Privacy hub

Privacy Policy

A clear overview of how Brain-Shot Academy handles personal data across its services.

Updated 23 August 2026

1. Controller

Brain-Shot Academy AG
Birsstrasse 320
4052 Basel
Switzerland

Email: privacy@brain-shot.academy
General contact: contact@brain-shot.academy

In this notice, “Brain-Shot Academy,” “we,” “us,” and “our” mean Brain-Shot Academy AG.

2. Scope

This notice applies when Brain-Shot Academy processes personal data through websites, applications, accounts, learning and event services, commerce, support, or related services that we operate.

Some services use a common account or shared operational systems. Where this is necessary to provide or secure a service, relevant identity, access, entitlement, support, and security data may be used across those services.

This notice does not apply to third-party services that we do not control. Those services are governed by their own privacy information.

3. Personal data and sources

Depending on how you interact with us, we may process:

  • identity, contact, and account data, such as your name, contact details, account identifiers, login and account status;
  • service and participation data, such as settings, permissions, entitlements, learning progress, event participation, and recordings where a session is recorded;
  • order and billing data, such as purchases, subscriptions, invoices, payment status, refunds, and accounting records;
  • communications data, such as enquiries, support messages, bookings, and communication preferences;
  • technical and security data, such as device, browser, network, session, log, usage, fraud-prevention, and security information; and
  • preference and consent data, including cookie choices, language preferences, unsubscribe records, and evidence of consent.

We obtain personal data from you, from your use of our services, from your device or browser, and from service providers or business partners where this is necessary to complete a transaction, provide a requested service, maintain security, or comply with law. Where data is not collected directly from you, the categories and sources are described above or in information provided for the relevant service.

Where the GDPR applies, we process personal data for the following purposes and legal bases:

PurposeLegal basis
Provide websites, applications, accounts, content, learning, events, purchases, and other requested servicesPerformance of a contract or steps requested before entering into a contract
Manage accounts, access, entitlements, service communications, and supportPerformance of a contract; our legitimate interests in operating and supporting our services
Process payments, invoices, refunds, accounting, tax, and required business recordsPerformance of a contract; compliance with legal obligations
Administer and, where applicable, record live or group sessionsPerformance of a contract; our legitimate interests in delivering and documenting the service; consent where required
Prevent fraud, abuse, unauthorised access, and technical incidents, and protect users and servicesOur legitimate interests in security and service integrity; compliance with legal obligations where applicable
Measure reliability and improve servicesOur legitimate interests in maintaining and improving our services; consent where required for optional technologies
Send marketing and measure campaignsConsent where required; otherwise our legitimate interests where permitted by applicable law
Record and respect choices, meet legal duties, and establish, exercise, or defend legal claimsCompliance with legal obligations; our legitimate interests in governance and protecting our rights

Our legitimate interests include operating and securing our services, supporting users, preventing misuse, improving reliability, maintaining appropriate records, and protecting our legal and commercial interests. We rely on those interests only where they are not overridden by your interests or fundamental rights.

Where processing is based on consent, you may withdraw it at any time without affecting processing that took place before withdrawal. Marketing messages include an unsubscribe method where required.

Where Swiss data-protection law applies, we process personal data in accordance with the applicable principles and requirements of that law.

5. Data you must provide

Fields marked as required, and information reasonably necessary for a requested service, contract, payment, security check, or legal duty, must be provided for that purpose. Without it, we may be unable to create an account, provide the requested service, complete a transaction, or respond to a request. Other information is optional unless we explain otherwise when collecting it.

6. Recipients

Where necessary for the purposes above, personal data may be disclosed to:

  • hosting, infrastructure, database, authentication, security, and technical-service providers;
  • communication, support, customer-management, event, learning, media, and content-delivery providers;
  • payment, billing, accounting, and professional advisers;
  • other parties involved in a transaction or service that you request; and
  • public authorities, courts, or other parties where disclosure is required or permitted by law.

Recipients process personal data under our instructions where they act as processors. Some recipients, such as payment providers or public authorities, may process data as independent controllers under their own legal obligations.

7. International transfers

Personal data may be processed outside Switzerland or the country where you are located. The current principal destination countries and the safeguards used for those transfers are described in our International Transfers page.

For countries without a recognised adequate level of protection, we use an applicable lawful mechanism, such as approved standard contractual clauses and supplementary protections. You may contact us for information about the safeguards relevant to your data.

8. Retention

We keep personal data only for as long as necessary for the purpose for which it was collected. In determining the period, we consider the nature of the data, the service or relationship, legal retention duties, security and evidential needs, limitation periods, disputes, and whether the data can be deleted or anonymised.

In general:

  • account, service, entitlement, learning, and participation records are kept while the account or service relationship is active and afterwards only as needed for closure, security, continuity, or legal claims;
  • billing, tax, accounting, and other legally required records are kept for the applicable statutory period;
  • communications, support, security, consent, and preference records are kept for as long as needed for the relevant purpose and to demonstrate or protect applicable rights; and
  • recordings are kept for the period communicated for the relevant session or programme and are then deleted unless a legal or evidential need requires longer retention.

9. Cookies and similar technologies

We use cookies and similar technologies to provide and secure services, remember choices, and, where permitted, measure use or campaigns. Details are provided in our Cookie Policy and Cookie Inventory.

10. Automated decisions

We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. If this changes, we will provide the information and review rights required by applicable law before such processing begins.

11. Your rights

Depending on the applicable law and circumstances, you may have the right to:

  • obtain information about and access to your personal data;
  • correct inaccurate personal data;
  • request deletion or restriction of processing;
  • object to certain processing;
  • withdraw consent;
  • receive personal data in portable form where applicable; and
  • lodge a complaint with a competent supervisory authority.

To exercise a right, email privacy@brain-shot.academy. We may need to verify your identity.

12. EU representative

For the purposes of the GDPR, our representative in the European Union is Prighter Group with its local partners. You may contact the representative or submit a rights request through:

https://app.prighter.com/portal/Brain-Shot-Academy-AG

13. Complaints

You may complain to the competent data-protection authority, including the Swiss Federal Data Protection and Information Commissioner or, where applicable, the authority in the EEA country where you live, work, or believe an infringement occurred.

We encourage you to contact us first so that we can try to resolve the matter.

14. Changes and contact

We may update this notice when our processing or legal obligations change. We will update the date above and provide any additional notice required by law.

Questions may be sent to:

Brain-Shot Academy AG
Birsstrasse 320
4052 Basel
Switzerland
privacy@brain-shot.academy