Data protection
Privacy policy
Last updated: 24 September 2026
Translation provided for information purposes: in the event of any discrepancy, the French version prevails.
In brief
- The platform's database is hosted in Switzerland, in Zurich.
- We only collect what is necessary to train your employees and follow their progress.
- No advertising, no audience measurement tool, no tracking, no resale of data.
- Passwords are never visible, neither to us nor to your company's administrator.
Who is responsible?
For the public website and the contact form, the controller is the publisher of the website, presented in the legal notice. Contact for any question about your data: formation@datalys.ch.
For employee accounts on the platform, it is the client company that decides to train its employees and that is responsible for this processing. We process this data on its behalf, as a processor, solely to provide the service.
What data do we process?
Visiting the website
Our hosting provider may record technical information related to your visit (IP address, date and time, page viewed, browser type) to ensure the operation and security of the website.
We do not use any audience measurement or advertising tool.
Contact form
Your name, your email address, the name of your company (optional) and your message. They are sent to us by email, solely to reply to you.
Account of the company and its administrator
The name of the company, the approximate number of employees indicated at registration, the name and email address of the administrator, and the date and version of the terms and conditions they accepted at registration.
Payment of the subscription
Payment is made on a page of our provider Stripe, which collects the card and billing details and applies its own privacy policy. We never have access to the card number: we only keep the customer and subscription identifiers provided by Stripe, the number of employee accounts purchased and the status of the subscription.
Employee accounts
- The name (optional) and the email address, entered or imported by the administrator.
- Progress in the modules: status (started, completed), module score (exercises and final test, weighted equally), dates of completion and last activity, modules made mandatory and their deadline.
- Messages sent with the "Report a problem" function: the message, the name, the email address, the role, the company, the page concerned and the browser type, so that the request can be handled.
Passwords are stored in an encrypted form that does not allow them to be read back. Passwords entered in the "Hacker challenge" exercise are analysed only in your browser: they are neither sent nor stored. For each account, we also store the chosen language, so that emails are sent in that language, and, if two-factor authentication is enabled, the method used (app or code by email); a code sent by email is only kept in an unreadable form and expires after 10 minutes.
Why?
- To provide the platform: create accounts, send access details, display the modules.
- To collect the subscription and keep the number of employee accounts purchased up to date.
- To allow the company's administrator to see who has completed which modules, and to send reminders if needed. They see neither the computer activity, nor the mailbox, nor the passwords.
- To reply to your messages and handle reported problems.
- To ensure the security of the service.
Cookies and storage in the browser
- A session cookie, essential to stay logged in to the platform.
- A cookie that remembers the chosen language (kept for one year).
- Progress within a module (current step, exercises already done) is saved in your browser, on your device, so that you can resume where you left off.
No advertising or audience measurement cookies, and no third-party trackers.
Who has access?
Within the client company, only its administrator sees the progress of its employees. Each company's data is isolated from that of the others at database level. For support purposes, the members of our team in charge of support have access to all companies: they can view accounts and progress, correct or delete an account, reset a password or progress, or sign in as a user to reproduce a problem. This access is protected by two-factor authentication and used only for support and the proper operation of the service; every change and every sign-in as a user is recorded in a log. Administrators' actions on their company's accounts (creation, modification, deletion, reminders) are also recorded. We use the following providers, who process the data solely to provide us with their service:
- Infomaniak Network SA (Geneva, Switzerland): Hosting of the website and the application.
- Supabase Pte. Ltd (Singapore; data hosted in Zurich, Switzerland): Platform database and account authentication.
- Brevo (Sendinblue SAS) (Paris, France): Sending emails: account access, forgotten password, two-factor authentication codes, reminders of modules to complete, subscription-related emails, contact form messages and their acknowledgement of receipt.
- Stripe Payments Europe, Limited (Dublin, Ireland): Payment of the subscription by card: card details are entered at Stripe, we never have access to them.
- Hostinger International Limited (Larnaca, Cyprus): Mailbox of the contact address: receipt of contact form messages and reported problems.
We neither sell nor rent any data.
Transfers abroad
The platform's data is hosted in Switzerland, in Zurich. Our database provider, Supabase Pte. Ltd, is established in Singapore, and some of its sub-processors (hosting, technical support) in the United States: they may have access to the data in order to provide the service. As Singapore is not recognised by Switzerland as offering an adequate level of protection, this transfer is governed by the European Commission's standard contractual clauses, adapted to Swiss law, which form part of Supabase's data processing agreement; Supabase undertakes to impose data protection obligations on its sub-processors that are at least equivalent.
Our other providers are established in Switzerland or in the European Union, whose level of data protection is recognised as adequate by Switzerland.
For how long?
Account data is kept as long as the company uses the platform, then deleted at the end of the contract, unless there is a legal obligation to retain it. Action logs (who created, modified or deleted an account or sent a reminder, and when) are kept for 12 months, including after an account is deleted or the contract ends, so that we can respond to a dispute; they are then deleted automatically. Messages received through the contact form are kept for as long as needed to handle the request.
Security
Exchanges with the website are encrypted (HTTPS), each company's data is segregated, and two-factor authentication is available for all accounts.
Your rights
In accordance with the Swiss Federal Act on Data Protection (FADP), you can request access to your data, have it corrected or deleted, object to its processing or obtain a copy of it. Write to formation@datalys.ch.
If you are an employee of a client company, please contact your employer first, as it is responsible for this processing: we will help it respond to your request.
You can also contact the Federal Data Protection and Information Commissioner (FDPIC).
Changes
This policy may change along with the service. The date of the last update is shown at the top of this page.