Last update
Last update
July 21, 2026

Privacy Policy

Privacy Policy

Privacy Policy

How Rebels AI AG collects, uses and protects your personal data

How Rebels AI AG collects, uses and protects your personal data

How Rebels AI AG collects, uses and protects your personal data

This Privacy Policy explains how Rebels AI AG (“we”, “us”) collects, uses and discloses your personal data as a controller. We process your data exclusively in accordance with the applicable data protection laws — in particular the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR). Effective date: July 21, 2026.

This Privacy Policy explains how Rebels AI AG (“we”, “us”) collects, uses and discloses your personal data as a controller. We process your data exclusively in accordance with the applicable data protection laws — in particular the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR). Effective date: July 21, 2026.

This Privacy Policy explains how Rebels AI AG (“we”, “us”) collects, uses and discloses your personal data as a controller. We process your data exclusively in accordance with the applicable data protection laws — in particular the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR). Effective date: July 21, 2026.

1. Data Controller
1. Data Controller

The data controller responsible for processing your personal data is:

Rebels AI AG
Schneeglöggliweg 20
8048 Zürich, Switzerland
Email: info@rebels.tech

The data controller responsible for processing your personal data is:

Rebels AI AG
Schneeglöggliweg 20
8048 Zürich, Switzerland
Email: info@rebels.tech

2. What Personal Data Do We Process, For What Purposes and On What Legal Basis?
2. What Personal Data Do We Process, For What Purposes and On What Legal Basis?

2.1 Providing our services — creation of a user account, sign-ups and use of our platform. When you sign up for our services (create a user account, join our waitlist or use our platform) we collect contact information (name, address, email address, phone number), payment data (such as billing details, where applicable) and communication data (messages and documents you exchange with us). We process this data to provide our services and issue invoices. Legal basis: art. 6(1)(b) GDPR (performance of the contract).

2.1 Communication with support and reviews. When you contact us — by telephone, email, via our website or LinkedIn — we process the personal data you provide in the course of that communication. If you leave a review of our services on a publicly available website, the respective platform provider is the controller of that data. Legal basis: art. 6(1)(b) GDPR where necessary for the performance of a contract, otherwise our overriding interest in providing our services and answering your requests, art. 6(1)(f) GDPR.

2.2 Scientific research, statistical analyses and improvement of AI models. The use of personal data for scientific research, statistical analyses or the training and improvement of AI models takes place only if you have given your separate explicit consent (art. 9(2)(a) GDPR). Before obtaining such consent, we will provide you with further information about the data concerned, the purposes, any pseudonymisation or anonymisation, the retention period and your rights. To the extent that synthetic data does not suffice, we may use anonymised and/or aggregated information to further develop and improve our services. Legal basis: our overriding interest in improving our services, art. 6(1)(f) GDPR.

2.3 Use of the website and platform. While you access our website or platform we process device information (IP address, device type, operating system, browser type), usage data (domain name, user settings, session ID, authentication data, visit time and interactions, demographic characteristics and interests) and location data derived from your IP address. Legal basis: art. 6(1)(b) and (f) GDPR.

2.4 Newsletter subscription and marketing. If you subscribe to our newsletter we collect and process your email address to send you updates and news about our services. Legal basis: your consent (art. 6(1)(a) GDPR) — revocable at any time via the “unsubscribe” link in every newsletter, or by contacting us as described in section 9. We may also inform you about our latest developments and invite you to participate in surveys. Legal basis: our overriding interest pursuant to art. 6(1)(f) GDPR, or your consent where you participate in a survey.

2.5 Legal and other purposes. We also process your personal data to fulfil legal obligations and to assert, defend or enforce claims, or where we have any other overriding interest to do so. Legal basis: art. 6(1)(c) and (f) GDPR.

Providing our services. When you sign up for our services (create a user account, join our waitlist or use our platform) we collect contact information (name, address, email address, phone number), payment data (such as billing details) and communication data (messages and documents you exchange with us). We process this data to provide our services and issue invoices. Legal basis: art. 6(1)(b) GDPR (performance of the contract).

Support and communication. When you contact us — by telephone, email, via our website or LinkedIn — we process the personal data you provide in the course of that communication (e.g. your name, contact details and the content of the communication). If you leave a review of our services on a publicly available website, the respective platform provider is the controller of that data. Legal basis: art. 6(1)(b) and (f) GDPR.

Research and improvement of AI models. The use of personal data for scientific research, statistical analyses or the training and improvement of AI models takes place only if you have given your separate explicit consent (art. 9(2)(a) GDPR). Before obtaining such consent, we will provide you with further information about the data concerned, the purposes, any pseudonymisation or anonymisation, the retention period and your rights. To the extent that synthetic data does not suffice, we may use anonymised and/or aggregated information to further develop and improve our services (art. 6(1)(f) GDPR).

Website and platform use. While you access our website or platform we process device information (IP address, device type, operating system, browser type), usage data (domain name, user settings, session ID, authentication data, visit time and interactions) and location data derived from your IP address — to ensure proper functioning, to further develop and improve our website and platform, and to provide a seamless, personalised experience. Legal basis: art. 6(1)(b) and (f) GDPR.

Newsletter and marketing. If you subscribe to our newsletter or updates, we process your email address to send you news about our services, based on your consent (art. 6(1)(a) GDPR) — revocable at any time via the unsubscribe link in every mailing or by contacting us. We may also inform you about our latest developments (including new features, products and services) and invite you to participate in surveys (art. 6(1)(f) GDPR).

Legal and other purposes. We also process personal data to fulfil legal obligations and to assert, defend or enforce claims. Legal basis: art. 6(1)(c) and (f) GDPR.

3. Cookies and Other Tracking Tools
3. Cookies and Other Tracking Tools

3.1 What are cookies? Cookies are small text files placed on your browser or device that allow us to recognise your browser or device and store certain information. They are widely used across the internet to improve functionality, enhance user experience, and collect certain personal data about site usage.

3.2 What data do we process when we use cookies and other tracking tools? We use cookies to gather information about the use of our website and platform, and to analyse our marketing communications. The following data may be collected: domain name, user settings (e.g. language preferences), session ID, IP address, authentication data, visit time (time stamp) and other metadata.

3.3 How do we use cookies and other tracking tools, and why? We use necessary cookies, required for the functionality of the website and our platform; analytic cookies, which track how you use our website and platform to help us improve functionality, content and user experience; and marketing/third-party cookies, used to analyse your use of the website and to show adverts that are relevant to you. Emails we send may contain tracking pixels to measure open rates and engagement.

3.4 On what legal basis do we use cookies and other tracking tools? Necessary cookies are used on the basis of art. 6(1)(f) GDPR (legitimate interest). Analytics and marketing cookies are used only on the basis of your prior explicit consent, pursuant to art. 6(1)(a) GDPR, obtained through our cookie banner.

3.5 How can you revoke your consent or manage your cookie settings? You may revoke your consent or manage and change your cookie preferences at any time via the cookie settings (our cookie banner) on our website. You can also manage your general cookie settings in your browser, and delete previously installed cookies — including those that stored your consent. Information on managing cookies is available in the help pages of Google Chrome, Mozilla Firefox, Apple Safari and Microsoft Edge.

Cookies are small text files placed on your browser or device that allow us to recognise it and store certain information. We use necessary cookies (required for the functionality of the website and platform), analytics cookies (to understand how visitors use our website and platform — for example which pages are visited, how users navigate and where technical or usability issues occur) and marketing cookies (to show adverts that are relevant and appealing to you). Emails we send may contain tracking pixels to measure open rates and engagement.

Necessary cookies rely on our legitimate interest in a properly functioning website (art. 6(1)(f) GDPR). Analytics and marketing cookies are used only with your prior explicit consent, obtained through our cookie banner (art. 6(1)(a) GDPR). You can revoke your consent or change your preferences at any time via the cookie settings on our website, and you can manage or delete cookies in your browser settings.

Cookies are small text files placed on your browser or device that allow us to recognise it and store certain information. We use necessary cookies (required for the functionality of the website and platform), analytics cookies (to understand how visitors use our website and platform — for example which pages are visited, how users navigate and where technical or usability issues occur) and marketing cookies (to show adverts that are relevant and appealing to you). Emails we send may contain tracking pixels to measure open rates and engagement.

Necessary cookies rely on our legitimate interest in a properly functioning website (art. 6(1)(f) GDPR). Analytics and marketing cookies are used only with your prior explicit consent, obtained through our cookie banner (art. 6(1)(a) GDPR). You can revoke your consent or change your preferences at any time via the cookie settings on our website, and you can manage or delete cookies in your browser settings.

4. Social Media Plugins
4. Social Media Plugins

Our website and platform may contain social media plugins (such as LinkedIn, Instagram or Facebook) that allow you to connect with your social media accounts. These plugins may collect information about your browsing behaviour and send it to the social media provider. When you interact with these plugins, the social media provider may receive information that you’ve visited our website, and — if you’re logged into your account while browsing — may link this information to your profile. In these cases, the respective social media platform provider is the controller of the personal data shared with them; we encourage you to review their privacy notices for more information.

Our website may contain social media plugins (such as LinkedIn, Instagram or Facebook) that allow you to connect with your social media accounts. These plugins may collect information about your browsing behaviour and send it to the social media provider; if you are logged into your account while browsing, the provider may link this information to your profile. The respective platform provider is the controller of the personal data shared with them — we encourage you to review their privacy notices.

Our website may contain social media plugins (such as LinkedIn, Instagram or Facebook) that allow you to connect with your social media accounts. These plugins may collect information about your browsing behaviour and send it to the social media provider; if you are logged into your account while browsing, the provider may link this information to your profile. The respective platform provider is the controller of the personal data shared with them — we encourage you to review their privacy notices.

Our website may contain social media plugins (such as LinkedIn, Instagram or Facebook) that allow you to connect with your social media accounts. These plugins may collect information about your browsing behaviour and send it to the social media provider; if you are logged into your account while browsing, the provider may link this information to your profile. The respective platform provider is the controller of the personal data shared with them — we encourage you to review their privacy notices.

5. Do We Share Your Personal Data With Third Parties?
5. Do We Share Your Personal Data With Third Parties?

In certain circumstances, we share your personal data with third parties, e.g. in connection with the provision of our services, if we have a legal obligation to do so, if you have consented, or if this is in our legitimate interest. These third parties may be located in Switzerland or abroad:

  • Third-party service providers — payment service providers, IT/software service providers including hosting, storage, support, maintenance and security providers, and CRM providers

  • Accountants and advisors — strategic consultants, lawyers and tax advisors, to the extent they require such information to provide their services to us

  • Competent authorities and courts — for law enforcement purposes if required by law, or to establish, exercise or enforce legal rights

  • Third-party organisations — in the context of reorganisations, restructurings or transactions such as a merger, consolidation or sale of assets, or in the event of insolvency or bankruptcy

  • Other — where we believe it necessary to investigate, prevent or take action regarding illegal activities, suspected fraud, emergencies involving potential threats to physical safety, or violations of our Terms of Use

We do our best to always keep your data confidential, e.g. through confidentiality agreements or other data protection undertakings with those who have access to your data. Where third parties process personal data on our behalf as processors, we have entered into data processing agreements with them in accordance with art. 28 GDPR.

In certain circumstances we share your personal data with third parties, which may be located in Switzerland or abroad:

  • Third-party service providers — payment, IT/software, hosting, storage, support, maintenance, security and CRM providers

  • Accountants and advisors — strategic consultants, lawyers and tax advisors, to the extent they require it

  • Competent authorities and courts — where required by law or to establish, exercise or enforce legal rights

  • Other organisations — in the context of reorganisations, restructurings or transactions such as a merger or sale of assets

  • Where necessary to investigate, prevent or take action regarding illegal activities, suspected fraud or threats to any person’s safety

Where third parties process personal data on our behalf, we have entered into data processing agreements in accordance with art. 28 GDPR. Rebels AI AG is headquartered in Switzerland, and your data is primarily processed within Switzerland and the EEA. Where data is transferred to a country with a lower level of data protection (such as the UK or the USA), we ensure appropriate safeguards — the Swiss-U.S. or EU-U.S. Data Privacy Framework where applicable, and/or the EU Standard Contractual Clauses including a Swiss addendum. You may request a copy of these safeguards at info@rebels.tech.

In certain circumstances we share your personal data with third parties, which may be located in Switzerland or abroad:

  • Third-party service providers — payment, IT/software, hosting, storage, support, maintenance, security and CRM providers

  • Accountants and advisors — strategic consultants, lawyers and tax advisors, to the extent they require it

  • Competent authorities and courts — where required by law or to establish, exercise or enforce legal rights

  • Other organisations — in the context of reorganisations, restructurings or transactions such as a merger or sale of assets

  • Where necessary to investigate, prevent or take action regarding illegal activities, suspected fraud or threats to any person’s safety

Where third parties process personal data on our behalf, we have entered into data processing agreements in accordance with art. 28 GDPR. Rebels AI AG is headquartered in Switzerland, and your data is primarily processed within Switzerland and the EEA. Where data is transferred to a country with a lower level of data protection (such as the UK or the USA), we ensure appropriate safeguards — the Swiss-U.S. or EU-U.S. Data Privacy Framework where applicable, and/or the EU Standard Contractual Clauses including a Swiss addendum. You may request a copy of these safeguards at info@rebels.tech.

6. Do We Transfer Your Personal Data Abroad?

Rebels AI AG is headquartered in Switzerland. Accordingly, your personal data is primarily processed within Switzerland and the European Economic Area (EEA).

We may transfer your personal data to third parties located abroad in connection with the purposes described in this Privacy Policy, such as the UK and/or USA. Where these third parties are located in a country with a lower level of data protection than Switzerland, the EEA or the UK — as is the case with the US — we ensure that appropriate safeguards are in place. We rely on the Swiss-U.S. or EU-U.S. Data Privacy Framework, respectively, where applicable, and/or implement appropriate safeguards, in particular the EU Standard Contractual Clauses (SCCs) including a Swiss or other addendum as required under the FADP, or other legal agreements.

You have the right to request a copy of these safeguards by contacting us at info@rebels.tech.

7. How Is Your Personal Data Protected?
7. How Is Your Personal Data Protected?

We implement appropriate technical and organisational measures to protect your personal data against, among other things, loss, unauthorised access, misuse, alteration or unlawful processing. These measures include:

  • A secure infrastructure for the storage and processing of personal data

  • End-to-end encryption of personal data, both during transmission and while at rest

  • Regular security assessments, vulnerability testing and system updates

  • Access controls ensuring that only authorised personnel have access on a need-to-know basis, supported by multi-factor authentication (MFA)

  • Redundant and geographically distributed backup systems

  • Employee training on data protection and security protocols

  • Audit trails, including the logging of all access to personal data and all modifications thereto

  • An incident response plan, including procedures for the detection, reporting and management of personal data breaches

We implement appropriate technical and organisational measures to protect your personal data, including:

  • End-to-end encryption of personal data, in transit and at rest

  • Regular security assessments, vulnerability testing and system updates

  • Access controls on a need-to-know basis, supported by multi-factor authentication

  • Redundant and geographically distributed backup systems

  • Audit trails logging all access to personal data and all modifications

  • An incident response plan for detecting, reporting and managing data breaches

We retain personal data until the contract or purpose for which it was collected has been fulfilled, in accordance with statutory retention obligations. In general: business records (e.g. invoices, contracts) are kept for ten (10) years; data processed on the basis of consent (e.g. newsletter) until consent is withdrawn; website data for a maximum of 30 days and cookie consent data for 12 months.

We implement appropriate technical and organisational measures to protect your personal data, including:

  • End-to-end encryption of personal data, in transit and at rest

  • Regular security assessments, vulnerability testing and system updates

  • Access controls on a need-to-know basis, supported by multi-factor authentication

  • Redundant and geographically distributed backup systems

  • Audit trails logging all access to personal data and all modifications

  • An incident response plan for detecting, reporting and managing data breaches

We retain personal data until the contract or purpose for which it was collected has been fulfilled, in accordance with statutory retention obligations. In general: business records (e.g. invoices, contracts) are kept for ten (10) years; data processed on the basis of consent (e.g. newsletter) until consent is withdrawn; website data for a maximum of 30 days and cookie consent data for 12 months.

8. How Long Do We Retain Your Personal Data?

Unless a more specific storage period is specified in this Privacy Policy, your personal data remains with us until the contract or other purpose for which it was collected has been fulfilled, in accordance with applicable statutory retention obligations, or until you withdraw your consent. In general, your personal data is stored for ten (10) years after our last interaction with you.

The following retention periods apply:

  • Business records (e.g. invoices or contract documents): ten (10) years

  • Newsletter data or other data processed based on your consent: until consent is withdrawn

  • Website data and cookies: a maximum of 30 days, and 12 months for cookie consent data

  • Data processed for scientific research, statistical analysis or AI model training: for the period communicated to you separately prior to obtaining your consent, or until you withdraw your consent, unless the data has been anonymised

9. What Rights Do You Have?
9. What Rights Do You Have?

As a data subject, you have various rights in relation to your personal data, including the:

  • Right of access

  • Right to rectification

  • Right to erasure (“right to be forgotten”), subject to statutory retention obligations

  • In certain cases, right to restrict our processing activities

  • Right to data portability, where applicable

  • In certain cases, right to object to processing based on legitimate interests

You may also withdraw your (explicit) consent at any time; such withdrawal will not affect the lawfulness of any processing carried out prior to the withdrawal on the basis of that consent. You may exercise your rights by contacting us at info@rebels.tech. We will respond as soon as possible and, in any event, within one month of receipt of your request. At our discretion, we may request proof of identity to process your request.

We may refuse or restrict the exercise of these rights on legal grounds or as permitted under data protection laws. If you believe we are not processing your personal data in accordance with applicable data protection laws, you have the right to lodge a complaint with a competent supervisory authority: for Switzerland, the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern, www.edoeb.admin.ch; for residents of Germany, the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit, Graurheindorfer Straße 153, 53117 Bonn, www.bfdi.bund.de.

As a data subject you have the right to:

  • Access your personal data

  • Rectify inaccurate data

  • Erasure (“right to be forgotten”), subject to statutory retention obligations

  • Restrict our processing activities in certain cases

  • Data portability, where applicable

  • Object to processing based on legitimate interests

  • Withdraw your consent at any time, without affecting the lawfulness of prior processing

You may exercise your rights by contacting us at info@rebels.tech — we will respond within one month. You also have the right to lodge a complaint with a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern (www.edoeb.admin.ch); for residents of Germany, the competent authority listed at www.bfdi.bund.de/anschriften.

As a data subject you have the right to:

  • Access your personal data

  • Rectify inaccurate data

  • Erasure (“right to be forgotten”), subject to statutory retention obligations

  • Restrict our processing activities in certain cases

  • Data portability, where applicable

  • Object to processing based on legitimate interests

  • Withdraw your consent at any time, without affecting the lawfulness of prior processing

You may exercise your rights by contacting us at info@rebels.tech — we will respond within one month. You also have the right to lodge a complaint with a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern (www.edoeb.admin.ch); for residents of Germany, the competent authority listed at www.bfdi.bund.de/anschriften.

10. Can This Privacy Policy Be Amended?
10. Can This Privacy Policy Be Amended?

We reserve the right to update and amend this Privacy Policy from time to time to reflect changes in the way we process your personal data or due to changes in legal requirements. Any changes will be published on this website — please check back regularly to stay informed. Material changes will be communicated through the website, by email and/or other suitable means. Questions? Contact us at info@rebels.tech.

We reserve the right to update and amend this Privacy Policy from time to time to reflect changes in the way we process your personal data or in legal requirements. Changes are published on this page; material changes will be communicated through the website, by email or other suitable means. Questions? Contact us at info@rebels.tech.

We reserve the right to update and amend this Privacy Policy from time to time to reflect changes in the way we process your personal data or in legal requirements. Changes are published on this page; material changes will be communicated through the website, by email or other suitable means. Questions? Contact us at info@rebels.tech.

We reserve the right to update and amend this Privacy Policy from time to time to reflect changes in the way we process your personal data or in legal requirements. Changes are published on this page; material changes will be communicated through the website, by email or other suitable means. Questions? Contact us at info@rebels.tech.

Imprint

Rebels AI AG
Schneeglöggliweg 20
8048 Zürich, Switzerland
Email: info@rebels.tech

Get in touch

Have an ambitious idea, a problem worth solving, or a future you want to create? We’d love to hear your story and explore how Rebels can help turn vision into reality.

Join the Rebellion

First name

Last name

Email

Phone

LinkedIn

Message

Get in touch

Have an ambitious idea, a problem worth solving, or a future you want to create? We’d love to hear your story and explore how Rebels can help turn vision into reality.

Join the Rebellion

First name

Last name

Email

Phone

LinkedIn

Message

Get in touch

Have an ambitious idea, a problem worth solving, or a future you want to create? We’d love to hear your story and explore how Rebels can help turn vision into reality.

Join the Rebellion

First name

Last name

Email

Phone

LinkedIn

Message