trovagenda logo

Privacy Policy

trovagenda

As of June 2026 — Draft, first version

See also: Terms of Use

1. Controller

The controller responsible for processing personal data in connection with trovagenda is trovagenda.

Contact: via the contact options indicated on the website.

2. Scope

This Privacy Policy describes which personal data we process when you use trovagenda, for what purposes and on what legal basis. It supplements our General Terms of Use.

3. Data Processed

3.1 Account data: When registering and using a user account, we process in particular email address, password (as a cryptographic hash), preferences chosen by you, location-related information and data related to invitation and referral features, where offered in the Service.

3.2 Usage and technical data: When accessing the Service, IP address, date and time of access, browser type, operating system, device type, pages and features accessed, and error and security logs may be collected automatically. When retrieving your personal calendar feed (ICS), technical access data is processed.

3.3 Communication: If you contact us (e.g. feedback, support), we process the information you provide and the content of your message.

3.4 Payment data (Premium): For paid subscriptions, payment data is processed by the respective payment service provider. We generally receive only information required for billing.

4. Purposes and Legal Bases

We process personal data for the following purposes:

PurposeLegal Basis (revDSG / GDPR)
Provision of the Service, account, agenda, calendar feedContract performance (Art. 6(1)(b) GDPR; Art. 31(2)(a) revDSG)
Personalisation of event informationContract performance; legitimate interest
Processing of Premium subscriptionsContract performance
Security, abuse detection, stabilityLegitimate interest
Further development and improvement of the ServiceLegitimate interest
Compliance with legal obligationsLegal obligation
Communication with youContract performance / legitimate interest

Where we obtain your consent for specific processing, processing is based on that consent, which you may withdraw at any time.

5. Cookies and Similar Technologies

We use technically necessary cookies or comparable storage mechanisms required for operation of the Service — in particular to maintain your login (session).

Optional analytics or convenience features are used only if you have consented or where permitted by law. You may configure your browser to reject cookies; individual features of the Service may then be limited.

6. Disclosure to Third Parties and Processors

We disclose personal data only where necessary to provide the Service, a legal obligation exists or you have consented.

This may include in particular: hosting and infrastructure providers, email service providers, payment service providers and technical providers for error analysis or security.

We enter into the agreements required by law with processors. Disclosure to countries without an adequate level of data protection occurs only under the safeguards provided by law.

7. Retention Period

Account data: for the duration of the user account; after deletion, data is deleted or anonymised unless statutory retention obligations apply.

Technical logs: generally for a limited period (e.g. up to 90 days), unless longer retention is necessary for security incidents.

Payment and accounting data: in accordance with statutory retention periods.

8. Calendar Feed (ICS)

Your personal calendar feed is provided via an individual URL. You should treat this URL like an access key.

Upon deletion of your account, the feed may be deactivated. Appointments already imported into external calendar applications are not automatically removed by us.

9. Your Rights

Under the revDSG and GDPR, you have in particular the following rights, where the statutory requirements are met:

  • information about the processing of your data
  • rectification of inaccurate data
  • erasure of your data
  • restriction of processing
  • data portability
  • objection to processing based on legitimate interests
  • withdrawal of consent given, with effect for the future

To exercise your rights, contact us via the contact options indicated on the website. You may also delete your account via the website where this function is available.

You also have the right to lodge a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC).

10. Data Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss or misuse. However, complete security of data transmission over the internet cannot be guaranteed.

11. Minors

The Service is not directed at persons under 16 years of age. We do not knowingly collect data from minors below this age.

12. Changes

We may amend this Privacy Policy. The current version is available on the website. In the event of material changes, we will inform you in an appropriate manner (e.g. by email or notice upon login).

This document is a preliminary draft and does not replace individual legal advice.