tridaquaDeutsch

Privacy policy

Last updated: 17 September 2026. This policy explains which personal data we process on tridaqua.com, my.tridaqua.com, the Tridaqua software and a future shop, for what purpose and what rights you have. It is based on the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR). This is a convenience translation. In case of discrepancies, the German version prevails.

1. Controller

  • Michael Matefi, Private individual, operator of the Tridaqua brand
  • Kriens LU, Switzerland
  • WhatsApp: +41 79 464 64 79

For any privacy matter, including exercising your rights, simply send a message to these contact details.

2. Visiting the website

When you visit the website, our hosting provider Vercel processes technically necessary data: IP address, date and time, page requested, browser and operating system, referrer. This serves delivery, security and troubleshooting and is deleted after a short time. Legal basis under the GDPR: legitimate interest (Art. 6(1)(f)).

The domains run through Cloudflare (DNS, protection against attacks), which may also process your IP address.

3. Cookies and Google Analytics

We use Google Analytics 4 (Google Ireland Ltd., Dublin, and Google LLC, USA) to understand how the website is used: pages viewed, time spent, approximate origin (country, city), device type, browser, scroll depth and clicks on external links.

Google Analytics only sets cookies if you choose "Accept" in the notice (consent, GDPR Art. 6(1)(a)). Without consent, the Google service only sends cookieless signals that cannot be traced back to you (Google Consent Mode). Google Signals, advertising features and personalised ads are switched off. Google Analytics 4 does not store IP addresses.

Your choice is stored in your browser's local storage. You can change it and withdraw consent at any time via "Cookie settings" at the bottom of every page.

We retain Google Analytics data for at most 14 months. More: policies.google.com/privacy.

4. Waiting list

If you join the waiting list, we store your email address, language and time of sign-up to inform you about the launch of Tridaqua. You confirm the sign-up via a link in an email (double opt-in). To protect against automated sign-ups we use Cloudflare Turnstile. Legal basis: consent. You can unsubscribe at any time, and we will then delete the address.

5. Account on my.tridaqua.com

For an account we process:

  • Login data: email address; when signing in with Apple or Google, the email and identifier provided by them; second factor settings
  • Information about your systems: tank name, paired Tridaqua devices, settings, invited members
  • Readings and states of your devices (for example temperature, pH, conductivity, light, pumps, dosing) as well as alerts and logs, if you pair your device with the cloud
  • Push subscriptions for alerts on your phone
  • Technical session data (session cookies strictly required for signing in)

The purpose is to operate your account and provide remote access to your systems. Legal basis: contract (GDPR Art. 6(1)(b)). The data is stored with Supabase in the Zurich region (Switzerland). In your account you can export your data and delete the account.

6. Tridaqua device and software

The Tridaqua device works locally on your network. Readings, settings and logs stay on the device unless you pair it with my.tridaqua.com; only then is the data listed in section 5 transferred. To check for updates the device contacts us, which transmits its IP address.

7. Contact via WhatsApp

If you contact us via WhatsApp, we process your phone number, name and the content of your message to answer your request. WhatsApp is operated by WhatsApp Ireland Ltd. and Meta Platforms Inc., USA; their privacy terms apply. If you prefer not to use WhatsApp, please ask for another way to contact us.

8. Shop orders

Once the shop is available, we process name, delivery and billing address, email, phone number, products ordered, payment status and serial numbers. Payment data is processed by the payment provider; we do not receive full card details. For shipping we pass name and address to the carrier. Legal basis: contract. Accounting records are kept for 10 years (Art. 958f Swiss Code of Obligations).

9. Recipients and processors

We only share personal data where necessary for the purposes described, with:

  • Vercel Inc., USA (website hosting)
  • Supabase Inc., USA, with data stored in Zurich (database, authentication, storage)
  • Cloudflare Inc., USA (DNS, attack protection, bot protection, secure connections)
  • Google Ireland Ltd. and Google LLC, USA (Google Analytics; Sign in with Google, if chosen)
  • Apple Distribution International Ltd., Ireland, and Apple Inc., USA (Sign in with Apple, if chosen)
  • an email delivery service for login codes and notifications
  • WhatsApp Ireland Ltd. and Meta Platforms Inc., USA (contact)
  • later, payment and shipping providers for orders

We do not sell personal data or share it for advertising purposes.

10. Transfers abroad

Some recipients are located in the EU or the USA or may access data from there. EU and EEA states provide adequate protection under Annex 1 of the Swiss Data Protection Ordinance. For US companies certified under the Swiss-U.S. Data Privacy Framework, the Swiss Federal Council has also recognised adequate protection since 15 September 2024. Where this does not apply, we rely on the standard contractual clauses approved by the European Commission and recognised by the Swiss FDPIC.

11. Retention

We keep personal data only as long as the purpose requires or the law demands: server logs for a few days, analytics data for at most 14 months, waiting list entries until you unsubscribe or launch, account data until the account is deleted, order and accounting data for 10 years.

12. Your rights

Within the applicable law you have the right to:

  • access your personal data (Art. 25 FADP, Art. 15 GDPR)
  • rectification of inaccurate data
  • erasure or restriction of processing
  • receive or transfer your data in a common electronic format (Art. 28 FADP, Art. 20 GDPR)
  • object to processing based on legitimate interest
  • withdraw consent with effect for the future

Contact us using the details in section 1. We may ask for proof of identity. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) or, in the EU, with the supervisory authority of your country of residence.

13. Security

We protect data with appropriate technical and organisational measures: encrypted connections (HTTPS/TLS), access rules at database level, two-factor sign-in, access only by authorised persons. No one can guarantee absolute security.

14. No automated individual decisions

We do not make decisions based solely on automated processing that have legal effects on you, and we do not carry out high-risk profiling.

15. Changes

We update this policy when our services or the law change. The version published here applies.