Privacy Policy
How we collect, use and protect personal data.
- Owner
- Data protection lead
- Version
- v1.0
- Effective date
- 25 July 2026
- Next review
- 25 July 2027
01Introduction
"bee Charity" Verein (“BeeCharity”, “we”, “us”, “our”) is a Swiss association (Verein) with its seat in Dübendorf, Canton of Zurich, registered under UID CHE-457.076.818. We are committed to protecting the privacy of everyone who visits our website, donates, volunteers, partners with us or otherwise shares information with us.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights available to you. It applies to https://www.beecharity.org and to any personal data we process in the course of our activities.
This document has been formally adopted by the board and is published as part of our open governance; it describes the standards we hold ourselves to.
02Definitions
To keep this policy clear, we use the following terms:
- “Personal data” means any information relating to an identified or identifiable natural person.
- “Processing” means any operation performed on personal data, such as collecting, storing, using, disclosing or deleting it.
- “Data subject” means the individual to whom the personal data relates — for example a visitor, donor, volunteer or partner contact.
- “Controller” means the party that decides why and how personal data is processed. For the purposes of this policy, the controller is "bee Charity" Verein.
- “Processor” means a third party that processes personal data on our behalf and under our instructions.
- “FADP” means the revised Swiss Federal Act on Data Protection (revDSG), in force since 1 September 2023.
- “GDPR” means the EU General Data Protection Regulation (Regulation (EU) 2016/679), which may apply to visitors and donors in the EU/EEA.
03Legal Basis
Under the Swiss FADP, we may process personal data where we have a legitimate purpose and the processing is proportionate, carried out in good faith and transparent. We do not require a separate statutory “legal basis” in the same way as the GDPR, but we always ensure a clear and lawful reason for every processing activity.
Where the GDPR applies (for example, to individuals in the EU/EEA), we rely on one or more of the following legal bases:
- Consent — for example, when you subscribe to updates or accept non-essential cookies.
- Contract — where processing is necessary to fulfil a request, such as administering a donation or volunteer application.
- Legal obligation — where we must process data to comply with applicable law, such as financial record-keeping.
- Legitimate interests — where processing is necessary for our legitimate interests (such as securing our website or understanding how it is used) and these are not overridden by your rights.
04Personal Data Collected
Depending on how you interact with us, we may collect the following categories of personal data:
- Identity and contact details — such as your name, email address, and any postal address or phone number you choose to provide.
- Donation information — the amount, frequency and designation of a donation, and limited transaction references. Card and bank details are handled by our payment provider, not stored by us.
- Volunteer and partner information — details you submit in an application or enquiry, including your interests, availability, skills and organisation.
- Correspondence — the content of messages you send us through forms, email or other channels.
- Technical data — such as IP address, browser type, device information and pages visited, collected through cookies and similar technologies.
05Children's Data
Our website and services are intended for adults. We do not knowingly collect personal data from children under 16 without the consent of a parent or legal guardian.
Where our projects involve children — for example in the communities we support — any information about them is handled under our Safeguarding and Child Protection Policy, with strict controls on collection, consent, storage and the use of images. If you believe we hold data about a child that should not have been provided, please contact us and we will delete it promptly.
06Special Category Data
Certain data is considered particularly sensitive — under the FADP this includes data on health, religious, political or philosophical views, trade union membership, genetic or biometric data, racial or ethnic origin, and administrative or criminal proceedings. The GDPR defines a similar set of “special category” data.
We do not seek to collect sensitive personal data through our website. We only process such data where it is strictly necessary — for example a safeguarding concern or an accessibility requirement you choose to share — and where we have your explicit consent or another lawful ground. We apply enhanced security and access restrictions to any sensitive data we do hold.
07How Information Is Collected
We collect personal data in the following ways:
- Directly from you — when you donate, complete a form, apply to volunteer, contact us or subscribe to updates.
- Automatically — through cookies and similar technologies when you use our website (see the Cookies chapter below).
- From third parties — such as our payment provider confirming a completed donation, or a partner organisation providing a contact where you have agreed to be introduced.
08Purpose of Processing
We process personal data only for specified, transparent purposes, including to:
- Administer donations, issue receipts and keep accurate financial records.
- Respond to enquiries and manage volunteer and partnership applications.
- Send updates, appeals or newsletters where you have asked to receive them.
- Operate, secure, maintain and improve our website.
- Meet our legal, regulatory and good-governance obligations.
- Protect the rights, safety and welfare of the people and communities we work with.
09International Transfers
We are based in Switzerland. Some of our service providers (for example website hosting, email or analytics) may process data outside Switzerland or the EU/EEA.
Where personal data is transferred abroad, we take steps to ensure it remains protected — for example by transferring only to countries recognised as providing adequate protection, or by putting appropriate safeguards in place such as the European Commission’s Standard Contractual Clauses together with any additional measures required under Swiss law.
10Retention Periods
We keep personal data only for as long as necessary for the purposes described in this policy, or for as long as we are legally required to retain it. When data is no longer needed, we securely delete or anonymise it.
Indicative retention periods (to be confirmed on formal adoption of this policy) include:
- Donation and financial records — retained for the period required by applicable Swiss accounting and tax law.
- Volunteer and partner records — retained for the duration of the relationship and a reasonable period afterwards.
- Enquiries and correspondence — retained only as long as needed to handle and follow up on your request.
- Marketing preferences — retained until you unsubscribe or object.
11Data Subject Rights
You have rights over the personal data we hold about you. The exact rights depend on whether Swiss or EU law applies to you, and are set out in the two chapters below. In all cases, you can exercise your rights by contacting us using the details in the Contact chapter. We will respond within the timeframes required by applicable law and will not charge a fee except where the law permits.
12Swiss FADP Rights
If your data is processed under the Swiss FADP, you have the right to:
- Be informed about the collection and processing of your personal data.
- Access the personal data we hold about you and receive information about how it is processed.
- Request the correction of inaccurate or incomplete data.
- Request the deletion or destruction of your data where there is no overriding reason to retain it.
- Object to processing and, where technically feasible, request data portability (the handover of your data).
- Lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC / EDÖB).
13GDPR Rights
If you are in the EU/EEA and the GDPR applies, you additionally have the right to:
- Access, rectify or erase your personal data.
- Restrict or object to processing in certain circumstances.
- Data portability — receive your data in a structured, commonly used, machine-readable format.
- Withdraw consent at any time, without affecting processing carried out before withdrawal.
- Lodge a complaint with your local supervisory authority in the EU/EEA.
15Third Party Processors
We use a small number of carefully selected service providers to help us operate. These providers process personal data on our behalf, under written instructions, and are not permitted to use it for their own purposes.
Typical categories of processor include:
- Website hosting and infrastructure providers.
- Payment and donation processing providers.
- Email, communication and newsletter providers.
- Analytics providers (only where you have consented).
16Security Measures
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration, including:
- Encryption of data in transit (HTTPS) across our website.
- Restricting access to personal data to those who genuinely need it.
- Using reputable providers that maintain recognised security standards.
- Applying our joint signing authority to significant data-related decisions, so that no single individual acts alone.
- Reviewing our practices regularly and improving them as needed.
17Data Breaches
Despite our safeguards, no system can be guaranteed completely secure. If a personal data breach occurs, we will assess it promptly and take steps to contain and remedy it.
Where a breach is likely to result in a high risk to your rights, or where we are otherwise legally required to do so, we will notify the competent supervisory authority — the FDPIC in Switzerland and, where the GDPR applies, the relevant EU/EEA authority — and affected individuals without undue delay, in line with applicable law.
18Complaints
If you have a concern about how we handle your personal data, please contact us first using the details in the Contact chapter. We take all concerns seriously and will do our best to resolve them.
You also have the right to lodge a complaint with a data protection authority: the Swiss Federal Data Protection and Information Commissioner (FDPIC / EDÖB) in Switzerland, or your local supervisory authority if you are in the EU/EEA.
19Contact
For any question about this Privacy Policy or to exercise your rights, please contact us:
Data protection contact: beecharity1@gmail.com
Postal address: "bee Charity" Verein, c/o Jasmin Semra Gabrielli, Bahnhofstrasse 33, 8600 Dübendorf, Switzerland
20Version History
We record changes to this policy here so you can see how it has evolved:
- v1.0 — Formally adopted by the board, effective 25 July 2026. Next scheduled review 25 July 2027.
