Legal
Privacy notice
This notice explains how PRIMAL processes personal data under the Swiss Data Protection Act and, where applicable, the GDPR.
Last updated: 3 August 2026Controller
Samuel Tim Einzelunternehmen, Föhrenstrasse 2, 8200 Schaffhausen, Switzerland · samueltim200@yahoo.de
Data and purposes
We process account data (name, email, date of birth, sex, country, language and password hash), security and session data, community contributions, event registrations and answers, scores, organizer content, and technical server logs. We use them to provide and secure accounts, operate the community, administer events, match historical results, translate content, prevent misuse and fulfil legal duties.
- Account and event services: performance of the user relationship or steps requested by you (GDPR Art. 6(1)(b), where applicable).
- Security, moderation and reliable operation: legitimate interests (GDPR Art. 6(1)(f), where applicable).
- Mandatory records: legal obligations (GDPR Art. 6(1)(c), where applicable).
- Optional marketing would require a separate choice. PRIMAL currently sends no marketing newsletter.
Transactional email
Brevo (Sendinblue SAS) delivers email verification codes, registration confirmations, event reminders, organizer updates and published results. These messages are necessary for account security or the event service and are not advertising. Withdrawing from an event cancels pending reminders.
Recipients and external services
Data is available only where needed to the operator, infrastructure providers, Brevo for delivery, Microsoft Azure AI in Sweden for translations, OpenStreetMap tile servers and Nominatim for maps/geocoding, and event organizers for registrations to their events. Public profile or community content is visible according to the feature used. Providers are contractually selected and access is limited to the purpose.
International disclosure
The controller is in Switzerland. EU data may therefore be processed in Switzerland, for which the European Commission recognises an adequate level of protection. Any other foreign disclosure is made only with an adequacy basis or appropriate contractual safeguards. Provider details can be requested from the controller.
Cookies and storage
PRIMAL currently uses only essential cookies: a 30-day HTTP-only login session, a language preference, and a temporary 30-minute pending-verification cookie. There are no advertising or analytics cookies. Verification codes expire after 15 minutes and their records are removed after expiry; completed or cancelled email delivery records are removed after 90 days. Other data remains while the account or event relationship exists and is then deleted or anonymised when no longer required, subject to legal claims and retention duties.
Your rights
You may request access, correction, deletion, restriction, objection where processing relies on legitimate interests, and a portable copy where applicable. Contact the controller by email. Requests are generally answered within 30 days. You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) and, where the GDPR applies, your competent EU/EEA supervisory authority.
Security and children
Passwords and verification codes are stored only as cryptographic hashes; verification codes in the delivery queue are encrypted. Transport uses HTTPS in production. PRIMAL accounts are limited to persons aged 16 or older. Do not enter health or other sensitive information unless an event form genuinely requires it and gives appropriate information.