GRIALTO
Browse challengesLog in
Create your challenge

Legal

TermsPrivacyImprint
history Version Aug 21, 2026 translate English is a courtesy translation — the German version is binding.

On this page

01Controller02Which Data We Process03Purposes of Processing04Disclosure to Third Parties (Processors)05Disclosure of Data Abroad06Cookies07Retention08Your Rights09Changes
tocOn this pageexpand_more01Controller02Which Data We Process03Purposes of Processing04Disclosure to Third Parties (Processors)05Disclosure of Data Abroad06Cookies07Retention08Your Rights09Changes

Privacy Policy

This privacy policy explains how Rocket Surgery Labs GmbH, as the operator of the platform Grialto, processes personal data. The revised Swiss Data Protection Act (revDSG) is authoritative. Insofar as the EU General Data Protection Regulation (GDPR) applies, it applies additionally.

1. Controller

Rocket Surgery Labs GmbH Oberfeld 25, 6430 Schwyz, Switzerland E-mail: legal@grialto.com

For all data protection matters you may contact the above address.

2. Which Data We Process

  • Account data: first name, last name, username, e-mail address, password (stored encrypted).
  • Challenge and donation data: the details you record regarding challenges, donation pledges, and time and amount figures.
  • Payment data: details in connection with the listing fee. Payment processing is handled by the payment service provider zahls.ch; card data is processed by them and not by us.
  • Server log data: when the Platform is visited, our servers automatically log every request: IP address, date and time, HTTP method and requested path (without query parameters), status code, amount of data transferred, processing duration, and the request headers sent by your browser (including User-Agent, Accept-Language and Referrer, the latter likewise without query parameters). In addition, the application logs technical operating events (e.g. errors or indications of abusive access) which may contain an IP address. Credentials — in particular cookies and Authorization headers — are removed before storage and are not logged.

3. Purposes of Processing

We process personal data in order to provide the Platform, manage accounts, handle challenges and donation pledges, collect the listing fee, communicate with you by e-mail (e.g. confirmations, reminders, status notifications), fulfil legal obligations, and ensure secure and trouble-free operation.

We process server log data (section 2) solely for secure and trouble-free operation, to defend against abuse and attacks, and for fault diagnosis. This processing is based on our overriding interest in the secure operation of the Platform (Art. 31 revDSG; where the GDPR applies, Art. 6(1)(f) GDPR). No evaluation for advertising or analytics purposes and no profiling take place.

4. Disclosure to Third Parties (Processors)

To provide our services we engage carefully selected service providers who process data on our behalf:

  • zahls.ch (siebenberge gmbh, Switzerland) — processing of the listing fee.
  • Infomaniak — hosting of the Platform and sending of e-mails (SMTP).

These service providers receive only the data required for their task and are contractually obliged to maintain confidentiality and comply with data protection.

5. Disclosure of Data Abroad

Data is generally processed and stored in Switzerland. Should disclosure to a country without an adequate level of data protection occur in an individual case, we ensure adequate protection with suitable safeguards (e.g. standard contractual clauses).

6. Cookies

The Platform uses exclusively two technically necessary cookies for logging in (jwt and refreshToken, each as an httpOnly cookie). These are required for operation and store no data for advertising or analytics purposes. No non-essential cookies are set; a cookie banner is therefore not required. You can block or delete cookies in your browser; logging in may then no longer work.

7. Retention

We retain personal data for as long as required for the stated purposes or on the basis of legal obligations. Thereafter the data is deleted or anonymised. Masking of personal data no longer required, beyond the statutory retention period, is planned.

We keep a log of the emails we send (recipient address, email type, time, delivery status) for operational and evidentiary purposes; the planned masking referred to above applies to the personal data it contains.

We retain server log data (section 2) for a maximum of 90 days; thereafter it is deleted automatically. Individual entries are kept longer only insofar as they are needed to investigate a specific security incident or to pursue legal claims.

8. Your Rights

Within the framework of applicable law, you have the right to information, rectification, erasure and restriction of the processing of your personal data and, insofar as applicable, to data portability. Registered users can delete their account themselves. To exercise your rights, please contact legal@grialto.com. You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC / EDÖB).

9. Changes

We may amend this privacy policy at any time. The version published on the Platform at the relevant time is authoritative.

GRIALTO

Every stride fuels change.

Links

AboutBlogImprintPrivacy PolicyTerms

Support

Support us

Register new challenge
|
© Rocket Surgery Labs GmbH