Privacy Policy
Last updated: 4 September 2026
This policy describes every kind of personal data ventranet.ch handles, why we handle it, who else sees it and when it gets deleted. It is written to be checked rather than admired: where a number appears, that number is the one the software actually uses.
It follows the Swiss Federal Act on Data Protection (FADP, revised version in force since 1 September 2023) and, for visitors and customers in the European Economic Area, the General Data Protection Regulation.
1. Who is responsible
The controller for the processing described here is:
Feuz Institute, c/o Regus, Hagenholzstrasse 56, 8050 Zürich, Switzerland
CHE-338.930.920 · Managing director: Silvano C. Feuz
Email: admin@ventranet.ch · Phone: +41 76 517 88 94
We are not required to appoint a data protection officer and have not appointed one. Data protection requests go to the address above and are handled by the managing director personally.
2. The short version
The full document follows. If you only read one section, read this one.
- Our analytics are our own and run on our own infrastructure. There is no Google Analytics, no Meta pixel, no advertising network and no cross-site tracking on this site.
- We have never sold personal data and we will not. Nothing here is shared with advertisers or data brokers.
- Before you consent, we count visits without any cookie and without any identifier that could recognise you. After you consent, we additionally record a pseudonymous visitor ID, clicks and a replay of your interactions on the page.
- All analytics data is deleted automatically after 365 days. Not anonymised — deleted.
- We never record what you type. Form fields and keystrokes are excluded from session recordings by design.
- The site publishes the names and photographs of event speakers, taken from public announcements. Section 11 explains this and how to have yours removed.
- One email to admin@ventranet.ch gets you a copy of your data, a correction, or deletion. No form, no account required.
3. What this policy covers
It covers ventranet.ch and its subdomains, the newsletter, the support form, the Ventracard and the sign-in. It does not cover the websites of event organisers we link to. When you follow a registration link you are on their site, under their policy, and we have no visibility into what happens there.
“Personal data” means information relating to an identified or identifiable person. That includes data that identifies you only indirectly, such as a pseudonymous visitor ID. It does not include figures that have been aggregated to the point where no individual can be picked out of them.
4. Visiting the website
We run our own analytics. The data is processed on our own infrastructure and is never passed to advertising networks, data brokers or third-party tracking services. There are two tiers, and the difference between them is your consent.
4.1 Anonymous baseline: always active, no cookie, no identifier
Without setting any cookie and without any identifier that could recognise you across visits, we record aggregate information about how the site is used: which pages were opened, how long a page was in view, how far it was scrolled, the approximate device type, browser, operating system, browser language, and the referring website.
A short-lived random session identifier is kept in your browser’s session storage so that several page views in one sitting can be counted as one visit. It is discarded when you close the tab, is never written to a cookie, and cannot connect one visit to another.
The legal basis is our legitimate interest in operating and improving the site (Art. 6(1)(f) GDPR), and under the FADP the processing is proportionate and recognisable to you from this policy. You can object at any time by writing to admin@ventranet.ch.
4.2 Detailed analytics: only after you accept
If you choose “Accept all” in the banner, we additionally collect:
- a pseudonymous visitor ID stored in a cookie, so that we can tell a returning reader from a new one;
- clicks and their position on the page, aggregated into anonymous heatmaps that show which parts of a page get attention;
- which events you open, how long you spend on them, and which outbound links you use, whether registration, tickets or the organiser website;
- the steps you take through the Ventracard purchase, so that we can see where people give up;
- a pseudonymous recording of your visit: mouse movement, clicks, scrolling and page changes, replayed to find usability problems.
If you choose “Anonymous only”, none of this happens and only section 4.1 continues. The legal basis for this tier is your consent, Art. 6(1)(a) GDPR and Art. 6 FADP. You can withdraw it at any time through the Cookie Settings link in the footer; withdrawal deletes the visitor ID cookie and stops the collection, and does not affect what was lawfully collected beforehand.
4.3 What session recordings do not capture
A recording is a reconstruction of interaction, not a video of your screen and not a copy of what is on it. We do not record keystrokes. We do not record the contents of any form field, including the newsletter field, the support form and the Ventracard editor. We do not capture passwords, payment details or anything you type anywhere.
A recording is linked to a pseudonymous visitor ID, not to your name. If you later give us your email address for something else, we do not join the two.
4.4 What we do not do at all
- No advertising or retargeting pixels, from anyone.
- No third-party analytics services.
- No device fingerprinting or probabilistic identification.
- No tracking of you across other websites.
- No sale, rental or sharing of personal data for anyone else’s purposes.
- No profiling that produces a decision about you. See section 18.
5. Cookies and local storage
The table below is the complete list of what this site stores on your device. Some entries are cookies; others are local or session storage, which never leaves your browser and is not sent to us with requests. They are listed together because from where you sit the distinction hardly matters.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| vn_consent | Cookie + local storage | Remembers your choice in the consent banner, so you are not asked again on every page. | 1 year |
| vn_vid | Cookie | Pseudonymous visitor ID. Distinguishes new from returning readers. Set only after you accept. | 1 year, deleted when you withdraw consent |
| vn_sid | Session storage | Random ID that ties several page views into one visit. No cookie, never persistent. | Until the tab is closed |
| ventranet_saved_events | Local storage | The events you marked with the save button. Stays on your device; we never receive it. | Until you clear it |
| vn_preloaded_* | Session storage | Notes that the intro animation has already played, so it does not replay on every page. | Until the tab is closed |
| vn_optout | Cookie | Excludes a device from analytics entirely. Set on our own devices so our work does not distort the figures; also available to you on request. | 1 year |
There are no third-party cookies on this site. You can delete all of it at any time in your browser settings. The site keeps working; it will simply ask about consent again and forget your saved events.
6. Server logs and abuse prevention
Our hosting provider, Vercel, keeps short-lived operational logs of requests, which can include IP addresses. That is standard infrastructure logging without which a server cannot be run or an outage diagnosed. It rests on our legitimate interest in the security and availability of the site.
Our own code uses your IP address for one purpose: a rate limit on the public forms, so that a script cannot fire a thousand newsletter sign-ups or checkout attempts. The address is held in memory only, for the length of the time window, and is never written to our database. When the server instance ends, it is gone.
8. Support requests
The support form asks for your name, your email address, optionally which event your question concerns, and the question itself. We use it to answer you. A notification is sent to our own inbox so that a message does not sit unread.
The legal basis is our legitimate interest in answering people who write to us, and, where your message concerns a purchase, the performance of that contract. Please do not put health data, financial details or other sensitive information into the form. It is not the right channel for it.
9. The Ventracard
When you buy a Ventracard we handle the following:
- Your email address, so that we can deliver the card and reach you about it.
- What you put on the card: name, headline, LinkedIn profile URL and, if you upload one, a photograph.
- Payment, which Stripe handles entirely. We store the Stripe session identifier and whether payment succeeded. We never receive or store your card number, expiry date or security code.
Your photograph is stored on Vercel Blob storage. The QR code is not stored anywhere: it is recalculated from your LinkedIn URL each time it is needed, so a change to the URL can never leave a stale code behind.
Your card page is publicly reachable by its address, because a card you cannot show someone is not a card. The address contains sixteen random characters, we never publish or link it, and the page carries a noindex, nofollow instruction so search engines leave it out of their results. Anyone you give the link to can open it, which is the point.
If you add the card to Apple Wallet, the pass is generated by us and signed with our Apple developer certificate. Apple receives no data from us about you in the process.
The legal basis is the performance of your purchase contract, Art. 6(1)(b) GDPR. Business records connected to the sale are kept for the ten years Swiss commercial law requires; see section 15.
10. Accounts and sign-in
Signing in works by a link sent to your email address, not by a password. To make that work we store your email address, the times you signed in, and a session record that keeps you signed in between page loads. Sign-in emails are delivered by Resend.
Where a subscription is attached to your account, we also store its status and period, so the software knows what you are entitled to. The legal basis is the performance of the contract and, for the sign-in mechanism itself, our legitimate interest in a login that does not depend on a password you might reuse.
11. Speakers, hosts and organisers
This is the section that concerns people who never visited the site. Event pages name the speakers and organisers, state their role and employer, and often show a photograph. If you are one of them, here is exactly where that came from and what you can do about it.
11.1 What we publish and where it comes from
Name, a single line giving role and employer, a photograph, and the fact that you are appearing at a particular event. It is taken from the organiser’s own public announcement of the event, from your public professional profile, or from material an organiser sent us for publication.
We publish it to describe an event that has already been announced publicly, and we do not go looking for anything that is not already part of that announcement. Private addresses, private contact details and anything not connected to the professional appearance have no place here and are not collected.
11.2 The legal basis, stated plainly
Our legitimate interest in reporting accurately on publicly announced professional events, and the public’s interest in knowing who is speaking at them (Art. 6(1)(f) GDPR; Art. 31 FADP). We have weighed that against your interests: the data is professional rather than private, it was already public, the volume is small, and it is used for nothing but describing the event. We consider the balance to fall in favour of publication — and if you disagree, section 11.3 is not a negotiation.
11.3 Having it removed
Write to admin@ventranet.ch with the page and what you want changed. We will correct it or remove it. You do not have to give a reason, you do not have to prove anything, and we will not ask you to justify the request. We aim to act within a few working days.
You also have the rights in section 17, including the right to object under Art. 21 GDPR. This paragraph exists so you do not have to invoke any of them to be taken seriously.
11.4 Cover images are illustrations, not photographs
The image at the top of an event page is generated by an AI model in the site’s visual style. It is not a photograph of the venue, the event or anyone attending, and no real person is depicted. We do not generate portraits of speakers. Speaker photographs are real photographs, sourced as described in 11.1.
12. Where we use AI
Two AI services are involved in producing the site. Neither of them ever receives data about visitors, customers, newsletter subscribers or support requests.
- Google Gemini reads event announcements — page content and screenshots of public event pages — and extracts the structured details we then check by hand: title, date, venue, price, speakers. Where an announcement names a speaker, that name passes through this step.
- OpenAI generates the cover illustrations described in 11.4, from a text prompt about the event. No personal data and no photograph is sent for this.
Both process the data on our instruction for that single purpose. Output is reviewed by a person before anything is published, and no AI system makes a decision about any individual. Both are US providers; section 14 covers what that means.
13. Who else sees your data
We use the providers below to run the service. Each processes data only on our instructions and for the stated purpose, under a data processing agreement. There is no other recipient. We do not share data with advertisers, data brokers or partners.
| Provider | What it does | What it sees | Where |
|---|---|---|---|
| Vercel Inc. | Hosting, CDN, file storage for uploaded images | Request logs including IP addresses; uploaded Ventracard photos | EU / USA |
| Neon Inc. | PostgreSQL database | Everything we store: subscribers, support requests, orders, analytics | EU |
| Stripe, Inc. | Payment processing for the Ventracard | Your payment details, email address, purchase amount | EU / USA |
| Resend | Delivery of sign-in emails | Your email address and the message | EU / USA |
| Our email provider | Newsletter and notification delivery over our own SMTP account | Recipient address and message | EU / Switzerland |
| Google (Gemini API) | Extracting event details from public announcements | Public event page content; speaker names where announced | USA |
| OpenAI | Generating cover illustrations | A text prompt about the event. No personal data | USA |
| Apple Inc. | Wallet pass format and signing certificate | Nothing about you is sent to Apple by us | USA |
Beyond these, we disclose data only where the law obliges us to — a court order, a criminal investigation, a binding request from a competent authority — or where it is necessary to establish or defend a legal claim.
14. Transfers outside Switzerland and the EEA
Some of the providers above are based in the United States or may process data there. Those transfers are covered by the European Commission’s Standard Contractual Clauses, by the EU-US Data Privacy Framework where the provider is certified under it, and by the equivalent recognition under Swiss law.
You may request a copy of the safeguards that apply to a specific transfer by writing to admin@ventranet.ch.
15. How long we keep things
| Data | Kept for | Why that long |
|---|---|---|
| Analytics, heatmaps and session recordings | 365 days, then deleted automatically | A year covers a full seasonal cycle of events. Beyond that the data answers no question we still have. |
| Newsletter address and preferences | Until you ask us to stop | Deleted on request, not flagged and retained. |
| Support requests | 24 months after the matter is closed | Long enough to recognise a recurring problem and to reconstruct what was agreed. |
| Ventracard: the card itself | While the card is active | Deleted when you ask us to take it down. |
| Ventracard: sale records | 10 years | Swiss commercial law requires business records to be kept for ten years (Art. 958f CO). This is an obligation, not a choice. |
| Account and sign-in records | While the account exists, then 90 days | The short tail allows a mistaken deletion to be undone. |
| Speaker and organiser details | While the event page is published | Removed sooner on request; see 11.3. |
16. Legal bases
Under the GDPR, each processing operation rests on one of the following.
| Processing | Basis |
|---|---|
| Anonymous baseline measurement | Legitimate interest, Art. 6(1)(f) |
| Detailed analytics and session recordings | Consent, Art. 6(1)(a) |
| Newsletter | Consent, Art. 6(1)(a) |
| Support requests | Legitimate interest, Art. 6(1)(f); contract where applicable |
| Ventracard purchase and delivery | Contract, Art. 6(1)(b) |
| Keeping sale records for ten years | Legal obligation, Art. 6(1)(c) |
| Accounts and sign-in | Contract, Art. 6(1)(b) |
| Rate limiting and security | Legitimate interest, Art. 6(1)(f) |
| Publishing speaker and organiser details | Legitimate interest, Art. 6(1)(f) |
Under the FADP the corresponding requirements are proportionality, recognisability and good faith, which this document is intended to satisfy by describing the processing rather than gesturing at it.
17. Your rights
You have the right to:
- Know what we hold and receive a copy of it, together with an explanation of what we do with it;
- Correct it if it is wrong or incomplete;
- Have it deleted, except where we are legally required to keep it, such as the ten-year record of a sale;
- Restrict processing while a dispute about accuracy or lawfulness is resolved;
- Object to processing based on legitimate interest, including publication of your details as a speaker;
- Receive your data in a structured, machine-readable format and have it sent to another controller where that is technically feasible;
- Withdraw consent at any time, with effect for the future, without affecting what was lawfully processed before;
- Complain to a supervisory authority. See section 22.
To exercise any of them, write to admin@ventranet.ch. There is no form and no account required. We answer within 30 days and usually much sooner. We may ask a question to confirm who you are, which protects you rather than us: we are not going to hand your data to someone who merely claims to be you.
Exercising these rights is free, and doing so has no consequence for you here.
18. No automated decisions about you
We do not carry out automated decision-making that produces legal effects for you or similarly significantly affects you, within the meaning of Art. 22 GDPR and Art. 21 FADP.
Newsletter personalisation filters which events you are sent according to the preferences you set yourself. It is a filter you control, it decides nothing about you, and it has no consequence beyond the contents of an email.
19. Security
The site is served over HTTPS only, with HSTS, so a browser will not fall back to an unencrypted connection. Access to the backoffice is restricted and its sessions are protected by signed tokens. Public forms are rate-limited and validate their input. Passwords, keys and certificates are held as environment secrets and never appear in the codebase.
No system is perfectly secure, and we do not claim otherwise. If you find a vulnerability, please tell us at admin@ventranet.ch before telling anyone else. We will take it seriously and we will not respond with lawyers.
20. Children
The site is intended for people aged 16 and over and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to admin@ventranet.ch and we will delete it.
21. Changes to this policy
We update this policy when what the site does changes. The date at the top is set by hand and states when the current version took effect; it is not the date you happen to be reading, which is how it used to work and was worse than useless.
Where a change materially affects how we handle data we already hold, we will say so prominently, and where the law requires consent for the change, we will ask for it rather than assume it.
22. Contact and supervisory authorities
Feuz Institute, c/o Regus, Hagenholzstrasse 56, 8050 Zürich, Switzerland.
Email: admin@ventranet.ch · Phone: +41 76 517 88 94
If we do not resolve your concern, you can complain to a supervisory authority. In Switzerland that is the Federal Data Protection and Information Commissioner (FDPIC) in Bern. In the EEA it is the data protection authority of the country where you live, where you work, or where the issue arose.
We would rather hear from you first. A complaint to an authority takes months; an email to admin@ventranet.ch usually takes a day. Your right to go to the authority is not affected either way, and you do not need our agreement to use it.
The terms that govern use of the site are on the Terms of Service page.