GDPR Compliance
Last updated: 2026-05-07Startup Valleys is committed to compliance with the EU General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (FADP / revDSG), and equivalent privacy frameworks worldwide. Although our directory is worldwide in scope, we apply EU-grade data-protection standards by default to every user, regardless of where they reside.
1. Data Controller
2. Our Commitment
- We process the minimum personal data needed to operate the Service.
- We never sell or rent personal data, and we do not run cross-site advertising trackers.
- Sensitive submission data (HR contacts, private fields) is never exposed through the public API.
- All traffic is encrypted (HTTPS/TLS); passwords are hashed with argon2id.
- Where we use processors outside the EU/EEA, transfers rely on Standard Contractual Clauses (SCC).
3. Lawful Bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Displaying the worldwide map and public content | Legitimate interest (Art. 6(1)(f)) |
| Operating your account | Contract (Art. 6(1)(b)) |
| Submissions, applications, RSVPs | Consent (Art. 6(1)(a)) + legitimate interest |
| Payment processing (Stripe) | Contract (Art. 6(1)(b)) |
| Security logging & fraud prevention | Legitimate interest (Art. 6(1)(f)) |
4. Your Rights as a Data Subject
You may exercise the following rights at any time:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion (“right to be forgotten”)
- Restriction — limit how we use your data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — for any processing based on consent
- Lodge a complaint — with the Swiss FDPIC or your local EU/EEA data protection authority
Although these rights derive from EU and Swiss law, we extend them on a best-effort basis to any user worldwide who contacts us.
5. How to File a Request
Email [email protected] with the subject line “GDPR request”. Include the email address associated with your account (if any) and the right you wish to invoke. We respond within 30 days; complex requests may extend by a further 60 days, in which case we’ll let you know.
6. International Transfers
Data processed by Startup Valleys may be transferred to processors located outside the EU/EEA (e.g. Stripe, Resend, Mapbox in the United States). These transfers rely on Standard Contractual Clauses (SCC) approved by the European Commission, on the EU-US Data Privacy Framework where applicable, or on equivalent safeguards.
7. Supervisory Authorities
- Switzerland (lead authority for our operator): Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch
- EU/EEA users: your national data protection authority. The full list is at edpb.europa.eu.
8. Related Documents
- Privacy Policy — what data we collect, why, and for how long
- Cookie Policy — cookies and local storage we use
- Terms of Use
- Imprint
9. Contact
For any GDPR or data-protection question: [email protected]