Privacy Policy
Privacy Policy · gynxtra GmbH
Version 1.12 · As of 25 September 2026 · revDSG-compliant
1 · Data Controller
Controller for data processing within the meaning of Art. 5 lit. j revDSG:
gynxtra GmbH
Höschgasse 50, 8008 Zurich
Switzerland
UID: CH-020.4.078.662-7
Medical lead and licence holder: Dr. med. Bettina von Seefried, FMH Gynaecology
Data protection enquiries: hello@gynxtra.ch
2 · What Data We Process
2.1 Identification and Contact Data
Surname, first name, date of birth, postal address, email address, phone number (optional, only with WhatsApp opt-in), profile picture (optional).
2.2 Health Data (sensitive personal data within the meaning of Art. 5 lit. c revDSG)
- Medical history and follow-up data (family and personal medical history, symptoms, lifestyle)
- Symptom and wellbeing tracking: self-reported ratings on a scale for sleep, mood, hormones, intimacy, body and weight
- Cycle information (cycle status, bleeding days)
- Free-text entries from check-ins (concerns, changes since the last check-in, topics for the next consultation)
- Body measurements and vital signs (weight, blood pressure, others where indicated)
- Laboratory values (hormone levels, HbA1c, lipid profile, vitamin D, other indicated markers)
- Prescribed medications, dosages, adherence, side effects and feedback on requested therapy adjustments
- Consultation records (medical notes, treatment plan, report, medical certificate)
- Off-label information sheets and signed consents
2.3 Usage and Interaction Data
- Login and session data in the Patient Cockpit
- Interaction with content (click paths, feature usage)
- Device information (browser, operating system, IP address - processed in truncated form)
2.4 Payment Data
- First and last name, billing address
- Stripe transaction IDs (card details are processed directly by Stripe and are not accessible to gynxtra)
2.5 Communication Data
- Email and WhatsApp history (where opt-in granted)
- Video call metadata (Daily.co · duration, time - no recording content without separate consent)
3 · Purposes of Data Processing
| Purpose | Data | Legal basis |
|---|---|---|
| Contract performance (treatment, cockpit, prescription) | Identification · health · usage | Art. 31 Abs. 2 lit. a revDSG |
| Medical diagnosis and treatment planning | Health | Consent + medical treatment |
| Payment processing | Identification · payment | Contract performance |
| Appointment reminders, refill notifications | Contact · usage | Contract performance |
| WhatsApp communication | Contact · phone | Explicit consent (opt-in) |
| Platform security, abuse prevention | Usage · device | Legitimate interest |
| Analytics (pseudonymised / aggregated) | Usage | Legitimate interest (Art. 31(1) FADP) · objection possible at any time |
| Conversion measurement for advertising (Google Ads / Analytics) | Usage (three pseudonymous events, no health data) | Consent (opt-in in the cookie banner) · withdrawal possible at any time |
| Statutory retention obligations | Health | Statutory duty (HMG, 10 years) |
4 · Recipients and Subprocessor List
We engage the following service providers. Where they process personal data on our behalf, a Data Processing Agreement (DPA) governs the purpose, the scope and their obligation to follow our instructions. The «Location» column states where the data is held and on what basis any transfer outside Switzerland takes place.
| Service provider | Purpose | Location / transfer mechanism |
|---|---|---|
| Lovable AB | Development environment for the Patient Cockpit and the Doctor Cockpit | Sweden (EU adequacy under Annex 1 DSV) |
| Supabase Inc. | Database, auth, storage, edge functions | US entity, EU-Frankfurt region (Swiss-U.S. DPF + SCC) |
| Vercel Inc. | Hosting and delivery of the website, the Patient Cockpit and the Doctor Cockpit, as well as the website's server functions | US entity, server functions in the Frankfurt region (Swiss-U.S. DPF + SCC) |
| Stripe Payments Europe Ltd | Payment processing | Ireland (EU adequacy) |
| Resend Inc. | Transactional emails | USA (Swiss-U.S. DPF / SCC) |
| Hostpoint AG | Mail hosting (hello@gynxtra.ch), DNS management | Switzerland |
| Cal.com Inc. | Appointment booking | USA (Swiss-U.S. DPF / SCC) |
| Daily.co (Pluot Inc.) | Video consultations · in turn uses an error reporting service | USA (Swiss-U.S. DPF / SCC) |
| Google Ireland Ltd (Google Forms) | Voluntary feedback after the consultation (form with a reference code) | Ireland, processing also in the USA (Swiss-U.S. DPF + SCC) |
| respond.io Pte Ltd | WhatsApp aggregator (with opt-in) | Singapore (SCC + explicit consent) |
| Meta Platforms Ireland Ltd | WhatsApp Business API (with opt-in) | Ireland (EU adequacy) |
| Swiss Analysis AG | Laboratory logistics (home blood test) | Switzerland |
| medicalvalues GmbH (Knes Platform) | Laboratory analytics software | Heidelberg, Germany (EU adequacy) |
| Hysek-Apotheke | Medication dispatch | Switzerland |
| PostHog Inc. (EU Cloud) | Product analytics (pseudonymised) · objection possible at any time | Data centre EU · provider domiciled in the USA · EU Standard Contractual Clauses (SCC) |
| Google Ireland Ltd / Google LLC | Conversion measurement for advertising (Google Ads / Analytics 4), only with consent · three pseudonymous events, no health data | Ireland / USA (Swiss-U.S. DPF) · independent controller for the advertising-related part, see note below |
| Meta Platforms Ireland Ltd / Meta Platforms Inc. | Conversion measurement for advertising (Meta pixel), only with consent · the same three pseudonymous events under neutral names, no page views, no health data | Ireland / USA (Swiss-U.S. DPF) · independent controller for the advertising-related part |
Note on Google: For the pure measurement, Google acts as a processor. To the extent the measurement data is linked to the Google Ads account and used for advertising purposes, Google is an independent controller in that respect. This collection only takes place with your explicit consent (opt-in in the cookie banner) and contains no health data.
5 · Third-Country Transfers
Some subprocessors process data outside Switzerland / the EU. Transfers take place on the basis of the following mechanisms pursuant to Art. 16 f. revDSG:
- USA: Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF, in force since 14 September 2024) for DPF-certified recipients. For non-certified recipients, EU Standard Contractual Clauses (SCC) additionally apply, including a Transfer Impact Assessment (TIA).
- EU / EEA (Ireland, Germany, Sweden): Adequate data protection under Annex 1 DSV (ordinance to the revDSG) - no additional mechanism required.
- Singapore (respond.io): No adequacy decision - transfer based on EU Standard Contractual Clauses (SCC) as well as the patient's explicit consent in the WhatsApp opt-in.
- Additional technical and organisational measures: pseudonymisation where possible, encryption in transit (TLS 1.3) and at rest (AES-256).
6 · Retention Periods
- Patient record (health data): at least 10 years after the last treatment (cantonal health law, HMG)
- Contract data / accounting: 10 years (OR Art. 958f)
- Marketing and analytics data: up to 24 months
- Non-medical communication (support): 24 months
- After expiry, data is deleted or anonymised
7 · Your Rights
As a data subject, you have the following rights under revDSG (and, where applicable, GDPR):
- Access to the data processed about you (Art. 25 revDSG)
- Rectification of inaccurate data
- Erasure of your data (unless a statutory retention obligation applies)
- Restriction of processing
- Data portability in a machine-readable format
- Withdrawal of consents granted (effective for the future)
- Objection to processing based on a legitimate interest, in particular to the usage statistics (see section 9)
- Complaint to the FDPIC (Federal Data Protection and Information Commissioner), Feldeggweg 1, 3003 Bern
Please direct enquiries to hello@gynxtra.ch. We process enquiries within 30 days.
8 · Data Security
We implement appropriate technical and organisational measures:
- Encryption in transit (TLS 1.3) and at rest (AES-256 in Supabase Storage)
- Row-level security at database level
- Audit logs for sensitive actions (prescription issuance, plan changes, off-label consents)
- Role-based access control (Patient, Coach, Doctor, Admin)
- Regular security reviews
- Obligation on all staff and processors to observe medical professional secrecy or confidentiality
9 · Cookies and Tracking
On gynxtra.ch we use technically necessary cookies (session, authentication, storage of your privacy choice). They are required to operate the website and cannot be switched off.
In addition we collect pseudonymised usage statistics with PostHog (EU Cloud, servers located in the EU) in order to understand which pages are viewed and where visitors drop off. A randomly generated identifier is stored in your browser's local storage for this purpose. The legal basis is our legitimate interest in a functioning and comprehensible website (Art. 31(1) FADP). We inform you about the processing on your device in accordance with Art. 45c TCA.
You may object at any time. On your first visit we show a short notice naming the purpose, the transfer to third parties and your right to withdraw, with the buttons "Necessary only" and "Agree". The names of the recipients and the country are given in the settings and in this section. Via "Settings" you reach the same choice with three separate categories: Necessary (no choice), Audience measurement (on by default, can be switched off at any time) and Third parties (off by default, only with your explicit consent). The two categories are stored separately and can be changed separately. After that the setting remains available via the "Cookie settings" link shown on every page. An objection takes effect immediately. Withdrawing consent is as easy as giving it: the same dialog, the same switch.
We count how often people consent and how often they decline. When you make a choice in the banner, whichever button you use, our own server records one line: which of the three answers it was, which version of the text you were shown, whether the choice came from the settings view, and the date without a time. Nothing else is in that line: no IP address, no identifier, no session, no cookie value, and not which page you were on. As with every request to our website, our server does see your IP address. It does not retain it anywhere for this count. There is therefore nothing in that line that could connect it to you.
We need the number for two reasons. Without your consent no statistics run at all, and so far we do not know how large that share is. It also shows us whether the banner is clear enough. We count every decision, including a refusal. Otherwise we would know nothing about precisely the refusals. The count has no effect on what you are shown. We keep it indefinitely, because it contains nothing about individual people.
Two pages deliberately show no consent element. On the pre-check and on the booking page, neither the first-visit notice nor the «Cookie settings» link appears. The reason is usability: on a mobile phone the element covered the answer options of the questionnaire and the available times in the calendar, that is, the very thing those pages are for. What runs in the background is unaffected: audience measurement runs as it does everywhere unless you have objected, and Google and Meta receive nothing without your consent. From the pre-check, no signals are sent to Google or Meta at all.
You can still object and withdraw, right there. Below the calendar on the booking page you will find a link to this privacy policy and a button that opens the same settings with all three categories. That button works even if you have never made a choice before. A change made there takes effect immediately and applies to the whole website, not just that one page. Once you leave the pre-check or the booking page, the consent element is back on the next page.
These usage statistics contain no information about you as a person, no questionnaire answers and no findings. The only exception is the count in the pre-check described below, which is kept separate from these statistics. We record which pages are viewed, including pages on individual treatment topics, how long a page was open, how far it was scrolled and where on it people click (as an anonymous heatmap). Addresses and titles of pages on individual symptoms are generalised so that no specific condition can be identified. This data is not combined into a profile over time: the identifier applies only to the current browser session and is discarded afterwards. Where we measure and where we do not is kept strictly apart. In the pre-check we record that the questionnaire was started and completed, and which of the three outcomes it produced. Your answers never leave your browser, with one exception: if the pre-check shows that we do not yet have a suitable programme for you, we count the reason, that is your age group (under 18, 18 to 37 or over 65), that you selected none of the listed symptoms, or both. We store only a total per week and reason, without a time, without an identifier and without any link to your session, and we keep these weekly totals indefinitely. The reason is not included in the usage statistics, and nothing is sent from that page to Google or Meta. The click on the button that leads to the pre-check is reported to Google and Meta as a step if you have consented to that sharing. From the questionnaire itself, nothing goes to Google or Meta. In the medical history questionnaire, the cockpit and the status pages, no statistics at all are collected. We do not use session replay.
Statistical data is deleted after a maximum of 24 months. Your objection is stored locally in your browser and therefore applies per browser and device. If you clear your browser storage, you will need to object again.
Advertising performance measurement with Google and Meta (only with your consent). If you explicitly consent in the cookie banner, we measure the performance of our advertising with Google Analytics 4 / Google Ads and with the Meta pixel. Only three pseudonymous events are transmitted (start of the pre-check, opening the booking page, booked first consultation), no page views, no answers, no symptom or topic pages and neither your name nor your email address. Pseudonymous means: Google and Meta can link the events to your account with them via a cookie, but learn nothing about your health. Meta receives the events under neutral names, without reference to the first consultation. The transfer goes to Google and Meta in the USA (Swiss-U.S. DPF). Unlike PostHog, Google and Meta can link these signals to your account with them for advertising. Nothing is transmitted without your consent; you can withdraw it at any time via "Cookie settings". The withdrawal switches both services off immediately and deletes their cookies.
10 · Automated Decisions
Treatment decisions are taken exclusively by qualified physicians. We do not use any fully automated decisions producing legal effect within the meaning of Art. 21 revDSG.
The upstream pre-check is a rule-based questionnaire. Whether one of our programmes suits you is decided solely on the basis of your age group and your symptoms. If the outcome is that we do not yet have a suitable programme for you, you can ask for a physician to review it (Art. 21 Abs. 2 revDSG). Requests to hello@gynxtra.ch.
AI-supported features (e.g. report preparation, symptom classification) serve solely as a tool; the final medical assessment is performed manually.
11 · Advertising and Marketing
- Patient Cockpit-related communication (appointment reminders, refills, adherence) is part of the contract and is not subject to marketing consent.
- Newsletters and product-related marketing only take place after a separate opt-in.
- Every marketing email contains a one-click unsubscribe link.
12 · Amendments to this Privacy Policy
We may amend this policy, in particular in response to legal or technical changes. Material changes are announced in the cockpit and take effect 30 days after announcement.
Change log
- v1.12 · 25 September 2026: Section 9 now describes that, when the pre-check outcome is that we do not yet have a suitable programme, we count the reason (age group, none of the listed symptoms, or both), only as a total per week and reason, without a time, without an identifier and without any link to the session. Section 10 now states what the pre-check is based on: age group and symptoms. This replaces the earlier wording "age, residence, exclusion criteria".
- v1.11 · 24 September 2026: The notice on your first visit now names the purpose (cookies for marketing purposes) and that data is passed to third parties in doing so. Names of the recipients and the country are given in the settings and in section 9. The description in section 9 has been adjusted accordingly.
- v1.10 · 24 September 2026: Section 9 now describes that we anonymously count the choices made in the consent banner: which of the three answers, which version of the text, whether it came from the settings view, and the date without a time. No IP address, no identifier, no session, no cookie value and no page path. The reason is that no statistics run without consent and the share of refusals was previously unknown.
- v1.9 · 22 September 2026: The list of service providers in section 4 has been aligned with the actual situation: the website and both cockpits have been hosted by Vercel since 25 August 2026. The website's server functions have run in the Frankfurt region since 22 September 2026, previously in the United States. The previous hosting provider no longer applies, Lovable is now listed as a development environment, and the voluntary feedback form (Google Forms) is now listed. Section 9 now distinguishes clearly between the pre-check, where the start, completion and outcome are measured, and the medical history questionnaire, the cockpit and the status pages, where nothing is measured. It also newly describes that no consent element appears on the pre-check and the booking page, and how withdrawal works there.
- v1.8 · 22 September 2026: The questionnaire before booking is now called the pre-check (previously Fit Check). Content and processing are unchanged.
- v1.7 · 21 September 2026: Usage statistics now also record how long a page was open, how far it was scrolled and where people click. Addresses and titles of symptom pages are generalised in all fields. The events sent to Google and Meta are now described as pseudonymous rather than anonymous; Meta receives them under neutral names.
- v1.6 · 20 September 2026: The first-visit notice is nowtwo-stage: first a short version naming the purpose, the recipients (Google, Meta), the third country (USA) and the right to withdraw, with the buttons "Necessary only" and "Agree", and below them "Settings" for the full choice. Categories, legal bases, defaults and withdrawal remain unchanged. Reason: on small screens the full dialog covered the content behind it.
- v1.5 · 17 September 2026: Consent is now managed inthree separate categories (Necessary · Audience measurement · Third parties) with separate storage. Previously audience measurement (legitimate interest) and third parties (consent) shared a single choice, mixing two different legal bases. Third parties are now explicitly off by default. Consent is recorded with a timestamp and the version of the notice text. Existing objections to audience measurement remain in force; a previously bundled consent to third parties is not carried over, so the notice appears once more.
- v1.4 · 16 September 2026: Section 2.2 aligned with the wellbeing categories actually collected (sleep, mood, hormones, intimacy, body, weight) and clarified that these are self-reported ratings on a scale. Cycle information and free-text entries from check-ins added. Change log now also in the English version.
- v1.3 · 28 August 2026: Added for measuring the performance of Google Ads campaigns: minimal, consent-based Google tracking (Google Analytics 4), two anonymous events (fit check started, initial consultation booked), no health data, transfer to the USA (Swiss-U.S. DPF), only after opt-in in the cookie banner. Google added to the subprocessor list (section 4), the purposes table (section 3) and cookies (section 9).
- v1.2 · 17 August 2026: Usage statistics (PostHog) are now operated on the basis of legitimate interest with a right to object at any time, instead of on consent. Clarification "pseudonymised" instead of "anonymised", retention period and transfer mechanism added, no session replay.
- v1.1 · 22 June 2026: Subprocessor list and data subject rights added.
- v1.0 · 3 June 2026: First version.
The current version is always available at: gynxtra.ch/en/legal/datenschutz
13 · Contact
Data protection enquiries:
gynxtra GmbH · Data Protection
Höschgasse 50, 8008 Zurich, Switzerland
hello@gynxtra.ch
Swiss supervisory authority:
Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Feldeggweg 1, 3003 Bern
www.edoeb.admin.ch
Version 1.12 · 25 September 2026 · gynxtra GmbH · revDSG-compliant