Privacy Policy
Last updated: 29.07.2026
Compliant with the Swiss Federal Act on Data Protection (nFADP) and the EU/EEA General Data Protection Regulation (GDPR).
1. Purpose
This Privacy Policy describes how IntimX collects, processes, stores and protects your personal data when you use the Service accessible at intimx.ch. It applies to all users (members, providers, establishments), whether or not they hold an account. Terms defined in the Terms of Use apply by reference.
2. Data Controller
The data controller within the meaning of Art. 5(j) nFADP and Art. 4(7) GDPR is: N.JULIEN Sion (VS), Switzerland Trade name: Artenic Data protection contact: privacy@intimx.ch The Publisher has not appointed a Data Protection Officer (DPO) within the meaning of Art. 10 nFADP, as this appointment is not mandatory. For any questions relating to your data, contact privacy@intimx.ch directly.
3. Legal Bases for Processing
Data processing by IntimX is based on the following legal grounds: — Performance of a contract (Art. 6(1)(b) GDPR / Art. 31(1) nFADP): registration, account management, messaging, subscriptions, billing. — Legitimate interests (Art. 6(1)(f) GDPR / Art. 31(1) nFADP): Service security, fraud prevention, aggregate statistics, Service improvement. — Legal obligation (Art. 6(1)(c) GDPR / Art. 31(1) nFADP): retention of transaction data (CO Art. 958f), cooperation with authorities. — Consent (Art. 6(1)(a) GDPR / Art. 31(1) nFADP): analytics cookies, push notifications, marketing communications.
4. Data Collected
Registration data: — All roles: email address, password (Argon2id hashed, never stored in plain text), display name, preferred language, timestamps for Terms and Privacy acceptance. — Member and Provider: date of birth (18+ verification). — Provider: category, service type, biography, physical attributes, rates, opening hours, public contact details. — Establishment: category, business metadata, public contact details, social links. Usage data: — Access logs: IP address, user agent, geolocation (city, country) — retained for 90 days. — Sessions: refresh token fingerprint (SHA-256), IP and user agent hash (SHA-256), geographic context, device information (browser, OS). — Trusted devices: device fingerprint (SHA-256), device info (browser, OS, mobile). — Messaging: message content (5,000 characters max), timestamps, conversation identifiers. — Gallery: images (JPEG, PNG, WebP, HEIC, max 8 MB), file metadata. — Profile statistics: aggregate counters (views, clicks) per day — no individual visitor data. — Presence: last active timestamp (updated via WebSocket). — Audience measurement: pages viewed, together with five non-identifying properties (language, account type, page type, service category, canton) and about ten usage events (registration steps, start and completion of an identity verification, profile view, contact click, conversation started). Processed by a Plausible Analytics instance self-hosted by the Publisher in Switzerland, without cookies, without any persistent identifier, and without the ability to track a visitor from one session to the next. — Push notifications (opt-in): browser-provided endpoint URL (Firebase, Mozilla Push, Apple Push), a public key (p256dh) and an authentication secret (auth) provided by your browser, used to encrypt notifications, subscription timestamp. Unsubscription is possible at any time from browser or account settings. Sensitive data (encrypted vault): — Identity verification (KYC): first name, last name, date of birth, phone number, address — encrypted with AES-256-GCM. Voluntary for members and establishments; required for providers wishing to publish their profile in the directory. — KYC documents: encrypted files stored separately.
5. Cookies and Similar Technologies
IntimX uses the following cookies: Essential cookies (no consent required, Art. 45c(2) TCA): — ix_access: access token JWT. Duration: 1 hour. HttpOnly, Secure, SameSite=Strict. — ix_refresh: refresh token JWT. Duration: 7 days (30 days with "Remember me"). HttpOnly, Secure, SameSite=Lax. — ix_age: age verification (Art. 197 Swiss Criminal Code). Duration: 365 days. Value: majority confirmation. — intimx_fp: technical device fingerprint (SHA-256 computed over seven browser characteristics: user agent, platform, primary language, list of accepted languages, time zone, screen resolution and colour depth, number of processor cores). Duration: 365 days. Used solely to recognise an already-approved device and to trigger one-time-code verification on an unknown device. No invasive fingerprinting technique (canvas, audio) is used. Analytics cookies: none. The audience measurement described in article 4 is handled by a Plausible Analytics instance self-hosted by the Publisher in Switzerland; it works without cookies and without any persistent identifier. If an analytics service requiring a cookie or an identifier were integrated in the future, your explicit consent would be requested beforehand. You may configure your browser to refuse cookies. Refusing essential cookies makes use of the Service impossible (authentication required).
6. Purposes of Processing
Your data is processed for the following purposes: — Service provision: account creation and management, profile display, messaging between users, booking management. — Security: age verification, email verification, suspicious login detection, account lockout, trusted device management. — Moderation: report processing, combating unlawful content, cooperation with authorities. — Communication: transactional emails (verification, password, subscription, booking), in-app notifications. — Statistics: aggregate profile viewing counters (views, clicks). No individual profiling. — Legal compliance: transaction data retention, audit logs, proof of consent.
7. Recipients and Processors
Your data may be disclosed to the following recipients: — Mapbox Inc. (United States): map display and address search. As soon as a map is displayed, your browser loads the map tiles directly from Mapbox's servers, which receive your IP address and the coordinates of the area being viewed. When you type an address into a location form or during establishment registration, that address is sent to them as you type in order to produce suggestions. The mapping library additionally sends usage data to their telemetry servers. This is not optional: it is triggered as soon as a map is displayed (see art. 8). — Infomaniak Network SA (Geneva, Switzerland): hosting of the main infrastructure — application servers, PostgreSQL databases, S3 object storage and transactional email service. — Plausible Analytics instance self-hosted by the Publisher, in Switzerland: audience measurement. The instance is operated by the Publisher itself; no data is disclosed to a third-party provider. — Push notification services (Google Firebase Cloud Messaging, Mozilla Push Service, Apple Push Notification service), only if you have enabled notifications: they relay notifications to your device. The content of each notification is unreadable to them — it is encrypted with a key supplied by your device (see art. 8). They do, however, hold the endpoint address they assigned to your browser. Their servers are located outside Switzerland. — GeoIP (local database): resolution of geolocation (city, country) from the IP address. No transmission to a third party — the database is embedded in the application. — Telegram (optional): alerts sent to administrators for security and moderation events. The messages contain only the event type and a closed category (role, reason, severity) — no identifier, no email address, no location, no device, no content written by a user. — Competent authorities: upon lawful request under Swiss law. IntimX never sells, rents or shares your personal data for advertising or commercial purposes.
8. International Transfers
All personal data processed by IntimX is hosted in Switzerland: on Infomaniak's infrastructure for the application, the databases, the documents and the email service; on an instance self-hosted by the Publisher, also in Switzerland, for audience measurement. Three technical flows leave this perimeter. — Maps and address search (Mapbox Inc., United States). This is the largest of the three flows, and the only one that is neither optional nor unreadable to its recipient. As soon as a map is displayed, your browser contacts Mapbox's servers directly, and they receive your IP address and the coordinates of the area being viewed. When you type an address into a location form or during establishment registration, that address is sent to them as you type. The mapping library also sends them usage data. HTTPS encryption protects these exchanges in transit, but their content is readable by Mapbox. — Push notifications, only if you have enabled them: they travel through your browser's push service — Google (Firebase Cloud Messaging), Mozilla or Apple depending on the browser — whose servers are located outside Switzerland. The content of each notification is end-to-end encrypted in accordance with the Web Push standard (RFC 8291), using a public key supplied by your device: the push service relays the message without being able to read it. It does know the endpoint address it assigned to you, the timestamp and the size of each delivery. You can unsubscribe at any time from your browser or account settings. — Technical alerts sent to administrators via Telegram, whose servers are located outside Switzerland. These messages contain only the event type and a closed category, never any personal data (see art. 7). No other transfer of personal data outside Switzerland takes place.
9. Retention Periods
Active account: your data is retained for the duration of your registration. Account deletion: a 30-day grace period applies (cancellable). Upon expiry, the account is closed and data is processed as follows: — Encrypted identity data (vault): purged 3 years after closure (nFADP Art. 31(1)(c)). — KYC documents: deleted 3 years after closure (files and encrypted columns). — Transaction data (subscriptions): retained 10 years (CO Art. 958f). — Access logs (IP, user agent, geo): purged after 90 days. — Sessions: revoked on expiry (7 or 30 days) or on sign-out. The corresponding technical record (hashes of the IP address and browser, geographic context) is kept for a further 30 days so that you can review your recent sign-in history, then deleted automatically. — KYC audit log: retained indefinitely (compliance proof, nFADP Art. 32). — Consent log: retained indefinitely (proof of consent, nFADP Art. 6(7) / GDPR Art. 7(1)). — Administrative actions: retained indefinitely (legal evidence).
10. Security Measures
IntimX implements the following technical and organisational measures: — Three-database architecture: application data, sensitive data (vault) and system data are isolated in separate databases, with separate accounts and passwords. A compromise of the application database does not grant access to the vault. — Encryption at rest: personally identifiable data (first name, last name, date of birth, phone, address) is encrypted with AES-256-GCM in the vault. — Password hashing: Argon2id (64 MB memory, 3 iterations, OWASP 2023+ compliant). Compromised passwords (HIBP database) are rejected. History of the last 5 passwords to prevent reuse. — Token hashing: refresh tokens are stored as SHA-256 hashes (never in plain text). — Transport: mandatory HTTPS (TLS 1.3), Secure cookies. — CSRF: origin check (Origin header) on all mutating requests, backed by restrictive SameSite cookies. — Account lockout: progressive mechanism (15 min, 1 h, 24 h, administrator lock). — Enhanced authentication: optional Passkey/WebAuthn support. — Device trust: SHA-256 hashed device fingerprint, email OTP verification for unrecognised devices. — Access control: PostgreSQL Row-Level Security (RLS) on every table of the application database and the vault — the two databases where your data is stored — enforced even for the database owner role. — Audit logging: immutable (append-only) logs for KYC actions, consent and administrative actions.
11. Your Rights
Under the nFADP (Art. 25-29) and the GDPR (Art. 15-22), you have the following rights: — Right of access: obtain a copy of your personal data. — Right to rectification: correct inaccurate or incomplete data. — Right to erasure: request deletion of your data (subject to legal retention obligations). — Right to data portability: receive your data in a structured, machine-readable format (see Art. 12). — Right to object: object to processing based on legitimate interests. — Right to withdraw consent: withdraw your consent at any time (without affecting the lawfulness of prior processing). To exercise your rights, send an email to privacy@intimx.ch stating your identity and the right you wish to exercise. We respond within 30 days (nFADP) or 30 days, extendable to 90 days in complex cases (GDPR). You have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland (edoeb.admin.ch).
12. Data Portability
IntimX provides a data export function from your account settings. The export includes: — Account data: identifier, email, role, language, registration and closure dates. — Profile: display name, biography, preferences, privacy settings. — Messages: conversation history (limited to recent entries). — Bookings, reviews, favourites, support tickets. — Subscriptions: subscription history. — Consents: acceptance and withdrawal history. — Active sessions: geographic context and device. The export requires password re-verification (within the last 5 minutes) and is limited to one request per 24 hours. Data is provided in structured JSON format.
13. Protection of Minors
IntimX is intended exclusively for persons aged 18 or over. In accordance with Art. 197 Swiss Criminal Code, an age gate is presented on every first access. IntimX does not knowingly collect personal data from minors. If we learn that a minor has created an account, it will be immediately suspended and the data deleted. Any report of content involving a minor is treated with absolute priority via legal@intimx.ch.
14. Policy Amendments
The Publisher reserves the right to amend this policy at any time. Registered users will be informed of any material amendment by email or on-platform notification, at least 30 days before it takes effect. The date of the last update is indicated at the top of this document. Previous versions are available upon request at support@intimx.ch.
15. Contact
For any questions regarding the protection of your personal data: Data controller: N.JULIEN Contact: privacy@intimx.ch For general enquiries or support: support@intimx.ch For urgent reports (authorities, minors): legal@intimx.ch Supervisory authority: Federal Data Protection and Information Commissioner (FDPIC) Feldeggweg 1, 3003 Bern, Switzerland edoeb.admin.ch