Privacy Policy

Privacy Policy

How SIPI processes your personal data.

A plain-language description of what we collect, why we keep it, and the rights you can exercise — under the revised Swiss Federal Act on Data Protection (revFADP) and the EU General Data Protection Regulation (GDPR).

1. Who is the data controller?

The Swiss Impact & Prosperity Initiative (“SIPI”) is a programme operated by B Lab Switzerland Foundation, a Swiss public-utility foundation registered in Geneva. The Foundation is the data controller for personal data processed through this website (impact.swiss).

Postal address:
B Lab Switzerland Foundation
Rue de Lyon 77
1203 Geneva, Switzerland

Data-protection contact: jnormand@blab-switzerland.ch · support@blab-switzerland.ch

2. Which laws apply?

Processing of personal data through this site is governed by the revised Swiss Federal Act on Data Protection (revFADP, in force since 1 September 2023) and, where the data subject is located in the European Economic Area, by the EU General Data Protection Regulation (GDPR, Regulation 2016/679). Where these two regimes diverge, we apply the standard most favourable to the data subject.

3. What personal data we collect

We collect the minimum amount of personal data needed to operate the site and respond to people who choose to contact us.

  • Form submissions. When you submit the “Engage with SIPI” or newsletter forms (powered by our internal sipi-engage-form and sipi-newsletter components), we receive the name and email address you provide, plus any free-text message and the timestamp of submission.
  • Server access logs. Our hosting provider (Infomaniak, Switzerland) keeps standard web-server logs containing your IP address, the requested URL, the HTTP response code, the browser user-agent string, and the timestamp of each request. These logs are necessary to operate the service, prevent abuse and diagnose incidents.
  • Authentication tokens for editorial staff. Authorised SIPI editors who log into the WordPress back-office use two-factor authentication; the resulting tokens (TOTP / WebAuthn / recovery codes) are stored in the WordPress database against the staff member’s user account.
  • Cookies. We set only essential cookies — a WordPress session cookie when an editor is logged in, a language-preference cookie if you change interface language, and the cookie that records your consent choice (see Section 9). We do not deploy analytics cookies, advertising trackers or social-media pixels at this time.
  • No analytics today. SIPI currently runs no third-party analytics on this site. If we add an analytics tool in the future (for example, a self-hosted, IP-anonymising tool such as Plausible or Matomo), this section will be updated and the cookie banner will offer a granular opt-in.

4. Why we process this data — legal bases

Each category of processing has a defined legal basis under Article 6 GDPR and Article 31 revFADP:

  • Form submissions: processed on the basis of your consent (Art. 6(1)(a) GDPR / Art. 31(1) revFADP), which you give by submitting the form. Consent can be withdrawn at any time by writing to the data-protection contact above.
  • Server logs and abuse prevention: processed on the basis of our legitimate interest in operating a secure, available website (Art. 6(1)(f) GDPR / Art. 31(2)(b) revFADP). This interest does not override your fundamental rights and freedoms, because the data is not used to profile or target you.
  • Editor authentication: processed because it is necessary for the contract between SIPI / B Lab Switzerland and the editorial team (Art. 6(1)(b) GDPR), and to comply with our duty to apply state-of-the-art security measures (Art. 8 revFADP).
  • Mandatory disclosures and accounting records: processed where required by Swiss accounting law and EU record-keeping obligations (Art. 6(1)(c) GDPR / Art. 31(2)(c) revFADP).

5. Who receives the data

SIPI does not sell, rent or share personal data with third parties for marketing purposes. The only parties that receive personal data through this site are:

  • Infomaniak Network SA (Geneva, Switzerland) — our hosting provider. Infomaniak operates the servers and stores backups exclusively in Switzerland. Infomaniak acts as a data processor under a written agreement and is bound by Swiss data-protection law.
  • B Lab Switzerland Foundation staff — a small number of authorised employees and contractors of the Foundation, on a strict need-to-know basis, in order to read form submissions and respond to enquiries.

We do not currently use any third-party data-processing service besides Infomaniak. We do not transfer personal data outside Switzerland or the European Economic Area. If a future processor changes that situation, this section will be updated and we will adopt the appropriate safeguards (standard contractual clauses, adequacy decision or equivalent).

6. How long we keep data

  • Form submissions (name, email, message): up to 24 months from the date of submission, then deleted, unless an active dialogue or service relationship requires us to keep it longer.
  • Server access logs: 90 days, after which they are rotated and irreversibly deleted by Infomaniak.
  • Encrypted backups of the website database: 12 months on a rolling basis, after which the oldest backup is overwritten.
  • Authentication and 2FA secrets for editors: kept for as long as the user account is active, and deleted within 30 days of account deactivation.
  • Mandatory accounting records that incidentally include personal data may be kept for up to 10 years as required by Swiss law.

7. Your rights as a data subject

Under both the revFADP and the GDPR you have the following rights, exercisable free of charge by writing to the data-protection contact above:

  • Right of access — obtain confirmation that we process data about you, and a copy of that data.
  • Right to rectification — ask us to correct inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”) — ask us to delete data we no longer need or that we hold without a valid legal basis.
  • Right to data portability — receive the data you provided to us in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interest, in which case we will stop unless we can demonstrate an overriding ground.
  • Right to withdraw consent — revoke any consent you previously gave us, with effect for the future.
  • Right to lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC); in the European Union it is the supervisory authority of your country of residence (a list is maintained by the European Data Protection Board).

We will respond to verified rights requests within 30 days. We may need to verify your identity before complying, in order not to disclose data to the wrong person.

8. Security measures

The site is served exclusively over HTTPS with HSTS, runs on managed Swiss-based infrastructure, and uses two-factor authentication for all editor accounts. We apply WordPress and PHP security updates on a continuous basis, restrict back-office access to known IP ranges where feasible, and keep encrypted off-site backups. No system is perfectly secure, but we treat security as an ongoing engineering responsibility, not a one-off project.

9. Cookies and the cookie banner

On your first visit you will see a banner letting you accept all cookies, reject non-essential cookies, or open the “Customize” panel for granular control. Today, only the “essential” category is in active use; the “analytics” and “marketing” categories exist in the banner so that, if we add such tooling later, your existing choice will already be on file. Your choice is recorded in a cookie called sipi_cookie_consent with a one-year lifetime. You can change your choice at any time via the Cookie settings link in the site footer.

10. Changes to this policy

If our processing changes materially we will update this notice, change the “Last updated” date below, and where appropriate ask for fresh consent. Minor editorial updates will not be flagged individually.

Last updated: 26 April 2026.