Privacy policy
Last updated: October 2026
This Privacy Policy explains how PAVE Space SA collects and uses personal data when you visit our website, contact us, submit a mission enquiry through “Book a flight”, or apply for a position with us. It also explains your choices and how to exercise your data protection rights.
Who is responsible for your data
The controller for this website, mission enquiries and applications for our current Swiss positions is:
PAVE Space SA, Route d’Arvel 19, 1844 Villeneuve, Vaud, Switzerland.
For questions about this policy or your personal data, contact privacy@pave.space. You may also write to us at the address above, marked “Privacy”.
Our German group company is Pave Space GmbH, Alte Landstraße 23, 85521 Ottobrunn, Germany. Its membership of the PAVE group does not automatically make it a controller of your Swiss application or give it access to that application. If we recruit for a German position or propose transferring your application to another group company, we will identify the responsible company and explain the relevant processing before doing so.
Information we collect
Website visits and security
When your device connects to our website, our infrastructure providers process technical information needed to deliver and protect the service. This can include your IP address, request time, requested page, browser and operating-system information, referring page where supplied by your browser, and security or error information.
For submission rate limits, our application services use a keyed, pseudonymous identifier derived from your IP address rather than storing the raw address in the application record. This does not mean that your connection is anonymous: our infrastructure and security providers may still process the IP address.
If you access a restricted preview or an internal service, authentication may also involve your work email address, login and session information, and access permissions.
Enquiries and mission requests
When you contact us or use “Book a flight”, we process the information you provide, such as your name, organisation, contact details and correspondence. A mission request may also include your preferred orbit, timeline, payload mass and dimensions, deployment interface, power requirements and mission notes. Some of this is business information, but it may identify you or other individuals.
Please do not include classified information, export-controlled technical material, passwords or other information requiring a specially agreed secure channel in a general website form.
Applications
We process the position you select, or your choice to submit a spontaneous application, together with the information you provide. This may include your name, email address, telephone number, location, availability, motivation, professional links, employment and education history, qualifications and any CV you upload. CV uploads are limited to PDF files.
We also process correspondence and job-related information generated during recruitment, such as interview arrangements, relevant assessment notes and the outcome of your application. If you supply professional links, we may review the professional information you have chosen to share through them. We do not need access to your private social-media accounts.
Provide only information relevant to the position. Unless we specifically request it through an appropriate process and explain why, do not send identity-document copies, financial-account details, medical information, criminal-record information or other sensitive personal data. Make sure you are entitled to share any information about other people, such as references. We will discuss reference checks with you before contacting a referee.
Information from other sources
We normally obtain your information directly from you or from your use of the website. Where relevant to a recruitment process, we may also receive information from a referee you have agreed we may contact or a recruitment provider acting in connection with your application. Where required, we will tell you the source and provide the relevant privacy information.
Why we use your information
We use personal data to:
- deliver, operate and protect the website, authenticate access where necessary, prevent automated abuse and investigate technical or security incidents;
- answer enquiries, assess mission requirements, communicate with you and take steps towards a potential business relationship;
- assess your suitability for the position concerned, arrange recruitment activities, communicate with you and decide whether to enter into an employment relationship;
- maintain proportionate records, handle privacy requests, comply with legal obligations and establish, exercise or defend legal claims.
We do not sell your personal data. Sending an enquiry or application does not subscribe you to marketing communications. A spontaneous application is not consent to indefinite storage or to inclusion in a talent pool. We do not place applications in an optional talent pool under this policy.
Applicable law and legal grounds
We process personal data in accordance with the Swiss Federal Act on Data Protection and other applicable Swiss law. For Swiss recruitment, we limit processing to information relevant to your suitability for the position or necessary for the prospective employment relationship, in accordance with Article 328b of the Swiss Code of Obligations.
Where the EU General Data Protection Regulation applies, our grounds for processing are, as appropriate:
- steps you request before entering into a contract, or performance of a contract, under Article 6(1)(b);
- compliance with a legal obligation under Article 6(1)(c);
- legitimate interests under Article 6(1)(f), including securing our services, responding to business contacts, organising recruitment and protecting legal rights, subject to your interests and fundamental rights;
- your consent under Article 6(1)(a), where we separately request it for a specific optional purpose.
For a business enquiry submitted on behalf of your organisation, our interest in communicating with its representative may be the relevant ground rather than a contract with you personally. We do not treat acknowledgement of this policy as blanket consent to all processing. If we need consent for a particular activity, we will explain that activity and ask separately. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.
Required and optional information
Fields marked as required are needed to handle the relevant request or application. Other fields are optional. If you do not provide sufficient contact information or information needed to assess your request, we may be unable to respond or proceed. You are not required to provide information that is unrelated to the purpose of the form.
Who can access your data
Within PAVE Space SA, access is limited to people who need the information for their responsibilities, such as the relevant hiring team, staff handling a mission enquiry, and authorised technical or administrative personnel.
We use service providers for website hosting, storage, security, communications and technical support. Our website infrastructure uses Cloudflare, including its hosting and storage services, access controls and Turnstile anti-bot protection. Providers acting on our behalf are subject to appropriate data-processing and confidentiality arrangements.
We may also disclose necessary information to professional advisers, courts, regulators or other competent authorities where required by law or necessary to establish, exercise or defend legal claims. We do not make CVs or application records publicly accessible.
Cloudflare Turnstile and access protection
Our forms use Cloudflare Turnstile to distinguish legitimate visitors from automated abuse. Turnstile processes technical signals such as IP address, browser information and connection characteristics. A form submission may be refused if the security check cannot be completed.
Cloudflare describes its processing for protecting our website and its separate processing to improve Turnstile in its Turnstile Privacy Addendum. Additional information is available in Cloudflare’s Privacy Policy.
Restricted previews and internal services may use Cloudflare Access and our identity provider to verify that a person is authorised to enter. These controls are separate from the recruitment assessment itself.
Cookies and external content
Security and authentication features may use cookies or similar browser storage to maintain an authorised session, remember a security check or prevent abuse. Blocking these features may prevent access to a restricted area or successful use of a form.
The website does not use application or mission-request information for behavioural advertising. If we introduce optional analytics or marketing technologies that require consent, we will explain their use and provide the necessary choice before activating them.
Some articles may contain embedded content from external providers, such as YouTube or Vimeo. When that content loads, the provider can receive connection information, including your IP address, and may use its own cookies or similar technologies. YouTube’s privacy-enhanced mode does not mean that no personal data is transmitted. Information about those providers is available in Google’s Privacy Policy and Vimeo’s Privacy Policy.
Links to external websites or social platforms take you to services operated under their own privacy policies. We do not control their processing.
Where data is processed
Our application databases and CV storage are configured for European Union jurisdiction. This is a storage configuration, not a guarantee that all processing, security checks, support access or network traffic stays within the EU. Authorised staff in Switzerland may access application information, and infrastructure services may process technical or application data internationally.
Where data is transferred to a country without an applicable recognition of adequate protection, we use the safeguards required by the applicable law, such as approved standard contractual clauses with the necessary Swiss adaptations and supplementary measures where needed, or another legally permitted mechanism. You can contact privacy@pave.space for information about the safeguards relevant to your data and a copy where applicable, subject to necessary redactions protecting confidential information or the rights of others.
How long we keep your data
We retain personal data only for the purpose for which it is needed, taking account of applicable legal obligations and the need to establish, exercise or defend legal claims.
Recruitment
We keep an application while the relevant recruitment process is active. We periodically review open applications and close processes that no longer have a recruitment purpose; leaving an application unanswered does not justify keeping it indefinitely.
For an unsuccessful Swiss application, we delete the application file no later than three months after communicating the rejection, unless a specific legal obligation or an actual or reasonably anticipated dispute justifies retaining limited information for longer. In that case, access and use are restricted to that purpose, and we delete the retained information when the reason ends.
If you withdraw your application, we stop considering you for the position and delete information that is no longer needed. Any limited retention for a legal obligation or legal claim remains subject to the necessity and restriction described above. The same principles apply when a position is cancelled or a spontaneous application is closed without an offer.
If you join PAVE Space, we transfer only information needed for the employment relationship into the personnel process and provide the applicable employee privacy information. Unnecessary recruitment material is not retained simply because you have been hired.
We do not retain your application for future unrelated vacancies through an optional talent pool. Any future proposal to do so would require separate information, a defined retention period and, where applicable, your freely given consent.
Enquiries, security records and backups
We keep enquiries and related correspondence while needed to answer you and manage any resulting business relationship. For enquiries that do not result in a contract, we delete or irreversibly anonymise the record within 12 months after the enquiry is closed. We review inactive enquiries at least every six months and close them when there is no longer an active purpose for keeping them.
Where an enquiry results in a contract, we retain only the information needed for that relationship and applicable legal obligations or claims. Swiss accounting records subject to Article 958f of the Code of Obligations are retained for ten years from the end of the relevant financial year. This does not mean that all enquiries, correspondence or application records are retained for ten years.
For records processed under our responsibility, the following operational limits apply:
- Routine website request and diagnostic logs are deleted or irreversibly anonymised within 30 days of collection.
- Security audit records identifying authorised staff access and administrative actions are retained for up to six months from the event, unless a specific legal logging obligation requires longer retention. These records do not contain CVs or the contents of application forms. References that could identify an applicant are removed or irreversibly anonymised when the relevant application is deleted, unless necessary for a documented legal obligation or incident investigation.
- Incomplete or abandoned file uploads that are not linked to an accepted submission are deleted within 24 hours of upload. Files rejected by validation or malware checks are deleted within seven days of that technical rejection. This is distinct from a decision about an applicant's suitability for employment.
- Following deletion from live systems, remaining recovery copies expire within a further 30 days. We do not retain additional long-term backup copies of website enquiry or application records.
Where a particular security incident, legal obligation or actual or reasonably anticipated dispute requires longer retention, we retain only the necessary information, restrict its use to that purpose and delete it when that reason ends. We do not extend every record's retention period because an unrelated incident or dispute exists.
Deletion deadlines include routine cleanup time; scheduled processing is not a reason to retain live records beyond those deadlines. Recovery copies are restricted to recovery purposes, not routine recruitment or reuse. Where a backup is restored, we reapply applicable deletion instructions before the restored data returns to normal use. Providers processing information for their own independent purposes describe their retention practices in their own privacy notices, linked above.
Security and automated checks
We use technical and organisational safeguards designed to limit unauthorised access, loss and misuse. These include access controls, separation of public submission services from staff records, and restricted document storage.
Uploaded CVs are subject to file validation and malware checks before they become available to recruiting staff. A file may be rejected or delayed if it is unsupported, cannot be inspected or fails a security check. These controls do not assess your suitability for employment. No system can guarantee absolute security; if a technical control prevents you from submitting an application, contact us so that we can discuss a suitable alternative.
We do not use the website application process to make solely automated hiring decisions with legal or similarly significant effects. Hiring decisions are made by people. Security and anti-abuse checks may automatically block a request or file; you may contact us if you believe this happened incorrectly.
Your rights
Depending on the law applicable to your data, you may ask us to:
- confirm whether we process your personal data and provide access to it;
- correct inaccurate or incomplete information;
- delete information or restrict its processing where the legal conditions are met;
- provide certain information in a portable format where that right applies;
- stop processing based on consent after you withdraw it.
Where processing is based on legitimate interests and the GDPR applies, you may object on grounds relating to your particular situation. We will then assess whether we have overriding lawful grounds to continue. You may object to direct marketing at any time.
To make a request, write to privacy@pave.space. Please describe your request and provide enough information for us to locate the relevant records. We may ask for proportionate information to verify your identity, but please do not send identity documents unless we request them through an appropriate channel. We will respond within the time required by applicable law and explain any lawful restriction or extension.
You may raise a concern with the Swiss Federal Data Protection and Information Commissioner. Where the GDPR applies, you may also complain to the competent supervisory authority, including the authority in the EU Member State of your habitual residence, place of work or the alleged infringement. Contacting us first is not a condition for exercising that right.
Changes to this policy
We may update this policy when our services, processing or legal requirements change. The current version and its update date will be available on this page. Where a change requires additional notice or a new choice from you, we will provide it as required by law.