Legal

Privacy policy

How your personal data is handled on the website and in your account, covered by one policy because the two are one system

Last updated 30 August 2026

Still being settled

2 sections below describe arrangements we have not finished settling. They are named here rather than left for you to discover.

This Policy covers the Halderstone website and everything you can do in your Halderstone account: courses, digital products, and events. It also covers the personal data that reaches us through our mandate work. It describes the target state of all of it.

1. About this policy

1.1 What this policy covers

This Privacy Policy explains how we process personal data when you use the Halderstone website and the signed-in area of your Halderstone account, where we deliver courses, digital products such as tools and templates, and events such as webinars. We call that signed-in area "the platform" throughout this Policy. Website and platform are operated by the same company and are covered by this single Policy. We also work under mandate, and we process personal data outside the website and the platform when we do. Section 5.2 covers that part, and the rest of this Policy applies to it as well.

Langer & Co is a Swiss company. Our processing is governed by the Swiss Federal Act on Data Protection (FADP), and it is supervised by the Federal Data Protection and Information Commissioner (FDPIC). Because we also address participants in the European Economic Area, the EU General Data Protection Regulation (GDPR) applies to them in addition. Section 9.1 sets out both frameworks in one place, so that the rest of this Policy can say plainly what we do rather than argue law at every turn.

1.2 Who is responsible

The entity responsible for the processing described here is:

Langer & Co
Zürcherstrasse 2
8852 Altendorf
Switzerland

Email: privacy@halderstone.com

1.3 Why we process personal data

We process personal data in order to:

  • provide and secure this website and the platform
  • deliver the courses, digital products, events and services you or your employer have bought
  • respond to enquiries and support requests
  • analyse usage and improve our content, where you have consented
  • identify technical errors, performance issues and abuse
  • meet our legal and accounting obligations

1.4 How this policy changes

We may revise this Policy as our services change. The version published here is the one that applies, and the date it carries is the date of that version. We recommend reviewing this page from time to time.

2. When you use our pages

2.1 Server logs

When you access this website or the platform, technical information is automatically recorded. This information may include:

  • IP address
  • date and time of access
  • browser type and version
  • operating system
  • pages requested and referrer URL
  • status code of the request

We use these logs to provide the service reliably, to diagnose errors and to protect against attacks and abuse. Our systems run on Amazon Web Services in the European Union (Frankfurt), which processes this data on our behalf. Log data is retained for a limited period, currently 90 days, and is then deleted automatically.

We do not use server logs for advertising or profiling, we do not combine them with data from third parties, and we do not use them to build a picture of individual visitors. Error diagnostics may incidentally contain an email address where it is part of the operation that failed. When you submit a form, we also hold the IP address of the submission briefly in order to limit the rate of submissions and block automated abuse; it is not stored with your message.

Server logs are technical records. Actions inside the platform that need to be accountable, such as a sign-in, an order, or a change to an assessment, are recorded separately and deliberately; see section 7.1.

2.2 Cookies and similar technologies

Our privacy controls sort these technologies into categories, and this section uses the same category names, so that the setting you see and what you read here are the same thing.

Essential. The cookies that carry the functions you asked for: keeping you signed in, completing a one-time sign-in code, and returning you to the page you came from, together with our consent setting, which has to store your choice in order to honour it. They carry no advertising identifier, nobody else reads them, and the service cannot be provided without them, so they are set without consent and cannot be switched off.

The essential cookies used by the current functions are:

  • hs_session, which holds a signed-in session for up to twelve hours
  • hs_cog_access, which supports passkey settings for up to one hour and is available only under the settings path
  • hs_otp, hs_otp_session, hs_email_draft and hs_return_to, which carry a sign-in or email-change step for up to ten minutes
  • hs_consent, which holds the signed current privacy choice and random receipt ID for up to twelve months
  • hs_privacy_notice, which remembers for up to twelve months that a visitor in a notice-and-opt-out country has dismissed the short notice; it contains only the current geography-ruleset version

Statistics. Google Tag Manager and Google Analytics 4, which measure how our public pages are used (section 2.4). In countries where prior permission is required, this category stays off until you allow it. In the United States and Australia it is on unless you switch it off or your browser sends Global Privacy Control. An absent, invalid or untrusted country signal always receives the stricter prior-permission setting. Statistics exist only on the public pages: in the signed-in area we set essential cookies and nothing else.

We run no marketing or advertising category. We do not use cookies to build an advertising profile of you, and we pass no cookie data to advertising networks.

Type faces are served from our own servers rather than fetched from a font provider, so simply displaying a page requests nothing from a third party and reveals your address to nobody.

You manage your choice through the privacy settings on this website (see section 2.3), and you can delete or block cookies in your browser at any time.

We use privacy settings built into this website to obtain and document consent where it is required, and to provide an objection wherever statistics are available without prior consent. The country rules are a versioned allow-list: version 1 permits the notice-and-opt-out setting only for the United States and Australia. The country supplied by our delivery edge is used to choose the setting; we do not add it to the consent record or either privacy cookie. Every other case fails closed to prior permission.

When you actively make or change a choice, we record only:

  • which consent-model version and categories you accepted or rejected
  • the date and time of the choice
  • a random consent ID and, where applicable, the random ID of the choice it replaced

We do not add your IP address, country, browser, device information, account or identity to that record. A signed essential cookie holds the current choice and its random ID; the corresponding server record provides the evidence. Both expire after twelve months. Merely receiving or dismissing the short notice creates no consent record. The separate notice cookie contains only the geography-ruleset version and also expires after twelve months. A changed consent model or geography ruleset causes the relevant choice or notice to be shown again.

This processing is necessary to honour and, where required, demonstrate your choice. You can change the setting at any time through the privacy settings in the footer. Where we rely on consent, this is how you withdraw it; where statistics are initially on, this is how you object. We also honour Global Privacy Control by keeping statistics off while the signal is present.

2.4 Google Tag Manager and Google Analytics 4

We use Google Tag Manager to administer the Google Analytics tag. Tag Manager may process standard HTTP request logs, which Google says it deletes within 14 days, and aggregated diagnostics about tag firing.

We use Google Analytics 4 to understand how visitors use our public pages. It does not run in the signed-in area. Once you have signed in, nothing measures what you read, how long you take over a section or when you work: we do not analyse your learning behaviour, and there is nothing to consent to there.

On the public pages, Google Analytics may process information such as:

  • pages visited and time spent on pages
  • clicks and interactions
  • device and browser information
  • approximate location derived from a shortened IP address

Google Analytics 4 does not store full IP addresses; they are shortened before storage. Google may process data on servers in the European Union and in other countries.

The _ga browser identifiers are configured to expire no later than twelve months after they are first created; their expiry is not extended on each visit. Our GA4 property's user-level and event-level retention is fourteen months, with reset on new activity switched off. This setting does not remove data from Google's standard aggregated reports on the same timetable.

Google Analytics is activated according to the privacy setting described in sections 2.2 and 2.3, and it is switched off when you turn statistics off or send Global Privacy Control. The privacy settings link to Google's Privacy Policy and Google's explanation of how it uses information from sites that use its services.

Our pages may link to external platforms such as LinkedIn or YouTube. These are ordinary links. They load nothing from those platforms, embed no player or plug-in, and transmit nothing about you until you click them. If you do, you leave our site and the external platform processes your data under its own privacy policy, over which we have no control.

3. Your account and what it holds

3.1 Your account and sign-in

You need an account to take a course, to open a digital product you have bought, to join an event, and to reach anything else we deliver to you. We process your email address, the display name you choose, the passkeys you register (their credential identifier, the name you give them and when they were created), and the one-time codes we email you.

Sign-in is passwordless. You never set a password with us, and we never ask you for one: you sign in either with a one-time code sent to your address or with a passkey held by your device. A passkey never leaves your device; we only hold the public part needed to verify it.

3.2 What your account holds

Your account records what you are entitled to and what you have done with it, so that we can deliver it and so that both sides can rely on the record.

Courses. Which modules you have access to, which sections you have completed and when, your position in a track, and the order and seat your access came from. Trainers of a course can see the progress of the participants in it. When you complete a course we issue a confirmation or a certificate in your name, it stays available in your account, and it can be checked by whoever you show it to (section 4.2).

Digital products. Which tools, templates and other downloads your account holds, when access was granted, and when a download was issued. We keep this because it is the proof that you own what you bought, and because a licence that cannot be evidenced is not much of a licence.

Events. Your registration for an event such as a webinar, the ticket or seat it came from, and whether you attended. Questions and comments you contribute during an event are visible to the host and, depending on the format, to other attendees.

3.3 When someone buys something for you

Organisations can buy course seats, digital products and event places for their people. In that case we receive the buyer's contact details and the email address of each person the purchase is intended for, from the buyer rather than from you, and we use that address to invite you and to give you access. The categories of data are those described in sections 3.1 and 3.2.

Because you did not give us the address yourself, we tell you about this processing when we first write to you. If you receive such an invitation and do not want an account, tell us and we will remove the invitation and the address.

4. Learning with us

4.1 Exercises, submissions and assessment

The platform records your answers to exercises, your written submissions, your workbook entries and the points and feedback they receive.

Written submissions may be assessed with the help of an artificial intelligence model to produce a provisional result against the published rubric. That result is never final: a trainer reviews it and can change it, and the trainer's decision is the one that counts. No decision about you is taken by a machine alone, and you can always ask for the reasoning behind a result and have a person look at it again.

The assessment happens inside our own environment at our infrastructure provider, and your text stays there. It is sent to a model hosted by that provider in the European Union over a private network connection, never across the public internet, and it may be processed in another of the provider's European locations when capacity requires it, but it does not leave Europe. The company that developed the model never receives your text. It is not used to train or improve any model, and our infrastructure provider retains it for no purpose of its own.

4.2 Certificates and the public verification register

A certificate is worth what a third party can check. A PDF can be edited by anyone, so we do not treat the document as the proof. We keep a register of every certificate we issue, and the document points at that register.

When you have completed a course and download your certificate for the first time, we create one register entry for it. It holds a random identifier that cannot be guessed, your name, the type of the document, the module, the dates, and the topics the module covered at the time you completed it. Results, scores and grades are never part of it. Your certificate carries that identifier as text and as a QR code, together with the address of its verification page. The document itself is not stored anywhere: it is rendered from the register entry each time you download it, which is also why a later correction to our layout or a new language reaches your old certificate.

Anyone holding the identifier can open the verification page without signing in and see those same facts. There is no way to search the register by name, no list of holders, and no way to arrive at an entry without being given its identifier. You decide who can verify your certificate by deciding who receives the document. If we ever have to invalidate a certificate, the verification page says so.

If you erase your account, the register entry stays, detached from the deleted account. We keep it because the certificate is a statement you have already handed to other people, and because a register with gaps proves nothing: if entries could quietly disappear, an employer checking a genuine document would see the same answer as one checking a forgery, and every other certificate would be worth less for it.

You can still ask us to end the verification of your certificate. We will do it, and we will tell you first what it costs you: documents you have already given out can no longer be confirmed. The verification page then shows a short neutral notice in place of the entry, saying that the verification was ended at the holder's request and that we did not invalidate the certificate. Your name, the module and the dates are gone from it. We keep that distinction deliberately, so that exercising a right never makes your certificate read like a failed or withdrawn one.

The one case we do not allow is using this to hide a revocation. If we have invalidated a certificate, the verification page keeps saying so.

We keep register entries for ten years from issuance, which is roughly how long a training certificate is still asked about, and then delete them. The name in an entry is the one you held when it was issued. If your name changes, that is a correction and not an erasure: tell us and we will correct the entry and re-issue the document.

4.3 Introductions and how your name appears to others

Learning together works better when participants know who else is in the room, so the platform offers short self-introductions. What you write in one is shown to your trainer, and to the other participants of that course if you choose to share it with them.

We use one real name for a person, and no pseudonyms. Your trainer always sees your real name. Other participants see it by default, and you can switch that off in your settings, in which case your contributions appear as an anonymous participant to them. You can withdraw an introduction at any time.

If an introduction is reported by another participant or found to be inappropriate, a trainer can hide it. We record who hid what and when so that the decision is accountable. A report by a participant never hides anything by itself.

4.4 Your feedback on our content is anonymous

When you rate or comment on our content, for example a course section or an event, we deliberately do not record who you are. No account identifier is stored with your response, only a coarse day-level date and a technical marker that prevents the same question being answered twice. We cannot trace feedback back to you, and neither can your trainer.

Because these responses carry no identifying data, they are not personal data once submitted, and requests to access or delete individual feedback cannot be answered: there is nothing to link them to.

5. Buying from us, and working with us

5.1 Payments

Payments for courses, digital products, events and services may be processed through Stripe.

When you proceed to payment you are taken to a payment page operated by Stripe. Billing information, transaction details, payment method data, IP address and device information are processed there directly by Stripe for payment processing, fraud prevention and regulatory compliance. Stripe processes data in the United States as well as in Europe.

We receive the outcome of the payment and the details we need to issue your access and our invoice, such as the buyer's name and email address, the item purchased and the amount. No card details ever reach our systems. Stripe's own receipts and records, and any invoices we issue manually, are accounting records kept independently of the platform.

Further information is available in Stripe's Privacy Policy.

5.2 Business clients and professional services

Besides the website and the platform, we work under mandate: advisory work, audits, and larger training programmes commissioned by an employer. Offers and invoices for that work are written by hand, outside the platform. This section covers the personal data that reaches us that way. Everything the rest of this Policy says about our providers, our security, the law, your rights and how long we keep things applies to it as well.

The people we deal with at a client. To conclude and administer a mandate we process the name, role, business contact details and correspondence of the people who commission it, sign for it, and receive the invoices. We keep the offers and the invoices themselves because Swiss accounting law requires it.

Personal data inside the material we are given. Performing a mandate means reading what a client hands us: documents, records, systems, and what people tell us in interviews. That material contains personal data about people we have no relationship with, usually the client's own employees. Where it does, we are the controller of it. We decide what we collect, what we write down and how long we keep it, because an audit finding or an advisory opinion has to be substantiated by what it rested on. A client cannot instruct us to delete that evidence, and we do not process it on a client's instructions.

If you are one of those people. You did not choose us, and you may not have been told we were coming. We ask our clients to inform the people concerned, and our terms of business oblige them to. Either way you can come to us directly: the rights in section 9.2 are yours and you do not need your employer's permission to use them. Where we have to withhold something, it is because releasing it would expose another person's data or the confidentiality we owe the client, and we say which of the two it is.

6. Talking to us

6.1 Contact, support and enquiry requests

When you contact us through a form on this website or the platform, we process the data you provide, such as your name, email address and the content of your message, in order to respond. If you are signed in, we take your email address from your account rather than from the form, so that a reply reaches the person we already know. We also record which page the request was sent from, so that the request has context, and we apply automated spam protection to the submission.

A request you send from the Help and support page in your account is recorded on the platform, together with our replies and anything you add to it later. We keep that record so that the request can be handled, so that you can see what you asked and where it stands, and so that a colleague can take it over. We also send you a copy of your request and of every reply by email, and the request itself reaches our support mailbox by email. A request sent from a form on the public website reaches us by email only.

Who inside Halderstone can read a request depends on what it is about. A question about course material can be read by the trainers as well as by administrators, because it is theirs to answer. Everything else, such as access, orders and session logistics, can be read by administrators only.

We do not pass requests to any third party other than the infrastructure providers that operate our systems and deliver our email (section 8.1). We keep them for as long as we need them to handle your request and any follow-up, within the period in section 8.2. If you close your account, the requests you sent are deleted with it; a reply one of our people wrote to somebody else stays, without naming its author.

6.2 Emails we send you

We send you the emails that delivery requires: one-time sign-in codes, order confirmations, notices that access or a download is ready, reminders about work that is due, joining details and reminders for an event you registered for, and replies to your requests.

We also send calendar invitations for calls you book with us, for the sessions of a course you are enrolled in and for events you registered for, so that the dates land in your own calendar. An invitation carries the appointment's time and title. Joining details are included when available or sent separately; accepting or declining the invitation happens in your calendar, not with us. When you finish a course, we send you your confirmation or certificate, which carries your name, what you completed and when.

6.3 Calls booked through the website

When you book a call, we store your name and email address, the selected time, any organisation and preparation notes you provide, and the page from which you booked. We use these details to reserve the time, send the invitation, and let you reschedule or cancel through the private link in the confirmation email. The booking record blocks that time immediately, whether or not either recipient has accepted the calendar invitation.

The picker checks only whether the calendars used for scheduling are free or busy. Event titles, attendees, locations and descriptions are not copied into this website. If live availability is unavailable, the dialog says so and sends your chosen time as a request rather than claiming it is booked.

These are service messages, not marketing. We do not send advertising emails, and we do not track whether you opened a message or clicked a link in it.

7. Running the service securely

7.1 Sign-in log and audit trail

We record when an account signs in, and we record consequential actions in an audit trail: for example the creation of an order, the claiming of a seat or a licence, a trainer changing an assessment result, the hiding of an introduction, or the erasure of an account. Each entry states who acted, what they did, on what, and when.

This exists so that the platform stays secure, so that a disputed result can be reconstructed, and so that customers in regulated industries can rely on the training records we produce for them.

7.2 Data security

Sign-in is passwordless and, with passkeys, resistant to phishing. Personal data is held in the European Union. Traffic to and from our services is encrypted in transit, data is encrypted at rest, connections between our application and our identity and email services stay inside a private network, credentials are held in a managed secrets store, and consequential actions leave an audit trail (section 7.1).

We use selected service providers as processors acting on our instructions and subject to appropriate data protection safeguards (section 8.1).

8. Who receives your data, and for how long

8.1 Service providers and where your data is processed

We host and operate our systems on Amazon Web Services in the European Union (Frankfurt). AWS acts as our processor under a data processing agreement including the EU Standard Contractual Clauses, and processes personal data only on our instructions.

Besides AWS, personal data reaches only the providers named in this Policy for the purpose described there: Stripe for payments (section 5.1), and Google for analytics where the privacy setting permits it (section 2.4) and for the free/busy calendar check used when you book a call (section 6.3).

Some of these providers are established in, or transfer data to, other countries. We disclose personal data abroad only where Swiss law permits it: to a country the Federal Council has listed as providing adequate protection, or under standard contractual clauses recognised by the FDPIC, or under the Swiss-US Data Privacy Framework where the recipient is certified. Where the same transfer is also subject to the GDPR, the corresponding EU mechanism applies alongside.

We do not sell personal data, and we do not share it with third parties for their own purposes.

8.2 How long we keep personal data, and account erasure

We keep personal data only for as long as it is needed for the purposes described here, or for as long as the law requires.

  • Server logs: currently 90 days (section 2.1).
  • Call bookings: twelve months after the call or its cancellation.
  • Consent records: twelve months after the choice.
  • Google Analytics browser identifiers: no later than twelve months after first creation. GA4 user-level and event-level data: fourteen months without reset on new activity; standard aggregated reports are not governed by that retention control (section 2.4).
  • Your account and your access to what you bought: for as long as we provide you that access. Where the access you bought does not expire, neither does the account that carries it, so we keep it until you ask us to erase it or the dormancy rule below applies.
  • Dormant accounts: if you have not signed in for five years, we write and ask whether you still want the account. If we hear nothing within 90 days, we erase it, in the way described further below. This is how an account that outlives its owner's interest in it does not simply sit here forever.
  • Your own work: the answers, written submissions and workbook entries you produced. Kept while you still have access to the module they belong to, so that returning to a course means returning to your own material, and deleted three years after that access ends.
  • Assessment results: the score, the pass or fail, and the trainer's review that produced it. Ten years, so that the training we attested can still be evidenced.
  • Records of what you bought and what you were given access to, including digital product licences and event registrations: for as long as the entitlement lives, and in any case at least ten years from the purchase.
  • Enquiries and support requests: twelve months after the matter is closed.
  • Accounting records including payment records: ten years, the retention period Swiss commercial law requires.
  • The sign-in log: twelve months. What a sign-in tells us about the security of the service is spent long before that.
  • Audit trail entries about consequential actions, such as an order, a claimed seat, an overridden assessment or an erasure: ten years, the same horizon as the records they explain.
  • Anonymous course feedback: kept indefinitely, since it contains no personal data.
  • Certificate register entries: ten years from issuance, whether or not the account behind them still exists (section 4.2).
  • Mandate records (section 5.2): the offers, invoices and correspondence for ten years, the same period commercial law sets for the accounts. The working papers of an advisory or audit mandate, including the personal data in them, for ten years after the mandate ends, because that is how long we may have to show what our conclusions rested on.

When an account is erased, we delete the sign-in identity including any passkeys, and the account's roles, enrolments, progress, submissions, workbook state, reminders, introductions, event registrations and sign-in history. Records that exist for an independent reason are kept without the erased person's identity attached: an order remains as evidence of what was delivered, with the buyer's address removed; a seat or licence that was used remains used, with the claimant detached; a trainer's assessment of someone else, and a report made about someone else, remain with the author detached; audit entries remain, with email addresses removed, so that the record of what happened survives without naming the person who asked to be forgotten. Anonymous feedback is untouched, because it was never linked to anyone.

Certificates are the one case where erasure and the interest of a third party pull against each other, because an employer may hold a document whose verification depends on a register entry. Those entries therefore survive the erasure of the account, detached from it, and you can ask separately for the verification to be ended. Section 4.2 sets out both.

Erasing an account also ends access to everything that account holds, including digital products you bought and the confirmations and certificates available for download. Keep your own copy of anything you want to retain before you ask us to erase the account.

9. Your rights and the law

Swiss law governs what we do. The FADP binds everything described above: processing must be lawful, in good faith, proportionate, recognisable to you and confined to the purpose stated when the data was collected (Art. 6 FADP). It must be protected by appropriate technical and organisational measures (Art. 8). Service providers may process data on our behalf only under contract, and only as far as we could process it ourselves (Art. 9). We keep a record of our processing activities (Art. 12). Data may be disclosed abroad only under the conditions of Art. 16, which is what section 8.1 describes. This Policy is the information we owe you when we collect your data (Art. 19). Where a decision about a person would be taken by automated means alone, Art. 21 gives that person the right to be informed and to have a human review it; section 4.1 is built so that the question does not arise. Your rights of access, data portability and correction or deletion follow from Art. 25, Art. 28 and Art. 32.

Swiss law does not require a private company to declare a legal basis for every ordinary processing operation. It requires the processing to respect the principles above, and that where it would infringe your personality it be justified by your consent, by an overriding private or public interest, or by law (Art. 30 and Art. 31 FADP).

EU law applies in addition where it reaches you. For participants in the European Economic Area the GDPR also applies, and it does ask for a basis per purpose. For the processing described here these are:

  • your account, the delivery of courses, digital products and events, assessment, service emails and payments: performance of our contract with you, or with the organisation that bought on your behalf, Art. 6(1)(b);
  • server logs, the sign-in log and audit trail, and the spam protection on our forms: our legitimate interest in a secure and accountable service, Art. 6(1)(f);
  • analytics and its choice record: your consent where prior permission is required, Art. 6(1)(a); in the versioned notice-and-opt-out allow-list, our legitimate interest in improving the public site, Art. 6(1)(f), subject to the immediate objection and Global Privacy Control described in section 2.3;
  • what you choose to share about yourself with other participants: your consent, Art. 6(1)(a);
  • accounting and tax records: our legal obligations, Art. 6(1)(c).

Where we rely on a legitimate interest you may object, and where we rely on consent you may withdraw it at any time.

9.2 Your rights

You may ask what personal data we hold about you and receive a copy, have inaccurate data corrected, ask for data to be deleted, ask us to stop a particular processing, and receive the data you gave us in a common electronic format. Where we rely on your consent, you can withdraw it at any time with effect for the future; withdrawing it does not make what happened before unlawful.

To exercise any of these, write to us as described in section 9.3. We may need to establish that the request really comes from you before we act on it.

If you are not satisfied with how we handle your data, you can report the matter to the Federal Data Protection and Information Commissioner (FDPIC) in Bern, the authority that supervises us. Participants in the EEA may instead approach the supervisory authority of their country of residence or workplace.

9.3 Contact

For any question about this Policy or about how we handle personal data, write to privacy@halderstone.com, or use the postal address in section 1.2.