Privacy notice
Introduction
The well · change atelier (hereinafter the "well") values privacy. With this privacy notice, the well informs the person using or viewing the Website (a "User") how it collects, uses, discloses and otherwise processes personal data. Other privacy notices, individual notices or information may apply to specific matters. Personal data is understood to be all information that relates to a specific or identifiable natural person.
1. Data controller and contact details
The controller of the data processing described in this privacy notice is the well. User can notify the well of any data protection-related concerns using the following contact details:
The well · change atelier
c/o Parayma GmbH
c/o Impact Hub Zürich AG
Sihlquai 131
CH – 8005 Zürich
hello@changeatelier.org
2. Collection and processing of personal data
The well processes personal data that it receive from User, its clients and their employees, business partners, from authorities or other third parties. Insofar as it is permitted to the well, it may also obtain certain personal data from publicly accessible sources.
The categories of personal data that the well collects and processes about User may include, in particular, the following:
Personal information and contact details, such as name, address, telephone number, e-mail address and gender. In addition, in case User shares this information with the well, personal information may further include date of birth, nationality, pictures, professional functions and activities, education, and qualifications.
Information contained in communication and other interactions with the well, such as correspondence by letter or e-mail or through other means of communication with User or with third parties.
Financial information, such as invoicing information, payment details and bank details. In addition, in case User shares this information with the well (for example to obtain a scholarship), personal financial information of User, including their financial situation.
Data related to marketing activities, such as preferences and interests, newsletter opt-ins and opt-outs, responses to marketing activities, invitations and participation in events and activities.
Data related to the use of the well’s website and other applications, such as connection data, IP address and other identifiers (e.g. user name in social media, MAC address of the smartphone or computer, data from cookies and similar technologies), date and time of the visit to the well’s website, duration of the visit to the website, requested internet address (URL), referrer URL (i.e. the internet address of the website from which User accessed its website, if applicable with the search term used), browser type and version, operating system used, amount of data sent in bytes, and the search term used, location data, pages and content accessed, functions used.
3. Purposes of data processing and legal bases
The well may process personal data in accordance with applicable data protection law for the following purposes and, if necessary under applicable data protection law, on the basis of the following legal basis:
For the performance of contracts and providing the products and services User requests: the well processes personal data in connection with the conclusion and performance of contracts with its clients and business partners, in particular in the context of providing services and products to its clients and the procurement of products and services from its suppliers and subcontractors, as well as in order to comply with its legal obligations relating thereto.
To inform User about the well’s projects, products, the website, events and other information relating to the well’s activities.
To offer scholarships to User provided they made a request in that sense and provided the well with due information regarding their situation.
To fulfill legal obligations: the well processes personal data in order to comply with its legal or regulatory obligations. Processing purposes include, but are not limited to documenting compliance with legal and regulatory requirements.
To safeguard legitimate interests: the well processes personal data for the following purposes if this is necessary to protect the legitimate interests of itself or of third parties or to protect legitimate public interests:
providing and developing our products, services and websites, applications and other platforms, on which we are active;
communication with third parties and the processing of their requests (e.g., job applications, media inquiries);
advertising and marketing (including organizing events), provided that User has not objected to the use of their data for this purpose;
asserting legal claims and defense in legal disputes and official proceedings;
ensuring its business operations, including its IT, websites, apps and other appliances.
Based on User’s consent: If User has given the well consent to process its personal data for certain purposes, it processes User’s personal data within the scope of and based on this consent, unless the well has another legal basis and we require such a basis. This is typically the case when the well needs to process an order placed by User,
In no event does the well use your data for profiling or automated decision-making.
4. Cookies, tracking and other technologies related to the use of the website
The well may use cookies and similar technologies on its website and with respect to its marketing communication that allows the well to store information on its device and/or access information stored on User’s device or to receive information on User’s response to website offerings and other marketing activities. In addition, the well uses on its website:
Google Analytics, which is a service of Google (google.com), with which the well can measure and evaluate the use of the website. Permanent cookies that Google sets are also used for this purpose. Google does not receive any personal data from the well (and does not retain any IP addresses), but it can track User’s use of the website. Further information on Google Analytics and the data processed can be found here: https://support.google.com/analytics/answer/6004245; and
Meta Pixel, which is a service of Meta (meta.com), with which the well can measure and evaluate the use of the website and the links between it and certain social media platforms such as Instagram. In particular, it records the actions User takes after viewing and/or interacting with the well’s content on certain social media platforms. No personal information is contained or collected by or as a result of Meta Pixel. You can use further information on Meta Pixel here: https://www.facebook.com/business/help/742478679120153?id=1205376682832142.
By using the well’s website, apps and consenting to receive newsletters and other marketing emails, User accepts the use of the above mentioned technologies. If User does not wish to do so, User can block or delete the cookies and similar technologies via the privacy settings of their browser and e-mail program, whereby this may under certain circumstances affect the use of the well’s website.
5. Disclosure of personal data to other persons
The well will not trade or sell the User’s personal data to third parties.
The well may disclose personal data to the following categories of recipients:
Business partners, service providers and suppliers the well works with (e.g., practitioners, coaches), who may act as independent data controllers or process personal data for the well’s own purposes (e.g., providers of cloud and payment services as well as other IT services);
The public, including users of our websites and social media, provided User has given express prior written consent.
6. Disclosure of personal data abroad
Recipients of personal data may be located in Switzerland or abroad. The well may disclose personal data to recipients in the EU/EEA, the UK, the USA or any other country of the world, whereby the location of the recipient depends on the matter at hand.
If the well discloses personal data to a country without adequate data protection legislation, the well will ensure that this is done in compliance with applicable data protection law. The well ensures adequate protection, namely by means of sufficient contractual guarantees such as the standard contractual clauses of the European Commission or by relying on another legal transfer tool. By providing User’s personal data, User consents to such transfers, storage, or processing.
Typically, the well’s website is hosted in the United States of America by Squarespace. In particular, they provide the well with the e-commerce platform that enables the well to provide its services. User’s data is stored in their Tier III data center. It is kept on a secure server protected by a firewall. Furthermore, they comply with the Swiss-U.S. Data Privacy Framework. You can find out more about them here.
Payments by bank transfer are made through ThriveCart LLC and Stripe Technology Europe, Limited, Dublin, Ireland. The payment details User provides when using the website are only stored by ThriveCart LLC or Stripe Technology Europe Ltd. In the case of a payment card registration for future reuse, the well only retains a partially masked card number, the expiry date and an identifier enabling the well to identify User to Stripe Technology Europe Ltd. User can find out more information about them here.
The well uses FloDesk (FloDesk Inc., San Francisco, United States of America) for its newsletter, to whom the well only transmits User’s name, surname and e-mail address when User subscribes to the well’s newsletter. User can find out more information about them here.
7. Duration of the retention of personal data
The well processes and stores personal data as long as it is necessary for the processing purpose for which the well collected it. Typically, this is for the term of our business relation and thereafter, as long as the well has a legitimate interest in retaining the information. In addition, there may be a contractual or legal obligation to retain or document data (e.g. in accordance with the Swiss Code of Obligations, Value Added Tax Act, etc.).
8. Data security
The well takes appropriate technical and organizational security measures to protect User’s personal data from unauthorized access and misuse, such as the issuance of warnings, training, IT and network security solutions, access controls and restrictions, encryption of data media and transmissions, pseudonymization, controls.
9. Rights of data subject
If User wants to know what personal data the well holds about them or wish for it to be deleted, they are kindly ask to reach out to the well at hello@changeatelier.org.
In certain circumstances, User possesses these data protection rights:
Access: User can ask for details about User’s personal data the well has.
Rectification: If the data is inaccurate or incomplete, User can request corrections.
Objection: User can contest the use of their data for specific reasons; for instance, using the unsubscribe option in the well’s emails.
Restriction: User can ask the well to limit the processing of User’s data.
Data Portability: Request a copy of User’s data from the well in a standard, machine-readable format.
Withdraw Consent: Should the well process data based on User’s consent, User can retract it at anytime.
User is kindly asked to understand the well might ask them to confirm their identity before acting on these requests. If unsatisfied with how the well handles User’s data, User can report to their local Data Protection Authority.
10. Modifications of the privacy notice
The well may amend this privacy notice at any time without prior notice. The current version published on the website shall apply.