PRIVACY POLICY
This privacy policy explains how noligy GmbH (“we”, “us”, “our”) collects, uses and protects personal data when you visit www.pascalheimlicher.com (the “Website”) and use our courses and services. We process personal data in accordance with the Swiss Federal Act on Data Protection (revFADP / revDSG) and, insofar as it applies, the EU General Data Protection Regulation (GDPR).
1. CONTROLLER
noligy GmbH
Sunnenbergstrasse 11, 8633 Wolfhausen, Switzerland
Email: info(at)noligy.com
Data protection contact: Pascal Heimlicher, mail(at)pascalheimlicher.com
We have not appointed a data protection officer or an EU representative, as we are not legally required to do so.
2. SCOPE AND LEGAL BASES
For visitors in Switzerland, processing is based on the revDSG. For visitors in the European Economic Area (EEA) and the United Kingdom, we process personal data on the following legal bases under Art. 6(1) GDPR:
– Consent (Art. 6(1)(a)) – e.g. newsletter sign-up, non-essential cookies and analytics;
– Performance of a contract (Art. 6(1)(b)) – e.g. creating an account, granting course access, processing payments;
– Legal obligation (Art. 6(1)(c)) – e.g. retention of accounting records;
– Legitimate interests (Art. 6(1)(f)) – e.g. secure and stable operation of the Website, fraud prevention, spam protection.
3. HOSTING AND SERVER LOG FILES
Our Website is hosted by Hostinger (Hostinger International Ltd.). When you access the Website, the hosting provider automatically collects and stores information in server log files that your browser transmits, including IP address, date and time of the request, browser type and version, operating system, and the referrer URL. This data is required to display the Website securely and reliably and is processed on the basis of our legitimate interest (Art. 6(1)(f) GDPR). A data processing agreement is in place with our hosting provider.
4. COOKIES AND CONSENT MANAGEMENT
Our Website uses cookies and similar technologies. Essential cookies are required for the Website to function and are set on the basis of our legitimate interest. Non-essential cookies (e.g. analytics, embedded third-party content) are only set with your consent.
We use Borlabs Cookie as our consent management tool to obtain, manage and document your cookie choices. Borlabs stores your consent settings in a cookie on your device so that we can respect your preferences. You can withdraw or change your consent at any time via the cookie settings on our Website.
5. CONTACT FORM AND reCAPTCHA
If you contact us via a form or by email, we process the data you provide (such as name, email address and your message) in order to handle your request. The legal basis is Art. 6(1)(b) GDPR (pre-contractual/contractual measures) or our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR).
To protect our forms against spam and abuse, we use Google reCAPTCHA provided by Google Ireland Ltd. / Google LLC. reCAPTCHA analyses information such as IP address, browser data and user behaviour to distinguish human users from bots. This may involve a transfer of data to Google servers, including in the USA. The legal basis is our legitimate interest in spam and abuse prevention (Art. 6(1)(f) GDPR) and/or your consent. Google’s privacy policy: https://policies.google.com/privacy.
6. USER ACCOUNTS AND ONLINE COURSES (LearnDash LMS)
To purchase and access our online courses, you create a user account. We process your registration and profile data, login credentials, purchase history and course progress. Our courses are delivered through LearnDash LMS, which runs on our own Website and records learning progress, quiz results and completion status so that we can provide the service. Course videos are delivered via online streaming and certain materials may be offered as digital downloads. The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR).
7. PAYMENTS (Stripe and PayPal)
Payments are processed by external payment service providers. Depending on the payment method you choose, your payment and billing data is transmitted to and processed by:
– Stripe – Stripe Payments Europe Ltd. / Stripe, Inc. (https://stripe.com/privacy);
– PayPal – PayPal (Europe) S.à r.l. et Cie, S.C.A. (https://www.paypal.com/privacy).
These providers act as independent controllers for the payment transaction. We do not store full credit card numbers on our own systems. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR).
8. NEWSLETTER (FluentCRM and Amazon SES)
If you subscribe to our newsletter, we process your email address and any additional details you provide. We use the double opt-in procedure: after signing up, you receive a confirmation email and your address is only added to our list once you confirm. We manage subscriptions using FluentCRM (hosted on our own Website) and send emails via Amazon Simple Email Service (Amazon SES), provided by Amazon Web Services, Inc. (USA). We record your sign-up and confirmation to document your consent, and we may measure whether emails are opened and links are clicked in order to improve our communications.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can unsubscribe at any time using the link in every newsletter or by contacting us; withdrawal does not affect the lawfulness of processing carried out before withdrawal.
9. WEB ANALYTICS (Google Analytics)
With your consent, we use Google Analytics 4, a web analytics service provided by Google Ireland Ltd. (“Google”). Google Analytics uses cookies and similar identifiers to help us understand how visitors use our Website (e.g. pages viewed, session duration, approximate location, device and browser information). IP addresses are shortened/anonymised by Google within member states of the EU/EEA before any transfer. The information generated may be transmitted to and stored by Google, including on servers in the USA.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you provide via our cookie banner and can withdraw at any time through the cookie settings. More information: https://policies.google.com/privacy.
10. AUTOMATION (Uncanny Automator)
We use Uncanny Automator to automate internal workflows on our Website, for example granting course access after a successful purchase or adding a customer to a newsletter list after they have given consent. This tool processes account and activity data already held within our systems in order to trigger these actions. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interest in efficient operations (Art. 6(1)(f) GDPR).
11. DATA RECIPIENTS AND PROCESSORS
We only share personal data where necessary and lawful, in particular with the service providers named above acting as processors or independent controllers (hosting, payment, email delivery, analytics, anti-spam), and with authorities or advisors where we are legally required to do so. We conclude data processing agreements with our processors where required.
12. INTERNATIONAL DATA TRANSFERS
Some of our providers (e.g. Google, Amazon Web Services, Stripe, PayPal) may process data outside Switzerland and the EEA, including in the United States. Where this occurs, the transfer is safeguarded by appropriate measures, such as the European Commission’s Standard Contractual Clauses, the equivalent Swiss transfer mechanisms recognised by the Federal Data Protection and Information Commissioner (FDPIC), and/or certification under the EU–U.S. Data Privacy Framework, together with supplementary measures where appropriate.
13. RETENTION
We retain personal data only for as long as necessary for the purposes described in this policy or as required by law. Accounting and transaction records are kept for the statutory retention period (generally ten years under Swiss law). Newsletter data is kept until you unsubscribe. Account and course data is kept for the duration of your account and deleted or anonymised thereafter, unless longer retention is legally required.
14. DATA SECURITY
We use appropriate technical and organisational measures to protect your data, including TLS/SSL encryption for data transmitted through our Website. Please note that no method of transmission over the internet is completely secure.
15. YOUR RIGHTS
Subject to applicable law, you have the right to request access to your personal data, to have inaccurate data corrected, to have data deleted, to restrict or object to processing, and to receive certain data in a portable format. Where processing is based on consent, you may withdraw that consent at any time. To exercise your rights, contact us at mail(at)pascalheimlicher.com.
You also have the right to lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC), https://www.edoeb.admin.ch. In the EEA you may contact the data protection authority of your country of residence.
16. CHANGES TO THIS POLICY
We may update this privacy policy from time to time to reflect changes in our services or legal requirements. The current version published on this page applies.
Last updated: August 2026