Privacy Policy
This is an English translation of our French privacy policy. In the event of any discrepancy between the two versions, the French version prevails.
Introduction
This privacy policy applies to the website valeriedemont.ch and to all services provided by Greenheart.business Sàrl (one-to-one mentoring, group programmes, workshops, training, online shop, newsletters and podcasts).
Data protection is a matter of trust, and the foundation of our work together. Protecting your personal data is a fundamental priority for us. This policy explains how we collect, use, share and protect your personal information, including when we use artificial intelligence tools.
We have written this policy to be transparent and accessible, so that you have a clear understanding of our data protection practices.
We invite you to read it carefully and to revisit it from time to time, as it may be updated to reflect changes in our activities, in the tools we use (particularly artificial intelligence) and in legislation. By choosing to use our services, you accept the practices described here. If you do not agree with this statement, please do not share your contact details with us.
If you have any questions or concerns about your personal data, please contact us at the address given in section 17.
1. Data controller
The controller responsible for processing your personal data is:
Greenheart.business Sàrl
Valérie Demont
Chemin des Cygnes 9
1007 Lausanne, Switzerland
CHE-425.604.630
info@valeriedemont.ch
We are not legally required to appoint a Data Protection Officer. Any request relating to your data can be sent directly to the address above and will receive a response within 30 days.
2. Definitions
Personal data: any information that, on its own or combined with other information, identifies a person or makes them identifiable. For example a name, an email address, an IP address, a voice recording or a transcript of a conversation.
Sensitive data: a special category of personal data subject to enhanced protection. It includes data relating to health, intimate life, philosophical, religious or political views and activities, and ethnic origin. In the course of our work together, some information you share spontaneously may fall into this category (see section 6).
Processing: any operation performed on personal data, whatever the means used: collection, storage, use, modification, disclosure, archiving, erasure or destruction.
Processor: a third-party provider that processes personal data on our behalf and according to our instructions (for example a newsletter service or a transcription tool).
Profiling: automated processing of personal data used to evaluate certain personal aspects, in particular to analyse or predict interests, behaviour or preferences.
Anonymisation: irreversible transformation of data so that no person can be identified any longer, including by cross-referencing. Genuinely anonymised data is no longer personal data.
3. Information we collect
We only collect the information you choose to share with us, together with the technical data strictly necessary for the operation and security of the website.
This may include your first name, surname, telephone number and email address, provided for instance when you make an enquiry by email, through a contact form on our site, or when booking an appointment.
Newsletter
When you subscribe to our French-language newsletter, the data you provide, in particular your email address and first name, is used to send you our newsletter via Mailchimp. If you subscribe to our English-language newsletter, your data is processed by Substack. Subscription uses double opt-in: you receive a confirmation email and your subscription only takes effect once you have confirmed it. You can unsubscribe at any time via the link in the newsletter or by letting us know by email.
We may segment our mailing list based on behavioural data (opens, clicks, content viewed) in order to send you more relevant content. This constitutes low-impact profiling. It produces no automated decision with legal or similarly significant effects for you, and you may object to it at any time by writing to us.
Embedded content
Pages on this site may include embedded content (videos, images, sounds, articles, share buttons). Embedded content from other websites behaves in the same way as if the visitor had visited that other website. These websites may collect data about you, use cookies, embed third-party tracking, and monitor your interaction with that embedded content if you have an account and are logged in to their site. By clicking a social media button (LinkedIn, Instagram, YouTube, TikTok, X, Facebook, etc.), you consent to the necessary data, such as your IP address and browsing activity, being transmitted to the operator of that social network.
Website analytics
We use Google Analytics 4 (GA4) from Google LLC to collect data through cookies and similar technologies. This data, such as your anonymised IP address, browser type, operating system and pages visited, helps generate reports on site activity, understand visitor behaviour and improve the site. The data collected is aggregated.
These cookies and this transfer are only activated after your explicit consent, given through our privacy preferences banner. Until you consent, no data is transmitted to Google. You can withdraw this consent at any time via the “Privacy Preferences” link at the bottom of every page.
Cookie consent
We use a technical cookie (see section 11) to remember your privacy preference settings, in accordance with the Swiss FADP and the GDPR.
Podcasts
We use Ausha to host and distribute our podcasts (Cœur Business and Being Is the New Doing — The Show). The embedded player only loads after your consent.
Online appointments and video calls
For appointments (one-off sessions, one-to-one Power Week) we use Calendly, Acuity Scheduling, Go High Level (HighLevel) and Google Calendar, along with Zoom and Google Meet for video sessions. When you book an appointment, your name, email and chosen time slot are recorded. During a Zoom session, your name, your image (if you turn your camera on), your voice and your screen content (if you share it) may be processed. No session is recorded without your explicit, prior and documented consent (see section 6).
Correspondence and incoming messages
When you write to us, by email, through a form or by messaging app, we keep the content of your message together with your contact details so that we can reply and follow up on our exchanges. This correspondence may be processed with the assistance of artificial intelligence tools under the conditions set out in section 5.
Session notes and transcripts (clients)
In the course of our work together (Power Week, Momentum, one-to-one sessions, VIP), we may use the tools Granola or Fathom to automatically transcribe our conversations and extract key points. You are informed before the session and your explicit consent is required. Transcripts are stored securely and used under the conditions set out in sections 5 and 6. You may request their deletion at any time.
Group communications (Group Power Week, Momentum)
For group programmes we use WhatsApp Business for collective communication during the programme. Your phone number is processed by Meta Platforms Ireland Ltd. and becomes visible to the other members of the group. You may leave the group or ask to be removed at any time.
Online shop
While you browse our online shop, we track:
- The products you have viewed, so we can show you recently viewed items;
- Your location, IP address and browser type, to estimate taxes and shipping costs;
- Your delivery address, to estimate shipping costs and dispatch your order.
We use cookies (see section 11) to keep track of your basket contents while you browse.
When you make a purchase, we ask for your name, billing address, delivery address, email, phone number, payment details and possibly account credentials. This information is used to:
- Send you information about your account and your order;
- Respond to enquiries, including refunds and complaints;
- Process payments and prevent fraud;
- Set up your account;
- Comply with our legal obligations, in particular tax and accounting requirements;
- Improve our offerings;
- Send you marketing messages, if you have consented to receive them.
Payments
We accept payment by bank transfer, by card via Stripe, or via PayPal. When processing online payments, certain data is transmitted to these external services (total amount, billing information, card details). We never have access to your full card number. Bank transfers are processed by our Swiss bank and involve no international transfer.
4. Purposes and legal bases
We only process your data for defined purposes, and each processing activity rests on an identified legal basis. The table below sets these out.
| Purpose | Data concerned | Legal basis |
|---|---|---|
| Delivering our services (mentoring, workshops, programmes) | Identity, contact details, content of exchanges, session notes | Performance of a contract |
| Managing orders and the online shop | Identity, addresses, order and payment data | Performance of a contract |
| Accounting, invoicing, tax obligations | Order and billing data | Legal obligation (Swiss law) |
| Responding to enquiries and following up on correspondence | Contact details, message content | Legitimate interest (responding to people who contact us) or pre-contractual steps |
| Sending the newsletter and marketing communications | First name, email, engagement data | Consent |
| Segmenting the mailing list | Open and click data | Legitimate interest (relevance of content sent), with a right to object |
| Website analytics (GA4) | Anonymised IP address, browsing data | Consent |
| Recording and transcribing sessions | Voice, image, content of exchanges | Explicit, separate and revocable consent |
| Developing our services, our teaching material and our content (see section 5) | Insights drawn from sessions, in anonymised or aggregated form | Explicit, separate and revocable consent |
| AI assistance in our internal operations | Correspondence, notes, working documents | Legitimate interest (operational efficiency), within the limits of section 5 |
| Website security and abuse prevention | IP address, connection logs | Legitimate interest (protecting our infrastructure) |
| Defending our rights in the event of a dispute | Data relevant to the dispute | Legitimate interest (establishing, exercising or defending legal claims) |
Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
5. Use of artificial intelligence
We want to be fully transparent about our use of artificial intelligence tools, because this subject sits at the heart of our work (in particular our AI Employees offering). This section sets out precisely what we do, and what we do not do.
5.1 Tools we use
We regularly use generative artificial intelligence tools, in particular ChatGPT (OpenAI), Claude (Anthropic), Gemini (Google), Granola and Fathom for transcription, Descript for audio and video editing, and other occasional tools.
5.2 What we use them for
- Preparing our editorial content: newsletters, articles, podcasts, posts;
- Synthesising our own notes and reflections;
- Preparing the teaching material for our programmes;
- Transcribing and summarising our internal meetings;
- Sorting, filing, summarising and drafting replies to our correspondence;
- Automating certain recurring administrative tasks;
- Developing our services, our teaching approach and our strategy, under the conditions set out in section 5.5.
5.3 Your personal data and AI tools
When we work with you, we do not enter your identifiable personal data (full name, email, financial data, sensitive information) into consumer AI tools without first anonymising it. We may use AI to structure an analysis, prepare feedback or clarify a strategy, but the material we submit is anonymised or generic enough that you cannot be identified.
Where we use AI tools on identifiable data, we use exclusively professional or enterprise plans for which:
- a data processing agreement compliant with Article 9 FADP and Article 28 GDPR has been signed;
- your data is not used to train the provider’s models;
- retention periods on the provider’s side are limited.
5.4 Email handling and automation
Our incoming and outgoing emails may be processed with the assistance of artificial intelligence tools, in order to sort, summarise, file or draft replies. In practice this means the content of your message and your contact details may be processed by these tools.
In doing so, we undertake to:
- Never let a reply go out without human review and approval. A human being systematically validates the content of our communications;
- Exclude from automated processing any correspondence containing identifiable sensitive or financial data;
- Use only tools with which a data processing agreement has been signed and for which model training on our data is disabled.
5.5 Developing our services and content
Our practice evolves through what we learn across our work with clients. We prefer to say this plainly rather than leave it implied.
With your explicit and separate consent, the insights drawn from our sessions (recurring patterns, types of blockages, frequent questions, phrasing that lands) may inform:
- the improvement and design of our services;
- our teaching material;
- our editorial content: newsletters, podcasts, articles, social media posts;
- our strategic thinking.
This use is carried out exclusively in anonymised or aggregated form. We never publish or reuse an extract, a quotation, a story or a detail that would allow you to be identified, or would allow someone who knows you to identify you, without your specific prior written agreement.
This consent is separate from the consent given for recording or transcribing a session. You may accept one and refuse the other. You may withdraw it at any time, by a simple email, without having to give a reason and without any effect on the quality of your accompaniment.
5.6 No automated decision-making
We make no decision producing legal effects, or similarly significantly affecting you, based solely on automated processing. No algorithm decides whether you are admitted to a programme, what price you are offered, or how your enquiry is handled. A human being always steps in and decides. Should this ever change, you would be informed and would have the right to obtain human intervention, to express your point of view and to contest the decision.
5.7 Transparency about content and conversational tools
In accordance with the transparency obligations of the European Artificial Intelligence Act (Article 50), applicable since 2 August 2026:
- when you interact with a conversational tool, an assistant or an automated quiz on our site, you are clearly informed of this, unless it is obvious from the context;
- when we publish content (text, images, audio, video) generated or substantially modified by artificial intelligence, we identify it as such in the cases required by the regulation.
5.8 Third-party provider policies
To understand how each tool handles data, please consult the privacy policies of OpenAI (ChatGPT), Anthropic (Claude), Google (Gemini), Granola, Fathom and Descript.
5.9 Your right to decline AI
If you would prefer that no artificial intelligence tool be used in our work together, you can tell us at any time. We will adapt, with no effect on the quality or the price of your accompaniment.
6. Sensitive data and session recordings
6.1 The nature of what is shared
Our work together concerns your professional activity, your inner posture and the way you make decisions. In that context you may spontaneously share information relating to your health, your intimate life, or your philosophical or spiritual convictions. Such information constitutes sensitive data within the meaning of Article 5 lit. c FADP and Article 9 GDPR.
We never solicit this information. When it is shared, it is treated with enhanced confidentiality, used solely to serve your accompaniment, and processed on the basis of your explicit consent. It is never disclosed to third parties, nor used for marketing purposes.
6.2 Audio and video recordings
No session is recorded without the prior, explicit and documented agreement of everyone present. This agreement is obtained in writing before the session, not verbally at the start of it.
You may decline to be recorded, with no consequence whatsoever for your accompaniment. You may also ask for the recording to be stopped during the session, or for an existing recording to be deleted.
6.3 Group sessions
In group formats (Momentum, Group Power Week, workshops), recording only takes place if every participant has consented. A single objection is enough to cancel the recording for the whole session.
We also remind participants in group formats that they are mutually bound by confidentiality: what is shared in the circle stays in the circle. Recording, capturing or sharing group exchanges is not permitted.
6.4 Access and storage
Only Valérie Demont has access to recordings, transcripts and session notes. They are kept in a space protected by a password and two-factor authentication, and deleted according to the periods set out in section 12.
7. International data transfers
Some of our providers (Mailchimp, Substack, Stripe, PayPal, Google, Zoom, Calendly, Meta, OpenAI, Anthropic, Granola, Fathom, Descript) are established in the United States or outside Switzerland and the European Economic Area. Where your data is transferred to these providers, such transfers are governed by:
- the Standard Contractual Clauses of the European Commission, supplemented where appropriate by additional technical measures;
- the EU–U.S. Data Privacy Framework and its Swiss extension, where the provider is certified under it;
- the equivalent safeguards provided for by the Swiss FADP for transfers from Switzerland.
Our main hosting provider, Infomaniak Network SA, is Swiss, and our operational data is stored in Switzerland wherever possible.
8. Sharing with third parties
We do not sell, trade or rent your personal information to any third party for commercial purposes.
The only data sharing that takes place is that strictly necessary to deliver our services: payment, newsletter distribution, video conferencing, transcription, hosting, accounting. Each of these providers acts as a processor, under a written agreement compliant with Article 9 FADP and Article 28 GDPR, and is not permitted to use your data for its own purposes.
We may also disclose data where the law requires it, or in order to establish, exercise or defend legal claims.
9. Information security
We implement a range of security measures to safeguard your personal information. We use encryption (SSL/HTTPS certificate) to protect sensitive information transmitted online. We also protect your information offline. The computers and servers used to store personal information are kept in a secure environment, protected by strong passwords and two-factor authentication. However, given the risks inherent to the internet, we cannot guarantee absolute security.
Website security
This site uses the Solid Security plugin (formerly iThemes Security) to protect against external attacks:
- Visiting the login page sets a temporary cookie that supports compatibility with other login methods. This cookie contains no personal data and expires after one hour.
- Visitors’ IP addresses, logged-in user IDs and login attempt identifiers are recorded conditionally to check for malicious activity. This information is kept for 60 days.
- This site is scanned for malware and vulnerabilities. No personal data is collected during these scans.
- Security logs are kept for 60 days.
- This site is part of a network of sites that protect one another against brute-force attacks. For this purpose, the IP address of visitors attempting to log in is shared with a service provided by SolidWP / StellarWP.
Hosting
Our website is hosted by Infomaniak Network SA, in Carouge (GE), Switzerland.
10. Data breaches
Despite our precautions, a security breach resulting in the loss, disclosure of, or unauthorised access to personal data remains possible.
Should such a breach occur and be likely to result in a high risk to your rights and personality, we undertake to:
- notify the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible, in accordance with Article 24 FADP;
- notify the competent European supervisory authority within 72 hours where the GDPR applies;
- inform you directly and without delay where the breach concerns you and presents a high risk to you, setting out the nature of the incident, its likely consequences and the measures taken.
11. Cookies
A cookie is a small data file downloaded onto your device when you visit a website. It is then sent back to the originating website on each subsequent visit, or to another website able to recognise it.
Technical, functional and session cookies. Necessary for navigation and for the site’s core functions (basket, preferences, security). We may place these without your consent, as the site cannot work without them.
Analytics, statistics and marketing cookies. These measure site usage, open rates, click rates and bounce rates. They are only placed with your explicit consent, given through our privacy preferences banner. Declining is as easy as accepting.
Managing cookies. You can change or withdraw your consent at any time via the “Privacy Preferences” link at the bottom of every page. You can also delete cookies through your browser settings. Our site may not function correctly if all cookies are disabled.
12. How long we keep your data
We keep your data only for as long as strictly necessary for the purpose for which it was collected.
| Type of data | Retention period |
|---|---|
| Order and billing data | 10 years (Swiss legal obligation, accounting and tax) |
| Newsletter data | Until you unsubscribe, then deleted within 30 days |
| Contact form data | 3 years after our last exchange |
| Email correspondence | 3 years after our last exchange, unless linked to an ongoing contract |
| Audio and video recordings of sessions | Deleted as soon as the transcript is produced, and at the latest 3 months after the session |
| Session transcripts and notes | For the duration of your accompaniment, then a maximum of 12 months, unless you request otherwise |
| Anonymised or aggregated insights (section 5.5) | No time limit, as this data no longer allows you to be identified and therefore no longer constitutes personal data |
| Analytics cookies (GA4) | 14 months maximum |
| Security logs | 60 days |
| Published comments and reviews | For as long as they remain published, unless deletion is requested |
Once these periods expire, the data is securely deleted or irreversibly anonymised.
13. Your rights
At any time, and free of charge, you have the right to:
- Access your personal data and request a copy of it;
- Rectify your data if it is inaccurate or incomplete;
- Erase your data (right to be forgotten), within the limits of legal retention obligations;
- Restrict the processing of your data or object to it, in particular for direct marketing or profiling;
- Request portability of your data, that is, receive it in a structured, machine-readable format;
- Withdraw your consent at any time, without affecting the lawfulness of prior processing;
- Request human intervention and contest any decision that would be taken by automated means;
- Decline the use of artificial intelligence tools in our work together;
- Lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or with the data protection authority of your country of residence in the European Union or the United Kingdom.
To exercise these rights, write to us at the address given in section 17. We respond within 30 days. We may need to verify your identity before acting, in order to protect your data against fraudulent requests.
14. Minors
Our services are intended exclusively for adults (18 years and over). We do not knowingly collect data concerning children or young people under 16. If you become aware that a minor’s data has been sent to us in error, please contact us so that we can delete it immediately.
15. Regulatory framework
This privacy statement is based on:
- the Swiss Federal Act on Data Protection (FADP) and its implementing ordinance, in force since 1 September 2023;
- the General Data Protection Regulation (GDPR) of the European Union, applicable to our visitors and clients residing in the EU;
- the UK GDPR and the Data Protection Act 2018, for our clients residing in the United Kingdom;
- the European Artificial Intelligence Act (Regulation (EU) 2024/1689), in particular its transparency obligations applicable since 2 August 2026, insofar as our services are directed at people located in the European Union;
- the Swiss Unfair Competition Act (UCA), Article 3 para. 1 lit. o, for the sending of commercial communications by electronic means.
Switzerland does not currently have general legislation specific to artificial intelligence. A draft regulation, intended to implement the Council of Europe Convention on AI, is being prepared. We will update this policy once it comes into force.
16. Records and impact assessment
We maintain an internal record of our processing activities. Where a processing activity is likely to result in a high risk to your personality or fundamental rights, in particular because of the use of artificial intelligence on sensitive data, we carry out a data protection impact assessment in accordance with Article 22 FADP and Article 35 GDPR.
17. Contact
For any question about our privacy policy, or to exercise your rights:
Greenheart.business Sàrl
Valérie Demont
Chemin des Cygnes 9
1007 Lausanne, Switzerland
info@valeriedemont.ch
CHE-425.604.630
18. Applicable law and jurisdiction
We undertake to comply with Swiss legislation, in particular the FADP, as well as with the GDPR for our visitors and clients residing in the European Union. In the event of a dispute, Swiss law applies and the courts of the Canton of Vaud have jurisdiction, subject to any mandatory consumer protection provisions applicable in your country of residence.
19. Changes to this privacy policy
We reserve the right to amend this policy to reflect changes in our practices, in the tools we use and in legislation. Any substantial change will be notified to you by email if you are subscribed to our newsletter or are an active client, or through a visible notice on the website.
Last updated: 3 August 2026.