Privacy Policy — Switzerland
Last updated: 26 July 2026This notice describes how Paak collects, uses and protects the personal data processed through the paak.club website and the Paak application — for users and clubs based in Switzerland. It is aligned with the revised Federal Act on Data Protection (nFADP / FADP, SR 235.1), in force since 1 September 2023, and with the EU General Data Protection Regulation (GDPR) where that applies.
1. Controller
Emmara by Cyrille Barraud, Swiss sole proprietorship (UID CHE-309.503.616), St. Alban-Anlage 25, 4052 Basel, Switzerland.
Contact for all data-protection matters: contact@paak.club.
2. Three distinct situations: site visitors, app users, club members
We distinguish three cases:
- Visitors to paak.club — you browse our public pages or complete a contact form. Data about you is processed by Paak as controller.
- Paak application users (club management, coaches, club staff) — you have created an account and manage a club. Your account data is processed by Paak as controller.
- Members of clubs managed in Paak (members, parents, minors) — your data is entered by the club that registered you. In this case the club is the controller and Paak acts as a processor within the meaning of Art. 9 nFADP (and Art. 28 GDPR). To exercise your rights, contact your club first.
3. Data collected
3.1 Visitors to the paak.club website
- Contact form / waiting list — first name, last name, email, stated role, club. Legal basis: consent (Art. 6 §6 nFADP; Art. 6 §1 a GDPR).
- Technical data — truncated IP address, browser type, pages visited — via our self-hosted Matomo instance. Only if you accept analytics cookies (see the Cookie Policy).
3.2 Application users (admin / staff account)
- Authentication data (email, Hanko session token), first and last name, role within the club.
- Billing data on a paid plan (billing email and name, transaction history).
- The minimum technical traces required for operation and security (access logs, login history, failed attempts).
3.3 Data managed by the club within the application
Clubs record in Paak the data they need to run the club: member contact details, federation licences, membership fees, coaching staff, attendance, equipment. Paak hosts and secures this data on the club's behalf, without using its content for its own purposes.
3.4 Sensitive data — health and injuries (Art. 5 lit. c nFADP)
Where a club records health-related information about an athlete (medical certificate, injury notes, emergency contact, severe allergies), that data qualifies as sensitive personal data within the meaning of Art. 5 lit. c nFADP. Processing it requires explicit consent from the member if of age — or from their legal representative for a minor (Art. 6 §7 nFADP). Paak provides the club with the interface to collect that consent; the substantive legal basis remains with the club as controller.
A scanned medical certificate is not required in Paak: by default only the expiry date is stored. If the club does upload a scan, access is restricted to club administrators and the document appears in no public export.
3.5 Sensitive data — criminal-record extracts for supervising staff
When checking the suitability of supervising staff (coaches, staff), Paak records only the extract number and the expiry date. No scan or photograph of the special private extract (Art. 371a of the Swiss Criminal Code, in force since 1 January 2015) is stored. Physical verification of the document takes place outside the platform and follows the Swiss Olympic Ethics Statute.
3.6 Member area (portal without an account)
Every member can use a member area without creating an account: the club sends a secure personal link by email, and sensitive areas (profile, documents) additionally require a one-time code delivered by email. The club remains the controller; Paak acts as processor (see section 2). Within this scope Paak processes:
- Portal session data — cryptographic hash (SHA-256) of the link and of the one-time code (never stored in clear text), timestamps for creation, last activity, expiry and revocation, IP address and browser. Purpose: operating and securing the portal. Justification: performance of the contract with the club and an overriding interest in security.
- Documents submitted voluntarily by the member — medical certificate or licence, uploaded through the portal with explicit, versioned consent captured at the moment of upload (sensitive data: Art. 5 lit. c nFADP; Art. 9 §2 lit. a GDPR where applicable). Files are stored encrypted in dedicated storage and are accessible only to the club concerned, which reviews and validates them. The retention periods in section 3.4 apply. Uploading online is optional: the document can be handed to the club directly at any time, with no disadvantage to the member. The consent covers the digital transmission channel — the document itself is required by the club's or the federation's own rules.
- Privacy settings — the portal includes a consent centre where the member can review and withdraw consent at any time; withdrawal applies to consent-based processing such as submitted documents. Processing that rests on an overriding interest (for example aggregated statistics) can be objected to. A request to restrict processing switches the portal to read-only mode.
4. Purposes of processing
- Providing the Paak services and support.
- Handling member payments and invoicing (Mollie, Netherlands).
- Sending operational communications (registration confirmations, payment reminders, security alerts).
- Improving the product using aggregated statistics (only with cookie consent).
- Meeting legal obligations (accounting duties under Art. 958f of the Swiss Code of Obligations, requests from authorities).
5. Justifications (nFADP) / legal bases (GDPR)
- Performance of a contract (Art. 31 §2 lit. a nFADP; Art. 6 §1 b GDPR) — user accounts, invoicing, operating the service.
- Consent (Art. 6 §6 and §7 nFADP; Art. 6 §1 a GDPR) — analytics cookies, optional contact forms, marketing communications, processing of sensitive data.
- Legitimate interest (Art. 31 §2 lit. d nFADP; Art. 6 §1 f GDPR) — security of the service, fraud prevention, functional improvement.
- Legal obligation (Art. 31 §2 lit. c nFADP; Art. 6 §1 c GDPR) — Swiss accounting rules (Art. 958f CO, 10 years), disclosures to authorities.
6. Processors and recipients
We use European processors exclusively. No data leaves the European Union or Switzerland (see section 11 for the one exception, which is under your control). The EU is listed in Annex 1 of the Data Protection Ordinance (SR 235.11) as providing an adequate level of protection for the purposes of the nFADP.
| Provider | Role | Country |
|---|---|---|
| OVHcloud | Hosting of the application and the database | France (EU) |
| Hanko | Authentication (passkeys, sessions) | Germany (EU) |
| Mollie | Online payments (membership fees, equipment, subscriptions; TWINT supported) | Netherlands (EU) |
| Brevo (formerly Sendinblue) | Transactional emails and newsletter | France (EU) |
| Matomo (self-hosted) | Audience measurement — on our own OVH server | France (EU) |
A data processing agreement is in place with each of these providers (DPA, Art. 9 nFADP / Art. 28 GDPR). An overview of those DPAs and their reach for the Swiss context is documented in our internal dossier (see NLPD-COMPLIANCE.md §3 — Vendor DPA Matrix).
7. Retention periods
- User account — for the duration of use, then up to 90 days after termination before final deletion.
- Billing data — 10 years (Swiss accounting obligation, Art. 958f CO).
- Waiting lists and contact requests — up to 2 years after the last exchange, unless you unsubscribe.
- Health data / medical certificate — duration of membership + 12 months (insurance challenge window), then final deletion.
- Member data managed by the club — according to the club's own policy. Deletion requests go through the club.
- Member-area sessions — deleted 90 days after expiry or revocation; one-time codes 30 days after use or expiry.
- Documents submitted through the member area — for as long as the club retains them; deleted immediately if the right to erasure is exercised.
- Technical security logs — 12 months maximum.
8. Your rights (Art. 25-27 nFADP)
Under the nFADP and the GDPR you have the following rights:
- Right of access (Art. 25 nFADP) — obtain a copy of your data.
- Rectification (Art. 32 nFADP) — correct inaccurate or incomplete data.
- Erasure — request deletion of your data (subject to legal obligations).
- Restriction — temporarily suspend processing you contest.
- Objection — refuse processing based on legitimate interest or marketing.
- Data portability (Art. 28 nFADP) — receive your data in a structured, machine-readable format.
- Withdrawal of consent at any time, without retroactive effect.
For rights over data managed by your club, contact your club first (Paak then acts as processor). For data we process as controller (website, admin account, invoicing), write to contact@paak.club. We reply within 30 days at the latest, in accordance with Art. 25 §7 nFADP.
9. Supervisory authority
The competent authority in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC / EDÖB / PFPDT), Feldeggweg 1, 3003 Bern — edoeb.admin.ch.
Data breaches can be reported through the portal at edoeb.admin.ch/en/databreach-2. Under Art. 24 nFADP, Paak reports breaches likely to result in a high risk to the personality or fundamental rights of a data subject to the FDPIC "as soon as possible". Where the GDPR applies, we notify without undue delay and at the latest within 72 hours (Art. 33 GDPR).
If you reside in the EU you may additionally contact your national supervisory authority (CNIL in France, BfDI in Germany, DSB in Austria, GBA/APD in Belgium, and so on).
10. Security
Data is encrypted in transit (TLS 1.2+). Authentication is password-free: it relies on passkeys (WebAuthn) with a one-time code sent by email as a fallback, through Hanko. Database backups are encrypted at rest. Administrative access is logged and protected by stronger authentication. Our multi-tenant architecture strictly isolates each club's data at the level of database queries (with dedicated test coverage — IDOR / cross-tenant).
11. International transfers
No transfer to a third country takes place through the processing we operate. The entire infrastructure is hosted in the European Union and every processor is established in the EU. Switzerland and the EU benefit from a mutual adequacy decision, which guarantees an equivalent level of protection in both directions.
One exception is under your control: if you choose Sign in with Google on the login page, you authenticate directly with Google LLC (United States), which is certified under the EU-US and Swiss-US Data Privacy Frameworks. Our infrastructure and our processors remain European; optional third-party sign-in is the user's choice. Passkeys and email one-time codes, which are the default, involve no non-European provider.
12. Changes to this notice
We may update this notice to reflect legal or technical developments. The date of the last update appears at the top. Material changes are communicated to active users by email.
Related pages
- Legal Notice
- Cookie Policy (Switzerland) — cookies and trackers used on the site
- Privacy Policy — France (EU) version