← Back to homeLegal

Privacy Policy

How we collect, use, and protect your personal data across the OFSET platform and services.

Data controller

OFSET, Genève, Switzerland

Contact / DPO

hello@ofset.ch

Applicable law

GDPR (EU) & FADP (Switzerland)

Last updated

20 July 2026

On this page
1

Introduction

This Privacy Policy describes how OFSET and its affiliates (collectively "OFSET", "we", "us", "our") collect, use, protect, and share personal data related to your use of our platform at ofset.ch (the "Platform") and associated services (the "Services").

It applies to all personal data we collect in the course of providing our Services — whether through the Platform, by phone, by email, or any other means of communication. Terms in this policy are interpreted in line with the data protection law that applies where you live, including the GDPR in Europe and the FADP in Switzerland.

2

Identity and Contact Details of Data Controllers

OFSET as data controller

For all personal data you provide directly, or that we collect through your use of the Platform, OFSET — registered office at Place Lise-Girardin 3, 1201 Genève, Switzerland — acts as data controller. We determine the purposes and means of processing, notably for booking management, improving the Platform, meeting our legal obligations, and managing our commercial relationship with you.

Providers as separate data controllers

In delivering the Services, we share your data with third-party providers — hotels, venues, transport companies, caterers — who carry out the services themselves. These providers act as separate, independent data controllers for their own services. We recommend reviewing their own privacy policies.

3

Categories of Personal Data We Collect

Automatically collected data

IP address, browser and operating system, pages viewed, approximate location, device identifiers.

Data you provide directly

Title, first and last name, job title, employer, professional email and phone, account credentials, booking history, payment data (handled via a PCI-DSS compliant provider), the content of your communications with us, and any specific requirements for event participants.

SMS / text data

If you opt in to SMS updates, we use your number solely to deliver those messages — never to sell to third parties.

Social login data

Authentication data when you sign in via Google or Microsoft Azure.

Recordings

Call recordings or chat transcripts, only with your consent.

Third-party sources

Publicly available professional information, e.g. from B2B databases.

4

Purposes & Legal Basis for Processing

Account creation & bookings

Performance of a contract — retained 3 years after your last event.

Customer support

Performance of a contract / legitimate interest — retained 3 years.

Marketing & B2B prospecting

Consent / legitimate interest — retained 3 years.

Platform improvement & analytics

Legitimate interest — analytics data retained for a maximum of 13 months.

Specific needs (e.g. accessibility)

Legitimate interest / legal obligation — retained 6 months after the event.

Swiss accounting obligations

Legal obligation — retained 10 years under the Swiss Code of Obligations.

5

Who We Share Your Data With

Your data is shared within OFSET, with our technical processors (including AWS, Google, Microsoft, Stripe, and HubSpot), with the event service providers delivering your event (venues, caterers), and with public authorities where the law requires it. Every processor we work with is bound by a strict data processing agreement.

6

Transfers Outside the EU/Switzerland

Your data is stored primarily in Switzerland or the EU. Where a transfer outside these regions is necessary (for example, to the United States), we put appropriate safeguards in place — Standard Contractual Clauses, or reliance on the Swiss-U.S. Data Privacy Framework.

7

How Long We Keep Your Data

We keep your data only for as long as it's needed for the purpose it was collected for — moving it from active use, to intermediate archiving, to deletion or anonymization. Section 4 above sets out the specific retention period for each purpose.

8

Your Rights

You have the right to access, correct, delete, restrict, or object to the processing of your data, and the right to data portability. To exercise any of these rights, contact us at hello@ofset.ch or by post.

9

How We Protect Your Data

Encryption

Data in transit and at rest is protected with TLS 1.3 and AES-256.

Access control

Role-based access, with multi-factor authentication (MFA) for our team.

Regular testing

Ongoing security testing of our systems and processes.

Breach notification

If a breach occurs, we notify the relevant authorities and you, in line with the level of risk involved.

10

Cookies

We use essential cookies to run the Platform, and only use non-essential cookies (e.g. analytics) with your consent, which you can withdraw at any time.

11

Minors

Our Services are B2B and are not intended for, or directed at, individuals under the age of 18.

12

Changes to This Policy

We may update this Privacy Policy from time to time. We'll notify you of material changes via the Platform.

13

Data Protection Officer

Email: hello@ofset.ch

Post: OFSET, Attn: DPO, Place Lise-Girardin 3, 1201 Genève, Switzerland

14

Jurisdiction-Specific Provisions

Switzerland

References to the GDPR in this policy should be read as references to the Swiss Federal Act on Data Protection (FADP). Transfers of data to the United States are governed by the Swiss-U.S. Data Privacy Framework.