Skip to main content

Data Privacy Policy

Privacy Policy

Introduction

The processing activities described in this privacy notice are primarily governed by the Swiss Federal Act on Data Protection (FADP) and its implementing ordinance. The EU General Data Protection Regulation (GDPR) may also apply in specific circumstances, where its territorial conditions are met. 

Your data is held and processed in line with the Orange Cyberdefense Switzerland information security policies. 

The responsible body in the sense of the FADP/GDPR and other data protection regulations (data controller) is Orange Cyberdefense Switzerland, Rue du Sablon 4, CH-1110 Morges. You can contact our data protection officer by mail at the address provided or directly by e-mail at: dpo[at]ch[.]orangecyberdefense[.]com.

What data does Orange Cyberdefense Switzerland collect and why?

We only collect the minimum information about our marketing events participants to enable them a flawless experience when attending the events. The personal data collected includes: 

• First name 

• Last Name 

• Company 

• Email address 

• City 

• Country 

• Event option(s) subscribed to if applicable 

• Payment means details 

• IP address 

• Data related to website usage (collected via Google Analytics) 

Photographs and videos may be taken during the event to document and communicate about Insomni’hack. General views may be published where participants are not individually highlighted. Where a participant is the principal subject of a photograph, video or interview intended for promotional use, specific consent will be requested where appropriate. Participants who do not wish to be photographed or filmed may inform the organizers before or during the event. We will implement reasonable measures to take their preference into account. 

Participants who do not wish to appear in such material may contact the organizers before or during the event.

Data retention period

Personal data is retained only for as long as necessary for the purposes for which it was collected. 
Registration and event management data are retained for the duration necessary to organize the event and manage any related administrative, contractual, and legal obligations. 
Accounting and payment related information may be retained for longer periods where required by applicable legal or tax regulations. 
Photographs and videos used for communication and promotional purposes may be retained until they are no longer relevant for such purposes or until a valid objection is received where applicable. 
Website analytics data are retained in accordance with the retention settings configured in the analytics platform. When retention is no longer required, personal data is securely deleted or anonymized. 

The following table indicates the data processing activities outlined in this notice.

Processing activityPurposeJustification or explanation
Event registration and managementRegister participants, manage selected options, and issue access badgesProcessing necessary to register for and participate in the event
Payment and invoicingProcess payments and comply with accounting requirementsProcessing of paid registrations and compliance with applicable legal obligations
Event securityManage access control and prevent misuseInterest of the organizer and participants in ensuring the security of the event
NewsletterSend information about Insomni’hack and similar eventsConsent
Website analyticsUnderstand how the website is usedConsent
Photographs and videosDocument and promote the eventConsent for specific interview

Who are the recipients of these data?

Your data is only processed by authorized Orange Cyberdefense Switzerland employees and by its subcontractors.

Processors

The table below details the list of processors used by Orange Cyberdefense Switzerland. The terms of use of our processors’ service comply with the provisions set by the EU General Data Protection Regulation or the FADP in Switzerland.

Processor namePurpose of the subprocessingData locationSafeguard for transfer
InwinkProvision of information related to a marketing event, registration, options selection, entry badge issuanceWest Europe (Primary)
North Europe (Secondary)
N/A. Processor and data are located within the E.U.
Google AnalyticsAnalysis of website usage to improve user experience and event marketingUnited StatesData is anonymized and aggregated to protect user privacy.
Part of the Data Privacy Framework.
InfomaniakHost of the website and emailing optionSwitzerlandN/A.
StripePayment platformUSAData Privacy Framework
InwinkManagement of user consent for cookies and tracking technologiesWest Europe (Primary)
North Europe (Secondary)
N/A. Processor and data are located within the E.U.

Security controls

Orange Cyberdefense Switzerland implements technical and organisational measures to ensure a level of security appropriate to the risk faced by marketing events participants’ data. Orange Cyberdefense Switzerland guarantees compliance with and certification under ISO/IEC 27001:2022.

What are your rights?

You may exercise the following rights regarding your personal data, subject to applicable legal requirements and limitations:

  • Request access to the personal data we process about you;
  • Request the correction of inaccurate or incomplete personal data;
  • Request the deletion of your personal data where applicable;
  • Request the restriction of processing where applicable;
  • Object to the processing of your personal data where applicable;
  • Where processing is based on your consent, withdraw your consent at any time, without affecting the lawfulness of processing carried out before such withdrawal;

To exercise your rights, please contact us at: dpo[at]ch[.]orangecyberdefense[.]com.

We will respond to your request without undue delay and within the time limits required by applicable data protection laws. Under the GDPR, a response will generally be provided within one month of receipt of the request. This period may be extended where permitted by law, taking into account the complexity and number of requests. Under the Swiss Federal Act on Data Protection (nFADP), requests will be handled within the statutory deadlines and in accordance with applicable legal requirements.

If you believe that your personal data has been processed in breach of applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority. In Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC/PFPDT). Individuals located in the European Economic Area may also lodge a complaint with their local data protection authority.