Data protection

1. General principles

1.1 The Strike Park SA (hereinafter «the Company» or «Raiffeisen Parc») attaches the utmost importance to the confidentiality, protection and security of the personal data of its users, clients and visitors.

1.2 This present Data Protection Policy (hereinafter «the Policy») describes the way in which the Company collects, processes, retains and protects personal information in accordance with the Swiss Federal Act on Data Protection (FADP) and, where appropriate, to General Data Protection Regulation (GDPR) for users located in the European Economic Area (EEA).

1.3 This Policy applies to all data processing carried out via:

  • the website www.raiffeisen-parc.ch ;

  • the mobile application linked to the system Apex Timing ;

  • electronic interactions (emails, newsletters, contact forms, bookings, online payments).

2. Data controller

2.1 The data controller the data is:

Strike Park SA
Rue Emile-Boéchat 87, 2800 Delémont, Switzerland
Identification number: CHE-451.592.122
Email: contact@raiffeisen-parc.ch

2.2 The Delémont Sports and Leisure Centre Ltd acts as data controller for all data collection and use operations related to its activity.

2.3 None Data Protection Officer (DPO) has been appointed to date, as Swiss law does not require it, but any questions relating to confidentiality may be sent to the address mentioned above.

3. Nature of the data collected

The Company may collect the following categories of data:

3.1 Identification data

  • Surname, first name, title, date of birth (where applicable)

  • Postal address, postcode, city, country

  • Email address

  • Telephone number

3.2 Account and authentication data

  • Account ID (login)

  • Password (encrypted and not accessible in plain text)

  • Login history and actions performed in the user area

3.3 Transactional and financial data

  • Information regarding purchases, gift vouchers, credits or bookings

  • Amounts, dates, payment methods

  • Billing details and accounting documents

  • Partial bank card details transmitted via Stripe, a PCI-DSS certified provider

3.4 Technical and navigation data

  • IP address, browser type, operating system

  • Log data, pages viewed, visit duration

  • Cookies, web beacons and similar technologies (see «Cookies» section)

3.5 Marketing and behavioural data

  • Communication campaign history

  • Opens and clicks in newsletters (via Brevo)

  • Data collected by advertising pixels (Meta, TikTok, LinkedIn, etc.)

3.6 Data from the Apex Timing system

  • Activity booking data (e.g. bowling, games, events)

  • Session identifiers and user preferences

  • Account and credit management data related to the platform

4. Purposes of processing

The collected data is used for the following purposes:

4.1 Account and benefit management

  • Creation, administration and securing of customer accounts

  • Processing of bookings and gift voucher sales

  • Management of credits, activities and usage schedules

4.2 Contractual performance

  • Order processing and payments

  • Invoicing and commercial relationship management

  • Delivery of electronic or physical gift vouchers

4.3 Communication and marketing

  • Sending of information regarding services and new features

  • Management of the newsletter and commercial offers via Brevo

  • Statistical analysis and audience segmentation

  • Running targeted advertising campaigns (Meta, TikTok, Google Ads, etc.)

4.4 Service improvement

  • Site and App Performance Evaluation

  • Analysis of browsing behaviour to optimise user experience

  • Technical tests and debugging

4.5 Compliance with legal obligations

  • Retention of invoices and accounting records

  • Fight against fraud and money laundering

  • Responses to legal or administrative requests

5. Legal bases for processing

The data processing is carried out on the basis of:

  • of the performance of a contract (Article 31(1) FADP) for bookings, purchases, payments and associated services; ;

  • you explicit consent for marketing operations and newsletters; ;

  • of legitimate interest of the Company for internal management, fraud prevention and systems security; ;

  • you compliance with legal obligations in tax, accounting and regulatory matters.

6. Shelf life

6.1 Data is kept for a period proportionate to the purposes for which it was collected:

Data categoryShelf life
Customer account dataWhile the account is active + 3 years after inactivity
Transaction data and invoicing10 years (Swiss accounting obligations)
Marketing data and newslettersUntil consent is withdrawn or you unsubscribe
Technical data and cookiesFrom 6 to 24 months depending on the type
Apex Timing dataWhile the contractual relationship remains in force

6.2 Upon expiry of these periods, the data are deleted, anonymised or securely archived.

7. Recipients and processors

The collected data may be shared with third parties exclusively for the purposes described above:

7.1 Technical service providers and partners

  • Apex Timing (France) – reservation management and user accounts

  • Stripe (Ireland / EU) – online payment processing

  • Brevo (ex-Sendinblue, France) – electronic communications management

  • Hostinger (Lithuania / EU) – secure hosting of the Site

  • e-Medias Sàrl (Switzerland) – technical maintenance and web support

7.2 Administrative authorities

Only upon lawful request, in the event of a legal obligation, inspection or judicial proceedings.

7.3 No data transfers are carried out to companies located outside the European Union or Switzerland without adequate protection guarantees (standard contractual clauses, EU hosting, etc.).

8. Data Security

8.1 The Company implements all necessary technical and organisational measures to guarantee the confidentiality, integrity and availability of the data.

8.2 These measures include:

  • SSL/TLS encryption of all web communications; ;

  • secure storage on protected servers; ;

  • access control and login logging; ;

  • regular and redundant backups; ;

  • internal privacy policy and staff training.

8.3 In the event of a security incident or data breach, the Company undertakes to notify the users concerned without delay and, where applicable, the competent authorities in accordance with the DPA.

9. User rights

In accordance with the Swiss LPD and, where appropriate, to European GDPR, the User has the following rights:

9.1 Right of access

Request confirmation that personal data concerning him or her are being processed and obtain a copy.

9.2 Right of rectification

Requesting the rectification or updating of inaccurate or incomplete data.

9.3 Right to erasure («right to be forgotten»)

Request the erasure of one's data when it is no longer necessary or when consent is withdrawn.

9.4 Right to object

Object at any time to the use of one's data for marketing or analytical purposes.

9.5 Right to data portability

Obtain, in a structured format, the data he has provided in order to transmit them to another controller (within the limits of technical capabilities).

9.6 Right to withdraw consent

Withdraw consent at any time for processing based on it, without retroactive effect.

9.7 Exercise of rights

These rights can be exercised by simple written request addressed to:
contact@raiffeisen-parc.ch
The Company undertakes to respond within a reasonable timeframe, generally less than 30 days.

10. Cookies, trackers and similar technologies

10.1 The Site uses functional, analytical and advertising cookies intended to improve navigation and measure audience engagement.

10.2 The main tools used are:

  • Google Analytics and Tag Manager audience measurement

  • Meta Pixel and TikTok Pixel marketing and conversion analysis

  • LinkedIn Insight Tag B2B analysis

10.3 By browsing the Site, the User implicitly accepts the use of these cookies.
No consent banner is displayed, in accordance with accepted practice in Switzerland.

10.4 The User may configure or disable cookies via their browser at any time.
However, disabling them may limit certain functionalities of the Site.

11. Newsletters and commercial communication

11.1 Subscription to the newsletter is voluntary and requires the User’s explicit consent.

11.2 Newsletters are sent via the service provider Brevo in accordance with its own privacy policy.
Every email contains an automatic unsubscribe link.

11.3 The User may unsubscribe at any time without giving a reason.
Withdrawal of consent does not affect the lawfulness of previous mailings.

12. International data transfers

12.1 The data is primarily processed and hosted in Switzerland and in the’European Union.

12.2 If any transfer to a third country should take place (e.g. backup, technical service provider), the Company shall ensure that:

  • the country in question has an adequate level of protection recognised by Switzerland or the EU; ;

  • or that the transfer is governed by standard contract terms approved by the European Commission.

13. Liability and remedies

13.1 The Company shall not be held liable for any unauthorised use of data resulting from any fault, negligence or breach of the Terms of Use by the User.

13.2 In the event of a dispute, the User is requested to contact the Company at the address set out above before taking any legal action.

13.3 As a last resort, any dispute relating to data processing shall fall within the jurisdiction of the Courts of the Canton of Jura, with its seat in Porrentruy, unless otherwise mandatorily provided.

14. Changes to the Privacy Policy

14.1 The Company reserves the right to amend this Policy at any time to take account of legal, technical or organisational developments.

14.2 The most recent version is the one published on the Website on the date of access.
By continuing to use the Website, you agree to the updated Policy.

15. Contact

If you have any questions regarding this Policy, the exercise of your rights or the processing of your personal data:
Email: contact@raiffeisen-parc.ch
Postal address: Strike Park SA, 87 Rue Emile-Boéchat, 2800 Delémont, Switzerland.