Privacy Policy

Last updated: 6 August 2026

This policy explains what personal data Mendva handles, why, who it is shared with, and what you can ask us to do about it. It covers studio owners, teachers, students booking through a studio, and anyone visiting our website.

Operator and controller

Mipam Guillot
Chemin de Mancy 40
1222 Vésenaz
Switzerland
contact@mendva.ch
  1. Who is responsible for your data

    Mendva is operated by the person named above, who is the controller for the data described in this policy under the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).

    There are two distinct roles, and which one applies changes your rights and who you should contact first:

    • For studio owners and teachers, we are the controller. You have an account with us, and we decide how that account data is handled.
    • For students, the studio you book with is the controller. Mendva is its processor: we hold and process student data on the studio's instructions, under a data processing agreement. If you are a student and want your data corrected or deleted, ask your studio first. You can also write to us and we will act on the studio's instruction or pass the request on.
  2. Data we collect about studio owners and teachers

    When you create a studio or accept a teacher invitation, we collect and store:

    • Identity and contact details: name, email address, phone number, preferred language, and profile photo if you upload one.
    • Account security data: a hashed password, and if you enable two-factor authentication, the secret and recovery codes needed to verify it.
    • Sign-in method: if you sign in with Google or Apple, the provider name and the account identifier they return. We never receive your password from them.
    • Studio details: studio name, description, logo, brand colour, website address, timezone, locations, and your schedule, class types, packages and prices.
    • Teacher profile data: name, email, biography, photo and social links, which appear publicly on your booking page and embedded widget if you publish them.
    • Billing data: your subscription plan, and the Stripe customer and subscription identifiers. Card details are entered directly with Stripe and never reach our servers, though we do store the card brand and last four digits Stripe reports back so you can recognise your payment method.
    • Technical records: IP address, browser user agent, session records and the time of your last sign-in.
  3. Data studios collect about their students

    A studio decides what it asks its students for. The platform can store the following, and the studio chooses which of it to use:

    • Identity and contact details: name, email address, phone number, postal address, date of birth, member number and preferred language.
    • Emergency contact: the name and phone number of a person to contact if something happens in class.
    • Health notes: a free-text field a studio can use for injuries, pregnancy or conditions relevant to practising safely. This is health data, which is sensitive personal data under FADP art. 5 let. c and a special category under GDPR art. 9. It is only ever collected when a studio asks for it, and the student provides it knowing why.
    • Booking and attendance history: classes booked, cancelled or waitlisted, check-in times and method, and any note or override an operator records at check-in.
    • Purchases: class packs, subscriptions and workshop registrations, with amounts paid and the related Stripe identifiers.
    • Liability waiver acceptances: which version of a studio's waiver was accepted and when, kept as evidence that it was agreed.
    • Referrals: the referral code used, and the link between the student who referred and the student who joined.
    • Notification preferences and, if the student installs the studio app and opts in, the browser push subscription needed to deliver reminders.
  4. Data we collect about website visitors

    On our public website and inside the app, we use PostHog to understand how the product is used and to catch errors. It records pages visited, features used, browser and device type, approximate location derived from IP address, and the details of any JavaScript error including its stack trace.

    For signed-in users these events are linked to your account, including your name and email address, so we can reproduce a problem you report. For signed-out visitors no profile is created.

    PostHog is configured on its European infrastructure and data is processed in the EU.

  5. Why we process this data and on what legal basis

    • To provide the service you signed up for, including scheduling, bookings, check-in and payments. Legal basis: performance of a contract (GDPR art. 6(1)(b)), and for students, the studio's own basis for its contract with them.
    • To send transactional messages such as booking confirmations, class reminders, substitution notices, password resets and billing receipts. Legal basis: performance of a contract.
    • To keep the service secure and working, including error tracking, abuse prevention and product analytics. Legal basis: legitimate interests (GDPR art. 6(1)(f)) in running a reliable service.
    • To send marketing emails, where you have opted in. Legal basis: consent, withdrawable at any time.
    • To handle health notes and any other sensitive data. Legal basis: explicit consent (GDPR art. 9(2)(a)), given to the studio that asks for it.
    • To meet legal obligations, including Swiss accounting and record-keeping duties. Legal basis: legal obligation (GDPR art. 6(1)(c)).
  6. Who we share data with

    We do not sell personal data and we do not share it for anyone else's advertising. We use the following processors, each bound by a data processing agreement:

    • Stripe, for payments, subscriptions and Stripe Connect payouts. Stripe receives the payer's name, email, payment details and transaction amounts, and acts as its own controller for fraud prevention and regulatory duties.
    • Our transactional email provider, which receives the recipient's name, email address and the message content in order to deliver it.
    • PostHog, for product analytics and error tracking, on its EU infrastructure.
    • Anthropic, only if you use the website import during onboarding. The text of the studio website you point us at is sent for extraction, which can include the names, biographies and photo addresses of teachers published on that site. No student data is ever sent.
    • Google and Apple, if you choose to sign in with them, which confirm your identity to us.
    • Browser push services operated by Apple, Google and Mozilla, which deliver push notifications to devices that opted in. They receive the delivery endpoint, not the content of your account.
    • Our hosting and infrastructure providers, which operate the servers and backups the service runs on.
  7. Where your data is stored

    The application database and its backups are hosted in Switzerland.

    Some processors listed above operate outside Switzerland, including in the European Economic Area and the United States. Where data reaches a country without an adequacy decision, the transfer is covered by the European Commission's Standard Contractual Clauses together with the safeguards recognised by the Swiss Federal Data Protection and Information Commissioner.

  8. How long we keep it

    • Account data is kept while the account is active. After an account is closed, personal data is deleted within 90 days, except where a longer period is required below.
    • Accounting and payment records are kept for 10 years, as required by Swiss law (Code of Obligations art. 958f).
    • Liability waiver acceptances are kept for as long as a claim could be brought against the studio that collected them, which is normally 10 years under Swiss law.
    • Product analytics and error records are kept for up to 12 months.
    • Backups are rotated on a rolling schedule, so deleted data can persist in a backup for a short period after deletion from the live database.
  9. How we protect it

    Traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes and are never readable by us. Two-factor authentication is available on every account and we recommend enabling it.

    Access to production data is limited to what is needed to operate the service. Each studio's data is separated so one studio cannot see another's records.

    No system is perfectly secure. If a breach occurs that is likely to result in a high risk to you, we will notify you and the competent authority as the FADP and GDPR require.

  10. Your rights

    Whatever your role, you can ask us to:

    • Confirm whether we hold data about you and give you a copy of it.
    • Correct data that is wrong or incomplete.
    • Delete your data, subject to the retention periods above.
    • Restrict or object to processing based on legitimate interests.
    • Receive your data in a portable, machine-readable format, or have it sent to another provider where technically feasible.
    • Withdraw consent at any time, which does not affect processing that already happened.
  11. How to exercise your rights, and how to complain

    Write to the email address at the top of this page. We answer within 30 days and may need to verify your identity first, so that nobody else can obtain your data by asking.

    If you are a student, the fastest route is usually your studio, which controls your record. We will not refuse a request for that reason, but the studio can act on it immediately.

    If you are unhappy with how we handled your request, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) in Bern, or, if you are in the EEA, to the supervisory authority where you live or work.

  12. Cookies and similar technologies

    We use the smallest set of cookies we can. There are no advertising cookies and no third-party trackers for advertising purposes. Analytics cookies are only set after you accept them in the cookie banner, and you can change that choice at any time through the cookie settings link in the footer.

    • A session cookie, which keeps you signed in. Strictly necessary, and the service cannot work without it.
    • A CSRF token cookie, which protects forms from cross-site request forgery. Strictly necessary.
    • A preference cookie remembering your chosen language and appearance.
    • PostHog analytics cookies, which recognise a returning browser so usage is not counted twice. Only set if you accept analytics.
    • Stripe may set cookies during checkout to detect fraud, under its own policy.
  13. Automated decisions and profiling

    We do not make decisions with legal or similarly significant effects about you by automated means, and we do not profile you for advertising.

  14. Children

    You must be at least 18 to open a studio owner or teacher account.

    Studios can have students who are minors. Where a studio registers a minor, it is responsible for obtaining consent from a parent or legal guardian, and for deciding what data is appropriate to collect.

  15. Changes to this policy

    We may update this policy as the product changes. The date at the top always reflects the current version. If a change materially affects your rights, we will tell registered users by email before it takes effect.

  16. Contact

    For any question about this policy or about your data, write to the address at the top of this page. We read every message.