Legal

Privacy Policy

Effective date: April 13, 2026

This policy explains how Heidifi collects, uses, shares, and protects personal data in connection with our platform and website. We comply with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP / DSG 2023).

1. Overview & Controller

Heidifi ("we", "us", "our") operates the guest Wi-Fi marketing platform available at heidifi.ai and portal.heidifi.ai (together, the "Platform").

Heidifi is the data controller for personal data related to operator accounts, website visitors, and our own business operations. Heidifi acts as a data processor for personal data collected by operators through their captive portals (guest data).

Controller contact: hello@heidifi.ai

2. Data We Collect

2.1 Account & operator data

  • Name, email address, and password when you register an account
  • Company name, venue name(s), and billing address
  • Payment information processed by our payment provider (we do not store card details)
  • Communication preferences and support correspondence

2.2 Platform usage data

  • Log data: IP address, browser type, pages visited, timestamps
  • Feature usage and interaction data within the dashboard
  • Error reports and performance data

2.3 Guest data (processed on behalf of operators)

When guests connect to Wi-Fi through a Heidifi-powered portal, operators may collect: name, email address, phone number, authentication method, consent records, visit timestamps, and session metadata. Heidifi processes this data as a data processor under instruction from the operator (see Section 3).

2.4 Data you provide voluntarily

  • Contact form submissions and email correspondence
  • Feedback, survey responses, and beta program participation

3. Operator vs. Guest Data

Operators are businesses (e.g., Airbnb hosts, hotels, restaurants) that subscribe to Heidifi to deploy captive portals at their venues. For operator account data, Heidifi is the data controller.

Guests are end-users who connect to Wi-Fi at an operator's venue and interact with a Heidifi-powered portal. For guest data, the operator is the data controller and Heidifi acts as a data processor under a Data Processing Agreement (DPA) incorporated into our Terms of Service.

If you are a guest seeking to exercise data rights (access, deletion, etc.), please contact the operator whose venue you visited. Operators may forward data subject requests to hello@heidifi.ai.

Processing ActivityLegal Basis (GDPR)nFADP Basis
Operator account creation & managementArt. 6(1)(b) — Contract performanceOverriding interest / contract
Billing & invoicingArt. 6(1)(b) / (c) — Contract & legal obligationLegal obligation
Platform analytics & improvementArt. 6(1)(f) — Legitimate interestOverriding interest
Marketing emails to operatorsArt. 6(1)(f) — Legitimate interest (existing customers) / ConsentConsent / overriding interest
Processing guest data for operatorsArt. 6(1)(b) — DPA / contractContract (DPA)
Security & fraud preventionArt. 6(1)(f) — Legitimate interestOverriding interest

5. How We Use Data

  • Provide, operate, and improve the Heidifi platform and services
  • Manage operator accounts, billing, and support
  • Process guest data on behalf of operators (captive portal sessions, CRM, campaigns)
  • Send transactional emails (receipts, account alerts, feature updates)
  • Send marketing communications to operators (opt-out available at any time)
  • Comply with legal and regulatory obligations
  • Investigate fraud, security incidents, and abuse
  • Enforce our Terms of Service

We do not sell personal data to third parties, and we do not use guest data collected on behalf of operators for our own marketing purposes.

6. Sharing & Sub-processors

We share personal data only as necessary with the following categories of recipients:

6.1 Infrastructure & hosting

Cloud infrastructure providers that host the Heidifi platform and its databases. These are bound by data processing agreements and operate under GDPR-equivalent safeguards.

6.2 Payment processing

We use a third-party payment processor to handle billing. We do not store payment card data. The processor acts as an independent controller for payment data.

6.3 Communications providers

Email and SMS delivery providers used to send campaigns and transactional notifications on behalf of operators. These act as sub-processors under our DPA.

6.4 Analytics

Platform analytics tools to understand feature usage and improve the product. These process data in aggregated or pseudonymous form where possible.

6.5 Legal & regulatory disclosure

We may disclose personal data if required by applicable law, court order, or regulatory authority — or to protect the rights, property, or safety of Heidifi, our operators, or guests.

7. Retention

Data TypeRetention Period
Operator account data7 years after account closure (legal/tax requirements)
Billing & payment records10 years (Swiss OR/VAT obligations)
Guest portal dataAs configured by operator (default: 24 months); deleted on operator request or account closure
Platform usage logs90 days rolling
Support correspondence3 years after resolution
Consent records (guest)As long as the underlying data is retained, plus 1 year

Operators can configure custom retention periods for guest data within the Heidifi dashboard. Heidifi applies hard-delete (not soft-delete) on expiry.

8. International Transfers

Heidifi is headquartered in Switzerland. Personal data may be processed by sub-processors in the EU/EEA, Switzerland, or other jurisdictions.

For transfers from the EU/EEA outside the EEA, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission or an adequacy decision. Switzerland has been recognized as adequate by the EU for data protection purposes.

For transfers under Swiss nFADP, we ensure equivalent safeguards are in place in the destination country, or use standard data protection clauses approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC).

9. Your Rights

Under GDPR (Art. 15–22) and nFADP (Art. 25–27), you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate or incomplete data
  • Erasure — request deletion of your data (subject to legal retention obligations)
  • Restriction — ask us to pause processing while a dispute is resolved
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interest or for direct marketing
  • Withdraw consent — where processing is consent-based, withdraw at any time without affecting prior processing
  • Lodge a complaint — with your national supervisory authority (Switzerland: FDPIC; EU: your local DPA)

To exercise any right, email hello@heidifi.ai. We will respond within 30 days (extendable by 60 days for complex requests with notice). We may ask you to verify your identity before processing the request.

Note for guests: If you are a guest who connected at an operator's venue, your data is controlled by that operator. Direct your request to them, or email us and we will forward it appropriately.

10. Cookies

Heidifi uses the following categories of cookies on our website and dashboard:

  • Strictly necessary — session authentication, CSRF protection. Cannot be disabled.
  • Functional — remember your language and display preferences.
  • Analytics — measure how the platform is used. Data is pseudonymous and aggregated. Requires consent.

We do not use third-party advertising cookies. You can manage cookie preferences through your browser settings. Note that disabling strictly necessary cookies will prevent you from using the platform.

11. Children

The Heidifi platform is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact hello@heidifi.ai and we will delete it promptly.

Operators deploying captive portals where minors may be present are responsible for configuring appropriate age verification flows.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify active operators by email at least 14 days before the change takes effect. The "Effective date" at the top of this page will always reflect the current version.

Continued use of the platform after the effective date constitutes acceptance of the updated policy.

13. Contact & DPO

For all privacy-related enquiries, data subject requests, or DPA questions:

Heidifi — Privacy Team

Email: hello@heidifi.ai

Switzerland

You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch, or with your local EU supervisory authority if you are in the EU/EEA.