Privacy Policy for spring4ever Websites
Version 1.3 · version date: 14 August 2026 · effective from the date of publication
1. Data controller
The controller of personal data currently processed in connection with the spring4ever websites is: Camo Code Sp. z o.o.
Contact the controller about privacy matters at contact@camocode.com.
The controller has appointed a Data Protection Officer. Contact the DPO at iod@camocode.com.
The controller’s full registered details are provided in section 16.
spring4ever is currently the name of a project and brand, not a separate
legal entity. Camo Code Sp. z o.o. acts as the interim controller and actually
determines the purposes and means of the processing covered by this policy.
Once the planned spring4ever Sàrl has been incorporated, the controller role may be transferred to it. Before such a change, or no later than when the new controller begins processing the data, data subjects will be informed of its identity and contact details, the date of the change, and the effect of the change on the processing. Camo Code may then act as a processor for the new controller.
2. Scope of this policy
This policy applies to processing in connection with:
- spring4ever websites;
- the form for registering interest in field testing in Gstaad;
- the form for registering interest in future membership;
- initial contact with and recruitment of people who have submitted an email address;
- voluntary marketing communications based on separate consent;
- the security, maintenance and basic technical analytics of the website.
This policy does not cover participation in the pilot itself, a user account, the band, the application, health data, profiling, Concierge, payments or the provision of a future membership service. Before such operations begin, a separate or supplementary privacy notice appropriate to the actual scope of the product will be provided.
The websites and forms covered by this policy are currently directed at people in Switzerland. They are not directed at minors.
3. Data we process
3.1. Data provided through a form
We collect only an email address through the interest forms. We also record the type, version and language of the form, the date and time of submission and, if marketing consent is given, the wording and version of the consent, the date it was given and the date it was later withdrawn.
Providing an email address is voluntary, but necessary for us to receive the submission and contact you about the selected initiative. Marketing consent is always voluntary and is not a condition for submitting or considering an application.
If we require other information at a later stage, in particular confirmation of age, place of residence or eligibility criteria, we will provide an additional notice appropriate to that stage before collecting it. Do not send identity documents or health data unless Camo Code expressly requests them and specifies a secure method and a legal basis for processing them.
3.2. Technical data
When you use the website, the following data may be processed:
- IP address;
- date and time of the request;
- the URL visited, referring page and selected language;
- basic information about the browser, operating system and device;
- operational, error and security logs;
- technical signals, token and verification result from Cloudflare Turnstile;
- limited performance data processed by Cloudflare Web Analytics.
3.3. Correspondence
If you contact us by email, we process your email address, the content and metadata of the correspondence, and any other information you provide voluntarily.
We do not currently ask for health, biometric or payment data, or copies of identity documents, through the website.
4. Sources of data
We receive data:
- directly from you when you submit a form, give consent or contact us;
- automatically from your browser, device and technical systems when you use the website;
- from technical providers where necessary to deliver messages, protect forms, analyse errors and ensure security.
5. Purposes and legal bases
As Camo Code is established in Poland, the legal bases under the GDPR are set out below. Processing directed at people in Switzerland is also carried out in accordance with the Swiss Federal Act on Data Protection (FADP).
| Purpose | Data | Legal basis under the GDPR |
|---|---|---|
| Receiving a submission, confirming interest and making contact about testing or membership | email address, type and time of submission, correspondence | steps taken at the data subject’s request before a possible contract — Article 6(1)(b); otherwise the legitimate interest in organising recruitment — Article 6(1)(f) |
| Considering submissions and conducting further communications | email address, correspondence, outcome of contact | Article 6(1)(b), or the legitimate interest in handling a submission — Article 6(1)(f) |
| Sending newsletters, updates and other marketing messages | email address, language, record of consent and opt-out, delivery data | voluntary consent — Article 6(1)(a); in addition, the requirements of electronic communications law |
| Protecting forms, preventing spam and abuse, detecting errors and ensuring security | IP address, browser and device data, logs, Turnstile data | the legitimate interest of the controller and users in the secure operation of the website — Article 6(1)(f) |
| Limited analytics of website performance and stability | technical data and aggregated statistics | legitimate interest in evaluating the operation of the website — Article 6(1)(f); consent where required because of the technology used or a change to its configuration — Article 6(1)(a) |
| Meeting legal obligations and handling requests and incidents | data depending on the obligation or matter | legal obligation — Article 6(1)(c) |
| Establishing, exercising or defending legal claims | data related to the matter | legitimate interest in protecting the rights of the controller and other persons — Article 6(1)(f) |
Where Article 6(1)(f) GDPR applies, the legitimate interest is assessed in each case, taking into account the nature of the data, the person’s reasonable expectations and the possible impact of the processing on their rights.
6. Marketing communications
We send marketing messages only if a separate, unchecked-by-default consent box has been selected. Not giving consent does not affect the ability to submit an application or have it considered.
Consent can be withdrawn at any time using the unsubscribe link in a message or by contacting contact@camocode.com. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Marketing and transactional messages are sent using Amazon Simple Email Service (AWS SES). A message confirming a submission or containing information directly related to it is not a marketing communication.
7. Recipients and processors
Data may be accessed only by people who need it for the purposes described:
- authorised Camo Code personnel;
- spring4ever founders acting under the direct authority of Camo Code, on the basis of an individual authorisation, documented instructions and a duty of confidentiality;
- the service providers listed below;
- legal advisers, auditors, competent authorities or courts where necessary and permitted by law.
Main providers:
- Amazon Web Services EMEA SARL, Luxembourg, together with the relevant AWS
infrastructure entities — API Gateway, Lambda, DynamoDB, S3 and SES; the
primary application region is AWS Europe (Zurich),
eu-central-2, in Switzerland; - Google Workspace, for which the contracting party for the Camo Code
account with a Polish billing address is Google Cloud Poland Sp. z o.o. —
internal collaboration and selected copies of submissions; the
Europeregion is selected for data covered by the data-region setting; - Cloudflare, Inc., United States — Turnstile for form protection and Web Analytics for limited performance measurement; Cloudflare may determine its own purposes for some network and security data in accordance with its terms and privacy notice;
- an authorised processor responsible for administering the spring4ever email account under a data processing agreement with Camo Code;
- Infomaniak Network SA, Switzerland — a subprocessor providing the spring4ever mailboxes under an agreement with the processor named above.
The providers’ current lists of subprocessors are available on their websites: AWS, Google Workspace and Cloudflare.
We do not sell personal data. Data covered by this policy is not used to train models or for research.
8. Data locations and international transfers
Data may be processed in the following countries and regions:
- Poland — the controller’s registered office, access by authorised personnel, handling of data-subject rights and Google Workspace;
- Switzerland — the primary AWS Europe (Zurich) region, Infomaniak email and access by duly authorised people;
- Luxembourg and other EEA countries — AWS contracting party and support,
and Google Workspace data storage covered by the
Europesetting; - United States — Cloudflare and possible limited access or processing by entities within provider groups;
- other countries identified in the current AWS, Google and Cloudflare subprocessor lists where a given service, support activity or operation actually requires this.
The Google Workspace data-region setting determines the location of data covered by it, but it does not exclude all support or security operations, or the involvement of subprocessors outside the selected region.
Switzerland is covered by a European Commission adequacy decision, and Poland and the other EEA countries are recognised by Switzerland as providing an adequate level of data protection. Where data is transferred to a country without such recognition, we use a mechanism permitted by the applicable law, in particular an appropriate data-protection framework or standard contractual clauses with the required adaptations and, where necessary, supplementary safeguards.
Information about the mechanism used or a copy of the relevant safeguards can be requested from the DPO, subject to the protection of confidential and security information.
9. Retention periods
We keep data only for as long as necessary for its purpose or to meet a legal obligation. The adopted schedule is:
- technical data from an incomplete or unsuccessful submission — up to 30 days;
- the email address of a candidate not selected for a pilot or membership — 12 months from notification of the decision or completion of the relevant recruitment round;
- data of a selected person — until they receive a separate notice about the pilot or future relationship and further processing under that notice;
- marketing data — until consent is withdrawn or after 24 months of inactivity;
- the minimum record of consent and its withdrawal, and the address on the suppression list — three years from the last message or withdrawal;
- ordinary correspondence — 24 months after the matter is closed;
- technical, security and access logs — up to 12 months, unless needed longer for a specific incident;
- backup data — overwritten cyclically, generally no later than 90 days after deletion from the primary system;
- data necessary to establish, exercise or defend claims — up to six years or until the relevant proceedings have ended;
- records that tax, accounting or other law requires us to keep longer — for the applicable statutory period.
Cloudflare states that it retains unaggregated Web Analytics beacon data for seven days and makes reports available for up to six months; aggregated data may be retained longer under the provider’s rules.
Until a backup is overwritten, deleted data is excluded from ordinary use and may be restored only for a justified business-continuity, security or legal purpose.
10. Cookies and similar technologies
The website may use technologies necessary for the security and operation of
forms. Cloudflare Turnstile analyses browser and device signals to distinguish
a user from automated traffic. If pre-clearance mode is enabled, Cloudflare
may set the cf_clearance cookie to protect the website.
Cloudflare Web Analytics uses a measurement script to collect limited performance metrics. We do not use it for personalised advertising or to track users across websites operated by different organisations.
We do not currently use marketing cookies from Google, Meta or LinkedIn, or tools such as Hotjar. If we introduce non-essential technologies requiring consent, they will remain disabled until a choice is made, and users will be given an easily accessible way to change that choice later.
11. Automated decision-making
We do not make decisions about people registering interest based solely on automated processing where those decisions would have legal or similarly significant effects. The current forms are not used for profiling.
12. Security
We apply technical and organisational measures appropriate to the risk, including protecting data in transit, restricting access to authorised people, separating roles, authentication, recording significant actions, managing backups and incident-response procedures.
No method of transmission or storage provides absolute security. If a breach occurs, we will assess the risk and make the notifications to competent authorities and affected people required by law.
13. Your rights
Within the limits of the GDPR, FADP and other applicable laws, you may:
- obtain confirmation as to whether we process your data and access the data and information about the processing;
- request correction or completion of the data;
- request deletion of the data;
- request restriction of processing;
- object to processing based on legitimate interests for reasons relating to your particular situation;
- withdraw consent at any time with effect for the future;
- receive data in a structured, commonly used format or request that it be transmitted to another controller where the statutory conditions are met;
- request information about safeguards used for data transfers.
A request may be sent to contact@camocode.com or to the DPO at iod@camocode.com. It is best to use the address to which the submission relates. If the request is sent from a different address, we may send a confirmation to the address held in our system or ask for additional, proportionate information. Do not send a copy of an identity document unless we expressly ask for one and provide a secure way to send it.
As a rule, we respond without undue delay and no later than one month after receiving a request. Where permitted by law, this period may be extended, in which case we will explain why. Exercise of a right may be subject to statutory limitations, in particular where data must be retained because of a legal obligation, the rights of others or the defence of claims.
If you believe that we process data unlawfully, you may lodge a complaint with the President of the Polish Personal Data Protection Office: uodo.gov.pl. A person in Switzerland may also contact the Federal Data Protection and Information Commissioner: edoeb.admin.ch. The right to complain does not limit other legal remedies.
14. Minors
The website and forms are not directed at minors. We do not knowingly collect their data. If we learn that a minor’s data has been submitted without proper authorisation, we will take steps to delete it.
15. Changes to this policy
This policy may be updated if the website, processing purposes, providers or the law change. The current version, number and date will be published in an easily accessible place. We will provide appropriate advance notice of a change that materially affects users’ rights or reasonable expectations and, where required, seek new consent.
16. Full registered details of the controller
Camo Code Sp. z o.o. (a Polish limited liability company), ul. Pustułeczki 4/1, 02-811 Warsaw, Poland, KRS: 0000502896, NIP: 9512378019, REGON: 147147226.
