

Privacy Policy
How Verbier Labs SA collects, uses and protects personal data across the VIRYA clinic, the virya-health.com website and the VIRYA Health app.
Effective date: 6 August 2026 · Verbier Labs SA, Verbier, Switzerland
1. Introduction
Verbier Labs SA ("VIRYA", "we", "us", "our") operates the VIRYA clinic in Verbier, Switzerland, the virya-health.com website and the VIRYA Health mobile application (together, the "Services"). This Privacy Policy explains how we collect, use, disclose and protect personal data when you use the Services. We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
2. Data controller
The controller responsible for the processing described in this Policy is Verbier Labs SA (CHE-382.373.897), Chemin de la Tinte 21, 1936 Verbier, Switzerland. For questions, requests or complaints regarding personal data, contact info@virya-health.com.
3. Personal data we collect
Identity and contact data
Name, email address, telephone number, date of birth, place of stay in Verbier, and how you heard about us.
Booking data
The treatments booked, appointment dates and times, and whether appointments took place.
Health data
Treatments received; notes recorded by our practitioners after each session, which are maintained as an unalterable clinical record; responses to intake forms; treatment requests; and the date on which consent was given. Health data is sensitive personal data under the FADP and special category data under the GDPR, and is processed only with explicit consent.
Payment data
Amounts paid, payment dates and the package or session concerned. Card details are processed exclusively by our payment providers: Stripe for payments made in the app and online, and SumUp for card payments taken at the clinic. We do not collect or store card numbers.
Communications data
Copies of booking-related emails and SMS messages sent to you, together with their delivery status. Our emails record whether a message was opened by means of a standard tracking image; if your email client blocks images, no open data is recorded. For SMS, only delivery status is available.
Account data
Login credentials (passwords are stored in hashed form and are not readable by us), notification preferences and, where you enable push notifications, a device token.
4. How we use personal data
• To provide treatments and bookings: performance of a contract
• To process health data: your explicit consent, obtained separately at registration and never bundled into general terms
• To send appointment communications (confirmations, changes, cancellations): performance of a contract. These are service communications, not marketing
• To maintain business and accounting records: compliance with legal obligations under Swiss law
• To send marketing communications: your consent, given by separate opt-in and withdrawable at any time. Withdrawal has no effect on your care
5. Sharing of personal data
Access to personal data within VIRYA is role-based and enforced at database level: clients can access only their own records, and practitioners can access client records for the purpose of providing treatment. Clinical notes cannot be altered or deleted once recorded. We do not sell personal data.
We share personal data with the following service providers, each of which processes data only on our instructions:
• Supabase: database and authentication (Frankfurt, EU)
• Resend: email delivery and delivery status (Ireland, EU)
• Twilio: SMS delivery (USA)
• Stripe: payment processing (USA/global)
• SumUp: card payments at the clinic (UK/EU)
• Vercel: hosting of staff systems
• Tally: intake forms
• Klaviyo: marketing email, opted-in contacts only
• Apple: push notification delivery (global)
During the migration from our previous booking systems, Acuity Scheduling and Jane App, records created in those systems remain with those providers until the migration is complete.
6. International data transfers
Personal data is hosted in the European Union (Frankfurt and Ireland), which Swiss law recognises as providing an adequate level of data protection. Where a provider processes personal data in the United States, we rely on certification under the Swiss–U.S. Data Privacy Framework, recognised by Switzerland since 15 September 2024, or on recognised standard contractual clauses.
7. Data retention
• Booking and payment records: ten years, as required by Swiss accounting law
• Health records: at least ten years after the last treatment, in line with Swiss health-record requirements
• Communications records: retained with the booking records to which they relate, ten years
• Marketing consent: until withdrawn
8. Your rights and choices
Under the FADP and, where applicable, the GDPR, you have the right to:
• request access to the personal data we hold about you, including its origin, purpose and recipients
• request rectification of inaccurate data
• receive a copy of the data you have provided in a commonly used electronic format
• withdraw consent at any time, including for health data, without affecting the lawfulness of processing carried out before withdrawal
• object to direct marketing at any time
• request erasure of personal data we are not legally required to retain
You can also delete your account at any time in the VIRYA Health app under Profile, Delete my account. Deletion permanently removes your login and cancels upcoming bookings. Records we are legally required to retain are kept for the statutory period and are not used for marketing.
To exercise these rights, contact info@virya-health.com. We respond within 30 days. You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch) and, if you are in the EU or EEA, with your national supervisory authority.
9. Data security
Personal data is hosted in the European Union and encrypted in transit. Database access is restricted by row-level security, so records are available only to the account they belong to and to the staff providing treatment. Passwords are stored in hashed form. Card details never reach our systems. Clinical notes are immutable by design.
10. Changes to this policy
We may update this Policy from time to time. If we change what we collect or the purposes for which we use it, we will update this page and notify you in the app before the change takes effect. The effective date above indicates the latest revision. This Policy was last updated on 6 August 2026.
