Thalyra

Privacy Policy

This policy applies to thalyra.com (checkout/landing) and portal.thalyra.com (course portal). It is drafted to meet the requirements of the revised Swiss Data Protection Act (revFADP) as well as — for visitors from the EU/EEA — the EU General Data Protection Regulation (GDPR), since Thalyra courses are also sold to consumers in the EU.

Deutsche Version →

Data controller under Art. 5(j) revFADP / Art. 4(7) GDPR
CuraCap Schweiz GmbH
Schänzlistrasse 37 · CH-2545 Selzach · Switzerland
Commercial register of the Canton of Solothurn · UID CHE-158.321.901
Email: info@curacap.biz

"Thalyra" is a brand of CuraCap Schweiz GmbH.

1. General & Scope

We take the protection of your personal data seriously and treat it confidentially, in line with the revised Swiss Data Protection Act (revFADP) and — for visitors from the EU/EEA — the GDPR. This policy explains what personal data we collect in connection with the purchase and use of Thalyra mini-courses, how we use it, and what rights you have.

Personal data is any data that can be used to identify you personally (e.g. name, email address, IP address, purchase data).

2. Two systems, one provider

Thalyra consists of two technically separate systems run by the same provider:

  • thalyra.com — checkout and landing page, hosted on Vercel Inc., runs the purchase flow via Stripe.
  • portal.thalyra.com — the course portal where you access your course content after purchase. It runs on the GoHighLevel/HighLevel Inc. platform (see section 5).

Both systems process your data either as our processor or jointly as controllers with us; below we specify who receives which data for which purpose.

3. Hosting of thalyra.com (Vercel Inc.)

thalyra.com is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. On every visit, technical log data is processed (IP address, date/time, requested URL, HTTP status code, data volume transferred, referrer, user agent).

A transfer to third countries (in particular the USA) takes place. Legal basis: Art. 31(1)(e) revFADP resp. Art. 6(1)(f) GDPR (legitimate interest in stable, secure delivery of the website). We have a data processing agreement with Vercel as well as EU Standard Contractual Clauses (Art. 46 GDPR) for the third-country transfer.

4. Payment processing (Stripe)

The purchase runs on a checkout page hosted by Stripe. You enter your payment data (card number, IBAN, Twint/PayPal account information, etc.) exclusively at Stripe — it never reaches our servers. We only process the payment outcome (paid/cancelled), a Stripe transaction reference, and the billing data you enter at checkout (email, name, billing address if applicable, chosen currency CHF/EUR).

Payment processor: Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Dublin 2, Ireland) and its US parent company Stripe, Inc. (USA). A transfer to the USA is possible. We have a data processing agreement and EU Standard Contractual Clauses with Stripe. Stripe's privacy notice: stripe.com/privacy.

Legal basis: Art. 31(2)(a) revFADP (contract performance); for EU visitors additionally Art. 6(1)(b) GDPR.

5. Course portal (GoHighLevel / HighLevel Inc.)

After a successful purchase, we set up your access to the course portal at portal.thalyra.com. This portal is technically operated by HighLevel LLC (400 N Saint Paul St, Suite 920, Dallas, TX 75201, USA) via its client-portal product. We transfer your email address, your name, and details of the purchased course so that the corresponding course access ("offer") can be unlocked for you.

Login is passwordless via a magic-link email: you receive a time-limited login link by email; no separate password is required or stored by us.

HighLevel LLC is a US provider; your data is transferred to and stored in the USA. We have a data processing agreement and EU Standard Contractual Clauses (Art. 46 GDPR) with HighLevel for the third-country transfer. Because the course portal is technically operated by HighLevel itself (own cookies, own security mechanisms for video delivery), HighLevel's own privacy notice additionally applies to the portal itself.

Legal basis: Art. 31(2)(a) revFADP (contract performance — you purchased a course and receive access to it); for EU visitors additionally Art. 6(1)(b) GDPR.

6. CRM and customer data

We store your email address, name, and purchase data (course purchased, timestamp, amount/currency) in our CRM (GoHighLevel — the same platform as the course portal, see section 5) for contract performance, customer support, and course-related communication (e.g. access emails, course-progress reminders).

We do not share your data with third parties for advertising purposes and we do not sell your personal data.

7. Cookies

thalyra.com itself currently sets no marketing or analytics cookies. During payment, the Stripe-hosted checkout page sets technically necessary session cookies required for secure payment processing (see Stripe's privacy notice, section 4). portal.thalyra.com is operated independently by HighLevel and sets its own technically necessary cookies there (login session, magic-link validity); HighLevel's own privacy notice applies in that respect.

8. Recipients and third-country transfers

Recipients of your personal data are: Vercel Inc. (hosting of thalyra.com), Stripe Payments Europe Ltd. / Stripe Inc. (payment processing), HighLevel LLC (course portal + CRM).

Transfers to third countries (in particular the USA) are made exclusively using EU Standard Contractual Clauses and/or — where certified — under the EU-US Data Privacy Framework, each supplemented by technical and organisational measures.

9. Retention period

We retain purchase-related data (in particular invoice data) for ten years pursuant to Art. 958f OR (Swiss Code of Obligations). Portal access data remains in place for as long as your course access is active; upon request we delete or anonymise your customer profile in the CRM as soon as no statutory retention obligations apply.

10. Your rights under the revFADP

You have the following rights against us: right of access (Art. 25 revFADP), right to data portability (Art. 28 revFADP), right to rectification (Art. 32 revFADP), and right to erasure of your data. To exercise these rights, an informal message to info@curacap.biz is sufficient. You also have the right to complain to the Federal Data Protection and Information Commissioner (FDPIC, Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch).

11. Your rights under the GDPR (visitors from the EU/EEA)

For visitors habitually resident in the EU/EEA, the GDPR additionally applies. You have the following rights against us: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection to processing based on legitimate interest (Art. 21), and the right to lodge a complaint with a supervisory authority at your place of residence or the place of the alleged infringement.

12. Data security

We use TLS encryption (HTTPS) for all data transfers between your browser and our servers or those of our processors.

13. Note on AI-generated content

This website and parts of the Thalyra course content contain some AI-generated content (text, image, video). This notice also appears in the footer of every page. AI-generated content is reviewed by a subject-matter expert before publication; it does not replace individual professional or legal advice.

14. Changes to this privacy policy

We update this policy whenever our data processing or the applicable legal requirements change. The version published on this page at any given time is authoritative.

Last updated: 30 July 2026

← Thalyra
ImpressumDatenschutzAGBPrivacyTerms
Diese Website enthält teils mit KI erstellte Inhalte (Text, Bild, Video).