Supplement for Swiss residents under the revised Federal Act on Data Protection (nFADP).
Last updated: 2026-07-16
This notice supplements the main Pistaclub Privacy Policy and applies to residents of Switzerland (and, where relevant, Liechtenstein). The applicable law is the revised Swiss Federal Act on Data Protection ("nFADP"), in force since 1 September 2023, together with the Data Protection Ordinance (DPO).
The controller is Pistaclub s.r.o., identified in the legal-entity block at the foot of this page and in the main Privacy Policy. Under Art. 14 nFADP a controller domiciled abroad must designate a representative in Switzerland if the processing meets certain thresholds (large-scale, high-risk, or regular in Switzerland). Pistaclub's current Swiss footprint is below the threshold that requires representative designation. If our footprint grows above the threshold, we will designate a representative and list them here.
Under Art. 10 nFADP a data protection advisor is optional for private-sector controllers. Pistaclub has appointed a data protection officer voluntarily; the contact is dpo@pistaclub.app.
Most requests can be handled in-app at Profile → Support. For email requests use privacy@pistaclub.app with the subject "nFADP request — [type]". We will respond within 30 days of receiving a valid request, the standard response window under the DPO.
You have the right to complain to the Swiss supervisory authority:
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB) / FDPIC
Feldeggweg 1, CH-3003 Bern
Phone: +41 58 462 43 95
www.edoeb.admin.ch
Our primary servers and sub-processors are established in the European Economic Area. Switzerland's Federal Council recognises the EEA as providing an adequate level of protection under Art. 16 nFADP, so transfers from Switzerland to the EEA do not require additional safeguards.
For transfers to any sub-processor outside the EEA that is not on the Swiss adequacy list, we rely on the Swiss version of the Standard Contractual Clauses (the "FDPIC-approved SCCs") or the Swiss addendum to the EU SCCs — detailed in the Sub-processors registry.
Under Art. 24 nFADP we notify the FDPIC of any high-risk personal-data breach as soon as possible after becoming aware of it. Where the breach is likely to result in a high risk to the rights of affected individuals, we also notify those individuals — same standard as our EU breach-notification runbook.
The nFADP introduces criminal liability for certain violations, including intentional failures to provide the information required under Art. 19 or to comply with the duty of care under Art. 8. We take our disclosure and security obligations seriously; this Privacy Policy family (main policy + regional supplements) is our primary Art. 19 disclosure.