At T&S_hearty, we’re serious about the security of the data on our servers and the protection of the privacy of our users. We employ several security professionals that work exclusively on technical and organizational security during operations and further development of the product. You can meet them on our team page. We continually take steps to protect your information against loss, misuse, unauthorized access, unauthorized disclosure, manipulation, or destruction.

As a basic principle, the Swiss Federal Data Protection Act (FADP) applies to the processing of your personal data. In certain circumstances, for example if you access our offers from a Member State of the European Union, the European Data Protection Regulation 2016/679 (GDPR) may also apply. If you access our services from the State of California, USA, the California Consumer Privacy Act of 2018 (CCPA) may also apply.

This Privacy Policy describes how the data is handled at At T&S_hearty. Please also consult our general data processing terms and your rights and disclosures required by the CCPA

Your data at At T&S_hearty

When you use At T&S_hearty, you send pieces of data to At T&S_hearty; this can be a name, an e-mail address, or information relating to your appointment. Other data is generated implicitly by your use of At T&S_hearty, e.g. log data. We use this information for internal analytical purposes to improve the product for you. Furthermore we employ other companies to perform tasks on our behalf and may need to share this information with them to provide services to you. We do not sell your data to third parties.

Log data

At T&S_hearty records certain requests and transactions in log files. This log data is used for troubleshooting, statistics, analytics, quality assurance, and to monitor system security and can be analyzed to that end. At T&S_hearty can publish anonymous statistics under the condition that no personally identifiable information can be derived from such statistics.

At T&S_hearty works with Crashlytics, Inc (“Crashlytics”) and Bit Stadium GmbH (“HockeyApp”) to report any bug affecting our iOS and Android Apps. HockeyApp’s software is built into our iOS App and Crashlytics’ software is built into our Android App. If either app crashes during normal use, the app will send certain information about the incident to Crashlytics or HockeyApp as applicable. This information consists of the device type, OS version and certain hardware information about your mobile device, and the time of the crash, the state of the application at the time of the crash, and stack traces. The information does not include your IP address or any other information that could be used to identify you or your mobile device individually, and does not include any other information from your mobile device. Click here to review Crashlytics’ privacy policy, and here for HockeyApp’s privacy policy.

This website is using Tidio, a chat platform that connects users with At T&S_hearty customer support. It will only collect email addresses, names and phone numbers with the consent of users, in order to start a chat. The messages and data exchanged are stored within the Tidio application. For more information, please refer to their Privacy Policy.

At T&S_hearty is not using these messages or data other than to follow up on users’ registered issues or inquiries. Your personal data will be processed and transmitted in accordance with the General Data Protection Regulations (GDPR).

Cookies

When you use At T&S_hearty, the service can store cookies on your computer. Cookies are little pieces of information that can help identify your browser and that can store information for future visits, e.g. your language preferences. At T&S_hearty uses cookies to track usage, to improve ease-of-use and the overall user experience, and to manage advertising inventories.

Most Internet browsers automatically accept cookies. You may however configure your browser at any time in such a manner that no cookies are saved on your computer or that an indication always appears when you receive a new cookie.

At T&S_hearty services may in principle be used without accepting cookies, although individual functions may thereby be limited.

You can choose to disable cookies but this may limit your ability to use At T&S_hearty service.

Social Login

At T&S_hearty employs third party tools to provide you with the convenience you are used to from elsewhere on the internet to sign in to T&S_hearty with one click (so called “social login”). Some of these tools can track your actions when you interact with them. At T&S_hearty you can sign in with Google, Microsoft, Facebook or your email/password.

Unauthorized access

T&S_hearty implements several mechanisms to prevent unauthorized access to polls, accounts, or other data.

To access a poll, you use the unique link which T&S_hearty provides and which contains a random access code. This link is an important element to prevent unauthorized access to a poll. You should send this link only to authorized people, i.e., the people you wish to participate in your poll. User-accounts are protected by passwords. You should choose a secure password and ensure its confidentiality to prevent unauthorized access to your account

For user surveys and market research

We use the data you provide exclusively to improve the user experience and to further develop our products. The results consist solely of aggregated and anonymous data. If you have given your consent, you may also be contacted by other companies of the TX Group for example to participate in other user surveys.

Payment processing

T&S_hearty supports the leading payment processing provider, PayPal. You can find their privacy policies here: PayPal. To make payments as easy and user-friendly as possible, T&S_hearty sends your name and e-mail address to Paypal during a payment process. All this information would be requested by the provider anyway. Doodle furthermore employs Stripe for credit card payments. You can find the privacy policy here.

Location of data

The T&S_hearty databases are located on cloud servers in Ireland and Frankfurt.

Transfer of Personal Data abroad

We are entitled to transfer your Personal Data abroad, including to third party companies (designated service providers) insofar as this is expedient for the Data Processing described in this Privacy Statement. The recipients will be obliged to protect Your Data to the same extent as ourselves. If the level of data protection in a particular country is lower than that applicable in Switzerland, we will ensure under contract that the level of protection for your Personal Data is equivalent to that applicable in Switzerland. We shall ensure this through one or more of the following measures:

by concluding EU Model Clauses with the appointed service providers, cf. through the appointed service providers having in place Binding Corporate Rules (BCR) that are recognised by a European data protection authority, cf.

Sharing personal information

T&S_hearty uses personal information according to the Terms of Service and this Privacy Policy.

T&S_hearty may share personal information with other companies or individuals only in the following limited circumstances: (i) T&S_hearty has your consent; (ii) T&S_heartyhas good faith that there is a legal obligation to share the data; (iii) T&S_hearty needs to access or share the data to protect the security of the service or of others users’ data; (iv) T&S_hearty needs to access or share the data to protect T&S_hearty rights and property or to enforce the Terms of Service.

Data retention

We shall only retain your data for as long as is legally necessary or in accordance with the purpose for which they were processed. If we carry out analyses, we shall store your data until the analysis has been concluded. If we store your data on the basis of a contractual relationship with you, these data will remain stored for at least the duration of the contractual relationship and at most for the duration of the limitation periods within which any claims may be brought by or against us, or for the duration of statutory or contractual duties of retention.

Legal basis

We shall only process your Personal Data in accordance with principles of data protection and if there is a legal basis to do so. If in furtherance of the establishment or implementation of our contract, it shall serve as the legal basis. Otherwise, we have an interest in continuously improving our Offers, adjusting our Offers in line with your needs and showing you advertising that may be of interest to you. This is necessary in order to develop our Offers further, as well as to be able to finance and guarantee the security of our Offers. We act on the presumption that our interests are predominant. If you have consented to data Processing, this consent will apply.

Right of erasure

In accordance with applicable European legislation you can delete your account and the events you own from the system in the account section of Sites. It is however possible that another user invites, or informs, you about an event again in the future. If you don’t want this either we can block your email address.

Your rights

You have the right to exercise your data protection rights at any time and to request information as to whether and which Personal Data relating to you has been processed by us. You may also arrange for your Personal Data to be corrected, blocked or cancelled at any time in writing, enclosing appropriate proof of your identity, by email.

We reserve the right to exchange correspondence with you in this regard.

Please note that we may be required to retain your Personal Data in part even after a request for blocking or cancellation under the terms of our statutory or contractual retention requirements (such as for accounting purposes) and in such an eventuality will only block your Personal Data insofar as necessary for this purpose. In addition, the cancellation of your Personal Data may have the effect that you are no longer able to acquire or use the services registered by you. Under certain circumstances, you have the right to require us to provide you or a third party specified by you with your personal data in a commonly used format.

In addition, you have the right to make a complaint concerning the data processing in question with the competent supervisory authority. You can do this with the supervisory authority at your place of residence, at your place of work or at the place of the alleged data breach. Your personal privacy cockpit offers you further information on the various systems and providers that we use, as well as the option to change your privacy settings at any time.

Changes

T&S_hearty reserves the right to update this Privacy Policy at any time.