Startup INVEST (“SUI”, “we”) provides the websites startupinvest.ch, startupmatcher.ch, startupdays.ch, ventureday.ch, ipoday.ch and startupguide.online as well as the online registration, ticket shop, side event tool, volunteer tool and matchmaking tool available through the above mentioned websites (the websites, online registration, ticket shop, side event tool, volunteer tool and matchmaking tool jointly the “SUI Services”). For these purposes SUI may collect and process personal data of the users of the SUI Services (“Users” or “you”).
The personal data of Users collected and processed by us in connection with the provision of the SUI Services can be divided into two general data categories: User Data and Technical Data (including cookies and web analytics). Both data categories are explained in more detail below.
User Data is personal data collected directly from you or from our customer organization, which you represent, and on behalf of which you are using the SUI Services (the “Customer Organization”). We may collect User Data from our Users in a variety of ways, including when Users register to the SUI Services, create a profile or subscribe to a newsletter. Further, please note that we also collect details of transactions, such as ticket purchases, you carry out through the SUI Services.
The following User Data received from the Users in connection with the registration to the SUI Services is necessary in order to use the SUI Services:
• First name;
• Last name;
• Email address;
• Password; and
• Marketing opt-in or opt-out.
We may also collect and process the following User Data (listed by feature) in connection with your registration to or use of the SUI Services:
• Picture, domicile, job title, organization, phone number;
• Information regarding interests, employer, education, professional background and/or other information the User chooses to provide in connection with his/her public profile on the matchmaking tool;
• Information about User’s activities within the tool, such as information related to User’s meetings;
• Information the User chooses to provide to other Users in the chat function available on the matchmaking tool; and
• Investor information: first name, last name, domicile, phone number, job title, organization, investment information (such as previous investments, industries, investments in hardware/software startups, social and environmental impact of the investments, range of typical investment, turnover stage and primary investment regions).
• Email address;
• Information relating to transactions and payments carried out through the SUI Services;
• Type of Event ticket purchased on the SUI Services;
• Organization and Job Title; and
• Address, Postal Code, Domicile or Location.
Side event tool
• Email address;
• Job title;
• Organization; and
• Other event specific information that might be requested via registration form (such as motivational information).
• Date of birth;
• Gender (optional);
• Information regarding education, skills, work experience, previous volunteering or other information the User chooses to provide in connection with his/her public profile; and
• Information regarding future recruiting interests.
• Email address;
• Event attendance information;
• Interests of the User;
• User account and profile information; and
• Information provided via matchmaking tool (please see the matchmaking tool section above).
• Customer feedback and other information the User provides to us in correspondence.
In addition, we may also collect User Data from our Customer Organizations when they purchase Event tickets on the SUI Services. The User Data we collect from the Customer Organizations include:
• the email address connected to the user account of the User to whom the Customer Organization addresses the ticket purchased by it; and
• the Customer Organization the User represents.
Although we do not normally use Technical Data to identify you as an individual, you can sometimes (e.g. in certain technical support cases) be recognized from it, either alone or when combined or linked with User Data. In these situations, Technical Data can also be considered personal data under applicable laws and we will treat such data as personal data.
We and/or our authorized third party service providers may automatically collect the following Technical Data when you visit or interact with the SUI Services:
• Browser type and version;
• Device and device identification number;
• Time spent at the SUI Services;
• Interaction with the SUI Services;
• URL of the website you visited before and after visiting the SUI Services;
• The time and date of your visits to the SUI Services;
• IP address; and
• Operating system and the Internet service providers utilized.
We use various technologies to collect and store Technical Data and other information when you visit the SUI Services, including cookies.
Web analytics services
The SUI Services use Google Analytics and other web analytics services to compile Technical Data and reports on visitor usage and to help us improve the SUI Services. For an overview of Google Analytics, please visit Google Analytics. It is possible to opt-out of Google Analytics with the following browser add-on tool: Google Analytics opt-out add-on.
> To organize Events and provide SUI Services
SUI processes your personal data to be able to organize Events and provide the SUI Services to you under the contract between you and SUI or between Customer Organization and SUI. We use the data, for example, to handle your online registration, ticket(s) and payments, to enable organization of side events and to provide you and the other Users with the information necessary for the proper use of the Matchmaking tool as well as other tools of the SUI Platform. We may also process personal data to contact you regarding the Events and SUI Services as well as to inform you of changes to the same. In the event you contact our customer service, we will use the provided information to answer your questions or solve possible issues. The legitimate grounds for processing is the performance of a contract.
> To provide personalized content and customized user experience
If you have selected to use our matchmaking tool, we process personal data to generate an optimal and customized user experience and to provide you with the most relevant content based on your user profile. This may, for example, include individualizing your matchmaking tool feed and providing you with customized recommendations. However, you may at any time decide to turn the matchmaking tool feature off and remove your profile. After removing the profile SUI no longer processes the user profile information for the abovementioned purposes. The legitimate grounds for processing is the performance of a contract.
> For customer communication, marketing and development
We process personal data for the purpose of maintaining our customer relationships as well as for marketing and advertising SUI Services and other products provided by us or via our SUI Platform. This means, for example, customizing the user experience by providing the User with targeted offers, side event information, employment opportunities and advertisements based on the information gathered from the User during his/her visits to the SUI Services. We process personal data also to run, maintain and develop our business and to create new customer relationships. The legitimate grounds for processing is the legitimate interests of SUI.
> Electronic direct marketing
When it comes to electronic direct marketing, the legitimate grounds for processing personal data is the legitimate interest of SUI. However, to be allowed to send electronic direct marketing (for example, utilizing email or text messages) a consent of the receiver of electronic direct marketing is collected (opt-in) where required by applicable laws. Such consent request may take place in certain parts of SUI Services. When the consent is given, the Users may withdraw given consent (opt-out) at any time by contacting us via email (see section 1 above) or by managing consent settings via their user account.
> To fulfil our legal obligations
SUI processes data to be able to administer and fulfil its obligations under law. This includes data processed for complying with our bookkeeping obligations and providing information to relevant authorities such as tax authorities. Personal data may also be disclosed due to mandatory grounds arising from the law or regulations or, if enquired, to the court or competent authority for legal and justified grounds. The legitimate grounds for processing is to comply with legal obligations.
> For potential claims handling and legal processes
SUI may process personal data in relation to claims handling, debt collection and legal processes. SUI may also process data for the prevention of fraud, misuse of our services and for data, system and network security. In these situations, the legitimate grounds for processing is the legitimate interests of SUI.
> For quality improvement, trend analysis and research
We may also process information about your use of the SUI Services to improve the quality of the SUI Services e.g. by analysing any trends in the use of the SUI Services. Further, we may process the information you provide us via SUI Platform for research purposes (e.g. compile a publication on the Startup Guide or similar). We will do this using only aggregated, non-personally identifiable data. The legitimate grounds for processing is the legitimate interests of SUI.
When choosing to use your data on the basis of our legitimate interests, we weigh our own interests against your right to privacy. We also use pseudonymized or non-personally identifiable data when possible.
We always take necessary steps to ensure that the Users’ personal data receives an adequate level of protection in the jurisdictions in which it is stored and processed. We provide adequate protection for the transfers of personal data to countries outside of Switzerland or the European Economic Area through a series of agreements with our service providers based on the Standard Contractual Clauses or through other appropriate safeguards, such as the Privacy Shield Framework.
Currently we store the Users’ personal data primarily in the United States of America, as it is the domicile of our service providers. However, SUI has service providers in certain other geographical locations too. As such, we and our service providers may transfer personal data to, or access in it, jurisdictions outside of Switzerland or the European Economic Area or the User’s domicile.
> For legal reasons
We may share personal data with third parties outside our organization if we have a good-faith belief that access to and use of the personal data is reasonably necessary to: (i) meet any applicable law, regulation, and/or court order; (ii) detect, prevent, or otherwise address fraud, security or technical issues; and/or (iii) protect the interests, properties or safety of SUI, the Users or the public in accordance with the law. When possible, we will inform the Users about such data transfer and processing.
> To authorized service providers
Please note that we use, for example, the services of Stripe Payments Europe, Ltd (company number:
513174, C/O A&L Goodbody, Ifsc, North Wall Quay, Dublin 1, Ireland “Stripe”) to manage and provide the ticket shop feature of the Platform. We use also an online advertising product Facebook Custom Audiences (Facebook Inc. 1601 S. California Avenue, Palo Alto, CA, 94304 “Facebook”) to target you with advertising relating to our services and products. It is possible to opt-out of such targeted advertising through your Facebook profile settings.
> With explicit consent
We may share your personal data with third parties outside SUI for other reasons than the ones mentioned above, when we have your explicit consent to do so. The User has the right to withdraw the aforementioned consent(s) at all times.
We use administrative, organizational, technical and physical safeguards to protect the personal data we collect and process. Measures include, for example and where appropriate, encryption, pseudonymization, firewalls, secure facilities and access right systems. Our security controls are designed to maintain an appropriate level of data confidentiality, integrity, availability, resilience and ability to restore the data.
Should despite of the security measures, a security breach occur that is likely to have negative effects to the privacy of the Users, we will inform the relevant Users and other affected parties, as well as relevant authorities when required by applicable data protection laws, about the breach as soon as possible.
Most personal data relating to a User’s user account with the SUI Services will be deleted after a period of five (5) years from the last use of the user account in question. SUI will inform you on the oncoming deletion. Thereafter, a part of the personal data relating to a User’s user account with the SUI Services may be stored in case processing is required by law or is reasonably necessary for our legal obligations or legitimate interests such as claims handling, bookkeeping, internal reporting and reconciliation purposes.
All personal data relating to a User’s user account with the SUI Services will be anonymized or deleted after a period of ten (10) years from last use of the user account, with the exception of personal data required in certain rare situations such as legal proceedings.
> Right to access
The Users have the right to access the personal data relating to them and processed by us. We give you the possibility to view certain data through your user account with the SUI Services or request a copy of your personal data.
> Right to object
If the data is processed based on our legitimate interest, you may have the right to object to certain use of your personal data. If you object to the further processing of your personal data, this may lead to fewer possibilities to use the SUI Services.
> Right to rectify
The Users have the right to have incorrect, imprecise, incomplete, outdated or unnecessary personal data we have stored about the User corrected or completed by contacting us. You can correct or update some of your personal data through your user account in the SUI Services.
> Right to erasure
The Users may also request us to delete their own personal data from our systems. We will comply with such request unless we have a legitimate ground not to delete the data. SUI legitimate ground may be based on e.g. applicable legislation.
> Right to data portability
In certain situations you may have the right to receive your personal data from us in a structured and commonly used format and to independently transmit the data in question to a third party.
> Right to withdraw consent
In case the processing is based on a consent granted by the User, the User may withdraw the consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
> Right to restriction of processing
You may request us to restrict processing of personal data, for example, when your data erasure, rectification or objection requests are pending and/or when we do not have legitimate grounds to process your data. However, this may lead to fewer possibilities to use the SUI Services.
The abovementioned rights may be exercised by sending a letter or an email to us on the addresses set out above in section 1. The message should include the following information: full name, home address, email address and telephone number. We may request the provision of additional information necessary to confirm the identity of the User. We may reject requests that are unreasonably repetitive, excessive or manifestly unfounded.
The User has the right to prohibit us from using the User’s personal data for direct marketing purposes, market research and profiling made for direct marketing purposes by contacting us on the address indicated above in section 1 or by using the unsubscribe function offered in connection with each direct marketing message.
The User can lodge a complaint with the local supervisory authority for data protection in case the User considers the Company’s processing of personal data to be inconsistent with the applicable data protection laws. In Switzerland, the local supervisory authority is the Federal Data Protection and Information Commissioner (www. www.edoeb.admin.ch). The contact details of the supervising authority are as follows:
Federal Data Protection and Information Commissioner
Postal address: Feldeggweg 1 CH – 3003 Berne
Telephone: +41 (0)58 462 43 95 (Monday to Friday from 10am to 12pm)