Privacy policy
This statement explains, in accordance with the revised Swiss Data Protection Act (revFADP) and – where applicable – the GDPR, how PrepperGuide processes personal data. The connection to the website is encrypted end-to-end via TLS (https).
1. Controller
The controller responsible for data processing is the operator of PrepperGuide, Marco Baumgartner, Zeughausstrasse 4, 3400 Burgdorf, reachable at marco.baumgartner@prepperguide.ch.
2. Scope and principle
This statement applies to the website prepperguide.ch. Purely informational use of the website is possible without consent to advertising or analytics services. Optional advertising via Google AdSense is only served in a personalised manner after your consent, obtained through a certified consent management platform; without consent, no advertising cookies are set. We do not use any analytics tool (e.g. Google Analytics).
3. Processing purposes
- Operating and providing the website with its informational content.
- Account management (registration, sign-in, email confirmation, password reset).
- Providing the personal checklist and radio plan functions.
- Serving ads via Google AdSense – only with your consent.
- Security, stability and abuse prevention.
The processing of account and content data is necessary for the performance of the user agreement (Art. 6(1)(b) GDPR).
4. Data categories
- Account/master data: email address, password (stored only as a hash), timestamps.
- Self-created content: checklists and radio plans including frequency entries and info fields (e.g. call sign).
- Server logs / IP addresses: automatically collected technical data (see section 8).
- Two-factor data: when two-factor authentication is enabled, the authenticator key and the hashes of the recovery codes.
Accounts whose email address is not confirmed within 14 days are automatically and completely deleted.
5. Cookies and similar technologies
We use as few cookies as possible. Technically necessary cookies do not require consent; advertising cookies are only set after your consent.
- Language-choice cookie (.AspNetCore.Culture): stores your chosen language so that a later visit to the home page appears again in the same language. Technically necessary, no tracking.
- Sign-in and security cookies: the sign-in cookie only exists for signed-in users; an antiforgery cookie protects forms against forgery (CSRF). Both are technically necessary.
- Google advertising cookies: set only after your consent via the consent management platform (see section 6). We do not set any analytics cookies.
We host our fonts and the map library ourselves; as a result, no data is transferred to external providers (such as Google Fonts) when the page loads.
6. Google AdSense and consent management
To fund the site we integrate Google AdSense (Google Ireland Limited / Google LLC). Your consent is obtained by a Google-certified consent management platform («Google Privacy & Messaging» / Funding Choices). The advertising script is integrated via Google Consent Mode v2 with the default setting “denied”: without your consent, no advertising cookies are set and no personalised ads are served; for the technical delivery of ads, your IP address may be transmitted to Google. Personalised advertising only takes place after your consent. No advertising script is loaded on legal, emergency and sensitive content pages.
How Google, as a third party, uses cookies and processes data from this site is described here: Google – How Google uses data on partner sites.
You can withdraw or change your consent at any time with effect for the future via the “Cookie settings” link in the footer.
7. Map service (swisstopo / geo.admin.ch)
On the situation pages we display an interactive map. The national map tiles are loaded directly from the federal servers (wmts.geo.admin.ch, swisstopo); switchable thematic layers such as the FOEN groundwater overlay come from wms.geo.admin.ch. When the map loads, your IP address is transmitted to these federal services. If you do not open a map page, no such transmission takes place. The data protection provisions of the Confederation apply.
8. Server logs and IP addresses
During operation, client IP addresses appear in the server logs (web server and application logs). Purpose: operation, security and abuse prevention (including the automatic blocking of attacking IP addresses). Legal basis: overriding legitimate interest. The server is located in Switzerland. Retention: web server logs maximum 14 days, application logs maximum 30 days.
9. Email dispatch
For registration confirmation and password reset we send emails via Proton Mail (Proton AG, Geneva, Switzerland). This is necessary for account and security management; your email address and the content of the respective message are processed. Processing takes place in Switzerland.
10. Disclosure abroad
Within Google AdSense, data may be disclosed to Google in the USA. The disclosure relies on appropriate safeguards in the form of standard contractual clauses pursuant to Art. 16 para. 2 let. d revFADP. The map tiles are obtained from federal services located in Switzerland.
11. Retention
We store personal data only for as long as is necessary for the respective purpose:
- Account and self-created content (checklists, radio plans): until you delete your account.
- Web server logs: maximum 14 days.
- Application logs: maximum 30 days.
- Consent signals of the consent management platform: in accordance with Google's specifications.
- Other data: until the respective processing purpose ceases.
12. Archive of official warning messages
In the situation overview we archive official warning messages (e.g. from Alertswiss) verbatim, as we received them from the authority. The purpose is traceability: the message should remain verifiable if the authority withdraws it or takes it offline. It is not analysed for advertising purposes and not redistributed.
The basis for processing is our overriding interest in the traceability of published hazard situations (Art. 31 para. 2 revFADP). This concerns exclusively information that an authority itself published via a public warning channel.
Such messages may contain personal data, for example the name and business address of a responsible person. We remove this information automatically before the message is stored: the contact fields of official messages are removed in full and email addresses are replaced throughout the remaining text. Every removal is visibly marked in the archived document.
These are third-party contents delivered by machine. Automated filtering therefore cannot be guaranteed to be complete — for example if an authority includes a name at an unexpected place in the message text.
If you find personal data in an archived record, please report it to marco.baumgartner@prepperguide.ch. We will remove it. Independently of this, you have the rights of access, rectification and erasure under the revFADP (see the following section).
The record is deleted together with the corresponding event and is not retained beyond that.
13. Your rights and withdrawal
You have the right to information, rectification, deletion and release of your data (Art. 25 et seq. revFADP). Signed-in users can exercise these rights as self-service under “My data” in the account area and delete their account there at any time. You can withdraw consent given to advertising at any time via “Cookie settings” in the footer; the lawfulness of processing carried out until then remains unaffected.
14. Supervisory authority
You have the right to lodge a complaint with the competent supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
Federal Data Protection and Information Commissioner (FDPIC).
15. Contact
For data protection matters, please contact marco.baumgartner@prepperguide.ch. Further details can be found in the imprint.