Privacy Policy
28 July 2026
WEFAM Group Sàrl (« WEFAM », « we ») operates the real estate platform available at wefamgp.com (the « platform »). This privacy policy describes, in a concise, transparent and easily accessible manner, how we process the personal data of visitors, sellers, buyers and other users of the platform, in accordance with the Federal Act on Data Protection (FADP, RS 235.23).
In short: we collect the data strictly necessary to bring real estate sellers and buyers together, to verify identity, to ensure security and to meet our legal obligations; we never sell it, we retain it for proportionate periods, and you at all times have a right of access, rectification, erasure and objection.
1. Controller
The controller within the meaning of art. 19 FADP is:
WEFAM Group Sàrl, whose registered office is in Genolier (VD), Switzerland.
Contact email: wefam@wefamgp.com.
For any question relating to data protection, you may write to this address with « Data protection » as the subject.
2. Scope
This policy applies to all processing of personal data carried out by WEFAM in the context of the platform, whether it concerns unregistered visitors, account holders (sellers and buyers), or third parties with whom we exchange in the context of a transaction (notaries in particular).
It supplements the Seller Brokerage Agreement and the Buyer Disclaimer, to which it is inseparably linked. In the event of a conflict, this policy prevails as regards the processing of personal data.
3. Categories of personal data processed
We process the following categories of personal data, depending on your status on the platform:
| Category of person | Data processed |
| Unregistered visitors | IP address (processed transiently, in memory only, to limit abusive access attempts), listings viewed and date of consultation, chosen display language. No account is created and no advertising profile is built. |
| Sellers | first name, last name, email address, phone number, verified first and last names, outcome and date of the identity verification (the identity document itself is transmitted directly to Stripe Identity and never reaches us), photographs and documents of the listed property, address and characteristics of the property, price and conditions of the listing, visit slots offered, offers received and associated messages. |
| Buyers | first name, last name, email address, phone number, listings viewed and saved as favourites, visit requests (including the announced number of people) and associated messages, offers and counter-offers made, notifications received. |
| Notaries and third parties | professional contact details necessary for the conclusion of the authentic deed of sale and for the collection of the commission. |
| Platform administrators | the administrator’s identity and email address, the action performed, the object concerned, the reason given and the timestamp, recorded in a tamper-evident access log (see art. 12). |
Sensitive data: only sellers undergo identity verification. Carried out by Stripe Identity, it covers only the photograph of an official identity document: no image of your face is captured and no facial recognition is performed. The processing of this document relies on your consent, collected on our information screen before any transmission and then by Stripe at the start of its own flow, as well as on our overriding interest in preventing fraud and identity theft (art. 31 FADP). This document is transmitted directly to Stripe and is never disclosed to us. Viewing listings and submitting an offer require no identity document.
4. Purposes of processing and legal basis
The table below summarises the purposes pursued and the legal basis for each processing operation (arts. 6, 31 and 32 FADP).
| Purpose | Legal basis |
| Performance of the brokerage agreement and seller–buyer matching | Performance of a contract (art. 31 para. 2 let. a FADP) |
| Identity verification (Stripe Identity) | Explicit consent + overriding interest (fraud prevention, art. 31 FADP) |
| Publication of listings and their photos/documents | Seller's consent (art. 31 para. 1 FADP) |
| Audience measurement for listings, reported back to their author (number of views) | Legitimate interest (art. 31 para. 1 FADP) |
| Moderation of listings and supervision of the platform, with access logging | Legitimate interest + legal obligation (art. 31 FADP; art. 4 DPO) |
| Security and fraud prevention (rate limiting) | Legitimate interest (art. 31 para. 1 FADP) |
| Communication with notaries and conclusion of the sale | Performance of a contract (art. 31 para. 2 let. a FADP) |
| Compliance with legal obligations (accounting, tax, retention) | Legal obligation (art. 31 para. 2 let. c FADP) |
| Customer service, handling of complaints and disputes | Legitimate interest (art. 31 para. 1 FADP) |
5. Recipients of the data
We only disclose your personal data to the following recipients, to the extent strictly necessary for the purposes described in art. 4:
the technical processors listed in art. 6 (hosting provider, Stripe, email service);
the notary in charge of the authentic deed of sale, for the data strictly necessary to the transaction;
the other party to the transaction (seller or buyer), insofar as the data is indispensable for the visit, the negotiation and the conclusion (name, contact details, property references);
Swiss or foreign authorities, only upon duly founded legal request;
no third party for advertising or commercial purposes. We never sell your data.
6. Processors
We use the following categories of processors within the meaning of art. 9 FADP. Each is bound by a written contract imposing technical and organisational guarantees equivalent to ours and prohibiting any processing for their own purposes.
Hosting provider: storage of the database and files, in Switzerland. No data is transferred outside Switzerland for hosting.
Stripe, Inc. (United States): verification of sellers’ identity (Stripe Identity). The contracting entity is Stripe Payments Europe, Limited (Ireland), acting together with Stripe, Inc. (United States). No payment is processed on the platform: the sale price and the commission pass through the notary in charge of the authentic deed. Transfers to the European Union and the United States are governed by art. 8.
Transactional email service: verification emails, visit notifications, offer confirmation. Email addresses are transmitted only to the extent necessary for sending.
7. Retention period
In accordance with the principle of proportionality (art. 6 FADP), we retain your personal data only for as long as is necessary for the purposes described or to meet our legal obligations. The applicable periods are set out in the table below.
| Category of data | Retention period | Basis / justification |
| User account | Lifetime of the account, then anonymisation upon request or on closure | Performance of the contract; minimisation (art. 6 FADP) |
| Identity documents (Stripe Identity) | For sessions started with v2 information, WEFAM stores verified first and last names linked to the account, verification outcome, date and session to prevent fraud. Other extracted fields received during retrieval are neither stored nor logged. Profile names remain editable. Names are erased on account anonymisation. Stripe erasure is requested immediately after saving the names and outcome and may take up to four days. Earlier sessions are not used to collect names retroactively. | Minimisation (art. 6 FADP) |
| Listings, visits, offers and messages relating to a concluded transaction | 10 years from the close of the financial year concerned | Accounting records relating to the brokerage commission — art. 958f CO (legal obligation) |
| Enhanced Visibility option subscriptions and deactivations | 10 years from the close of the financial year concerned | Accounting records and proof of consent — art. 958f CO (legal obligation) |
| Listings withdrawn without a sale and associated data | 12 months from withdrawal of the listing | Evidence in case of dispute; minimisation (art. 6 FADP) |
| Listing consultation history | 24 months | Audience measurement of listings for the benefit of sellers (legitimate interest, art. 31 FADP) |
| Enquiries about a property development (name, email, phone, message) | 24 months from the enquiry | Pre-contractual measure requested by the data subject (art. 31 para. 2 let. a FADP) |
| Administrator access log | 12 months minimum | Art. 4 DPO (legal logging obligation) |
| IP address (login rate limiting) | In memory only, from 15 minutes to 1 hour; never written to the database | Security (legitimate interest, art. 31 FADP) |
| Verification and password reset tokens | Deleted on expiry, by automatic purge | Security; minimisation (art. 6 FADP) |
| Backups | Rotation of 30 to 90 days | Technical continuity; no retention beyond the cycle |
Upon expiry of these periods, the data is either deleted or anonymised in such a way that it no longer allows you to be identified. Anonymising an account does not erase past listings, visits and offers: it removes from them any data that could identify you, so that the other party to the transaction retains a consistent history of its own dealings.
8. Transfers of data abroad
Data is hosted in Switzerland; no data is transferred abroad for storage.
However, identity verification is carried out by Stripe Payments Europe, Limited, headquartered in Ireland, acting together with Stripe, Inc. (United States). Images of your identity document are therefore processed in the European Union and in the United States. The transfer to the United States relies on the Swiss-U.S. Data Privacy Framework (Swiss–US data protection framework, in force since 15 September 2024), of which Stripe is certified. Failing or in addition to this, the transfer is governed by the standard contractual clauses approved by the FDPIC (art. 16 para. 2 let. c FADP).
The recipient countries are Ireland, a member of the European Union and as such covered by an adequacy decision, and the United States of America. In the event of Stripe’s failure to comply with this framework, you have a right of recourse before the FDPIC and before the US Department of Commerce (see https://www.dataprivacyframework.gov).
10. Identity verification (Stripe Identity)
The publication of a listing is conditional upon verification of the seller’s identity using the Stripe Identity service. For this purpose, the seller transmits a photograph of an official identity document (identity card, passport or driving licence), taken on the spot. No photograph of the face is requested and no facial recognition is performed. Until that verification succeeds, the listing remains pending and is visible to no one but its author.
For sessions started with v2 information, WEFAM stores verified first and last names linked to the account, verification outcome, date and session to prevent fraud. Other extracted fields received during retrieval are neither stored nor logged. Profile names remain editable. Names are erased on account anonymisation. Stripe erasure is requested immediately after saving the names and outcome and may take up to four days. Earlier sessions are not used to collect names retroactively.
You may decline verification; only publication of your listing will be blocked. For successful v2 sessions, Stripe erasure is requested immediately after saving the names and outcome and may take up to four days. Other sessions follow Stripe’s policy (https://stripe.com/privacy), in principle three years, with earlier erasure on request or account deletion.
11. Automated individual decisions
WEFAM does not take any decision based solely on automated processing producing legal effects concerning you (art. 21 FADP). Where applicable, the automated check carried out by Stripe Identity may lead to the rejection of an illegible or non-compliant identity document; this rejection is purely technical and does not constitute a decision within the meaning of art. 21 FADP. In the event of a rejection, you may request human review by writing to wefam@wefamgp.com.
12. Data security
We implement appropriate technical and organisational measures (art. 7 FADP) to ensure the security of your data, in particular:
TLS encryption of communications;
secure hosting in Switzerland, restricted and logged access;
hashed and salted passwords (bcrypt);
separation of privileges and need-to-know principle;
pseudonymisation by default in the back office: email addresses, phone numbers and family names are masked there, and can only be displayed in clear text through an explicit, justified and logged action;
a tamper-evident access log recording the administrator’s identity, the action performed, the object concerned, the reason given and the timestamp (art. 4 DPO). This log contains neither IP addresses nor any copy of the data consulted;
breach management procedure and continuity plan.
13. Breach notification
In the event of a security breach likely to result in a high risk to your rights and freedoms, we undertake to notify the FDPIC without delay and at the latest 72 hours after becoming aware of it (art. 24 FADP). Where applicable, we will also inform you of the measures taken to limit the consequences of the breach.
14. Rights of data subjects
In accordance with arts. 25 to 30 FADP, you have the following rights, upon written request to wefam@wefamgp.com:
Right of access (art. 25 FADP): know what data we process about you;
Right to rectification (art. 26 para. 1 FADP): correct inaccurate data;
Right to erasure (art. 26 para. 2 FADP): request the deletion of your data, subject to legal retention obligations;
Right to restriction (art. 27 FADP): request a temporary suspension of processing;
Right to portability (art. 28 para. 2 FADP): receive your data in a structured format;
Right to object (art. 30 FADP): object, for legitimate reasons, to processing based on our legitimate interest;
Right to withdraw your consent at any time, without retroactive effect, for processing based on consent (identity verification, publication of listings).
To exercise these rights, you must identify yourself (art. 16 DPO). We respond to your request within 30 days and, in principle, free of charge (fees may only be charged in the event of a manifestly abusive or disproportionate request, up to a limit of CHF 300, art. 29 FADP). Deletion of your account can be requested directly from the « Account » section of your settings: the request is sent from your logged-in session, which serves as identification, and its date is recorded. A person then checks that no transaction is under way before proceeding; the erasure of your identity document at Stripe is requested on that occasion. These rights are not mere statements: our back office provides the functions needed to compile a complete export of your data and to irreversibly anonymise your account. Each of these operations is itself recorded in the access log.
If you believe that we have infringed your rights, you may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Berne, hotline 058 462 43 95, or bring the matter before the civil court (art. 32 FADP).
15. Data protection impact assessment
As the processing of identity documents presents a high risk (art. 22 FADP), a data protection impact assessment (DPIA) has been carried out. The summary of this assessment is available on request to wefam@wefamgp.com (art. 23 para. 1 FADP).
16. Record of processing activities
WEFAM maintains a record of processing activities (art. 12 FADP), which can be consulted by the FDPIC. The relevant elements of this record are reflected in this policy.
17. Changes to this policy
We may update this policy to reflect changes in the law, our services or our processors. In the event of a substantial change, we will inform you by email and publish the new version on the platform, with the date of entry into force. The applicable version is the one online at the time of processing.
Contact
For any question relating to this privacy policy or the exercise of your rights, you can contact us at: wefam@wefamgp.com, with « Data protection » as the subject.
Supervisory authority: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Berne, https://www.dataprotection.admin.ch.