This privacy policy explains how Rocket Surgery Labs GmbH, as the operator of the platform Grialto, processes personal data. The revised Swiss Data Protection Act (revDSG) is authoritative. Insofar as the EU General Data Protection Regulation (GDPR) applies, it applies additionally.
Rocket Surgery Labs GmbH Oberfeld 25, 6430 Schwyz, Switzerland E-mail: legal@grialto.com
For all data protection matters you may contact the above address.
We process personal data in order to provide the Platform, manage accounts, handle challenges and donation pledges, collect the listing fee, communicate with you by e-mail (e.g. confirmations, reminders, status notifications), fulfil legal obligations, and ensure secure and trouble-free operation.
We process server log data (section 2) solely for secure and trouble-free operation, to defend against abuse and attacks, and for fault diagnosis. This processing is based on our overriding interest in the secure operation of the Platform (Art. 31 revDSG; where the GDPR applies, Art. 6(1)(f) GDPR). No evaluation for advertising or analytics purposes and no profiling take place.
To provide our services we engage carefully selected service providers who process data on our behalf:
These service providers receive only the data required for their task and are contractually obliged to maintain confidentiality and comply with data protection.
Data is generally processed and stored in Switzerland. Should disclosure to a country without an adequate level of data protection occur in an individual case, we ensure adequate protection with suitable safeguards (e.g. standard contractual clauses).
The Platform uses exclusively two technically necessary cookies for logging in (jwt and
refreshToken, each as an httpOnly cookie). These are required for operation and store no data for
advertising or analytics purposes. No non-essential cookies are set; a cookie banner is therefore
not required. You can block or delete cookies in your browser; logging in may then no longer work.
We retain personal data for as long as required for the stated purposes or on the basis of legal obligations. Thereafter the data is deleted or anonymised. Masking of personal data no longer required, beyond the statutory retention period, is planned.
We keep a log of the emails we send (recipient address, email type, time, delivery status) for operational and evidentiary purposes; the planned masking referred to above applies to the personal data it contains.
We retain server log data (section 2) for a maximum of 90 days; thereafter it is deleted automatically. Individual entries are kept longer only insofar as they are needed to investigate a specific security incident or to pursue legal claims.
Within the framework of applicable law, you have the right to information, rectification, erasure and restriction of the processing of your personal data and, insofar as applicable, to data portability. Registered users can delete their account themselves. To exercise your rights, please contact legal@grialto.com. You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC / EDÖB).
We may amend this privacy policy at any time. The version published on the Platform at the relevant time is authoritative.