Legal
Privacy Policy
How VITAE handles your personal data, under the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).
Version 1.0 · 21 July 2026
1 · Who is responsible
The controller responsible for the processing described here is:
VITAE Respiratory Health & Longevity
Via Camara 58
6932 Breganzona, Switzerland
info@vitaeclinic.ch
If you have a question about this policy or about how your data is handled, write to that address. We answer data protection requests within 30 days.
2 · What this policy covers
It covers two different things, and the difference matters.
This website (vitaeclinic.ch). A brochure. It has no contact form, no database, no cookies and no analytics. Fonts and graphics are embedded in the page itself, so your browser does not contact any third-party server while you read it.
The VITAE platform (portal.vitaeclinic.ch). A separate, access-controlled system holding client accounts, consent records, breathing measurements and reports. If you become a client or a partner, that is where your data lives, and the sections below marked platform apply to you.
3 · What we process, and why
When you write to us
The booking and contact buttons on this site open your own email application. You decide what to send. We receive what you write — usually your name, your email address, a phone number if you include one, and the times that suit you. We use it to answer you and to arrange an appointment. The legal basis is the taking of steps at your request before entering into a contract, together with our legitimate interest in responding to enquiries.
When you visit this website
Our hosting provider records the standard technical information needed to serve and protect the site: IP address, browser type, the page requested and the time of the request. These logs are kept briefly and used only to operate the service, investigate faults and defend against attacks. The legal basis is our legitimate interest in a secure, functioning website. We do not use this data to build a profile of you, and we do not track you across other websites.
When you become a client — platform
To provide a BreathProfile assessment and the training that follows, we process:
- the account and contact details you give when registering;
- the consent you give, with the date and the version of the consent text;
- the measurements recorded during your assessment, and the reading and training plan produced from them;
- practice activity in the app, where you choose to save it;
- appointment, billing and correspondence records.
The legal basis for providing the service is our contract with you. Because information about your breathing relates to your health, it is sensitive personal data under the FADP and a special category of data under the GDPR: we process it only with your explicit consent, which you give before the assessment and may withdraw at any time.
When you work with us as a partner — platform
Partner organisations submit respiratory values under a pseudonymous reference. Identities stay with the partner. By design, VITAE cannot connect a reading to a named individual unless that person is our own client. We process partner staff account details to operate the portal, on the basis of our contract with the partner organisation.
4 · Collecting less on purpose
We deliberately collect less than we could. Two examples. Where the app asks you to confirm that a practice is safe for you, we record only that you confirmed, with the date and the version of the text — never your individual answers about your health. And in the partner portal we work from a pseudonymous reference, so a reading reaches our clinical team without a name attached.
5 · Who else processes data for us
We keep the number of suppliers small. Each acts only on our instructions, under a data processing agreement.
| Provider | Purpose | Where data is processed |
| Supabase | Platform database, file storage and backups | Zurich, Switzerland |
| Vercel | Website and application hosting | Frankfurt, Germany (EU) |
| Resend | Transactional email — confirmations and notifications | EU / United States |
Client records, reports and backups are held in Switzerland. Application hosting runs in the EU and processes data in transit. Where a provider processes data outside Switzerland or the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses together with the additional safeguards Swiss law requires.
We use no external artificial-intelligence service to process client data. That is a deliberate design decision, not an omission.
We never sell personal data, and we never share it for advertising. We disclose data to public authorities only where Swiss law obliges us to, and we tell you when we are permitted to.
6 · How long we keep it
| What | How long |
| Enquiry emails that do not lead to an appointment | 12 months |
| Website server logs | Up to 90 days |
| Client records, readings and reports | 10 years from the last contact |
| Contracts, invoices and accounting records | 10 years, as Swiss commercial law requires |
| Consent and access records | As long as the underlying record exists |
When a period ends we delete the data, or anonymise it so it can no longer be connected to you.
7 · Your rights
You may:
- ask what data we hold about you, and receive a copy;
- have inaccurate data corrected;
- have your data deleted, where we are not legally required to keep it;
- withdraw your consent at any time, which stops any further processing that relied on it;
- object to processing we base on legitimate interest;
- ask us to restrict processing while a question is resolved;
- receive the data you gave us in a common machine-readable format, or have it sent to another provider.
Write to info@vitaeclinic.ch. We may need to verify your identity before releasing data — that protects you, not us. Exercising these rights is free.
In the app and the portal you can also delete your account yourself, which removes your data apart from records we must keep by law.
If you believe we have handled your data improperly, you may complain to the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland. If you are in the EU or the UK, you may complain to your local supervisory authority.
8 · How we protect it
Data is encrypted in transit and at rest. Access to the platform requires two-factor authentication. Every access to a clinical record is logged, and those logs cannot be altered. Records are isolated at database level, so one organisation can never read another's. Access is limited to the people who need it for their work.
No system is perfectly secure. If a breach ever affects your data and presents a high risk to you, we will inform you and the FDPIC as the law requires.
9 · Automated decisions
We do not make decisions about you by automated means alone, and we do not profile you. Every reading is reviewed and signed off by a qualified person before it is released.
10 · Children
Our services are intended for adults. We do not knowingly collect data from anyone under 18. If you believe a minor has given us personal data, write to us and we will delete it.
11 · Changes to this policy
If our processing changes we will update this page and change the version and date at the top. If a change materially affects you, we will tell you directly.