

legal
Terms and Conditions
The following Terms and Conditions apply to all services provided by Masterclass Cocktail Manufaktur Toutoulas, including, in particular, catering, academy, and consulting services. They govern booking, service delivery, payment, cancellation, liability, data protection, and rights of use. Any deviating agreements are valid only if they have been confirmed in writing.
1.
Introduction and purpose of this privacy policy
2.
Responsible entity
3.
Definitions and basic principles
4.
Scope of application
5.
Principles of data processing
6.
Categories of data subjects
7.
Categories of personal data
8.
Purposes of data processing
9.
Legal bases under Swiss FADP and GDPR
10.
Website usage and server log files
11.
Hosting, technical infrastructure, and security
12.
Contact via form, email, phone, and social media
13.
Catering inquiries and event execution
14.
Academy, training, and certifications
15.
Consulting, workshops, and project documentation
16.
Applications and network staff
17.
Customer, supplier, and business partner data
18.
Newsletter, direct marketing, and customer relations
19.
Cookies and similar technologies
20.
Consent management / cookie banner
21.
Web analytics and tracking
22.
Google services
23.
Meta, LinkedIn, and social media pixels
24.
Appointment booking, video conferencing, and digital communication
25.
Payment processing and accounting
26.
Photo, video, and media recordings at events
27.
References, testimonials, and project communication
28.
Social media presence
29.
Embedding external content
30.
Data sharing with third parties
31.
Processors and service providers
32.
International data transfers
33.
Retention periods
34.
Data security
35.
Data protection impact assessment and risk assessment
36.
Data subject rights
37.
Withdrawal, objection, and opt-out
38.
Automated decision-making and profiling
39.
Minors
40.
Special categories of personal data
41.
Data protection in alcohol service and age verification
42.
Data protection incidents
1.
Introduction and Purpose of this Privacy Policy
This Privacy Policy explains how Masterclass Cocktail Manufaktur, a brand and business division of Moenus Group GmbH, processes personal data. It outlines which personal data is collected, for what purposes such data is used, on which legal basis the processing takes place, to whom personal data may be disclosed, and which rights data subjects have in relation to their personal information.
This Privacy Policy is primarily based on the Swiss Federal Act on Data Protection (FADP). Where we provide services to individuals located within the European Union or specifically target our services and offerings to such individuals, we additionally comply with the requirements of the General Data Protection Regulation (GDPR).
This Privacy Policy applies to visitors of our website, prospective customers, customers, event partners, training participants, applicants, coaches, freelancers, suppliers, service providers, and other business partners.
The purpose of this Privacy Policy is to provide transparent, clear, and professional information regarding the processing of personal data in connection with our premium hospitality, catering, academy, training, and consulting services.
2.
Data Controller
The controller responsible for the processing of personal data is:
Moenus GroupMasterclass Cocktail ManufakturAarepark 5A5000 AarauSwitzerland
Email: info@masterclass-cocktail.chPhone: +41 78 725 78 70Website: www.masterclass-cocktail.ch
For any questions or concerns regarding data protection and the processing of personal data, you may contact the controller using the contact details provided above.
If you would like to contact a specific person regarding data protection matters, you may in particular reach out by email to:
Kyriakos ToutoulasFounder, Masterclass Cocktail Manufaktur
3.
Definitions and General Understanding
Personal Data means any information relating to an identified or identifiable natural person. This may include, for example, names, contact details, billing information, communication content, IP addresses, contractual information, application documents, or photographs and video recordings.
Processing means any operation performed on personal data, regardless of the means and procedures used. This includes, in particular, the collection, storage, use, analysis, disclosure, transmission, archiving, deletion, or destruction of personal data.
The Controller is the natural or legal person, public authority, agency, or other body that determines the purposes and means of the processing of personal data.
Processors are service providers or other third parties that process personal data on behalf of and under the instructions of the Controller.
4.
Scope of Application
This Privacy Policy applies to all processing activities carried out in connection with Masterclass Cocktail Manufaktur (“MCM”), including in particular:
-
the use of our website and its subpages;
-
contact, catering, academy, consulting, and application forms;
-
enquiries submitted by email, telephone, messenger services, or social media;
-
the preparation of quotations, conclusion of contracts, and provision of services;
-
event planning, event execution, and post-event activities;
-
training courses, workshops, academy programmes, and certifications;
-
consulting projects and related project documentation;
-
applications and the management of talent pools and professional networks;
-
customer relationship management, references, and marketing communications;
-
collaboration with service providers, partners, coaches, and suppliers.
This Privacy Policy applies regardless of the location from which our services, website, or communication channels are accessed and covers all processing of personal data in connection with the activities described above.
Where we specifically target individuals located within the European Union or provide services to such individuals, we additionally comply with the requirements of the General Data Protection Regulation (GDPR).
5.
Principles of Data Processing
MCM processes personal data in accordance with the principles of lawfulness, transparency, purpose limitation, proportionality, data minimisation, accuracy, integrity, confidentiality, and data security.
Personal data is processed only where necessary for the respective purpose or where processing is based on consent, a legal obligation, contractual necessity, or a legitimate interest. Where processing is based on legitimate interests, we ensure that such interests relate to our need to provide professional, secure, and efficient services, as well as the legitimate interests of third parties, and that no overriding interests, fundamental rights, or freedoms of the data subject prevail.
In particular:
-
Personal data is not collected without a legitimate and justifiable purpose.
-
Access to personal data is restricted internally to authorised individuals who require such access to perform their duties.
-
Personal data is deleted, anonymised, or securely archived once it is no longer required for the purpose for which it was collected, unless statutory or contractual retention obligations apply.
-
When engaging external service providers, we ensure that appropriate technical and organisational measures are implemented to protect personal data and maintain an adequate level of security.
6.
Categories of Data Subjects
The processing of personal data may concern, in particular, the following categories of data subjects:
-
visitors to our website;
-
prospective customers and individuals making enquiries;
-
customers and clients;
-
contact persons at companies, agencies, hotels, venues, and brands;
-
event guests, where processing is necessary for event organisation, security, or documentation purposes;
-
participants in academy programmes, training courses, and workshops;
-
consulting clients and project stakeholders;
-
applicants, coaches, bartenders, service staff, freelancers, and other independent contractors;
-
suppliers, service providers, and business partners;
-
recipients of newsletters, marketing communications, and other promotional content.
7.
Categories of Personal Data
Depending on the nature of the interaction, service provided, or use of our website and services, we may process the following categories of personal data:
Identification Data: first name, last name, company name, job title, position, and department;
Contact Data: email address, telephone number, postal address, and social media contact details;
Enquiry Data: type of enquiry, event date, venue, number of participants, requested services, budget range, and specific requirements;
Contractual Data: quotations, order confirmations, service descriptions, correspondence, contracts, and project-related documentation;
Payment and Billing Data: billing address, payment status, payment terms, transaction information, and accounting records;
Technical Data: IP address, browser type, device information, operating system, access times, and pages visited;
Communication Data: emails, messages, telephone records, meeting notes, and other communication-related information;
Academy Data: course selections, participant information, attendance records, certification data, and learning or training-related information;
Application Data: curriculum vitae (CV), qualifications, professional experience, availability, language skills, references, photographs, and cover letters;
Media Content: photographs, video recordings, testimonials, reference materials, and event documentation;
Consent Data: cookie preferences, consent records, withdrawals of consent, and opt-in or opt-out information.
8.
Purposes of Data Processing
MCM processes personal data for the following purposes in particular:
-
providing, maintaining, and improving our website and digital services;
-
receiving, processing, and responding to enquiries and requests;
-
preparing customised quotations and service proposals;
-
negotiating, establishing, performing, and administering contractual relationships;
-
planning, organising, delivering, and evaluating catering, event, hospitality, and beverage services;
-
conducting academy programmes, training courses, workshops, and certification activities;
-
delivering consulting services, workshops, operational assessments, and concept development projects;
-
managing applications and maintaining a professional network of coaches, freelancers, and hospitality professionals;
-
communicating with customers, prospective customers, partners, suppliers, service providers, and other business contacts;
-
invoicing, accounting, payment processing, financial administration, and compliance with tax obligations;
-
quality assurance, internal administration, business operations, and process improvement;
-
marketing activities, customer relationship management, reference communications, brand development, and promotional activities;
-
complying with legal and regulatory obligations and establishing, exercising, or defending legal claims;
-
ensuring information security, preventing misuse, detecting fraud, and maintaining the technical stability and security of our systems and services.
9.
Legal Bases under the Swiss FADP and the GDPR
The processing of personal data is primarily governed by the Swiss Federal Act on Data Protection (FADP).
Where the General Data Protection Regulation (GDPR) applies – in particular where individuals located within the European Union (EU) or the European Economic Area (EEA) are concerned, or where our services and activities are specifically directed towards the EU/EEA market – we additionally rely on the legal bases set out in Article 6 GDPR.
Under the Swiss FADP, the processing of personal data is generally permitted where it is based on a legal obligation, is necessary for the performance of a contract or pre-contractual measures, is based on consent, is justified by overriding private or public interests, or is exceptionally required to protect vital interests.
Where the GDPR applies, personal data is processed on one or more of the following legal bases pursuant to Article 6(1) GDPR:
Performance of a Contract and Pre-Contractual Measures (Article 6(1)(b) GDPR), particularly in connection with enquiries, quotations, bookings, contractual relationships, and the provision of our services;
Consent (Article 6(1)(a) GDPR), for example in relation to newsletter subscriptions, certain cookies and tracking technologies, media usage, or the voluntary provision of additional information;
Legitimate Interests (Article 6(1)(f) GDPR), particularly our interest in maintaining a secure and reliable website, communicating with customers and business partners, conducting direct marketing activities, ensuring quality assurance, preventing misuse, and establishing, exercising, or defending legal claims;
Compliance with Legal Obligations (Article 6(1)(c) GDPR), particularly in relation to accounting requirements, tax obligations, statutory retention periods, regulatory requirements, and requests from competent authorities;
Protection of Vital Interests (Article 6(1)(d) GDPR), in exceptional circumstances where processing is necessary to protect the vital interests of a data subject or another natural person, for example in connection with safety-related incidents during events or training activities.
10.
Website Use and Server Log Files
When you visit our website, certain technical data is automatically processed to ensure the availability, stability, functionality, and security of the website and to protect it against misuse and unauthorised access.
Such data may include:
-
the IP address of the device used to access the website;
-
the date and time of access;
-
the pages, content, and files requested;
-
the volume of data transmitted;
-
browser type and browser version;
-
operating system and device type;
-
referring website (referrer URL);
-
system, error, and security log information.
This information is generally not used to directly identify individual users unless such identification is necessary to investigate suspected misuse, technical malfunctions, security incidents, unlawful activities, or to comply with legal obligations.
Server log files are typically stored only for a limited period and are subsequently deleted, anonymised, or aggregated. Longer retention may be necessary in individual cases where there are specific indications of unlawful use, security incidents, fraud attempts, technical disruptions, or where retention is required for operational, security, or legal reasons.
11.
Hosting, Technical Infrastructure and Security
Our website may be operated and supported through external hosting providers, website-building platforms, content delivery networks (CDNs), and other infrastructure service providers. These providers process technical data required for the operation, delivery, maintenance, and security of the website and related digital services.
Where Wix Studio or similar platforms are used, personal data may be processed on servers operated by the respective provider. Such processing may include technical data, website interactions, form submissions, media files, administrative data, and other information necessary for the provision and management of the website.
The service providers currently used include:
Website Platform / CMS: Wix Studio
Hosting Provider: Wix.com Ltd.
Domain and Email Provider: IONOS SE
Consent Management Provider: Wix Consent Banner (Wix.com Ltd.)
Analytics and Website Performance Tools: Wix Analytics (Wix.com Ltd.)
These service providers may engage carefully selected subcontractors and sub-processors to support the delivery of their services. Where such subcontractors are used, we take reasonable steps to ensure that appropriate data protection, confidentiality, and security standards are maintained throughout the processing chain.
12.
Contact via Forms, Email, Telephone and Social Media
When individuals contact MCM, the information provided is processed for the purpose of handling the enquiry, communicating with the individual, and managing any subsequent business relationship or related activities.
This includes, in particular, communications submitted through contact forms, email correspondence, telephone calls, messenger services, social media messages, and personal meetings or conversations.
Personal data collected in this context is retained for as long as necessary to process the enquiry, maintain and administer any resulting business relationship, comply with legal retention requirements, or protect legitimate interests relating to documentation, record-keeping, and the establishment, exercise, or defence of legal claims.
The legal basis for such processing depends on the specific circumstances and may include the performance of pre-contractual measures or contractual obligations, the data subject’s consent (particularly where optional information is voluntarily provided), or our legitimate interests in maintaining professional communications, efficient business operations, and appropriate documentation of business activities.
13.
Catering Enquiries and Event Management
In connection with catering services, hospitality projects, and event enquiries, MCM processes personal data that is necessary for planning, preparing quotations, organising, delivering, and managing the requested services.
Such data may include, in particular:
-
the name and contact details of the client or authorised contact person;
-
details of the company, brand, agency, hotel, venue, or organisation involved;
-
event type, date, time, venue, schedule, and event programme;
-
expected number of participants, guest profile, and desired service level;
-
requested services, bar concepts, beverage selections, staffing requirements, equipment, and operational setup;
-
special requirements such as non-alcoholic alternatives, allergies, dietary restrictions, VIP services, accessibility requirements, or security-related instructions;
-
information relating to setup and dismantling, electricity and water access, storage facilities, loading areas, parking arrangements, and on-site contacts;
-
billing information, quotation details, contractual records, and related business communications.
Where event guests are affected, personal data is processed only to the extent necessary for event organisation, guest services, security management, access control, invoicing, operational coordination, or event documentation.
Where personal data relating to guests or other participants is processed as part of event delivery, such processing is generally carried out on behalf of, or under the responsibility of, the respective client, organiser, or event host. MCM processes such data only to the extent required for the operational delivery of services, safety and security measures, administrative purposes, invoicing, or documentation.
14.
Academy, Training Programmes and Certifications
As part of its Academy activities, MCM processes personal data for the registration, organisation, delivery, administration, support, and follow-up of courses, training programmes, workshops, and educational activities.
The categories of personal data processed may include, in particular:
-
participant names, contact details, and company information;
-
booked courses or programmes, training level, number of participants, and requested learning objectives or content;
-
attendance records and participation information;
-
certification data, certificate issue dates, and course or programme titles;
-
feedback, evaluations, assessments, and voluntarily submitted comments;
-
organisational information relating to locations, schedules, training materials, and equipment;
-
information regarding preferred language, previous experience, professional background, and training objectives.
Certification records may be retained internally to verify participation, confirm certification status, issue replacement certificates, or respond to future verification requests.
Training materials, methodologies, concepts, presentations, educational content, and related documentation remain the intellectual property of MCM unless otherwise agreed in writing.
15.
Consulting Services, Workshops and Project Documentation
n connection with consulting services, MCM processes personal and business-related data that is necessary for analysis, assessments, advisory services, concept development, workshop facilitation, and project implementation.
Such data may include, in particular:
-
contact details of project stakeholders and authorised representatives;
-
information relating to bar, restaurant, hotel, brand, beverage, or hospitality concepts;
-
operational processes, workflows, and organisational structures;
-
team structures, responsibilities, staffing models, and training requirements;
-
beverage concepts, menu structures, guest experience strategies, and service processes;
-
workshop records, presentations, notes, reports, recommendations, and project documentation;
-
business metrics and operational data, where voluntarily provided and relevant to the consulting project.
Confidential information obtained during consulting engagements is treated with a high degree of care and confidentiality. Such information will not be disclosed to third parties without appropriate authorisation, unless disclosure is required by law, necessary for the provision of agreed services, or otherwise permitted under applicable data protection and confidentiality obligations.
16.
Applications and Talent Network Personnel
In connection with job applications, freelance collaboration requests, or expressions of interest in joining our professional network, MCM processes personal data that is necessary to assess suitability, communicate with candidates, plan assignments, and evaluate potential collaboration opportunities.
The categories of personal data processed may include, in particular:
-
name, contact details, and place of residence;
-
curriculum vitae (CV), professional experience, qualifications, certifications, and references;
-
language skills, availability, preferred working regions, and travel readiness where relevant;
-
the desired role or area of activity, such as bartender, service professional, coach, event staff member, project support specialist, or other hospitality-related positions;
-
photographs or profile images, where voluntarily provided;
-
correspondence, communication history, interview notes, and internal assessments relating to potential collaboration.
Application and recruitment-related data is generally processed solely for the purpose of managing the application process and evaluating potential employment, freelance engagement, or future collaboration opportunities.
Inclusion in a talent pool, coach network, freelancer database, or personnel pool will only take place where the individual has been informed accordingly or has provided the necessary consent.
Unless an individual is included in such a talent pool or network, application documents and related records will generally be deleted within approximately six (6) months following completion of the recruitment or selection process, unless statutory retention obligations, legal requirements, or overriding legitimate interests require a longer retention period, for example for the establishment, exercise, or defence of legal claims.
17.
Equipment, Bar-Setup and Materials
MCM processes personal data relating to customers, suppliers, service providers, contractors, and other business partners for the purpose of establishing, managing, administering, and maintaining business relationships.
This may include, in particular:
-
contact details and business contact information;
-
contractual and project-related information;
-
billing, payment, and accounting records;
-
communication and correspondence data;
-
details of authorised representatives and contact persons;
-
quotations, proposals, and procurement-related documentation;
-
service records, delivery confirmations, and performance documentation;
-
accounting, tax, and compliance-related documents.
Such data is processed only to the extent necessary for the initiation, performance, administration, documentation, and ongoing management of the respective business relationship, as well as for compliance with legal, regulatory, accounting, and tax obligations.
18.
Newsletters, Direct Marketing and Customer Relationship Management
Where MCM distributes newsletters, invitations, updates, industry insights, event information, educational content, or other marketing communications, personal contact details are used only to the extent permitted by applicable law.
Electronic marketing communications are generally sent on the basis of the recipient’s consent or, where legally permitted, within the context of an existing customer relationship and our legitimate interests in maintaining professional business communications and customer relationships.
Recipients may unsubscribe from newsletters or comparable marketing communications at any time. Any withdrawal of consent or unsubscribe request will apply to future communications and will be processed without undue delay.
Where newsletters or similar electronic communications are offered, registration may be carried out using a double opt-in procedure. Following registration, the individual will receive a confirmation email requesting verification of the subscription. Subscription records are logged and retained to demonstrate compliance with applicable legal requirements and to document the subscription process. Such records may include the date and time of registration, the date and time of confirmation, and the IP address used during the registration process.
Individuals may withdraw their consent at any time and unsubscribe from marketing communications. A corresponding unsubscribe link is included in every newsletter or comparable marketing email.
19.
Cookies and Similar Technologies
Our website uses cookies and similar technologies, including Local Storage, Session Storage, and related technical mechanisms. These technologies may be used by Wix and, where applicable, by integrated third-party service providers to ensure the proper operation of the website, store user preferences, analyse website usage, and provide specific functionalities and services.
The following categories of cookies and similar technologies may be used on our website:
-
Strictly Necessary Cookies
Required for the technical operation, security, stability, and core functionality of the website. -
Functional Cookies
Enable the website to remember user preferences and settings, improving usability and the overall user experience. -
Analytics Cookies
Used to analyse website usage, visitor interactions, and website performance, for example through Wix Analytics. -
Marketing Cookies
May be used for marketing, advertising, audience measurement, and campaign effectiveness purposes where corresponding services are implemented. -
Third-Party Content Cookies
May be set by external content and third-party services integrated into the website, such as videos, maps, social media features, or similar embedded content.
The management of user consent is carried out through the Wix Consent Management Tool implemented on this website. Detailed information regarding the specific cookies and similar technologies used, including their providers, purposes, and retention periods, can be accessed at any time through the cookie settings or consent management interface available on the website.
Where consent is required for the use of specific cookies or similar technologies, such technologies will only be activated after the user has provided the necessary consent.
Previously granted consent can be modified or revoked at any time with effect for the future via the consent management tool implemented on the website.
20.
Consent Management / Cookie Banner
Where required by applicable law, MCM obtains user consent before activating non-essential cookies, analytics technologies, marketing tools, or similar tracking technologies through a consent management platform.
Users may review, modify, or withdraw their cookie preferences and consent choices at any time through the consent management tool available on the website. Any withdrawal of consent shall apply only to future processing activities and shall not affect the lawfulness of processing carried out prior to the withdrawal.
Strictly necessary cookies and similar technologies may be used without consent where they are required for the operation, security, functionality, or technical provision of the website and its services.
21.
Web Analytics and Tracking
MCM may use the analytics functionalities provided by Wix to analyse, monitor, and optimise the performance of its website and online services. In particular, Wix Analytics may be used for this purpose.
In this context, technical usage data may be processed, including page views, user interactions, click behaviour, session duration, referrer information, device characteristics, browser information, and approximate location data. Such information is used to evaluate website performance, improve user experience and navigation, understand visitor behaviour, and measure the reach and effectiveness of our online presence.
The website also uses the consent management system provided by Wix, which enables visitors to manage their preferences and consent choices relating to non-essential cookies, analytics technologies, and similar tracking mechanisms.
Any additional analytics, tracking, advertising, marketing, or measurement services will only be used where they have been explicitly activated and are specifically identified in this Privacy Policy.
22.
Google Services
Where Google services are used, personal data may be transferred to and processed by companies within the Google group. This may be relevant, in particular, in connection with services such as Google Analytics, Google Tag Manager, Google Maps, Google Fonts, Google reCAPTCHA, YouTube, or Google Workspace.
Depending on the specific service used, the processing may include technical information, IP addresses, usage data, device information, location data, cookie identifiers, and user interaction data.
Where Google Analytics is used, privacy-friendly settings should be implemented wherever possible, including IP anonymisation and appropriate data retention limitations. If MCM uses Google Analytics, IP anonymisation is enabled so that users’ IP addresses are shortened within Switzerland, the European Union (EU), or the European Economic Area (EEA) before being transmitted to Google.
Google services will only be used where required for the operation of our website, communication systems, analytics functions, embedded content, or other legitimate business purposes, and where any necessary consent has been obtained through the consent management platform, where applicable.
23.
Meta, LinkedIn and Social Media Pixels
Where MCM uses social media pixels, marketing tags, or similar tracking technologies, usage data may be transmitted to platforms such as Meta, LinkedIn, or comparable advertising and social media providers. These technologies may be used to measure campaign performance, create audience segments, conduct retargeting activities, and track conversions resulting from marketing and advertising efforts.
Where required by applicable law, such processing will only take place after the user has provided the necessary consent.
The respective platform providers may process personal data independently and for their own purposes. Users are therefore encouraged to review the privacy policies and data protection notices of the relevant platforms for further information regarding their processing activities.
Where the GDPR applies, such processing is generally carried out only on the basis of the user’s consent obtained through the website’s cookie and consent management platform. Users may withdraw their consent at any time with future effect through the available cookie settings or consent management tools.
24.
Appointment Booking, Video Conferencing and Digital Communication
MCM may use digital tools for appointment scheduling, consultations, introductory meetings, academy administration, project coordination, and online communication.
Depending on the service used, personal data such as name, email address, telephone number, preferred appointment times, meeting content, chat messages, calendar information, IP addresses, and technical connection data may be processed.
The service providers used may include, for example:
Wix Bookings
Google Calendar or Microsoft Outlook
Google Meet, Zoom, Microsoft Teams, or comparable video conferencing and communication platforms
These services enable efficient scheduling, communication, project coordination, and the delivery of online consultations, workshops, training sessions, and business meetings.
The above-mentioned providers may process personal data in countries outside Switzerland or the European Economic Area (EEA), including the United States. Where no recognised adequacy decision exists, such transfers are based on appropriate safeguards, including standard contractual clauses approved by the European Commission or other legally recognised transfer mechanisms. Where required, data transfers may also be based on the data subject’s explicit consent or on overriding private or public interests as permitted under the Swiss Federal Act on Data Protection (FADP).
25.
Payment Processing and Accounting
For the purposes of invoicing, payment administration, accounting, financial reporting, and compliance with tax and regulatory obligations, MCM processes contractual, billing, and payment-related data.
Such data may be disclosed to accounting service providers, fiduciaries, banks, payment service providers, tax advisors, auditors, or competent authorities where necessary for the provision of services, the fulfilment of contractual obligations, compliance with legal requirements, or the protection of legitimate business interests.
The categories of data processed may include customer information, contractual records, invoices, payment details, transaction information, correspondence relating to payments, and accounting documentation.
Invoices, accounting records, and tax-related documentation are retained in accordance with applicable statutory retention requirements and regulatory obligations.
26.
Photography, Video Recording and Media Content at Events
During events, training sessions, workshops, and other projects, photographs, video recordings, and other media content may be created. Such recordings may be used for documentation purposes, internal quality assurance, reference materials, social media communications, marketing activities, and the presentation of MCM’s services and projects.
Where individuals are clearly identifiable and constitute the primary focus of an image or recording, MCM will seek to rely on an appropriate legal basis, such as consent, a contractual agreement, or another lawful justification under applicable data protection laws.
For general event photography, atmosphere shots, venue impressions, or crowd images, MCM will take reasonable steps to respect privacy rights and personal interests while documenting the event and its environment.
Participants, guests, and other individuals who do not wish to appear in published photographs, videos, or other media content may contact MCM at any time. Where legally, technically, and operationally feasible, MCM will make reasonable efforts to accommodate such requests and take appropriate measures to prevent or discontinue the use of the relevant material.
27.
References, Testimonials and Project Communications
MCM may use completed projects, customer logos, event categories, general project descriptions, case studies, or testimonials as references where permitted by law or where the necessary approval has been obtained.
Personal testimonials, named quotations, photographs, logos, identifiable client references, or detailed project information will generally only be published on the basis of consent, contractual permission, or another appropriate legal basis.
Reference materials may be used for marketing, business development, portfolio presentation, website content, social media communications, sales materials, proposals, and other professional communications relating to MCM’s services and expertise.
For sensitive projects, VIP events, private functions, confidential consulting engagements, or projects subject to specific confidentiality obligations, any use of references, testimonials, images, or project-related information will only take place following prior consultation and approval from the relevant client or authorised party.
28.
Social Media Presence
MCM may maintain profiles and business pages on social media platforms such as Instagram, LinkedIn, Facebook, TikTok, YouTube, and other comparable social networking services.
When users interact with these profiles, send messages, comment on posts, react to content, or share information, personal data may be processed both by the respective platform provider and, where applicable, by MCM.
MCM processes such data primarily for the purposes of communication, community engagement, responding to enquiries, customer support, brand communication, marketing activities, and the presentation of its services, projects, events, and educational programmes.
The operators of the respective social media platforms process personal data independently and under their own responsibility. Such processing is governed exclusively by the privacy policies, terms of use, and data protection practices of the respective platform providers. Users are therefore encouraged to consult the privacy notices of the relevant platforms for further information regarding the processing of their personal data.
29.
Integration of External Content
Our website may incorporate content, features, and services provided by third parties, including maps, videos, fonts, booking tools, forms, social media feeds, review widgets, and other embedded content.
When such content is loaded or displayed, personal data may be transmitted to the respective third-party provider. This may include, in particular, the user’s IP address, browser information, device details, operating system data, and information about the specific pages visited on our website.
Depending on the nature of the integrated service, additional technical or usage-related information may also be processed by the relevant provider in accordance with its own privacy policy.
Where reasonably possible, external content is integrated in a privacy-friendly manner, for example through consent-based loading mechanisms, privacy-enhanced settings, or technical measures designed to minimise data transfers. Where legally required, external content will only be activated after the user has provided the necessary consent through the website’s consent management platform.
30.
Disclosure of Personal Data to Third Parties
Personal data is disclosed to third parties only where such disclosure is necessary, legally permitted, contractually required, or otherwise justified under applicable data protection laws.
Recipients of personal data may include, in particular:
-
IT service providers, hosting providers, website operators, and technical infrastructure partners;
-
newsletter platforms, form providers, CRM systems, communication platforms, and related software providers;
-
accounting firms, fiduciaries, auditors, tax advisors, and financial service providers;
-
banks, payment service providers, and payment processing partners;
-
coaches, trainers, event staff, freelancers, subcontractors, and operational project partners;
-
venues, hotels, agencies, event organisers, clients, or contracting parties where necessary for the planning, coordination, and delivery of events or services;
-
transport providers, logistics companies, equipment suppliers, and related service partners;
-
public authorities, regulatory bodies, courts, legal advisors, or other parties where disclosure is required by law or necessary for the establishment, exercise, or defence of legal claims;
-
insurance providers and insurance representatives in connection with claims, incidents, liability matters, or risk management activities.
Personal data is disclosed only to the extent necessary for the relevant purpose and, where appropriate, subject to contractual confidentiality obligations, data processing agreements, or other suitable safeguards.
31.
Processors and Service Providers
Where external service providers process personal data on behalf of MCM, such providers are selected with appropriate care and due diligence.
MCM takes reasonable steps to ensure that service providers implement suitable technical and organisational measures to protect personal data and process such data only within the scope of the agreed instructions and applicable legal requirements.
Where required by law or considered appropriate, MCM enters into data processing agreements or comparable contractual arrangements with its service providers. Such agreements are intended to ensure, among other things:
-
the confidentiality of personal data;
-
appropriate technical and organisational security measures;
-
processing only for specified and legitimate purposes;
-
compliance with applicable data protection laws;
-
restrictions on unauthorised disclosure or use of personal data;
-
appropriate controls regarding the engagement of sub-processors and subcontractors.
MCM also seeks to ensure that any authorised sub-processors engaged by its service providers maintain an adequate level of data protection, confidentiality, and information security.
32.
International Data Transfers
Personal data may be processed in Switzerland, within the European Economic Area (EEA), or in other countries where service providers, technology platforms, hosting providers, communication systems, cloud services, or other business partners operate their infrastructure.
International data transfers may occur in particular where MCM uses globally operated technology services, cloud-based applications, communication platforms, analytics tools, booking systems, or other digital service providers.
Where personal data is transferred to countries that do not provide an adequate level of data protection under applicable law, MCM seeks to implement appropriate safeguards. Such safeguards may include:
-
Standard Contractual Clauses (SCCs);
-
supplementary technical and organisational security measures;
-
contractual data protection commitments;
-
recognised transfer mechanisms under applicable data protection laws;
-
the data subject’s explicit consent, where required.
As many digital services operate internationally, it may not always be technically possible to completely prevent international data transfers.
The Swiss Federal Data Protection and Information Commissioner (FDPIC) publishes information regarding countries that are considered to provide an adequate level of data protection from a Swiss legal perspective. Where personal data is transferred to countries without such recognition, MCM relies, where appropriate and reasonably practicable, on Standard Contractual Clauses, additional contractual and technical safeguards, or, in exceptional circumstances, on other lawful transfer mechanisms, including explicit consent or overriding legitimate interests permitted under the Swiss Federal Act on Data Protection (FADP).
33.
Data Retention Periods
MCM retains personal data only for as long as necessary to fulfil the respective purpose for which the data was collected, or where longer retention is required or justified by legal obligations, contractual requirements, regulatory obligations, or legitimate business interests.
Indicative retention periods include:
General Enquiries and Contact Requests: typically up to 12 months following the conclusion of the communication, unless a longer retention period is required for legal, operational, or evidentiary purposes;
Quotations, Contracts and Project Documentation: retained in accordance with applicable statutory retention requirements and legitimate business and evidentiary interests;
Accounting, Billing and Financial Records: retained in accordance with applicable tax, accounting, and commercial law requirements;
Academy and Certification Records: retained for as long as necessary to verify participation, confirm certification status, issue replacement certificates, or maintain appropriate training records;
Application and Recruitment Data: generally retained for up to six (6) months following completion of the recruitment process, unless the individual is included in a talent pool, coach network, or professional database based on consent or another lawful basis;
Newsletter and Marketing Data: retained until consent is withdrawn, the individual unsubscribes, or the relevant purpose no longer exists;
Cookie and Consent Records: retained in accordance with the settings of the consent management platform and any applicable legal documentation requirements;
Photographs, Videos, Testimonials and Reference Materials: retained for as long as their use remains lawful, relevant to the intended purpose, and no overriding objection or legal restriction requires their removal.
Upon expiry of the applicable retention period, personal data will generally be deleted, anonymised, securely destroyed, or, where technically feasible, retained only in a form that no longer permits the identification of a specific individual.
34
Data Security
MCM implements appropriate technical and organisational measures to protect personal data against accidental or unlawful loss, misuse, unauthorised access, alteration, disclosure, destruction, or other forms of unlawful processing.
Depending on the nature, scope, context, and risks associated with the processing activities, such measures may include:
-
access controls and role-based permissions;
-
password protection and multi-factor authentication, where available;
-
encryption of data transmissions, particularly through secure HTTPS connections;
-
regular updates, maintenance, and security monitoring of systems, applications, and digital tools;
-
backup procedures, disaster recovery measures, and business continuity arrangements;
-
confidentiality obligations for employees, contractors, coaches, freelancers, and service providers;
-
appropriate separation of private and business-related data and systems;
-
restricted disclosure of personal data on a strict need-to-know basis;
-
structured data retention, archiving, and deletion procedures.
While MCM takes reasonable and appropriate measures to protect personal data, no method of electronic transmission, storage, or processing can be guaranteed to be completely secure. Accordingly, absolute security cannot be guaranteed.
35.
Data Protection Impact Assessments and Risk Evaluation
Where a planned processing activity is likely to result in a high risk to the rights, freedoms, or personal interests of individuals, MCM will assess whether a Data Protection Impact Assessment (DPIA) or a comparable risk assessment is required under applicable data protection laws.
Such assessments may be particularly relevant in cases involving large-scale processing, systematic monitoring, the processing of sensitive personal data, the use of innovative technologies, automated decision-making, profiling activities, or other forms of complex data processing that may present elevated privacy risks.
For MCM’s standard business activities, including catering services, academy programmes, training activities, consulting services, and hospitality projects, a formal Data Protection Impact Assessment is generally not considered necessary, provided that no unusual risks, large-scale processing of sensitive personal data, extensive monitoring activities, or comparable high-risk processing operations are involved.
This assessment is reviewed periodically and should be re-evaluated whenever new technologies, systems, service providers, business processes, or data processing activities are introduced that could materially affect privacy risks or data protection obligations.
36
Rights of Data Subjects
Under applicable data protection laws, data subjects may have various rights regarding the processing of their personal data. Depending on the circumstances and the applicable legal framework, these rights may include:
the right to obtain information about and access personal data being processed;
the right to request the correction of inaccurate or incomplete personal data;
the right to request the deletion of personal data, provided that no legal retention obligations or overriding legitimate interests prevent such deletion;
the right to request the restriction of processing, where applicable;
the right to receive personal data in a structured format or to request the transfer of personal data to another controller, where applicable;
the right to withdraw consent previously granted, with effect for future processing activities;
the right to object to certain processing activities, where permitted by law;
the right to lodge a complaint with a competent data protection authority.
In Switzerland, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC). Individuals located within the European Union (EU) or the European Economic Area (EEA) may also have the right to contact their respective national or regional data protection authority where the GDPR applies.
Requests relating to data protection rights may be submitted using the contact details provided in Section 02 (Data Controller). In order to protect personal data and prevent unauthorised disclosure, MCM may request appropriate proof of identity before processing such requests.
37.
Withdrawal of Consent, Objection and Unsubscription
Any consent previously provided may be withdrawn at any time with effect for future processing activities. The withdrawal of consent does not affect the lawfulness of any processing carried out prior to such withdrawal.
Recipients of marketing communications may unsubscribe at any time. Where cookies, analytics technologies, or tracking tools are used on the basis of consent, consent preferences may be modified or withdrawn through the website’s cookie banner, consent management platform, or, where applicable, through browser settings.
Data subjects may also have the right to object to certain processing activities where such processing is based on legitimate interests and where there are no overriding legitimate grounds requiring the continued processing of the personal data.
Requests relating to withdrawals of consent, objections to processing, or marketing unsubscribes may be submitted using the contact details provided in Section 02 (Data Controller). Where available, such requests may also be made through the unsubscribe links included in communications or through the relevant settings and preference management tools provided on our website.
38.
Automated Decision-Making and Profiling
MCM does not generally make decisions based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect a data subject.
Limited profiling activities may occur in connection with website analytics, audience measurement, marketing activities, advertising technologies, or similar digital services. Such profiling is generally used to better understand user interactions, improve website performance, optimise communications, and evaluate the effectiveness of marketing activities.
Where profiling activities require consent under applicable data protection laws, such processing will only take place after the necessary consent has been obtained through the relevant consent management mechanisms.
MCM does not use automated decision-making systems for employment decisions, customer eligibility assessments, contractual decisions, or other activities that would result in significant legal or comparable effects for individuals.
39.
Minors
MCM’s services are generally intended for adults, businesses, event organisers, professional teams, and other adult participants.
Where minors participate in academy programmes, training activities, events, workshops, or application processes, additional consent, authorisation, or confirmation from a parent, legal guardian, or other authorised representative may be required, depending on the applicable legal requirements and the nature of the activity.
Individuals who have not reached the legal minimum age for alcohol service, alcohol consumption, or participation in alcohol-related educational activities may only participate where such participation is legally permitted and has been appropriately authorised and organised.
If MCM becomes aware that personal data relating to a minor has been collected or provided without the required consent or legal basis, MCM will take reasonable steps to delete such data or otherwise limit its processing, unless continued processing is required or permitted under applicable law or necessary to comply with legal obligations.
40.
Special Categories of Personal Data
MCM generally processes special categories of personal data only where such processing is necessary, voluntarily disclosed by the individual concerned, legally permitted, or based on an appropriate legal basis under applicable data protection laws.
In individual cases, this may include, in particular:
-
information relating to allergies, dietary restrictions, intolerances, or similar requirements in connection with events, hospitality services, training programmes, or workshops;
-
health-related information where relevant to participation, safety, accessibility, or emergency planning;
-
information regarding specific support, accessibility, or accommodation requirements;
-
photographs, video recordings, or other media content where privacy rights, personal interests, or special protections may be affected.
Such information is treated with an increased level of care, confidentiality, and security. Access is restricted to individuals who require the information for organisational, safety-related, operational, accessibility, or service delivery purposes.
Where required by applicable law, the processing of special categories of personal data will only take place on the basis of an appropriate legal basis, including explicit consent where necessary.
41.
Data Protection in Alcohol Service and Age Verification
In connection with events involving the service of alcoholic beverages, MCM or the respective client, organiser, or venue operator may be required to implement age verification procedures, safety measures, or other organisational controls in order to comply with applicable legal and regulatory requirements.
In such cases, personal data may be processed to the extent necessary to verify eligibility for participation, confirm legal age requirements, ensure compliance with applicable laws, or support health and safety obligations.
As a general principle, MCM does not permanently retain identification documents, identity card details, passport information, or similar age verification records unless such retention is required by law, necessary for the investigation of a specific incident, required by competent authorities, or otherwise justified under applicable legal obligations.
Any personal data processed for age verification or compliance purposes will be handled confidentially and only for the duration and purposes necessary to fulfil the relevant legal, operational, or safety requirements.
42.
Data Protection Incidents and Personal Data Breaches
A data protection incident or personal data breach may occur where personal data is accidentally or unlawfully lost, altered, disclosed, destroyed, accessed without authorisation, or otherwise processed in a manner that compromises its confidentiality, integrity, or availability.
MCM investigates suspected data protection incidents with appropriate care and takes reasonable measures to contain, assess, mitigate, and remediate any potential adverse effects.
Where required by applicable law, MCM will notify the competent supervisory authority and, where necessary, the affected individuals within the applicable legal timeframes.
Where the Swiss Federal Act on Data Protection (FADP) or, where applicable, the General Data Protection Regulation (GDPR) imposes a notification obligation, MCM will assess whether the incident must be reported to the relevant supervisory authority and/or communicated to affected individuals and will take all steps reasonably required to fulfil such obligations.
43
Changes to this Privacy Policy
MCM reserves the right to amend, update, or modify this Privacy Policy at any time, particularly where required due to changes in applicable laws or regulations, the introduction of new services, technologies, tools, service providers, website features, business processes, or data processing activities.
Any updated version of this Privacy Policy will be published on our website and will become effective upon publication unless otherwise stated.
The version of this Privacy Policy published on the website at the relevant time shall be the current and applicable version.
44.
Data Protection Contact
Questions, requests for information, requests relating to data subject rights, withdrawals of consent, objections to processing, or any other data protection matters may be directed to:
Moenus Group GmbHMasterclass Cocktail ManufakturAarepark 5A5000 AarauSwitzerland
Email: info@masterclass-cocktail.chTelephone: +41 78 725 78 70
To ensure the correct identification of the requesting individual and to protect personal data from unauthorised disclosure, MCM may request appropriate proof of identity before processing a request.
45.
Appendix A – Website Form Notices
Catering Enquiry Form
Mandatory Notice:
We use the information you provide to process your enquiry, prepare quotations, and organise and deliver potential event and hospitality services.
Required Checkbox:
☐ I have read the Privacy Policy and consent to the processing of my personal data for the purpose of handling my enquiry.
Optional Checkbox:
☐ I would like to receive information about relevant MCM services, events, news, and updates.
Academy Enquiry Form
Mandatory Notice:
We use the information you provide to organise, administer, advise on, and deliver Academy courses, workshops, and training programmes.
Required Checkbox:
☐ I have read the Privacy Policy and consent to the processing of my personal data for the purpose of handling my enquiry.
Optional Checkbox:
☐ I agree that my participation and certification records may be retained internally for the purpose of verifying attendance and issuing future participation or certification confirmations.
Consulting Enquiry Form
Mandatory Notice:
We use the information you provide to assess your enquiry, prepare consultations, develop proposals, and provide consulting services.
Required Checkbox:
☐ I have read the Privacy Policy and consent to the processing of my personal data for the purpose of handling my enquiry.
Application Form
Mandatory Notice:
We use the information you provide solely for the assessment of your application and potential collaboration opportunities.
Required Checkbox:
☐ I have read the Privacy Policy and consent to the processing of my application data.
Optional Checkbox:
☐ I agree that MCM may retain my application information for future employment, freelance, coaching, staffing, or collaboration opportunities within its talent and professional network.

