Privacy Policy
Version 2 · 09.08.2026
Privacy Policy — Hango Pro
1. Controller
SwissNights Sàrl, Chemin de Bellevue 5, c/o Gustave Henzi, 1052 Le Mont-sur-Lausanne, Switzerland (UID CHE-233.559.692) is the controller for the processing described below. Contact for any data protection matter: hello@hango.pro.
2. Scope
This policy applies to the public website and the Hango Pro portal (including the PWA), the associated communications (transactional emails) and the processing carried out in connection with the Hango Pro services. It is drawn up in accordance with the Swiss Federal Act on Data Protection (FADP) and, where the GDPR applies, with the GDPR.
3. Categories of data
- Account data: name, email address, phone, role, language, password (stored exclusively in hashed form).
- Organization and profile data: legal name, addresses, billing contacts, venue information (categories, hours, description, social handles), uploaded media (logos, photos).
- Contract data: contracts, accepted terms versions, electronic signature data (signer identity, signature trace, timestamp, IP address, browser, cryptographic document hash).
- Billing data: invoices, payment references, incoming payments, credits, collection correspondence.
- Usage and technical data: login and audit logs, IP addresses, preferences (language, cookie consent), notifications.
- Lead data: information submitted through the contact and partnership forms.
- Under Hango Social: content, statistics and access to the customer's social accounts via Meta/Google tools (never passwords).
4. Purposes and legal bases
- Contract performance: provision of the portal, profile and subscription management, invoicing, electronic signature, distribution to channels and partners, support.
- Legal obligations: retention of accounting records (art. 958f CO), VAT, debt-collection requirements.
- Legitimate interests: portal security (logs, rate limiting), abuse and fraud prevention, service improvement, professional communication with customers.
- Consent: marketing cookies and the Meta Pixel (art. 6); consent may be withdrawn at any time with effect for the future.
5. Cookies
The site uses necessary cookies (session, CSRF security, language, storage of the consent choice) and, only with consent, marketing trackers. Details are set out in the Cookie Policy, which forms an integral part of this policy.
6. Meta Pixel
Only with your consent do we use the Meta Pixel (Meta Platforms Ireland Ltd, Dublin, Ireland) to measure the effectiveness of our campaigns (pages viewed and conversion events such as pricing views, registration started, application submitted, contact). Meta may process such data outside Switzerland/the EU, notably in the United States; such transfers rely on recognized mechanisms (Swiss-U.S./EU-U.S. Data Privacy Framework adequacy or standard contractual clauses). No billing data is transmitted to Meta. Without consent, the Pixel is not loaded.
7. Recipients and processors
We do not sell personal data. Data is disclosed only:
- to our technical processors: hosting and email in Switzerland (Infomaniak Network SA, Geneva);
- to distribution partners, limited to the profile and event data required for the agreed distribution (e.g. Lausanne Tourisme);
- to banking providers in the context of payment reconciliation;
- to authorities where required by law.
Our processors are bound by contractual confidentiality and security obligations consistent with art. 9 FADP.
8. Cross-border disclosure
Data is hosted in Switzerland. Transfers abroad may occur for the Meta Pixel (art. 6) and, where enabled, for the AI assistant (question processing by an API provider; no data is used for training without agreement). Such transfers rely on an adequacy decision or appropriate safeguards (standard contractual clauses).
9. Retention
- Contractual and accounting records (signed contracts, invoices, credit notes): 10 years (art. 958f CO).
- Account and profile data: duration of the contractual relationship, then deletion or anonymization within a reasonable period, subject to statutory obligations.
- Technical and audit logs: 12–24 months depending on their nature, absent a security incident.
- Dormant leads: no longer than 24 months after the last contact.
10. Security
TLS encryption in transit, robust password hashing (Argon2id), role-based access control, per-customer data isolation, audit logging, rate limiting, upload validation, backups. Document access is subject to authorization; no predictable public URLs are used.
11. Your rights
In accordance with art. 25 et seq. FADP (and, where applicable, art. 15 et seq. GDPR), you have the rights of access, rectification, erasure, restriction, objection and data portability/delivery. You may additionally request the deletion of your account directly from the portal (Settings → Request account deletion); records subject to statutory retention are kept, other data is deleted or anonymized. To exercise your rights: hello@hango.pro. You may contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where the GDPR applies, the competent supervisory authority.
12. Whether provision is required
Account, organization and billing data are necessary for the conclusion and performance of the contract; without them the services cannot be provided. Optional data is marked as such.
13. Changes
The version published on the site prevails. Substantial changes are communicated appropriately. Each version is archived and dated.