Legal

Privacy policy

Last updated: 30 September 2026

This English version is provided for convenience. The German version is legally binding.

1. Controller

The controller responsible for processing personal data on gotime.ch and on the GoTime platform is:

Derouck GmbH, c/o Milan Derouck
Via d'Alvra 19a, 7522 La Punt Chamues-ch, Switzerland
Email: milan@derouck.ch

2. Legal basis

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP). Where persons in the EU or EEA are concerned, the General Data Protection Regulation (GDPR) also applies, in particular Art. 6(1)(b) (contract) and (f) (legitimate interest in secure operation).

3. Who is responsible for what

GoTime is a platform for event organisers. The data an organiser records in GoTime, such as participants, volunteers, guests, partners, accreditations, contracts and financial data, is the responsibility of that organiser. Derouck GmbH processes this data exclusively on the organiser's behalf and in accordance with its instructions (data processing on behalf). Please address questions about this data to the organiser first.

Derouck GmbH is itself responsible for the website gotime.ch, user accounts and the technical operation of the platform.

4. Data processed

  • Account data of users: name, email address, role and permissions with the organiser
  • Volunteer accounts on an organiser's volunteer page: profile details, registrations, assignments and confirmed hours
  • Device binding of digital passes: a random device identifier, so that a pass only works on the device of the authorised person
  • Content data recorded by organisers and their staff (see section 3)
  • Information from an organiser's public forms, such as replies to invitations, volunteer registrations, accreditation and room requests
  • Technical data: time of access, IP address, browser, log of changes
  • Enquiries by email or via the contact details on the website

5. Purposes

We process personal data to provide the platform, manage accounts, send notifications and invitations by email, ensure secure operation, fix errors and answer enquiries. We do not sell personal data and do not use it for third-party advertising.

6. Service providers and data location

We use the following processors to operate the platform:

  • Supabase: database, sign-in and file storage. Data is stored in the EU (Frankfurt, Germany).
  • Vercel: operation of the application. The application runs in the Frankfurt region (Germany); Vercel is a company based in the USA.
  • Resend: sending of emails (notifications, invitations). Recipient address and message content are processed. Sending runs via the Ireland region (EU); Resend is based in the USA.

Data processing agreements are in place with all service providers. Where data may be transferred to the USA, we rely on the Swiss-U.S. or EU-U.S. Data Privacy Framework or on the Standard Contractual Clauses of the European Commission.

7. Cookies and tracking

We only use technically necessary cookies: for sign-in and for settings such as the selected event context. There are no tracking, analytics or advertising cookies and no social media plug-ins.

8. Retention and deletion

We keep personal data for as long as necessary for the purposes stated or as required by law. We delete or anonymise an organiser's data after the end of the contract on the organiser's instructions. Organisers can anonymise contacts and export data in GoTime themselves at any time.

9. Your rights

You have the right to access your personal data and to have it corrected, deleted, restricted and handed over in a common format. Where the GDPR applies, you may also object to processing and lodge a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC).

Please send requests to milan@derouck.ch. If your request concerns data recorded by an organiser, we will forward it to them.

10. Data security

We protect data with technical and organisational measures: encrypted transmission (TLS), strictly separated areas for each organiser, role-based permissions, logging of changes and regular backups.

11. Changes

We update this policy when our processing or the legal situation changes. The version published on this page applies.