About Me

Last updated: 22 April 2026

Privacy Policy

Prep & Rehab GmbH (“we”, “us”, “our”) operates the website prep-rehab.ch. This Privacy Policy explains what personal data we collect when you visit our Site or use our services, how we use it, and what rights you have.

1. Data Controller

The controller responsible for the processing of your personal data is:

Prep & Rehab GmbH
Zurich, Switzerland
Email: info@prep-rehab.ch

2. Data We Collect

2.1 Contact Form

When you submit the contact form, we collect:

  • Full name
  • Email address
  • Phone number (optional)
  • Inquiry type (client, company, or other)
  • Message content

2.2 Appointment Booking Form

When you request an appointment, we collect:

  • Full name
  • Email address
  • Phone number (optional)
  • Service type (orthopedic rehabilitation, pelvic floor training, or geriatric therapy)
  • Preferred date and time
  • Additional notes about your condition or preferences (optional)
Note on health-related dataThe service type you select may constitute health-related data. We handle this information with the utmost discretion and use it solely to prepare and deliver your physiotherapy appointment. See Section 6 for details.

2.3 Technical Data (Automatically Collected)

When you visit our Site, the following data is automatically recorded:

  • Language preference — stored in a browser cookie and local storage
  • Standard server logs (IP address, browser type, pages visited) — retained by our hosting and database provider as part of normal infrastructure operation

3. How We Use Your Data

PurposeLegal Basis
Responding to contact inquiriesLegitimate interest / Pre-contractual measures (Art. 6(1)(b) GDPR; Art. 31 nDSG)
Confirming and preparing appointmentsPerformance of a contract / Pre-contractual measures (Art. 6(1)(b) GDPR)
Processing health-related service selectionExplicit consent / Necessary for healthcare provision (Art. 9(2)(a)(h) GDPR)
Storing language preferenceLegitimate interest — technical functionality (Art. 6(1)(f) GDPR)
Improving our SiteLegitimate interest (Art. 6(1)(f) GDPR)

4. Data Storage & Processors

Your data is stored securely in our database provided by Supabase (Supabase Inc., San Francisco, CA, USA). Supabase offers GDPR-compliant data processing and stores data on servers within the European Union. For details, see the Supabase Privacy Policy.

Our Site also makes requests to the following third-party services:

  • Google Fonts (Google LLC, Mountain View, CA, USA) — to load the typefaces used on this Site. Your IP address is transmitted to Google in the process. See the Google Privacy Policy.
  • Netlify (Netlify, Inc., San Francisco, CA, USA) — for serving our logo image. Your IP address is transmitted to Netlify in the process. See the Netlify Privacy Policy.

We do not use web analytics, advertising networks, social media tracking pixels, or payment processors.

5. Cookies & Local Storage

We use the following minimal set of cookies and browser storage. We do not use advertising, tracking, or analytics cookies.

NameTypePurposeDuration
languageCookieStores your language preference (de / en / it / fr)12 months
languagelocalStorageStores your language preference for client-side renderingUntil cleared
Supabase session cookiesCookie (HttpOnly)Technical session management required for secure server-side rendering — no user account data is stored in these cookiesSession

6. Health-Related Data

The service type selected during appointment booking (e.g., pelvic floor training, orthopedic rehabilitation, geriatric therapy) may be considered a special category of personal data (health data) under the Swiss Federal Act on Data Protection (nDSG) and/or the EU General Data Protection Regulation (GDPR Art. 9).

We collect this information exclusively to:

  • match you with the appropriate physiotherapy service, and
  • allow our therapist to prepare appropriately for your appointment.

This data is not shared with any third party, used for profiling, or processed for any purpose other than delivering your requested service.

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected:

  • Contact form submissions — retained for up to 2 years
  • Appointment records — retained for up to 5 years, in line with Swiss record-keeping obligations for healthcare providers
  • Language preference — until you clear your browser data or the cookie expires (12 months)

8. Your Rights

Under the Swiss Federal Act on Data Protection (nDSG) and, where applicable, the EU General Data Protection Regulation (GDPR), you have the following rights:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — ask us to correct inaccurate or incomplete data
  • Right to erasure — ask us to delete your data, subject to statutory retention obligations
  • Right to restriction — ask us to restrict the processing of your data
  • Right to data portability — request your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, please contact us at info@prep-rehab.ch. We will respond within 30 days.

If you are in the European Economic Area (EEA), you have the right to lodge a complaint with your local supervisory authority. For Swiss residents, the supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch.

10. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us so we can delete it promptly.

11. Security

We take appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse. These include encrypted data transmission (HTTPS), access controls, and the use of reputable, security-audited service providers.

However, no method of data transmission over the internet can be guaranteed to be 100% secure. We encourage you to contact us immediately if you suspect any unauthorized use of your data.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The current version is always available at prep-rehab.ch/privacy-policy. Material changes will be indicated by updating the “Last updated” date at the top of this page.


13. Contact

For any questions about this Privacy Policy or to exercise your data rights, please contact:

Prep & Rehab GmbH
Zurich, Switzerland
info@prep-rehab.ch