Privacy Policy and Data Protection Statement
At Hot Chilli Bells, we take the protection of your personal data extremely seriously. We understand that your privacy is of utmost importance, and we are committed to providing a safe and transparent environment for all our users. In this Privacy Statement, we explain in detail how we collect, use, store, and secure your information when you use our services. Our practices are strictly aligned with the Swiss Federal Data Protection Act (FADP) and, where applicable, international standards such as the GDPR, to ensure a consistently high level of protection.
Categories of collected data
Identification and contact data
When you interact with our platform, for example by creating an account, participating in activities, or contacting our customer service, we collect necessary data such as your full name, email address, and date of birth. The collection of the date of birth is a strict legal requirement to verify that all our users are at least 18 years old. Without this basic information, we cannot grant you access to the full functionality of our services, as we are bound by strict compliance rules.
Usage and device data
With each visit to our website, we automatically collect information about how you use our services. This includes your IP address, the type of device you use (e.g., mobile or desktop), your operating system, browser type, the pages you visit, and the duration of your sessions. This technical data is primarily used for monitoring system stability, optimizing loading times, and preventing unauthorized access to our servers.
Transaction data and communication history
If you carry out financial transactions on our platform, we record the details of these operations, such as the amount, date, and payment method used. We never store full card details; these are processed directly and securely by our certified payment providers. In addition, we keep copies of correspondence you have with us via email or chat. This enables us to provide consistent and high-quality support for any questions or disputes.
Legal bases for processing
The processing of your personal data takes place exclusively on the basis of the following legal frameworks:
- Performance of the contract: To provide you with the services for which you have registered and to comply with our general terms and conditions.
- Legitimate interest: For purposes such as fraud prevention, network security, and internal improvement of our products.
- Legal obligation: To comply with specific Swiss laws and regulations, including reporting obligations and consumer protection rules.
- Explicit Consent: For activities for which you have given explicit consent, such as receiving marketing information or using specific tracking technologies.
How we use your data
Management of your user account and identity
Your data is primarily used to create, maintain, and secure your account. This process includes verifying your identity, managing your preferences, and ensuring you meet our platform's eligibility criteria. We also use this information to send you important updates about changes to our services or policies.
Security, fraud prevention, and integrity
Security is a cornerstone of our daily operations. We analyze patterns in usage data to detect unusual activities that may indicate attempts at fraud, hacking, or misuse of our terms and conditions. Through proactive monitoring, we keep the environment safe for all legitimate users and protect the integrity of the digital infrastructure.
Customer support and platform improvement
The information you share with us enables our team to respond accurately to your questions and effectively resolve technical issues. Furthermore, we use anonymized statistics to evaluate the website's content and features. This helps us determine which innovations are most valued by our Swiss users and where further optimization is needed.
Data retention and storage periods
We retain your personal data no longer than is strictly necessary for the purposes for which it was collected. When you decide to close your account, your data will be removed from active systems or irreversibly anonymized after a reasonable period. However, we are legally obliged to retain certain information (such as transaction data and proof of identity verification) for a longer period to comply with tax legislation and audit requirements in Switzerland.
Data sharing and cross-border transfer
External service providers and partners
We may share your data with trusted third parties who perform services on our behalf, such as IT hosts, payment processors, data analysts, and legal advisors. Each external partner is contractually obligated to treat and secure your data confidentially according to standards that are at least equivalent to ours.
International transfers
In cases where data is processed outside Switzerland, we ensure that appropriate safeguards are in place. This is done through standard contractual clauses approved by the competent authorities, or by working with countries that offer an adequate level of protection. Your data is never sold to third parties for marketing purposes without your explicit consent.
Security measures
We implement robust technical and organizational measures to protect your data against loss, theft, unauthorized alteration, and access. This includes advanced encryption (SSL/TLS) for all data transfers, multi-level firewalls, and strict access controls for our employees. While we strive for the highest possible security, we remind you that no method of transmission over the internet is completely risk-free.
Your rights as a data subject
Under Swiss law, you have extensive rights regarding your personal data:
- Right to access: You can request what specific data we hold about you.
- Right to rectification: You can have inaccurate or incomplete data directly corrected.
- Right to erasure: You can request the deletion of your data when it is no longer needed.
- Right to restriction of processing: You can request that processing be temporarily stopped.
- Right to data portability: You can request to receive your data in a structured format.
- Right to object: You can object to processing based on legitimate interest.
To exercise any of these rights, please contact us at [email protected].