Privacy Policy

Last updated: Juli 2026

1. Controller

QDC GmbH, Laurenzenvorstadt 61, 5000 Aarau, Switzerland ("we" or "provider"). Contact details see Imprint.

2. Scope

This privacy policy explains the nature, extent and purpose of the processing of personal data when using the eu-lex-enhanced platform. It applies in accordance with the revised Swiss Data Protection Act (FADP) and the EU General Data Protection Regulation (GDPR).

3. Data processed

We process the following personal data:

  • Registration data: email address, username, organisation
  • Usage data: language preference, last visited regulation, session data
  • Payment data: processed directly by Stripe (we store only the Stripe customer ID, no card data)
  • Technical data: IP address, browser type, access times (server logs)

4. Purpose of processing

  • Provision and operation of the platform
  • Authentication and account management
  • Handling subscriptions and payments
  • Improving the platform (anonymised analytics, where consented)

5. Legal bases

Processing is based on:

  • Performance of a contract (Art. 6(1)(b) GDPR / Art. 31 FADP)
  • Legitimate interests (Art. 6(1)(f) GDPR) for technical logs and platform security
  • Consent (Art. 6(1)(a) GDPR) for analytics cookies

6. Processors and third parties

  • Stripe, Inc. / Stripe, LLC – payment processing (Privacy Policy)
  • Resend, Inc. – email delivery (transactional emails)
  • MongoDB, Inc. – database hosting
  • Upsun / Platform.sh – application hosting
  • Google Analytics – web analytics (only with consent)

7. Transfers abroad

Certain personal data is transferred to service providers in the USA (Stripe – payments; Resend – email). There is no general adequacy decision for the USA; transfers are based on appropriate safeguards (Swiss-U.S. Data Privacy Framework or Standard Contractual Clauses). Details can be found in the respective providers' privacy notices.

8. Cookies

We use technically necessary cookies (session) and optional analytics cookies. You can change your cookie preferences at any time via the cookie settings.

9. Data security

We take appropriate technical and organisational measures to protect your data, in particular encrypted transmission (TLS), hashed passwords and access restrictions.

10. Retention period

Personal data is deleted once the purpose no longer applies, at the latest upon deletion of your account. Payment and invoice data is retained by the payment processor and to meet statutory retention obligations (commercial law, typically 10 years) even after account deletion. Upon account deletion the associated Stripe customer record is deleted; transaction records subject to statutory retention are kept.

11. Your rights

You have the right to information, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with the competent supervisory authority (Switzerland: Federal Data Protection and Information Commissioner FDPIC; EU: competent data protection authority). Contact us using the details in the imprint.

12. Changes

We reserve the right to amend this privacy policy where necessary. The current version is always available on this page.

Give Feedback
Loading...

Loading feedback questions...

Feedback System

Attribution notice
All legislative text displayed in the MDR Enhanced WebApp is fetched through the official EUR-Lex Web-service.¹ We do not edit, abridge or translate any passage; we only add usability layers such as collapsible headings, quick links and search highlights. EUR-Lex makes its legal documents freely re-usable under the Creative Commons Attribution 4.0 International Licence (CC BY 4.0). Whenever you download, quote or redistribute material, please credit "© European Union, EUR-Lex" and indicate any modifications.² Only the versions published in the Official Journal of the European Union are legally authentic. The Publications Office of the EU accepts no responsibility for any re-use of the data, and this WebApp does not constitute legal advice.² --- ¹ A permanent CELEX link guarantees that the reference will never change, provided the EUR-Lex copyright notice is respected. (eur-lex.europa.eu) ² Licence & liability statements: (eur-lex.europa.eu)