Privacy Policy
Last updated July 8, 2026
This Privacy Policy explains what personal data we collect through the GSED website (gsed.ch), what we use it for, who we share it with, and the rights you have. GSED (Global Secondary Education) is an international education program operated jointly by Swiss Innovators Club and Feydey LLC.
Swiss Innovators Club is a Swiss-registered non-profit educational association (CHE-278.360.520), Route de la Cretasse 1, office 5, 1854 Leysin, Switzerland. Feydey LLC is a US company (California) that operates the FEYDEY school and the FEYDEY-Grade Results learning platform. Together they act as joint controllers of the personal data described here.
We process personal data in line with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP). Because the FEYDEY school and diploma are US-based, we also observe the applicable US student-privacy laws (FERPA, COPPA and SOPIPA). Our core principles are simple:
- we do not collect more information than we need;
- we do not use your data for purposes other than those described here;
- we do not keep your data once it is no longer needed;
- we do not sell your data, and we share it only with the service providers and in the situations described below;
- we secure the data we hold and give you clear ways to access, correct or delete it.
If you have any questions about this policy or how we handle your data, contact us at support@feydey.com.
Who is responsible for your data
The joint controllers responsible for deciding what personal data is collected and how it is used are Swiss Innovators Club (Switzerland) and Feydey LLC (USA). Swiss Innovators Club handles registration and settlements; Feydey LLC provides the school enrollment, the learning platform and the final documents. For any data-protection request you can reach both through a single point of contact: support@feydey.com.
In respect of payment card data we act only as a facilitator: card details are collected and processed directly by our payment provider (Stripe) and are never stored on our systems.
Whose data we hold
We hold personal data about the following groups of people (data subjects):
Students (children and their parents/guardians), people who submit our callback or registration forms, partner-school contacts, and applicants and staff.
What personal data we collect
Depending on how you interact with us, we may collect:
- Parent/guardian details you enter when registering: first and last name, email address and phone number.
- Student details: each child's first and last name, their grade, and (optionally) a Latin-script spelling of the name.
- Current-schooling details: whether the child studies at a school, is homeschooled or is not currently enrolled; the name of the current school (if given); and your family's country and city.
- A partner-school code, if you enter one, so the correct pricing can be applied.
- Payment and transaction data: the plan, amount and payment status for your enrollment. Card numbers themselves are handled by Stripe, not by us.
- Consent records: that you accepted the Public Offer and this Privacy Policy at registration.
- Your language preference (Russian or English).
- Technical and usage data collected automatically when you browse the site — see "Website analytics and campaign attribution" below.
We collect student information about children under 13 only from their parent or guardian, at the point of enrollment; we do not knowingly collect it directly from the child through this website.
How we collect it
Browsing the website
You can visit gsed.ch without telling us who you are. While you browse, we collect only limited, mostly anonymous technical data (such as your browser language and device type) as described under "Website analytics and campaign attribution".
Registration and callback forms
When you submit our callback or registration form, you provide the details listed above. We use them to contact you, prepare your enrollment and give you access to the program. We also run a bot-protection check (Cloudflare Turnstile) on form submissions to keep the site secure.
Payment
When you pay for enrollment, you enter your card details on a secure page hosted by our payment provider (Stripe). We receive confirmation of the payment and its status, but not your full card number.
Other sources
You may also give us personal data by corresponding with us by email, phone or messaging, or when a partner school refers a family to the program.
Special categories of personal data
We do not ask for special categories of personal data (such as data about race or ethnicity, health, religious or philosophical beliefs, or biometric data). Please do not send us such data unless it is strictly necessary and we have asked for it.
Website analytics and campaign attribution
We run a first-party analytics system on our own infrastructure to understand how our website is used. It records anonymous page-view statistics only: the page you visited, the domain of the site that referred you, any campaign tag in the link you followed, your browser's language, your device type, and an approximate location (country and city) inferred from your connection. This system does not use cookies, and we do not store your IP address — the approximate location is derived at the network edge and only the resulting country and city are kept — nor do we share this data with any third-party analytics provider. A random identifier is held in your browser for the length of a single visit, so we can tell which page views belong together, and it is discarded automatically as soon as you close the tab.
The first time you visit, we also record which campaign or link brought you here, for instance a campaign tag in the URL, the site that referred you, and the page you landed on, and keep it in your browser for future reference. If you go on to submit our callback or registration form, this record travels with your enquiry so we know which channel it came from. On its own it does not identify you, and you can remove it at any time by clearing your browser's site data.
The individual page-view records described above are deleted within around 35 days. After that, only aggregated daily statistics, with no detail about any single visit, are kept for the longer term.
For emails we send you, such as payment links or receipts, our email delivery provider reports back whether the message was delivered, bounced, or marked as spam. We keep this delivery status linked to the message so we can keep our mailings reliable; the content of the email itself is not part of this record.
How we use your data and our lawful bases
We use your personal data to:
- register a student, prepare enrollment and deliver the educational services — lawful basis: performance of a contract (or steps taken at your request before entering into one);
- process payments and keep financial and accounting records — lawful basis: performance of a contract and our legal obligations;
- contact you about your enquiry, your enrollment and important changes to the service — lawful basis: performance of a contract and our legitimate interests;
- keep the website secure, prevent abuse and understand how the site is used — lawful basis: our legitimate interests;
- send you informational or promotional messages about the program — lawful basis: your consent, which you can withdraw at any time.
Where we rely on legitimate interests, we have considered that the processing is what you would reasonably expect, is limited to what is necessary, and does not override your rights and freedoms.
Cookies
We keep cookies to a minimum and do not use advertising or third-party analytics cookies. The cookies and similar storage we do use are functional only:
- a cookie that remembers your language choice (Russian or English);
- a cookie set by our bot-protection provider (Cloudflare Turnstile) on form pages to tell humans from bots;
- cookies set by Stripe on the payment page to process your payment securely.
Our own analytics do not use cookies (see "Website analytics and campaign attribution" above). You can block or delete cookies in your browser settings, though some parts of the site may then not work as intended.
Who we share data with
We do not sell your personal data. We share it only with the service providers that help us run the program, and only as far as they need it to provide their service to us. These processors are:
- Supabase — our database and authentication (data hosted in the EU);
- Vercel — website hosting and content delivery;
- Stripe — payment processing;
- Resend — sending transactional emails (such as payment links and receipts);
- Upstash — rate-limiting to protect our forms (processes your IP address transiently);
- Cloudflare — bot-protection (Turnstile) on our forms.
We may also disclose personal data where we are legally required to (to comply with a law, regulation or valid governmental request), to detect or prevent fraud or security issues, or in anonymized, aggregated form that cannot identify you. Between the joint controllers, we share the personal (identity and contact) data needed to deliver the program jointly.
International data transfers
Some of our providers are located outside Switzerland and the European Economic Area, in particular in the United States (Feydey LLC, Stripe and Resend). Where we transfer personal data internationally, we rely on appropriate safeguards recognized under the GDPR and the Swiss nFADP — such as the European Commission's Standard Contractual Clauses and, where applicable, adequacy decisions — so that your data continues to be protected. You can contact us at support@feydey.com for more information about these safeguards.
Children's privacy
Our program serves school-age children, and their data is provided by a parent or guardian. In line with the US Children's Online Privacy Protection Act (COPPA), we collect personal information about children under 13 only from their parent or guardian, at enrollment. In line with FERPA and California's SOPIPA, student data is used only for educational purposes — never for advertising — and is not shared for non-educational purposes.
The only information we may receive directly from a student is what they enter on the learning platform as part of their studies (such as test answers and class discussions); that is handled as part of delivering their education.
How we keep your data secure
We take appropriate technical and organizational measures to protect personal data against loss, misuse or unauthorized access. Connections to our site and platform are encrypted, access to personal data is limited to staff who need it for their role, and our providers are chosen for their security standards. Staff who handle personal data are bound to keep it confidential.
No method of transmission or storage is completely secure, but we work to protect your data in line with recognized industry practice.
Your rights
Under the GDPR and the Swiss nFADP you have the following rights in respect of your personal data, which you can exercise against the controller:
- a. Right to be informed: to be told what personal data we collect and store about you and how it is used.
- b. Right of access: to request a copy of the personal data we hold, together with confirmation of the purposes of the processing, the categories of data concerned, the recipients it has been or will be disclosed to, how long it will be stored, and — where the data was not collected directly from you — information about its source.
- c. Right of rectification: to have inaccurate or incomplete personal data corrected.
- d. Right to erasure and restriction: in certain circumstances, to have your personal data erased, or to have its processing restricted (for example while a correction is being reviewed).
- e. Right of portability: to have the personal data you provided transferred to another organization, where it was provided in a structured, commonly used, machine-readable format.
- f. Right to object to direct marketing: to object where processing is carried out for direct-marketing purposes.
- g. Right to object to automated processing: not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects on you.
- h. Right to withdraw consent: where we rely on your consent, to withdraw it at any time.
To exercise any of these rights, contact us at support@feydey.com. We may need to verify your identity before acting on a request, to protect your data.
Accessing, correcting or deleting your data
Providing personal data is optional, but without it you will not be able to register or make a payment. If you have an account on the learning platform, you can access the data associated with it there. Otherwise, contact us at support@feydey.com to request a copy, a correction, or deletion of your data.
Every marketing email we send includes an unsubscribe link, and you can also ask us to stop contacting you at any time. Where a transaction has taken place, we may retain the related records for as long as required for accounting, legal or safeguarding reasons.
How long we keep your data
We keep personal data only for as long as necessary for the purposes described in this policy — for the duration of the enrollment and study, and thereafter for as long as we are required to keep it to meet our legal, accounting and safeguarding obligations. Website page-view records are deleted within around 35 days, after which only aggregated statistics are kept (see "Website analytics and campaign attribution"). When data is no longer needed, we delete or anonymize it.
Complaints
If you have any questions or concerns about how we use your personal data, please contact us first at support@feydey.com so we can help. You also have the right to lodge a complaint with a data-protection supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU/EEA, the authority in your country of residence.
What the defined terms mean
Where this policy uses the following terms, they have these meanings:
- Controller — the party responsible for deciding what personal data to collect and how to use it (a term defined in the GDPR).
- Processor — the party that processes personal data on behalf of, and on the instructions of, the controller (a term defined in the GDPR).
- Data Subject — the individual who can be identified from the personal data.
- Personal Data — data that can be used to identify a living individual, whether on its own or when combined with other details.
- Special Categories of Personal Data — details about an individual's race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade-union membership, health, or genetic and biometric data.
Changes to this policy
We may update this Privacy Policy from time to time. The current version is always published on this page, and the "last updated" date at the top shows when it last changed. For material changes we will take reasonable steps to let registered users know.
