Privacy Policy

How Life Beyond collects, processes, stores, secures and shares personal, technical and administrative data.

1. Identity of the data controller

The data controller is: Life Beyond, non-profit organization, based in Lausanne, Switzerland Contact: contact@life-beyond.ch

The association may designate an internal data manager ("Association Data Officer"). Failing that, this responsibility is assumed collectively by the committee.


2. Purpose of the policy

This policy defines the rules for the collection, processing, storage, security and sharing of personal, technical and administrative data within the Life Beyond association, hereinafter "LB".

It ensures compliance:

  • with the General Data Protection Regulation (GDPR) applicable in the European Union;
  • with the Federal Data Protection Act (DPA) revised and in force in Switzerland.

3. Scope

This policy applies to:

  • the members, volunteers and bodies of the association;
  • partners, participants in activities and events;
  • any person whose data is processed by LB.

It covers all the treatments performed:

  • in person or online;
  • on paper or digital media;
  • within the European Union and in Switzerland.

4. Types of data processed

4.1 Personal Data

LB can process, in particular:

  • identity data (surname, first name, date of birth);
  • contact details (email address, telephone number);
  • information related to student or academic status;
  • digital identifiers (accounts, internal platforms);
  • data from membership or activity participation forms.

LB does not, by default, collect personal data considered sensitive within the meaning of the GDPR and the DPA.

4.2 Scientific and technical data

  • plans, technical drawings, prototypes;
  • measurements, simulations, test results;
  • internal research reports.

This data falls under the GDPR only insofar as it allows the identification of a natural person.

4.3 Administrative Data

  • accounting documents;
  • invoices and supporting documents;
  • contracts and partnership or funding files.

4.4 Communication Data

  • photographs, videos, publications;
  • scientific or institutional communication content.

The data processing carried out by LB is based on the following legal grounds:

PurposeLegal basis
Membership and association activities managementExecution of the associative relationship
Internal and institutional communicationLegitimate interest
Newsletter and external communicationsConsent
Event organizationLegitimate interest or consent
Accounting and legal obligationsLegal obligation
IT security and accessLegitimate interest

6.1 Lawfulness

The treatment is based on:

  • The explicit consent (membership, newsletter);
  • or the legitimate interest of LB (internal management, IT security, institutional communication).

6.2 Minimisation

Collect only what is necessary according to the principles of GDPR and of the DPA.

6.3 Accuracy and Updating

Members have an obligation to report outdated data.

6.4 Storage limitations

The data is kept only for the period necessary for the intended purposes.

6.5 Integrity and Confidentiality

LB implements reasonable measures to protect data against unauthorized access, in accordance with the principle of appropriate safety (GDPR Art. 32, DPA Art. 8).


7. Preservation and archiving

  • Members' personal data: deleted or anonymized 1 year after the end of their commitment.
  • Accounting documents: deleted after 10 years of storage
  • Technical/scientific data: kept as long as they are useful to the project.
  • Published content: retained indefinitely unless a legitimate removal request is made.

8. Data security

8.1 Technical Measures

  • mandatory authentication with strong passwords and two-factor authentication where available;
  • individual access to the platforms, accounts are not shared;
  • regular backups on encrypted media or secure cloud on EU or Swiss servers only;
  • Limitation of access rights according to roles.

8.2 Organizational Measures

  • raising awareness among members;
  • confidentiality agreements for members with access to sensitive or technical data.

8.3 Physical Support

  • computer equipment and paper documents stored in locked premises;
  • restricted access to technical areas or areas containing prototypes.

9. Data sharing and transfer

9.1 Academic or industrial partners

Any data transmission:

  • must be justified by the project's objectives;
  • requires committee approval.
  • must be subject to a non-disclosure agreement (NDA) if sensitive technical data is involved.

9.2 International Transfer

In accordance with the GDPR:

  • Switzerland is recognized as a country offering an adequate level of data protection.
  • Transfers to a country not recognized as adequate require standard contractual clauses (SCC).

9.3 Public Communication

Publishing photos, results, or technical content requires authorization:

  • from the communications manager,
  • and the committee.

Identifiable individuals must provide their explicit consent for the use of their image in accordance with the requirements of the GDPR and the DPA.


10. Rights of individuals

Any person whose data is being processed may request:

  • access to its data;
  • rectification of incorrect data;
  • suppression (right to be forgotten);
  • limitation or objection to processing;
  • portability of its data;
  • information in case of data breach presenting a risk.

Applications can be sent to contact+data@life-beyond.ch. Proof of identity may be requested. Applications are processed within a timeframe of 30 days.


11. Data breach

In case of an incident (loss, leak, hacking):

  1. inform the committee immediately;
  2. internal risk analysis for the people concerned;
  3. immediate corrective action (access revocation, restoration, etc.);
  4. mandatory notification:
    • GDPR: notification to the competent authority within 72 hours if there is a high risk.
    • Switzerland: notification with reasonable notice depending on the level of risk (DPA art. 24).
  5. Document the incident for internal audit.

12. Revision

This policy is reviewed annually or in the event of legal or organizational changes.


13. Last modification

This policy was last modified on January 26, 2026.