beUnity

Home · Legal Notices · Privacy · Platform

Privacy Policy — beUnity Platform

Privacy policy for the use of the beUnity Platform · dated 18 July 2025

Note: This English translation is provided for convenience only. The legally binding version is the German original.

Preamble

The protection of your personal data is important to us. With this privacy policy, we inform you about the nature, scope and purpose of the processing of your personal data when using the beUnity Platform.

We operate a data protection management system and work closely with external specialist bodies in order to meet the applicable legal requirements at all times. In doing so, we observe the requirements of the EU General Data Protection Regulation (GDPR), the revised Swiss Data Protection Act (revFADP) and other relevant national data protection provisions.

This privacy policy reflects the status as of 18 July 2025. We reserve the right to make changes – you can find the current version at any time under: Legal Notices

General information

Scope

This privacy policy applies to the use of the beUnity SaaS platform at beunity.app (hereinafter "Platform" or "App"). All associated digital offerings are jointly referred to as "Services".

Controller and contact

The controller for data processing within the meaning of the GDPR and the revFADP is:

beUnity AG
Gattikonerstrasse 123
8136 Gattikon, Switzerland
E-mail: datenschutz@beunity.io

Further details can be found in the Imprint.

Definitions

Where this privacy policy uses terms such as "personal data", "processing", "controller", "processor" or "data subject", their meanings are governed by the definitions in Art. 4 GDPR.

These terms are gender-neutral and refer to all data subjects regardless of gender or identity.

Data processing on the Platform

General

We process your personal data exclusively for the purposes stated in this privacy policy. The data is stored only for as long as is necessary for the stated purposes or as required by statutory retention obligations.

Accessing the Platform

When you visit our Platform, we automatically collect technical access data (e.g. IP address, browser type, time of access). We use this data to ensure stability and security. Legal basis: Art. 6 para. 1 lit. b and f GDPR / revFADP.

Registration and membership

Upon registration, we process mandatory data (name, e-mail) and, optionally, further details (e.g. profile picture). This data serves your personalised access and the display of your profile within the Platform. Legal basis: Art. 6 para. 1 lit. a and b GDPR / revFADP.

Use of the Platform

In the course of using the Platform, we process personal data that you actively provide or that arises from your activities. This includes in particular:

  • Creation of content: When you publish posts (e.g. news, surveys, events), we store the content you create together with your profile name and, where applicable, your profile picture.
  • Interaction with content: When you take part in surveys, like, comment on or save content, we process corresponding activity data for display and traceability within the Platform.
  • Communication via chat: Messages you send in direct or group chats are stored in encrypted form and displayed exclusively to the persons addressed.
  • Usage behaviour: To improve user-friendliness, we analyse anonymised usage data (e.g. interaction frequency, feature usage). This analysis is based on our legitimate interest in continuously improving the Platform.

Data processing takes place exclusively within the scope of Platform use and in accordance with the contractually agreed purposes. Legal bases: Art. 6 para. 1 lit. b (performance of contract) and lit. f (legitimate interest) GDPR / revFADP.

Use of the mobile app

When the app is installed (iOS and Android), an app token ID is created. This is linked to your account in order to enable push notifications, for example. Legal basis: Art. 6 para. 1 lit. b GDPR / revFADP.

Contacting us

When you contact us via e-mail or "Give feedback", we process your details in order to respond to your request. Legal basis: Art. 6 para. 1 lit. a and b GDPR / revFADP.

Notifications & e-mail summaries

If you sign up for e-mail notifications, we use your e-mail address to send you information and updates from your community. You can unsubscribe from these notifications at any time. Dispatch takes place via a specialised dispatch service provider acting as a processor on our behalf. Further information on the service providers used can be found in Annex C to the DPA. Legal basis: Art. 6 para. 1 lit. a GDPR / revFADP (consent)

Our own cookies & technologies

Cookies for security and functionality

We use cookies and comparable technologies for login, session management and user recognition. You can control their use via your browser settings. Legal basis: Art. 6 para. 1 lit. f GDPR / revFADP (legitimate interest in the secure and stable operation of the Platform).

Cookies for usage analysis

To optimise the Platform, we use anonymised analytics cookies and operate a self-hosted instance of Matomo (web analytics tool). The data is processed in fully anonymised form. Legal basis: Art. 6 para. 1 lit. f GDPR / revFADP (legitimate interest in improving our offering).

Cookies for marketing/advertising purposes

On our Platform, we use NO cookies for marketing or advertising purposes. There is no user-based advertising, no profiling and no retargeting.

Disclosure to third parties

Your data is only disclosed where there is a legal obligation, with your consent, or to service providers for the performance of the contract. In doing so, we pay attention to data protection compliance and data security.

Examples of service providers used:

  • Exoscale (CH): hosting and encrypted storage
  • AWS (EU): storage of public images
  • SendGrid (USA): dispatch of e-mails

A current and complete list of our subprocessors can be found in Annex C to the DPA.

Rights of the data subject

Overview of your rights

You have the following rights under the EU General Data Protection Regulation (GDPR) and the revised Swiss Data Protection Act (revFADP):

  • Information about the data stored about you
  • Rectification of inaccurate or incomplete data
  • Erasure ("right to be forgotten")
  • Restriction of processing
  • Data portability
  • Objection to certain processing operations
  • Withdrawal of consent given
  • Right to lodge a complaint with a competent data protection supervisory authority

Legal foundations

Detailed information on these rights can be found in the respective legal texts:

Right to lodge a complaint / legal protection

You have the right to lodge a complaint with a data protection supervisory authority –

  • in the EU pursuant to Art. 77 GDPR,
  • in Switzerland pursuant to Art. 15 revFADP.

To exercise your rights, you can contact us at any time at: datenschutz@beunity.io

Data security

We take appropriate technical and organisational measures (TOM) to protect your personal data against loss, misuse, unauthorised access or disclosure – in line with the current state of the art and the legal requirements (GDPR, revFADP).

These include in particular:

  • Encryption of all data transmissions using TLS (Transport Layer Security)
  • Access restrictions through role and authorisation concepts
  • Firewalls, security updates and regular system checks
  • Logging and monitoring of security-relevant events

The protective measures are continuously reviewed and adjusted as necessary to ensure an appropriate level of protection.