Privacy Policy

Last updated: 20 July 2026

This policy describes how Paak collects, uses and protects the personal data processed on paak.club and within the Paak application. It is written in compliance with the Swiss Federal Act on Data Protection (FADP, revised version in force since 1 September 2023) and, where applicable, the European General Data Protection Regulation (GDPR — EU Regulation 2016/679).

1. Controller

Emmara by Cyrille Barraud, Swiss sole proprietorship (UID CHE-309.503.616), St. Alban-Anlage 25, 4052 Basel, Switzerland.
For any question related to personal data: contact@paak.club.

2. Who this applies to: visitor, app user, or club member

Three distinct situations must be distinguished:

3. Data we collect

3.1 Visitors of paak.club

3.2 App users (admin / staff accounts)

3.3 Data entered by clubs in the app

Clubs enter in Paak the data they need to manage their activity: member details, licences, fees, coaching, attendance, equipment. Paak hosts and secures this data on behalf of the club, without exploiting its content.

Two categories deserve a specific mention. Liability waiver: if the club has enabled a waiver at registration, the member's (or their legal guardian's) electronic signature is recorded together with the typed name, timestamp, IP address, browser identifier and a cryptographic fingerprint of the signed text — these elements constitute the proof of signature and are retained as such (see section 7). Gender: an optional field entered by the club or the member; it serves federation requirements (competition categories, licences) and aggregated, anonymised statistics — never individual profiling.

3.4 Member portal (account-less)

Every member can access a member portal without creating an account: the club emails them a secure personal link, and sensitive areas (profile, documents) additionally require a one-time code sent by email. The club remains the controller; Paak acts as processor (see section 2). In this context Paak processes:

4. Purposes

5. Legal bases (GDPR) / grounds of justification (FADP)

6. Processors and recipients

We rely on European processors to deliver the service. No data is transferred outside the European Union or Switzerland (see section 11 for the one exception, which is under your control).

ProviderRoleCountry
OVHcloudApplication and database hostingFrance (EU)
HankoAuthentication (passkeys, sessions)Germany (EU)
MollieOnline payments (fees, equipment, subscriptions)Netherlands (EU)
Brevo (ex-Sendinblue)Transactional emails and newslettersFrance (EU)
Matomo (self-hosted)Website analytics — on our own OVH serverFrance (EU)

Data-processing agreements (DPA, art. 28 GDPR / art. 9 FADP) are in place with each of these providers.

7. Retention

8. Your rights

Under the FADP and the GDPR, you have the following rights:

To exercise these rights on data managed by your club, address your club first (Paak acts as processor in that case). For data we process as controller (website, admin account, billing), write to contact@paak.club. We answer within 30 days.

9. Supervisory authority

You have the right to lodge a complaint:

10. Security

Data is encrypted in transit (TLS 1.2+), user passwords are replaced by passkeys (Hanko, passwordless authentication), database backups are encrypted. Administrator access is logged and protected by strong authentication.

11. International transfers

No data is transferred to a third country by the processing we operate. The entire infrastructure is hosted in the European Union, with exclusively European processors. Switzerland benefits from an adequacy decision from the European Commission, ensuring equivalent protection in both directions.

One exception is under your control: if you choose Sign in with Google on the login page, you authenticate directly with Google LLC (United States), which is certified under the EU-US and Swiss-US Data Privacy Frameworks. Our infrastructure and our processors remain European; optional third-party sign-in is the user's choice. Passkeys and email one-time codes, which are the default, involve no non-European provider.

12. Changes to this policy

We may update this policy to reflect legal or technical developments. The last update date appears at the top of this document. Material changes will be notified by email to active users.

Related pages