Alpmate
Alpmate
Compliance & Trust

Privacy Policy & Swiss Data Protection (revDSG).

We are committed to absolute data sovereignty. Hosted exclusively in Switzerland under the Swiss Federal Act on Data Protection (FADP) and EU GDPR.

Last updated: August 2026 · Governing Law: Switzerland

1. Data Controller Identity

The data controller responsible for the processing of personal data on this website and platform is:

Alpmate Alpine SaaS AG
Bahnhofstrasse 14, 8001 Zürich, Switzerland
Company Registration ID: CHE-419.288.102
Email: privacy@alpmate.com

2. Scope of Processing & Roles

Alpmate functions in two distinct capacities depending on whose data is being processed:

  • Data Controller: For account information collected from school operators, administrators, and guides (e.g. name, email, billing address, IP address).
  • Data Processor: For personal information collected on behalf of school operators from their booking guests (e.g. participant names, height/weight for ski sizing, ability levels, meeting point confirmations). The school operator remains the Data Controller for participant records.

3. Categories of Data Collected

A. Operator Account Data: Name, professional email, phone number, school legal name, Swiss UID or EU VAT number, and payment connection credentials.

B. Guest Booking Information: Participant full names, age/date of birth (for junior ski camps), skill levels, equipment sizing parameters (height, weight, shoe/boot size for equipment release DIN settings), and emergency contact numbers.

C. Financial & Transaction Tokens: Transaction reference IDs, invoice amounts, and settlement statuses. We never store credit card numbers or banking passwords. All card transactions are handled directly by Stripe or your authorized Swiss financial institution.

4. Swiss Data Residency & Storage Security

All primary databases, backups, and media assets are hosted within ISO 27001-certified Tier IV datacenter facilities located in Zürich and Geneva, Switzerland.

Technical & Organizational Measures (TOMs):
• Encryption in transit via TLS 1.3 with strict HSTS enforcement.
• AES-256 encryption at rest for all database volumes and snapshot archives.
• Physical per-tenant database isolation to prevent multi-tenant data bleed.
• Multi-factor authentication (MFA) available for all staff logins.

5. Third-Party Sub-Processors

We only engage sub-processors that guarantee compliance with the Swiss FADP and EU GDPR through signed Data Processing Agreements (DPAs):

Sub-ProcessorPurposeLocation
Exoscale / Swiss CloudApplication & Database HostingSwitzerland
Stripe Payments EuropePayment Processing InfrastructureIreland / EU
Postmark / TwilioTransactional Email & SMS DispatchEU / USA (Standard Contractual Clauses)

6. Your Rights Under Swiss FADP & GDPR

Under Swiss data protection legislation and Articles 15–21 of the GDPR, you and your booking guests hold the right to:

  • Request access to all stored personal records free of charge.
  • Request rectification of inaccurate contact or sizing information.
  • Request the deletion of records (Right to be Forgotten), subject to statutory Swiss tax retention periods.
  • Request a machine-readable export (JSON / CSV) of all school customer history.

To exercise any of these rights, contact our Data Protection Officer at privacy@alpmate.com.