PoiGeo← Map

Supplement · Switzerland

Switzerland (revised FADP) Supplement

Last updated:

1. Applicability

The revised Federal Act on Data Protection of 25 September 2020 (“revFADP”) and the Data Protection Ordinance of 31 August 2022 apply to our processing of personal data about persons in Switzerland insofar as that processing has an effect in Switzerland (Art. 3 revFADP). We accept that the revFADP applies to our Service.

2. Representative in Switzerland

Article 14 revFADP requires controllers established outside Switzerland to designate a representative in Switzerland if their processing (i) relates to the offering of goods or services or to the monitoring of behaviour of persons in Switzerland, (ii) is on a large scale, (iii) is regular, and (iv) presents a high risk to the personality of the data subjects. All four conditions must be met cumulatively.

Our processing of data about Swiss users is currently neither on a large scale nor high risk, and a representative is therefore not required by law. We will appoint a Swiss representative if and when our processing meets the cumulative threshold, and will publish the appointment in this Supplement before relying on it. In the interim, you may contact us directly using the addresses below; we respond to all Swiss requests in line with the revFADP whether or not the representative requirement applies.

3. Lawful basis & purpose limitation

We process personal data in accordance with the principles of lawfulness, good faith, proportionality, and purpose limitation set out in Art. 6 revFADP. Where the GDPR would require a specific lawful basis (Art. 6 GDPR), the revFADP does not, but we observe an equivalent standard: each processing operation is tied to a specific, legitimate purpose, and we do not process personal data in a way that is incompatible with that purpose without informing you.

4. International disclosures (Art. 16–17)

We disclose personal data about Swiss users to recipients in the European Union and the United States. For EU/EEA destinations, the Federal Council's adequacy decision applies; no additional safeguard is required (Art. 16(1) revFADP). For the United States, we rely on the EU Standard Contractual Clauses (Module relevant to the transfer) read together with the Swiss FDPIC's notice of 27 August 2021, which permits use of the EU SCC with the agreed Swiss adaptations. We apply the supplementary technical and organisational measures described in the global Privacy Policy §13.

5. Your rights

  • Right of access (Art. 25) — including the right to receive a copy of your personal data in a form that is comprehensible.
  • Right to data portability (Art. 28) — receive personal data you have given us in a common electronic format.
  • Right to rectification (Art. 32(1)).
  • Right to object to processing (Art. 30) and to obtain restriction or deletion where applicable.
  • Right to information at collection (Art. 19) — provided in the global Privacy Policy and reinforced here.

We respond to verified requests within thirty (30) days. Routine responses are free of charge.

6. Profiling and automated decisions

We do not engage in “high-risk profiling” (Art. 5(g) revFADP) and we do not take automated individual decisions that produce legal effects or similarly significantly affect you (Art. 21). Where you submit a coordinate for analysis, the AI-generated commentary is an informational output, not a decision about you.

7. Security and breach notification

We apply the technical and organisational measures described in the global Privacy Policy §13 to protect personal data against unauthorised access, alteration, or loss (Art. 8 revFADP and Art. 1–6 DPO). Where a data security breach is likely to result in a high risk to the personality or fundamental rights of the data subject, we notify the FDPIC as soon as possible (Art. 24).

8. Complaints to the FDPIC

You may bring a matter before the Federal Data Protection and Information Commissioner — edoeb.admin.ch — at any time. The FDPIC may open an investigation and issue orders directly against the controller. We ask that you contact us first.

9. Contact

Email privacy@poigeo.app. Data Protection Officer (DPO): dpo@poigeo.app.