This Data Protection Statement forms an integral part of our General Terms and Conditions (“T&Cs”) and is also referred to in our Impressum / Legal Notice.
The revised Swiss Federal Act on Data Protection (FADP) applies to our processing of personal data. Where we offer services to individuals in the EU / EEA or are otherwise subject to the EU General Data Protection Regulation (GDPR), we also comply with the GDPR for those processing activities.
“Personal data” means any information relating to an identified or identifiable natural person.
If you provide us with personal data of other individuals (e.g. employees, participants, family members), please ensure that you are authorised to do so and that such data is accurate.
1. Controller and Contact
The controller responsible for the processing described in this Data Protection Statement is:
Márcia Ayacaba
Elevation Leadership
Chemin des Bluets 5
1009 Pully
Switzerland
Email: marcia@elevation.coach
If you have any questions about this Data Protection Statement or about how we process personal data, you can contact us at the above address or email.
At present, we have not appointed a statutory data protection officer under Swiss law. If we are required to appoint a data protection officer or an EU/EEA representative in the future, we will update this Data Protection Statement accordingly.
2. Categories of Personal Data We Process
We primarily process personal data that we receive directly from you, from our customers and business partners, or from persons acting on their behalf. We may also collect certain data automatically when you use our websites or platforms. The categories of Personal Data we process are:
2.1 Master and Contract Data
- Name, title, gender
- Contact details (postal address, email address, phone number)
- Company / organisation, role or function
- Contractual relationship and correspondence
- Services and programs booked, participation history
- Invoice and basic payment information (e.g. payment method, payment status)
2.2 Coaching and Program Data
In the context of coaching, workshops and programs, we may process:
- Information you share during coaching sessions or in preparation / follow-up (e.g. your goals, your challenges, your personal and professional context)
- Exercises, assignments, feedback forms and notes relating to your participation
- Information on attendance, completion of modules and learning progress
We do not actively seek medical diagnoses or detailed health-related data. If you voluntarily decide to share such information, we will treat it with particular care and will not keep any written record. Please note that our services do not replace medical or psychological treatment (see Section 3 of our T&Cs).
2.3 Payment Data
When you pay for our services online, your payment is processed via external payment service providers, in particular:
Stripe Payments Europe, Limited
3 Dublin Landings
North Wall Quay
Dublin 1
D01 C4E0
Ireland
- We do not receive or store your full credit card number or card verification value (CVV/CVC).
- We only receive limited payment information such as the payment method, the result of the transaction (success / failure), and, where applicable, the last four digits of the card, the card type and a tokenised reference from the payment provider for reconciliation and accounting purposes.
Payment service providers process payment data under their own responsibility and/or as processors on our behalf. Their own privacy notices apply in addition to this Data Protection Statement.
2.4 Online Usage and Communication Data
- Technical data (e.g. IP address, device ID, browser type and version, operating system, date and time of access)
- Log data about the use of our websites and platforms (e.g. pages viewed, length of visit, navigation paths)
- Data from cookies and similar technologies (see Section 4)
- Communication data (e.g. emails, messages via contact forms, booking confirmations, notes from calls or video calls)
2.5 Data from Third Parties
To the extent permitted by law, we may also obtain personal data from third parties, such as:
- Your employer or contracting organisation (for corporate programs only)
- Co-facilitators, trainers and business partners involved in delivering services
- Publicly accessible sources (e.g. social media profiles, professional profiles, company websites)
- Service providers (e.g. payment providers, video-conferencing tools, learning platforms)
3. Purposes of Processing and Legal Bases
We process personal data mainly for the following purposes and on the following legal bases:
3.1 Provision of Services and Contract Performance
- Planning, delivery and administration of coaching sessions, programs and workshops
- Managing user accounts and access to online platforms
- Handling bookings, payments, invoices and accounting
- Customer support and communication
Legal bases:
Performance of a contract or pre-contractual measures; legitimate interests in providing our services; compliance with legal obligations (e.g. accounting, tax).
For payments, we use external payment service providers (e.g. Stripe). These providers process payment data under their own responsibility and/or as processors on our behalf. Their own privacy notices apply in addition to this Data Protection Statement and our T&Cs (Section 4).
3.2 Relationship Management and Communication
- Maintaining and developing relationships with clients, participants, partners and suppliers
- Responding to enquiries (e.g. by email or via contact forms)
- Organising and documenting meetings, calls and workshops
Legal bases:
Legitimate interests in effective communication and relationship management; performance of contract.
3.3 Marketing, Information and Events
- Sending information about our services, programs, news and events (e.g. newsletters, email campaigns)
- Conducting satisfaction surveys, feedback rounds and evaluations
- Market and opinion research to improve our offerings
Legal bases:
Legitimate interests in informing existing customers and improving our services; consent where required (e.g. for certain marketing communications under telecom / unfair competition laws).
You can object to direct marketing at any time (see Section 10).
3.4 Operation and Optimisation of Websites and Platforms
- Ensuring the secure and stable operation of our websites, learning platforms and IT systems
- Analysing use of our websites and platforms to improve usability, content and security
- Managing cookie and tracking technologies (see Section 4)
Legal bases:
Legitimate interests in the secure, efficient and user-friendly operation of our online services; consent where required for non-essential cookies and tracking technologies.
3.5 Legal Compliance and Risk Management
- Compliance with Swiss and foreign legal obligations (e.g. tax, accounting, reporting obligations)
- Enforcement or defence of legal claims
- Prevention and investigation of misuse, security incidents and fraud
Legal bases:
Legal obligations; legitimate interests in the protection of our rights, security and property.
3.6 Consent
Where we rely on your consent (e.g. for certain marketing activities or specific uses of data), we will inform you separately. You may withdraw consent at any time with effect for the future. The lawfulness of processing based on consent before its withdrawal remains unaffected.
4. Cookies, Tracking and Similar Technologies
We use cookies and similar technologies on our websites and platforms to provide and improve our services.
Cookies are small text files stored on your device when you visit our website. Similar technologies include pixels, tags and local storage.
4.1 Types of Cookies and Tools
We may use:
- Necessary cookies to enable core functions such as navigation, security, and booking processes. These are required for the website and platforms to function properly.
- Preference and functional cookies to remember settings (e.g. language, login preferences).
- Analytics / performance cookies to understand how visitors use our sites and platforms (e.g. pages visited, duration of visits).
- Marketing / tracking technologies to display or measure relevant content and communications.
Some of these tools are provided by third parties (e.g. analytics or hosting providers) that may process personal data on our behalf or as independent controllers.
4.2 Legal Bases and Control
Depending on the tool and applicable law:
- Necessary cookies are used based on our legitimate interests in providing a functional, secure website and platform.
- Other cookies / tracking technologies are used based on your consent, obtained via a cookie banner or settings interface.
You can:
- manage your cookie preferences via the cookie banner or browser settings, and
- delete cookies already stored on your device.
If you disable certain cookies or technologies, parts of the website or platform may no longer function properly.
5. Disclosure of Personal Data and Data Transfers Abroad
5.1 Recipients in Switzerland and Abroad
In connection with the purposes set out in Section 3, we may disclose personal data to the following categories of recipients:
- IT service providers (e.g. hosting, email and collaboration tools, learning platforms, video-conferencing systems)
- Payment service providers (e.g. Stripe) for processing customer payments
- Co-facilitators, trainers and subcontractors involved in delivering programs and services
- Business partners and advisors (e.g. legal and tax advisors)
- Your employer or contracting organisation (for corporate programs), where agreed
- Banks, insurance companies and other financial institutions
- Authorities, courts and public bodies, where required by law or necessary to protect our rights
- Potential acquirers or parties to a transaction in the context of corporate transactions (e.g. sale of business units)
Some of these recipients are located in Switzerland, others may be located abroad, including in countries that may not have an adequate level of data protection according to Swiss law.
5.2 International Transfers and Safeguards
If we transfer personal data to a country without an adequate statutory level of data protection, we ensure appropriate protection by, for example:
- relying on an adequacy decision (if available),
- concluding standard contractual clauses or other recognised contractual safeguards with the recipient, and/or
- relying on exceptions permitted by law (e.g. performance of a contract, public interest, establishment or defence of legal claims, or your explicit consent).
You may contact us (Section 1) if you would like more information about the safeguards in place for international transfers.
6. Retention Periods
We process and retain personal data:
- for as long as it is necessary for the purpose for which it was collected (e.g. for the duration of the contractual relationship);
- for as long as we have a legitimate interest in storage (e.g. for documentation, evidence and security purposes); and
- for as long as required by legal retention obligations (e.g. accounting and tax retention periods).
As a rule, we keep data relating to contracts and business relationships for at least 10 years after the end of the relationship, in line with statutory retention periods for business records. Shorter retention periods apply to technical logs and system data (typically up to 12 months, unless needed longer for security or evidence purposes).
7. Data Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, misuse, accidental loss, alteration or destruction.
These measures include, for example:
- access controls and “need-to-know” principles
- encryption and pseudonymisation where appropriate
- secure configuration and maintenance of our IT systems
- training and confidentiality obligations for staff and contractors
- regular review of our security measures and procedures
However, no security measure is absolutely perfect, and we cannot guarantee absolute security.
8. Obligation to Provide Personal Data
In the context of our business relationship, you may need to provide certain personal data (e.g. contact and billing details) so that we can enter into and perform a contract with you or your organisation. If you do not provide the required data, we may not be able to offer certain services or enter into a contract.
When using our websites and platforms, the processing of certain technical data (e.g. IP address) is unavoidable to enable the connection and use of the services.
9. Profiling and Automated Individual Decision-Making
We do not generally use personal data to carry out profiling that produces legal effects concerning you or similarly significantly affects you, nor do we use fully automated individual decision-making in the sense of the FADP or GDPR.
We may use basic analysis of participation and usage behaviour (e.g. completion of modules, feedback results) to improve our programs and to adapt content for you. If we were to use automated decisions with significant effects in the future, we would inform you separately and, where required, provide the safeguards required by law.
10. Your Rights
Depending on the applicable law (Swiss FADP and, where applicable, GDPR), you have the following rights in relation to your personal data:
- Right of access: to obtain information about whether and how we process your personal data.
- Right to rectification: to have inaccurate or incomplete data corrected.
- Right to deletion: to request deletion of your personal data, provided we are not obliged or entitled to retain it.
- Right to restriction of processing: to request restriction of processing under certain conditions.
- Right to data portability (where applicable): to receive certain data in a commonly used format or have it transmitted to another controller.
- Right to object: to object to processing based on our legitimate interests, especially in relation to direct marketing.
- Right to withdraw consent: where processing is based on your consent, you may withdraw that consent at any time with effect for the future.
To exercise these rights, please contact us using the details provided in Section 1. We may need to verify your identity before responding.
You also have the right to lodge a complaint with the competent data protection authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC). If the GDPR applies, you may also lodge a complaint with the supervisory authority at your place of residence, place of work or place of the alleged infringement in the EU / EEA.
11. Changes to this Data Protection Statement
We may amend this Data Protection Statement at any time, in particular if we change our data processing practices or if legal requirements change. The version published on our website is the current version.
For significant changes, we may inform you actively (e.g. by email or via our platforms), where appropriate.