Privacy policy
This policy explains which personal data Tessara processes, why, and what rights you have under the revised Swiss Federal Act on Data Protection (revFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
Last updated: 19 August 2026
1. Controller
The controller responsible for the data processing described in this policy is Lyo GmbH, Europaallee 41, 8004 Zürich, Schweiz, reachable at support@tessara.ch. See the Imprint for full details.
2. What data we process
Depending on how you use the Platform, we process the following categories of personal data:
- Account data: name, email address, password hash, account type (company or leader), account status.
- Leader profile data: professional experience, headline, biography, references, languages, availability and, if provided, a CV file and LinkedIn profile. CVs are stored privately and are never publicly visible.
- Company data: company name, industry, size, location, logo, and the leadership needs a company posts.
- Payment metadata: billing name, address and VAT number where provided, and the status/amount of a contact-unlock payment. Card and bank details are processed solely by our payment provider (Stripe) and never reach our own systems.
- Usage data: pages visited, features used and coarse product-analytics events, collected without directly identifying content such as names, email addresses or CVs (see section 8, Cookies).
3. Purposes of processing
- Operating the marketplace: account management, publishing and verifying profiles, matching, contact requests and the contact-unlock mechanism.
- Processing payments for the unlock fee and preventing fraud or abuse of the fee mechanism.
- Communication: transactional emails (confirmations, match and payment notifications, reminders) and, where you have opted in, product updates.
- Security and platform integrity: rate limiting, abuse detection, and maintaining audit trails for verification and payment events.
- Product improvement: aggregated, non-identifying usage analytics to understand how the Platform is used.
4. Legal bases
Where the GDPR applies (e.g. to visitors in the EU/EEA), we rely on: performance of a contract (Art. 6(1)(b) GDPR) for account and marketplace functions; legitimate interest (Art. 6(1)(f) GDPR) for security, fraud prevention and baseline product analytics; and consent (Art. 6(1)(a) GDPR) for optional communications and non-essential analytics, where required. Under the revFADP, processing is generally permitted unless it unlawfully infringes a data subject's personality, and we process personal data only for the purposes stated above and disclosed to you at the time of collection.
5. Processors and locations
We use the following processors to operate the Platform. Each is bound by a data processing agreement. Where a processor is established in a country without an adequate level of data protection, in particular the United States, we rely on the EU Standard Contractual Clauses together with the Swiss addendum and on the provider's own contractual and technical commitments as the transfer mechanism.
- Supabase (database, authentication and file storage): Supabase, Inc., United States. The project's data is held on Amazon Web Services (AWS) infrastructure in the region eu-central-2 (Zurich, Switzerland), so storage and day-to-day processing take place in Switzerland. Where administrative or support access from the United States occurs, the transfer rests on the mechanism described above.
- Vercel (application hosting and content delivery): Vercel, Inc., United States. Server-side rendering is pinned to the fra1 region (Frankfurt, Germany), which is where requests carrying personal data are processed. Static content (pages, images, scripts) is delivered worldwide from Vercel's edge locations, so a visitor outside Europe can be served from an edge location outside Europe. Any resulting transfer to the United States rests on the mechanism described above.
- Stripe (payment processing for the contact-unlock fee): Stripe Payments Europe, Limited, Dublin (Ireland), is the contracting entity for users in the EU/EEA and Switzerland; Stripe, Inc., United States, acts within the same group, in particular for fraud prevention and group-internal processing. Any transfer to the United States rests on the mechanism described above.
- Resend (transactional email delivery): Resend, Inc., United States. Sending for our domain runs over Amazon Simple Email Service in the region eu-west-1 (Ireland), so the messages themselves are handed over and dispatched inside the EU. Transmitted are the recipient's email address and the subject and content of the transactional message. The transfer to the United States that follows from Resend operating the service rests on the mechanism described above.
- PostHog (product analytics): PostHog, Inc., United States, with processing on PostHog's EU cloud (eu.i.posthog.com, hosted in the EU), configured to avoid collecting names, email addresses, CVs or other directly identifying content. Analytics only run after you have accepted them. Where support access from the United States occurs, the transfer rests on the mechanism described above.
- Sentry (error and crash monitoring): Functional Software, Inc., doing business as Sentry, United States, with processing on Sentry's EU region in Germany (ingest endpoint ingest.de.sentry.io). Transmitted are technical error data: the error message and stack trace, browser and operating system, the IP address as connection data, the URL on which the error occurred, and a small sample of performance traces. No user id or account data is attached, because no user identification is configured in the Sentry SDK, and no session replay is enabled, so nothing you see or type on the Platform is recorded. Error events are retained for 90 days and are then deleted. Where support access from the United States occurs, the transfer rests on the mechanism described above.
6. Retention
We keep personal data only as long as we need it for the purposes described above, or as long as a statutory retention duty requires. Once neither applies, the data is deleted or anonymised. Where a period below runs until your account is deleted, a grace period of 30 days follows before the data is irreversibly removed. That grace period exists for two reasons: deletions are sometimes triggered by mistake, and a dispute about a recent match or payment can still surface in the days after. Within those 30 days you can ask us to restore the account; afterwards we cannot.
The following periods apply per category. Where a longer statutory retention duty applies to a document, that duty prevails.
- Account and profile data (name, email address, login data, leader profile, company profile and published leadership needs): until your account is deleted, plus the 30-day grace period. We keep such data while the account exists because it is what the Platform runs on.
- Uploaded documents (CV, profile photo, company logo and documents submitted for verification): until your account is deleted plus the 30-day grace period, and at most 12 months after a profile has been rejected or taken offline, whichever comes first. The 12 months exist so that someone whose profile was rejected can ask for a re-review without submitting everything again.
- Contact requests, matches and the messages exchanged within them: 24 months after the last activity on the request, then deleted or anonymised. They record who agreed to what before a paid unlock, which is what we need to answer a later complaint or refund request.
- Payment records (unlock payments, invoices, refunds, billing name and address, VAT number, payment status): 10 years from the end of the financial year in which the payment was booked. This period is not ours to choose: Swiss commercial law requires accounting records and vouchers to be kept for ten years, and Swiss VAT law requires the same for records relevant to the tax. These records survive the deletion of an account.
- Server logs and audit records: technical logs (IP address, access and error logs, rate-limit counters) are kept for 90 days and are then deleted; internal audit records of verification decisions and payment events are kept for 24 months, and, where they belong to a booked payment, for the 10 years that apply to payment records.
- Analytics data (PostHog): 12 months from collection, then deleted. Analytics are only collected after you have accepted them, contain no names, email addresses or CVs, and stop being collected the moment you withdraw your consent.
- Support correspondence: 24 months after the enquiry is closed. Correspondence about a data protection request (access, correction, deletion) is kept for 3 years, so that we can show a request reached us and how we answered it; correspondence about a payment or a refund is kept with the payment record and follows the 10-year period above.
7. Your rights
Subject to applicable law, you have the right to request access to your personal data, correction of inaccurate data, deletion of your data, and a copy of your data in a portable format. You may also object to certain processing based on legitimate interest and withdraw consent where processing is based on consent.
To exercise any of these rights, contact support@tessara.ch. You can close your account yourself at any time, in the signed-in area under Account. What is deleted and what we are required by law to keep is set out there before you confirm. For all other requests, including a copy of your data, we aim to respond within 30 days.
8. Cookies
We use technically necessary cookies for login and session management, and, where enabled, PostHog analytics cookies to understand product usage. We do not use advertising cookies or third-party ad trackers. See the Cookie Policy for details.
9. Data security
We apply technical and organisational measures appropriate to the risk, including row-level security policies at the database level, private (non-public) file storage for CVs and other sensitive documents with access only via short-lived signed URLs, encrypted transport, security headers and rate limiting on the Platform. Further technical and organisational measures are documented internally and reviewed regularly.
10. Changes to this policy
We may update this policy from time to time to reflect changes to our processing activities or legal requirements. Material changes will be communicated on the Platform.
11. Contact for data protection matters
For any question about this policy or the processing of your personal data, contact support@tessara.ch.