Privacy Policy
This privacy notice explains how personal data is processed when you visit this website. Letzte Aktualisierung: 2026-05-17
Controller
Signalfeuer GmbH i.G.
Solecht 42, 3303 Jegenstorf, Switzerland
Represented by: Manuel Gysin, Managing Director
Email: info@signalfeuer.ch
Solecht 42, 3303 Jegenstorf, Switzerland
Represented by: Manuel Gysin, Managing Director
Email: info@signalfeuer.ch
Access data
When accessing the website, certain technical information may be processed (truncated IP address, date/time, user agent). This is used to provide and maintain the website securely and is not used to identify you.
Recipients / Processors
To operate the website and handle course registrations, we use the following external services within the EU/CH:
- Hetzner Online GmbH (Germany / Finland) – hosting of the Kubernetes cluster and database.
- Lettermint (Netherlands) – sending transactional and confirmation emails.
- Mollie B.V. (Netherlands) – payment processing for bank transfers / cards.
- Plausible Community Edition – self-hosted on our infrastructure (no external data transfer).
- Gnosis Chain (public blockchain) – only for the optional minting of NFT badges. On-chain data is public.
Workshop registration data
For workshop registrations we process name, email address, and – voluntarily – other details (preferred dates, prior experience, notes). For outdoor and survival courses this may include health basics (allergies, medications, emergency contact) which we need for course safety (Art. 31 para. 2 revFADP Switzerland, overriding interest in protecting life/health). These sensitive fields are stored field-encrypted in our database (AES-256-GCM) and retained for 36 months after the course (limitation period for tort claims under Art. 60 OR), then deleted. For anonymous Ghost Protocol bookings the physical burn-bag procedure applies (see GTC §9) – the envelope is destroyed unprocessed after the course if no emergency occurred.
Newsletter
If you subscribe to the newsletter via the footer form, your email address is processed for the purpose of sending the newsletter. We use a double-opt-in procedure: you receive a confirmation email and only become a recipient after clicking the link. We store the confirmation timestamp and a hashed IP marker as proof of consent. You can unsubscribe at any time via the link in every email; after unsubscribing your data is deleted within 30 days. Dispatch is handled by Lettermint as data processor (see Recipients section).
Analytics (Plausible, self‑hosted)
We use Plausible Analytics as the self‑hosted Community Edition on our own Kubernetes cluster in the EU (Hetzner, Helsinki). No cookies are set, no personal profiles are built and no data is shared with third parties. Plausible only works with aggregated statistics (e.g., pageviews, referrers, devices). The data never leaves our infrastructure.
Contact
If you contact me by email, the information you provide will be processed to handle your request. Data is retained only as long as necessary to respond.
Participant portal
When you sign in to the participant portal, we set a session cookie (HttpOnly, SameSite=Lax, rolling 30-day lifetime to avoid repeated logins) and a non-HttpOnly CSRF cookie. Both are technically necessary for the login flow; you can end them at any time via the logout button. Magic-link login tokens are stored for 15 minutes. On login we record an IP-hash abuse marker to defend against brute-force attempts. All administrative actions are recorded in an audit log with timestamp and actor id; retention is indefinite since the volume is negligible.
Ghost Protocol & anonymity
Anonymously redeemed ghost codes create a pseudonymous user account without an email. If you mint an NFT badge on Gnosis Chain, the wallet address you supply is linked on-chain with your pseudonym — this partially undermines your anonymity against public blockchain observers. For maximum anonymity, use a freshly created wallet funded with cash.
Your rights
Depending on applicable law, you may have rights to access, rectify, erase, or restrict processing. Please send requests to info@signalfeuer.ch.