隐私政策
本文件目前以英文提供。
Version: 2.0 (draft in revision)
Effective date: 1 September 2026
Last updated: 1 September 2026
This Privacy Policy describes how the Ocio Platform processes personal data in connection with end-user online access to the Ocio Platform. The Ocio Platform powers several branded applications (each, an "App"). Each App can be used for booking, for community / peer connection, for content discovery, or for any combination of these. The set of Apps evolves over time; the App you are currently using is identifiable by its branding and domain. Capitalised terms not defined here have the meaning given in the Ocio End-User Terms and Conditions.
The controller of personal data processed via the Ocio Platform is:
Apsara Software GmbH
Mailing address: Hohlstrasse 210, 8004 Zürich, Switzerland
Email: [email protected]
Phone: +41 78 704 2572
(the "Operator", "we", "us", "our").
We act as data controller under the Swiss Federal Act on Data Protection ("FADP", revFADP in force since 1 September 2023) and, where the EU General Data Protection Regulation ("GDPR") applies, under GDPR Article 4(7).
EU representative. As of the Effective Date we have not appointed an EU representative under GDPR Art. 27 because our current processing does not target EU-based data subjects at meaningful scale. We will appoint a representative when this changes.
Supervisory authorities. You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner ("FDPIC") at edoeb.admin.ch, or, if you are in the EU/EEA, with the data-protection authority of your habitual residence or place of work.
2.1 This policy applies to personal data processed by the Operator in operating the Ocio Platform — including the customer-facing Apps, the operator administration interfaces, the backend services, and related communications. It covers end-user online access: every natural person who uses the Ocio Platform through an App, including persons who do so as a Tenant's owner, administrator, teacher, or other staff.
2.1a If you act for a Tenant. For a person who uses the Ocio Platform on behalf of a Tenant, this policy governs the processing connected with their individual online access, while the separate, individually agreed Business Contract between the Operator and the Tenant governs the processing connected with the business relationship — including any data-processing arrangements under which the Operator processes the Tenant's customer data on the Tenant's documented instructions. For those persons, the entire scope of the applicable privacy terms is the combination of this policy and that Business Contract; concerning the business relationship, the Business Contract prevails.
2.2 This policy does not apply to:
(a) personal data that a Tenant processes independently of the Ocio Platform — for example, on-premises CCTV, door-access logs, paper sign-up sheets, in-house marketing lists, separate customer-relationship systems. The Tenant is a separate, independent controller for those activities and publishes its own privacy notice;
(b) third-party websites or services that you reach by following a link from the Ocio Platform; or
(c) personal data processed by Stripe, by your OAuth identity provider (where you sign in via Google/Apple/etc.), or by other third parties acting in their own controller capacity. Their privacy notices apply to their own processing.
When you sign up on any App, the Ocio Platform creates a single, portable Ocio Account that works across every App. You are identified externally by a stable Profile Name (e.g. user_ab12cd34); your internal account identifier is never exposed to other Users, Tenants, or third parties. You can update your Profile Name within the limits the Ocio Platform allows.
This means: if you sign up on one App today and visit another App tomorrow, the same Ocio Account works on both — but each Tenant only sees what the Ocio Platform exposes, never your raw account ID.
We collect only the data we need to operate the Ocio Platform. Categories below are non-exhaustive; specific fields evolve with product features.
4.1 Account data
- Required at sign-up: email address and password, or an OAuth identity (where supported by the relevant App).
- Optional: display name, first / last name, profile picture, Profile Name, locale.
- Account state: account creation date, last login, language preference, notification preferences.
We do not collect at sign-up: date of birth, gender, nationality, identity-document data, biometric data, sexual-orientation data, health data, religious data, political opinions. A Tenant may request such data for a specific activity (e.g. age verification for an alcohol-licensed venue) — when it does, that data flows under the Tenant's privacy notice, not this one, unless we explicitly store it on the Tenant's behalf.
4.2 Booking data
When you place a Booking on a Tenant's site, we record:
- the Catalog item booked (Facility, Instructor, Class) and the slot times;
- the Order state (
submitted,confirmed,cancelled,superseded); - the linked Stripe payment intent ID (no card data — see § 4.5);
- any
| Purpose | Lawful basis |
|---|---|
| Create and operate your Ocio Account; authenticate you. | GDPR Art. 6(1)(b) (contract); FADP Art. 31(2)(a). |
| Render a Tenant's Catalog and process your Bookings. | GDPR Art. 6(1)(b). |
| Process payments via Stripe. | GDPR Art. 6(1)(b) and 6(1)(c) (legal obligation: tax / accounting). |
| Issue and verify Access Tokens. | GDPR Art. 6(1)(b). |
| Send transactional emails (booking confirmations, password resets, security alerts). | GDPR Art. 6(1)(b). |
| Operate Chat, Plans, Profiles, Member Directories, Connections, and other community features. | GDPR Art. 6(1)(b) (community is a core feature you signed up for). |
| Generate Member, Plan, and Event recommendations and matches. | GDPR Art. 6(1)(f) (legitimate interest in helping Users find relevant people and activities), or 6(1)(a) consent where the App presents this as an opt-in. You can object at any time. |
| Compile aggregated and anonymised statistics about Communities, Tenants, and the Ocio Platform overall. |
We share personal data only as described below.
6.1 Service providers (processors) acting on our instructions
| Recipient | Purpose | Country |
|---|---|---|
| Stripe Payments Europe Ltd. | Card processing, payouts to Tenants. Stripe acts as an independent controller for fraud prevention. | Ireland (EU); transactional metadata may be processed outside the EEA under Stripe's own SCCs. |
| [TBD: Q3 — hosting provider] | Primary hosting of the Ocio Platform backend (PostgreSQL, edge runtime, object storage). | Germany (EU). |
| [TBD: Q4 — transactional email provider] | Booking confirmations, password resets, security alerts. | EU. |
| Google Ireland Ltd. | Product analytics (Google Analytics 4) — loaded only after you accept analytics cookies on the in-App banner; configured with IP-anonymisation and without Google Signals or advertising integrations. | Ireland (EU); telemetry under Google's SCCs. |
| OAuth identity providers |
7.1 Primary hosting in Germany (EU/EEA). The Ocio Platform's primary servers are located in Germany. Switzerland and the EU/EEA mutually recognise each other as providing an adequate level of data protection, so transfers between them require no additional safeguard.
7.2 Possible future relocation within the EU/EEA. We may relocate the hosting environment to another country within the EU/EEA without further notice, provided the level of protection is not reduced. We will not relocate hosting outside the EU/EEA without updating this policy and, where applicable, putting Article 46 GDPR safeguards in place.
7.3 Limited transfers outside the EEA. Stripe and Google may process certain telemetry outside the EEA under their own GDPR SCCs. Aside from this, we do not currently transfer personal data outside Switzerland or the EU/EEA.
We keep personal data only for as long as we need it.
| Category | Retention |
|---|---|
| Account profile while account is active | For the lifetime of the Ocio Account. |
| Account profile after deletion | Up to 30 days for accidental-deletion recovery, then erased from primary systems; backups age out within 35 days. |
| Booking and payment records | 10 years after the end of the calendar year of the transaction (Swiss CO art. 958f; German HGB §257 parallel). |
| Access Token plaintext | Until the booked slot ends, then erased. The hash is retained with the Order for the same 10-year accounting period. |
| Chat messages | Until the User or the Tenant deletes them, or until the relevant Community is deleted; backups age out within 35 days. |
| Logs and security telemetry | 90 days, except where a longer retention is needed for an open security or abuse investigation. |
| Marketing-consent records | Until you withdraw consent + 3 years to evidence the prior consent. |
You have the following rights, subject to the conditions and exceptions of applicable law:
- Access — request a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure ("right to be forgotten") — have your data deleted, subject to retention obligations in § 8.
- Restriction — restrict processing in certain situations.
- Portability — receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
- Object — object to processing based on legitimate interests, including profiling for marketing.
- Withdraw consent — at any time, with effect for the future only, where processing is based on consent.
- No automated individual decisions with legal/similarly significant effects — see § 5.
- Lodge a complaint with the FDPIC (Switzerland) or your local EU/EEA data-protection authority.
To exercise any of these rights, contact us at the address in § 13. We may need to verify your identity before responding. We aim to respond within 30 days (extendable per GDPR Art. 12(3)).
10.1 We apply technical and organisational measures appropriate to the risk, including:
- HTTPS/TLS in transit;
- password hashing using Supabase Auth (bcrypt / Argon2);
- row-level security (RLS) isolating each Tenant's data in the database;
- a least-privilege role-based permission model for Tenant staff (16-bit permission bitset, e.g.
MANAGE_ORDERS,MANAGE_CATALOG,MANAGE_PRICING); - SHA-256 hashing of Access Tokens for venue verification, with a short-lived plaintext copy retained only for legitimate display and scanning purposes;
- backup rotation;
- access logging and monitoring of administrator actions;
- vulnerability management and security updates.
10.2 No system can be guaranteed perfectly secure. We will notify you of personal-data breaches affecting your data when required by law (GDPR Art. 34, FADP Art. 24).
11.1 The Ocio Platform is intended for Users 18 years or older. We do not knowingly collect personal data of children under 18 without parental or guardian consent.
11.2 Where a Tenant offers activities for minors and supports parent/guardian-mediated registration, the parent or guardian assumes responsibility under the Ocio End-User Terms and Conditions. The Operator processes the minor's data on behalf of the parent / guardian and the Tenant.
11.3 Reports of suspected child-safety violations (CSAM, grooming, sextortion, trafficking, sexualisation of minors) are handled per § 16 of the Ocio End-User Terms and Conditions and reported to the appropriate authorities, including clickandstop.ch in Switzerland and, where applicable, the National Center for Missing and Exploited Children (NCMEC).
We may amend this Privacy Policy as our processing changes or as the law evolves. Material changes will be notified by email and/or in-App at least 30 days before they take effect, except where a shorter notice period is required by law.
To exercise your rights or ask any question about this policy:
Apsara Software GmbH
Mailing address: Hohlstrasse 210, 8004 Zürich, Switzerland
Email: [email protected]
Phone: +41 78 704 2572
