In short
- We use your information to assess your application, communicate with you about it and, if you enrol, to invoice tuition.
- We don’t sell your data, don’t use advertising trackers, and every admission decision is made by people.
- You can download a copy of your data or ask us to delete it at any time.
1. Who we are
UGSM-Monarch Business School GmbH (“Monarch”, “we”), Vorderbergstr. 34, CH-6318 Walchwil, Switzerland, is responsible for (the “controller” of) the personal data processed in this portal.
For anything about your personal data, write to administration@umonarch.ch or call 0041 41 780 08 82, with “Data protection” in the subject.
Our representative in the European Union (GDPR Art. 27): UMonarch Administration.
We are based in Switzerland, so the Swiss Federal Act on Data Protection (FADP) applies. Because we admit applicants from the European Union and the European Economic Area, we also follow the EU General Data Protection Regulation (GDPR).
2. What we collect
| Information | Examples | Where it comes from |
|---|---|---|
| Identity and contact | Title, name, email addresses, phone, postal address, citizenship | You, in the application form |
| Education and career | Degrees and institutions, employer, managerial experience, programme and study plan you choose | You |
| Documents | Photo, passport or ID, CV, transcripts or diplomas, recommendation letters | You (uploads) |
| Your application’s progress | Status, documents accepted or not, the Admission Committee’s decision and conditions, offer and attendance choices, scholarship requests and awards, letters we issue | You and our admissions staff |
| Payments | Invoices, amounts paid, payment method and status (never your card number) | You, Stripe and our finance staff |
| Messages | Emails we send you and whether they were delivered, opened or bounced; help requests you send us | You, our staff and our email provider |
| Technical and security | IP address, browser, sign-in times, security-check results for uploaded files, error records | Your device and our servers |
Questions marked as required are needed to consider your application; without them we can’t assess it. We do not ask for sensitive data such as health, religion or ethnic origin. Your photo and identity document are used only to confirm who you are; we don’t use them for facial recognition.
If you only ask to be told when the portal opens, we keep just your email address. If you send a help request without an account, we keep your name, email and message.
3. Why we use it, and on what basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Receiving and assessing your application, asking for more information, making and communicating the admission decision, offers and letters | Steps you ask us to take before a study contract (Art. 6(1)(b)) |
| Enrolment, tuition invoices, payments and scholarships | Performing the contract (Art. 6(1)(b)); keeping accounting records the law requires (Art. 6(1)(c)) |
| Emails about your application and reminders when something is waiting for you | Steps before a contract (Art. 6(1)(b)); our legitimate interest in knowing important messages reached you (Art. 6(1)(f)) |
| Answering help requests | Our legitimate interest in helping you (Art. 6(1)(f)), or steps before a contract |
| Security: sign-in codes, protection against abuse, security checks of uploaded documents, logs and backups | Our legitimate interest in keeping the portal and your data safe (Art. 6(1)(f)); security of processing (Art. 32) |
| Anonymous statistics about applications (for example, how applicants found us) | Our legitimate interest in running and improving admissions (Art. 6(1)(f)) |
| The one email telling you the portal has opened, if you asked for it | Your consent (Art. 6(1)(a)), which you can withdraw at any time |
We don’t make decisions about you by automated means alone: every application is reviewed by the Admission Committee. We don’t use your data for advertising and don’t sell it.
5. Transfers outside Switzerland and the EU
Some providers above process data outside Switzerland and the European Economic Area. Where the destination country is not recognised as providing adequate protection, the transfer is protected as follows:
- Our hosting provider (DigitalOcean, Frankfurt am Main, Germany (fra1)): Data processing agreement.
- Cloudflare, Inc. (Worldwide network; company in the United States): EU–US and Swiss–US Data Privacy Framework, and standard contractual clauses.
- Zoho Corporation (ZeptoMail) (India): Standard contractual clauses in Zoho’s data processing agreement.
- Stripe Payments Europe, Ltd. (Ireland, with processing in the United States): EU–US and Swiss–US Data Privacy Framework, and standard contractual clauses.
- Google LLC (Google Fonts) (The United States): EU–US and Swiss–US Data Privacy Framework.
You can ask us for a copy of the safeguards that apply.
6. How long we keep it
| Data | Kept for |
|---|---|
| Your account, applications, answers, documents, letters and the emails we sent you | While your application is in progress and afterwards as the record of your application, until you ask us to delete it. If you enrol, as part of your student record. |
| Invoices and payment records | 10 years, as Swiss accounting law requires (Code of Obligations, Art. 958f). Kept even if you ask us to delete your other data. |
| Help requests | As long as your account, or until you ask us to delete them |
| Server security and error logs (including IP addresses) | 90 days |
| Security-check records of uploaded files | 180 days; records of files that failed the check are kept |
| Sign-in codes | Deleted one day after they expire |
| Encrypted backups | 14 days, then overwritten |
| “Notify me at launch” email address | Until we have told you the portal is open, or until you ask us to remove it |
8. How we protect it
Connections are encrypted (HTTPS). Uploaded documents are checked for malicious content before they are saved and are encrypted on our server, and backups are encrypted. You sign in with a single-use code sent to your email, so there is no password to steal. Staff access is limited by role, protected by two-step verification or the school’s Microsoft sign-in, and recorded.
If a security incident puts your data at risk, we will inform the authorities and, where required, you, without undue delay.
9. Your rights
Under the GDPR and the FADP you have the right to:
- Access your data and receive a copy of it;
- Correct data that is wrong or incomplete;
- Delete your data, unless we must keep it (for example invoices);
- Restrict or object to processing based on our legitimate interests;
- Data portability: receive the data you gave us in a machine-readable format;
- Withdraw consent where we rely on it, without affecting what was done before.
10. Questions and complaints
Please contact us first at administration@umonarch.ch; we will try to resolve any concern. You also have the right to complain to a supervisory authority:
- In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch;
- In the EU or EEA: the data protection authority in the country where you live or work, listed at edpb.europa.eu.
11. Changes to this notice
We update this notice when the way we handle personal data changes. The version you read is recorded when you submit an application. This is version 2026-09-28.