Privacy Policy

PRIVACY POLICY

This Privacy Policy explains how HL Forum GmbH (“we,” “us,” “the Forum”) collects, uses, and protects your personal data in connection with the St. Moritz Longevity Forum event, our websites at www.stmoritzlongevityforum.ch and www.stmlforum.ch (together, the “Website”), our newsletters, our social media presence, and our communications with you.

This Privacy Policy complies with the Swiss Federal Act on Data Protection (“FADP”) and, where applicable, the EU General Data Protection Regulation (“GDPR”). Additional privacy notices may apply to specific services or interactions where indicated.

1. Who We Are (Data Controller)

The controller responsible for your personal data is:

HL Forum GmbH San Bastiaun 50A/21, 7503 Samedan, Switzerland Email: hello@stmlforum.ch

For privacy-related questions, requests, or to exercise your rights under this Privacy Policy, please contact us at hello@stmlforum.ch.

2. Personal Data We Collect

We collect and process the following categories of personal data, depending on how you interact with us:

2.1 Website and technical data. When you visit the Website, we automatically collect IP address, device type, operating system, browser, language settings, referring URL, pages visited, time and duration of visit, and cookie identifiers.

2.2 Contact and inquiry data. When you contact us through forms, email, or social media, we collect your name, email address, message content, and any other information you choose to provide.

2.3 Newsletter subscription data. When you subscribe to our newsletter, we collect your name, email address, language preference, and consent record.

2.4 Ticket purchase and attendance data. When you purchase a ticket or attend the Forum, we (and our ticketing provider, Ticketino AG) collect your name, contact details, billing information, company or affiliation, dietary requirements, accessibility needs, badge information, and any other data necessary for registration and event administration.

2.5 Event participation data. During the Forum, we may collect badge scan data, session attendance, and information shared during networking or workshop activities.

2.6 Photography, video, and audio. During the Forum, we capture photographs, video, and audio recordings that may include your image and voice. See Section 5.5 for details and your right to object.

2.7 Marketing and engagement data. We process information about how you interact with our communications, including email opens, link clicks, and engagement with our social media content.

2.8 Press and partnership data. Where you apply for press accreditation, sponsorship, partnership, or speaker roles, we collect the data submitted as part of that application.

3. Why We Process Your Data and Our Legal Basis

We process your personal data only where we have a lawful basis to do so. The table below sets out our processing purposes and the legal basis for each.

PurposeLegal Basis (FADP / GDPR Art. 6)
Operating, securing, and improving the WebsiteLegitimate interest in providing a functional, secure website
Processing ticket purchases and managing attendancePerformance of a contract with you (the Terms of Purchase and Attendance)
Sending transactional emails relating to your purchase, inquiry, or registrationPerformance of a contract, or our legitimate interest in responding to your inquiry
Sending marketing newsletters and event invitationsYour explicit consent, which you may withdraw at any time
Analytics and measuring engagement with our Website and communicationsYour consent (for non-essential cookies) or legitimate interest, depending on the tool
Capturing photography, video, and audio during the ForumLegitimate interest in documenting and promoting the Forum, subject to your right to object (see Section 5.5)
Complying with legal obligations (tax, accounting, anti-money-laundering)Compliance with a legal obligation
Defending or asserting legal claimsLegitimate interest in protecting our legal position
Press, partnership, sponsorship, and speaker managementPerformance of a contract or pre-contractual steps at your request

Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

Where we rely on legitimate interests, you have the right to object — see Section 5.

4. Who We Share Your Data With

We share your personal data only with the following categories of recipients, and only to the extent necessary:

4.1 Service providers. We work with the following service providers, who process data on our behalf:

  • Ticketing and payment processing: Ticketino AG, Switzerland (and its payment partners)
  • Website analytics: Google LLC (Google Analytics and Site Kit), United States
  • Newsletter delivery: Mailchimp (Intuit Inc.), United States
  • Professional advisors: lawyers, accountants, and auditors, where necessary

These providers process data only on our instructions and under appropriate data processing agreements.

4.2 Forum partners and sponsors. Where you have given specific consent (for example, by visiting a sponsor’s booth or opting into lead capture), we may share limited contact information with the relevant partner or sponsor.

4.3 Legal and regulatory recipients. We may disclose personal data where required by Swiss or applicable foreign law, court order, or to defend our legal rights.

4.4 Business transfers. In the event of a reorganization, merger, or sale of the Forum, personal data may be transferred to the relevant party, subject to the protections of this Privacy Policy.

We do not sell your personal data.

5. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

5.1 Access. You may request a copy of the personal data we hold about you.

5.2 Rectification. You may ask us to correct inaccurate or incomplete data.

5.3 Deletion. You may ask us to delete your personal data where legal grounds for retention no longer apply.

5.4 Restriction. You may ask us to restrict processing in certain circumstances.

5.5 Objection. You may object to processing based on our legitimate interests, including objection to photography or video capture during the Forum. To opt out of appearing in promotional materials, please notify us in advance at the contact email above and request a visible identifier at registration; we will use reasonable efforts to honor such requests but cannot guarantee exclusion from general audience or venue footage.

5.6 Portability. You may request your data in a structured, machine-readable format, or ask us to transfer it to another controller, where technically feasible.

5.7 Withdrawal of consent. Where processing is based on your consent, you may withdraw it at any time.

5.8 Complaint to a supervisory authority. You have the right to lodge a complaint with the competent data protection authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (www.edoeb.admin.ch). EU residents may also contact the supervisory authority in their country of residence.

To exercise any of these rights, contact us at the email address in Section 1. We may need to verify your identity before responding. We aim to respond within 30 days.

6. International Data Transfers

Some of our service providers are located outside Switzerland and the European Economic Area. In particular, Google LLC (which provides our analytics services) and Mailchimp (which delivers our newsletters) process data in the United States. Where personal data is transferred outside Switzerland or the EEA, we ensure appropriate safeguards are in place, including the EU-US Data Privacy Framework and Standard Contractual Clauses approved by the European Commission or the Swiss FDPIC.

You may request a copy of the relevant safeguards by contacting us at the email address in Section 1.

7. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including legal, accounting, or reporting requirements. Indicative retention periods are:

DataRetention period
Website analytics and cookie dataUp to 14 months (Google Analytics default) or as set out in the cookie banner
Newsletter subscription dataUntil you unsubscribe or withdraw consent; engagement data deleted after 24 months of inactivity
Contact and inquiry dataUp to 24 months after last contact, unless an ongoing relationship requires longer retention
Ticket purchase and attendance data10 years after the relevant Forum edition, in line with Swiss accounting and tax retention requirements
Photography and video from past Forum editionsRetained indefinitely for archival, historical, and promotional purposes, subject to your right to object
Marketing engagement dataUntil consent withdrawal or 24 months of inactivity, whichever is earlier

After the applicable retention period, we delete or anonymize personal data in accordance with our standard procedures.

8. Cookies and Similar Technologies

The Website uses cookies and similar technologies for the following purposes:

  • Strictly necessary cookies: required for the Website to function (set without consent).
  • Analytics cookies: Google Analytics and Site Kit, used to understand how visitors use the Website. Set only with your consent.

You can manage your cookie preferences at any time through the cookie consent banner on the Website, or by adjusting your browser settings to reject or delete cookies.

For full details of the specific cookies used, their purposes, providers, and durations, please see our [Cookie Notice / Cookie Banner Preferences].

9. Social Media

We maintain pages on LinkedIn, Instagram, Facebook, X (Twitter), and YouTube. When you interact with these pages, the platform operator also processes your personal data as an independent data controller, including for analytics, advertising, and platform management.

For pages where the platform’s analytics functions create a joint controllership (for example, Facebook and Instagram Page Insights), we have entered into joint controller arrangements with Meta in accordance with GDPR Art. 26. The essential terms of these arrangements are available from the relevant platform.

For information on how each platform processes your data, please consult their privacy notices:

  • LinkedIn: https://www.linkedin.com/legal/privacy-policy
  • Meta (Instagram, Facebook): https://www.facebook.com/privacy/policy
  • X: https://x.com/en/privacy
  • YouTube/Google: https://policies.google.com/privacy

10. Security

We implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These include access controls, encryption in transit, secure hosting, and confidentiality obligations on our staff and service providers. No system is entirely secure, however, and we cannot guarantee absolute security.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Updates take effect when posted on the Website and apply prospectively. For material changes affecting your rights, we will use reasonable efforts to notify you where we hold your contact details. The “Last updated” date at the top of this Privacy Policy indicates when it was last revised.

12. Governing Law and Jurisdiction

This Privacy Policy is governed by Swiss law, excluding its conflict of law rules. The competent courts of the Canton of Graubünden, Switzerland have exclusive jurisdiction over disputes arising from or in connection with this Privacy Policy, subject to any mandatory consumer protection rules that may apply to data subjects resident outside Switzerland and the rights of EU/EEA data subjects to bring a claim before their local supervisory authority or courts under GDPR.