Skip to content

In this privacy policy, Fondation Aline (“we”, “us”) explains how we process personal data. This applies in particular to visits to our website fondationaline.org, funding applications, donations, purchases in our shop, Sheltered Funds and any other communication with us.

Personal data means any information relating to an identified or identifiable natural person. Additional information may apply to specific processing activities, for example in application forms, contracts or terms of participation.

If you provide us with personal data of other persons (e.g. project participants, beneficiaries or family members), please make sure that you are entitled to do so, that the information is correct and that the persons concerned are aware of this privacy policy.

Controller and contact

The controller responsible for the data processing described in this privacy policy is:

Fondation Aline
Matthofstrand 8, 6005 Lucerne, Switzerland
Postal address: P.O. Box 3770, 6002 Lucerne
Email: welcome@fondationaline.org
Phone: +41 41 368 10 78

Please send any data protection enquiries to this address, preferably by email with the subject line “Data protection”.

Applicable law

This privacy policy is based on the Swiss Federal Act on Data Protection (FADP), in force since 1 September 2023, and the Data Protection Ordinance (DPO). Where the EU General Data Protection Regulation (GDPR) also applies in an individual case, for example because we address persons in the EU or the EEA, we additionally take its requirements into account.

The terms used in this privacy policy also cover the corresponding terms of the GDPR.

Personal data we process

We mainly process data that you provide to us yourself and data generated when you use our website. This concerns in particular applicants and project partners, donors, supporting members, founders of Sheltered Funds, business partners, website visitors and newsletter subscribers.

  • Master and contact data: name, address, email, phone number, language, where applicable position and organisation, as well as interests and communication preferences.
  • Application and project data: information contained in funding applications and their enclosures, for example project description, budget, contact persons, beneficiaries and project reports. Depending on the project, this may include sensitive personal data (section 5).
  • Donation and payment data: amount, date, payment method, bank details for transfers and donation receipts. We do not receive credit card data (section 7).
  • Contract data: information relating to Sheltered Funds, partnerships and other agreements.
  • Communication data: content of emails, letters, phone calls and meetings.
  • Compliance data: information on the identification and origin of contributions, insofar as this is necessary to comply with legal obligations, for example to combat money laundering or to comply with sanctions.
  • Technical data: IP address, device and browser information, date and time of access, pages viewed, referring website and cookie data (section 6).
  • Data from third parties and public sources: for example from the commercial register, the media and the internet, or from partner organisations, banks, advisers and authorities, insofar as this is appropriate for reviewing applications, projects or donor relationships.

Purposes and legal bases

We process personal data for our charitable activities in the fields of health and sport, culture and social affairs, and ethics and society. Under Swiss law, we generally do not require a legal basis for this; where necessary, we rely on the grounds for justification under Art. 31 FADP. Where the GDPR applies, the legal bases set out in the table apply.

 

Purpose

 

Legal basis under the GDPR

 

Reviewing, deciding on and monitoring funding applications and projects

 

Art. 6(1)(b) (contract, pre-contractual measures); Art. 6(1)(f) (legitimate interest in the proper use of funds)

 

Receiving and acknowledging donations, donation receipts

 

Art. 6(1)(b); Art. 6(1)(c) (accounting and tax obligations)

 

Managing Sheltered Funds and partnerships

 

Art. 6(1)(b)

 

Responding to enquiries and general communication

 

Art. 6(1)(b) and (f)

 

Newsletter

 

Art. 6(1)(a) (consent)

 

Informing existing donors about projects, events and fundraising appeals

 

Art. 6(1)(f) (direct marketing)

 

Attracting new donors, including from publicly accessible sources

 

Art. 6(1)(f)

 

Operation, security and further development of the website

 

Art. 6(1)(f); Art. 6(1)(a) for non-essential cookies

 

Further development of our activities, media monitoring

 

Art. 6(1)(f)

 

Compliance with legal obligations, e.g. towards the foundation supervisory authority and tax authorities, anti-money laundering, sanctions

 

Art. 6(1)(c) and (f)

 

Enforcement of claims, defence in proceedings

 

Art. 6(1)(f)

 

Protection of persons, premises and IT systems

 

Art. 6(1)(f)

 

You may object to the use of your data for marketing purposes at any time; we will then add you to a blocking list. You may withdraw any consent you have given at any time with effect for the future.

Sensitive personal data in funding applications

Funding applications in the fields of health and social affairs may contain information about health or social assistance measures. Such data is considered sensitive (Art. 5(c) FADP, Art. 9 GDPR).

We only process it to the extent necessary to review and implement the application, and on the basis of the explicit consent of the person concerned. Access is limited to the Board of Trustees, the management and the persons involved in the review.

Please only submit such information if it is required for the application, and anonymise information about beneficiaries wherever possible.

Website, cookies and analytics

Server log files. When you visit our website, our hosting provider Parallactic GmbH, Zurich, records technically necessary data such as IP address, time, page accessed and browser type. This data is used to operate the website securely and is retained for a maximum of twelve months.

Cookies. We set technically necessary cookies, for example for language selection, without consent. We only use all other cookies and similar technologies, for example for analytics or marketing, with your consent given via our cookie banner. You can change your selection at any time via “Cookie settings” or delete and block cookies in your browser; certain functions may then be restricted.

Web analytics. With your consent, we use Google Analytics 4 from Google Ireland Limited, Dublin, Ireland. Google analyses how our website is used and provides us with aggregated reports. According to Google, Google Analytics 4 does not store IP addresses. Data may be transferred to Google LLC in the USA; Google LLC is certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework. We retain analytics data for 14 months. Further information can be found in Google’s privacy policy (policies.google.com/privacy).

Embedded content. We only load content from third-party providers, such as maps or external videos, after you have given your consent.

Donations, shop and payment processing

Online donations and shop purchases are processed via the payment service provider Payrexx AG, Thun, Switzerland. Payrexx and the payment institutions involved process your payment data, such as card details, under their own responsibility and in accordance with their own data protection provisions. We only receive the information we need for booking, acknowledgement and donation receipts, for example name, address, email, amount and payment method.

For donations by bank transfer, we receive your name, account details and the amount paid from our bank, PostFinance Ltd, Bern.

We retain donation records for ten years in accordance with statutory bookkeeping obligations.

Newsletter and social media

Newsletter. We only send our newsletter with your consent, which you give via a confirmation link (double opt-in). You can unsubscribe at any time via the link in each issue. We analyse whether and when newsletters are opened and links are clicked in order to improve our communication.

Social media. We maintain profiles on Facebook (Meta Platforms Ireland Ltd.) and LinkedIn (LinkedIn Ireland Unlimited Company). On our website, we only link to these profiles; the respective provider only receives data from you when you click on a link. We are jointly responsible with Meta for the statistics relating to our Facebook page (Art. 26 GDPR). Otherwise, the providers process your data under their own responsibility in accordance with their data protection provisions.

Disclosure to third parties

We only disclose personal data insofar as this is necessary and permissible for the purposes set out in section 4. Recipients include in particular:

  • Service providers processing data on our behalf: for example for IT, hosting, email and cloud services, payment processing, accounting, auditing and the entity mandated with the management and administration of the foundation, Fineva AG, Lucerne. We contractually oblige these service providers to comply with data protection requirements.
  • Banks and payment service providers.
  • Project partners and beneficiaries, insofar as this is necessary for reviewing, implementing and monitoring a funded project.
  • Authorities and courts, in particular the competent foundation supervisory authority and the tax authorities, where we are obliged or entitled to do so.
  • Advisers such as lawyers and fiduciaries, as well as other parties to legal proceedings.
  • The public: we only publish names of project partners, project descriptions and images, for example on our website or in annual reports, with the consent of the persons concerned.

Transfers abroad

We mainly process personal data in Switzerland. However, recipients may also be located in EU and EEA countries and in the USA. In the case of funded projects abroad, data may also be transferred to project partners in the respective project country.

We transfer data without further safeguards to countries whose level of data protection has been recognised as adequate by the Swiss Federal Council (Annex 1 DPO, including all EU and EEA countries). Recipients in the USA certified under the Swiss-U.S. Data Privacy Framework have also been deemed to provide adequate protection since 15 September 2024.

We only transfer data to all other countries with appropriate safeguards, generally the standard contractual clauses of the European Commission (Implementing Decision 2021/914, https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj) with the adjustments required for Switzerland. In exceptional cases, we rely on the statutory exceptions under Art. 17 FADP, for example where the transfer is necessary for the performance of a contract or the implementation of a project, where you have consented, or where legal claims are concerned.

Retention period

We retain personal data for as long as necessary for the respective purpose, our legal obligations or legitimate interests, for example for evidentiary purposes as long as claims can be asserted. We then delete or anonymise it.

  • Business records, vouchers and donation records: ten years
  • Documents relating to funded projects: ten years after completion of the project
  • Rejected funding applications: two years after the decision
  • Newsletter data: until you unsubscribe
  • Server log files: a maximum of twelve months

Data security

We protect personal data against unauthorised access, loss and misuse by means of appropriate technical and organisational measures. These include access restrictions, instructions and training, encrypted transmission (TLS), encryption of data carriers, backups and regular checks. However, no one can guarantee complete security when transmitting data over the internet.

Obligation to provide data

As a rule, you are under no legal obligation to provide us with personal data. However, without the information required for an application, a donation or a contract, we cannot process it. Likewise, the website cannot be used without the technical data required for data traffic, such as the IP address.

Profiling and automated individual decisions

We do not make automated individual decisions within the meaning of Art. 21 FADP and Art. 22 GDPR. Decisions on funding applications are always made by people.

Your rights

Within the scope of the applicable data protection law, you have in particular the following rights:

  • Access to your personal data processed by us (Art. 25 FADP, Art. 15 GDPR)
  • Rectification of inaccurate data
  • Erasure or restriction of processing
  • Objection to processing, in particular for direct marketing
  • Receipt or transfer of your data in a commonly used electronic format (Art. 28 FADP, Art. 20 GDPR)
  • Withdrawal of consent with effect for the future

To exercise your rights, please contact us at the address given in section 1. Where your identity cannot otherwise be established, we may request proof of identity. We generally respond within 30 days. Access is in principle free of charge; only in cases of disproportionate effort may we request a contribution to costs of up to CHF 300, of which we will inform you in advance.

We may restrict your rights to the extent provided for by law, for example where we must retain data due to legal obligations or need it to enforce claims.

You may also lodge a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern (www.edoeb.admin.ch). In the EU and the EEA, the supervisory authority of your country of residence is competent.

Changes

We may amend this privacy policy at any time. The current version published on our website applies. Where this privacy policy forms part of an agreement with you, we will inform you of material changes by email or in another appropriate manner.