Privacy Policy
How Life Beyond collects, processes, stores, secures and shares personal, technical and administrative data.
1. Identity of the data controller
The data controller is: Life Beyond, non-profit organization, based in Lausanne, Switzerland Contact: contact@life-beyond.ch
The association may designate an internal data manager ("Association Data Officer"). Failing that, this responsibility is assumed collectively by the committee.
2. Purpose of the policy
This policy defines the rules for the collection, processing, storage, security and sharing of personal, technical and administrative data within the Life Beyond association, hereinafter "LB".
It ensures compliance:
- with the General Data Protection Regulation (GDPR) applicable in the European Union;
- with the Federal Data Protection Act (DPA) revised and in force in Switzerland.
3. Scope
This policy applies to:
- the members, volunteers and bodies of the association;
- partners, participants in activities and events;
- any person whose data is processed by LB.
It covers all the treatments performed:
- in person or online;
- on paper or digital media;
- within the European Union and in Switzerland.
4. Types of data processed
4.1 Personal Data
LB can process, in particular:
- identity data (surname, first name, date of birth);
- contact details (email address, telephone number);
- information related to student or academic status;
- digital identifiers (accounts, internal platforms);
- data from membership or activity participation forms.
LB does not, by default, collect personal data considered sensitive within the meaning of the GDPR and the DPA.
4.2 Scientific and technical data
- plans, technical drawings, prototypes;
- measurements, simulations, test results;
- internal research reports.
This data falls under the GDPR only insofar as it allows the identification of a natural person.
4.3 Administrative Data
- accounting documents;
- invoices and supporting documents;
- contracts and partnership or funding files.
4.4 Communication Data
- photographs, videos, publications;
- scientific or institutional communication content.
5. Purposes and legal bases of processing
The data processing carried out by LB is based on the following legal grounds:
| Purpose | Legal basis |
|---|---|
| Membership and association activities management | Execution of the associative relationship |
| Internal and institutional communication | Legitimate interest |
| Newsletter and external communications | Consent |
| Event organization | Legitimate interest or consent |
| Accounting and legal obligations | Legal obligation |
| IT security and access | Legitimate interest |
6. Legal principles of processing
6.1 Lawfulness
The treatment is based on:
- The explicit consent (membership, newsletter);
- or the legitimate interest of LB (internal management, IT security, institutional communication).
6.2 Minimisation
Collect only what is necessary according to the principles of GDPR and of the DPA.
6.3 Accuracy and Updating
Members have an obligation to report outdated data.
6.4 Storage limitations
The data is kept only for the period necessary for the intended purposes.
6.5 Integrity and Confidentiality
LB implements reasonable measures to protect data against unauthorized access, in accordance with the principle of appropriate safety (GDPR Art. 32, DPA Art. 8).
7. Preservation and archiving
- Members' personal data: deleted or anonymized 1 year after the end of their commitment.
- Accounting documents: deleted after 10 years of storage
- Technical/scientific data: kept as long as they are useful to the project.
- Published content: retained indefinitely unless a legitimate removal request is made.
8. Data security
8.1 Technical Measures
- mandatory authentication with strong passwords and two-factor authentication where available;
- individual access to the platforms, accounts are not shared;
- regular backups on encrypted media or secure cloud on EU or Swiss servers only;
- Limitation of access rights according to roles.
8.2 Organizational Measures
- raising awareness among members;
- confidentiality agreements for members with access to sensitive or technical data.
8.3 Physical Support
- computer equipment and paper documents stored in locked premises;
- restricted access to technical areas or areas containing prototypes.
9. Data sharing and transfer
9.1 Academic or industrial partners
Any data transmission:
- must be justified by the project's objectives;
- requires committee approval.
- must be subject to a non-disclosure agreement (NDA) if sensitive technical data is involved.
9.2 International Transfer
In accordance with the GDPR:
- Switzerland is recognized as a country offering an adequate level of data protection.
- Transfers to a country not recognized as adequate require standard contractual clauses (SCC).
9.3 Public Communication
Publishing photos, results, or technical content requires authorization:
- from the communications manager,
- and the committee.
Identifiable individuals must provide their explicit consent for the use of their image in accordance with the requirements of the GDPR and the DPA.
10. Rights of individuals
Any person whose data is being processed may request:
- access to its data;
- rectification of incorrect data;
- suppression (right to be forgotten);
- limitation or objection to processing;
- portability of its data;
- information in case of data breach presenting a risk.
Applications can be sent to contact+data@life-beyond.ch. Proof of identity may be requested. Applications are processed within a timeframe of 30 days.
11. Data breach
In case of an incident (loss, leak, hacking):
- inform the committee immediately;
- internal risk analysis for the people concerned;
- immediate corrective action (access revocation, restoration, etc.);
- mandatory notification:
- GDPR: notification to the competent authority within 72 hours if there is a high risk.
- Switzerland: notification with reasonable notice depending on the level of risk (DPA art. 24).
- Document the incident for internal audit.
12. Revision
This policy is reviewed annually or in the event of legal or organizational changes.
13. Last modification
This policy was last modified on January 26, 2026.