1. Overview & Controller
Heidifi ("we", "us", "our") operates the guest Wi-Fi marketing platform available at heidifi.ai and portal.heidifi.ai (together, the "Platform").
Heidifi is the data controller for personal data related to operator accounts, website visitors, and our own business operations. Heidifi acts as a data processor for personal data collected by operators through their captive portals (guest data).
Controller contact: hello@heidifi.ai
2. Data We Collect
2.1 Account & operator data
- Name, email address, and password when you register an account
- Company name, venue name(s), and billing address
- Payment information processed by our payment provider (we do not store card details)
- Communication preferences and support correspondence
2.2 Platform usage data
- Log data: IP address, browser type, pages visited, timestamps
- Feature usage and interaction data within the dashboard
- Error reports and performance data
2.3 Guest data (processed on behalf of operators)
When guests connect to Wi-Fi through a Heidifi-powered portal, operators may collect: name, email address, phone number, authentication method, consent records, visit timestamps, and session metadata. Heidifi processes this data as a data processor under instruction from the operator (see Section 3).
2.4 Data you provide voluntarily
- Contact form submissions and email correspondence
- Feedback, survey responses, and beta program participation
3. Operator vs. Guest Data
Operators are businesses (e.g., Airbnb hosts, hotels, restaurants) that subscribe to Heidifi to deploy captive portals at their venues. For operator account data, Heidifi is the data controller.
Guests are end-users who connect to Wi-Fi at an operator's venue and interact with a Heidifi-powered portal. For guest data, the operator is the data controller and Heidifi acts as a data processor under a Data Processing Agreement (DPA) incorporated into our Terms of Service.
If you are a guest seeking to exercise data rights (access, deletion, etc.), please contact the operator whose venue you visited. Operators may forward data subject requests to hello@heidifi.ai.
4. Legal Basis for Processing
| Processing Activity | Legal Basis (GDPR) | nFADP Basis |
|---|---|---|
| Operator account creation & management | Art. 6(1)(b) — Contract performance | Overriding interest / contract |
| Billing & invoicing | Art. 6(1)(b) / (c) — Contract & legal obligation | Legal obligation |
| Platform analytics & improvement | Art. 6(1)(f) — Legitimate interest | Overriding interest |
| Marketing emails to operators | Art. 6(1)(f) — Legitimate interest (existing customers) / Consent | Consent / overriding interest |
| Processing guest data for operators | Art. 6(1)(b) — DPA / contract | Contract (DPA) |
| Security & fraud prevention | Art. 6(1)(f) — Legitimate interest | Overriding interest |
5. How We Use Data
- Provide, operate, and improve the Heidifi platform and services
- Manage operator accounts, billing, and support
- Process guest data on behalf of operators (captive portal sessions, CRM, campaigns)
- Send transactional emails (receipts, account alerts, feature updates)
- Send marketing communications to operators (opt-out available at any time)
- Comply with legal and regulatory obligations
- Investigate fraud, security incidents, and abuse
- Enforce our Terms of Service
We do not sell personal data to third parties, and we do not use guest data collected on behalf of operators for our own marketing purposes.
6. Sharing & Sub-processors
We share personal data only as necessary with the following categories of recipients:
6.1 Infrastructure & hosting
Cloud infrastructure providers that host the Heidifi platform and its databases. These are bound by data processing agreements and operate under GDPR-equivalent safeguards.
6.2 Payment processing
We use a third-party payment processor to handle billing. We do not store payment card data. The processor acts as an independent controller for payment data.
6.3 Communications providers
Email and SMS delivery providers used to send campaigns and transactional notifications on behalf of operators. These act as sub-processors under our DPA.
6.4 Analytics
Platform analytics tools to understand feature usage and improve the product. These process data in aggregated or pseudonymous form where possible.
6.5 Legal & regulatory disclosure
We may disclose personal data if required by applicable law, court order, or regulatory authority — or to protect the rights, property, or safety of Heidifi, our operators, or guests.
7. Retention
| Data Type | Retention Period |
|---|---|
| Operator account data | 7 years after account closure (legal/tax requirements) |
| Billing & payment records | 10 years (Swiss OR/VAT obligations) |
| Guest portal data | As configured by operator (default: 24 months); deleted on operator request or account closure |
| Platform usage logs | 90 days rolling |
| Support correspondence | 3 years after resolution |
| Consent records (guest) | As long as the underlying data is retained, plus 1 year |
Operators can configure custom retention periods for guest data within the Heidifi dashboard. Heidifi applies hard-delete (not soft-delete) on expiry.
8. International Transfers
Heidifi is headquartered in Switzerland. Personal data may be processed by sub-processors in the EU/EEA, Switzerland, or other jurisdictions.
For transfers from the EU/EEA outside the EEA, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission or an adequacy decision. Switzerland has been recognized as adequate by the EU for data protection purposes.
For transfers under Swiss nFADP, we ensure equivalent safeguards are in place in the destination country, or use standard data protection clauses approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC).
9. Your Rights
Under GDPR (Art. 15–22) and nFADP (Art. 25–27), you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data (subject to legal retention obligations)
- Restriction — ask us to pause processing while a dispute is resolved
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest or for direct marketing
- Withdraw consent — where processing is consent-based, withdraw at any time without affecting prior processing
- Lodge a complaint — with your national supervisory authority (Switzerland: FDPIC; EU: your local DPA)
To exercise any right, email hello@heidifi.ai. We will respond within 30 days (extendable by 60 days for complex requests with notice). We may ask you to verify your identity before processing the request.
Note for guests: If you are a guest who connected at an operator's venue, your data is controlled by that operator. Direct your request to them, or email us and we will forward it appropriately.
10. Cookies
Heidifi uses the following categories of cookies on our website and dashboard:
- Strictly necessary — session authentication, CSRF protection. Cannot be disabled.
- Functional — remember your language and display preferences.
- Analytics — measure how the platform is used. Data is pseudonymous and aggregated. Requires consent.
We do not use third-party advertising cookies. You can manage cookie preferences through your browser settings. Note that disabling strictly necessary cookies will prevent you from using the platform.
11. Children
The Heidifi platform is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact hello@heidifi.ai and we will delete it promptly.
Operators deploying captive portals where minors may be present are responsible for configuring appropriate age verification flows.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify active operators by email at least 14 days before the change takes effect. The "Effective date" at the top of this page will always reflect the current version.
Continued use of the platform after the effective date constitutes acceptance of the updated policy.
13. Contact & DPO
For all privacy-related enquiries, data subject requests, or DPA questions:
You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch, or with your local EU supervisory authority if you are in the EU/EEA.