Privacy policy
This policy explains which personal data Tessara processes, why, and what rights you have under the revised Swiss Federal Act on Data Protection (revFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Controller
The controller responsible for the data processing described in this policy is [PLACEHOLDER - LEGAL ENTITY], [PLACEHOLDER - ADDRESS], reachable at support@tessara.ch. See the Imprint for full details once finalised.
2. What data we process
Depending on how you use the Platform, we process the following categories of personal data:
- Account data: name, e-mail address, password hash, account type (company or leader), account status.
- Leader profile data: professional experience, headline, biography, references, languages, availability and, if provided, a CV file and LinkedIn profile. CVs are stored privately and are never publicly visible.
- Company data: company name, industry, size, location, logo, and the leadership needs a company posts.
- Payment metadata: billing name, address and VAT number where provided, and the status/amount of a contact-unlock payment. Card and bank details are processed solely by our payment provider (Stripe) and never reach our own systems.
- Usage data: pages visited, features used and coarse product-analytics events, collected without directly identifying content such as names, e-mail addresses or CVs (see section 8, Cookies).
3. Purposes of processing
- Operating the marketplace: account management, publishing and verifying profiles, matching, contact requests and the contact-unlock mechanism.
- Processing payments for the unlock fee and preventing fraud or abuse of the fee mechanism.
- Communication: transactional e-mails (confirmations, match and payment notifications, reminders) and, where you have opted in, product updates.
- Security and platform integrity: rate limiting, abuse detection, and maintaining audit trails for verification and payment events.
- Product improvement: aggregated, non-identifying usage analytics to understand how the Platform is used.
4. Legal bases
Where the GDPR applies (e.g. to visitors in the EU/EEA), we rely on: performance of a contract (Art. 6(1)(b) GDPR) for account and marketplace functions; legitimate interest (Art. 6(1)(f) GDPR) for security, fraud prevention and baseline product analytics; and consent (Art. 6(1)(a) GDPR) for optional communications and non-essential analytics, where required. Under the revFADP, processing is generally permitted unless it unlawfully infringes a data subject's personality, and we process personal data only for the purposes stated above and disclosed to you at the time of collection.
5. Processors and locations
We use the following processors to operate the Platform. Each is bound by a data processing agreement and, where data leaves Switzerland or the EU/EEA, appropriate safeguards (such as the EU Standard Contractual Clauses) are used.
- Supabase (database, authentication and file storage): infrastructure hosted on Amazon Web Services (AWS), region [PLACEHOLDER - CONFIRM REGION, e.g. eu-central-1/Frankfurt].
- Vercel (application hosting and content delivery): global edge network; primary application region [PLACEHOLDER - CONFIRM REGION].
- Stripe (payment processing for the contact-unlock fee): Stripe Payments Europe, Limited (Ireland) / Stripe, Inc., depending on your location.
- Resend (transactional e-mail delivery).
- PostHog (product analytics), EU-hosted instance (eu.i.posthog.com), configured to avoid collecting names, e-mail addresses, CVs or other directly identifying content.
6. Retention
We retain personal data for as long as your account is active and as necessary to fulfil the purposes above, in particular ongoing statutory retention obligations for payment-related records (typically up to 10 years under Swiss commercial and tax law). Where an account is deleted, we anonymise or erase data that is not subject to a retention obligation. [PLACEHOLDER - precise per-category retention periods, once the deletion/export process (docs/11-security.md §5) is finalised.]
7. Your rights
Subject to applicable law, you have the right to request access to your personal data, correction of inaccurate data, deletion of your data, and a copy of your data in a portable format. You may also object to certain processing based on legitimate interest and withdraw consent where processing is based on consent.
To exercise any of these rights, contact support@tessara.ch. Requests for deletion or data export are currently handled manually by our support team while a fully self-service process is being built; we aim to respond within 30 days.
8. Cookies
We use technically necessary cookies for login and session management, and, where enabled, PostHog analytics cookies to understand product usage. We do not use advertising cookies or third-party ad trackers. See the Cookie Policy for details.
9. Data security
We apply technical and organisational measures appropriate to the risk, including row-level security policies at the database level, private (non-public) file storage for CVs and other sensitive documents with access only via short-lived signed URLs, and security headers and rate limiting on the Platform (see docs/11-security.md for the internal technical documentation).
10. Changes to this policy
We may update this policy from time to time to reflect changes to our processing activities or legal requirements. Material changes will be communicated on the Platform.
11. Contact for data protection matters
For any question about this policy or the processing of your personal data, contact support@tessara.ch.