An Island of Light1- 30 September 2026

Privacy Policy



Last updated: 16 August, 2026


→ About Michelangelo Foundation for Creativity and Craftsmanship and this Privacy Policy


Michelangelo Foundation for Creativity and Craftsmanship hosts the Swiss location of Michelangelo Foundation for Creativity and Craftsmanship and has its registered offices at Rue du Rhône 8, 1204 Geneva, Switzerland. In this privacy policy (“Privacy Policy”), we use the term “Michelangelo Foundation” (and "we", "us" and "our") to refer to the Michelangelo Foundation for Creativity and Craftsmanship at the registered address above and our premises located at the address above.


This Privacy Policy explains how we collect, use, disclose and transfer the personal data that you provide to us through our websites (including www.homofaber.com, evaluation-tool.homofaber.com and www.michelangelofoundation.org), mobile applications (including the Homo Faber mobile application), by telephone or through social media (together, the “Platforms”). It also explains how we process personal data when you activate or use Homo Faber Connect within the mobile application. We process personal data in accordance with Swiss law and, where applicable, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).


The Platforms are managed and modified by the Michelangelo Foundation.



→ Updates to this Privacy Policy


From time to time we may update this Privacy Policy and the Cookies Policy. When we do, we will publish the changes on this Platform.



→ Information you provide to us and how we use it


We may collect personal data from you as detailed below:


To access certain areas of our Platform, you register to have access on the Platform. This registration process uses a single sign-on solution of Authentification called Auth 0, available for all the Homo Faber platforms and some of its partners.


During such registration process you will be asked to submit personal information about yourself (including your name and address, date of birth, e-mail address, country and telephone number, etc.). By entering your details in the fields requested, you enable the Michelangelo Foundation, directly or through its partners, to provide you with the services you select.


By registering on the platform, you may be invited to answer questionnaires.


When you purchase products online or by phone, we collect information such as your purchase details and relevant payment data


When you correspond with us (for example, if you contact us with a query), or if you contact the Michelangelo Foundation by telephone we may collect personal information from you. Please note that phone calls may be recorded for security, training and development purposes.


If you choose to interact with the Michelangelo Foundation via a social media platform or other third party service, we will collect the information you have provided to us through that platform.


We also collect certain information automatically about visitors to our Platform, described in the section headed "Cookies and other information that we automatically collect", below.


We will collect data about your location to the extent that we provide any location services, described in the section headed “Location services” below.



We will use the data we collect from you to:


Manage and fulfil purchase orders and facilitate delivery, if any.


Manage our accounts and records.


Deal with your enquiries and requests.


Send service-related communications, including announcements and administrative messages such as order confirmation, if applicable.Identify products, services or contents we think you might be interested in based on your information, such as your purchase history, pages visits and researches on the website, if any, and your previous interactions with us.


Send you marketing communications relating to the Michelangelo Foundation and, where applicable, our partners, including by email or in-app or push notifications, where we have a lawful basis to do so. We will obtain consent where required and you may opt out at any time (please see the “Your choices” section below).


Conduct market research so that we can continuously improve the services we provide. and


Understand how our Platform is used so that we can continuously improve the Platform.


Ensure compliance with legal and regulatory obligations



Where you have agreed to a particular use of your information, we process it on the basis of your consent. You may withdraw that consent at any time (for example, for us to send you marketing communications or to use optional location or analytics features) by contacting us or using the relevant settings. We also process your data where this is necessary for the performance of a contract with you, for compliance with a legal obligation, or for our legitimate interests in operating, securing and improving our business, preventing fraud and abuse, protecting users, and establishing, exercising or defending legal claims. Where applicable law provides a public-interest basis for a particular processing activity, we will rely on it only to the extent supported by that law. The Connect-specific activities and bases are described below.


By visiting any event organised by the Michelangelo Foundation:


You are aware that you may receive details and information such as practical information about transportation, Food and Beverages, workshops, programme and planification of your visit at this event.


You agree to be photographed and video-recorded (in particular through security cameras) and your personal information may have been provided to us in order for us to give you access to the exhibition (“Exhibition”).


Please note that Michelangelo Foundation for Creativity and Craftsmanship may use your personal data in order to enable your access to the Exhibition and related services, such as information about the Exhibition’s programme, your security and internal statistics.


→ Homo Faber Connect


If you choose to activate Homo Faber Connect, an optional feature of the Homo Faber mobile application, we process additional personal data to create and operate your Connect account, provide profiles, connections, recommendations and direct messaging, protect users and comply with applicable law. You may use the other features of the Platforms without activating Connect where those features are available. Registration and account data. To activate Connect, we process your name, email address, country or region, telephone number (if you provide it), date of birth or age-gate confirmation, authentication identifiers and account status. Some information may be required to create or secure your account; optional information will be identified in the app.


Profile data and images. You may choose to provide a biography, craft interests, preferred materials, favorite cities or destinations, event preferences, a profile picture, additional photographs and other free-text information. We process the text and images you upload or transmit, including personal data about you or other people shown in them. You do not have to complete optional profile fields, but they may help other users identify you and improve connection or event recommendations. Do not post personal data that you would not want to be visible under your chosen settings.


Location data. If you allow location access or provide a city or destination, we process device-derived or user-provided location information (which may be derived from GPS, sensors, beacons, Wi-Fi access points or similar signals) to suggest connections in your area or in destinations you plan to visit and to support relevant event recommendations. Location access is optional and can be withdrawn in your device or app settings, although location-based functionality may be reduced.


Connections and recommendations. We process connection requests, accepted connections, profiles viewed, your connections and other Connect activity to operate the service and generate personalized connection suggestions. We may use your profile fields, interests, destinations, event preferences and, where provided, location. You may adjust your profile or activate private mode to stop appearing in matching suggestions. This matching is automated ranking only and does not make decisions producing legal or similarly significant effects.


Direct messages and communications. Where direct messaging is enabled, we process the content of direct messages and related information, such as who communicated with whom, when and, if applicable, attachments and reports, to deliver messages, operate notifications, support the service, investigate abuse and protect users. Connect messaging is not end-to-end encrypted. Direct messages are subject to automated moderation scanning as described in “AI-assisted moderation” below. If you do not wish to have message content processed for these safety purposes, please do not use the direct messaging feature. Note: v1 of Connect does not support posts, comments, replies or likes; direct messaging is the only social interaction feature at launch. Additional social features may be introduced in subsequent versions.


Visibility and sharing. Connect allows you to connect with users who choose to connect with you. By default, your profile is visible only to users you have connected with or to anyone who receives a direct link to your profile. You may make your profile public through your settings or activate private mode, which excludes you from matching suggestions. Users you connect with may see the profile information you have made available to them and communicate with you through direct messages. Public content may be viewed or re-shared by others.


We use the data described above, including your profile, profiles you have viewed, connections, interests, destinations, event preferences and, where provided, location, to generate and rank personalized connection suggestions and, where offered, event recommendations. You can control the data used by editing your profile or activate private mode to opt out of appearing in matching suggestions.


Lawful bases for Homo Faber Connect. We use the following lawful bases, depending on the feature and the requirements of applicable law:


Performance of contract. We process registration and account data, profile information you choose to provide, connections, message content and related metadata, and other information needed to provide Connect features that you request.


Consent. We rely on consent where required for device-based location, non-essential cookies, SDKs or analytics, marketing communications, or other optional processing. You may withdraw consent at any time; withdrawal does not affect processing already carried out and may reduce functionality.


Legitimate interests and legal obligations. We process data to secure the Platforms, moderate content, prevent fraud and abuse, respond to reports, enforce the Terms of Use, improve the service, protect users and establish, exercise or defend legal claims. We rely on legal obligations where applicable.


Homo Faber Connect is intended for users aged 18 or over, or any higher minimum age required by applicable law. Before activating Connect, you must confirm that you meet the applicable minimum age; we record the confirmation and its time. If we learn that we have collected personal data from someone below the applicable minimum age in connection with Connect, we will take steps to delete it and may suspend the account.


Connect is not intended to collect or require special category or other sensitive personal data. Do not include genetic, biometric or health data, data revealing racial or ethnic origin, political opinions, religious or ideological convictions, trade union membership, sexual life or sexual orientation, criminal history or similar sensitive information in your profile, images or messages. If you nevertheless provide such information, we will process it only where permitted by applicable law and may remove or restrict it.


AI-assisted moderation. To keep Connect safe, comply with applicable law and enforce the Terms of Use, we review public content and, if applicable, direct messages using internal AI-assisted moderation technology and human review. Connect messaging is not end-to-end encrypted, which allows proactive safety scanning where direct messaging is enabled.


Public content. Profiles, biographies, profile pictures and other images are scanned when submitted and may be scanned periodically thereafter, including scheduled scans, using internal AI-assisted moderation technology built on Gemini. Content flagged as potentially prohibited is sent to our moderation team for review; automated tools do not by themselves remove content or suspend an account.


Direct messages. Where direct messaging is enabled, direct messages are processed by GetStream for delivery and scanned using internal AI-assisted moderation technology built on Gemini for automated moderation triage. The moderation technology analyses message content and identifies potentially prohibited material, including illegal content, threats, harassment or other violations of the Terms of Use, for review by designated moderators. We will configure GetStream not to use data provided by us for its own system testing or model improvements, subject to final contract and configuration confirmation. Our internal moderation technology is not used to train or improve AI models outside the approved Homo Faber Connect safety use case.


Reports and enforcement. Users or third parties may report profiles, images, biographies or messages through the app. A moderator may review reported or flagged content and related account data to decide whether to leave it in place, remove or restrict it, warn the user, or suspend or terminate an account. We will provide reasons and an appeal route where required by applicable law and the Terms of Use; no moderation action is taken by automated means alone.


We may also use personal data, including communications and technical information, to secure the Platforms, prevent or investigate fraud, abuse or violations of law or the Terms of Use, protect users and others, and respond to serious threats. We may preserve or disclose relevant data to law enforcement or other authorities where permitted or required by law.



Our services may evolve and new Connect features may require new categories of personal data or materially change how we use or share it. We will provide additional notice and update this Privacy Policy before or when those changes take effect, as required by applicable law.



→ Cookies and other information that we automatically collect


Our websites and mobile applications, including Homo Faber Connect, use cookies and similar technologies in accordance with our Cookie Policy. On the mobile application, similar technologies may include software development kits (SDKs), local storage, pixels, device or advertising identifiers, push-notification tokens, log files and other technologies that recognize a device or record how the app is used. Essential technologies are used to authenticate users, maintain sessions, provide security, operate messaging and notifications, remember settings and deliver requested features. We use non-essential analytics or other SDKs only as described in the Cookie Policy and, where required, after obtaining your consent. You can manage optional technologies through the cookie banner, app settings or device settings.



→ IP addresses


We may collect technical and usage data from your computer or mobile device, including IP address, device and app identifiers, operating system, device model, browser type (where applicable), log-in times, crash and error logs, event logs, push-token status and information about how you use the Platforms. We use this information to authenticate users, provide and secure the Platforms, troubleshoot, prevent fraud, measure performance and conduct analytics. We may use aggregated or de-identified information for reporting and service improvement.



→ Location services


Where you enable location services, the app may process information derived from GPS, sensors, beacons, Wi-Fi access points or comparable signals. We use this information for the Connect purposes described above, including connection suggestions in your area or planned destinations and relevant event recommendations. Location permission is optional; you can turn it off in device settings or within the app. If you do so, location-based features may not work, but you can continue to use Connect without sharing location unless a feature requires it.



→ Sharing your information


We share personal data only as described in this Privacy Policy, where necessary to provide the Platforms, where you choose to make it visible, or where permitted or required by law. When we use service providers, we require them to process personal data under our instructions and contractual safeguards.


Service providers. We share personal data with providers that support authentication and account management (including Auth0, if used), hosting and cloud infrastructure, app operation, customer support, communications, security, analytics and other IT services. These providers may process identifiers, contact and account data, technical and usage data and User Content as necessary for their services.


If you activate Connect, other users may see your profile, images, biography, interests and other User Content according to your settings. People you connect with may communicate with you through direct messages, where that feature is enabled. Content that you make public may be viewed or re-shared by others, so you should not provide information that you do not want to make public. Note: v1 of Connect does not support posts, comments, replies or likes; additional social features may be introduced in subsequent versions.



Messaging and moderation providers. We share the data necessary to operate Connect messaging with Stream.io, Inc. (GetStream), which provides messaging infrastructure and acts as our processor, where direct messaging is enabled. This may include profile and connection identifiers, sender and recipient metadata, message content and, if applicable, attachments and reports, For safety moderation, public content and, where direct messaging is enabled, message content is processed using internal AI-assisted moderation technology built on Gemini. We require GetStream to process personal data only for the relevant services and not for its own purposes, subject to the applicable DPA and configuration. Our internal moderation technology is not used to train or improve AI models outside the approved Homo Faber Connect safety use case.



We may disclose personal data to law enforcement, courts, regulators, public authorities or other third parties where necessary to comply with law, respond to lawful requests, protect users or others, or establish, exercise or defend legal rights. In an emergency involving an imminent threat to life or safety, we may preserve or disclose relevant data as permitted by law.


we will disclose your personal information to any third party that purchases, or to which we transfer, all or substantially all of our assets and business. Should such a sale or transfer occur, we will use reasonable efforts to try to ensure that the entity to which we transfer your personal information uses it in a manner that is consistent with this Privacy Policy.



→ International transfers


We may transfer personal data to countries outside Switzerland, the European Economic Area and the United Kingdom, including to service providers and their sub-processors. For transfers subject to European, UK or Swiss data protection law, we rely on an adequacy decision or an applicable transfer framework (including the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Data Privacy Framework where available) or the EU and UK Standard Contractual Clauses and any required Swiss modifications, together with supplementary measures where appropriate. Stream may process personal data in the United States or wherever it or its sub-processors operate, subject to these safeguards.



→ Protecting your information


We want you to feel confident about using our Platform, and we are committed to protecting the personal information we collect. We limit access to personal information about you to employees who reasonably need access to it, to provide products or services to you or in order to do their jobs. We have appropriate technical and organisational physical, electronic, and procedural safeguards to protect the personal information that you provide to us against unauthorised or unlawful processing and against accidental loss, damage or destruction. However, where we ask you to choose a password in order to access certain parts of our Platform, you are responsible for selecting a secure password and keeping that password confidential. You should choose a password which you do not use on any other site, and you should not share it with anyone else.



→ Retaining your information


We keep personal data only as long as necessary for the purposes described in this Privacy Policy, including to provide the Platforms, meet legal and regulatory obligations, resolve disputes, enforce our Terms of Use, protect users, prevent fraud and abuse, and establish, exercise or defend legal claims. When personal data is no longer needed, we delete it or anonymise it. For Connect, while your account is open we retain the information needed to operate your profile, connections and, if applicable, messaging, recommendations and moderation. If you delete your Connect profile or close your account, we will generally remove your profile and content from public view promptly and delete active account data within 30 days.



Some data may be retained after deletion: (i) direct messages in active GetStream systems are intended to be deleted after 7 days, unless flagged for moderation or subject to a legal hold; (ii) moderation records where no violation is found are retained for up to 6 months, with only minimal report metadata thereafter where needed to detect malicious or duplicate reporting; (iii) content removed or restricted is retained for up to 24 months; (iv) records relating to suspended or terminated accounts are retained for up to 5 years to prevent ban evasion and support appeals or legal defence; and (v) data escalated to Group Legal or authorities, or preserved for an imminent threat, may be frozen for longer, including indefinitely, until the matter is resolved. These periods remain subject to applicable law and final technical and business confirmation.


Legal holds and preservation. We may pause deletion and preserve relevant personal data, including messages, reports, moderation records, account data and technical logs, where reasonably necessary for legal claims, investigations, audits, law-enforcement requests, safety emergencies or legal or regulatory obligations. We will delete or anonymise preserved data when the hold or obligation ends, subject to applicable law and normal backup cycles.


If we sought your consent to process your personal information and we have no other lawful basis to continue with that processing, and you withdraw your consent, we will stop the relevant processing and delete the applicable personal data, subject to data retained for legal holds, legal obligations, security, fraud prevention or the establishment, exercise or defence of legal claims.


If you request that we no longer send you direct marketing communications, we will keep a record of your request and contact details to ensure that your request is respected.



→ Your choices


You may have the following rights under applicable law: to access your personal data and receive a copy; to correct inaccurate or incomplete data; to request deletion; to request restriction of processing; to object to processing based on our legitimate interests or, where applicable, the public interest, including profiling for recommendations, and to direct marketing; to receive data in a portable format; to withdraw consent where processing is based on consent; and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where applicable. We may need to verify your identity, and these rights are subject to applicable exceptions, including legal obligations, rights of others, security and fraud prevention, and legal holds.


You can ask us to stop sending direct marketing communications at any time. We may continue to send service-related communications, such as account, security, moderation or feature notices. If you wish to exercise any of your rights, please write to us at the address listed below or use the relevant settings within the app where available.


If you use Homo Faber Connect, you may at any time, through the app settings where available: edit or delete individual profile items; remove images; change profile visibility; activate private mode; turn off location access; manage push notifications; delete individual messages; delete your Connect profile; or delete your entire account. Deletion is applied to our systems and, subject to periods needed to preserve flagged content or comply with a legal hold, we will instruct our service providers to apply deletion in accordance with their contracts and applicable law. Deletion may not remove copies retained by message recipients or content already shared by others.


Moderation and automated processing. You may challenge a moderation action through the appeal function described in the Terms of Use. Connection suggestions use automated processing but are not legal or similarly significant decisions, and moderation decisions are not made solely by automated means.


You may unsubscribe from e-mail marketing communications at any time by e-mailing the address below in the section headed “Contact us” or updating this information in your personal account on homofaber.com if you created it or clicking on the ‘unsubscribe’ link in any Michelangelo Foundation and Homo Faber marketing e-mails.


If you have a concern about how we use your information, as a first step please contact us using the details set out below and we will do our best to resolve your concern. After investigating your concern, we will respond to you in writing within a reasonable time setting out our proposed remedial action. If you think we have processed your personal information in a manner which is unlawful or breaches your rights you also have the right to complain to a European Data Protection Authority in your place of residence or work, or the jurisdiction in which the processing took place.



→ Contact us


If you have any questions or comments about this Privacy Policy or Cookie Policy, or about how we process personal data in connection with Homo Faber Connect, please contact us at the address provided below. You can also use this address to exercise your rights, request access to the personal data we hold about you or unsubscribe from further marketing communications. Please identify the relevant account or email address and the nature of your request; we may ask for information to verify your identity.



Michelangelo Foundation for Creativity and Craftsmanship

Rue du Rhône 8

1204 Geneva, Switzerland