Skip to content Skip to footer

Privacy Policy

Privacy Policy

Effective Date: 16 April 2026

1. Who we are

This website (stramedia.ch) is operated by STRAMEDIA SA, a company incorporated under the laws of Switzerland.

  • Registered office: Via Livio 14, 6830 Chiasso, Switzerland
  • UID: CHE-244.021.563
  • Data protection contact: privacy@stramedia.ch

2. Scope of this policy

This Privacy Policy describes how STRAMEDIA SA (“we”, “us”) processes personal data collected through the website stramedia.ch. It does not cover services operated by third parties to which the site may link.

3. Data we process

  • Contact form and email data: name, email address, company, and any information you voluntarily provide when contacting us.
  • Technical and usage data: IP address, browser type, device information, referring URL, pages visited, and interaction events, collected through cookies and analytics tools.
  • Communication data: messages, attachments, and metadata associated with correspondence you send us.

4. Purposes and legal basis

  • Responding to inquiries and managing commercial relationships — performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR); Art. 31(2)(a) Swiss FADP.
  • Website analytics and service improvement — consent where required (Art. 6(1)(a) GDPR / Art. 31(1) Swiss FADP), or legitimate interest in operating and improving the service.
  • Security, fraud prevention, and integrity of the site — legitimate interest (Art. 6(1)(f) GDPR) and legal obligation where applicable.
  • Compliance with legal obligations — Art. 6(1)(c) GDPR.

5. Cookies and tracking

The site uses cookies and similar technologies for strictly necessary, functional, analytics, and (where applicable) marketing purposes. Non-essential cookies are set only after you provide consent through the cookie banner. See our Cookie Policy for the full list and how to manage your preferences.

6. Recipients and processors

Personal data may be shared with service providers acting as processors on our behalf, including hosting and infrastructure providers, email providers, analytics providers (e.g. Google Analytics), and professional advisors where strictly necessary. We do not sell personal data.

7. Data received from Meta platforms (Instagram, Facebook)

When you connect an Instagram Business or Facebook Page account to a Stramedia-operated app or service (the “Service”), we receive and process Platform Data from Meta only to deliver that Service to you. This section describes that processing in detail.

7.1 Categories of data we receive. Subject to the permissions you authorize at login, we may receive: account profile information (Instagram or Facebook user identifier, username, profile picture, account type, follower count); media content you have published or are about to publish (videos, images, captions, hashtags, mentions, scheduled timestamps); engagement data on content you control (impressions, reach, plays, saves, shares, profile visits, story exits, demographic breakdowns); comments and direct messages on accounts you have connected, when you have authorized us to manage them on your behalf; identifiers and metadata required by Meta to authenticate API calls (access tokens, page IDs, business IDs).

7.2 Permissions we request. Stramedia requests only the permissions strictly necessary for the features you use. Typical permissions include instagram_business_basic (read profile and media metadata), instagram_business_content_publish (publish content you have approved), instagram_business_manage_comments (moderate comments on your behalf), instagram_business_manage_messages (read and send direct messages on your behalf when you delegate inbox handling), instagram_business_manage_insights (read account analytics), pages_show_list and pages_read_engagement (list and read the Pages linked to your Instagram Business account). The exact set is shown in the Meta consent screen at the time you connect.

7.3 Purposes. We use Platform Data exclusively to authenticate your account and verify ongoing API access; display analytics, performance and content insights inside the Service; schedule, publish or republish content you have authored or approved; respond to messages and comments on your behalf when you delegate this function; monitor and prevent abuse, fraud and integrity issues on our platform.

7.4 Legal basis (GDPR / Swiss FADP). The legal basis is your consent (Art. 6(1)(a) GDPR; Art. 31(1) Swiss FADP) granted at the time you connect your Meta account, combined where applicable with the performance of the contract for the Service (Art. 6(1)(b) GDPR; Art. 31(2)(a) Swiss FADP).

7.5 What we do not do. We do not sell Platform Data. We do not use Platform Data to train general-purpose machine learning models. We do not aggregate Platform Data from one client with that of any other client for any purpose. We do not share Platform Data with advertisers, data brokers or any third party other than the technical processors listed in section 6 of this Policy, and only to the strict extent necessary to operate the Service.

7.6 Retention. Access tokens are retained for the lifetime of your subscription to the Service and are revoked promptly upon termination. Cached media, captions and engagement metrics required to display historical analytics are retained for the duration of the engagement and for up to 90 days thereafter, then deleted.

7.7 Revoking access and deleting data. You can revoke our access to your Meta account at any time directly from Meta. Instagram: Settings > Security > Apps and Websites. Facebook: Settings & Privacy > Settings > Apps and Websites. Revoking access in Meta automatically prevents future API calls from Stramedia. To request deletion of any Platform Data we have already cached, follow the procedure described in our Data Deletion Instructions.

7.8 Compliance with Meta Platform Terms. Stramedia’s processing of Platform Data complies with the Meta Platform Terms, the Meta Developer Policies, and the Instagram Platform Policy. Where any provision of those terms imposes a stricter requirement than this Policy, the stricter requirement prevails for that data.

8. International transfers

Some processors are located outside Switzerland and the EEA. Transfers are protected by appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the Swiss FDPIC’s approved clauses, adequacy decisions, or equivalent measures.

9. Retention

  • Inquiries and contact form submissions: up to 24 months from last interaction.
  • Contractual and accounting records: as required by Swiss law (typically 10 years).
  • Analytics data: per the retention settings of the analytics provider, typically up to 14 months.

10. Your rights

Subject to applicable law, you have the right to access, rectify, delete, restrict, and port your personal data, and to object to processing based on legitimate interest. Where processing is based on consent, you may withdraw consent at any time.

To exercise these rights, write to privacy@stramedia.ch. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) or, where GDPR applies, your local supervisory authority.

11. Security

We apply reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or misuse.

12. Children

The website is not directed to children under 16. We do not knowingly collect personal data from children.

13. Changes

We may update this Privacy Policy from time to time. The “Effective Date” above indicates when the latest version took effect.

14. Contact

STRAMEDIA SA — Via Livio 14, 6830 Chiasso, Switzerland — privacy@stramedia.ch