Privacy Policy

Effective: June 2026

This Privacy Policy explains how Leidzirkular.ch processes personal data when our website and services are used.

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP). Where the European Union General Data Protection Regulation (GDPR) applies in an individual case, we also comply with its requirements.

1. Data controller

The controller responsible for data processing is:

Leidzirkular.ch CyberJus GmbH Engelberg 17 6242 Wauwil Switzerland

Email: info@leidzirkular.ch Data protection enquiries: datenschutz@leidzirkular.ch

2. Purpose of Leidzirkular.ch

Leidzirkular.ch enables users to create, manage and share digital obituary notices. This may involve processing bereavement messages, information about funeral services, burials and receptions, RSVP registrations, condolences and recipient lists.

Submitted content may include information about the deceased person and personal data relating to the creator, relatives, guests, recipients or other third parties. The creator is responsible for ensuring that they are authorised to enter, process and publish the relevant information.

3. Data we process

Depending on how our service is used, we process the following data in particular:

3.1 Contact and account data

  • name, if provided
  • email address
  • telephone number where required for verification, notifications or enquiries
  • preferred language
  • login and authentication information
  • technical account ID

3.2 Data used to create an obituary notice

  • name of the deceased person
  • date of birth and date of death, if provided
  • freely entered texts and messages
  • details of the funeral, burial, memorial service or reception
  • event locations, dates and times
  • uploaded photographs
  • visibility settings such as a public link, private link or PIN protection
  • language versions and translations
  • notice status, such as draft, published, under review or disabled

3.3 Recipient and delivery data

When an obituary notice is sent or shared by email, we may process:

  • recipient email addresses
  • recipient names, if provided
  • message language
  • delivery status
  • delivery error messages
  • date and time of delivery

The creator is responsible for being authorised to provide and use these recipient details for delivery.

3.4 Payment data

Payments are handled by external payment providers. We do not store complete credit card or payment details ourselves.

We may process the following payment information in particular:

  • selected package
  • amount
  • currency
  • payment status
  • transaction ID
  • Stripe Checkout Session ID
  • Stripe Payment Intent ID
  • billing and accounting information where required

3.5 RSVP and condolence data

If the relevant functions are enabled, visitors may submit:

  • name
  • email address, if requested
  • acceptance or refusal
  • number of attendees
  • personal message
  • condolence text
  • date and time of submission

Depending on the settings, condolences may be moderated before they are published.

3.6 Support, contact and abuse reports

When you contact us, submit a deletion request or report abuse, we may process:

  • name
  • email address
  • telephone number, if provided
  • message content
  • affected page or obituary notice
  • selected reason for the report
  • internal processing notes
  • request status
  • date and time of the request

3.7 Technical and usage data

When our website is visited, technical data may be processed, including:

  • IP address or shortened or hashed IP address
  • date and time of access
  • pages accessed
  • browser type and version
  • operating system
  • device type
  • referrer URL
  • server logs
  • error logs
  • security and abuse events
  • PIN attempts
  • delivery and system events

Where possible, we use shortened, hashed or anonymised data.

4. Purposes of processing

We process personal data in particular for the following purposes:

  • providing and operating Leidzirkular.ch
  • creating, storing and publishing digital obituary notices
  • managing drafts and published pages
  • authentication and SMS verification where used
  • payment processing
  • sending invitations, notifications and status messages
  • providing RSVP and condolence functions
  • customer service and support
  • handling deletion, correction and privacy requests
  • reviewing and handling abuse reports
  • preventing fraud, abuse, spam and unauthorised publications
  • technical security, error analysis and service stability
  • compliance with legal obligations
  • accounting and evidence of transactions
  • improving our website, texts, templates and functions
  • creating and maintaining translations where the relevant functions are used

5. Legal bases

For users in Switzerland, processing is based on the Swiss FADP, in particular the performance of our service, the consent of the data subject, overriding private interests, compliance with legal obligations, and security and abuse prevention.

Where the GDPR applies, processing is based in particular on:

  • Art. 6(1)(b) GDPR for contract performance
  • Art. 6(1)(c) GDPR for compliance with legal obligations
  • Art. 6(1)(f) GDPR for legitimate interests
  • Art. 6(1)(a) GDPR where consent is given

Our legitimate interests include operating the platform securely, preventing abuse, handling support cases, analysing technical errors and improving our offering.

6. Publication and visibility of obituary notices

The creator decides whether an obituary notice is public, accessible through a private link or protected by a PIN, where these functions are available.

Public notices can be accessed by people who know the link or find the page by other means. Depending on the settings, public pages may also be indexed by search engines. Private or PIN-protected pages are protected from search engines where possible using technical measures such as noindex. Absolute protection against onward sharing by recipients or visitors cannot be guaranteed.

The creator is responsible for not publishing information they are not authorised to publish.

7. Sensitive personal data and content

Depending on their content, obituary notices may include particularly sensitive information concerning health, religion, beliefs or family circumstances. Such information is generally not required to use Leidzirkular.ch and should only be entered where this is expressly intended and lawful.

Causes of death, diagnoses, religious information and private addresses of relatives are not mandatory fields.

8. Third-party providers and processors

We use external service providers to operate Leidzirkular.ch technically. They process data only to the extent required for the relevant service.

The following providers may currently be used in particular:

Supabase

Supabase is used for the database, authentication, storage and certain system functions. The Leidzirkular.ch Supabase project is configured in the Zurich, Switzerland region. The central database and primary storage are therefore operated in the Supabase Zurich region.

Supabase or its subprocessors may nevertheless process certain technical, administrative or security-related data outside Switzerland where this is required for operation, maintenance, security or service delivery.

Vercel

Vercel is used for hosting, website delivery and technical infrastructure. Technical access data, server logs and deployment data may be processed.

Stripe

Stripe is used for payment processing. Payment and transaction data is transmitted to Stripe; we do not store credit card data. Depending on the processing, Stripe may act as a processor or an independent controller.

Resend

Resend is used to send transactional emails. Email addresses, message content, delivery status and technical delivery data may be processed. Resend may store or process data in the United States.

Other technical providers

Depending on the function, other providers may be used for security, error analysis, captchas, translations, image generation, PDF creation or email delivery. We take care to use only providers required for the relevant purpose.

9. International data transfers

Personal data may be processed in Switzerland, the EU, the EEA, the United States or other countries in which our providers or their subprocessors operate.

Where data is transferred to countries without an adequate level of protection, we use appropriate safeguards where required, including standard contractual clauses, data processing agreements, recognised privacy mechanisms or other legally permitted bases.

Despite these measures, it cannot be completely ruled out that foreign authorities may access data under the laws applicable in their jurisdiction.

10. Automatic translations and AI functions

Leidzirkular.ch may offer text suggestions, automatic translations or similar assistance functions.

When these functions are used, the necessary texts and contextual information may be transmitted to technical providers. We aim to transmit only the information required and to minimise sensitive content.

Where external AI or translation providers are used, we provide the necessary information within the relevant function or in this Privacy Policy.

11. Cookies and similar technologies

We use cookies and similar technologies required to operate the website, in particular for:

  • session management
  • authentication
  • security
  • language settings
  • checkout processes
  • PIN access where enabled

If we use analytics, marketing or tracking cookies in the future, we will provide information and obtain consent where required.

We currently do not use advertising cookies.

12. Server logs and security

Technical logs may be stored to ensure the security and stability of our platform. They are used in particular for:

  • detecting technical errors
  • preventing abuse and spam
  • analysing security incidents
  • preventing unauthorised access
  • reviewing abuse reports

Where possible, IP addresses are shortened, hashed or anonymised.

13. Retention periods

We retain personal data only for as long as required for the relevant purposes or by statutory retention obligations.

The following principles generally apply:

  • drafts are stored for as long as needed by the creator or until deleted
  • published notices remain stored while active or until a justified deletion, deactivation or anonymisation
  • recipient and delivery data is retained only as long as required for delivery records, support and abuse prevention
  • support, privacy and abuse requests are retained as long as needed for handling and documentation
  • technical logs are generally retained only briefly unless a security or abuse investigation is required
  • payment and accounting data is retained in accordance with legal obligations, generally for ten years

Once the retention period expires, data is deleted or anonymised unless legal, contractual or legitimate reasons require continued retention.

14. Rights of data subjects

Under applicable data protection law, data subjects have the following rights in particular:

  • access to personal data being processed
  • correction of inaccurate data
  • deletion of personal data
  • restriction of or objection to certain processing
  • provision or transfer of data where applicable
  • withdrawal of consent
  • complaint to a competent data protection authority

Requests may be sent to: datenschutz@leidzirkular.ch

The deletion or objection request page provided on the website may also be used. Submit a deletion request

We may require proof of identity or authority, particularly where a request concerns an obituary notice, a deceased person or information about relatives.

15. Deletion, deactivation and objections concerning notices

If an obituary notice contains incorrect information, was published without authorisation or infringes personality rights, correction, deactivation or deletion may be requested.

Particularly urgent cases, such as a report that the person is alive or that a publication is abusive, are reviewed as a priority. During the review, access may be restricted or the notice may be taken offline.

16. Data security

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration or disclosure.

These measures include in particular:

  • encrypted HTTPS transmission
  • access restrictions
  • authentication mechanisms
  • role and permission concepts in the admin area
  • logging of security-related operations
  • data minimisation
  • regular review of security-related settings

Absolute protection cannot be guaranteed for electronic data transmission and internet-based services.

17. Email communications

Email content may pass through different servers depending on the provider and transmission route. Email communication is not always fully confidential. Please send particularly sensitive information only where necessary.

18. Links to external websites

Our website may contain links to external websites. Their operators are responsible for their content and data processing, and their respective privacy policies apply.

19. Changes to this Privacy Policy

We may amend this Privacy Policy at any time, particularly when we develop our services, introduce new functions, use different providers or legal requirements change.

The current version is available on our website.

20. Right to complain

Data subjects may lodge a complaint with a competent data protection supervisory authority.

In Switzerland, this is in particular the Federal Data Protection and Information Commissioner (FDPIC).

Effective: June 2026