top of page

DATA PRIVACY POLICY

Privacy Policy

This privacy policy provides information about how we process personal data, for what purposes, and in connection with our SHUBiDU app and other services, including the SHUBiDU website. It also explains the rights of individuals whose data we process.

Supplementary privacy statements or other legal documents, such as our Terms of Use, may apply to certain services.

Our services are subject to Swiss data protection law and, where applicable, foreign data protection laws, particularly those of the European Union (EU) under the General Data Protection Regulation (GDPR). The European Commission has recognized that Swiss data protection law ensures an adequate level of data protection.

1. Contact Details

Data Controller:
SHUBiDU AG
Wengisteinstrasse 3b
4500 Solothurn
Switzerland
Email: feedback@shubidu.com

If another entity is responsible for processing personal data in a specific case, we will explicitly inform you of this.

Data Protection Representation in the European Economic Area (EEA):
According to Article 27 GDPR, we have the following representative for data protection in the EEA to act as an additional point of contact for regulatory authorities and data subjects regarding the GDPR:

VGS Datenschutzpartner UG
Am Kaiserkai 69
20457 Hamburg
Germany
Email: info@datenschutzpartner.eu

2. Processing of Personal Data

2.1 Definitions
Personal data refers to any information relating to an identified or identifiable person. A data subject is an individual whose personal data is processed. "Processing" encompasses any handling of personal data, regardless of the methods and means used, including storing, sharing, collecting, deleting, altering, and using data.

The European Economic Area (EEA) includes the European Union (EU), as well as Liechtenstein, Iceland, and Norway. Under the GDPR, the term "processing" of personal data is used.

2.2 Legal Bases
We process personal data in accordance with Swiss data protection law, particularly the Federal Act on Data Protection (FADP) and its accompanying Ordinance (FODP). Where the GDPR applies, we base our processing of personal data on one or more of the following legal grounds:

  • Article 6(1)(b) GDPR for the performance of a contract with the data subject or for pre-contractual measures.

  • Article 6(1)(f) GDPR for safeguarding legitimate interests, provided that such interests are not overridden by the fundamental rights and freedoms of the data subject.

  • Article 6(1)(c) GDPR for compliance with a legal obligation to which we are subject.

  • Article 6(1)(e) GDPR for tasks performed in the public interest.

  • Article 6(1)(a) GDPR with the consent of the data subject.

  • Article 6(1)(d) GDPR to protect vital interests of the data subject or another individual.

2.3 Types, Scope, and Purpose of Data Processing
We process personal data that is required to provide our services, including the SHUBiDU app, in a permanent, user-friendly, secure, and reliable manner. Such personal data may fall into categories like contact information, browser and device data, content data, calendar data, metadata, usage data, location data, sales data, contract data, and payment data.

Access to Data on User Devices:
Some functions may require access to the address book, photos, or location data on a user’s smartphone. This access occurs only with the user’s consent. Depending on the operating system, users may need to explicitly grant or deny access on their device.

Address Book:
Phone numbers from your address book are transmitted in a hashed (one-way encrypted) format to our servers to match them with existing SHUBiDU users for sharing events and groups. These hashes are deleted immediately after the matching process and are not stored on our servers.

Photos and Camera:
Access to your camera or media library is needed to upload family profile photos, attach photos to events, or scan entire event sheets, which you can then save on our servers.

Location:
Your location is used to suggest addresses for events or group profiles. This data is not transmitted to our servers.

We process personal data only as long as required for the respective purposes or as legally mandated. Personal data no longer needed for processing is anonymized or deleted.

2.4 Third-Party Processing and International Transfers
We may process personal data via commissioned third parties or in collaboration with third parties. Third parties involved in such processing are generally located in Switzerland or the EEA but may also be located in other countries. We ensure adequate data protection with such third parties, for example, through contracts or certifications.

3. Rights of Data Subjects

Individuals whose personal data we process have the following rights under applicable data protection laws:

  • Right to Access: You may request information about whether and how we process your personal data.

  • Right to Rectification and Deletion: You may request corrections to incorrect data or deletion of your data, subject to certain conditions.

  • Right to Restriction: You may request that we limit the processing of your data in certain circumstances.

  • Right to Data Portability: Where the GDPR applies, you may request your data in a structured, commonly used, and machine-readable format.

  • Right to Object: You may object to the processing of your data under certain conditions.

  • Right to Lodge a Complaint: You may lodge a complaint with the competent data protection authority in Switzerland or the relevant supervisory authority in your jurisdiction.

4. Data Security

We implement appropriate technical and organizational measures to protect personal data from unauthorized access and misuse. This includes data encryption (SSL/TLS), firewalls, access restrictions, and regular security audits.

5. Use of the Website

Cookies: Our website uses cookies to enhance functionality and optimize user experience. These cookies may include first-party or third-party cookies.

Log Files: When you access our website, certain data is automatically logged for technical and security purposes, including IP addresses and browser information.

6. Notifications and Communications

We send notifications and communications, such as newsletters, by email or other channels. These messages may include tracking mechanisms like counting links or open rates to improve our content.

7. Social Media

We maintain a presence on various social media platforms to communicate with users and promote our services. Each platform’s privacy policies apply to your interactions with them.

8. Third-Party Services

We use third-party services for hosting, analytics, advertising, and payment processing. These third parties may process data in countries without equivalent data protection standards. We ensure compliance through appropriate safeguards like EU standard contractual clauses.

9. Updates and Amendments

We reserve the right to update this privacy policy. Substantial changes will be communicated appropriately, typically through our website.

bottom of page