Privacy Policy
Last updated: 4 July 2026
1. Responsible Entity
Responsible for data processing (Controller):
NeverBanked GmbH
Heidenmösliweg 7
8713 Uerikon, Switzerland
Represented by its Managing Director, Nicolas Schwarz
Email: info@neverbanked.com
Phone: +41 79 128 90 10
(Hereafter referred to as NeverBanked, we or us)
2. Scope and Consent
This Privacy Policy explains the nature, scope, and purpose of how we collect and use your personal data when you visit our website (www.neverbanked.com / www.neverbanked.ch / courses.neverbanked.com / neverbanked-os.vercel.app), our landing pages, and use our services (e.g., accessing free resources, purchasing online courses, participating in coaching programs).
Where required by applicable data protection law, we process personal data based on your explicit consent. In all other cases, personal data is processed based on statutory legal bases, in particular for the performance of a contract or our legitimate interests as described in this Privacy Policy.
3. Categories of Personal Data Processed
We process the following categories of personal data:
Master & Contact Data: Name, address, email, phone number.
Contract & Payment Data: Information related to your purchases, subscriptions, and payment details (processed securely by third-party providers; we do not store full payment card data).
Application & Content Data: For coaching programs, this includes CVs, cover letters, LinkedIn profiles, questionnaires, survey responses, other documents you upload, as well as recordings of coaching or consultation calls where such recording is agreed in advance. Participation in recorded sessions is voluntary; refusal to consent to recordings has no impact on the availability or quality of the coaching services.
Communication Data: Correspondence via email, messages, notes from calls, and written feedback or statements provided during the coaching relationship.
Third-Party Data Entered by Clients: In connection with coaching programs, clients may enter into our CRM and networking tools personal data relating to third parties (for example, names, roles, employers, and interaction notes concerning professional contacts, such as bankers they network with). We process this data to deliver the coaching service. Details are set out in Section 6.5.
Technical & Usage Data: IP address, browser type/version, operating system, device information, referrer URL, time of access, pages visited, and interaction data. This includes data collected via cookies, log files, and similar technologies such as tracking pixels (e.g. Meta Pixel, LinkedIn Insight Tag), where implemented.
4. Purposes of Processing & Legal Bases
We process your data for the following purposes and on the corresponding legal bases:
Contract Fulfillment: Providing and administering purchased courses and coaching services, processing payments, and communicating with you about the service. Legal basis: Performance of a contract (Art. 31(2) FADP / Art. 6(1)(b) GDPR).
Legitimate Interests: Operating, securing, and improving our website and services; direct marketing of our own similar products/services; preventing misuse. Legal basis: Legitimate interest (Art. 31(1) FADP / Art. 6(1)(f) GDPR).
Legal Compliance: Fulfilling our accounting, tax, and other legal obligations under Swiss law. Legal basis: Compliance with a legal obligation (Art. 6(1)(c) GDPR).
Consent: For specific, optional purposes where we have asked for and you have given explicit consent (e.g., certain newsletters). Legal basis: Your consent (Art. 30 FADP / Art. 6(1)(a) GDPR).
5. Log Files, Hosting & Cookies
5.1 Hosting & Log Files
Our website and landing pages are hosted on the ClickFunnels and Kajabi platforms. Our client CRM application runs on Vercel (application hosting) and Supabase (database). When you access our sites or apps, these providers automatically collect and store technical data in server log files (as detailed in Section 3). This data is essential for technical operation, security, and error analysis. IP addresses are anonymized or deleted after a short period.
5.2 Cookies & Tracking Technologies
We use necessary cookies to ensure the basic functionality of the website (e.g., maintaining your login session). We may also use analytics and marketing technologies, such as cookies and tracking pixels (e.g. Meta Pixel, LinkedIn Insight Tag), to measure the effectiveness of our marketing campaigns, analyse user interactions, and improve our services.
Where required by applicable law, such technologies are only used based on your consent. You can manage cookie and tracking settings via your browser or any consent tools implemented on the website. Restricting cookies or tracking technologies may limit website functionality.
You may withdraw or adjust your consent to cookies and tracking technologies at any time with future effect via your browser settings or any consent management tool implemented on the website.
6. Data Disclosure to Third Parties
We engage specialised third-party service providers to operate our business. They are categorized and obligated as follows:
Processors: Service providers who process personal data only on our documented instructions and are contractually obligated to comply with data protection law (e.g., Kajabi for hosting, Bexio for accounting).
Independent Controllers: Service providers who determine the purpose and means of their processing independently. Their processing is governed by their own privacy policies (e.g., payment providers like Stripe, advertising platforms like Meta). Users are encouraged to review the privacy policies of Independent Controllers.
Key processors and third-party services include:
- Kajabi LLC: Primary platform for hosting, online courses, and parts of our customer management. Data may be transferred to and processed in the United States, based on recognised safeguards including standard contractual clauses.
- ClickFunnels: Landing pages and marketing funnels. Data may be transferred to and processed in the United States, based on recognised safeguards.
- Kit (ConvertKit): Email marketing and automation. Data may be transferred to and processed in the United States, based on recognised safeguards.
- Close: Customer relationship management (CRM). Data may be transferred to and processed in the United States, based on recognised safeguards.
- Notion Labs, Inc.: Internal knowledge management, CRM records, and content organisation. Data may be transferred to and processed in the United States, based on recognised safeguards.
- Vercel: Application hosting for our client CRM app. Data may be transferred to and processed in the United States, based on recognised safeguards.
- Supabase: Database infrastructure used for the client CRM and application data. Data is hosted in the region configured for our project.
- Calendly: Scheduling of calls and appointments. Data may be transferred to and processed in the United States, based on recognised safeguards.
- Zapier / ManyChat: Workflow automation and automated messaging across our systems and social platforms. Data may be transferred to and processed in the United States, based on recognised safeguards.
- Bexio AG: Accounting, invoicing, and statutory record-keeping. Data is processed in Switzerland or the European Economic Area.
- Payment Providers (e.g., Stripe, TWINT): For secure payment processing. These providers act as independent controllers for payment-related data. Please refer to their respective privacy policies.
- Analytics & Advertising Providers (e.g., Meta Platforms, LinkedIn): Tracking pixels and insight tags to measure campaign performance, conversion events, and audience interactions. These providers process data as independent controllers under their own privacy policies.
Personal data is disclosed to other third parties (e.g., authorities) only where required by Swiss law or necessary to protect our rights.
6.5 Data Entered by Clients About Third Parties
As part of our coaching services, clients may enter personal data relating to third parties (for example, professional contacts such as bankers) into our CRM and networking tools. Where a client does so, the client is responsible for ensuring they have a lawful basis for entering that data.
We process such data on the basis of our and the client's legitimate interest in delivering the coaching service (Art. 31(1) FADP / Art. 6(1)(f) GDPR), limited to professional contact and interaction data. We retain it for the duration of the relevant coaching relationship and delete or anonymise it thereafter, subject to legal retention obligations. Third parties whose data has been entered may exercise the rights set out in Section 10; such requests are handled in coordination with the relevant client where appropriate.
7. International Data Transfers
As indicated above, data may be transferred to countries outside Switzerland and the European Economic Area (EEA), notably to the USA. We ensure such transfers are protected by appropriate safeguards, such as the standard contractual clauses approved by the Swiss Federal Council and the European Commission.
8. Data Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. However, absolute security on the internet cannot be guaranteed.
9. Data Retention
We retain personal data only as long as necessary for the fulfillment of the purposes outlined in Section 4 or as required by law (e.g., Swiss accounting law requires retention of business records for 10 years).
Course & Coaching Data: Retained for up to 24 months after the end of the contractual relationship for service continuity and support, unless longer retention is required for legal reasons.
Marketing Data: Retained as long as you are an active customer or have not withdrawn your consent or objected to marketing.
10. Your Rights
You have the following rights regarding your personal data:
- Right of Access
- Right to Rectification
- Right to Erasure (“Right to be Forgotten”), subject to legal limitations
- Right to Restriction of Processing
- Right to Data Portability
- Right to Object to processing based on our legitimate interests
- Right to Withdraw Consent at any time with future effect
Please note that these rights are subject to conditions, exceptions, or restrictions (e.g., to protect third parties or trade secrets).
To exercise these rights, contact us at info@neverbanked.com. We may require proof of identity.
You also have the right to lodge a complaint with the competent supervisory authority, the Swiss Federal Data Protection and Information Commissioner (FDPIC).
11. Changes to This Privacy Policy
We reserve the right to change this Privacy Policy at any time. The latest version will always be published on this page, with the “Last updated” date revised accordingly.
We will notify you of material changes that affect your rights or our core processing activities (e.g., a change of controller, a new purpose of processing) through appropriate means, such as a prominent notice on our website or direct communication. For other updates, your continued use of our services after the publication of the revised policy constitutes acceptance of the changes.