Privacy Policy — QR Suisse
This English version is a translation provided for information purposes only. In case of discrepancy between language versions, the French version is legally binding.
1. Who is responsible for your data
Skyday Sàrl, operator of the QR Suisse service, is responsible for the processing of your personal data within the meaning of the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the GDPR (see §7).
- Registered office / full address: Rue de Lousse 32a, 1987 Hérémence, Switzerland (source: Commercial Register, zefix.ch, consulted on 2026-09-11)
- Company identification number (UID): CHE-347.343.213
- Contact for any question relating to your data: contact@qrsuisse.ch
For the part of payment processing that it carries out on its own behalf, Stripe is a separate controller (see §6.2). The same applies to Stripe Link (see §2.3).
2. What data we collect, and why
QR Suisse only collects the data strictly necessary for the operation of the service and the measurement of its audience. No data is collected for advertising purposes, resale, or individual profiling of your behaviour. The audience measurement of our public website (§2.4), subject to your consent, is aggregated and is not intended to identify you individually.
Certain of the processing activities described below, in particular the audience measurement of the public website (§2.4), are subject to your explicit consent, collected via a banner on first access to the website, changeable at any time.
2.1 Your account data (if you hold an account)
| Data | Why we collect it |
|---|---|
| Email address | Login identifier for your account; also transmitted to Stripe if you subscribe to a plan (§2.3) |
| Password | Authentication — never stored or transmitted in plain text: only a cryptographic fingerprint (bcrypt hash, cost factor 12) is kept, impossible to convert back into the original password |
| Password reset link (if you use "Forgot your password?") | Allowing you to set a new password — only a cryptographic fingerprint of the link is kept (never the link itself), together with its expiry date; the link is single-use and time-limited (§5) |
| Account creation date | Administrative management of the account |
| Content of your QR codes | Label, destination address and, for a contact card, the contact details you choose to publish (name, title, phone numbers, emails, addresses) — entered by you, displayed only to the people who scan the corresponding QR code |
| Plan and account status | Plan chosen (Free or Pro), account status (active, grace period, blocked) — determines the number of active QR codes and the depth of history available (§2.2, §2.3) |
These accounts are not created through public self-registration: they are created individually by Skyday Sàrl, by invitation.
If you use "Forgot your password?" on the login page to regain access to your account:
- The email address you enter is neither stored nor logged by us, whether or not it matches an account: it is used only to look up the account concerned. If the address matches an active user of an account that is neither suspended nor pending deletion, an email containing a single-use link is sent to the address registered on that account — never to any other address.
- The response displayed to you is identical whether or not the address matches an account ("If an account matches this address, you will receive an email within a few minutes"). We do not reveal whether an address is registered with us.
- To limit abuse (serial requests), we count requests per IP address and per email address using non-reversible fingerprints (salted hash), held in the server's memory only over a 60-minute window. These fingerprints are never written to a database or to disk, never linked to your account, and neither the IP address nor the email address appears in them in plain text. When the window expires they stop being taken into account and are removed from memory by an automatic purge; in any case they disappear when the server restarts.
- The link you receive is not passed on to any third party: the pages concerned are not subject to audience measurement (§2.4), and the browser is instructed not to communicate the page's address to other websites.
- When you set your new password, your open sessions are closed — you must log in again with the new password — and we send you a notification email (with no link at all) so that you can react if the change was not made by you. The same applies when the link was triggered for you by an administrator of your account.
If you take part in a test on our validation environment ("staging") before a new feature goes into production, a test account is created there under the same rules — see §6.3 for details of this environment and §5 for its own, shorter retention period compared to your production account. On this environment, payment is simulated (Stripe test mode): no real banking data is ever entered there.
2.2 Usage statistics for your QR codes
For each QR code you create, we keep:
- a counter of the total number of scans (
scanCount); - a count of scans per calendar day (a single line per QR code and per day, with no other information), which feeds the trend curve on your dashboard.
Neither of these contains the slightest individual detail about the people who scan: no per-scan log, no individual timestamp, no device, no country, no browser, no IP address stored in the database. Two people who scan the same QR code on the same day are strictly indistinguishable within it.
The viewable history depth depends on your plan: the last 7 days (Free) or 15 months (Pro). The daily data itself is retained for 15 months for all accounts, then automatically deleted (§5) — so switching to the Pro plan immediately gives access to the history already built up.
Transient, non-persistent technical processing: at the moment of a scan, the IP address of the person scanning is transformed into a non-reversible fingerprint (salted hash) and kept in the server's memory for a maximum of 5 seconds, solely to avoid counting an accidental scan twice (double-tap, automatic preview by a camera app). This fingerprint is never written to a database, never associated with an identity, never visible in your statistics, and disappears permanently after the 5 seconds expire or when the server restarts. This mechanism is strictly identical on our validation environment (§6.3).
2.3 Subscription and billing (if you subscribe to the Pro plan)
Payment for the Pro subscription (monthly or annual) is entrusted to Stripe, our payment provider (§6.2). Specifically:
| Data | Who processes it | Why |
|---|---|---|
| Your email address and an internal reference for your account | Transmitted by us to Stripe when the payment page opens | Linking the payment to your account, sending you receipts and invoices |
| Your bank card data | Entered directly on the payment page hosted by Stripe, never transmitted to our servers | Charging, renewal — Stripe is PCI DSS certified |
| Promotional code, if any | Entered by you with Stripe | Applying the discount or free access |
| IP address and device characteristics at the time of payment | Collected by Stripe, for its own purposes | Fraud detection (Stripe Radar) — see Stripe's privacy policy |
| Stripe customer ID, subscription ID, plan, subscription status, period and grace-period end dates | Received from Stripe and stored by us | Knowing whether your account is active, in grace period or blocked, and applying the corresponding quotas |
| Payment history, invoices and receipts | Kept by Stripe; viewable by you in the Stripe customer portal and by Skyday Sàrl in its Stripe dashboard | Contract performance, accounting obligations (§5) |
We do not require a name or billing address (Skyday Sàrl is not subject to VAT), and we do not store any card number or fragment, address, amount or invoice ourselves.
Stripe Link. When paying, the Stripe page may offer you the option to use Link, Stripe's one-click payment wallet: it allows your name, contact details and payment data to be saved with Stripe, for reuse afterwards with other merchants who, like us, use Stripe. We have chosen to keep this option enabled. For this specific feature, Stripe acts under its own terms, as an independent controller — not as a mere provider acting on our instructions: you and Stripe each separately determine the purposes and means of this particular processing (Link terms: stripe.com/legal/link; Link's own privacy policy: link.com/privacy). You can always enter your card manually, without ever using Link — this option always remains available on the payment page; Link is only ever offered, never required.
Subscription-related emails (receipts, invoices, failed payment) are sent to you by Stripe.
If your Pro subscription ends (cancellation or payment failure) while your account exceeds the Free plan quota, your account enters a grace period (14 days) and then a blocked state: your QR codes beyond the quota then show a neutral information page to the person scanning. This page never mentions the reason (unpaid invoice, cancellation) — it only indicates that the account is no longer active.
2.4 Audience measurement of the public website
In addition to the data described above (which concerns your account and your use of the service once registered), we measure traffic on our public website (pages viewed before registration, source of the visit, registration conversion rate, drop-off point in the registration form), using Google Analytics 4 (GA4), a tool provided by Google LLC.
This processing is separate from the scan statistics for your QR codes (§2.2): it only concerns traffic on our own website, not the use of your QR codes by your customers.
At this stage, this processing only concerns visitors to the public website and the registration journey — not your use of the dashboard once logged in to your account, which is not measured by this tool.
| Data | Why |
|---|---|
| Pages visited, source of the visit (referring site, campaign) | Measuring traffic and its origin |
| Device and browser type | Aggregated usage statistics |
| Conversion event (registration completed) | Measuring the conversion rate |
| Form abandonment event (step reached, field left) — never the value entered in a field | Identifying friction points in the registration journey |
| IP address, anonymised before any storage | Necessary for the operation of the measurement tool |
This processing is only triggered after your explicit consent: as long as you have not accepted via the cookie banner, Google Analytics does not load on this website (no request is sent to Google) and no information about your visit is transmitted to it.
Legal basis: your consent, given via the cookie banner, for the placing of cookies/identifiers by Google Analytics (Art. 45c of the Telecommunications Act for Switzerland; Art. 5(3) of the EU "ePrivacy" Directive for visitors residing in the European Union); as a complementary basis, the legitimate interest of Skyday Sàrl in measuring the use of its own website in order to improve it, for the processing of the data itself once the cookie has been placed.
Retention: audience measurement data is retained for a rolling 14 months, set in the configuration of Google Analytics 4 (§2.4). This duration allows us, at any time of the year — including during the first two months of a new measurement period —, to have the 12 previous complete months available, in order to compare traffic trends year-on-year and improve the user experience of the website. It also corresponds, incidentally, to the maximum retention period offered by Google Analytics 4 itself (the tool only allows a choice between 2 or 14 months of retention). The data is then deleted according to that tool's own purge mechanism.
Objecting / withdrawing your consent: you may at any time refuse or withdraw your consent via the "Manage my preferences" link in the footer, available on every page of the website.
3. Legal basis for processing
- Account and content of QR codes: performance of the contract binding us — the pilot agreement for SMEs still in the pilot phase, the terms and conditions (general terms) from the point of subscription, including on the Free plan (Art. 31 para. 2 let. a nFADP by analogy / Art. 6(1)(b) GDPR where applicable). No separate consent required.
- Aggregated scan statistics: the legitimate interest of Skyday Sàrl and of the account holder in measuring the use of a QR code they have created, in a strictly aggregated and non-individualising way — processing is reduced to the minimum necessary for this purpose (§2.2).
- Subscription and billing: performance of the subscription contract; retention of accounting records under a legal obligation (Art. 958f of the Swiss Code of Obligations (CO)). The processing that Stripe carries out on its own behalf (fraud, regulatory obligations, and Link for the part it processes in its own name) is based on the legal grounds described in Stripe's privacy policy (and, for Link, in Link's own policy).
- Audience measurement of the public website: your consent, given via the cookie banner (Art. 45c of the Telecommunications Act for Switzerland; Art. 5(3) of the EU "ePrivacy" Directive for visitors residing in the EU); as a complementary basis, the legitimate interest of Skyday Sàrl in measuring the use of its own website — details in §2.4.
4. Who has access to your data
- Internally: only the person(s) operating the service for Skyday Sàrl, including via the Stripe dashboard for billing.
- You only see the data of your own account and the aggregated statistics of your own QR codes — never those of another account holder.
- People who scan a contact-card type QR code receive the contact details you have chosen to publish there.
- No reseller, no advertising partner, no data broker has access to your data. The only third parties are our hosting and payment processors (§6), as well as Google and Gencie for the audience measurement of the public website (§2.4, §6.4, §6.5), only if you have consented to it. If you use Stripe Link (§2.3), Stripe shares your data with the other merchants with whom you choose to pay via Link — outside our relationship with you, under Link's own terms.
- Google LLC, for the audience measurement of the public website described in §2.4, only if you have given your consent via the cookie banner. Google processes this data for its own complementary purposes, within the limits of its privacy policy (policies.google.com/privacy).
- Gencie (Weboard product, a Swiss company), to whom we grant read-only access to our Google Analytics and Search Console data, via an official API connection, so that we can view it in a single dashboard. Gencie does not carry out any additional collection on this website: it only accesses the data already described in §2.4. This mention is strictly limited to the reporting module of Weboard, the only module we use; Weboard also offers other features, not activated here, including an analysis module relying on third-party artificial intelligence tools — this module is not described in this policy as long as it is not used for this website, and an update would be published before any future activation.
5. Retention period
- During the relationship (pilot, or Free/Pro subscription): your account, your QR codes and their total counter are retained for as long as the relationship exists.
- Daily statistics: retained on a rolling 15-month basis, regardless of plan, then automatically deleted — the service's first automated deletion mechanism, limited to this daily data only. The total counter is not affected. The statistics of a deleted QR code or account disappear along with it.
- End of a pilot with no follow-up (rule confirmed by the management of Skyday Sàrl on 2026-09-11, duration specified on 2026-09-16, applicable to SMEs still in the pilot phase): a pilot officially ends either when the SME switches to the Pro subscription (the "End of the Pro subscription" rule below then applies — no deletion), or, failing that, automatically 6 months after it begins. In this second case — a pilot ending without a switch to the subscription — the account and associated QR codes are deleted no later than 3 months after this official end of the pilot, unless you instruct us otherwise.
- End of the Pro subscription: your account is not deleted — it reverts (after the grace period, §2.3) to the rules of the Free plan, and you can resubscribe at any time.
- Inactive Free account (mechanism implemented and active): a Free plan account is considered inactive after 6 months without a login or a scan of any of its QR codes; this period restarts completely from zero at the slightest login or scan. As this period elapses, you are warned by a series of emails: reminders at months 1, 2, 3 and 4 of inactivity, an explicit warning at month 5, then reminders at day -7, -2 and -1 before the 6-month deadline. At the deadline (day 0), we send you a deletion notice together with a recovery link valid for 30 days, and your account enters the "pending permanent deletion" state: your data (account, QR codes, statistics) remains intact but is only accessible via this recovery link. If you do not reactivate your account within this additional 30-day period, it is permanently and irreversibly deleted — account, QR codes and statistics.
- Public website audience measurement data (GA4): retained on a rolling 14-month basis, set in the configuration of Google Analytics 4 (§2.4) — this duration allows us to have the 12 previous complete months available at any time of the year, in order to compare traffic trends year-on-year and improve the user experience of the website; it also corresponds to the maximum duration offered by this tool (see §2.4 for details).
- On simple request, at any time (right to erasure, §8): account deletion within a maximum of 30 days of your request. Once your request has been processed by our team, deletion — account, QR codes, statistics, and your Stripe customer record (name, email, address, payment methods) — takes place right away, through the same technical mechanism as the automatic deletion of inactive Free accounts (above); Stripe retains only a technical identifier, without any identifying data. Invoices already issued remain stored independently (see "Invoices and payment history" below), because Stripe fixes the name/email/address on each invoice at the time it is issued — this accounting retention is not affected by the deletion of the customer record. Any remaining Link data, where applicable, continues to be managed under Link's own terms, independently of this deletion.
- Invoices and payment history: retained for 10 years (accounting obligation, Art. 958f CO), with Stripe and in Skyday Sàrl's accounts — even after your account is deleted. They only contain the elements of an invoice (email, plan, amount, date), never card data.
- Transient IP fingerprint for deduplication: a maximum of 5 seconds, never persisted (§2.2).
- Password reset link (§2.1): valid for 60 minutes when you request it yourself via "Forgot your password?" (24 hours when an administrator of your account triggers it for you), and single-use — each new request cancels the previous link. We keep only its cryptographic fingerprint: it is erased as soon as the link is used; otherwise, the link can no longer be used once its validity period has expired, and its fingerprint, now useless, is overwritten by that of any new request or deleted along with the account.
- Address entered in "Forgot your password?" and anti-abuse counters: the address entered is not retained. The non-reversible fingerprints used to limit serial requests are held in the server's memory only, over a 60-minute window, and are never persisted (§2.1).
- Test accounts on the validation environment ("staging"): retained for the duration of the announced test window, then deleted no later than 30 days after that window closes.
Justification: unlike the pilot, the subscription-based commercial relationship is no longer time-bound; without an inactivity rule, retention would become unlimited by default, contrary to the principle of proportionality (Art. 6 para. 2-4 nFADP). The 15-month retention of daily statistics and the 6-month inactivity rule (with its cascade of email warnings and its 30-day recovery period) limit this retention; the 10-year retention of invoices is a legal obligation, not a choice. Deletion for inactivity of a Free account is now an automated, technically verified mechanism; deletion linked to the end of a pilot remains, to date, an action carried out by Skyday Sàrl.
6. Hosting and processors
6.1 Infomaniak (hosting, Switzerland)
Your account data, your QR codes, your statistics and the subscription identifiers we keep are hosted exclusively in Switzerland, with Infomaniak:
- Application server (production): Jelastic Cloud, Geneva (DC2).
- Database (production): separate Infomaniak hosting (MariaDB).
Infomaniak acts as a processor within the meaning of Art. 9 nFADP / Art. 28 GDPR. A standard Data Processing Agreement (DPA) published by Infomaniak, covering both the nFADP and the GDPR, must be signed on Skyday Sàrl's Infomaniak account.
Messaging (service emails). The service emails that our application sends you (in particular: password reset link and password-change notification, invitation to join an account, messages relating to account inactivity, reminder of an unfinished Pro plan choice) are sent via Infomaniak's messaging service (SMTP relay), also hosted in Switzerland. This relay therefore carries the recipient's address and the content of these emails — including, for a password reset, the single-use link — while they are being delivered; Infomaniak acts here too as a processor, under the data processing agreement described above. Subscription-related emails (receipts, invoices, failed payment) are, for their part, sent by Stripe (§2.3).
6.2 Stripe (payment and subscription)
Payment, subscription management (customer portal) and the sending of receipts and invoices are handled by Stripe Payments Europe, Limited, Dublin, Ireland (a company of the Stripe group, whose parent company is based in the United States). Stripe acts in three capacities:
- as a processor for Skyday Sàrl for the management of your subscription, under Stripe's Data Processing Agreement (stripe.com/legal/dpa), incorporated into its terms of service;
- as an independent controller for the payment processing itself — fraud detection, compliance with its legal and regulatory obligations (anti-money laundering, identification), improvement of its services. For this part, Stripe's privacy policy applies: stripe.com/privacy;
- also as an independent controller for Stripe Link (§2.3) — under Link's own terms and privacy policy (stripe.com/legal/link, link.com/privacy).
Stripe uses its own processors and affiliated companies, the list of which is published at stripe.com/legal/service-providers. The resulting transfers outside Switzerland are described in §7.
6.3 Validation environment ("staging")
In addition to the production environment, Skyday Sàrl may use a second Infomaniak environment, separate but equivalent in nature (Jelastic Cloud Geneva DC2 + separate MariaDB database, same application code, same security measures), to test a feature before it goes into production. This environment is only accessible to the management of Skyday Sàrl and, occasionally and by invitation, to a limited number of account holders taking part in a test ("key users") — never publicly accessible, its address is neither published nor indexed. Stripe operates there in test mode only (no real banking data). If you take part in it, see §2.1 and §5.
6.4 Google LLC (public website audience measurement, with consent)
For the audience measurement described in §2.4, we use Google Analytics 4, a service of Google LLC (United States). This processing only applies to visitors to the public website who have given their consent (§2.4) — never to your use of the dashboard once logged in. Google acts here as a separate third party, whose processing on its own behalf is governed by its own privacy policy. See §7 for the resulting data transfer.
Apart from this case, no other provider processes your personal data, except for Gencie (§6.5 below). The development of the service relies on software development assistance tools (including an AI assistant), but these tools have no access to any real personal data — they only work on the project's source code and documentation.
6.5 Gencie (Weboard) — read-only access to our audience reports
To view our website's audience statistics (§2.4) in a single dashboard, we use Weboard, a product of Gencie, a Swiss company. Gencie connects in read-only mode to our Google Analytics 4 (and Search Console) account via an official API — it does not place any additional cookie or tracker on this website and does not collect any new data: it only views the data already described in §2.4. Gencie acts as a processor for this processing, under a data processing agreement compliant with the nFADP/GDPR. Weboard's main infrastructure is hosted in Switzerland (Infomaniak).
This description is strictly limited to the reporting module of Weboard, the only module we currently use. Weboard offers other features not activated for this website, including an analysis module relying on third-party artificial intelligence tools based outside Switzerland; this module, should it ever be activated, would involve a data transfer to other countries, which would then be documented here before its activation, with the corresponding safeguard check — not retroactively.
7. Data transfers outside Switzerland
- Account, QR codes, statistics, subscription status: no transfer — hosting with Infomaniak in Switzerland (production and validation).
- Payment and subscription data entrusted to Stripe (§2.3): transferred to Ireland (Stripe Payments Europe Ltd), then, for the purposes of Stripe and its processors, to other countries, including the United States (Stripe, Inc.). Legal bases:
- Ireland: EU member state, recognised by the Federal Council as ensuring an adequate level of protection (Annex 1 of the Data Protection Ordinance — Art. 16 para. 1 nFADP).
- United States: Swiss-U.S. Data Privacy Framework, recognised by the Federal Council as ensuring an adequate level of protection for certified US companies, in force since 15 September 2024; Stripe declares its certification to this framework (stripe.com/legal/data-privacy-framework). As an additional safeguard, Stripe's DPA incorporates the standard contractual clauses applicable where this framework does not apply.
- Other countries of Stripe's processors: contractual safeguards provided for in Stripe's DPA.
- If you use Stripe Link: your data may be transferred and reused under Link's own terms, outside our contractual relationship with Stripe (§2.3, §6.2).
- Audience measurement data entrusted to Google (§2.4), only if you have consented: transferred to the United States (Google LLC). Safeguard: Swiss-U.S. Data Privacy Framework, recognised by the Federal Council as ensuring an adequate level of protection for certified US companies. Google LLC's certification to this framework (including its Swiss component) is active, verified on 2026-09-16 in the official register (dataprivacyframework.gov).
- Gencie (§6.5), which views our audience reports in read-only mode, hosts the infrastructure of the reporting module we use in Switzerland (Infomaniak): this does not, for this particular module, involve any additional transfer outside Switzerland.
GDPR: the service is currently offered by invitation to Swiss SMEs; the GDPR only applies in addition to the nFADP where a person residing in the European Union is affected by a processing activity (an assumption to be reassessed when online registration opens, and already confirmed for visitors to the public website because of the audience measurement, §2.4). Stripe's DPA already covers the GDPR.
8. Your rights
Whether you are an account holder, a person appearing on a contact card published by an account holder, a visitor to the public website who has consented to the audience measurement (§2.4), or simply a person whose IP address was transiently processed during a scan (see §2.2 — in this last case, the absence of any persistent or identifying data limits, in practice, the exercise of these rights), you have the following rights, as provided for by the Swiss Federal Act on Data Protection (nFADP) and, where the GDPR applies in addition (see §7), by that regulation:
- Right of access (Art. 25 nFADP): to obtain confirmation that data concerning you is being processed, and a copy of that data.
- Right to rectification (Art. 32 para. 1 nFADP): to have inaccurate data corrected (e.g. email address); if the accuracy of a piece of data cannot be established, you may request that a note of its disputed nature be added to it.
- Right to erasure and to the prohibition of a specific processing activity, through the action for protection of personality rights (Art. 32 para. 2 nFADP, referring to Art. 28, 28a and 28g to 28l of the Swiss Civil Code): you may request the deletion of your account and associated data (see §5 for the timeframes and for the accounting records that the law requires us to retain), the prohibition of a specific processing of your data, or the prohibition of its disclosure to a specific third party. For the audience measurement of the public website (§2.4), this right is simply exercised by refusing or withdrawing your consent.
- Right to data portability (Art. 28 nFADP), where the legal conditions are met (automated processing of data you have provided to us, in the context of your consent or the performance of the contract): your QR codes and their statistics may be provided to you, or transmitted to another controller, in a commonly used electronic format, on request.
- Where the GDPR applies (a person residing in the European Union affected by a processing activity, see §7): you additionally have, for that processing, the right to object (Art. 21 GDPR) and the right to restriction of processing (Art. 18 GDPR), as defined by that regulation. Swiss law does not name these two rights separately; their substance — stopping or limiting a specific processing activity — is covered, for all account holders, by the action for protection of personality rights described above.
To exercise any of these rights, contact contact@qrsuisse.ch. We respond within the timeframes provided for by the nFADP and, where applicable, the GDPR. For data that Stripe processes on its own behalf (§6.2), including for Link, you may also contact Stripe (or Link) directly, in accordance with their respective privacy policies. For data that Google processes on its own behalf (§2.4, §6.4), you may also contact Google directly, in accordance with its own privacy policy.
You also have the right to lodge a complaint with the competent supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC), https://www.edoeb.admin.ch; if the GDPR applies to your situation (§7), also the competent supervisory authority of your state of residence in the European Union.
9. Security of your data
Technical and organisational measures are in place to protect your data: password hashing (bcrypt, cost factor 12), encrypted sessions, limiting of login attempts and of password reset requests, HTTPS/HSTS, strict validation of submitted data, HTTP security headers (including a strict Content Security Policy). For password reset: a single-use, time-limited link (60 minutes) of which only the fingerprint is stored; an identical response whether or not the account exists; closing of open sessions and a notification email after any change; the link's address is passed neither to the audience measurement tool nor to third-party websites (no measurement on these pages, "Referer" header disabled). For payment: no card data passes through our servers; the notifications sent by Stripe to our application are signed and verified; our application's access to Stripe uses a key with restricted permissions. For the audience measurement of the public website (§2.4): no Google Analytics tag loads and no request is sent to Google before your explicit consent (basic Consent Mode); a refusal is immediately and symmetrically respected; the IP address is anonymised before any storage; form abandonment tracking never captures the value entered in a field. These measures apply identically on the production environment and on the validation environment (same code deployed). In the event of a data breach affecting you, a data breach management procedure applies.
10. Changes to this policy
This policy may be updated if the service evolves (a new feature processing personal data, a change of hosting or payment provider, etc.). Any substantial change will be communicated to account holders. The version in effect is always the one published in the application.