Privacy Policy
Privacy Policy
Melzer Labs
Gaissbergstrasse 2, CH-8280 Kreuzlingen
Legal form: Sole proprietorship
UID: CHE-217.593.064
Commercial register: Canton of Thurgau
Effective: July 2026
1. Data Controller
Responsible for data processing:
Melzer Labs
Gaissbergstrasse 2
CH-8280 Kreuzlingen
Switzerland
Legal form: Sole proprietorship
UID: CHE-217.593.064
Commercial register: Canton of Thurgau
Contact for data protection matters: legal@roundwork.ai
EU/EEA representative (GDPR Art. 27): Roundwork AI (operated by Melzer Labs) is offered exclusively in Switzerland. The payment callables that complete a paid transaction are geo-restricted server-side to Switzerland (`MARKET_ALLOWED_COUNTRIES = ['CH']`), and the Platform is not marketed or systematically offered to data subjects located in the EU/EEA. Because the Operator does not, on a regular basis, offer goods or services to data subjects in the EU/EEA, the Operator does not appoint a representative under Article 27 GDPR (Art. 27(2)(a) exception). If you are temporarily located in the EU/EEA and have a GDPR-related concern, please write to legal@roundwork.ai; the Operator will respond. Should the Platform be extended to the EU/EEA in the future, an Article 27 representative will be designated and named here at that time.
2. Scope
This Privacy Policy applies to the platform "Roundwork AI" and describes the type, scope, and purpose of the collection and use of personal data.
Personal data is processed in accordance with the Swiss Federal Act on Data Protection (FADP/nFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
2.1 Minors
The Platform is not directed at children. Students under the age of 16 (or the applicable age of digital consent in their country) may use the Platform only with the consent and under the supervision of a parent or legal guardian, who is responsible for the booking and for accepting these terms. This authorization is also required before a minor publishes a recommendation or a personal photo (see Section 3.7). We do not knowingly collect personal data from children without such consent; if we learn that we have, we will delete it.
3. Data Collected
3.1. Registration Data
- First and last name
- Email address
- Password (stored encrypted)
- Role (Student, Partner/Instructor)
3.2. Profile Data (Partners)
- Teaching address and geolocation data
- Profile description and photos
- Calendar data (when Google Calendar integration is enabled)
- Tax and business information (via Stripe Connect)
3.3. Usage Data
- Booking data (times, duration, status)
- Credit transactions
- Page views and interactions
3.4. Payment Data
- Stripe customer ID
- Payment references and transaction data
- Billing information (processed and stored by Stripe)
3.5. Integration Data (optional, Partner-initiated)
- Zoom: when a Partner connects their own Zoom account, we store their Zoom user ID, Zoom account email, account ID, and OAuth tokens (server-side only). For online lessons, the lesson topic, start time, and duration are sent to Zoom to create a meeting on the Partner's account; the resulting join link is shared with the booking student.
- Google Calendar: when a Partner connects their own Google account, we store OAuth tokens (server-side only) and event start/end times used to block booking slots.
3.6. On-site Lesson Address Disclosure
For on-site lessons (see AGB §4a), the full street address of the lesson location is shared between Partner and Student only as required to perform the booked service:
- A Partner's full teaching address is disclosed to a Student after the Student has a confirmed booking or an active credit balance scoped to that Partner. Before booking, only approximate location information (city or district) is shown publicly so that Students can discover relevant Partners.
- Where the lesson takes place at the Student's address, that address is provided to the Partner only after the booking is confirmed, and only to the extent the Student or Partner enters it into the booking. The Operator does not otherwise collect or store the Student's home address.
The legal basis for this disclosure is contract performance (Swiss FADP / nFADP Art. 31(2)(a); GDPR Art. 6(1)(b)): without sharing the lesson location, the booked lesson cannot be delivered. The disclosure is limited to what is necessary for the lesson and is not used for marketing or any other purpose.
3.7. Learner Advocacy Data (recommendations and referrals)
The Platform lets a signed-in Student publicly recommend an Instructor and share a personal referral link ("Learner Advocacy"). These features are optional; where you use them, we process:
- Recommendations: a star rating (1–5), your recommendation text, your public first name, your profile picture and/or an optional photo you upload, and an automatic "verified learner" indicator (set when you have a past, non-cancelled lesson with that Instructor). A published recommendation and any attached photo are shown publicly on the Instructor's page. Only your first name is shown; surnames are not intentionally displayed.
- Publication consent record: when you publish a recommendation we store a consent record (a consent token, the version of the consent text, the Instructor concerned, and a timestamp) so we can evidence that you agreed to publication.
- Referral attribution and rewards: a referral code and link unique to you and the chosen Instructor, a pseudonymous visitor identifier, and referral events (link visits, registrations, shares, and bookings attributed to your code), together with aggregate counters and any learning credits awarded to you. The related functional browser-storage entries are described in Section 10.
Recommendation photos are stored under `users/{your-user-id}/` in our storage bucket. Recommendations can only be created or changed through our server; clients cannot write them directly. By default, recommendations are held for Instructor moderation before they become publicly visible.
4. Purposes of Data Processing
Data is processed for the following purposes:
- Providing and operating the Platform
- Booking and payment processing
- Communication (booking confirmations, cancellations, system notifications)
- Partner onboarding and identity verification (KYC via Stripe)
- Publishing learner recommendations you choose to submit
- Operating the referral program: attribution, abuse prevention, and awarding learning credits
- Platform improvement and bug fixing
- Compliance with statutory retention obligations
5. Legal Basis
- Contract performance: Registration, booking, payment processing.
- Legitimate interest: Platform security, fraud prevention, service improvement, and operating and securing the referral program (attribution, abuse prevention, and rewarding successful referrals).
- Consent: Optional features such as calendar integration, marketing communications, and publishing a recommendation and any attached photo on an Instructor's page.
- Legal obligation: Tax record retention, AML/KYC compliance.
Under the Swiss FADP / nFADP, publishing a recommendation and any attached photo is based on your explicit consent, and the operation of the referral program (attribution, abuse prevention, and rewards) is based on the provision of the service you requested and our legitimate interests. GDPR bases apply only where the GDPR is relevant as described in Section 1.
6. Data Sharing with Third Parties
Personal data is shared with the following third-party providers as necessary for Platform operation:
| Provider | Purpose | Location |
|---|---|---|
| Google Firebase / Cloud | Hosting, database, authentication, analytics (with consent) | EU/US |
| Google Firebase App Hosting (Google Cloud CDN) | Edge caching and delivery of the web application | EU/US |
| Stripe | Payment processing, Partner onboarding (KYC) | EU/US |
| Zoom | Online lesson video meetings created on the Partner's own connected Zoom account (optional; requires separate OAuth consent). We send the lesson topic, start time, and duration; we receive the Partner's Zoom user ID, email, account ID, and a meeting join link. | EU/US |
| Google Calendar API | Calendar synchronization (optional; requires separate OAuth consent) | EU/US |
| Google Maps / Geocoding / Places API | Address autocomplete and geocoding for instructor locations (server-to-server only) | EU/US |
| Google Gemini AI | AI-assisted page building and instructor setup features; instructor profile content (names, descriptions) may be sent for processing | EU/US |
| OpenStreetMap Foundation (tile.openstreetmap.org) | Map tile delivery when a visitor displays the instructor discovery map. Your IP address and browser user-agent are transmitted to the OSMF for the purpose of serving the tiles. | UK / global CDN |
Appropriate data processing agreements are in place with processors we engage directly (Google, Stripe). OpenStreetMap is a content delivery network that receives connection metadata (IP, user-agent) when your browser fetches map tiles; no personal account information is sent to it by us. The Platform no longer loads third-party stylesheets or scripts from external CDNs (e.g., jsDelivr); page-builder layout CSS is served same-origin from `/assets/page-builder-tailwind.css`.
6.1 Google API Services — Limited Use Disclosure
The use and transfer of raw or derived user data received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Roundwork AI limits its use of Google user data obtained through OAuth (including the Google Calendar API) as follows:
- We use Google Calendar data solely to provide optional calendar synchronization features requested by instructors: reading busy times to prevent double-bookings and writing lesson events when bookings are confirmed, rescheduled, or cancelled.
- We do not use Google user data for advertising, retargeting, or marketing purposes.
- We do not sell Google user data to third parties.
- We do not use Google user data to train generalized AI or machine learning models.
- We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger or acquisition with user consent.
6.2 Zoom Integration
The Zoom integration is optional and is initiated by a Partner connecting their own Zoom account.
- We request only the `user:read:user` and `meeting:write:meeting` scopes. We do not read meeting lists, recordings, participants, chat, or account-wide admin data.
- Zoom OAuth tokens are stored encrypted at rest, server-side only, and are never exposed to the browser.
- Zoom data is used solely to create and manage video meetings for online lessons. It is not used for advertising, sold to third parties, or used to train AI models.
- Partners can disconnect Zoom at any time from Manage → Integrations; this deletes the stored tokens and revokes our access. Partners may also remove the app from the Zoom App Marketplace.
- When a Partner removes the app on Zoom's side, Zoom notifies us and we delete the associated Zoom data. All Zoom data is also deleted when the Roundwork account is deleted.
6.3 User-initiated Sharing (Learner Advocacy)
The Share & Earn panel lets you share your referral link or a referral image through channels you choose — WhatsApp, Instagram, LinkedIn, email, your device's native share sheet, or by copying the link. These actions are triggered only by you; the Platform does not post to these services on your behalf. Once content leaves the Platform through a channel you selected, it is governed by the privacy terms of the recipient app or service, and we cannot recall a card or link you have already shared or downloaded. QR codes on referral cards are generated on your own device; no referral URL or connection metadata is sent to a third-party QR service.
7. International Data Transfers
Data may be transferred to countries outside Switzerland and the EU (notably the US). Protection is ensured through appropriate safeguards (e.g., Standard Contractual Clauses, adequacy decisions).
8. Data Security
We implement appropriate technical and organizational measures to protect personal data:
- Encrypted data transmission (TLS/HTTPS)
- Encrypted storage of sensitive data
- Access restrictions and role-based permissions
- Regular security reviews
8.1 Firebase App Check (abuse prevention)
The Platform uses Firebase App Check to mitigate abusive or automated traffic to backend endpoints (callable Cloud Functions, Firestore, Storage). App Check issues a short-lived attestation token confirming that a request originates from a legitimate Roundwork AI web client. The underlying reCAPTCHA v3 attestation provider (operated by Google) may evaluate technical signals (e.g., browser characteristics, IP address, request timing) on Google's servers solely to return the App Check verdict; no application account data, profile content, or booking content is sent to the App Check provider. App Check is a strictly necessary security measure for the Platform under FADP / GDPR Art. 6(1)(f) (legitimate interest in preventing abuse and protecting the service).
9. Retention and Deletion
- Account data is retained as long as the account is active.
- Upon account deletion, personal data is removed immediately. Financial records required by tax law are retained for the legally mandated retention period (in Switzerland: up to 10 years) with personal identifiers minimized.
- Transactional email records are deleted as part of account deletion.
- Integration tokens and data (Zoom, Google Calendar) are deleted when the Partner disconnects the integration, when the account is deleted, or — for Zoom — when the app is removed via the Zoom App Marketplace.
- Learner Advocacy data: you can remove a recommendation you published at any time, and Instructors can hide or remove recommendations on their page through moderation. When you delete your account, your recommendations (including any attached photos), referral links, referral events, referral statistics, and recommendation consent records are deleted; recommendations left on your page in your capacity as an Instructor are removed as well. We cannot retract a referral card or link you have already downloaded or shared through an external channel.
10. Cookies and Tracking
The Platform uses technically necessary cookies for authentication and session management. Analytical cookies (Firebase Analytics) are only activated after the user provides explicit consent via the cookie consent banner displayed on first visit. No tracking occurs before consent is given. Consent preferences are stored locally and can be changed at any time.
Separately, the referral feature stores a small number of functional entries in your browser's local storage so that an inbound referral can be correctly attributed to a booking: the referral code (`roundwork-ai:referral-code`), a per-Instructor referral-code map (`roundwork-ai:referral-codes-by-instructor`), a pseudonymous visitor identifier used to de-duplicate visit counts (`roundwork-ai:referral-visitor-id`), and the last Instructor page you viewed (`roundwork-ai:last-instructor-id`). These entries are necessary to provide the referral attribution you requested, are not advertising or cross-site tracking identifiers, and the code for a given Instructor is cleared after a successful attributed booking.
11. Rights of Data Subjects
You have the following rights:
- Access: Information about what data is stored about you.
- Rectification: Correction of inaccurate data.
- Erasure: Deletion of your data, subject to statutory retention requirements.
- Data portability: Provision of your data in a common format.
- Objection: Against processing based on legitimate interests.
- Withdrawal of consent: At any time, without affecting the lawfulness of prior processing.
- Recommendations and publication consent: You can remove any recommendation you published at any time from the Instructor's page; this withdraws your consent to its continued publication and does not affect the lawfulness of publication before withdrawal.
Please direct requests to legal@roundwork.ai or the address listed in Section 1.
11.1 Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority:
- In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern (edoeb.admin.ch).
- In the EU/EEA: the supervisory authority of your country of residence, place of work, or place of the alleged infringement.
12. Changes
This Privacy Policy may be updated at any time. Material changes will be communicated via email or in-app notification.
13. Contact
For privacy-related questions, contact:
Melzer Labs
Gaissbergstrasse 2
CH-8280 Kreuzlingen
Switzerland
Legal form: Sole proprietorship
UID: CHE-217.593.064
Commercial register: Canton of Thurgau
