Skip to main content

Privacy Policy for the Hello Geneva App

This Privacy Policy explains how the Geneva Tourism & Convention Foundation (hereinafter the “Publisher”) collects, processes and protects the personal data of users (hereinafter, individually, the “User”) of the Hello Geneva mobile application (hereinafter the “App”).

This Privacy Policy forms an integral part of the App’s Terms and Conditions of Use. By using the App, the User acknowledges that they have read and accepted the terms of this Privacy Policy.

1. Data controller

The data controller responsible for the personal data collected through the App is the Publisher, namely:

Geneva Tourism & Convention Foundation

Place de Cornavin 7

1201 Geneva

Switzerland

Contact: info@geneve.com

If the User contacts the Publisher using the contact details above, the information provided (including, in particular, the User’s first and last name, address and enquiry) will be processed by the Publisher solely for the purpose of responding to the User’s request.

2. Principles of processing and legal compliance

The Publisher undertakes to process personal data in accordance with the principles of lawfulness, fairness, proportionality, purpose limitation and data accuracy, as set out in the Swiss Federal Act on Data Protection (hereinafter the “FADP”), its implementing ordinance and, where applicable, the General Data Protection Regulation (GDPR). The Publisher processes only such personal data as is strictly necessary for the use of the App and for the fulfilment of its intended purpose.

3. Personal data collected and purposes of processing

The Publisher processes different categories of personal data for specific purposes:

(a) Data provided by the User when creating a profile:

  • Data collected: The User’s interests, group composition (travelling alone, with family or as a couple), dates of stay, language preferences and status (resident or visitor), as provided by the User when creating their profile.

  • Purpose: To create and manage the User’s profile, secure access to the App through an anonymous technical identifier (UUID), and personalise the User’s experience of the App, including by providing relevant weather information.

(b) Data collected when ordering and downloading tourist passes:

  • Data collected: The User’s first and last name, email address, booking reference and the name of the accommodation where they are staying (depending on the type of pass ordered). The pass provider may also collect the same information in respect of persons travelling with the User for whom the User orders a similar pass, it being understood that the User is solely responsible for obtaining the consent of those persons to do so.

  • Purpose: To enable the User to order tourist passes and to issue passes that can be downloaded within the App.

(c ) Geolocation data:

  • Data collected: Geolocation data from the device used, namely the geographical coordinates (latitude and longitude) of the User’s device at a given point in time.

  • Purpose: To display the User’s location on the map and identify nearby points of interest. This data is also collected when the User interacts with the conversational assistant in order to enhance the User’s experience.

(d) Data collected automatically through use of the App:

  • Data collected: Technical data (including device type, operating system version, IP address and user agent), together with the dates and times of access.

  • Purpose: To ensure the proper technical operation of the App, maintain its security, prevent misuse, carry out diagnostics in the event of technical issues, and resolve any technical incidents.

(e) Data relating to interactions with the conversational assistant (AI chatbot):

  • Data collected: The content of conversations (questions and responses), IP address, an identifier used to distinguish the User, and geolocation data.

  • Purpose: To provide a response to the User’s request. Conversations are subsequently anonymised in all cases so that they may be used to train and improve the conversational assistant’s algorithms, without any possibility of linking the data back to an individual User.

  • Warning: The User is expressly informed that they must not disclose any personal, sensitive or confidential information when interacting with the conversational assistant.

The Publisher does not collect or process any sensitive personal data within the meaning of Article 5 of the Swiss Federal Act on Data Protection (FADP).

4. Disclosure of data to third parties

The Publisher does not sell, trade or otherwise transfer the User’s personal data to third parties for commercial purposes.

Personal data may be disclosed to processors (including technical service providers) where this is necessary to fulfil the purposes of the App described above. Such processors are selected on the basis of their compliance with applicable data protection requirements and are contractually bound to ensure the security and confidentiality of the personal data entrusted to them. The User’s attention is drawn to the fact that certain processors are established in the United States, which does not provide the same level of data protection as Switzerland or the European Union.

Personal data is transferred to the following service providers:

(a) Primary hosting provider:

Service provider

Country

Data concerned

Infomaniak (MySQL, Redis, S3, SMTP)

Switzerland

All personal data collected through the App

(b) Transfers outside Switzerland / the European Union:

Service provider

Country

Data concerned

Google (Gemini 3 Flash Preview) via OpenRouter

United States 

Conversations with the AI assistant and User context data used, in particular, to generate dashboard widgets. The Publisher may change the AI model used, which may result in the data being processed in a different country depending on the provider of the model.

Mapbox

United States

GPS coordinates (for reverse geocoding) when using the map, and data transmitted to the large language model (LLM) in connection with use of the conversational assistant.

(c ) Other service providers:

Service provider

Country

Data concerned

Omnisoftory

Switzerland

Booking data relating to Guest Cards

OpenMeteo

European Union

GPS coordinates used to provide weather information (without the use of an API key)

(d) Internal tools used by Atipik (the Publisher’s App developer):

Tool

Country

Data concerned

Langfuse

Switzerland

Prompts and response logs relating to the conversational assistant (AI quality monitoring and tracing)

Sentry

Switzerland

Stack traces generated in the event of a technical error

5. Data security

The Publisher implements appropriate technical and organisational security measures to protect the User’s personal data against accidental or unlawful destruction, loss, alteration, disclosure or unauthorised access. These measures include encryption of communications, pseudonymisation of data where possible, and strict access controls.

However, the absolute security of the data collected cannot be guaranteed. In particular, the User’s attention is drawn to the fact that data transmitted via the internet or by email when contacting the Publisher may be intercepted and read by unauthorised third parties.

In the event of a data security breach likely to result in a high risk to the User’s personality or fundamental rights, the Publisher undertakes to notify the incident to the Federal Data Protection and Information Commissioner (FDPIC) and, where necessary, to inform the User concerned, in accordance with Article 24 FADP.

6. Data retention

Personal data is retained only for as long as is necessary to fulfil the purposes for which it was collected, or for such longer period as may be required by law.

The User’s profile data is retained for as long as the User’s account remains active. The User may delete their profile at any time. Conversations with the conversational assistant are automatically anonymised, although geolocation data associated with anonymised conversations is retained. Data collected for technical purposes (including, in particular, the IP address and user agent) is retained for a period of one year. 

7. User rights

In accordance with the FADP, the User has the following rights in relation to their personal data:

  • Right of access: The User may request confirmation from the Publisher as to whether personal data relating to them is being processed and, where this is the case, obtain information concerning such processing.

  • Right to rectification: The User may require the Publisher to rectify any inaccurate or incomplete personal data relating to them.

  • Right to erasure: The User may request that the Publisher erase their personal data, subject to any legal obligations requiring the Publisher to retain such data.

  • Right to data portability: The User may request that the Publisher provide their personal data in a commonly used electronic format.

  • Right to object: The User may object to the processing of their personal data in specific circumstances, subject to the existence of legitimate grounds for the processing.

To exercise these rights, the User may submit a written request, together with proof of identity, to the postal or email address set out in Section 1 of this Privacy Policy. In addition, the User may delete their profile and all associated data at any time through the App’s settings.

8. Amendments to the privacy policy

The Publisher reserves the right to amend this Privacy Policy at any time, in particular to reflect changes in applicable laws, regulations or technology. Where any material changes are made, the User will be informed through the App. The version of the Privacy Policy published within the App is the version currently in force.

Version 1.0 – Effective date: 13.07.2026