|---|---|---|---|
| cc_cookie | videodesign.com (first party; software: vanilla-cookieconsent, self-hosted) | Stores your cookie decision: categories, revision, timestamps, random identifier (section 3.4). Also set on "Reject". | Necessary | 182 days from the latest decision | Art. 45c lit. b FMG; Art. 6(1)(f) GDPR; Art. 5(3), second sentence, Directive 2002/58/EC (storage of the consent itself) |
| videodesign-theme (localStorage) | videodesign.com (first party) | Remembers your choice "light" or "dark". Written only when you pick an appearance in the settings menu; "System" deletes the entry. Value: "light" or "dark". | Necessary | Unlimited – until you choose "System" or clear the site data in your browser | ditto (setting explicitly chosen by you) |
| videodesign-contact-thankyou (sessionStorage) | videodesign.com (first party) | Set after the contact form has been submitted successfully so that the thank-you page can show the confirmation once. Contains no personal data. Deleted on first read. | Necessary | Only in the open browser tab; deleted when the tab closes at the latest | ditto |
| videodesign-contact-newsletter (sessionStorage) | videodesign.com (first party) | Set after the contact form has been submitted successfully; contains a signed token, valid for ten minutes, holding the email address entered in the form so that the thank-you page can offer the newsletter subscription without asking for the address again. Deleted on first read. The address is transmitted to our newsletter service (Mailchimp) only if you trigger the subscription yourself. | Necessary | Only in the open browser tab; deleted when the tab closes at the latest | ditto |
| videodesign-photo-carousel-paused (sessionStorage) | videodesign.com (first party) | Remembers within the tab whether you have paused the photo gallery on the team or jobs page. Contains no personal data. | Necessary | Only in the open browser tab; deleted when the tab closes at the latest | ditto |
4.2 Analytics and advertising measurement
The website loads Google Tag Manager only if you allow "Analytics" or "Marketing". Google Analytics 4 and Google Ads measurement run through it only if "Analytics" is allowed; the website passes your choice per category to the Google services it loads (Google Consent Mode). Google Tag Manager does not set cookies itself; the services it loads can set the cookies listed below. The provider in Europe is Google Ireland Limited. Google LLC can process data in the USA and is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework. Section 5 explains the transfer. The cookies that are actually set depend on the services published in Tag Manager, your browser and your region.
| Name | Provider | Purpose | Category | Duration | Legal basis |
|---|---|---|---|---|---|
| _ga | Distinguishes users for Google Analytics 4 | Analytics | 2 years | Consent (Art. 6(1)(a) GDPR; Art. 45c lit. b FMG); transfer to the USA: section 5 | |
| _ga_6Y22RXT4F0 | Stores the session state for Google Analytics 4 | Analytics | 2 years | ditto | |
| _gcl_au | Supports Google Ads conversion measurement | Analytics | 90 days | ditto | |
| _gcl_aw | Links an ad click to a later conversion | Analytics | 90 days | ditto |
4.3 Marketing
Only if you allow "Marketing" may the services loaded through Google Tag Manager recognise you for advertising: Google Ads remarketing and audiences, and the LinkedIn Insight Tag (section 5.5). For this, Google Ads may set the following cookie in addition to those in section 4.2; LinkedIn sets the following cookies under the domain linkedin.com. The entries come from the providers' cookie tables; which cookies are set in your case depends on whether you are logged in to LinkedIn, on your browser and on your region.
| Name | Provider | Purpose | Category | Duration | Legal basis |
|---|---|---|---|---|---|
| IDE | Google (domain doubleclick.net) | Per Google: advertising and security | Marketing | 13 months (EEA/UK) | Consent (Art. 6(1)(a) GDPR; Art. 45c lit. b FMG); transfer to the USA: section 5 |
| li_sugr | LinkedIn (domain linkedin.com) | Per LinkedIn: used to make a probabilistic match of a user's identity | Marketing | 90 days | ditto |
| bcookie | LinkedIn (linkedin.com) | Per LinkedIn: browser identifier cookie to uniquely identify devices accessing LinkedIn, to detect abuse and for diagnostic purposes | Marketing | 1 year | ditto |
| lidc | LinkedIn (linkedin.com) | Per LinkedIn: to facilitate data center selection | Marketing | 24 hours | ditto |
| UserMatchHistory | LinkedIn (linkedin.com) | Per LinkedIn: LinkedIn Ads ID syncing | Marketing | 30 days | ditto |
| AnalyticsSyncHistory | LinkedIn (linkedin.com) | Per LinkedIn: stores information about the time a sync took place with the lms_analytics cookie | Marketing | 30 days | ditto |
| li_gc | LinkedIn (linkedin.com) | Per LinkedIn: stores consent of guests regarding the use of cookies for non-essential purposes | Marketing | 6 months | ditto |
| lms_ads | LinkedIn (linkedin.com) | Per LinkedIn: used to identify LinkedIn Members off LinkedIn for advertising | Marketing | 30 days | ditto |
| lms_analytics | LinkedIn (linkedin.com) | Per LinkedIn: used to identify LinkedIn Members off LinkedIn for analytics | Marketing | 30 days | ditto |
| li_fat_id | LinkedIn (linkedin.com) | Per LinkedIn: member indirect identifier for conversion tracking, retargeting, analytics | Marketing | 30 days | ditto |
| ln_or | LinkedIn (linkedin.com) | Per LinkedIn: used to determine if Oribi analytics can be carried out on a specific domain | Marketing | 1 day | ditto |
4.4 Embeds
These cookies only come into existence when you switch the "Embeds" category on. Before that, the website shows a preview image from our own server in place of the content, plus a notice with the link "cookie settings"; the third party's server is not contacted.
4.4.1 Technical companion cookies of the embed manager (first party)
After your consent, the software that unlocks embedded content sets one marker cookie per service with the value "1". It contains no identifier. The website does not read your decision from these cookies but from cc_cookie; they are deleted as soon as you switch "Embeds" off again. They are set on every page while the category is active – including pages without an embed.
| Name | Provider | Purpose | Category | Duration | Legal basis |
|---|---|---|---|---|---|
| im_googlemaps | videodesign.com (first party; software: iframemanager, self-hosted) | Marks Google Maps as unlocked. Value "1", no identifier. | Embeds | 182 days; deleted when the category is withdrawn | Consent (Art. 6(1)(a) GDPR; Art. 45c lit. b FMG) |
| im_calendly | videodesign.com (first party; software: iframemanager) | Marks Calendly as unlocked. Value "1". | Embeds | 182 days; deleted on withdrawal | ditto |
| im_vimeo | videodesign.com (first party; software: iframemanager) | Marks Vimeo as unlocked. Value "1". | Embeds | 182 days; deleted on withdrawal | ditto |
4.4.2 Google Maps (third party)
Where: contact page (map of our location). What loads: an iframe from www.google.com with the map view. Google documents the cookies of its services in general, not specifically for embedded maps; the following entries come from Google's page "How Google uses cookies" (per provider documentation — verify before launch).
| Name | Provider | Purpose | Category | Duration | Legal basis |
|---|---|---|---|---|---|
| NID | Google (domain google.com) | Per Google: preferences such as your preferred language; also security and advertising | Embeds | 6 months | Consent; transfer to the USA: section 5 |
| SOCS | Google (google.com) | Per Google: state of your cookie choices at Google | Embeds | 13 months | ditto |
| AEC | Google (google.com) | Per Google: detection of abuse and fraud | Embeds | 6 months | ditto |
| __Secure-ENID | Google (google.com) | Per Google: preferences (alternative to NID, depending on your cookie choices at Google) | Embeds | 13 months | ditto |
4.4.3 Calendly (third party)
Where: contact page (appointment booking). The Calendly booking page loads as an iframe only after you consent to the "Embeds" category in our cookie settings. This consent also covers the Calendly cookies described below. Calendly's cookie banner is hidden in our embed. Calendly remains the controller for its own cookies. The provider documents used for this policy do not list individual cookie names or durations for optional cookies, so we describe the documented groups.
| Name | Provider | Purpose | Category | Duration | Legal basis |
|---|---|---|---|---|---|
| Session cookies of the booking page | Calendly (domain calendly.com) | Technical operation of the booking page | Embeds | Session | Consent; transfer to the USA: section 5 |
| Optional Calendly cookies | Calendly and its service providers | Improvement and personalisation, interaction analysis and marketing according to the provider documentation | Embeds | Not stated in the provider documents used | Your consent to "Embeds"; Calendly is the controller for these cookies |
4.4.4 Vimeo (third party)
Where: home page (showreel and example videos in the video window) and blog posts that contain a Vimeo video. What loads: an iframe of the Vimeo player from player.vimeo.com. Vimeo documents the cookies of its embedded player in the Help Center article "Vimeo Player Cookies" (per provider documentation — verify before launch). Our embed does not currently use the "dnt=1" (Do Not Track) parameter with which Vimeo refrains from setting new cookies.
| Name | Provider | Purpose | Category | Duration | Legal basis |
|---|---|---|---|---|---|
| vuid | Vimeo (domain vimeo.com) | Per Vimeo: Vimeo-generated ID for analytics information for the video owner | Embeds | 2 years | Consent; transfer to the USA: section 5 |
| player | Vimeo | Per Vimeo: player preferences (volume, quality, captions) | Embeds | 1 year | ditto |
| flags | Vimeo | Per Vimeo: feature flags enabled by the video owner | Embeds | 1 year | ditto |
| player_clearance | Vimeo | Per Vimeo: bot prevention | Embeds | 7 days | ditto |
| cf_clearance | Cloudflare (for Vimeo) | Per Vimeo: bot prevention | Embeds | 1 year | ditto |
| __cf_bm | Cloudflare (for Vimeo) | Per Vimeo: bot management | Embeds | 30 minutes | ditto |
| _cfuvid | Cloudflare (for Vimeo) | Per Vimeo: enforcement of rate limiting | Embeds | Session | ditto |
4.4.5 YouTube (third party)
Where: blog posts that embed a YouTube video. What is loaded: an iframe of the YouTube player from www.youtube-nocookie.com. We embed only this "no-cookie" host, never youtube.com, and we do not use the YouTube IFrame Player API (a Google script). Nothing is sent to Google before you consent: the preview image is served from our own server, and the iframe is created only after you allow the "Embeds" category. The provider is Google Ireland Limited; Google also processes data in the USA, see section 5.
According to Google, the "no-cookie" host sets no personalisation cookies for as long as no video is played. Once you start playback, Google may set the entries below (per provider documentation — verify before launch).
| Name | Provider | Purpose | Category | Duration | Legal basis |
|---|---|---|---|---|---|
| VISITOR_INFO1_LIVE | YouTube (Google) | Per Google: estimates bandwidth and picks the player variant | Embeds | 6 months | Consent; transfer to the USA: section 5 |
| YSC | YouTube (Google) | Per Google: session identifier for the player's view statistics | Embeds | Session | ditto |
| VISITOR_PRIVACY_METADATA | YouTube (Google) | Per Google: stores the visitor's cookie choice | Embeds | 6 months | ditto |
4.5 Hosting – no cookie set by us
The website is delivered as a static site via Cloudflare Pages. Our own server sets no cookie. Cloudflare may set one technically necessary cookie to protect against automated traffic (__cf_bm, lifetime 30 minutes); it serves security only and belongs to the «Necessary» category.
Cloudflare Turnstile checks whether a contact request comes from a person. When the form is sent, the IP address, browser data, and security-check result are sent to Cloudflare. Per Cloudflare, Turnstile sets the technically necessary cf_clearance cookie when a challenge is solved. Provider and transfer: Cloudflare, Inc.; see section 5.4.
5. Third-party services and international transfers
As soon as you switch "Embeds" on, your browser loads the respective content directly from the provider's server. The provider necessarily receives your IP address, the address of the page you are viewing (referrer), browser and device data and any cookies it previously set under its domain. If you are logged in with the provider, it can attribute the request to your account there. We receive no data from these providers that identifies you as a person.
All providers named here are based in the USA. Since 15 September 2024 Switzerland recognises US companies certified under the Swiss-U.S. Data Privacy Framework (DPF) as recipients providing adequate data protection (Art. 16(1) Swiss Data Protection Act); for persons in the EU the European Commission's adequacy decision on the EU-U.S. DPF applies (Art. 45 GDPR). Where a provider additionally relies on Standard Contractual Clauses (Art. 46(2)(c) GDPR), we say so. We have taken the certification statements from the providers' privacy policies.
5.1 Google Maps
What loads after consent
An iframe from www.google.com with the map view of our location (Pilatusstrasse 18, Lucerne). We use only the Google Maps embed address, not the Google Maps JavaScript API; no Google script runs on our page. The map loads only once it scrolls into view. Google may set its own cookies inside the map (section 4.4.2).
Provider and transfer
Google Ireland Limited (Ireland) for users in the EEA and in Switzerland; Google LLC (USA). Google LLC is certified under the EU-U.S. DPF, its UK Extension and the Swiss-U.S. DPF (Google, "Data Privacy Framework", effective 23 August 2025). Privacy policy: policies.google.com/privacy. Cookies: policies.google.com/technologies/cookies.
5.2 Calendly
What loads after consent
An iframe with our booking page calendly.com/videodesign/erstberatung. We do not use the Calendly widget script. Whatever you enter in the booking form – name, e-mail address, any details about the appointment – you transmit directly to Calendly; Calendly processes this data on our behalf and makes it available to us so that we can hold the appointment. The embed loads only after your consent to "Embeds". This consent also covers Calendly's cookies; its own cookie banner is hidden in our embed. Calendly itself is the controller for these cookies (section 4.4.3).
Provider and transfer
Calendly, LLC, 115 E Main St., Ste A1B, Buford, GA 30518, USA. EU representative: [email protected]. Calendly states that it complies with the EU-U.S. DPF, its UK Extension and the Swiss-U.S. DPF and additionally relies on Standard Contractual Clauses for transfers (Calendly Privacy Notice, effective 3 July 2026). Privacy notice: calendly.com/legal/privacy-notice.
5.3 Vimeo
What loads after consent
An iframe of the Vimeo player from player.vimeo.com with the respective video. On the home page the player opens in a video window when you start the showreel or an example video; in blog posts it appears in place of the video. The preview image shown before consent comes from our server, not from Vimeo. We load neither Vimeo player scripts nor Vimeo's preview interface. Short decorative videos on the website are stored on our own server and do not involve Vimeo. Vimeo sets its own cookies inside the player, including an identifier for viewing statistics that we, as the video owner, only see in aggregated form (section 4.4.4).
Provider and transfer
Vimeo.com, Inc., 330 West 34th Street, 10th Floor, New York, NY 10001, USA. EU representative: EDPO, Avenue Huart Hamoir 71, 1030 Brussels, Belgium; Swiss representative: EDPO Switzerland Sàrl, Rue de Lausanne 37, 1201 Geneva. Vimeo states that it complies with the EU-U.S. DPF, its UK Extension and the Swiss-U.S. DPF and uses Standard Contractual Clauses where appropriate (Vimeo Privacy Policy, last updated 19 September 2025). Privacy policy: vimeo.com/privacy. Player cookies: Vimeo Help Center, "Vimeo Player Cookies".
5.4 Hosting
The website is delivered via Cloudflare Pages. In doing so Cloudflare necessarily processes your IP address and your browser's request data (server log files; privacy policy section 8.2). The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework; the transfer relies on that certification.
5.5 LinkedIn Insight Tag
What loads after consent
Only if you allow "Marketing" does Google Tag Manager load the LinkedIn Insight Tag, a script from LinkedIn. It reports the visit to our pages to LinkedIn so that we can later show visitors advertising on LinkedIn and measure the effect of our LinkedIn ads. LinkedIn receives your IP address, the address of the page you are viewing, browser and device data and the cookies named in section 4.3. If you are logged in to LinkedIn, LinkedIn can attribute the visit to your account. We receive only aggregated reports, no information about individual persons. According to LinkedIn, direct identifiers are removed within seven days and the remaining pseudonymised data is deleted within 180 days.
Provider and transfer
LinkedIn Ireland Unlimited Company (Ireland) for users in the EEA and in Switzerland; LinkedIn Corporation (USA). LinkedIn Corporation is certified under the EU-U.S. DPF, its UK Extension and the Swiss-U.S. DPF and additionally relies on Standard Contractual Clauses for certain transfers (LinkedIn, "EU/EEA, UK, and Swiss data transfers"). Privacy policy: linkedin.com/legal/privacy-policy. Cookies: linkedin.com/legal/l/cookie-table.
6. Changing or withdrawing consent
Open the cookie settings via the button on this page. If you withdraw a category you previously granted, the page reloads, because a script that is already running cannot be unloaded.
You have four ways:
- The button "Open cookie settings" at the end of this page. It opens the same window as on your first visit. There you switch categories on or off and confirm with "Save selection" – or you choose "Reject" or "Accept all".
- The link in every blocked content block: wherever a map, a booking form or a video is not loaded for lack of consent, a notice with the link "cookie settings" opens the same window.
- Footer: the entry "Cookie Policy" in the footer of every page leads to this page and thus to the button.
- Browser: you can delete or block cc_cookie and all other entries in your browser settings at any time. The cookie prompt then appears again on your next visit. Cookies that a third party set under its own domain (section 4.4) cannot be deleted by us; that is only possible in your browser or with the provider.
Withdrawing is as easy as granting: one click on "Reject" in the settings withdraws all optional categories. Withdrawal takes effect for the future; the lawfulness of processing up to that point is unaffected (Art. 7(3) GDPR). After withdrawal the companion cookies of the embed manager are deleted and embedded content is replaced by the preview image again.
Why the page reloads: a website cannot retroactively stop a service your browser is already running. Only a reload guarantees that nothing is still running after the withdrawal. The reload is therefore not an error but the proof that the withdrawal has taken effect. When you add a category, the page does not reload.
7. Your rights
You have the right to access, rectification, erasure, restriction of processing, data disclosure and data portability, as well as the right to object to processing and to withdraw consent at any time (section 6). These rights, their limits and the procedure are described in section 6 of the privacy policy.
For the cookies and storage entries described in this policy this means in practice: we hold no data about them on our systems; the entries exist only in your browser. We can therefore answer an access request about these entries only with what is on this page – and you delete the entries fastest yourself (section 6). For cookies that a third party sets under its own domain, you exercise your rights directly with the provider; contact details are in section 5.
Please send requests to [email protected] or by post to Videodesign.ch GmbH, Pilatusstrasse 18, 6003 Lucerne, Switzerland. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC); where the GDPR applies, also with the data protection supervisory authority competent for you in the EU or EEA.
8. Changes to this policy
We amend this policy whenever the cookies, services or legal bases used change. The current version, with its date, is always on this page.
Every version that affects the scope of the cookies carries a revision number that is stored in the website. The current revision is 3. When we raise the revision – for example because an analytics service is added – consent given earlier is no longer valid for the new version, and the cookie prompt appears again on your next visit. You therefore do not have to check yourself whether your consent is still current. Purely editorial changes that do not affect the scope of the cookies do not trigger a new prompt.