Status: August 13, 2023
Table of contents
- Responsible
- Overview of the processing
- Relevant legal bases
- Security measures
- Transmission of personal data
- International data transfers
- Rights of the data subjects
- Use of cookies
- Provision of the online offer and web hosting
- Contact and enquiry management
- Presence in social networks (social media)
- Plugins and embedded functions and content
Responsible
Waldemar Bruderer
Stiglenstrasse 33
CH-8052 Zurich
Email:
Relevant legal bases
Relevant legal basis according to the Swiss Data Protection Act: If you are in Switzerland, we process your data on the basis of the Federal Data Protection Act (in short "Swiss DPA", applicable from 01 September 2023). This also applies if our processing of your data otherwise concerns you in Switzerland and you are affected by the processing. The Swiss DPA does not require (unlike the GDPR, for example) that a legal basis for the processing of personal data be stated. We only process personal data if the processing is lawful, is carried out in good faith and is proportionate (Art. 6 para. 1 and 2 of the Swiss DPA). Furthermore, personal data is only obtained by us for a specific purpose that is identifiable to the data subject and is only processed in a way that is compatible with those purposes (Art. 6 para. 3 of the Swiss FADP).
Overview of the processing
The following overview summarises the types of data processed and the purposes of their processing and refers to the data subjects.
Types of data processed
- Inventory data.
- Location data.
- Contact details.
- Content data.
- Usage data.
- Meta, communication and procedural data.
Categories of persons concerned
- Communication partner.
- Users.
Purposes of the processing
- Contact requests and communication.
- Safety measures.
- Managing and responding to enquiries.
- Feedback.
- Marketing.
- Provision of our online offer and user-friendliness.
- Information technology infrastructure.
Security measures
We take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons.
The measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, entry into, disclosure of, assurance of availability of and segregation of the data. We also have procedures in place to ensure the exercise of data subjects' rights, the deletion of data and responses to data compromise. Furthermore, we already take the protection of personal data into account in the development or selection of hardware, software and procedures in accordance with the principle of data protection, through technology design and through data protection-friendly default settings.
Transmission of personal data
In the course of our processing of personal data, the data may be transferred to or disclosed to other bodies, companies, legally independent organisational units or persons. The recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.
International data transfers
Disclosure of personal data abroad: In accordance with the Swiss Data Protection Act (DPA), we only disclose personal data abroad if adequate protection of the data subjects is guaranteed (Art. 16 Swiss DPA). If the Federal Council does not determine adequate protection, we take alternative security measures. These may include international agreements, specific guarantees, data protection clauses in contracts, standard data protection clauses approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC) or internal company data protection regulations recognised in advance by the FDPIC or a competent data protection authority in another country.
According to Art. 16 of the Swiss FADP, exceptions may be allowed for the disclosure of data abroad if certain conditions are met, including consent of the data subject, performance of a contract, public interest, protection of life or physical integrity, data made public or data from a register provided for by law. These disclosures are always made in accordance with legal requirements.
Rights of the data subjects
Rights of data subjects under the Swiss DPA:
As a data subject, you are entitled to the following rights in accordance with the provisions of the Swiss Data Protection Act:
- Right to information: You have the right to request confirmation as to whether personal data concerning you is being processed and to receive the information necessary to enable you to exercise your rights under this law and to ensure transparent data processing.
- Right to data output or transfer: You have the right to request the release of your personal data that you have disclosed to us in a commonly used electronic format.
- Right of rectification: You have the right to request that inaccurate personal data concerning you be corrected.
- Right to object, erasure and destruction: You have the right to object to the processing of your data and to request that the personal data concerning you be deleted or destroyed.
Use of cookies
We use the consent tool "Real Cookie Banner" to manage the cookies and similar technologies (tracking pixels, web beacons, etc.) used and the related consents. Details on how "Real Cookie Banner" works can be found at https://devowl.io/de/rcb/datenverarbeitung/.
The legal basis for the processing of personal data in this context is Art. 6 para. 1 lit. c DS-GVO and Art. 6 para. 1 lit. f DS-GVO. Our legitimate interest is the management of the cookies and similar technologies used and the related consents.
The provision of personal data is neither contractually required nor necessary for the conclusion of a contract. You are not obliged to provide the personal data. If you do not provide the personal data, we will not be able to manage your consents.
Cookies are small text files or other memory notes that store information on end devices and read information from the end devices. For example, to save the login status in a user account, the contents of a shopping basket in an e-shop, the contents called up or the functions used in an online offer. Cookies can also be used for various purposes, e.g. for the purpose of functionality, security and comfort of online offers as well as the creation of analyses of visitor flows.
Notes on consent: We use cookies in accordance with the law. We therefore obtain prior consent from users, except where this is not required by law. In particular, consent is not required if the storage and reading of information, i.e. including cookies, are absolutely necessary in order to provide a telemedia service (i.e. our online offer) expressly requested by the users. Cookies that are strictly necessary usually include cookies with functions that serve the display and operability of the online offer , load balancing, security, storage of users' preferences and choices or similar purposes related to the provision of the main and secondary functions of the online offer requested by users. The revocable consent will be clearly communicated to the users and will contain the information on the respective cookie use.
Information on the legal basis for data protection: The legal basis under data protection law on which we process users' personal data with the help of cookies depends on whether we ask users for consent. If users consent, the legal basis for processing their data is their declared consent. Otherwise, the data processed using cookies is processed on the basis of our legitimate interests (e.g. in the business operation of our online offer and improvement of its usability) or, if this is done in the context of the performance of our contractual obligations, if the use of cookies is necessary to fulfil our contractual obligations. We explain the purposes for which we process the cookies in the course of this data protection declaration or as part of our consent and processing procedures.
Storage period: With regard to the storage period, the following types of cookies are distinguished:
- Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offer and closed their end device (e.g. browser or mobile app).
- Permanent cookies: Permanent cookies remain stored even after the terminal device is closed. For example, the login status can be saved or preferred content can be displayed directly when the user visits a website again. Likewise, user data collected with the help of cookies can be used to measure reach. Unless we provide users with explicit information on the type and storage duration of cookies (e.g. when obtaining consent), users should assume that cookies are permanent and that they can be stored for up to two years.
General information on revocation and objection (so-called "opt-out"): Users can revoke the consent they have given at any time and object to the processing in accordance with the legal requirements. For this purpose, users can, among other things, restrict the use of cookies in the settings of their browser (whereby this may also restrict the functionality of our online offer). An objection to the use of cookies for online marketing purposes can also be made via the websites https://optout.aboutads.info and https://www.youronlinechoices.com/ be explained.
- Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO). Consent (Art. 6 para. 1 p. 1 lit. a) DSGVO).
Further guidance on processing operations, procedures and services:
- Processing of cookie data on the basis of consent: We use a cookie consent management procedure in which the consent of users to the use of cookies, or the processing and providers named in the cookie consent management procedure, can be obtained and managed and revoked by the users. The declaration of consent is stored in order not to have to repeat the request and to be able to prove the consent in accordance with the legal obligation. The storage can take place on the server side and/or in a cookie (so-called opt-in cookie or with the help of comparable technologies) in order to be able to assign the consent to a user or their device. Subject to individual information on the providers of cookie management services, the following information applies: The duration of the storage of consent can be up to two years. A pseudonymous user identifier is created and stored with the time of consent, information on the scope of consent (e.g. which categories of cookies and/or service providers) and the browser, system and end device used; Legal basis: Consent (Art. 6 para. 1 p. 1 lit. a) DSGVO).
Provision of the online offer and web hosting
We process users' data in order to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or terminal device.
- Types of data processed: Usage data (e.g. web pages visited, interest in content, access times). Meta, communication and procedural data (e.g. IP addresses, time data, identification numbers, consent status).
- Persons concerned: Users (e.g. website visitors, users of online services).
- Purposes of the processing: Provision of our online offer and user-friendliness; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.). Security measures.
- Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO).
Further guidance on processing operations, procedures and services:
- Collection of access data and log files: Access to our online offer is logged in the form of so-called "server log files". The server log files may include the address and name of the web pages and files accessed, the date and time of access, the amount of data transferred, notification of successful access, browser type and version, the user's operating system, referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files can be used for security purposes, e.g. to prevent server overload (especially in the case of abusive attacks, so-called DDoS attacks) and to ensure the utilisation of the servers and their stability; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO). Deletion of data: Log file information is stored for a maximum of 30 days and then deleted or anonymised. Data whose further storage is required for evidentiary purposes is exempt from deletion until the respective incident has been finally clarified.
Contact and enquiry management
When contacting us (e.g. by post, contact form, email, telephone or via social media) as well as in the context of existing user and business relationships, the information of the enquiring persons is processed to the extent necessary to respond to the contact enquiries and any measures requested.
- Types of data processed: Contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times). Meta, communication and procedural data (e.g. IP addresses, time data, identification numbers, consent status).
- Persons concerned: Communication partner.
- Purposes of the processing: Contact requests and communication; managing and responding to requests; feedback (e.g. collecting feedback via online form). Provision of our online offer and user-friendliness.
- Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO).
Presence in social networks (social media)
We maintain online presences within social networks and process user data in this context in order to communicate with users active there or to offer information about us.
We would like to point out that user data may be processed outside the European Union. This may result in risks for the users because, for example, it could make it more difficult to enforce the rights of the users.
Furthermore, user data within social networks is usually processed for market research and advertising purposes. For example, usage profiles can be created based on the usage behaviour and resulting interests of the users. The usage profiles can in turn be used, for example, to place advertisements within and outside the networks that presumably correspond to the interests of the users. For these purposes, cookies are usually stored on the users' computers, in which the usage behaviour and the interests of the users are stored. Furthermore, data independent of the devices used by the users may also be stored in the usage profiles (especially if the users are members of the respective platforms and are logged in to them).
For a detailed presentation of the respective forms of processing and the options to object (opt-out), we refer to the data protection declarations and information provided by the operators of the respective networks.
In the case of requests for information and the assertion of data subject rights, we would also like to point out that these can be asserted most effectively with the providers. Only the providers have access to the users' data and can take appropriate measures and provide information directly. If you still need help, you can contact us.
- Types of data processed: Contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms); usage data (e.g. websites visited, interest in content, access times). Meta, communication and procedural data (e.g. IP addresses, time data, identification numbers, consent status).
- Persons concerned: Users (e.g. website visitors, users of online services).
- Purposes of the processing: Contact requests and communication; feedback (e.g. collecting feedback via online form). Marketing.
- Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO).
Further guidance on processing operations, procedures and services:
- Instagram: Social network; Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO); Website: https://www.instagram.com. Privacy Policy: https://instagram.com/about/legal/privacy.
- Facebook pages: Profiles within the social network Facebook - We are jointly responsible with Meta Platforms Ireland Limited for the collection (but not further processing) of data from visitors to our Facebook page (so-called "Fanpage"). This data includes information about the types of content users view or interact with, or the actions they take (see under "Things you and others do and provide" in the Facebook Data Policy: https://www.facebook.com/policy), as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data; see under "Device Information" in the Facebook Data Policy: https://www.facebook.com/policy). As explained in the Facebook Privacy Policy under "How do we use this information?", Facebook also collects and uses information to provide analytics services, called "Page Insights", to Page operators to provide them with insights into how people interact with their Pages and the content associated with them. We have entered into a specific agreement with Facebook ("Page Insights Information", https://www.facebook.com/legal/terms/page_controller_addendum), which regulates in particular which security measures Facebook must observe and in which Facebook has agreed to fulfil the rights of data subjects (i.e. users can, for example, send information or deletion requests directly to Facebook). The rights of users (in particular to information, deletion, objection and complaint to the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the "Information on Page Insights" (https://www.facebook.com/legal/terms/information_about_page_insights_data); Service provider: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO); Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/about/privacy; Basis third country transfer: EU-US Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum). Further information: Agreement on joint responsibility: https://www.facebook.com/legal/terms/information_about_page_insights_data. The joint responsibility is limited to the collection by and transfer of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, which concerns in particular the transfer of the data to the parent company Meta Platforms, Inc. in the USA (on the basis of the standard contractual clauses concluded between Meta Platforms Ireland Limited and Meta Platforms, Inc.).
Plugins and embedded functions and content
We integrate functional and content elements into our online offer that are obtained from the servers of their respective providers (hereinafter referred to as "third-party providers"). These can be, for example, graphics, videos or city maps (hereinafter uniformly referred to as "content").
The integration always requires that the third-party providers of this content process the IP address of the user, as without the IP address they would not be able to send the content to their browser. The IP address is thus required for the display of this content or function. We endeavour to only use content whose respective providers only use the IP address to deliver the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as "web beacons") for statistical or marketing purposes. The "pixel tags" can be used to analyse information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user's device and may contain, among other things, technical information about the browser and operating system, referring websites, time of visit and other information about the use of our online offering, as well as being linked to such information from other sources.
- Types of data processed: Usage data (e.g. websites visited, interest in content, access times); meta, communication and procedural data (e.g. IP addresses, time data, identification numbers, consent status); inventory data (e.g. names, addresses); contact data (e.g. e-mail, telephone numbers); content data (e.g. entries in online forms). Location data (information on the geographical position of a device or person).
- Persons concerned: Users (e.g. website visitors, users of online services).
- Purposes of the processing: Provision of our online offer and user-friendliness.
- Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO).
Further guidance on processing operations, procedures and services:
- Google Maps: We integrate the maps of the "Google Maps" service of the provider Google. The data processed may include, in particular, IP addresses and user location data; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO); Website: https://mapsplatform.google.com/; Privacy Policy: https://policies.google.com/privacy. Basis third country transfer: EU-US Data Privacy Framework (DPF).
- YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Legitimate interests (Art. 6 para. 1 p. 1 lit. f) DSGVO); Website: https://www.youtube.com; Privacy Policy: https://policies.google.com/privacy; Basis third country transfer: EU-US Data Privacy Framework (DPF). Possibility of objection (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, settings for the display of advertisements: https://adssettings.google.com/authenticated.
Created with the free Datenschutz-Generator.de by Dr. Thomas Schwenke