Privacy Policy — Switzerland

Last updated: 26 July 2026
Status: draft for the Swiss market, pending legal review. The content reflects Paak's actual processing activities (see the ROPA in NLPD-COMPLIANCE.md); it will be reviewed by counsel before we make an "nFADP-compliant" claim on the homepage again.

This notice describes how Paak collects, uses and protects the personal data processed through the paak.club website and the Paak application — for users and clubs based in Switzerland. It is aligned with the revised Federal Act on Data Protection (nFADP / FADP, SR 235.1), in force since 1 September 2023, and with the EU General Data Protection Regulation (GDPR) where that applies.

1. Controller

Emmara by Cyrille Barraud, Swiss sole proprietorship (UID CHE-309.503.616), St. Alban-Anlage 25, 4052 Basel, Switzerland.
Contact for all data-protection matters: contact@paak.club.

2. Three distinct situations: site visitors, app users, club members

We distinguish three cases:

3. Data collected

3.1 Visitors to the paak.club website

3.2 Application users (admin / staff account)

3.3 Data managed by the club within the application

Clubs record in Paak the data they need to run the club: member contact details, federation licences, membership fees, coaching staff, attendance, equipment. Paak hosts and secures this data on the club's behalf, without using its content for its own purposes.

3.4 Sensitive data — health and injuries (Art. 5 lit. c nFADP)

Where a club records health-related information about an athlete (medical certificate, injury notes, emergency contact, severe allergies), that data qualifies as sensitive personal data within the meaning of Art. 5 lit. c nFADP. Processing it requires explicit consent from the member if of age — or from their legal representative for a minor (Art. 6 §7 nFADP). Paak provides the club with the interface to collect that consent; the substantive legal basis remains with the club as controller.

A scanned medical certificate is not required in Paak: by default only the expiry date is stored. If the club does upload a scan, access is restricted to club administrators and the document appears in no public export.

3.5 Sensitive data — criminal-record extracts for supervising staff

When checking the suitability of supervising staff (coaches, staff), Paak records only the extract number and the expiry date. No scan or photograph of the special private extract (Art. 371a of the Swiss Criminal Code, in force since 1 January 2015) is stored. Physical verification of the document takes place outside the platform and follows the Swiss Olympic Ethics Statute.

3.6 Member area (portal without an account)

Every member can use a member area without creating an account: the club sends a secure personal link by email, and sensitive areas (profile, documents) additionally require a one-time code delivered by email. The club remains the controller; Paak acts as processor (see section 2). Within this scope Paak processes:

4. Purposes of processing

5. Justifications (nFADP) / legal bases (GDPR)

6. Processors and recipients

We use European processors exclusively. No data leaves the European Union or Switzerland (see section 11 for the one exception, which is under your control). The EU is listed in Annex 1 of the Data Protection Ordinance (SR 235.11) as providing an adequate level of protection for the purposes of the nFADP.

ProviderRoleCountry
OVHcloudHosting of the application and the databaseFrance (EU)
HankoAuthentication (passkeys, sessions)Germany (EU)
MollieOnline payments (membership fees, equipment, subscriptions; TWINT supported)Netherlands (EU)
Brevo (formerly Sendinblue)Transactional emails and newsletterFrance (EU)
Matomo (self-hosted)Audience measurement — on our own OVH serverFrance (EU)

A data processing agreement is in place with each of these providers (DPA, Art. 9 nFADP / Art. 28 GDPR). An overview of those DPAs and their reach for the Swiss context is documented in our internal dossier (see NLPD-COMPLIANCE.md §3 — Vendor DPA Matrix).

7. Retention periods

8. Your rights (Art. 25-27 nFADP)

Under the nFADP and the GDPR you have the following rights:

For rights over data managed by your club, contact your club first (Paak then acts as processor). For data we process as controller (website, admin account, invoicing), write to contact@paak.club. We reply within 30 days at the latest, in accordance with Art. 25 §7 nFADP.

9. Supervisory authority

The competent authority in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC / EDÖB / PFPDT), Feldeggweg 1, 3003 Bern — edoeb.admin.ch.

Data breaches can be reported through the portal at edoeb.admin.ch/en/databreach-2. Under Art. 24 nFADP, Paak reports breaches likely to result in a high risk to the personality or fundamental rights of a data subject to the FDPIC "as soon as possible". Where the GDPR applies, we notify without undue delay and at the latest within 72 hours (Art. 33 GDPR).

If you reside in the EU you may additionally contact your national supervisory authority (CNIL in France, BfDI in Germany, DSB in Austria, GBA/APD in Belgium, and so on).

10. Security

Data is encrypted in transit (TLS 1.2+). Authentication is password-free: it relies on passkeys (WebAuthn) with a one-time code sent by email as a fallback, through Hanko. Database backups are encrypted at rest. Administrative access is logged and protected by stronger authentication. Our multi-tenant architecture strictly isolates each club's data at the level of database queries (with dedicated test coverage — IDOR / cross-tenant).

11. International transfers

No transfer to a third country takes place through the processing we operate. The entire infrastructure is hosted in the European Union and every processor is established in the EU. Switzerland and the EU benefit from a mutual adequacy decision, which guarantees an equivalent level of protection in both directions.

One exception is under your control: if you choose Sign in with Google on the login page, you authenticate directly with Google LLC (United States), which is certified under the EU-US and Swiss-US Data Privacy Frameworks. Our infrastructure and our processors remain European; optional third-party sign-in is the user's choice. Passkeys and email one-time codes, which are the default, involve no non-European provider.

12. Changes to this notice

We may update this notice to reflect legal or technical developments. The date of the last update appears at the top. Material changes are communicated to active users by email.

Related pages