Your data. Transparently protected.
Here you can find out what data Mapresto processes, what it is used for and what rights you have.
Privacy Policy
General
General
Mapresto warmly welcomes you to the Mapresto website. We appreciate your use of our mobile apps and our services.
Mapresto, located in Switzerland, is the data controller for most of the services described here.
Mapresto places great importance on adequate data protection. Below, we inform you about how we handle your personal data in connection with the use of our services ("Privacy Policy").
By continuing to use Mapresto's services, you confirm that you are at least 18 years old. Please note that we may amend this Privacy Policy from time to time. The current version applies according to the update note (last updated: 24. September 2026).
Purpose and scope of the privacy policy
Purpose and scope of the privacy policy
It is of utmost importance to us to protect your privacy and to ensure the lawful handling of the personal data of all users of our Electronic Services. We are aware that by using our Electronic Services you may entrust us with personal information ("Data"), and we want to assure you that we take our responsibility for protecting and securing this Data very seriously. Therefore, with this Privacy Policy, we inform you about what data we process when you use our Electronic Services, for what purpose, how we process it, to whom we disclose data, and what security measures we have taken to protect your Data.
This Privacy Policy applies to all Data that we receive as a result of your use of our Electronic Services. It does not apply to Data that we receive through other channels, nor to Third-Party Electronic Services ("Third-Party Electronic Services"), even if you access them via links from our Electronic Services or if they are necessary for the provision of our Electronic Services. We have no influence over the content and privacy policies of third-party electronic services and therefore cannot assume any responsibility for them.
Type of processed data
Type of processed data
As soon as you use our Electronic Services, our backend systems may automatically record details of your usage (e.g., , your IP address, the type of browser you are using, the HTTP header user agent, device-specific information, the content you accessed on our website including date and time, usage and user interaction, and the website from which you were redirected to our Electronic Services). Furthermore, we process personal data such as name, address, email address, telephone number, date of birth, gender, and other data that you provide when you register to use our Electronic Services or fill out a registration form or message field for the newsletter, a product demonstration, etc.
Legal basis and purpose of data processing
Legal basis and purpose of data processing
We process the data on the following legal bases:
- Legitimate interest of Mapresto or third parties;
- Your consent (provided the processing is based on a specific request for consent, for example for sending newsletters for which you have registered);
- Fulfillment of contractual obligations and implementation of measures prior to the conclusion of contracts;
- Legal requirements.
We process the data for the following purposes:
- Provision Electronic services, e.g., B., to assist you with registration processes, setting user preferences, and responding to your feedback and problem reports;
- : Administration, research, and development related to the services;
- : Marketing and advertising measures (e.g., B., sending newsletters via email, online advertising);
- : Analysis and monitoring of the use of electronic services, related user behavior, and navigation;
- : Verification of the identity and suitability of customers for specific products and services;
- : Creation of a basis for future information about the products offered by Mapresto and Services and to improve their quality;
- Ensuring the security and operational stability of our IT environment;
- Enabling application processes in accordance with the data processing and privacy policy for applicants, to which you give your consent before the start of the application process;
We process your personal data in accordance with applicable data protection laws and for as long as necessary.
Disclosure and transfer of your data
Disclosure and transfer of your data
All persons and companies mentioned that receive data are obliged to comply with the applicable national and international data protection laws as well as the data protection standards of Mapresto.
Mapresto may transfer your data to countries outside of Switzerland:
- for the purpose of providing electronic services;
- if you have given your consent (e.g., in your contracts with Mapresto or within the framework of data protection settings); or
- based on legal requirements, following an official request, or within the framework of comparable processes in accordance with applicable law.
In most cases, your data may be transferred to countries. We may also transfer data without your consent if it is necessary for the establishment, exercise, or enforcement of legal claims, or if the physical integrity of a data subject needs to be protected. The laws of some countries to which Mapresto transfers your data may not offer a level of protection for personal data comparable to that of Switzerland or the EU. In these cases, Mapresto will generally ensure adequate data protection, for example, by concluding data transfer agreements with the recipients of your data located in those countries. These include agreements approved by the European Commission and the Federal Data Protection and Information Commissioner (FDPIC), also known as standard contractual clauses. You can request a sample data transfer agreement, such as the one commonly used by Mapresto, from the Data Protection Officer (“DPO”; contact details below).
Safety measures of Mapresto
Safety measures of Mapresto
Mapresto takes appropriate technical and organizational security measures to protect your data processed in the IT environment controlled by Mapresto against unauthorized access, misuse, loss, and/or destruction.
Mapresto implements both physical and electronic as well as procedural security precautions. These include, for example, the use of firewalls, personalized passwords, and encryption and authentication technologies. Our employees and authorized service providers are bound by confidentiality agreements and are obligated to comply with data protection regulations. Furthermore, access to personal data is strictly limited to those employees and third parties (e.g., service providers) who have a genuine need to access it ("need-to-know" principle).
Data Storage
Data Storage
Mapresto stores your data for the period necessary to fulfill the purposes set out in this policy, unless longer storage is required or permitted by applicable law or necessary by regulatory requirements.
Transmission of data over an open network
Transmission of data over an open network
If you use our Electronic Services via an open network, Mapresto would like to inform you that third parties (for example, app stores, network providers, or your device manufacturer) can access and process your data regardless of their location. Open networks are not under Mapresto's control and therefore cannot be considered a secure environment. There is no guarantee that data transmitted over such an open network is secure or error-free, as it may be intercepted, altered, damaged, destroyed, lost, delayed, incomplete, contain viruses, or be monitored. In particular, data transmitted over an open network—even if the sender and recipient are located in the same country—may leave that country and be transferred to and processed in a third country with less stringent data protection regulations than the country where you are currently located. We cannot be held liable for the protection of data transmitted over an open network. Accordingly, we assume no responsibility or liability for the security of your data during such transmission. We therefore recommend that you do not transmit highly confidential information over open networks. Where you deem it appropriate, you may communicate with Mapresto via other means.
Cookies and Services
Cookies and Services
Mapresto uses technically necessary cookies and local browser storage for sessions and cookie selection. The following overview shows which services are activated. Optional statistics services are only loaded after consent. Declining optional services does not prevent registration and booking.
You can change your selection in the cookie settings and delete saved entries via your browser. Deleting necessary session cookies may require you to log in again. External functions may establish connections to their respective providers; the cookie selection does not block all external connections.
Left
Left
The electronic services of Mapresto may contain links to third-party electronic services that are neither operated nor monitored by us. Please note that such third-party electronic services are not subject to this privacy policy, and we are neither responsible for their content nor for these providers' data handling policies. Therefore, we recommend that you read and review the privacy policies or terms of use for the relevant third-party electronic services.
Rights of Affected Parties
Rights of Affected Parties
According to applicable data protection laws and regulations, you may have the following rights:
- You can request information about the personal data we hold about you.
- You can request that the data be provided in a generally usable, machine-readable, and standardized format (data portability).
- You can request that inaccurate personal data be corrected.
- You can request that your data be deleted if the bank is not entitled or legally obliged to retain it.
- You can request that the processing of your data be restricted.
- You can object to the processing of your personal data.
Furthermore, you may have the right to lodge a complaint with a competent data protection authority.
Cookies and Local Storage Technologies
Cookies and Local Storage Technologies
This overview is generated from the central configuration of the enabled services. It is not an automatic browser scan. Different entries are used depending on the function visited.
| Service | Cookie / local storage | Purpose | Storage duration |
|---|---|---|---|
| Mapresto – Registration | CFID, CFTOKEN / JSESSIONID | Technically necessary session management. The cookie names used depend on the server configuration. | According to the active session configuration; a login may expire beforehand. |
| Mapresto – Cookie Selection | mapresto_cookie_consent_v2 (Local Storage), cc_cookie_tlc | Saves your decision. The public website uses Local Storage, older views use cc_cookie_tlc. | Local Storage until modified or deleted; cc_cookie_tlc for up to 182 days. |
| Google Analytics 4 - Google | _ga, _ga_* | Optional usage statistics after consent; connection to Google servers. | According to Google Analytics configuration; may be deleted earlier by the browser. |
Optional statistics services are only loaded with your consent. You can change your selection via the cookie settings. Your consent will be saved for this browser.
How the concierge handles your requests
To enable the concierge to answer your questions and support you with tasks, Mapresto uses the OpenAI API. Your request, as well as any previous messages and task-related data, are transmitted. Depending on the task, this may also include customer and treatment information. Mapresto uses the transmitted customer and treatment data exclusively to process the respective request or task for your studio. If you use external speech recognition, your dictation will be processed by the respective provider.
Mapresto is committed to adhering to this purpose limitation and complying with the data protection and terms of use agreed upon with OpenAI. Data is transmitted to OpenAI via encrypted HTTPS. OpenAI does not use API data to train its models by default. For security purposes, logs may be stored for up to 30 days. Depending on the service and settings, exceptions or additional retention periods are possible. Processing may also take place outside of Switzerland.
Your studio is responsible for determining which customer and treatment data may be used for AI tasks. With regard to health-related data, it is particularly important to carefully check whether processing is permissible and what consent is required; consent to the customer database does not automatically cover all AI uses. If you have any questions about data processing or your data protection rights, your studio and Mapresto will be happy to assist you.
Questions about data processing? Write to us at support@mapresto.ch.