Skip to content
Seat · Schloss Wylihof · Luterbach · Switzerland

Privacy statement

Privacy

CIFA processes personal data solely within the applicable data protection laws, in particular the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).

1Controller

Confédération Internationale de la Formation et de l'Esthétique (CIFA), Wylihof 7, CH-4542 Luterbach.
Email: post@cifaworld.ch

2What this website does not do

This website is deliberately built so that simply visiting it generates as little data as possible. It:

  • sets no cookies — not even technically necessary ones
  • loads no fonts, maps, videos or scripts from third-party hosts; everything is served from our own server
  • uses no analytics or tracking tools, in particular no Google Analytics
  • embeds no social media plugins
  • contains one form only — the certificate check; its input is sent solely to the verification service (see below) and not stored

This is why the site carries no consent banner. That is not an omission but a consequence of how it is built.

3Server logs

When pages are requested, the hosting provider's web server necessarily logs access data — as a rule IP address, time, file requested, volume transferred, referring page, browser and operating system identifiers. These logs serve solely secure operation and fault diagnosis, are not combined with other data and are deleted after seven days.

The website is operated on servers of hosttech GmbH, Seestrasse 15a, 8805 Richterswil, Switzerland, which acts as a processor on our behalf.

When you use the certificate check, the number you enter is sent directly from your browser to the verification service at csl3.de, which answers whether a document with this number exists. The number is not stored for this purpose; to prevent misuse, the number of requests per IP address is limited for a short time.

The legal basis is the legitimate interest in secure operation (Art. 6(1)(f) GDPR).

4Data in institutional procedures

Anyone contacting CIFA or initiating a procedure transmits data by email or post. The following are processed in particular:

  • name and legal form of the organisation
  • contact persons and contact details
  • information on structure, quality and education, as far as required for assessment
  • correspondence within the procedure

The purposes are handling institutional enquiries, conducting certification and recognition procedures, and administering memberships. The legal bases are Art. 6(1)(b) GDPR (pre-contractual and contractual measures), (f) (legitimate interest) and statutory obligations.

Personal data is not used for mass advertising communication without consent.

5International transfer

As CIFA operates internationally, processing may also take place outside the data subject's country of residence. Where data is transferred to third countries, appropriate safeguards such as standard contractual clauses are applied.

6Retention

Personal data is stored only for as long as required for the respective purpose or as long as statutory retention obligations exist.

7Rights of data subjects

Data subjects have the right to information, rectification, erasure, restriction of processing, data portability and objection. Please address requests to the contact given above.

8Data security

CIFA takes appropriate technical and organisational measures to protect personal data against unauthorised access, loss and misuse. The website is served exclusively over an encrypted connection (HTTPS).

9Changes

This statement may be updated as required. The version published at the time applies.

As at 28 September 2026 · Luterbach, Switzerland