Privacy Policy
Introduction
The processing activities described in this privacy notice are primarily governed by the Swiss Federal Act on Data Protection (FADP) and its implementing ordinance. The EU General Data Protection Regulation (GDPR) may also apply in specific circumstances, where its territorial conditions are met.
Your data is held and processed in line with the Orange Cyberdefense Switzerland information security policies.
The responsible body in the sense of the FADP/GDPR and other data protection regulations (data controller) is Orange Cyberdefense Switzerland, Rue du Sablon 4, CH-1110 Morges. You can contact our data protection officer by mail at the address provided or directly by e-mail at: dpo[at]ch[.]orangecyberdefense[.]com.
What data does Orange Cyberdefense Switzerland collect and why?
We only collect the minimum information about our marketing events participants to enable them a flawless experience when attending the events. The personal data collected includes:
• First name
• Last Name
• Company
• Email address
• City
• Country
• Event option(s) subscribed to if applicable
• Payment means details
• IP address
• Data related to website usage (collected via Google Analytics)
Photographs and videos may be taken during the event to document and communicate about Insomni’hack. General views may be published where participants are not individually highlighted. Where a participant is the principal subject of a photograph, video or interview intended for promotional use, specific consent will be requested where appropriate. Participants who do not wish to be photographed or filmed may inform the organizers before or during the event. We will implement reasonable measures to take their preference into account.
Participants who do not wish to appear in such material may contact the organizers before or during the event.
Data retention period
The following table indicates the data processing activities outlined in this notice.
| Processing activity | Purpose | Justification or explanation |
| Event registration and management | Register participants, manage selected options, and issue access badges | Processing necessary to register for and participate in the event |
| Payment and invoicing | Process payments and comply with accounting requirements | Processing of paid registrations and compliance with applicable legal obligations |
| Event security | Manage access control and prevent misuse | Interest of the organizer and participants in ensuring the security of the event |
| Newsletter | Send information about Insomni’hack and similar events | Consent |
| Website analytics | Understand how the website is used | Consent |
| Photographs and videos | Document and promote the event | Consent for specific interview |
Who are the recipients of these data?
Your data is only processed by authorized Orange Cyberdefense Switzerland employees and by its subcontractors.
Processors
The table below details the list of processors used by Orange Cyberdefense Switzerland. The terms of use of our processors’ service comply with the provisions set by the EU General Data Protection Regulation or the FADP in Switzerland.
| Processor name | Purpose of the subprocessing | Data location | Safeguard for transfer |
| Inwink | Provision of information related to a marketing event, registration, options selection, entry badge issuance | West Europe (Primary) North Europe (Secondary) | N/A. Processor and data are located within the E.U. |
| Google Analytics | Analysis of website usage to improve user experience and event marketing | United States | Data is anonymized and aggregated to protect user privacy. Part of the Data Privacy Framework. |
| Infomaniak | Host of the website and emailing option | Switzerland | N/A. |
| Stripe | Payment platform | USA | Data Privacy Framework |
| Inwink | Management of user consent for cookies and tracking technologies | West Europe (Primary) North Europe (Secondary) | N/A. Processor and data are located within the E.U. |
Security controls
Orange Cyberdefense Switzerland implements technical and organisational measures to ensure a level of security appropriate to the risk faced by marketing events participants’ data. Orange Cyberdefense Switzerland guarantees compliance with and certification under ISO/IEC 27001:2022.
What are your rights?
You may exercise the following rights regarding your personal data, subject to applicable legal requirements and limitations:
- Request access to the personal data we process about you;
- Request the correction of inaccurate or incomplete personal data;
- Request the deletion of your personal data where applicable;
- Request the restriction of processing where applicable;
- Object to the processing of your personal data where applicable;
- Where processing is based on your consent, withdraw your consent at any time, without affecting the lawfulness of processing carried out before such withdrawal;
To exercise your rights, please contact us at: dpo[at]ch[.]orangecyberdefense[.]com.
We will respond to your request without undue delay and within the time limits required by applicable data protection laws. Under the GDPR, a response will generally be provided within one month of receipt of the request. This period may be extended where permitted by law, taking into account the complexity and number of requests. Under the Swiss Federal Act on Data Protection (nFADP), requests will be handled within the statutory deadlines and in accordance with applicable legal requirements.
If you believe that your personal data has been processed in breach of applicable data protection laws, you have the right to lodge a complaint with the competent supervisory authority. In Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC/PFPDT). Individuals located in the European Economic Area may also lodge a complaint with their local data protection authority.




