Privacy Policy
If you have any questions or concerns, please feel free to contact us!
If you have any questions or concerns, please feel free to contact us!
Last updated: 16 August 2026
GenossenSchaffen GmbH
Bergstrasse 12
8044 Zurich
Email: info@genossenschaffen.ch
This privacy policy applies to the use of the website www.genossenschaffen.ch, the registration and management of a subscription for apartment notifications, the sending of notifications by email and – if selected – by WhatsApp, the verification of eligibility for the KulturLegi discount, as well as to billing via Chargebee/Stripe.
The following categories of personal data may be processed:
Processing takes place for the following purposes:
The legal bases are in particular the necessity for the performance of the contract, our legitimate interests in secure operation, and statutory retention obligations.
Cookiebot is used on the website. Via the Cookiebot script embedded at the bottom of the page, you can at any time see which cookies are set and give, change or withdraw your consent for non-essential cookies.
The following are used
. The current list is available from Cookiebot.
We use the following categories of service providers:
These service providers process data only in accordance with our instructions and only insofar as this is necessary for the provision of the respective service.
The main storage takes place in the EU (AWS Frankfurt and Ireland, Chargebee EU) and – for the KulturLegi discount – in Switzerland (AWS Zurich). Disclosure to other countries, in particular the USA, takes place in connection with the use of Postmark (email delivery), Stripe (payment processing), Meta (conversion measurement) and Sentry (error logging). In these cases we rely on the Swiss adequacy decision (e.g. Swiss-U.S. Data Privacy Framework) or on standard contractual clauses recognised by Switzerland.
Personal data is retained only for as long as necessary for the purposes stated above.
We send
We take appropriate technical and organisational measures to protect the data (access restrictions, encryption, logging). Complete protection against all risks cannot be guaranteed.
Under the Swiss Data Protection Act (DSG), data subjects have in particular the rights to information (Art. 25), rectification, erasure/anonymisation, data portability (Art. 28) and withdrawal of consent given.
In the event of a data breach likely to result in a high risk, we report the incident to the FDPIC and – where necessary – to the data subjects (Art. 24 DSG; Art. 15 VDSG).
We may amend this privacy policy if our services or the legal requirements change. The version published on the website at any given time applies.
When you use the KulturLegi discount, we ask KulturLegi/Caritas to confirm that you are eligible. To perform this check, we send your card’s issuing office and number together with your date of birth over an encrypted connection. We keep only the result: valid or invalid. We do not retain any other information returned by KulturLegi.
We do not store the card number or your date of birth in plain text. Instead, we use a secret key to create a pseudonymous identifier from the issuing office and card number. The original card number cannot be recovered from this identifier. We store the identifier in AWS in the Zurich region together with the technical references needed to manage the reservation, discount code and associated subscription. This ensures that each card can be linked to only one active discount.
Temporary reservations expire after a short period. We retain the card identifier for as long as the discounted subscription remains active. When the subscription ends, we release the record and delete it automatically after approximately 30 days. Chargebee and Stripe process payment and subscription data as described above.