Privacy policy.
This page describes what personal data The People Attraction Theory collects through peopleattractiontheory.com, for what purpose, where it is stored, for how long, and what your rights are. Written for transparency and readability, not legal dilution.
01 · Preamble
Preamble
This policy applies to the processing of personal data carried out by Gates Solutions Sàrl in connection with the operation of the site peopleattractiontheory.com and the interactions arising from it (contact form, CV submission, VOD purchase, email exchanges, appointment bookings).
It is drafted to comply with both the revised Swiss Federal Act on Data Protection (nLPD, in force since September 1, 2023) and the European General Data Protection Regulation (GDPR, EU Regulation 2016/679), which applies to visitors residing in the European Union.
In case of divergent interpretation between the two frameworks, the provision most protective of the data subject applies.
02 · Controller
Who collects your data
The data controller is:
Data controller
Gates Solutions Sàrl
Route du Risoud 9, 1348 Le Brassus
Vaud, Switzerland
IDE CHE-210.509.281
Represented by Guillaume Alexandre, managing director.
Email for any personal data question:
[email protected]
Gates Solutions Sàrl does not appoint a data protection officer (DPO), as its size and the nature of its processing do not make it mandatory under art. 37 GDPR or the nLPD.
03 · Data
What data and in which cases
Five distinct situations give rise to data collection:
a) Contact form
When you fill out the contact form, the following data is transmitted:
- Full name
- Professional email address
- Company name
- Phone number (optional field)
- Subject of the request
- Free text content of the message
This data transits through a Cloudflare Worker that performs invisible validation and anti-spam protection, then is stored in the Odoo CRM operated by Gates Solutions Sàrl.
b) CV submission via Jarvi
If you choose to submit a CV via the "Submit my CV" link, you are redirected to a Jarvi page specific to PAT, where you provide:
- Your CV in the format of your choice
- The details you enter (name, email, phone and, where applicable, additional professional information)
The submission takes place directly on the Jarvi infrastructure, operated by Jarvi Tech SAS (10 rue du Réage, 35510 Cesson-Sévigné, France). The data is processed by this subprocessor according to its own privacy policy, accessible from the submission page.
c) Appointment booking via Google Calendar
If you book a slot via a calendar link, you are redirected to Google Calendar Appointment Schedules. The data collected at this stage (name, email, booked slot) is processed by Google Ireland Ltd according to Google's privacy policy. No Google cookie is set on peopleattractiontheory.com, as the service is consulted exclusively via external redirect.
d) VOD purchase (Module 1 standalone)
When you click "Buy M1", you are redirected to a Stripe Payment Link. The data collected is:
- Name and email address (entered directly with Stripe)
- Payment data (card number, expiration date, CVC) — never transmitted to the PAT server, entered directly into the Stripe form
- Billing address (entered with Stripe)
After a valid payment, Stripe generates an invoice and a confirmation email. This email contains a unique access link to your VOD content hosted by Teachable.
e) Technical site connection
On each visit, your browser automatically transmits technical information (IP address, browser type, referring page, etc.) to the Cloudflare hosting infrastructure. These server logs are managed by Cloudflare according to its own retention and security policy. Gates Solutions Sàrl has no direct access to this raw data outside of a security incident investigation.
Important note
This site does not collect banking information (beyond what is strictly necessary via Stripe for the VOD purchase), ID document numbers, or special categories of data (ethnic origin, religious or political opinions, health, sexual orientation, etc.). If a free-text message you send incidentally contains such information, it will be processed with the same confidentiality as the rest, but we recommend avoiding sending it through this channel.
04 · Purposes
Why (purposes and legal bases)
Each processing rests on an explicit purpose and an identified legal basis, in accordance with art. 6 GDPR and art. 31 nLPD.
| Data | Purpose | Legal basis |
|---|---|---|
| Contact form | Handle your commercial or informational request | Performance of pre-contractual measures (art. 6.1.b GDPR) / Overriding interest (art. 31 para. 2 nLPD) |
| CV submission (Jarvi) | Assess the relevance of a mission or networking opportunity | Legitimate interest of Gates Solutions Sàrl in building a talent pool (art. 6.1.f GDPR) / Overriding interest (art. 31 para. 2 nLPD) |
| Server logs (Cloudflare) | Site security, attack and fraud prevention | Legitimate interest in system security (art. 6.1.f GDPR) / Overriding interest (art. 31 para. 2 nLPD) |
| Cloudflare Web Analytics statistics | Understand aggregate site usage to improve editorial quality | Legitimate interest, without cookies or persistent identifiers (art. 6.1.f GDPR) / Overriding interest (art. 31 para. 2 nLPD) |
| VOD purchase (Stripe + Teachable) | Process payment, issue invoice, provide access to VOD content | Performance of the sales contract (art. 6.1.b GDPR) / Overriding interest (art. 31 para. 2 nLPD) |
| Accounting data linked to invoices | Issue, keep and declare invoices | Legal obligation (art. 6.1.c GDPR) / Swiss legal obligation (art. 958f CO) |
05 · Retention
How long
Each data category has its own retention period, aligned with its purpose:
- Contact form data (Odoo CRM): kept for 3 years from the last active contact. Beyond that, it is archived or deleted depending on the situation.
- Details and CVs submitted via Jarvi: kept for 2 years from submission, with deletion possible at any time on request to [email protected].
- VOD data (Stripe purchase + Teachable access): the purchase email and invoice are kept for 10 years for accounting purposes (art. 958f Swiss CO). Your Teachable account stays active for the subscribed access period (currently 1 year post-purchase), then can be deleted on request to Teachable directly or via [email protected].
- Post-contact email exchanges: kept in the professional inbox according to the legal durations applicable to commercial exchanges (typically up to 10 years for items linked to invoicing).
- Server logs: managed by Cloudflare according to its own retention policy.
- Accounting data (invoices, supporting documents): 10 years, in accordance with Swiss legal obligation (art. 958f of the Code of Obligations).
- Cloudflare Web Analytics data: aggregated at site level, kept for 6 months on the free plan, without cookies or persistent identifiers and without any possible link to an identifiable person.
06 · Subprocessors
With whom this data is shared
Your data is never sold, rented or transferred to third parties for commercial purposes. It is shared only with a limited number of technical subprocessors necessary for the operation of the site and the business, governed by a data processing agreement compliant with art. 28 GDPR and art. 9 nLPD.
| Subprocessor | Role | Location | Policy |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, DNS, invisible anti-spam validation (Turnstile) | United States, EU data residency options | Read ↗ |
| Odoo SA | CRM, contact and lead management (shared with Gates Solutions) | Belgium, EU infrastructure | Read ↗ |
| Sendinblue SAS (Brevo) | Transactional email notifications (contact form replies, automated confirmations). Replaces Resend since May 29, 2026. | France (headquarters), EU infrastructure | Read ↗ |
| Telegram FZ-LLC | Private real-time notifications sent to Guillaume Alexandre when a lead is submitted (restricted private channel). Contains the visitor's name, email and a message excerpt. You can request that your data not be relayed via Telegram by stating so in your message. | United Arab Emirates (jurisdiction without an EU adequacy decision) — transfer covered by Standard Contractual Clauses (SCC) and Transfer Impact Assessment (Schrems II / GDPR Chapter V). | Read ↗ |
| Cloudflare Web Analytics | Cookieless audience analytics (already covered by Cloudflare, Inc. above as host — listed separately here for transparency on the analytics purpose) | Cloudflare global edge network | Read ↗ |
| Infomaniak Network SA | Email transit (MX mail server) | Switzerland | Read ↗ |
| Google Ireland Ltd | Workspace email and Google Calendar Appointment Schedules | Ireland and United States | Read ↗ |
| Jarvi Tech SAS | ATS for CV submission (only if you use it) | France (Cesson-Sévigné) | Read ↗ |
| Stripe Payments Europe Ltd. | VOD payment processing (Module 1 standalone T4) via Stripe Payment Link. Card data never transits through the PAT server — it is entered directly with Stripe. | Ireland (contracting entity) + United States (processing infrastructure) | Read ↗ |
| Teachable Inc. | Hosting of Module 1 VOD videos post-purchase. After Stripe payment, a confirmation email contains a Teachable access link. Teachable enrollment uses the visitor's email. | United States | Read ↗ |
This list is kept up to date. Any substantial addition of a new subprocessor will be flagged on this page, and the "Last modified" date at the top will be revised accordingly.
07 · Transfers
Transfers outside the EU and Switzerland
Several subprocessors above involve transfers or storage outside the EU and Switzerland: Cloudflare (United States), Google (United States, via an Irish contracting entity for Workspace), Stripe (Ireland + United States), and Teachable (United States).
The legal safeguards associated with these transfers are:
- Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework, which constitutes a transfer framework recognized by the European Commission (adequacy decision of July 10, 2023) and by the Swiss Federal Data Protection Commissioner.
- Google Ireland Ltd is the European contracting entity for Google Workspace. Further transfers to US servers are carried out under Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by the equivalent protection commitments required by the Schrems II decision.
- Stripe Payments Europe Ltd. is the European contracting entity for VOD payments. Further transfers to US infrastructure are carried out under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs).
- Teachable Inc. (United States) handles access to VOD content post-purchase. The transfer of your email to Teachable is carried out under the EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs) according to Teachable's current certification.
If you reside in the European Union or Switzerland, you may ask us at any time for a copy of the safeguards applicable to a specific transfer by writing to [email protected].
08 · Your rights
Your rights
In accordance with the nLPD and the GDPR, you have the following rights at any time:
- Right to access: obtain confirmation of the processing and a copy of your data.
- Right to rectify: have inaccurate or incomplete data corrected.
- Right to delete: request the deletion of your data, subject to legal retention obligations (notably accounting).
- Right to port: receive your data in a structured and usable format.
- Right to object to processing based on legitimate interest.
- Right to withdraw consent, at any time, where processing relies on this ground.
- Right to define the fate of your data after death (only for visitors residing in France, in accordance with the Loi Informatique et Libertés).
To exercise these rights, send an email to [email protected] specifying the right invoked and, if necessary, the data concerned.
The response will reach you within a maximum of 30 days. No proof of identity is required by default. In case of serious doubt about the identity of the requester (request from an email address different from the one originally used, for example), additional verification may be requested.
09 · Security
Security
The following technical and organizational measures are in place:
- All site traffic is encrypted in HTTPS, via TLS certificates automatically renewed by Cloudflare.
- Forms are protected by invisible anti-spam protection, without persistent cookies.
- Contact form data is server-side validated before transmission to the Odoo CRM.
- Stripe payments are processed directly with Stripe, never stored on the PAT server side (tokenization).
- Access to internal tools (Odoo CRM, professional inbox, Cloudflare infrastructure) is restricted to Guillaume Alexandre, protected by a strong password and two-factor authentication.
- No backup of your data is performed on unencrypted media.
No system being infallible, in case of a personal data breach likely to create a risk for your rights and freedoms, you will be informed within the deadlines provided by the GDPR (notification to the competent authority within 72 hours, communication to affected individuals without undue delay) and by the nLPD.
10 · Minors
Minors
The site peopleattractiontheory.com is aimed at an adult professional audience (recruitment teams, executives, conference organizers, trainers). The services offered are not intended for persons under 16.
No targeted collection of data concerning minors is carried out. If you believe that a minor under 16 has submitted their data through this site, immediately contact [email protected] for deletion.
11 · Complaint
Complaint to authorities
If you believe your rights are not respected, and after seeking an amicable solution by email with Gates Solutions Sàrl, you may file a complaint with the competent authority:
Swiss authority
Federal Data Protection and Information Commissioner (FDPIC / PFPDT)
Feldeggweg 1, 3003 Bern, Switzerland
www.edoeb.admin.ch
European authority (based on your residence)
You may contact the supervisory authority of the Member State of your habitual residence or place of work.
For example, in France: Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, 75007 Paris, www.cnil.fr.
12 · Modifications
Modifications to this policy
This policy may be modified to reflect technical, legal or organizational changes. The "Last modified" date at the top of the page is the authoritative reference.
In case of substantial modification (addition of a major new subprocessor, change of purpose, extension of a retention period), a visible notification will be displayed on the site for at least 30 days.
13 · Contact
Contact to exercise your rights
For any request relating to your personal data or the exercise of your rights:
Primary channel
Email: [email protected]
Phone: +41 79 962 41 92
Mail: Gates Solutions Sàrl, Route du Risoud 9, 1348 Le Brassus, Vaud, Switzerland