Privacy Policy
Last updated: 17 September 2026
This privacy policy explains which personal data the Tech Club HSG processes when you visit this website, apply for membership or take part in our events, why we do so and which rights you have. It is based on the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies, this policy also serves to meet its requirements.
1. Controller
Tech Club HSGUniversity of St. Gallen
TechClub
Postfach 64
Dufourstrasse 50
9000 St. Gallen
Switzerland
For all questions about data protection, please write to the address above.
2. Visiting this website
When you open this website, your browser automatically transmits technical data to our hosting provider: IP address, date and time, the page requested, referrer, browser and operating system. This data is needed to deliver the website, keep it secure and analyse errors. It is kept in server logs for a limited time.
No cookies, no advertising. This website does not set cookies, does not use advertising tools and does not build user profiles. Fonts are served from our own server; no data is sent to font providers.
Anonymous statistics. To understand how the website is used, we use Vercel Web Analytics. It counts page views, referring pages, country, device type and browser without cookies and without storing IP addresses; visitors are not tracked across days or websites. We use these statistics only in aggregated form to improve the website.
Event images. Some event images are loaded directly from the servers of the event platform UNICLUBS. When a page shows such an image, your browser connects to those servers, which receive your IP address.
3. Membership application
When you apply for membership through our form, we process:
- first and last name, email address
- optionally: phone number, study programme, expected graduation year, your message to us
- whether you would like to receive news about events, and the time you accepted this privacy policy
- a payment reference we assign to your application, and later the receipt of your membership fee
We use this data to handle your application, to send you the payment details, to confirm your payment and to manage your membership. The legal basis is the membership relationship you are asking to enter (Art. 6(1)(b) GDPR, where applicable).
Protection against abuse. To prevent automated or mass submissions, we process a pseudonymised form of your IP address and email address to limit the number of applications. This data is deleted within 24 hours.
Inquiries from companies
When you contact us through the partnership form, we process your company, name, email address, optionally your role, phone number and website, your areas of interest and your message. We use this data to answer your inquiry and to prepare a possible collaboration. The same protection against abuse applies as for membership applications.
4. Members' area, events and emails
Members log in to our internal club app with a login link sent by email. For running the club we process:
- Profile: the details from your application and, if you add them, your LinkedIn address, a short bio and a profile picture link, as well as the time of your last login
- Events: your registrations, waitlist position, number of guests, a check-in code and the time you checked in at the event (attendance record)
- Offices: for members who hold an office, which position they held and when; this history is kept permanently so the club can trace responsibilities
- Active members: task assignments and attendance at internal meetings
- Board notes: internal notes about a person, visible to the board only
- Change log: which user changed which record and when, to keep club administration traceable
- Email log: recipient address, subject and delivery status of emails sent by the app
News about events is only sent if you agreed to it. Every such email contains a link to unsubscribe, and you can withdraw your consent at any time without affecting your membership.
5. Service providers
We use carefully selected service providers who process data on our behalf:
- Vercel Inc. (USA): hosting of this website and of the club app. Processing, including form submissions, takes place in Ireland; requests are routed and content is delivered through Vercel's worldwide network.
- Supabase Inc. (USA): database and login for the club app, including sending the login emails. The database is located in Ireland. Supabase keeps its own user record with your email address and session data.
Because these companies are based in the USA, data may also be accessed from the USA. Where this is the case, we rely on the safeguards recognised by law, such as the Swiss-U.S. and EU-U.S. Data Privacy Framework or standard contractual clauses.
We do not sell personal data and do not pass it on for advertising purposes.
6. Links to other platforms
This website links to LinkedIn, Instagram, UNICLUBS, Microsoft Forms and partner companies. Only when you click such a link does the respective provider receive data from you; its own privacy policy then applies.
7. Retention
We keep personal data only as long as it is needed for the purposes described above, and as long as statutory retention obligations require, for example for accounting records of membership fees. Data used to protect against abuse is deleted within 24 hours. The history of club offices and the change log are kept permanently, as described in section 4.
8. Your rights
You have the right to request information about the data we hold about you, to have incorrect data corrected, to have data deleted or its processing restricted, to object to processing, to receive your data in a common format and to withdraw consent at any time. To exercise these rights, contact us using the details in section 1.
You may also lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC).
9. Changes
We may update this privacy policy when our website or our processes change. The version published on this page applies. See also our imprint.