Privacy Policy
Draft of 5 October 2026 for the new online booking. Not yet legally reviewed.
Your trust is the foundation of our work. This applies not only on the treatment table, but also in the way we handle your data. Below, you will find out which data we collect, how we use it and what rights you have.
We comply with the requirements of the Swiss Federal Act on Data Protection (FADP; DSG).
1. Controller
Onua - Massage & Therapie, Papic
(trading under the brand «Onuā»)
Ansel Papic, Owner
Hohlstrasse 481
8048 Zürich
Switzerland
Email: info@onua.ch
2. Data we collect
We only collect data that is necessary to provide our services and operate our website.
When you visit our website
When you visit our website, certain technical data is automatically collected:
- IP address (anonymised)
- Browser type and version
- Operating system
- Referrer URL (where you came to our site from)
- Date and time of access
This data is used to provide the website technically and is not linked to you personally.
When you contact us
If you contact us by email or via the contact form, we process your message and the contact details you provide (name, email address) to handle your enquiry. Resend delivers the email.
Newsletter
When you subscribe to the newsletter, we store your email address, language, signup source, and subscription time with Resend. Your subscription becomes active as soon as you submit the form (single opt-in). You can unsubscribe at any time through the unsubscribe link in each newsletter email.
FAQ assistant
If you ask your own question below the FAQ, it goes to OpenAI (USA) to be answered; we remove email addresses and phone numbers first. We keep the question and answer for 12 months to improve the FAQ. Please don’t enter personal details there.
3. Appointment booking and customer account
You book your appointments directly on our website. To do so, you open a customer account, which you confirm with your email address. We process:
- first and last name, email address and mobile number
- your appointments: treatment, duration, therapist, time, status, payment status and your message to us
- your appointment requests (waitlist): preferred days, times of day and your note
- further details in your account that we need for invoices and reimbursement receipts, such as date of birth, gender, address, health insurer and insurance number
- invoices, reimbursement receipts and other documents relating to your treatments
Clerk provides sign-in and your account (email confirmation, sign-in, sessions). Supabase stores your account, appointment and treatment data, and Vercel operates the booking backend. We send emails via Resend and text messages via Twilio.
You receive confirmations and changes of your appointments by email. We send reminders before your appointment and offers for your appointment requests by email and, if you gave us a mobile number, also by text message. We email you your reimbursement receipts. On your birthday, based on your date of birth, you receive a little surprise by email and text message. In your account under «Notifications» you choose which of these messages you receive; reminders keep email or text messages on.
Information about your health, such as complaints in your message or notes about your treatment, is sensitive personal data. We process it only for your treatment and billing. The practice owners can see all appointments and notes; our therapists only those of their own appointments.
4. Payment and gift vouchers via SumUp and Stripe
Online payments for appointments and gift vouchers are processed by SumUp (card, Apple Pay, Google Pay). Payment information such as card details is processed exclusively by SumUp and is not stored on our systems. We store the amount, status and reference of the payment. You can find more information at: sumup.com/privacy
Online payments with TWINT for appointments are processed by Stripe (Stripe Payments Europe, Limited, Ireland). For this we send Stripe the amount in Swiss francs, the description «Onuā Termin» or «Onuā Terminänderung» and our payment reference, but not your name, your email address or any health data. You confirm the payment in your TWINT app; on the payment page, Stripe and TWINT process the data needed for it under their own responsibility. Refunds go back to your TWINT through Stripe. Here too, we store the amount, status and reference of the payment. You can find more information at: stripe.com/privacy
When you buy a gift voucher, we process the purchaser’s name and email address, the recipient’s name and optional email address, a personal message, the voucher selection, amount, language and voucher status. Supabase stores the voucher and delivery data, and Vercel operates the backend. If you redeem a voucher when booking, we link it to your appointment.
5. Use of your data
We use your data exclusively for the following purposes:
- Providing our services (customer account, appointment booking, waitlist, treatment, gift vouchers)
- Messages about your appointments and appointment requests by email and SMS
- Reimbursement receipts by email and a little surprise on your birthday
- Invoices and reimbursement receipts for your health insurer
- Processing your enquiries
- Operating and improving our website
- Complying with legal obligations
We do not create a profile of you and do not make automated decisions based on your data.
6. Sharing your data
We do not share your data with third parties unless this is necessary to provide our services (see the section «Third-party providers») or we are legally required to do so.
7. Third-party providers
We work with the following third-party providers:
Provider, purpose and privacy policy
- Clerk: Customer account and sign-in (clerk.com/legal/privacy)
- SumUp: Payment processing for appointments and vouchers (sumup.com/privacy)
- Stripe: Payment processing for TWINT payments (stripe.com/privacy)
- Google Analytics: Website analytics (policies.google.com/privacy)
- Meta Pixel: Reach measurement and marketing (facebook.com/privacy/policy)
- LinkedIn Insight Tag: Reach measurement and marketing (linkedin.com/legal/privacy-policy)
- Cloudflare: Website hosting, DDoS protection, and Turnstile security checks (cloudflare.com/privacypolicy)
- Vercel: Operation of the booking and voucher backend (vercel.com/legal/privacy-policy)
- Supabase: Storage of account, appointment, treatment and voucher data (supabase.com/privacy)
- Resend: Storage and management of newsletter contacts and delivery of booking, receipt, birthday, contact, voucher and newsletter emails (resend.com/legal/privacy-policy)
- Twilio: Delivery of SMS about your appointments, appointment requests and your birthday (twilio.com/legal/privacy)
- OpenAI: Answering questions in the FAQ assistant (openai.com/policies/privacy-policy)
- Google Maps: Map display on the contact page and address suggestions when an address is entered, see «Google Maps: map and address suggestions» below (policies.google.com/privacy)
- Unicorn Studio: Interactive visual content (unicorn.studio/privacy-policy)
We select storage locations according to the purpose and provider. Where third-party providers process data abroad, this takes place in compliance with the legal requirements and with appropriate safeguards.
Google Maps: map and address suggestions
We use the Google Maps Platform from Google (Google Cloud EMEA Limited, Ireland, and Google LLC, USA). The map on the contact page loads only when you click «Load map». Address suggestions (Maps JavaScript API and Places API) appear in the «Street and number» field of your account on our website and in the address fields of our practice software when our team enters or corrects your address.
Google receives data only once someone uses an address field, and only what the suggestions need: the characters typed (in our practice software from the third character), the chosen address, the IP address, browser and device information and the page the request comes from. Google groups the requests of one search with a session token. We do not send your name, email address, appointments or health information to Google.
We use the suggestions so that addresses are complete and correctly spelled, for example on invoices and reimbursement receipts. We rely on our overriding legitimate interest (Art. 31 FADP; where the GDPR applies, Art. 6(1)(f) GDPR).
You don’t have to choose a suggestion and can type your address yourself. The characters you enter still go to Google while you type.
Google LLC is certified under the Swiss-U.S. and EU-U.S. Data Privacy Framework; Google’s standard contractual clauses also apply. How long Google keeps the data is determined by Google: policies.google.com/privacy and cloud.google.com/maps-platform/terms
8. Cookies and tracking
Our website uses cookies. Cookies are small text files that are stored in your browser.
Necessary cookies
These cookies are required for the operation of the website and cannot be deactivated. They include cookies for basic functions such as language settings.
Analytics and marketing cookies
We use Google Analytics, Meta Pixel, and the LinkedIn Insight Tag unless you have opted out. These services help us measure website use and the reach of our communication.
Third-party cookies
For sign-in, Clerk sets necessary cookies that keep your session secure. When you pay, SumUp loads its payment form and may set its own cookies needed for the payment. For a TWINT payment you move to Stripe’s payment page, which may also set its own cookies needed for the payment.
Interactive visual scenes are loaded through Unicorn Studio as part of the page design. Visiting a page with such a scene can establish a connection to Unicorn Studio and its delivery network.
Non-essential analytics and marketing services are enabled by default. Use «Decline cookies» in the footer to disable them and «Allow cookies» to enable them again later.
9. Security of your data
We use appropriate technical and organisational measures to protect your data from unauthorised access, loss or misuse. Our website is provided via an encrypted HTTPS connection. Your customer account is protected by confirming your email address and a secure sign-in. Only the people who need your appointment and health data for your treatment and billing can access it. Card details are processed exclusively by SumUp.
10. Retention period
We store your data only for as long as is necessary for the respective purpose or as required by statutory retention obligations. Contact enquiries are deleted after processing has been completed, unless a statutory retention obligation applies.
We keep your customer account and details for as long as the account exists. We keep invoices and other accounting records for ten years (Art. 958f CO). We keep information about your treatments for as long as it is needed for your care or required by law.
11. Your rights
Under the Swiss Federal Act on Data Protection (FADP; DSG), you have the following rights:
- Access: You can find out at any time whether and which data we process about you.
- Rectification: You can request the correction of inaccurate data.
- Erasure: You can request the deletion of your data, provided there is no statutory retention obligation.
- Objection: You can object to the processing of your data.
- Data disclosure: You can request that we provide your data to you in a commonly used format or transfer it to another controller.
- Withdrawal: You can withdraw consent you have given at any time.
To exercise your rights, please contact: info@onua.ch
You can ask us to delete your customer account at any time. Records we are required to keep remain stored until the retention period ends.
If you believe that the processing of your data violates data protection law, you can lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC; EDÖB): edoeb.admin.ch
12. Legal basis
We process your data on the basis of your consent (e.g. cookies, contact form) or for the performance of a contract (e.g. appointment booking, voucher purchase). Where legally required, we rely on our legitimate interest (e.g. website operation, security, address suggestions).
13. Applicable law
This Privacy Policy is governed by Swiss law. The place of jurisdiction is the registered office of Onua - Massage & Therapie, Papic, Hohlstrasse 481, 8048 Zürich, Switzerland (trading under the brand «Onuā»).
14. Changes
We may amend this Privacy Policy at any time. The current version is always available on our website. In the event of material changes, we will inform you in an appropriate manner.
Contact
If you have any questions about data protection, you can contact us at any time at info@onua.ch.