Legal
Privacy Policy
GutUp Sàrl · Lausanne, Switzerland
Effective May 1, 2026.
GutUp Sàrl is committed to protecting your personal data with care and transparency. This policy explains what data we collect, why we collect it, and how you can exercise your rights.
1.
Who are we?
GutUp Sàrl is a Swiss limited liability company specialising in gut health and sustainable nutrition. We publish the platform gutup.ch.
Data controller: GutUp Sàrl, Rue de Bourg 27, 1003 Lausanne, Canton of Vaud, Switzerland — privacy@gutup.ch
2.
What data do we collect?
Platform users (B2C accounts)
We collect only the data strictly necessary to create your account:
- First name (required)
- Email address (required)
- Reviews and comments you publish on the platform (optional)
Expert partners
- First and last name, profile photo
- Professional email address
- Declared certifications and training
- Bank card fingerprint (processed by Stripe, never stored by GutUp)
- Published editorial content: recipes, advice, articles
Producers and Brands
- Company name and address
- Contact email
- VAT or Swiss IDE number
- Product sheets, visuals and descriptions
- Billing data (processed by Stripe)
Spots
- Establishment name, address and GPS coordinates
- Contact email
- Opening hours, offers and descriptions
3.
Why do we use your data?
We process your data for the following purposes:
- Operating the platform and providing you with the service you subscribed to (legal basis: performance of contract, Art. 6.1.b GDPR)
- Sending transactional emails related to your account (legal basis: performance of contract)
- Sending newsletters and marketing communications, only if you have consented (legal basis: opt-in consent, Art. 6.1.a GDPR)
- Managing billing and accounting (legal basis: legal obligation, CO Art. 958f)
- Displaying the interactive Spots map (legal basis: consent or performance of contract)
4.
Third-party tools and processors
Each of the following tools acts as a data processor under the Swiss nFDP and GDPR, and is subject to a data processing agreement.
- Infomaniak (Switzerland): platform and data hosting, data stored in Switzerland, nFDP compliant
- Brevo (France, EU): transactional and marketing emails, GDPR compliant, adequate country
- Stripe (USA): online payment and billing, transfer governed by Standard Contractual Clauses (SCCs)
- Google Maps (USA): interactive Spots map display, transfer governed by SCCs, loaded only after your consent
SCCs = Standard Contractual Clauses approved by the European Commission.
5.
Hosting and international transfers
User data is hosted in Switzerland on the servers of Infomaniak Network SA (Geneva), ISO 27001 certified. No primary data is transferred outside Switzerland or the EEA without adequate safeguards.
Stripe processes data outside Switzerland and the EEA. These transfers are governed by Standard Contractual Clauses. Switzerland is recognised by the European Commission as a country providing an adequate level of data protection.
6.
How long do we keep your data?
- Active user account: duration of subscription, then 2 years
- Billing data: 10 years (legal obligation under CO Art. 958f)
- Connection logs: 6 months
- Published reviews and comments: duration of publication, then 1 year after deletion
- Brevo emailing data: until unsubscription, then 3 years
- Stripe payment data: per Stripe policy, GutUp does not store card data
7.
Cookies
gutup.ch uses only cookies that are strictly necessary for the platform to function. No advertising or analytics cookies are used. No general cookie banner is displayed.
Exception: the interactive Spots map uses Google Maps, which places third-party cookies only after your explicit consent via a popup. If you decline, the map does not load and no Google cookie is placed.
For full details on cookies used, see our Cookie Policy at gutup.ch/cookies.
8.
Your rights
Under the Swiss nFDP and GDPR, you have the following rights over your personal data:
- Right of access: obtain a copy of all personal data GutUp holds about you
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure: request deletion of your data, except where legal retention obligations apply
- Right to restriction: request temporary suspension of the processing of your data
- Right to portability: receive your data in a structured, machine-readable format
- Right to object: object to processing for direct marketing purposes at any time
- Withdrawal of marketing consent: withdraw your consent to marketing communications at any time
To exercise your rights, write to us at privacy@gutup.ch. We will respond within 30 days. You can also delete your account directly from your profile on gutup.ch.
Under the Swiss nFDP (Art. 19), you have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.
9.
Data breach notification
In the event of a security breach likely to result in a high risk to your rights, GutUp Sàrl will notify the FDPIC as soon as possible and no later than 72 hours after becoming aware of the breach (nFDP Art. 24 / GDPR Art. 33), inform affected users of the nature of the breach and the measures taken, and document every incident in an internal register.
We implement appropriate technical and organisational measures: encryption of data in transit and at rest, restricted and logged access, and certified hosting by Infomaniak.
10.
Changes to this policy
GutUp Sàrl reserves the right to modify this policy at any time. In the event of a material change, you will be notified by email at least 30 days before the change takes effect.
11.
Contact
GutUp Sàrl
Rue de Bourg 27, 1003 Lausanne, Switzerland
privacy@gutup.ch
gutup.ch