1. Who this Notice applies to
This Notice explains how Pensive Labs Sàrl ("Pensive Labs", "we", "us" or "our") collects and processes personal data when an individual applies to, joins or uses the Pensive Labs community and related onboarding, messaging, matching and introduction services (the "Community" or "Service").
Pensive Labs is the controller for the processing described here under the Swiss Federal Act on Data Protection (FADP). Third-party services may be separate controllers for processing they conduct for their own purposes, as explained below.
This Notice is provided for transparency. It is not a request for blanket consent and does not limit your statutory rights. Where consent is legally required for an optional activity, we will ask for it separately.
The Community is intended only for adults aged 18 or over who are resident in Switzerland. You must tell us if your country of residence changes. We may suspend access until we have assessed whether the Service and this Notice remain appropriate for the new country.
2. Personal data we collect and where it comes from
Depending on how you use the Service, we process the following categories of personal data:
- identity, eligibility and contact information, including name, phone number, email address, confirmation that you are at least 18 and resident in Switzerland, and membership status;
- professional profile information that you choose to provide, including role, experience, business interests, skills, goals, needs, preferences and topics on which you seek or can offer help;
- Community communications, including WhatsApp or email messages, voice notes and voice-note transcripts;
- matching and introduction information, including suggested matches, the reasons for a suggestion, acceptance or refusal, feedback and introduction status;
- support and operational records, including requests, complaints, preferences and records needed to administer the Community; and
- technical and security information made available by our systems or providers, including timestamps, message or request identifiers, device or connection information, authentication events and security logs.
We collect most information directly from you. We may receive limited information from another member who proposes an introduction, from an onboarding form, or from our service providers. We do not create a persistent profile for a non-member solely because another member mentions that person. If we decide that it is necessary to retain personal data about a non-member, we will inform that person as required by Swiss law unless a statutory exception applies.
3. Why we process personal data
We process personal data only for clear purposes connected with the launch, operation and protection of the Community:
- reviewing applications and confirming launch eligibility;
- creating and maintaining member profiles from information members choose to provide;
- transcribing voice notes and structuring messages so that the Service can understand a member's stated interests and needs;
- searching, comparing and ranking possible professional or networking matches;
- asking the relevant members whether they agree to a proposed introduction and sending the introduction only after the required approval;
- providing administration, support, maintenance, service continuity and incident resolution;
- protecting the Service and members, preventing abuse, investigating security events and maintaining proportionate logs;
- complying with legal obligations and responding to lawful requests; and
- producing aggregated or anonymised statistics for security, capacity planning and service improvement.
We do not sell member personal data. We do not use it for unrelated advertising or build advertising profiles. We do not send optional marketing messages unless permitted by law and you can opt out of them without losing essential Community communications.
4. Swiss legal framework and justifications
We process personal data in accordance with the FADP principles of lawfulness, good faith, transparency, proportionality, purpose limitation, accuracy and security. The core processing is carried out to provide the Service requested by members and to perform the membership relationship. Depending on the activity, processing may also be justified by your consent, an overriding private interest of Pensive Labs or another person, compliance with law, or the establishment, exercise or defence of legal claims.
You are not required to provide optional profile details. However, we need basic contact information and enough professional context to assess membership and provide matching and introductions. If you do not provide the minimum information, we may be unable to admit you or deliver the Service.
5. AI-assisted processing, profiling and member choice
The Service is AI-assisted. AI and algorithmic tools may transcribe voice notes, extract and organise professional information, create searchable profile fields, compare stated interests and needs, rerank possible matches and draft suggested introduction text. Pensive Labs personnel may review, correct or filter outputs for relevance, quality and safety.
This processing may constitute profiling in the ordinary sense because it uses member information to evaluate possible professional compatibility. It is not intended to be high-risk profiling: we do not use sensitive personal data or extensive cross-context tracking to evaluate essential aspects of a member's personality, and we do not use the results to determine employment, credit, insurance, access to essential services or legal rights.
A match is only a suggestion. It does not automatically disclose contact details or create an introduction. The relevant members are asked to agree first and may decline without giving a reason. We do not currently make a decision based solely on automated processing that produces a legal effect or a similarly significant effect. If this changes, we will provide the information and human-review rights required by law before the feature is used.
6. AI model training and provider use
Pensive Labs does not use member personal data to train or fine-tune general-purpose AI models. We use commercial or API services rather than personal consumer AI accounts, and we do not intentionally opt in to provider programmes that use customer inputs or outputs for general model training. We also avoid submitting member content through optional feedback tools.
AI providers may still process limited data for service delivery, security, abuse prevention, legal compliance and other purposes permitted by their business terms and data processing agreements. Pensive Labs will not activate a provider for member personal data unless appropriate processor terms and, where required, international-transfer safeguards are in place.
7. Introductions and information shared with members
For a proposed introduction, we may first share a short explanation of the potential fit without disclosing unnecessary contact details. After the required members agree, we may share limited information such as name, email address, professional context and the reason for the introduction.
After an introduction, each member independently decides whether and how to communicate and is responsible for handling information received from the other member lawfully and respectfully. Community information must not be used for spam, harassment, scraping, resale, public posting or unrelated solicitation. These behavioural rules are also addressed in the separate Member Terms and Community Rules.
8. Sensitive data and information about other people
The Service is not designed for routine processing of sensitive personal data, including detailed health information, religious or political beliefs, intimate information, criminal records, government identifiers or biometric data used for identification. Do not intentionally submit such information unless we have expressly requested it and explained the applicable safeguards.
If sensitive or excessive information is submitted unexpectedly, we may minimise it, restrict access, ask you to remove or clarify it, exclude it from AI processing, or delete it where appropriate. Members should not submit confidential or unnecessary personal information about employees, co-founders, investors, family members or other third parties.
9. WhatsApp and other communication platforms
The launch Service communicates through the WhatsApp Business Platform and email. WhatsApp and Meta process account, device, routing, security and communication data under the terms applicable to their platforms. For parts of the WhatsApp Business service, Meta Platforms Ireland Limited processes data on our behalf; Meta or WhatsApp may also process certain data independently for their own platform, security and legal purposes.
Pensive Labs does not control the processing that occurs in a member's personal WhatsApp account or device. Members should use the Service only for information suitable for transmission through the chosen channel. You may contact us by email to ask whether an alternative channel is available.
10. Recipients and processors
Personal data may be disclosed only as reasonably necessary to:
- authorised Pensive Labs personnel and contractors who need access for operations, support, security or maintenance and are bound by confidentiality;
- hosting, storage, backup, AI, transcription, search, matching, email and messaging providers acting under contractual obligations;
- another member as part of an approved introduction;
- professional advisers, insurers, auditors, financing or transaction counterparties, subject to appropriate confidentiality;
- courts, regulators, law-enforcement bodies or other public authorities where disclosure is legally required; and
- a successor or acquirer in a merger, financing, reorganisation or transfer of the Community, subject to appropriate safeguards and notice where required.
Pensive Labs remains responsible for selecting and instructing processors and for ensuring that outsourced processing complies with applicable Swiss data-protection requirements. The main launch providers are listed in Annex 1.
11. Processing outside Switzerland
Core application hosting and backups are intended to remain in Switzerland. Certain AI, messaging and email providers process limited personal data in the European Economic Area, the United Kingdom, the United States and, depending on their infrastructure, other countries identified in their current subprocessor documentation.
Where the destination is recognised by Switzerland as providing adequate protection, personal data may be disclosed on that basis. For other destinations, Pensive Labs uses safeguards permitted under the FADP, principally recognised standard contractual clauses adapted for Swiss law. Transfers to a certified US recipient may also rely on the Swiss-U.S. Data Privacy Framework. In exceptional cases, a statutory derogation may apply, for example where a transfer is necessary for the performance of a contract or for legal claims.
You may request more information about the countries, recipients and applicable safeguards by contacting nathan@pensivelab.com. The provider register in Annex 1 is part of this Notice and will be updated before a material new international data flow is introduced.
12. Retention and deletion
We retain personal data only for as long as needed for the stated purpose, subject to legal obligations and proportionate records needed for security, disputes or legal claims. The standard launch periods are:
- application data for a person who is not admitted or withdraws: normally 6 months after the decision or withdrawal;
- active member profile, matching preferences and introduction history: during membership and normally 30 days after membership ends;
- WhatsApp and email conversation history, voice notes and transcripts retained by Pensive Labs: normally 12 months from the communication;
- support and operational records: normally 12 months after closure of the relevant issue;
- technical and security logs: normally 6 months, unless a longer period is necessary to investigate an incident or prevent abuse; and
- residual backups: protected and overwritten or deleted under the normal backup cycle, normally within 90 additional days after deletion from active systems.
Limited records may be kept longer where required by law or reasonably necessary to document consent or preferences, comply with accounting obligations, prevent abuse, resolve a dispute or establish, exercise or defend legal claims. Data that has been irreversibly anonymised is no longer personal data and may be retained for statistical purposes.
13. Security
We apply technical and organisational measures appropriate to the launch risk, including role-based and least-privilege access, confidentiality obligations, strong authentication and multi-factor authentication where supported, encrypted transmission, encrypted storage where supported, environment separation, backups, logging of relevant administrative events, vulnerability and patch management, provider review, and incident-response procedures.
No communication or information system is completely secure. Members must keep their devices and accounts secure and promptly tell us if they believe their account, messages or personal data may have been compromised.
14. Your data-protection rights
Subject to the FADP and any permitted limitations, you may ask us to:
- confirm whether we process personal data about you and provide access to the information required by law;
- correct inaccurate or incomplete personal data;
- delete or destroy personal data that is no longer needed or is processed unlawfully;
- restrict or object to particular processing where the law provides that remedy;
- provide personal data in a commonly used, machine-readable format where the statutory right to data portability applies;
- withdraw consent at any time for future processing that is based on consent; and
- receive information about, express your point of view on, and request human review of a qualifying automated individual decision.
Send requests to nathan@pensivelab.com and describe the request clearly. We may take proportionate steps to verify your identity. We normally respond within 30 days; if more time is needed or a request is restricted or refused, we will inform you as required by law. Requests are generally free of charge, subject to the limited circumstances in which Swiss law permits a fee.
15. Data-security breaches
If a data-security breach occurs, Pensive Labs will document and assess it. We will notify the Swiss Federal Data Protection and Information Commissioner as soon as possible where the breach is likely to result in a high risk to the personality or fundamental rights of affected individuals. We will inform affected members where this is necessary for their protection or otherwise required by law.
16. Changes to this Notice
We may update this Notice to reflect changes to the Service, providers, law or security practices. The current version will be made available through the Community or onboarding channel. We will provide reasonable advance notice of a material change where practicable. If a new activity requires consent, we will ask for that consent separately before the activity begins.
17. Contact and complaints
Controller: Pensive Labs Sàrl, Route de Berne 317, 1000 Lausanne 25, Switzerland.
Privacy contact: nathan@pensivelab.com
You may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC). Information about data-protection rights and complaints is available at the FDPIC website. Private-law claims may need to be pursued before the competent civil court.
Annex 1 - Main launch service providers and foreign processing
This register reflects the intended Swiss launch architecture as at 21 July 2026. Pensive Labs must verify the selected account region, contract and transfer mechanism before activating a provider for member personal data. Provider infrastructure can change; current subprocessor documentation is consulted and this Notice is updated before a material new data flow begins.
| Provider / role | Purpose | Data involved | Processing locations disclosed for launch | Safeguard and key restriction |
|---|---|---|---|---|
| Infomaniak Network SA Processor | Application hosting, database, storage and backups | Member account, profile, messages, matching and operational data stored in the application | Switzerland | Swiss processor agreement. Core hosting and backups configured in Switzerland. |
| OpenAI Ireland Ltd. and OpenAI group Processor | Voice transcription and AI-assisted structuring, analysis and drafting | Voice notes, transcripts, prompts and minimised profile or message excerpts needed for the requested feature | Primarily EEA/Switzerland where configured; certain processing and subprocessors may be in the United States and other countries listed by OpenAI | OpenAI business/API DPA; Swiss-adapted SCCs and/or Swiss-U.S. DPF for certified US recipients. No general model training by default; optional data sharing disabled. |
| Anthropic, PBC and subprocessors Processor | AI-assisted analysis, summarisation and matching support | Prompts and minimised profile or message excerpts needed for the requested feature | Data storage in the United States; processing may also occur in Europe, Asia and Australia under Anthropic's commercial infrastructure | Anthropic commercial DPA including SCCs. No general model training by default; optional development or feedback programmes not used for member content. |
| Mistral AI Processor and separate controller for limited activities | AI-assisted analysis, structuring, verification and drafting | Prompts and minimised profile, message or sequence excerpts needed for the requested feature | Mistral AI is established in France; processing may also occur in locations used by subprocessors disclosed in its Trust Center | Mistral AI commercial DPA and SCCs for restricted-country transfers. Paid API inputs and outputs are not used for model training except for stated contractual exceptions. Feedback tools must not be used for member content, and zero data retention should be enabled where available. |
| Cohere Inc. Processor only after launch checks | Semantic search or reranking of possible matches | Pseudonymised or minimised profile and matching inputs | Cohere is established in Canada; processing may also occur in United States locations used by Cohere and its subprocessors | Must not receive member personal data until a written processor agreement and Swiss transfer safeguards are in force. Inputs must be minimised and no unrelated service-improvement use permitted. |
| CloudMailin Processor only after launch checks | Operational and introduction email delivery or routing | Email address, delivery metadata and the minimum message content needed for delivery | Selected EU server for the Pensive Labs account; provider infrastructure may also involve the United States or Asia-Pacific locations | Signed DPA and confirmed server country required before activation. Swiss-adapted SCCs where a non-adequate destination is involved. |
| Meta Platforms Ireland Ltd., Meta Platforms, Inc. / WhatsApp Processor and separate controller depending on activity | WhatsApp Business message routing, delivery, security and platform operation | Phone number, messages, routing information, delivery status, device or platform metadata | Ireland, United States and other locations used by Meta/WhatsApp under their current terms | WhatsApp Business and Meta data-processing terms; Swiss-U.S. DPF for certified US processing and/or SCCs. Meta/WhatsApp may independently process certain platform data. |
Current provider information: Infomaniak trust and data protection OpenAI subprocessor list Anthropic privacy centre Mistral AI Trust Center CloudMailin security and privacy Meta data-processing terms