Working-Test-App

Privacy Policy

Last updated: 27 July 2026

This privacy policy explains which personal data is processed in the operation of this working test application, for which purposes this happens, and which rights data subjects have.

Controllers

Operation of the application

The technical provision and operation of this application are carried out by:

Simon Lüscher

Weiherstrasse 3

6275 Ballwil

Switzerland

Email: impressum@retriever-at-work.com

Event organiser

The data recorded for an event – registrations, participants, dogs, scores as well as helpers – is the responsibility of the respective organiser using this application. The organiser determines the purposes and means of that processing. In this respect the operator of the application acts as a processor within the meaning of Art. 9 FADP and Art. 28 GDPR, and processes that data solely on the organiser's instructions.

This installation is operated for: Swiss Working Retriever Club. Requests concerning event data should primarily be addressed to that organiser; they may also be sent to the contact address above and will be forwarded from there.

Scope and applicable law

The operator is based in Switzerland. Processing is governed by the Swiss Federal Act on Data Protection (FADP) and its implementing ordinance. Where individuals in the European Union or the European Economic Area are affected and the processing falls within the scope of the General Data Protection Regulation (GDPR), the GDPR applies in addition. Where the two differ, the stricter requirement is applied.

Representation

No representative in the European Union pursuant to Art. 27 GDPR is currently designated. Requests from data subjects in the EU should be sent directly to the contact address above and are handled in the same way.

Data processed

Depending on how the application is used, the following categories of personal data are processed:

  • Account data: username, email address, password (stored solely as a cryptographic hash), role and the time the account was created.
  • Master and contact data: first name, surname, street, postcode, town, country, phone number and email address.
  • Dog data: call name, breed, sex, date of birth, microchip number and pedigree number. Via the handler, this information can be linked to a specific individual.
  • Registration data: the selected working test, class, bib number, team membership, remarks as well as information on helper duty including any reason given for declining.
  • Result data: scores for individual exercises, total points, rankings, run-off results, qualifications and the details shown on certificates.
  • Technical data: IP address and time of failed login attempts, sign-ups and password reset requests, as well as the hosting provider's standard connection logs.
  • Session data: login state and the selected display language, held in the server-side session.
Source of the data

Some of the data is collected directly from the data subjects, for example when creating an account, registering for a working test or volunteering as a helper. In addition, the organiser may enter participant, dog and judge data directly or import it from a registration list. In that case the data originates from the organiser or from the body that received the registration.

Purposes and legal bases

Processing takes place for the purposes below. Where the GDPR applies, the legal bases stated apply; under Swiss law, processing is based on the principles of Art. 6 FADP.

  • Running the event: registration, start lists, scoring, rankings and certificates. Legal basis: contract or pre-contractual measures (Art. 6(1)(b) GDPR).
  • Managing user accounts: sign-up, login, password reset and management of one's own dogs. Legal basis: contract (Art. 6(1)(b) GDPR).
  • Communication by email: sign-up confirmation, password reset and event-related messages. Legal basis: contract or legitimate interest (Art. 6(1)(b) and (f) GDPR).
  • Security and abuse prevention: limiting failed login attempts, protecting public forms against automated submissions, and traceability of security-relevant events. Legal basis: legitimate interest in secure operation (Art. 6(1)(f) GDPR).
  • Optional information: data beyond what is required for participation, such as volunteering as a helper or free-text remarks. Legal basis: consent (Art. 6(1)(a) GDPR), which may be withdrawn at any time.
  • Compliance with legal requirements, insofar as statutory retention, disclosure or reporting obligations exist. Legal basis: legal obligation (Art. 6(1)(c) GDPR).

Providing the data marked as mandatory is necessary in order to take part. Without it, a registration cannot be processed. All other information is optional.

Cookies and local storage

The application sets only one strictly necessary session cookie, which links a request to the current session and holds the login state and language choice within it. It cannot be read by JavaScript, is set with "SameSite=Strict" and, over encrypted connections, additionally as a "Secure" cookie, and expires when the browser is closed. No audience measurement, tracking or advertising takes place. This necessary cookie requires no consent under Art. 5(3) of EU Directive 2002/58/EC, which is why no cookie banner is shown.

Connection logs and abuse prevention

When the application is accessed, the hosting provider logs the usual connection data, including IP address, timestamp, the address requested and the status code. In addition, the application stores the IP address and time of failed login attempts as well as sign-up and password reset requests in order to limit automated attacks. This data serves secure operation only, is not analysed to identify individuals, and is not combined with other data sources.

Recipients and processors

Personal data is neither sold nor disclosed for advertising purposes. Data is disclosed only to the following recipients:

  • the organiser and the people it appoints, such as administrators, judges and station staff, insofar as this is necessary to run the event;
  • the hosting provider on whose servers the application and the database are operated: Hetzner Online GmbH, Deutschland;
  • the email service provider used to send outgoing messages; the recipient address, subject and message content are transmitted;
  • the content delivery network jsDelivr (operated by Prospect One, Poland, with delivery servers distributed worldwide), from which the icon font used is loaded. The device's IP address is transmitted to that network, which is technically necessary for delivery;
  • authorities and courts, insofar as there is a legal obligation to disclose.

Service providers that process personal data on our behalf are selected with care and contractually bound to comply with data protection requirements (processing on behalf under Art. 9 FADP and Art. 28 GDPR).

Disclosure abroad

The application and the database are operated in a data centre in Europe. Switzerland and the European Economic Area mutually recognise each other as providing an adequate level of data protection. If data is disclosed beyond that to countries which do not ensure an adequate level of protection, this only happens on the basis of appropriate safeguards, in particular the European Commission's standard contractual clauses with the adaptations recognised by the FDPIC for Switzerland. When content is delivered via a content delivery network, the connection may for technical reasons be routed via a location outside Europe.

Retention and deletion

Personal data is retained only for as long as necessary for the stated purposes. The organiser keeps an event's registration, participant and result data for the running of the event and the subsequent documentation of the results, and deletes or anonymises it thereafter. Confirmation and password reset links expire after a short time and are invalidated once they expire or are used. Account data is kept until the account is deleted. Log data used for abuse prevention is only needed for the duration of the lockout. Statutory retention obligations remain reserved.

Results and publication

Start lists, rankings and certificates contain the participant's first name and surname, the dog and the results achieved. Within the application this information is accessible to the organiser's authorised personnel and, where provided for, to participants. Whether and in what form results are published beyond that – for example on a notice board, as a PDF or on a club website – is decided by the organiser, who is responsible for such publication.

Rights of data subjects

Within the limits of applicable law, data subjects have the following rights:

  • access to the personal data processed (Art. 25 FADP, Art. 15 GDPR);
  • rectification of inaccurate or incomplete data (Art. 32 FADP, Art. 16 GDPR);
  • erasure of the data (Art. 32 FADP, Art. 17 GDPR);
  • restriction of processing (Art. 18 GDPR);
  • release or transfer of the data in a common electronic format (Art. 28 FADP, Art. 20 GDPR);
  • objection to processing based on a legitimate interest (Art. 30 FADP, Art. 21 GDPR);
  • withdrawal of consent with effect for the future; the lawfulness of processing carried out until then remains unaffected (Art. 7(3) GDPR).

An informal message to the contact address above is sufficient to exercise these rights. Proof of identity may be requested in order to prevent misuse. If the request concerns event data, it is forwarded to the responsible organiser. Requests are handled free of charge and within the statutory deadlines, under the GDPR generally within one month.

Right to lodge a complaint

Irrespective of the above, there is a right to lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern. Individuals resident in the EU or EEA may contact the data protection authority of their place of residence, place of work or the place of the alleged infringement.

No automated decision-making

There is no solely automated decision-making in individual cases and no profiling within the meaning of Art. 21 FADP or Art. 22 GDPR. Rankings are calculated from the points awarded; the assessment itself is carried out by judges.

Data security

Data is transmitted encrypted via HTTPS. Passwords are stored solely as a cryptographic hash. Access to event data is restricted by role, the data of different organisers is kept in separate databases and separate sessions, and login attempts are rate-limited. Absolute security of data transmission over the internet cannot, however, be guaranteed.

Changes to this privacy policy

This privacy policy may be amended to reflect changes in the legal framework or in the application. The version published on this page at any given time applies.

Legal notice

Back