In short
- We are webinaire.ch, an agency based in Lausanne. Any question? Write to contact@webinaire.ch.
- The website measures our ads with the Meta pixel and the LinkedIn tag. They set cookies as soon as you arrive.
- When you book a call, your details go into our CRM. We use them to prepare the call and to follow up.
- On live.webinaire.ch, the webinar organiser decides about your data. If it's one of our clients, we process it on their behalf.
- Our providers are mostly in the United States and the European Union. We put safeguards on these transfers.
- You can access, correct or delete your data. One email is enough.
1. Who is responsible
The controller is webinaire.ch, 1005 Lausanne, Switzerland. You can reach us at contact@webinaire.ch.
We follow the Swiss Federal Act on Data Protection (FADP). If you live in the European Union, the General Data Protection Regulation (GDPR) applies too. This page gives you the information required by Article 19 FADP and Article 13 GDPR.
We have not appointed a data protection officer. Write directly to the address above.
On the live.webinaire.ch platform, our role depends on who organises the webinar. Section 3 explains it.
2. On the webinaire.ch website
Your visit
Our host, Vercel, keeps a technical log of every visit: IP address, browser, page requested, date and time. This log keeps the site running and protects it. We don't use it to identify you.
Measuring our ads
The website loads the Meta pixel (Facebook, Instagram) and the LinkedIn Insight Tag. They tell us that a page was viewed and whether the visit came from one of our ads. Meta and LinkedIn also use them to show our ads to the right people and to measure the results. These tools set cookies, listed in section 8.
The questionnaire on our booking page
Our ads lead to a five-question questionnaire: what you sell, the price of your offer, your audience, your revenue and your ad budget. We don't ask for your name or email at this step.
At the end, the questionnaire decides on its own whether to show our calendar. If it doesn't and you disagree, write to us. Someone from the team will look at your situation.
A summary of your answers lands in the team's internal messaging (Telegram). The result also goes to Meta, with your IP address, your browser and the Meta cookie identifiers. If the questionnaire concludes we're not the right fit, we use it to stop showing you our ads.
Booking a call
Our calendar comes from Cal.com. It appears on the home page, on the booking page and after the questionnaire. As soon as it appears, your browser connects to Cal.com's servers, even if you don't book.
When you book, you give us your name, your email and, depending on the form, your phone number and your answers. We add the page you came from, the questionnaire summary, the ad click identifier, and your Instagram or LinkedIn handle if you arrived through one of our messages.
This data goes into our CRM, hosted by Notion. If writing to the CRM fails, the team gets your name and contact details in a Telegram alert, so the booking isn't lost. We also report the booking to Meta and LinkedIn to measure our ads. Meta receives your email, phone number and name in hashed form, meaning turned into an unreadable fingerprint, along with the Meta cookie identifiers. LinkedIn receives your hashed email and your name.
The call
Our calls take place on Google Meet. With your consent, asked at the start of the call, we transcribe it with Tactiq. The text goes through Zapier into your record in our CRM. Claude, Anthropic's AI, turns it into a summary: your context, your needs, your objections, your budget, the next step and our view of the fit. If you say no, we don't transcribe anything.
If we messaged you
We reach out to creators and entrepreneurs by direct message on Instagram and LinkedIn. In that case, our CRM keeps your name, your public handle, the status of our conversation and our follow-up dates. This comes from your public profile and our messages. Tell us you don't want to hear from us, and we stop.
Your emails
If you write to us, your message and contact details are kept in our Google Workspace mailbox.
3. On the live.webinaire.ch platform
live.webinaire.ch is our webinar platform. We use it for our own webinars and for our clients' webinars. Other organisers, called hosts, can also use it to run their own webinars.
Who decides about your data
- You have a host account. webinaire.ch is the controller for your account data.
- You register for a webinar organised by webinaire.ch. We are the controller.
- You register for a host's webinar, one of our clients for example. The host is the controller. We process your data on their behalf and under their instructions, as a processor. Their own privacy policy applies. Contact them first.
Host accounts
To open and run an account, we process your name, your email, your password (stored in hashed form), your organisation and your team members. We also keep your webinar content: videos, images, offers, speakers' names and photos, and the keys of the tools you connect. For your emails, you can set the sender name, the address that receives replies and your own sending domain.
If you ask for a new password, we keep an unreadable fingerprint of the link we send and the IP address of the request, to limit abuse. These traces are deleted after one day.
Registrants and viewers
When you register for a webinar, the platform processes:
- your first name and email, and depending on the form your last name, phone number, country and any fields the host added
- where you came from, read from the registration link (UTM parameters)
- your attendance at the live or the replay: arrival, departure, duration and device type
- your chat messages, questions, reactions, and your answers to polls and quizzes
- your clicks on the offers and resources shown
- your purchases, when the host's shop sends them to us (Stripe, Shopify or another tool): email, name, product and amount
From these signals, the platform computes an engagement score. It helps the organiser know who to follow up with. The platform makes no decision about you based on it.
Your chat messages are visible to other participants, with the name you gave. They can show up again in the replay, at the moment you sent them. Viewers are never filmed. Only the host's broadcast is recorded, for the replay.
Platform emails
The organiser chooses their webinar's emails. By default, you get the registration confirmation, a reminder the day before, a reminder one hour before, a message when the live starts and the replay link. The organiser can edit them, remove some and write others, for example after the live ends. They can keep some for people who watched, or for people who didn't. The platform keeps a list of the emails sent.
Every email has a one-click unsubscribe link. Unsubscribing covers all of that organiser's webinars. We keep your address on their unsubscribe list as long as their account exists, so they don't write to you again. You can resubscribe from the link in any email you received.
These emails, like the one that lets a host choose a new password, go out through Amazon Web Services (SES), from Frankfurt.
The host's own tools
A host can connect their own tools: a webhook (to Zapier for example), Klaviyo or WhatsApp. We then send your registration data to these tools, on their instruction. The host can also turn on their own Meta pixel, and chooses how. By default, the platform asks for your consent before loading it. The host can also load it straight away: a banner then tells you what it's for and lets you refuse. See section 8.
What your browser loads
Video is delivered through Cloudflare's network, which therefore sees your IP address. Fonts are served by the platform itself: no request goes to Google.
4. Our clients' webinars before the platform
Before live.webinaire.ch, we ran webinars for our clients with WebinarJam. For those webinars, the client is the controller and we process the data on their behalf.
We still track registrations, attendance, sales and instalment payments for these launches. The tools involved are WebinarJam, ManyChat (WhatsApp messages), Notion, the client's Stripe account and the client's Meta pixel. Our internal Telegram alerts show a truncated email address for each sale, and the buyer's name when an instalment fails or is late.
5. Why, and on what legal basis
For people living in the European Union, the GDPR requires a legal basis for each processing activity. Here are ours. The articles cited are GDPR articles.
| What we do | Legal basis |
|---|---|
| Run and protect the website and the platform | Legitimate interest (Art. 6(1)(f)) |
| Measure and target our ads: pixel, LinkedIn tag, conversions, questionnaire | Legitimate interest (Art. 6(1)(f)). See also section 8. |
| Organise the call you book and follow up | Pre-contractual steps at your request (Art. 6(1)(b)) and legitimate interest for follow-up (Art. 6(1)(f)) |
| Transcribe and summarise the call | Your consent (Art. 6(1)(a)) |
| Contact you by direct message | Legitimate interest (Art. 6(1)(f)) |
| Provide the platform to hosts | Contract (Art. 6(1)(b)) |
| Register you for our webinars, send reminders and the replay | Contract (Art. 6(1)(b)) |
| Analyse engagement during our webinars | Legitimate interest (Art. 6(1)(f)) |
| Load a host's Meta pixel, when they ask for your consent | Your consent (Art. 6(1)(a)) |
| Respect your unsubscribe from emails | Legal obligation (Art. 6(1)(c)) |
| Process data for a host or a client | The host's instructions (Art. 28 GDPR, Art. 9 FADP). Their legal basis applies. |
| Keep our accounts | Legal obligation (Art. 6(1)(c)) |
Our legitimate interests: making the agency known, finding clients, knowing what our ads bring in and improving our webinars.
Some data is required. Without a name and an email, we can't confirm a call or a registration. Everything else is optional.
6. Who receives your data
We don't sell your data. We entrust it to providers who process it for us. Within the team, each person only accesses what they need.
| Provider | Purpose | Country |
|---|---|---|
| Vercel | Hosting of the website and the platform interface | United States |
| Render | Platform server and database | United States |
| Cloudflare | Video storage and delivery | United States, global network |
| Amazon Web Services (SES) | Platform emails | Germany (Frankfurt) |
| Google (Workspace, Meet) | Email, video calls | United States, Ireland |
| Cal.com | Call booking | United States |
| Notion | CRM | United States |
| Telegram | Internal team alerts | United Arab Emirates, servers in several countries |
| Tactiq | Call transcription | Australia, Google Cloud servers |
| Zapier | Sending transcripts to the CRM | United States |
| Anthropic | AI call summaries | United States |
| Meta | Pixel, Conversions API, WhatsApp | Ireland, United States |
| Insight Tag, Conversions API | Ireland, United States | |
| WebinarJam, ManyChat | Our clients' webinars before the platform | United States |
| Stripe | Sales of the clients and hosts who use it | Ireland, United States |
Meta and LinkedIn are not mere providers. They also use this data for their own advertising purposes. For the collection on our website and its transmission, we are joint controllers with them. Their privacy policies apply from there on.
We also share data with an authority when the law requires it.
7. Transfers abroad
Several providers process your data outside Switzerland. Switzerland recognises that the European Union protects data adequately. For other countries, we put safeguards in place.
- United States: we rely on the Swiss-US Data Privacy Framework, and on the EU-US Data Privacy Framework for people in the European Union, when the provider is certified. Otherwise, on the European Commission's standard contractual clauses, recognised by the Swiss Federal Data Protection and Information Commissioner.
- Other countries (Australia, United Arab Emirates, Cloudflare's global network): the standard contractual clauses included in the provider's terms.
- Failing that, the transfer relies on an exception provided by law, such as the performance of a contract with you (Art. 17 FADP, Art. 49 GDPR).
You can ask us for a copy of the safeguards we use. Write to contact@webinaire.ch.
9. How long we keep your data
- Technical logs of the website and the platform: a few days, 30 days at most.
- Bookings, prospect records, call transcripts and summaries: 24 months after our last exchange.
- Contracts, invoices and related correspondence: 10 years, as Swiss law requires.
- Host accounts: as long as the account is open. There is no button to close an account yet: write to us. After it closes, we delete its data within 90 days, except accounting records.
- Traces of a new password request: one day.
- Registrants of our own webinars: 24 months after the webinar.
- Registrants of a host's webinar: as long as the host decides. A deleted webinar disappears from the host's account and the public pages, but its registrations, messages and answers stay stored. The host can ask us to delete them. At the latest, we delete them 90 days after the host's account closes.
- An organiser's unsubscribe list: as long as their account exists, so they don't write to you again.
- Replays: until the expiry date set by the host, then the video is deleted within 7 days. Without an expiry date, as long as the webinar exists. The video of a deleted webinar is deleted after 7 days.
- Data processed for a client: until the end of the engagement. We then delete it or return it to the client.
- Cookies: see section 8.
After these periods, we delete the data or make it anonymous.
10. Your rights
At any time, you can:
- find out whether we process your data and get a copy
- have inaccurate data corrected
- have your data deleted
- restrict or object to a processing activity, advertising in particular
- receive your data in a common format, or have it sent to another provider
- withdraw your consent, without affecting what was done before
- ask for a person to review an automated decision
Write to contact@webinaire.ch. We answer within 30 days. We may ask you to prove your identity. It is free of charge in principle.
For a host's webinar, contact the host first. If you write to us, we pass your request on to them.
You can also contact a data protection authority. In Switzerland, it is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, edoeb.admin.ch. In the European Union, it is the authority of the country where you live or work.
11. Security
We protect your data with technical and organisational measures:
- encrypted connections (HTTPS) on the website and the platform
- passwords and API keys stored in hashed form
- keys of connected tools encrypted in the database
- protection against repeated login attempts
- access limited to the team members who need it
No system is flawless. If a breach poses a high risk to you, we notify the FDPIC and, where needed, the people affected.
12. Changes
We update this page when our tools or practices change. The date at the top shows the current version. If an important change affects you, we let you know by email or on the platform.
Any question? Write to us at contact@webinaire.ch.