Privacy policy
What this site does with your data, what it does not, and who else is involved.
Where we stand
We collect no data for commercial, advertising or profiling purposes. We do not sell, rent or share any data for marketing. We display no advertising and carry out no behavioural tracking.
That does not mean no data is processed at all: an email you send us contains data by definition, and a host keeps technical logs. This page states precisely what and by whom.
Legal framework
Two texts apply. The Swiss Federal Act on Data Protection (FADP, SR 235.1), in force since 1 September 2023. And the General Data Protection Regulation (GDPR), where we offer our services to people located in the European Union or the European Economic Area (art. 3(2)(a) GDPR), which happens for some of our engagements. Where both regimes overlap, we follow the more protective rule.
Controller
Rethink Mindset
Cours des Bastions 13
1205 Geneva, Switzerland
For any request relating to data protection, write to contact@rethinkmindset.ch.
Within the meaning of art. 5 let. j FADP and art. 4(7) GDPR.
What we process ourselves
Emails you send us
This site has no form. If you write to us by email, we process your name, email address and the content of your message, solely to answer your request. This information is used for nothing else. It is disclosed to no third party, except Infomaniak, which hosts our mailbox in Switzerland on our behalf, as a processor.
You are not obliged to write to us; without this information we simply cannot answer you. Messages are kept for the duration of the exchange, then twelve months at most, subject to statutory retention periods if an engagement is concluded.
Basis: pre-contractual steps taken at your request (art. 6(1)(b) GDPR); failing that, our legitimate interest in answering an enquiry (point f). Under Swiss law, processing that complies with the principles of art. 6 FADP requires no justification (art. 30 and 31 FADP).
Server technical logs
On every visit, the server hosting this site automatically records your IP address, the date and time, the page requested and the browser type. An IP address is personal data. These logs serve only to keep the site secure and working; we do not combine them with any other information to identify you.
Basis: our legitimate interest in running a secure site (art. 6(1)(f) GDPR). Under Swiss law, processing that complies with the principles of art. 6 FADP requires no justification (art. 30 and 31 FADP). The logs are kept by our host Infomaniak, which retains them for at least seven days according to its public documentation; once that retention period has elapsed, entries can no longer be restored. We keep no copy.
Cookies
This site sets no cookies and stores nothing in your browser: no technical cookie, no audience measurement, no advertising tracker, no social media button. There is therefore no banner, because there is nothing to accept or refuse. The language shown depends only on the address of the page.
Our provider
A single provider is involved when you visit.
| Provider | Role | Location | When |
|---|---|---|---|
| Infomaniak Network SA | Website and email hosting. Technical logs: IP address, browser, pages visited, date and time. | Geneva, Switzerland | On every visit; when you write to us |
Infomaniak acts as a processor: it handles the logs and hosts our mailbox on our behalf, under a contract. Its policy (in French): infomaniak.com.
This site embeds no third-party service: no video, no map, no measurement tool, no external platform.
Where your data goes
Your data is processed in Switzerland: the site and our mailbox are hosted by Infomaniak in its Swiss data centres. We disclose no data abroad.
Switzerland benefits from an adequacy decision of the European Commission (Decision 2000/518/EC of 26 July 2000, confirmed by the report of 15 January 2024).
Your rights
Under Swiss law (FADP), you may request access to your data (art. 25), their delivery or transfer in a commonly used electronic format where the statutory conditions are met (art. 28), and their rectification, erasure or a ban on processing, and you may object to processing (art. 30 para. 2 let. b and art. 32).
Where the GDPR applies, you also have the rights of access, rectification, erasure, restriction of processing and data portability (art. 15 to 18 and 20 GDPR).
Right to object (art. 21 GDPR). Where we process your data on the basis of our legitimate interest (answering your emails, technical logs), you may object at any time on grounds relating to your particular situation.
The request is free of charge. We respond within thirty days as a general rule (art. 25 para. 7 FADP) or within one month (art. 12(3) GDPR), extendable by two months for a complex request, in which case we will tell you. Write to contact@rethinkmindset.ch.
You may report the matter to the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern (art. 49 para. 1 FADP). If you reside in the European Union, you may also lodge a complaint with the supervisory authority of your member state of residence, your place of work, or the place of the alleged infringement (art. 77 GDPR).
What we do not do
No automated individual decision-making (art. 22 GDPR; art. 21 FADP) and no profiling (art. 4(4) GDPR; art. 5 let. f FADP). No unsolicited marketing. This site collects no data falling within the special categories of art. 9 GDPR or the sensitive data of art. 5 let. c FADP.
Appointing a data protection officer is not required (art. 37 GDPR): our processing involves neither large-scale monitoring nor large-scale processing of special categories. We have not appointed a representative in the Union under art. 27 GDPR, our processing of data relating to people in the Union being occasional and unlikely to result in a risk (the conditions of the derogation in art. 27(2)). This assessment is reviewed if our activity in the Union changes.
Security
The site is served over HTTPS only. It loads no font, script or image from a third-party domain, which avoids invisible transmissions of IP addresses. A restrictive content security policy prevents the execution of any code that is not ours. We check that our providers apply appropriate measures.
Changes
This policy is amended when the processing changes, for instance if we enable audience measurement, a form, a scheduling tool, a training platform or an embedded video. Any amendment is published on this page with its date.
In force since March 2026 · last updated: 6 October 2026