Skip to content

Privacy Policy

This policy explains how Stylla collects personal data about you, how we use, store, share, modify and delete it, how we protect it, and how you can exercise your rights. It applies to everyone we interact with in the course of our business: visitors to our website (our "Site"), holders of a customer account, newsletter registrants, customers who buy from us through a third-party marketplace, business partners, suppliers and investors.

This policy is published in several language versions. Each version is intended to have the same meaning, and you may rely on the version in the language in which you concluded your contract with us.

1. Who we are and how to contact us

Stylla ("Stylla", "we", "us", "our") is a brand of Swiss Prime Lab SA, a company incorporated under Swiss law, registered in the Commercial Register of the Canton of Vaud under number CHE-220.856.620, with its registered office at Rue de la Grotte 6, 1003 Lausanne, Switzerland.

For any question about the processing of your personal data or to exercise your rights:

  • Email: info@styllacare.com
  • Telephone: +41 21 588 11 49
  • Post: Swiss Prime Lab SA, Rue de la Grotte 6, 1003 Lausanne, Switzerland

GDPR representative for the EU: Timelex CV/SC (incorporated and existing under the laws of Belgium under number 0890.217.005), with registered office at rue Joseph Stevensstraat 7, 1000 Brussels, Belgium. Email: geert.somers@timelex.eu.

2. Our role in the processing

When we process your personal data we act as data controller, which means we determine the purposes and the means of the processing described in this policy. We do so in accordance with:

  • the General Data Protection Regulation (GDPR), for residents of the European Economic Area (EEA) and the United Kingdom;
  • the Swiss Federal Act on Data Protection (FADP), for Swiss residents.

In some cases we use processors (third-party service providers) to carry out specific processing on our behalf. These processors are bound by written agreements requiring confidentiality, security and compliance with our instructions and with applicable law. We do not disclose your personal data to third parties unless its confidentiality, integrity, availability and security are guaranteed.

3. Buying from us through a marketplace

Our products may also be offered for sale on third-party marketplaces operated by other companies.

When you buy a Stylla product on a third-party marketplace, the marketplace operator collects and processes your personal data as an independent data controller, under its own privacy policy and under its own responsibility. That policy, and not this one, governs the data the marketplace operator collects from you, including the data collected when you create an account on the marketplace, browse it or pay for your order.

Stylla receives from the marketplace operator only the data needed to fulfil, invoice and support your order, namely your name, your delivery address, your contact details and the details of your order. Stylla processes that data as data controller for those purposes only, on the basis of the performance of the contract (Article 6(1)(b) GDPR) and of its legal obligations (Article 6(1)(c) GDPR), in particular accounting and tax obligations. The rest of this policy applies to that processing.

Where you buy through a marketplace, the payment is processed by the marketplace operator and its payment service provider, which acts as an independent controller for that payment data. Stylla does not receive or store your card details.

4. When and how we collect your personal data

We collect most of your personal data directly from you, in particular:

  • when you create a customer account on our Site, including login credentials sent directly or separately, or register using a social media plugin, subject to that platform's terms;
  • when you place an order, including the contact and address details needed to deliver the products;
  • when you contact our support service about a warranty question, an after-sales issue or a withdrawal request; we may ask for additional information to confirm that you are the customer;
  • when you write to us by e-mail, webchat, contact form or instant messenger, in which case we collect at least your full name and e-mail address, may ask for further information to confirm your identity, and may temporarily save the conversation to improve customer service;
  • when you mention, rate or comment on Stylla on social networks;
  • when you call us: where permitted and after informing you, we may record calls to improve our customer support.

We also collect some data automatically when you use our Site: your IP address, unique device identifiers, location data, information derived from cookies stored on your device, and information about the pages you visit, the search terms you enter and the links you click.

Some data reaches us from third parties rather than from you (Article 14 GDPR). This is the case in particular for the fulfilment data transmitted to us by marketplace operators, and for demographic and behavioural data provided by advertising partners on the basis of the consent they have obtained from you.

Please do not share or transmit personal, confidential or sensitive data about other people through free-form text or instant messaging functions on our Site, unless you are authorised to do so and have informed the persons concerned of the processing of their data.

5. What data we use, why, on what legal basis, and for how long

Data Why we use it Legal basis How long we keep it
Contact and account data (last name, first name, e-mail, postal address, telephone, account and login details) Create and manage your customer account; manage the customer relationship and our contract with you; provide the products and services you request; respond to your requests; facilitate and personalise your use of the Site; contact you at your request or with your consent, for example about a problem with the Site Performance of the contract (Article 6(1)(b) GDPR); explicit consent for subscriptions (Article 6(1)(a) GDPR); legitimate interest in efficient account management (Article 6(1)(f) GDPR) For the duration of your account, your use of the Site or your contract with us, after which the data is deleted or anonymised, except where a legal retention duty applies. Where a request does not lead to a contract, the data is deleted once the request is resolved and no further follow-up is required
Order and transaction data (order details, products, delivery information, invoices, transaction history) Process your orders and deliveries; invoice you; provide assistance with warranties and claims; meet accounting, tax and administrative obligations; respond to requests from the competent authorities Performance of the contract (Article 6(1)(b) GDPR); compliance with a legal obligation (Article 6(1)(c) GDPR) For the duration of the contractual relationship, then deleted or anonymised. Invoices, order records and other accounting and tax vouchers are kept for 10 years under article 958f of the Swiss Code of Obligations (see section 13)
Payment data (bank details, payment status, transaction history) Manage and validate payments; issue refunds; send reminders in the event of non-payment of invoices; prevent fraud; meet legal obligations Performance of the contract (Article 6(1)(b) GDPR); compliance with a legal obligation (Article 6(1)(c) GDPR) Card details are held by our payment service provider under its own policies and only for as long as necessary to validate transactions or meet legal obligations. We do not store your card details. Accounting and tax documents are kept for 10 years under article 958f of the Swiss Code of Obligations
Professional (B2B) contact data (last name, first name, professional e-mail, professional telephone of the staff of our business partners, suppliers, veterinary practices, pharmacies and pet shops) Facilitate communication with our business partners and suppliers; manage the contractual relationship, including billing and order management. This data is shared with business partners and suppliers only where necessary for the business relationship Performance of the contract (Article 6(1)(b) GDPR); legitimate interest in managing our business relationships (Article 6(1)(f) GDPR) For the duration of the contractual relationship, after which it is deleted, except where a legal retention duty applies
Customer support and complaints data (your contact details, the details of your request or complaint, your interaction history) Handle support requests, warranty claims and complaints; improve our services by analysing complaints Performance of the contract (Article 6(1)(b) GDPR); legitimate interest in improving our services (Article 6(1)(f) GDPR) 2 years after closure of the request, with a possible extension where a dispute or legal claim is pending. Data relating to a dispute is kept until the dispute is resolved and, where necessary, until the expiry of the applicable limitation period
Live chat and instant messaging data (message content including attachments, and metadata such as date, time and participant identifiers) Respond to your requests, solve technical problems and provide customer support; follow up on our interactions; improve our services; prevent abuse Performance of the contract (Article 6(1)(b) GDPR); legitimate interest, including where the service is offered as a feature of our Site (Article 6(1)(f) GDPR) 12 months after your last interaction, longer where legally required
Marketing and newsletter data (e-mail address, contact details, preferences, purchase history, interactions with our campaigns) Send you newsletters, personalised offers and promotions; serve targeted advertising on third-party platforms; send you communications about products similar to those you have already purchased; share our news with customers and business partners Consent, given by opt-in (Article 6(1)(a) GDPR); legitimate interest in advertising similar products, subject to your right to opt out (Article 6(1)(f) GDPR) Until you unsubscribe or, if earlier, 13 months after your last interaction with us
Website and device data (IP address, connection logs, unique device identifiers, browser type, operating system, location data, pages visited, search terms, clicks) Ensure the security and smooth operation of our Site; detect and prevent fraud; secure our systems Legitimate interest in securing our services and our systems (Article 6(1)(f) GDPR); prior consent where the data is collected through non-essential cookies or similar technologies (Article 6(1)(a) GDPR) Connection logs: maximum 6 months, unless otherwise required by law. Cookie-derived data: maximum 13 months
Analytics and profiling data (browsing history, purchases made, clicks on marketing campaigns, technical information such as browser type and operating system, approximate geographical data, and demographic and behavioural data obtained from advertising partners) Measure the audience of our Site and produce anonymous statistical reports; analyse your interactions with the Site and collect feedback to improve our products, services and user experience; better understand our audience; personalise our offers and improve our marketing strategy; broaden our audience and run targeted campaigns Prior consent for non-essential cookies and for profiling (Article 6(1)(a) GDPR), including consent obtained on our behalf by our advertising partners; legitimate interest for strictly necessary cookies and for measuring and improving the use of our Site (Article 6(1)(f) GDPR) Maximum 13 months from collection. Data obtained from advertising partners is kept as agreed with the provider and in any event no more than 13 months. Anonymised data may be kept indefinitely

We rely on consent only where you have given it: newsletters and personalised marketing offers, non-essential advertising and analytics cookies and similar technologies, and the processing of sensitive or specific categories of data. You may withdraw your consent at any time.

6. Business analysis and reporting

To understand how our business is performing, we consolidate data from our operational systems — in particular our online store, our CRM and our accounting system — into a central cloud data warehouse, where it is analysed and presented in reporting dashboards.

  • Data concerned: order and transaction data, product data, and delivery information, linked to a customer identifier. We limit the data used in this system to what is necessary for analysis and reporting, and we do not use it to contact you.
  • Purpose: measuring sales and commercial performance, understanding demand and stock requirements, producing internal management reporting, and improving our products and service.
  • Legal basis: our legitimate interest in managing and developing our business (Article 6(1)(f) GDPR). We have assessed this interest against your rights and freedoms; the processing is internal, is not used to take decisions about you individually, and does not involve automated decision-making.
  • Recipients: our data integration provider and our cloud data warehouse and business intelligence providers, acting as processors on our instructions under data processing agreements. Access is restricted to the members of our team who need it for management reporting.
  • Location: the data warehouse used for this purpose is hosted in the European Union. Where any element of this processing involves a transfer outside the EEA or Switzerland, we rely on the standard contractual clauses approved by the European Commission, together with the Swiss addendum required by the FADP.
  • Retention: data held in the warehouse for this purpose is kept only for as long as it is needed for analysis and reporting, and in any event no longer than the retention period applying to the source data from which it is derived. Beyond that period it is deleted or anonymised, so that our reporting is based on aggregated figures rather than on data identifying you. This period is separate from, and shorter than, the ten-year legal retention period applying to invoices and accounting records. The legal obligation to keep an invoice does not entitle us to keep a copy of your data in our analysis systems for the same length of time.
  • Deletion: where you ask us to delete your personal data, or where a retention period expires, we apply the deletion to the data warehouse as well as to the source systems. Where the law requires us to keep the underlying invoice or accounting record, we keep that record for the legal period and restrict its use to that purpose alone; it is not used for analysis, reporting or marketing.
  • Your rights: you may object at any time to this processing on grounds relating to your particular situation, by writing to info@styllacare.com.

7. Data minimisation

We apply the principle of data minimisation in accordance with Article 5(1)(c) GDPR and the FADP. We collect only the personal data that is strictly necessary for the purposes set out in this policy, and when data is no longer required we delete it, anonymise it or make it securely inaccessible. In practice:

  • the mandatory fields in our forms are limited to the information needed to process your request, for example your name, e-mail address and delivery address for an order;
  • we anonymise or pseudonymise data where the purpose can be achieved without direct identifiers;
  • our retention rules ensure that data exceeding the necessary or legal period is deleted;
  • we pass on to our partners and processors only the information they need, under strict contractual guarantees.

Your data is processed proportionately, in line with the principles of privacy by design and by default.

8. Who we share your data with, and where it is stored

Only authorised persons may access your personal data. They must respect the same confidentiality and security standards as Stylla, and may use your data only for the purposes set out in this policy. Recipients may include:

  • our in-house employees and consultants, who manage the customer relationship, process orders and provide support;
  • our e-commerce platform provider, which hosts the data relating to customer accounts, orders and interactions with our online store on infrastructure located in several countries, including outside the EEA, subject to the safeguards described in section 9;
  • our payment service provider, which is PCI-DSS compliant, processes payments made on our online store and may access the information strictly necessary to secure them; Stylla does not store your card details and does not access them unless we need to refund you or send you a payment reminder;
  • our hosting and IT service providers, which host and back up our data, including for maintenance and in the event of breakdowns;
  • our CRM and marketing platform providers, which store your marketing data such as newsletter subscriptions and interactions, on servers mainly located in Europe (Ireland, France) with secure backups;
  • our ERP, which centralises information about your interactions with our teams, hosted on servers located in Switzerland and Europe with advanced encryption measures;
  • our data integration and cloud data warehouse providers, which consolidate and host our commercial data in the European Union so that we can analyse and report on our activity (see section 6);
  • auditors and logistics partners;
  • business partners, in the framework of specific collaborations, for example the distribution of targeted advertising content.

You may ask us at any time for the identity of the recipients to whom your personal data has been disclosed, by writing to info@styllacare.com. You may also ask for a copy of the contractual guarantees put in place to protect your data, such as the standard contractual clauses, and you may object to the sharing of your data, except where the sharing is necessary for the performance of a contract or to comply with a legal obligation.

9. International transfers

Your personal data may be transferred internationally, in particular where it is hosted on servers located abroad by our providers, or where we work with business partners outside the EEA, the United Kingdom or Switzerland.

Transfers within the EEA, the United Kingdom and Switzerland do not require additional safeguards, as Switzerland is recognised by the European Commission as offering an adequate level of protection equivalent to European privacy law. The complete list of countries to which transfers of personal data may be considered safe is published by the Federal Data Protection and Information Commissioner (FDPIC).

Where data is transferred to a country outside the EEA, the United Kingdom and Switzerland that is not recognised as offering an adequate level of protection, we rely on appropriate legal mechanisms:

  • the standard contractual clauses approved by the European Commission, together with the Swiss addendum where required;
  • specific transfer agreements with our partners;
  • additional technical measures, such as encryption of data in transit.

Most of our providers use data centres located in countries recognised as offering an appropriate level of protection, for example Ireland, Luxembourg and France. For providers based in the United States, we work only with entities certified under the Data Privacy Framework or meeting comparable standards. If you are located in a country that does not recognise ours as offering an adequate level of protection, we rely on these safeguards to access your personal data outside your country of residence.

10. Cookies and tracking technologies

We use cookies and similar tracking technologies (including web beacons, tracking pixels in our e-mails, and social network plugins) in the following categories:

  • strictly necessary cookies, which make the Site work, allow you to authenticate and navigate between pages and secure your online experience;
  • performance cookies, which remember your language, preferences and settings and optimise your browsing experience;
  • statistical cookies, which tell us how the Site is used, such as pages visited, time spent and actions taken, so that we can improve it;
  • social network cookies, which let you share content or connect to certain accounts; these platforms may access your browsing information on their own terms;
  • advertising and retargeting cookies, used for marketing campaigns run through third-party platforms which collect data under their own terms and privacy policies.

Strictly necessary cookies are placed on the basis of our legitimate interest. For all other cookies and tracking technologies we request your prior consent (opt-in) before placing them on your device, or grant you a right to object (opt-out), depending on the law of your country. You can view the list of cookies we use and manage or change your preferences at any time in our cookie consent management tool, available in the footer of our Site, and you can configure your browser or e-mail software to limit or refuse cookies. If you refuse cookies automatically, your preferences may not be remembered, some functionality may be lost and some areas of the Site may become inaccessible.

Our analytics and advertising providers receive data through these technologies, including your IP address and other device identifiers. For statistics we use services such as Google Analytics, so Google and similar providers also have access to that information; you can refuse and deactivate that service by following the instructions Google makes available. Cookies and cookie-derived data are kept for a maximum of 13 months.

11. Marketing communications and unsubscribing

We may send you information about our services in the context of your contract, your account or your membership, as well as news about our activities and products. If you have chosen to receive information or updates from us, you can unsubscribe from our commercial communications at any time by clicking the "unsubscribe" link in any e-mail, or by contacting us at info@styllacare.com.

12. Security and data breaches

We implement appropriate technical and organisational measures to protect your personal data against accidental or unauthorised processing, loss, disclosure, use, alteration or destruction, and we take measures allowing us to restore access to your data. These include:

  • encryption of sensitive data such as bank details, both in transit and at rest (AES 256-bit), and HTTPS/SSL protocols for secure browsing on our Site;
  • pseudonymisation and de-identification where appropriate;
  • role-based access controls and multi-factor authentication for access to internal systems, restricting access to authorised persons only;
  • firewalls and bastion hosts protecting our databases, continuous monitoring to detect and prevent intrusions, regular backups and disaster recovery plans;
  • regular awareness-raising and training of our employees on security and data protection;
  • regular tests, evaluations and periodic audits of our systems, internal processes and third-party partners, to identify and correct vulnerabilities and check that our controls remain in line with technological and regulatory developments;
  • contractual requirements on our providers: adherence to strict information security protocols and to recognised international certifications such as ISO 27001, SOC 2 and PCI-DSS compliance, signature of data protection agreements guaranteeing compliance with our standards and applicable law, and immediate notification to us of any incident affecting data processed on our behalf.

When we no longer need your information, we anonymise or delete it.

Data breach management. In the event of a personal data breach we:

  • react immediately to identify and correct the source of the breach, and implement corrective actions to prevent a recurrence;
  • notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR and Article 24 of the revised Swiss Federal Act on Data Protection (FADP). The competent supervisory authority is, in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) and, in the EEA, the competent data protection authority of the data subject's country of residence;
  • inform you as soon as possible where the breach is likely to result in a high risk to your rights and freedoms, in accordance with Article 34 GDPR and the corresponding provisions of the revised Swiss FADP.

13. Where the law requires us to keep your data

Certain data cannot be deleted on request, because we are legally required to keep it. This is the case in particular for invoices, order records and other accounting vouchers, which we must keep for ten years under article 958f of the Swiss Code of Obligations and under the equivalent tax and accounting rules of the countries we sell to.

In that situation we do not delete the data. Instead we restrict its use to the legal purpose for which we must keep it: the data remains in our accounting records, and we stop using it for any other purpose, including marketing, profiling, analysis and reporting. Once the legal period expires, the data is deleted or anonymised.

When your data is no longer required, we delete it from our systems, including those of our third-party service providers, and we apply deletions and the expiry of retention periods to our data warehouse and reporting systems as well as to the source systems from which the data was collected. Where complete deletion is technically impossible or unnecessary, for example for statistical analysis, we anonymise the data instead.

14. Your rights and how to exercise them

Under the GDPR and the FADP you have the following rights over your personal data, subject to legal or technical limitations and depending on the purpose and the legal basis of the processing concerned.

  • Right of access (Article 15 GDPR): you can request a copy of the personal data we hold about you and information about how it is processed.
  • Right of rectification (Article 16 GDPR): you can ask us to correct data that is inaccurate or incomplete.
  • Right to erasure, or "right to be forgotten" (Article 17 GDPR): you can request deletion of your personal data where it is no longer needed for the purposes for which it was collected, where you withdraw your consent or object to the processing, or where the data is processed unlawfully.
  • Right to restriction of processing (Article 18 GDPR): you can ask us to restrict processing where you dispute the accuracy of the data, or where you oppose its deletion but want its use limited.
  • Right to data portability (Article 20 GDPR): you can ask to receive your personal data in a structured, machine-readable format, or ask us to transfer it to another controller.
  • Right to object (Article 21 GDPR): you can object at any time to the processing of your data for direct marketing purposes, and object on grounds relating to your particular situation to processing based on our legitimate interest.
  • Right to withdraw consent (Article 7 GDPR): where we process your data on the basis of your consent, you can withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.

The right to erasure is not absolute. Where we are required by law to keep certain data — in particular invoices and accounting records, which we must keep for ten years — we cannot delete it (Article 17(3)(b) GDPR). In that case we restrict its use to that legal purpose and stop using it for anything else, as described in section 13. We will always tell you which data we have deleted, which data we have had to keep, and why.

You may also request early deletion of your data, subject to legal requirements, and request a copy of the data we hold before it is deleted or anonymised.

How to exercise your rights. Write to us at info@styllacare.com, or by post to Swiss Prime Lab SA, Rue de la Grotte 6, 1003 Lausanne, Switzerland. We undertake to respond within 30 days of receipt, except in the case of complex requests. We may ask you for additional information to verify your identity before processing your request.

Right to complain. If you believe that we are not respecting your rights or applicable law, you may lodge a complaint with the competent supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EEA, the competent data protection authority of your country of residence.

15. Automated decision-making

We do not use algorithms to take decisions based solely on automated processing, including profiling. A person is always involved to validate any decision resulting from such use.

16. Links to other websites

Our service may contain links to sites that are not operated by us. If you follow such a link you will be directed to a third-party site. We strongly advise you to consult the privacy notice of each site you visit. We have no control over, and assume no responsibility for, the content, privacy policies or practices of any third-party site or service.

17. Children and minors

Our online store is not intended for persons under the age of 16, and we do not knowingly collect personal data from persons under the age of 16. If you are a parent, a guardian or a person having parental authority and you believe that we hold personal data relating to your child, please contact us at info@styllacare.com. We will delete that data.

18. Changes to this privacy policy

Stylla may update this privacy policy from time to time by posting revisions on our Site. In the event of material revisions, we may place a notice or pop-up notice on the Site and, if required by law, we will notify you directly.

Last updated: 5 August 2026