Privacy Policy.
How Ingredient Clarity Lab — a Skin Match Technology Switzerland AG brand — collects, uses, shares, and protects personal data under the Swiss FADP and the EU GDPR.
Introduction
Ingredient Clarity Lab (“ICL”, “we”, “us” or “our”), a brand of Skin Match Technology Switzerland AG, is committed to protecting the personal data of visitors to https://ingredientclarity.com and of the Brands, Partners, and individuals who use our Services (collectively, the “Website” and the “Services”). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights You have in respect of Your personal data.
ICL processes personal data in accordance with the Swiss Federal Act on Data Protection of 25 September 2020 (the “FADP”) and, where applicable, the EU General Data Protection Regulation 2016/679 (the “GDPR”). Although Skin Match Technology Switzerland AG is established in Switzerland, we have aligned our practices with the GDPR so that visitors and users from the European Economic Area (EEA) and the United Kingdom benefit from an equivalent level of protection.
This Privacy Policy is incorporated into, and forms part of, our Terms of Use. Capitalised terms not defined here have the meaning given to them in the Terms of Use.
Data Controller
The controller responsible for the processing of Your personal data, within the meaning of Article 4(7) GDPR and the FADP, is:
Skin Match Technology Switzerland AG
Ingredient Clarity Lab
c/o Estella Benz
Mutschellenstrasse 197
8038 Zurich, Switzerland
UID: CHE-330.323.981 — VAT: CHE-330.323.981 MWST
Email:
Website: https://ingredientclarity.com
DPO & EU Representative
ICL has not appointed a Data Protection Officer (DPO), as the criteria of Article 37 GDPR and Article 10 FADP are not met. Any privacy-related question may be addressed directly to the contact details set out in Section 2 above.
ICL has not designated a representative within the European Union under Article 27 GDPR. To the extent that processing carried out by ICL may bring it within the scope of Article 27, ICL will reassess this position and appoint a representative if and when required. Until then, all rights and requests under the GDPR may be exercised directly with ICL using the contact details in Section 2.
Categories of Personal Data
We process the following categories of personal data, depending on how You interact with us:
4.1 Website visitors
- Technical data: IP address (truncated where feasible), browser type and version, device and operating system, screen resolution, referrer URL, pages viewed, session duration, language, approximate location derived from IP.
- Cookie identifiers and similar technologies (see Section 11 below).
- Information You voluntarily submit via contact, demo-request, or newsletter forms (name, business email, company, role, message).
4.2 Brands and Certification Dashboard users
- Account data: first and last name, business email, password (stored as a salted hash), company name, role, country, telephone number (optional).
- Authentication data: login timestamps, IP address at login, session identifiers, multi-factor-authentication tokens (where enabled).
- Product and Formulation data submitted for Certification (which may contain identifiers of the responsible person within the Brand, e.g. a regulatory or R&D contact).
- Communications with ICL, including support tickets, emails, and any attached documents.
4.3 Subscription and billing
- Billing contact name, business email, company name, billing address, VAT number.
- Subscription metadata: plan, status, renewal date, invoice history.
- Limited payment metadata received from our payment provider (last four digits of the card, card brand, expiry, country of issue). ICL does not store full payment-card numbers; these are handled directly by Chargebee and Stripe in their PCI-DSS compliant environment.
4.4 Marketing recipients
- Contact data: name, business email, company, role, country, preferred language.
- Engagement data: emails opened, links clicked, content downloaded, web pages visited where reasonably attributable to You via HubSpot tracking.
- Marketing preferences and consent records.
Purposes & Legal Bases
We process personal data for the purposes and on the legal bases listed below. References to legal bases are made under both the GDPR (Article 6(1)) and, where relevant, the FADP.
- Operating and securing the Website (logging, fraud and abuse prevention, technical administration) — legitimate interest (Art. 6(1)(f) GDPR) and Art. 31(2)(c) FADP.
- Providing the Services and managing the Certification Dashboard, including authentication, assessment of submitted Formulations, issuance and lifecycle management of Certifications and Seals — performance of a contract (Art. 6(1)(b) GDPR).
- Processing subscriptions, invoicing, payment, accounting, and tax compliance via Chargebee and the underlying payment processor — performance of a contract and compliance with legal obligations (Art. 6(1)(b) and 6(1)(c) GDPR).
- Responding to enquiries, demo requests, support tickets, and other communications — performance of pre-contractual measures or legitimate interest (Art. 6(1)(b) or 6(1)(f) GDPR).
- Sending transactional emails relating to Your account, Certifications, subscriptions, or service updates — performance of a contract (Art. 6(1)(b) GDPR).
- Sending marketing communications (newsletters, product updates, event invitations) via HubSpot — Your consent (Art. 6(1)(a) GDPR) or, for existing business customers, legitimate interest in the limits permitted by applicable law and Art. 3 of the Swiss Federal Act against Unfair Competition (UCA).
- Measuring and analysing Website usage via Google Analytics and HubSpot analytics cookies — Your consent (Art. 6(1)(a) GDPR).
- Carrying out randomised audits and verifying appropriate use of Certifications and Seals — legitimate interest in protecting the integrity of the certification system (Art. 6(1)(f) GDPR).
- Establishing, exercising, or defending legal claims and complying with legal, regulatory, or accounting obligations — legitimate interest and legal obligation (Art. 6(1)(c) and 6(1)(f) GDPR).
Sources of Personal Data
We collect personal data primarily directly from You — when You visit the Website, fill in a form, create an account, submit a Product for Certification, subscribe to a plan, or contact us. In some cases we receive personal data from third parties, including (i) Your colleagues or company representatives who add You as a user of the Brand’s Dashboard account, (ii) public business registers, professional networks, or trade-show participant lists from which we may obtain business contact details for B2B outreach, and (iii) our service providers (e.g. Chargebee, Stripe, HubSpot) in connection with the Services they provide to us.
Recipients & Sub-processors
Within ICL and Skin Match Technology Switzerland AG, only employees and contractors who need access to personal data to perform their duties are authorised to do so, under appropriate confidentiality obligations.
We share personal data with the following categories of third parties, who act either as our processors under data processing agreements (DPAs) or, in limited cases, as independent controllers:
- Google Ireland Limited / Google LLC (Google Analytics 4) — measurement of Website usage. IP truncation is enabled and advertising features are disabled. Privacy information: policies.google.com/privacy.
- HubSpot, Inc. — customer-relationship management, marketing automation, form handling, and email delivery for marketing and transactional communications. Privacy information: legal.hubspot.com/privacy-policy.
- Chargebee, Inc. — subscription management, billing, invoicing, dunning, and tax determination. Privacy information: chargebee.com/privacy.
- Stripe Payments Europe Ltd. (and its affiliates) — payment-card processing, fraud prevention, and 3-D Secure authentication on behalf of Chargebee. Privacy information: stripe.com/privacy.
- Cloud-infrastructure providers — hosting of the Website, the Certification Dashboard, databases, backups, and logs. The current hosting region(s) and provider(s) are listed on this page and updated as our infrastructure evolves. ICL selects providers that offer EU or Swiss hosting regions wherever technically feasible.
- Email and productivity providers — secure email, document storage, and internal collaboration tools used by ICL personnel.
- Professional advisers — auditors, accountants, lawyers, and insurers, bound by professional secrecy obligations.
- Public authorities, courts, and law-enforcement bodies, where disclosure is required by law or to protect ICL’s legal rights.
We do not sell personal data and do not share it with third parties for their own marketing purposes.
International Transfers
ICL is based in Switzerland. Switzerland is recognised by the European Commission as providing an adequate level of data protection (Decision 2000/518/EC, as updated), so transfers between the EEA and Switzerland do not require additional safeguards.
Some of our service providers — including Google, HubSpot, Chargebee, and Stripe — are established in, or process data through affiliates in, countries outside Switzerland and the EEA, including the United States. Where such transfers take place, we rely on one or more of the following safeguards:
- EU Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914), together with the Swiss addendum recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC).
- The EU–U.S. Data Privacy Framework and the Swiss–U.S. Data Privacy Framework, where the recipient is certified.
- Supplementary technical, contractual, and organisational measures such as encryption in transit and at rest, pseudonymisation, access controls, and transfer impact assessments.
A copy of the safeguards in place for a specific transfer is available on request to .
Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. The following indicative retention periods apply:
- Server and security logs: up to 12 months, then deleted or anonymised.
- Website analytics data (Google Analytics 4): up to 14 months.
- Marketing contact and engagement data (HubSpot): until You unsubscribe or object, or after 24 months of inactivity, whichever is earlier.
- Account and dashboard data: for the duration of the account and for 12 months after closure, after which the data is deleted or anonymised, save for information required to meet legal retention obligations.
- Formulation and Certification data: for the duration of the Certification and for as long as the Certification could be relied upon by third parties, plus the limitation periods applicable to any claims arising from the Certification.
- Billing, invoicing, and tax records: 10 years from the end of the relevant fiscal year, in accordance with Article 958f of the Swiss Code of Obligations and applicable VAT legislation.
- Records of consent: at least as long as the underlying processing, and for a reasonable period thereafter, to evidence compliance.
Your Rights
Subject to the conditions set out in the FADP and, where applicable, the GDPR, You have the following rights in respect of Your personal data:
- Right of access — obtain confirmation of whether we process Your personal data and, if so, a copy of that data.
- Right to rectification — request correction of inaccurate or incomplete personal data.
- Right to erasure (“right to be forgotten”) — request deletion of personal data where one of the grounds in Article 17 GDPR applies.
- Right to restriction — request restriction of processing in the circumstances set out in Article 18 GDPR.
- Right to data portability — receive Your personal data in a structured, commonly used, and machine-readable format, and have it transmitted to another controller, where Article 20 GDPR applies.
- Right to object — object at any time, on grounds relating to Your particular situation, to processing based on legitimate interests, and at any time and without justification to processing for direct-marketing purposes.
- Right to withdraw consent — where processing is based on consent, withdraw consent at any time without affecting the lawfulness of prior processing.
- Right not to be subject to automated decisions — based solely on automated processing producing legal or similarly significant effects (see Section 14).
- Right to lodge a complaint — with the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) or, where applicable, with the supervisory authority in Your EEA Member State of habitual residence.
To exercise any of these rights, please contact us at . We may need to verify Your identity before responding and will reply within the timeframes required by applicable law (one month under the GDPR, extendable by two further months where necessary).
Cookies & Similar Technologies
We use cookies and similar technologies (such as pixels, local storage, and software development kits) to operate the Website, to remember Your preferences, to measure usage, and — subject to Your consent — for analytics and marketing purposes.
On Your first visit, a consent banner allows You to accept, refuse, or selectively enable non-essential cookies. You can change Your choice at any time via the “Cookie Settings” link in the Website footer. Disabling certain cookies may limit the functionality of the Website or the Certification Dashboard.
The categories of cookies and similar technologies we use are summarised in the table below.
| Cookie / service | Category | Purpose | Provider | Retention |
|---|---|---|---|---|
| Session / authentication cookies | Strictly necessary | Keep You signed in to the Certification Dashboard, maintain session integrity, and protect against CSRF. | ICL (first-party) | Session to 30 days |
| CSRF / load-balancing cookies | Strictly necessary | Secure form submission and balance traffic across servers. | ICL (first-party) | Session |
| Consent preference cookie | Strictly necessary | Store Your cookie consent choices so the banner is not shown again. | ICL (first-party) | Up to 12 months |
| _ga, _ga_* | Analytics | Distinguish unique visitors and measure aggregated website usage via Google Analytics 4. | Google Ireland Ltd. / Google LLC | Up to 24 months |
| __hstc, hubspotutk, __hssc, __hssrc | Analytics / marketing | Identify returning visitors to our HubSpot-served content, attribute form submissions, and measure marketing campaign performance. | HubSpot, Inc. | Session to 13 months |
| Chargebee session cookies | Strictly necessary | Operate the secure checkout, manage Your subscription session, and prevent fraud during payment. | Chargebee, Inc. | Session to 12 months |
| Stripe payment cookies (m, __stripe_*) | Strictly necessary | Card-payment processing, fraud prevention (Radar) and 3-D Secure authentication. | Stripe Payments Europe Ltd. | Up to 24 months |
Browser controls: most browsers allow You to manage cookies through their settings, including blocking or deleting them. Information on how to do this for major browsers is available at aboutcookies.org.
Marketing Communications
Where required by law, we send marketing emails only with Your prior consent, which You may withdraw at any time by using the “unsubscribe” link in every marketing email or by contacting us at . Withdrawing Your consent does not affect the lawfulness of processing carried out before the withdrawal.
Where we send marketing communications to existing business customers in accordance with Swiss law (in particular Article 3(1)(o) UCA) and applicable GDPR provisions on legitimate interest, You may object to such communications at any time by the same means.
Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage, including: encryption of data in transit (TLS) and at rest, role-based access controls, multi-factor authentication for administrative access, network segregation, logging and monitoring, regular backups, hardened cloud-infrastructure configurations, vendor security assessments, employee confidentiality undertakings, and incident response procedures.
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority and, where required, affected individuals, within the timeframes set out in applicable law.
Automated Decision-Making
The Certification assessment carried out by ICL is based on rule-based evaluation of the ingredients declared in a Formulation. While certain steps may be automated, the issuance of a Certification does not produce legal effects concerning a natural person, nor does it significantly affect a natural person in a manner comparable to such effects within the meaning of Article 22 GDPR or Article 21 FADP.
We do not otherwise take decisions based solely on automated processing that produce legal or similarly significant effects in respect of individuals. Where this changes, we will update this Privacy Policy and, where required, request Your explicit consent or implement other appropriate safeguards.
Children
The Website and the Services are directed at businesses and at adult professionals; they are not intended for, and are not directed to, children. We do not knowingly collect personal data from children under the age of 16. If You believe that we have collected personal data of a child without appropriate consent, please contact us so that we can delete the data.
Third-Party Websites & Social Media
The Website may contain links to third-party websites (including LinkedIn, Instagram, and TikTok). This Privacy Policy applies only to ICL’s own processing of personal data; we are not responsible for the privacy practices of third-party websites. We encourage You to read the privacy notices of any third-party website You visit.
Changes to this Privacy Policy
We may revise this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The “Last Updated” date at the top of this Privacy Policy indicates when it was last revised. Material changes will be communicated to active Brands and account holders by email or via a notice on the Website with reasonable advance notice where practicable. Your continued use of the Website or the Services after the effective date of any revised Privacy Policy constitutes Your acceptance of the changes.
Contact
If You have any questions, comments, or requests regarding this Privacy Policy or the processing of Your personal data, please contact us:
Skin Match Technology Switzerland AG
Ingredient Clarity Lab — c/o Estella Benz
Mutschellenstrasse 197, 8038 Zurich, Switzerland
Email:
By using the Website or the Services, You acknowledge that You have read and understood this Privacy Policy.