Earlier quoted context omitted.
Really not trying to be devil's advocate here, but the company is based in Switzerland, and neither Switzerland nor UK are in the EU.
If you offer something to EU residents, you have to comply with GDPR. Even if you are not part of the EU.
These GDPR conversations tend to pointlessly go back and forth on this because one side is describing the GDPR from the point of view of: what does the law say? The other is looking at it from the point of view of: I only have to follow my country’s laws.
The latter is closer to correct in some technical sense; laws have finite jurisdictions. But the EU has a big market and so lots of entities play ball with them, to some extent, in general, so it is probably better for most people to comply.