Last updated: 27 July 2026
This privacy policy explains which personal data is processed in the operation of this working test application, for which purposes this happens, and which rights data subjects have.
Operation of the application
The technical provision and operation of this application are carried out by:
Simon Lüscher
Weiherstrasse 3
6275 Ballwil
Switzerland
Email: impressum@retriever-at-work.com
Event organiser
The data recorded for an event – registrations, participants, dogs, scores as well as helpers – is the responsibility of the respective organiser using this application. The organiser determines the purposes and means of that processing. In this respect the operator of the application acts as a processor within the meaning of Art. 9 FADP and Art. 28 GDPR, and processes that data solely on the organiser's instructions.
This installation is operated for: Swiss Working Retriever Club. Requests concerning event data should primarily be addressed to that organiser; they may also be sent to the contact address above and will be forwarded from there.
The operator is based in Switzerland. Processing is governed by the Swiss Federal Act on Data Protection (FADP) and its implementing ordinance. Where individuals in the European Union or the European Economic Area are affected and the processing falls within the scope of the General Data Protection Regulation (GDPR), the GDPR applies in addition. Where the two differ, the stricter requirement is applied.
No representative in the European Union pursuant to Art. 27 GDPR is currently designated. Requests from data subjects in the EU should be sent directly to the contact address above and are handled in the same way.
Depending on how the application is used, the following categories of personal data are processed:
Some of the data is collected directly from the data subjects, for example when creating an account, registering for a working test or volunteering as a helper. In addition, the organiser may enter participant, dog and judge data directly or import it from a registration list. In that case the data originates from the organiser or from the body that received the registration.
Processing takes place for the purposes below. Where the GDPR applies, the legal bases stated apply; under Swiss law, processing is based on the principles of Art. 6 FADP.
Providing the data marked as mandatory is necessary in order to take part. Without it, a registration cannot be processed. All other information is optional.
The application sets only one strictly necessary session cookie, which links a request to the current session and holds the login state and language choice within it. It cannot be read by JavaScript, is set with "SameSite=Strict" and, over encrypted connections, additionally as a "Secure" cookie, and expires when the browser is closed. No audience measurement, tracking or advertising takes place. This necessary cookie requires no consent under Art. 5(3) of EU Directive 2002/58/EC, which is why no cookie banner is shown.
When the application is accessed, the hosting provider logs the usual connection data, including IP address, timestamp, the address requested and the status code. In addition, the application stores the IP address and time of failed login attempts as well as sign-up and password reset requests in order to limit automated attacks. This data serves secure operation only, is not analysed to identify individuals, and is not combined with other data sources.
Personal data is neither sold nor disclosed for advertising purposes. Data is disclosed only to the following recipients:
Service providers that process personal data on our behalf are selected with care and contractually bound to comply with data protection requirements (processing on behalf under Art. 9 FADP and Art. 28 GDPR).
The application and the database are operated in a data centre in Europe. Switzerland and the European Economic Area mutually recognise each other as providing an adequate level of data protection. If data is disclosed beyond that to countries which do not ensure an adequate level of protection, this only happens on the basis of appropriate safeguards, in particular the European Commission's standard contractual clauses with the adaptations recognised by the FDPIC for Switzerland. When content is delivered via a content delivery network, the connection may for technical reasons be routed via a location outside Europe.
Personal data is retained only for as long as necessary for the stated purposes. The organiser keeps an event's registration, participant and result data for the running of the event and the subsequent documentation of the results, and deletes or anonymises it thereafter. Confirmation and password reset links expire after a short time and are invalidated once they expire or are used. Account data is kept until the account is deleted. Log data used for abuse prevention is only needed for the duration of the lockout. Statutory retention obligations remain reserved.
Start lists, rankings and certificates contain the participant's first name and surname, the dog and the results achieved. Within the application this information is accessible to the organiser's authorised personnel and, where provided for, to participants. Whether and in what form results are published beyond that – for example on a notice board, as a PDF or on a club website – is decided by the organiser, who is responsible for such publication.
Within the limits of applicable law, data subjects have the following rights:
An informal message to the contact address above is sufficient to exercise these rights. Proof of identity may be requested in order to prevent misuse. If the request concerns event data, it is forwarded to the responsible organiser. Requests are handled free of charge and within the statutory deadlines, under the GDPR generally within one month.
Irrespective of the above, there is a right to lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern. Individuals resident in the EU or EEA may contact the data protection authority of their place of residence, place of work or the place of the alleged infringement.
There is no solely automated decision-making in individual cases and no profiling within the meaning of Art. 21 FADP or Art. 22 GDPR. Rankings are calculated from the points awarded; the assessment itself is carried out by judges.
Data is transmitted encrypted via HTTPS. Passwords are stored solely as a cryptographic hash. Access to event data is restricted by role, the data of different organisers is kept in separate databases and separate sessions, and login attempts are rate-limited. Absolute security of data transmission over the internet cannot, however, be guaranteed.
This privacy policy may be amended to reflect changes in the legal framework or in the application. The version published on this page at any given time applies.