Privacy Policy
Disclaimer: This is an informal translation. In case of ambiguity, the German version of this text applies.
Controller
The controller responsible for the processing described in this privacy policy is:
felixideas GmbH
Aeschenplatz 6
4052 Basel
Switzerland
Email: info@letsboot.ch
We process personal data confidentially and in accordance with applicable data protection law and this privacy policy. You can use our website without actively submitting personal data, although technical and usage data is processed automatically when you access it. Data transmission over the internet, for example by email, may have security gaps; complete protection against access by third parties is not possible.
Cookies
Our website may use cookies and comparable technologies to provide, secure, analyse and improve our services and to support advertising. Cookies are small text files stored by your browser. Some are deleted at the end of your visit (“session cookies”); others remain on your device for a period determined by the relevant service or until you delete them. You can restrict or delete cookies in your browser settings. Depending on the cookie, doing so may limit individual functions of the website.
Forms, inquiries and course registrations
Through our forms (contact, in-house request, sparring, waiting list, course registration) we collect the data you enter – depending on the form: name, company, email address, phone number, topic, number of participants, timeframe, your message, and for course registrations additionally the billing address and billing contact. We may also process technical data such as the time of submission, source page, browser and device details and your IP address to operate our forms and protect against abuse and spam.
We use this data to handle inquiries, send quotes and course information, manage business relationships, organise and run courses, issue invoices and comply with legal obligations. Where permitted, we may also use it to inform you about relevant courses and offers, improve and develop our services, perform internal analyses, maintain security and business records, and establish, exercise or defend legal claims.
Depending on the processing, we rely on the initiation or performance of a contract, compliance with legal obligations, your consent, or our legitimate interests. Our legitimate interests include operating and improving our services, maintaining security, preventing misuse, managing customers and business relationships, marketing our services, developing new offers, maintaining records and protecting our rights.
You may withdraw consent at any time with effect for the future. Withdrawal does not affect processing already carried out and does not require deletion where another legal basis or retention obligation applies.
Services and other recipients
We work with service providers, partners and other recipients who support our activities. Depending on the service and contractual arrangement, they may act as processors, joint controllers or independent controllers. We use recipients from the following categories:
- Hosting, infrastructure and operations – servers, container registry, code and deployment platforms, monitoring, security and backups
- Email, calendar, file storage and collaboration – communication, documents and internal coordination
- Customer, course and quote management – master data, inquiries, course dates and registrations
- Communication and newsletter delivery – information, course confirmations, transactional messages and marketing communications
- Course delivery – video conferencing, lab and learning platforms, venues, partners and the trainers we engage
- Accounting, invoicing and payment processing – including banks, payment providers, fiduciary and audit services
- Professional advice and legal compliance – legal, tax, insurance, security and other professional advisers as well as competent authorities
- Analytics, reach measurement and advertising – see the services listed below
- AI-assisted and automated tools – drafting, translation, summarisation, classification, analysis, customer support, workflow automation, quality assurance and service development; where appropriate, results are subject to human review
We may disclose personal data to these recipients and to other recipients within these categories where necessary for the purposes described in this policy, to perform contracts, operate and develop our business, protect our rights, comply with legal obligations, or in connection with a reorganisation, financing, sale or transfer of all or part of our business.
We may replace providers or engage functionally comparable providers within these categories. We update this policy where required by law or where a change materially affects the processing. Where a service requires consent, we use it only after consent has been given; other services may be used on another basis permitted by applicable law, with an objection mechanism where required.
Disclosure abroad
Recipients may process personal data in Switzerland and abroad. Based on the services currently used, relevant destinations include member states of the EEA, the United Kingdom and the USA. The countries involved may change when providers or their processing locations change; we provide or update more specific information where required by law.
Where the destination does not provide adequate data protection, we use recognised safeguards where required, such as standard contractual clauses with any necessary Swiss supplements, binding corporate rules or additional contractual and technical measures. Transfers may also be based on an applicable statutory exception, for example where necessary to perform a contract. For transfers to the USA, adequacy may apply to recipients certified under the Swiss-US Data Privacy Framework.
Retention
We retain personal data for as long as reasonably necessary for the purposes described. We may retain it beyond that period where required by law, contract or internal documentation duties, during applicable limitation periods, to document consent or an objection, maintain suppression lists, investigate security incidents, collect claims or establish, exercise or defend legal rights. Data relating to booked courses and invoices is generally retained for ten years.
Deletion and anonymisation take place according to reasonable operational cycles. Residual copies may remain temporarily in backups, archives and technical systems. After you unsubscribe from marketing, we may retain limited information needed to record the objection, prevent further communications and demonstrate compliance.
Newsletter and marketing communications
If you subscribe to our newsletter, we process your email address and information used to document the subscription. We use this data to send information about our courses, dates and offers and to evaluate use of the newsletter, for example whether messages are opened or links are used. A service provider may assist with delivery and analysis.
Where permitted by law, we may also inform current, former or prospective customers and business contacts about similar or relevant services. Depending on the circumstances, we rely on consent or another permitted basis, including applicable existing-customer exceptions. You can object to direct marketing at any time, in particular through the unsubscribe link in an email or by contacting us.
Analytics, reach measurement and advertising
We want to understand how our website is used and advertise our courses where they are relevant. For this purpose, we may use analytics, conversion tracking, audience measurement and remarketing services. These may process usage and device data such as pages viewed, time of access, approximate location, browser and device details, identifiers and IP address, use cookies or comparable technologies, and transmit data to their providers, including to the USA.
These services are centrally managed via Google Tag Manager (Google Ireland Limited). We currently use:
- Google Analytics 4 – web analytics (Google Ireland Limited): privacy policy
- Google Ads – conversion measurement and remarketing (Google Ireland Limited): more information
- LinkedIn Insight Tag – campaign measurement and audience building (LinkedIn Ireland Unlimited Company): privacy policy
- Microsoft Advertising (UET) – conversion measurement and remarketing on Microsoft/Bing ads (Microsoft Ireland Operations Limited): privacy policy
- Leadinfo – identification of companies based on the IP address, enriched with publicly available company information (Leadinfo B.V., Rotterdam): opt out
We may replace or add functionally comparable services for the purposes and data categories described above. Depending on the technology, purpose, risk and applicable law, we use these services based on consent or another permitted basis, with an appropriate consent or objection mechanism. Where renewed consent or additional notice is required, we provide it before the relevant processing.
Consent and withdrawal
Where consent is required, we request it before the relevant processing. You may withdraw consent with effect for the future through the settings made available on the website or by contacting us. Your choice may be stored locally in your browser and considered on future visits. Withdrawal does not affect prior processing and does not prevent processing based on another permitted ground.
Where applicable, we use consent-management technologies such as Google Consent Mode to communicate and implement your selection. The data transmitted and the behaviour of individual services depend on the selected settings and the configuration of the respective service.
Your rights
Subject to the conditions, exceptions and limitations of applicable law, you may request access to and a copy of your personal data, correction of inaccurate data, deletion or restriction of processing, object to processing, withdraw consent and request the release or transfer of certain data. In particular, you may object to direct marketing at any time.
Requests are generally handled free of charge, but we may verify your identity and rely on statutory restrictions, refuse manifestly unfounded or excessive requests, or charge a fee where permitted by law. To exercise your rights, contact us using the details above. You may also report a suspected data protection violation to the Swiss Federal Data Protection and Information Commissioner or, where applicable, another competent supervisory authority.
Changes to this policy
We may amend this policy when our processing, services or legal obligations change. The version published on the website applies from its stated date. Where required, we provide additional notice or obtain renewed consent.
Last updated: 19 July 2026