Legal
Privacy Policy
Last updated: 11 September 2026
1. Who we are
Viviane Guignard, Florastrasse 21, 8008 Zurich, Switzerland, operates the website https://good-trials.ch (the “Service”) as a sole proprietorship. She is the data controller responsible for your personal data. For data protection enquiries, contact: [email protected]
2. Applicable law
This policy is governed by the Swiss Federal Act on Data Protection (nDSG), which entered into force on 1 September 2023. Where the European Union’s General Data Protection Regulation (GDPR) applies to residents of EU/EEA member states, we comply with its requirements as well. References to “applicable data protection law” mean whichever of these instruments applies to you.
3. Data we collect and why
| Category | Data | Purpose & legal basis |
|---|---|---|
| Account | Name, email, hashed password | Authentication and account management. Basis: contract performance (nDSG Art. 31 para. 2 lit. b). |
| Progress | Module completions, quiz scores, timestamps | Enabling the learning experience and certificate issuance. Basis: contract performance. |
| Certificate | Name, score, date, course level | Issuing and verifying your credential, and allowing a third party to check it. See section 6 for exactly what the public endpoint discloses. Basis: contract performance. |
| Correspondence | Emails you send us, including course feedback and any answers to the course evaluation questionnaire | Answering you, and improving the course. Sending feedback is entirely optional and never affects your certificate. It reaches us as ordinary email and is held in our mailbox, not stored in your course account. Feedback is reported to swissethics only in summary, never per learner. Basis: legitimate interest. |
| Payment | Transaction ID, payment status (Stripe) | We do not store card details; Stripe processes and stores payment data under its own privacy policy. We receive only payment confirmation. Basis: contract performance & legal obligation. |
| Email logs | Email delivery metadata (Resend) | Transactional emails (welcome, certificate). Basis: contract performance. |
| Server logs | IP addresses, request timestamps, browser type | Security, fraud prevention, and debugging. Retained for 30 days. Basis: legitimate interest. |
4. How we use your data
We use your data only for the purposes described above. We do not:
- Sell, rent, or trade your personal data to third parties
- Use your data for advertising or profiling
- Process your data for purposes incompatible with those stated above
5. Third-party processors
We share data with the following processors under data processing agreements:
- Hosting provider — application server located in Germany (EU/EEA; no transfer outside the EEA)
- Cloudflare — CDN, reverse proxy and TLS termination (USA; certified under the EU–US Data Privacy Framework, with EU Standard Contractual Clauses as fallback)
- Stripe — payment processing (USA/Ireland; SCCs apply)
- Resend — transactional email delivery (USA; SCCs apply)
- Supabase — PostgreSQL database (Supabase, Inc., USA; EU Standard Contractual Clauses under its data processing agreement)
6. Certificate verification (public endpoint)
The URL https://good-trials.ch/api/certificate/verify/[id] is publicly accessible without authentication, so that an employer or ethics committee can check your credential without an account. It serves two versions of the same record.
- The page a browser shows — your name, the course level, the date of issue, the certificate identifier, and the guideline version the course was reviewed against. It does not show your assessment score.
- The machine-readable version (an Open Badges 3.0 credential, served to software that requests JSON) — the same fields, plus your final assessment score and an irreversible SHA-256 hash of your email address. The hash lets a badge platform confirm the credential belongs to a given address without the address itself being published.
We publish this to perform our contract with you: a certificate that cannot be checked by a third party would not be a certificate. You may ask us to withdraw the public endpoint at any time by contacting us; this will invalidate your certificate for third-party verification purposes.
7. Data retention
- Account and progress data: retained for as long as your account exists, and deleted once you ask us to delete it
- Correspondence: retained for as long as it is useful to answer you and to improve the course, and deleted once you ask us to delete it
- Certificate data: retained indefinitely while the certificate is valid
- Payment records: retained for 10 years per Swiss accounting obligations (OR Art. 958)
- Server logs: 30 days
8. Your rights
Under the nDSG (and GDPR where applicable) you have the right to:
- Access — receive a copy of the personal data we hold about you
- Correction — have inaccurate data corrected
- Deletion — request erasure of your data (subject to retention obligations above)
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest
- Complaint — lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch
To exercise any of these rights, email [email protected]. We will respond within 30 days.
9. Cookies and tracking
We use cookies only to sign you in and keep you signed in. Our authentication library (Auth.js) sets a session cookie — __Secure-authjs.session-token over HTTPS, or authjs.session-token in local development — together with a CSRF token cookie and a callback-URL cookie that the sign-in flow needs. We do not use analytics cookies, advertising cookies, or third-party tracking scripts. No cookie consent banner is required for strictly necessary cookies of this kind under Swiss law.
10. Security
Passwords are hashed using bcrypt (cost factor 12) and are never stored in plaintext. The site is served over HTTPS, so traffic between your browser and the Service is encrypted in transit.
11. Changes to this policy
We may update this policy when required by changes in the law or our practices. Any update is published on this page with a new “Last updated” date, which is the date the current version took effect. Please check back here for the version that applies to you.
Questions? Contact [email protected]