Skip to main content
vsds

Privacy

Privacy notice

This notice explains how VSDS processes personal data when operating the website, handling membership applications and administering protected member services.

Controller and contact

Swiss Spatial Design Association (VSDS) Michelstrasse 13 8049 Zurich Switzerland Email: info@vsds.ch

Website use and data categories

When the public website is accessed, IP address and ordinary request, device, security and error information may be processed to deliver and protect the service. Email registration and Magic Link authentication process an email address, authentication events and session data. Membership applications may contain contact and professional information, location, requested category, motivation, website details, review consent and workflow timestamps.

Purposes of processing

VSDS processes personal data only for the purposes connected with the requested website and association services:

  • Operating, securing and delivering the public website.
  • Providing email registration, Magic Link authentication and session management.
  • Receiving, checking and responding to membership applications.
  • Administering membership profiles, categories, status and the membership relationship.
  • Controlling access to protected member services through role and status information.
  • Preparing, displaying and retaining membership invoices, fee and accounting records.
  • Providing authorised access to protected member documents, invoice records and PDFs.
  • Answering contact and support correspondence.
  • Detecting abuse, troubleshooting and investigating security incidents.
  • Meeting applicable legal, accounting and association-governance obligations.

Membership applications and manual decisions

Authorised admin or board roles review every membership application manually. No automated system accepts or rejects membership applications. For a linked account, a separate controlled activation step may update the application, profile, membership profile, role and administrative audit record.

Member profiles and protected access

Authenticated services process account and session information, member profile data, membership category and status, role and access-control information. Access to protected pages is determined server-side from the signed-in account and the recorded membership and role state.

Membership fees, invoices and documents

Membership fees and invoices are currently administered through a controlled manual workflow. The protected member area can display an authorised member's invoice records and a minimal protected PDF for eligible issued or paid invoices. Member-document and invoice metadata may be processed. General Storage uploads, broad downloads and online payment are not enabled.

Service providers and technical logs

VSDS uses service providers for the following bounded technical functions. Ordinary operational, authentication, access, audit and security logs may be generated for delivery, troubleshooting, abuse prevention and incident handling.

  • Supabase provides Auth, database and protected membership-processing functions, including sessions, applications, profiles, roles, invoices and document metadata. Processing locations may depend on the service configuration and subprocessors.
  • Vercel provides website hosting, deployment, server and request handling, and related technical logging.
  • Infomaniak supports domain and DNS administration and VSDS email, mailbox and communication services. Email or SMTP delivery may create message and delivery metadata.

Processing grounds, access and security

Under applicable Swiss data-protection law, processing takes place where necessary to provide requested registration and membership services, take steps concerning an application, administer an established membership relationship, meet legal and accounting duties, protect website and information-security interests, and handle communications. Consent is used only where a specific activity actually relies on it. Server-side sessions, Row Level Security and role controls restrict protected data; no service-role key is used in application runtime code.

Retention periods

The following periods express the approved VSDS retention policy. Until separately approved automation is implemented, retention may be enforced through controlled periodic manual review. Longer retention may apply for statutory duties, accounting requirements, legal claims, active disputes, security investigations, fraud prevention or legal holds:

  • Incomplete registration or abandoned application data: delete or anonymise after 90 days of inactivity.
  • Rejected or withdrawn membership applications: retain for 12 months after the rejection decision or withdrawal.
  • Disputed applications: retain until the dispute is resolved, plus 12 months.
  • Approved application source form: retain for 12 months after approval, then remove nonessential application-only information.
  • Member profile, membership category and membership status: retain during membership plus 12 months after it ends.
  • Invoices, membership fees, payment and accounting records: retain for 10 years from the end of the relevant financial year.
  • General contact and support correspondence: retain for 24 months after the matter is closed, unless it forms part of a legal or accounting record.
  • Ordinary authentication, security and access logs: retain for 90 days.
  • Security-incident records: retain for 12 months after incident closure, subject to legal holds and active investigations.
  • Privacy-consent and material administrative audit records: retain for the duration of the relevant relationship plus 3 years.
  • Completed access, correction or deletion request records: retain the minimum proof of handling for 3 years after completion.

Processing outside Switzerland

Some providers or their subprocessors may process personal data outside Switzerland. Depending on the destination and circumstances, safeguards may include a recognised adequacy decision, contractual safeguards or another mechanism permitted by applicable law. VSDS does not state that every provider-specific transfer assessment or contract review is complete.

Cookies, analytics and external services

Technically necessary cookies or equivalent local and session mechanisms may be used for authentication, security and session handling. The selected language is reflected in the localised route. VSDS does not currently use advertising tracking, marketing pixels, active analytics, newsletter tracking or nonessential consent cookies.

Your rights

Requests may be sent to info@vsds.ch. Rights depend on the applicable law and the circumstances of the request:

  • Request information about and access to personal data concerning you.
  • Request correction of inaccurate or incomplete information.
  • Request deletion where legally available; deletion is not absolute where accounting duties, legal claims, disputes, security investigations or legal holds require retention.
  • Request restriction of processing or object where applicable.
  • Withdraw consent for future processing where a particular activity relies on consent.
  • Contact the competent Swiss data-protection authority, including the Federal Data Protection and Information Commissioner, if you consider your data-protection rights infringed.

Functions not enabled

Online payment, card or TWINT checkout, automated membership decisions, newsletters, advertising, analytics, marketing tracking, public uploads and general file downloads are not enabled. Sanity does not supply the current public runtime content, and CMS rendering remains inactive.

Changes and questions

VSDS will update this notice when relevant functions, providers or data flows change. Questions about the current processing may be sent to info@vsds.ch.