Privacy notice
Privacy notice
version 2026-09-15.1
1. Who is responsible
Yaaka, Sierre, Switzerland (« Yaaka »), operates the Yaaka service and is the controller of the account, invoicing and technical data described below. Contact: contact@yaaka.ch.
For the register an association keeps in Yaaka — its members, their guardians, its committee — the association is the controller and Yaaka its processor (terms of service, art. 4). Questions about that data go to the association first; we help it answer.
2. What we collect
Account data: your e-mail address, your first and last name, the roles an association gives you, your language and theme, the security settings you configure (a second factor, passkeys) and the browsers that hold a session.
The association's register, on its behalf: its members and the people around them (parents, guardians, emergency contacts), their contact details and dates of birth, their categories and groups, their photos, the documents and decisions the association holds — medical certificates and health notes, consents, publication choices — and the fees it invoices them and their payments. Some of this is sensitive data and data about minors: the association decides what it records and answers for the lawfulness of that collection.
Invoicing data: the association's billing name, address and reference, the invoices we issue it and their payment.
Technical data: the server logs needed to run and secure the service (address, browser, timestamps, the pages requested), and an append-only audit trail of who changed what in a register, kept with that register. The service is intended for Swiss associations and may refuse connections from outside Switzerland and Liechtenstein: to do so it looks up the country of the connecting address in a database and keeps that answer for one hour.
Messages: what you write through the contact form (name, e-mail, association, message), and a copy of every e-mail the service sends on our behalf or on an association's — except the sign-in codes, which are never copied — kept in an archive mailbox of ours so that a question about what was sent can be answered.
3. What we use it for
To run the service for the association and its people, to secure access (sign-in codes, second factors, session and device lists), to answer your requests, to invoice the association's subscription and to meet our legal obligations. Nothing is sold, shared for marketing or used to train anything; we run no advertising and no third-party analytics.
4. Who receives it
The data is hosted by Oracle Cloud Infrastructure in Switzerland; each association's register is isolated at the database level. The e-mails the service sends go through an e-mail delivery provider acting on our instructions. Payments are bank transfers on a Swiss QR-bill: no payment processor and no card data. Our staff reach an association's screens only for support, as a named member and for the duration of one session, and every such access is recorded and shown on every page.
No data is transferred outside Switzerland by design. Should a provider ever process data abroad, we would do so only under the safeguards the Federal Act on Data Protection requires and would say so here.
5. How long we keep it
Server logs: ninety days. Account data: as long as the account exists, then deleted with it; the list of your devices, one year after each device's last use. An association's register: thirty days after the end of its contract, then deleted; backups are purged within ninety days. Invoicing records: ten years, as Swiss commercial law requires. Contact messages and the archive copies of sent e-mails: twelve months.
6. Your rights
You can ask for access to, correction or deletion of your personal data, object to a processing, and receive your data in a common format. For the data an association holds about you, address the association — it is the controller and we help it answer within the legal time. For your account and for our own processing, write to the contact above. You may also lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC). The Swiss Federal Act on Data Protection (FADP) applies.
7. Cookies
Only cookies and local-storage items strictly necessary to the service: the session, the protection of forms, your language and your theme. No consent banner is needed (art. 45c TCA); the terms of service, art. 12, say the same.
8. Changes
This notice carries a version. When it changes in substance, the associations' administrators are told, and the previous versions stay available on request.