Preamble

The following privacy policy is intended to inform you about the types of personal data (hereinafter also referred to simply as «data») that we process, the purposes for which we do so, and the extent to which we process it. This Privacy Policy applies to all processing of personal data carried out by us, both in the course of providing our services and, in particular, on our websites and within external online platforms, such as our social media profiles (hereinafter collectively referred to as the «online offering»).

The terms used are not gender-specific.

As at 28 September 2026

Table of Contents

Data controller

Swiss Media Design GmbH
Bahnhofstrasse 49
9470 Buchs SG
Switzerland

T: +41 81 756 00 30
E: info@swissmediadesign.com

Overview of processing operations

The following overview summarises the types of data processed and the purposes for which they are processed, and identifies the data subjects.

Types of data processed

  • Stock data.
  • Payment details.
  • Location data.
  • Contact details.
  • Table of contents.
  • Contract details.
  • Usage data.
  • Meta data, communication data and procedural data.
  • Log data.

Categories of data subjects

  • Beneficiaries and clients.
  • Prospective customers.
  • Communication partners.
  • Users.
  • Business and contractual partners.

Purposes of processing

  • Provision of contractual services and fulfilment of contractual obligations.
  • Communication.
  • Safety measures.
  • Direct marketing.
  • Range measurement.
  • Tracking.
  • Office and organisational procedures.
  • Target group identification.
  • Organisational and administrative procedures.
  • Feedback.
  • Marketing.
  • Profiles containing user-related information.
  • Provision of our online services and user-friendliness.
  • Information technology infrastructure.
  • Public relations.
  • Sales promotion.
  • Business processes and management practices.

Relevant legal bases

Relevant legal bases under the GDPR: Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country or ours, depending on where you or we are resident or have our registered office. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.

  • Consent (Article 6(1), first sentence, point (a) of the GDPR) – The data subject has given their consent to the processing of their personal data for a specific purpose or for several specific purposes.
  • Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR) – The processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.
  • Legal obligation (Article 6(1), first sentence, point (c) of the GDPR) – The processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR) – the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that such interests are not overridden by the interests, fundamental rights and freedoms of the data subject which require the protection of personal data.

Relevant legal bases under the Swiss Data Protection Act: If you are in Switzerland, we process your data in accordance with the Federal Act on Data Protection (the „Swiss FADP» for short). Unlike, for example, the GDPR, the Swiss Data Protection Act does not, in principle, require a legal basis to be specified for the processing of personal data, and stipulates that the processing of personal data must be carried out in good faith and must be lawful and proportionate (Art. 6(1) and (2) of the Swiss Data Protection Act). Furthermore, we only collect personal data for a specific purpose that is recognisable to the data subject and only process it in a manner compatible with that purpose (Art. 6(3) of the Swiss Data Protection Act).

Applicability of data protection regulations in the country where the company is based: In the country where the controller is established, national data protection regulations apply in addition to the General Data Protection Regulation (GDPR).

Safety measures

We implement technical and organisational measures appropriate to the circumstances and the purposes of the processing, as well as to the varying probabilities of occurrence and the severity of the threat to the rights and freedoms of natural persons, in accordance with the statutory requirements, taking into account the state of the art, the costs of implementation, and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihoods and severity of threats to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, and safeguarding of the availability of the data, and ensuring its segregation. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is deleted and that appropriate action is taken in the event of a data breach. Furthermore, we take the protection of personal data into account right from the development and selection stages of hardware, software and procedures, in accordance with the principle of data protection by design, through technical design and data protection-friendly default settings.

Securing online connections using TLS/SSL encryption technology (HTTPS): To protect users’ data transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the presence of ‘HTTPS’ in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.

Transfer of personal data

In the course of our processing of personal data, it may happen that such data is transferred to or disclosed to other bodies, companies, legally independent organisational units or individuals. Recipients of this data may include, for example, service providers commissioned to carry out IT tasks or providers of services and content integrated into a website. In such cases, we comply with the statutory requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.

International data transfers

Data processing in third countries: Where we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in connection with the use of third-party services or the disclosure or transfer of data to other persons, bodies or organisations (which can be identified by the postal address of the respective provider or where the privacy policy expressly refers to data transfers to third countries), this is always carried out in accordance with the legal requirements.

For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the European Commission dated 10 July 2023. In addition, we have entered into standard contractual clauses with the relevant service providers which comply with the European Commission’s requirements and set out contractual obligations to protect your data.

This dual safeguard ensures comprehensive protection of your data: the DPF provides the primary layer of protection, whilst the Standard Contractual Clauses serve as an additional safeguard. Should any changes arise in relation to the DPF, the Standard Contractual Clauses will act as a reliable fallback option. In this way, we ensure that your data remains adequately protected at all times, even in the event of any political or legal changes.

For each service provider, we will inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the US Department of Commerce’s website at https://www.dataprivacyframework.gov/ (in English).

Appropriate security measures apply to data transfers to other third countries, in particular standard contractual clauses, explicit consent or transfers required by law. Information on transfers to third countries and applicable adequacy decisions can be found on the European Commission’s website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

Disclosure of personal data abroad: In accordance with the Swiss Data Protection Act, we only disclose personal data abroad if adequate protection for the data subjects is guaranteed (Art. 16 of the Swiss Data Protection Act). Where the Federal Council has not determined that adequate protection exists (list: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we take alternative security measures.

For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by a Swiss adequacy decision dated 15 September 2024. In addition, we have entered into standard data protection clauses with the relevant service providers, which have been approved by the Federal Data Protection and Information Commissioner (FDPIC) and set out contractual obligations regarding the protection of your data.

This dual safeguard ensures comprehensive protection of your data: the DPF provides the primary layer of protection, whilst the Standard Data Protection Clauses serve as an additional safeguard. Should any changes arise in relation to the DPF, the Standard Data Protection Clauses will act as a reliable fallback option. In this way, we ensure that your data remains adequately protected at all times, even in the event of any political or legal changes.

For each service provider, we will inform you whether they are certified under the DPF and whether standard data protection clauses are in place. You can find the list of certified companies and further information on the DPF on the US Department of Commerce’s website at https://www.dataprivacyframework.gov/ (in English).

Appropriate security measures apply to data transfers to other third countries, including international treaties, specific safeguards, standard data protection clauses approved by the FDPIC, or internal corporate data protection policies recognised in advance by the FDPIC or a competent data protection authority in another country.

General information on data storage and deletion

We delete the personal data we process in accordance with statutory provisions as soon as the underlying consents are withdrawn or there is no longer any legal basis for processing. This applies to cases where the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule apply where legal obligations or specific interests require the data to be retained or archived for a longer period.

In particular, data which must be retained for commercial or tax law reasons, or where storage is necessary for the purposes of legal proceedings or to protect the rights of other natural or legal persons, must be archived accordingly.

Our privacy notices contain additional information on the retention and deletion of data, which applies specifically to certain processing operations.

Where there are several specifications regarding the retention period or deletion deadlines for a particular item of data, the longest period shall always apply. We process data that is no longer retained for its originally intended purpose, but rather due to legal requirements or other reasons, exclusively for the purposes that justify its retention.

Data retention and deletion: The following general time limits apply to data retention and archiving under Swiss law:

  • 10 years: retention period for books and records, annual accounts, inventories, management reports, opening balance sheets, accounting vouchers and invoices, as well as all necessary work instructions and other organisational documents (Art. 958f of the Swiss Code of Obligations (CO)).
  • 10 years: Data necessary for the assessment of potential claims for damages or similar contractual claims and rights, as well as for the processing of related enquiries, based on previous business experience and standard industry practices, will be retained for the statutory limitation period of ten years, unless a shorter period of five years applies, which is relevant in certain cases (Art. 127, 130 OR). After five years, claims for rent, lease payments and interest on capital, as well as other periodic payments arising from the supply of foodstuffs, for board and lodging and for pub debts, as well as from craft work, the retail sale of goods, medical services, professional services provided by solicitors, legal agents, attorneys-at-law and notaries, and from the employment relationship of employees (Art. 128 OR).

Commencement of a time limit at the end of the year: If a time limit does not expressly commence on a specific date and is of a duration of at least one year, it shall automatically commence at the end of the calendar year in which the event triggering the time limit occurred. In the case of ongoing contractual relationships under which data is stored, the event triggering the time limit is the date on which the termination or other cessation of the legal relationship takes effect.

Rights of data subjects

Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:

  • Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. Where personal data relating to you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
  • Right of access: You have the right to request confirmation as to whether the data in question is being processed, and to request access to this data, as well as further information and a copy of the data, in accordance with the legal requirements.
  • Right to rectification: In accordance with the relevant legal provisions, you have the right to request that the data relating to you be completed or that any inaccurate data relating to you be rectified.
  • Right to erasure and restriction of processing: In accordance with the statutory provisions, you have the right to request that data relating to you be erased without delay or, alternatively, in accordance with the statutory provisions, to request a restriction on the processing of such data.
  • Right to data portability: You have the right to receive the data relating to you that you have provided to us in a structured, commonly used and machine-readable format, in accordance with the relevant legal requirements, or to request that it be transferred to another data controller.
  • Complaint to the supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place where the alleged infringement occurred, if you consider that the processing of personal data relating to you infringes the provisions of the GDPR.

Rights of data subjects under the Swiss Data Protection Act (DSG):

As a data subject, you are entitled to the following rights in accordance with the provisions of the Swiss Data Protection Act (DSG):

  • Right of access: You have the right to request confirmation as to whether personal data relating to you is being processed, and to receive the information necessary to enable you to exercise your rights under this Act and to ensure that data processing is carried out transparently.
  • Right to data disclosure or data portability: You have the right to request that we provide you with the personal data you have supplied to us in a commonly used electronic format.
  • Right to rectification: You have the right to request the rectification of any inaccurate personal data relating to you.
  • Right to object, erasure and destruction: You have the right to object to the processing of your data and to request that your personal data be deleted or destroyed.

Business services

We process the personal data of our contractual and business partners, such as customers, clients, prospective customers, suppliers and other cooperation partners (collectively referred to as „contractual partners»), for the purpose of establishing, implementing and managing contractual relationships and similar legal relationships. This also includes pre-contractual measures carried out upon request, as well as communication relating to the respective contractual relationship.

The processing serves, in particular, to fulfil our principal and ancillary contractual obligations. These include the provision of the agreed services, any obligations to provide updates and information, the handling of warranty claims and other breaches of performance, the processing of cancellations, terminations of continuing contractual relationships, reversals, refunds, and the processing of other contract-related declarations and enquiries. This covers both one-off contracts and ongoing contractual relationships.

In particular, we process master data such as name, address and, where applicable, company name; contact details such as email address and telephone number; contract and service data such as the subject matter of the contract, contract term, order or transaction number; usage and performance data; payment and billing data; and the content and history of communications. Where necessary, we also process data that is disclosed or transmitted to us in the course of carrying out an order.

Furthermore, we process the data to safeguard our rights and to fulfil legal obligations. This includes, in particular, retention requirements under commercial and tax law, documentation requirements and, where applicable, obligations to provide evidence and account for our actions. Furthermore, processing takes place on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, as well as in protecting our business operations and our contractual partners from misuse and threats to data, confidential information and other legal interests. This may also involve the use of external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax and legal advisers or other agents, insofar as this is necessary for the performance of the contract or to fulfil legal obligations.

Personal data will only be disclosed to third parties to the extent that this is necessary for the performance of a contract, the implementation of pre-contractual measures, the protection of legitimate interests or the fulfilment of legal obligations. We provide separate information regarding any further processing, in particular for marketing purposes, within this privacy policy.

We inform our contractual partners of the data required in each individual case when collecting data, for example by clearly indicating this in online forms or during face-to-face contact.

Data will be deleted as soon as it is no longer required for the aforementioned purposes and there are no statutory retention obligations preventing this. Statutory retention periods, in particular under commercial and tax law, may require data to be retained for a longer period. We will delete data transmitted in connection with a specific order once the order has been completed and any retention periods have expired, provided there are no further statutory or contractual obligations to retain the data.

The legal basis for the processing is Article 6(1)(b) of the GDPR for the implementation of pre-contractual measures and the fulfilment of the relevant contractual relationship, as well as Article 6(1)(c) of the GDPR for the fulfilment of legal obligations. Where processing is based on legitimate interests, it is carried out on the basis of Article 6(1)(f) of the GDPR. Where processing is based on Article 6(1)(f) of the GDPR, it is carried out to safeguard our legitimate interests in the proper and efficient organisation of our business, the internal administration and documentation of business transactions, the enforcement and defence of legal claims, ensuring IT and data security, preventing misuse and fraud, and the economic management and further development of our business operations. These interests consist, in particular, of ensuring secure and legally compliant business operations and safeguarding our ability to act as a business.

  • Types of data processed: Personal details (e.g. full name, home address, contact details, customer number, etc.); payment details (e.g. bank details, invoices, payment history); contact details (e.g. postal and email addresses or telephone numbers). Contract details (e.g. subject matter of the contract, term, customer category).
  • People affected: Service recipients and clients; prospective clients. Business and contractual partners.
  • Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; communication; office and organisational procedures; organisational and administrative procedures. Business processes and business management procedures.
  • Retention and deletion: Deletion in accordance with the information set out in the section «General information on data storage and deletion».

Provision of the online service and web hosting

We process users’ data in order to provide them with our online services. To this end, we process the user’s IP address, which is necessary to deliver the content and functions of our online services to the user’s browser or device.

  • Types of data processed: Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved). Log data (e.g. log files relating to logins, data retrieval or access times).
  • People affected: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)). Security measures.
  • Retention and deletion: Deletion in accordance with the information set out in the section «General information on data storage and deletion».

Further information on processing procedures, methods and services:

  • Hosting an online service on rented server space: To provide our online services, we use storage space, computing capacity and software which we rent or otherwise obtain from a relevant server provider (also known as a «web host»); Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
  • Hostpoint (server location: Switzerland): We host our online services with Hostpoint AG. The website and the data generated in connection with it (including server log files) are hosted on servers in Switzerland; Service provider: Hostpoint AG, Neue Jonastrasse 60, 8640 Rapperswil-Jona, Switzerland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Website: https://www.hostpoint.ch; Privacy Policy: https://www.hostpoint.ch/hostpoint/kontakt-agb.html#datenschutz.
  • Collection of access data and log files: Access to our online service is logged in the form of so-called «server log files». Server log files may include the address and name of the web pages and files accessed, the date and time of the request, the volume of data transferred, confirmation of a successful request, browser type and version, the user’s operating system, the referrer URL (the page visited previously) and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, e.g. to prevent server overload (particularly in the event of malicious attacks, known as DDoS attacks), and, on the other hand, to ensure server capacity utilisation and stability; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and is then deleted or anonymised. Data which must be retained for evidential purposes is exempt from deletion until the relevant incident has been fully resolved.

Use of cookies

The term „cookies» refers to functions that store and retrieve information on users’ devices. Cookies may also be used for various purposes, such as ensuring the functionality, security and user-friendliness of online services, as well as for analysing visitor traffic. We use cookies in accordance with legal requirements. To this end, we obtain users’ consent in advance where necessary. Where consent is not required, we rely on our legitimate interests. This applies where the storage and retrieval of information is essential to provide explicitly requested content and functions. This includes, for example, the storage of settings and ensuring the functionality and security of our online services. Consent may be withdrawn at any time. We provide clear information about the scope of this and which cookies are used.

Information on the legal basis for data protection: Whether we process personal data using cookies depends on consent. Where consent has been given, this serves as the legal basis. Where no consent has been given, we rely on our legitimate interests, which are explained earlier in this section and in the context of the relevant services and procedures.

Retention period: With regard to their storage duration, a distinction is made between the following types of cookies:

  • Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest once a user has left an online service and closed their device (e.g. browser or mobile application).
  • Persistent cookies: Persistent cookies remain stored even after the device has been switched off. This allows, for example, the user’s logged-in status to be retained and their preferred content to be displayed immediately when they revisit a website. Similarly, user data collected via cookies may be used for audience measurement. Unless we provide users with explicit information regarding the type and storage period of cookies (e.g. when seeking consent), they should assume that these are persistent and that the storage period may be up to two years.

General information on withdrawal and opting out: Users may withdraw the consents they have given at any time and may also object to the processing of their data in accordance with the relevant legal requirements, including via their browser’s privacy settings.

  • Types of data processed: Meta data, communication data and transaction data (e.g. IP addresses, time stamps, identification numbers, individuals involved).
  • People affected: Users (e.g. website visitors, users of online services).

Further information on processing procedures, methods and services:

  • Processing of cookie data on the basis of consent: We use a consent management solution to obtain users’ consent to the use of cookies or to the procedures and providers specified within the consent management solution. This procedure serves to obtain, log, manage and revoke consents, in particular with regard to the use of cookies and similar technologies employed to store, read and process information on users’ end devices. As part of this procedure, users’ consent is obtained for the use of cookies and the associated processing of information, including the specific processing activities and providers mentioned in the consent management procedure. Users also have the option to manage and withdraw their consents. Consent declarations are stored to avoid having to request them again and to be able to provide evidence of consent in accordance with legal requirements. Storage takes place on the server and/or in a cookie (known as an ‘opt-in cookie’) or using comparable technologies, in order to be able to associate the consent with a specific user or their device. In the absence of specific details regarding the providers of consent management services, the following general guidelines apply: Consent is stored for up to two years. A pseudonymous user identifier is created, which is stored together with the time of consent, details of the scope of consent (e.g. relevant categories of cookies and/or service providers) and information about the browser, the system and the end device used; Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR).

Blogs and publication media

We use blogs or similar means of online communication and publication (hereinafter referred to as «publication medium»). Readers’ data is processed for the purposes of the publication medium only to the extent necessary for its presentation and for communication between authors and readers, or for security reasons. For all other matters, please refer to the information on the processing of visitors to our publication medium as set out in this privacy policy.

  • Types of data processed: Master data (e.g. full name, home address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); Content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation); Usage data (e.g. page views and time spent on the site, click paths, intensity and frequency of use, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
  • People affected: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Feedback (e.g. collecting feedback via an online form); provision of our online services and user-friendliness; security measures; organisational and administrative procedures.
  • Retention and deletion: Deletion in accordance with the information set out in the section «General information on data storage and deletion».

Further information on processing procedures, methods and services:

  • Comments and posts: When users leave comments or other posts, their IP addresses may be stored on the basis of our legitimate interests. This is done for our own protection in the event that someone posts unlawful content in comments or contributions (insults, prohibited political propaganda, etc.). In such cases, we ourselves could be held liable for the comment or contribution and are therefore interested in the author’s identity.

    Furthermore, we reserve the right to process users’ data for the purpose of detecting spam, on the basis of our legitimate interests.

    On the same legal basis, we reserve the right, in the case of surveys, to store users’ IP addresses for the duration of the survey and to use cookies to prevent multiple votes.

    We store the personal information provided in comments and posts, any contact and website details, as well as the content of the posts, on a permanent basis until the user objects; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Contact and enquiry management

When you contact us (e.g. by post, via the contact form, by email, by telephone or via social media), and in the context of existing user and business relationships, the personal data provided by the enquirers is processed to the extent necessary to respond to enquiries and to carry out any requested actions.

  • Types of data processed: Contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, individuals involved).
  • People affected: Communication partners.
  • Purposes of processing and legitimate interests: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form). Provision of our online services and user-friendliness.
  • Retention and deletion: Deletion in accordance with the information set out in the section «General information on data storage and deletion».

Further information on processing procedures, methods and services:

  • Contact form: When you contact us via our contact form, by email or through other channels of communication, we process the personal data provided to us in order to respond to and deal with your enquiry. This generally includes details such as your name, contact details and, where applicable, any further information provided to us that is necessary for the matter to be dealt with appropriately. We use this data exclusively for the stated purpose of establishing contact and communication; Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Marketing communications via email, post, fax or telephone

We process personal data for the purposes of marketing communications, which may be carried out via various channels, such as email, telephone, post or fax, in accordance with legal requirements.

Recipients have the right to withdraw their consent at any time or to opt out of marketing communications at any time, free of charge, using the contact details provided above.

Following revocation or objection, we store the data necessary to prove prior authorisation for contacting you or sending you communications for up to three years after the end of the year in which the revocation or objection took place, on the basis of our legitimate interests. The processing of this data is limited to the purpose of potentially defending against claims. On the basis of our legitimate interest in permanently honouring users’ withdrawals or objections, we also store the data necessary to prevent us from contacting them again (e.g. depending on the communication channel, the email address, telephone number or name).

  • Types of data processed: Master data (e.g. full name, home address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers). Content data (e.g. text-based or image-based messages and posts, as well as related information such as details of authorship or the time of creation).
  • People affected: Communication partners.
  • Purposes of processing and legitimate interests: Direct marketing (e.g. by email or post); marketing; sales promotion.
  • Retention and deletion: Deletion in accordance with the information set out in the section «General information on data storage and deletion».

Web analytics, monitoring and optimisation

Web analytics (also referred to as „reach measurement») is used to analyse visitor traffic to our website and may include pseudonymised data on visitors’ behaviour, interests or demographic information, such as age or gender. With the help of audience measurement, we can, for example, identify at what times our online platform, its functions or its content are used most frequently, or encourage repeat visits. It also enables us to identify which areas require optimisation.

In addition to web analytics, we can also use testing methods to, for example, test and optimise different versions of our website or its components.

Unless otherwise stated below, profiles, i.e. data aggregated to reflect a usage session, may be created for these purposes, and information may be stored in a browser or on a device and subsequently retrieved. The data collected includes, in particular, websites visited and the features used on them, as well as technical information such as the browser used, the computer system used and details of usage times. Where users have consented to the collection of their location data by us or by the providers of the services we use, the processing of location data is also possible.

In addition, users’ IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymisation by truncating the IP address) to protect users. Generally speaking, no personally identifiable data (such as email addresses or names) is stored in the context of web analytics, A/B testing and optimisation; instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective processes.

Notes on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved).
  • People affected: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Audience measurement (e.g. traffic statistics, identification of returning visitors); profiles containing user-specific information (creation of user profiles). Provision of our online services and user-friendliness.
  • Retention and deletion: Deletion in accordance with the information set out in the section «General information on data storage and deletion». Cookies may be stored for up to two years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
  • Safety measures: IP masking (pseudonymisation of IP addresses).

Further information on processing procedures, methods and services:

  • Google Analytics: We use Google Analytics to measure and analyse the use of our online service on the basis of a pseudonymous user identification number. This identification number does not contain any personally identifiable data, such as names or email addresses. It serves to associate analytical information with a device in order to identify which content users have accessed during one or more sessions, which search terms they have used, whether they have revisited the content, or how they have interacted with our online service. The time of use and its duration are also stored, as well as the sources from which users have accessed our online service and technical details of their devices and browsers.
    In doing so, pseudonymous user profiles are created using information derived from the use of various devices, and cookies may be used for this purpose. Google Analytics does not log or store individual IP addresses for EU users. However, Analytics provides approximate geographical location data by deriving the following metadata from IP addresses: city (and the derived latitude and longitude of the city), continent, country, region, subcontinent (and ID-based equivalents). For EU data traffic, IP address data is used exclusively for this derivation of geolocation data before being deleted immediately. It is not logged, is not accessible and is not used for any other purposes. When Google Analytics collects measurement data, all IP lookups are carried out on EU-based servers before the traffic is forwarded to Analytics servers for processing; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR); Website: https://marketingplatform.google.com/intl/de/about/analytics/; Safety measures: IP masking (pseudonymisation of the IP address); Privacy Policy: https://business.safety.google/privacy/; Data Processing Agreement: https://business.safety.google/adsprocessorterms/; Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses (https://business.safety.google/adsprocessorterms), Data Privacy Framework (DPF), Standard Contractual Clauses ( https://business.safety.google/adsprocessorterms); Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of adverts: https://myadcenter.google.com/personalizationoff. Further information: https://business.safety.google/adsservices/ (Types of processing and the data processed).
  • Unterscheidung nach Aufenthaltsort: Für Besuche aus der Schweiz stützen wir die Reichweitenmessung auf unser überwiegendes Interesse an einer bedarfsgerechten Gestaltung unseres Onlineangebotes (Art. 31 Abs. 1 DSG) in Verbindung mit Art. 45c FMG, der eine Widerspruchsmöglichkeit genügen lässt. Sie können der Messung jederzeit über den Cookie-Hinweis widersprechen. Für Besuche aus dem Europäischen Wirtschaftsraum und dem Vereinigten Königreich erfolgt die Messung ausschliesslich auf Grundlage Ihrer Einwilligung (Art. 6 Abs. 1 lit. a DSGVO, Art. 5 Abs. 3 ePrivacy-Richtlinie). Lässt sich der Aufenthaltsort nicht zweifelsfrei bestimmen, behandeln wir den Besuch wie einen aus dem Europäischen Wirtschaftsraum.
  • Keine Werbefunktionen: Die Messung ist so eingerichtet, dass keine Google-Signale erhoben, keine Daten für personalisierte Werbung verwendet und keine Zielgruppen an Google Ads übergeben werden.

Social media presence

We maintain an online presence on social media platforms and, in this context, process user data in order to communicate with users active on those platforms or to provide information about us.

We would like to point out that user data may be processed outside the European Union as a result. This may entail risks for users, as it could, for example, make it more difficult to enforce their rights.

Furthermore, users’ data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created on the basis of users’ behaviour and the interests derived from it. These profiles may in turn be used, for instance, to display adverts both within and outside the networks that are presumed to correspond to users’ interests. Consequently, cookies are usually stored on users’ computers, in which their usage behaviour and interests are recorded. In addition, data may also be stored in the user profiles regardless of the devices used by users (particularly if they are members of the respective platforms and are logged in there).

For a detailed explanation of the various forms of data processing and the options for objecting (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.

We would also like to point out that, in the case of requests for information and the exercise of data subjects’ rights, these can most effectively be addressed with the service providers. Only the service providers have access to user data and are able to take appropriate action and provide information directly. Should you nevertheless require assistance, please do not hesitate to contact us.

  • Types of data processed: Contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation). Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and features).
  • People affected: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Communication; feedback (e.g. collecting feedback via an online form). Public relations.
  • Retention and deletion: Deletion in accordance with the information set out in the section «General information on data storage and deletion».

Further information on processing procedures, methods and services:

  • Instagram: A social network that allows users to share photos and videos, comment on and like posts, send messages, and follow profiles and pages; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://www.instagram.com; Privacy Policy: https://privacycenter.instagram.com/policy/. Basis for transfers to third countries: Data Privacy Framework (DPF), Data Privacy Framework (DPF).
  • Facebook pages: Profiles on the Facebook social network: The data controller is jointly responsible with Meta Platforms Ireland Limited for the collection and transmission of data relating to visitors to our Facebook page („fan page»). This includes, in particular, information on user behaviour (e.g. content viewed or interacted with, actions taken) as well as device information (e.g. IP address, operating system, browser type, language settings, cookie data). Further details can be found in Facebook’s Data Policy: https://www.facebook.com/privacy/policy/. Facebook also uses this data to provide us, via the „Page Insights» service, with statistical analyses that give us an insight into how people interact with our page and its content. This is based on an agreement with Facebook („Information about Page Insights»: https://www.facebook.com/legal/terms/page_controller_addendum), which sets out, amongst other things, security measures and the exercise of data subjects’ rights. Further information can be found here: https://www.facebook.com/legal/terms/information_about_page_insights_data. Users may therefore submit requests for access or erasure directly to Facebook. Users’ rights (in particular the right of access, erasure, objection and the right to lodge a complaint with a supervisory authority) remain unaffected by this. Joint controllership is limited exclusively to the collection of data by Meta Platforms Ireland Limited (EU). Meta Platforms Ireland Limited is solely responsible for any further processing, including any possible transfer to Meta Platforms Inc. in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://www.facebook.com; Privacy Policy: https://www.facebook.com/privacy/policy/. Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum), Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
  • LinkedIn: Social network: Together with LinkedIn Ireland Unlimited Company, we are responsible for the collection (but not the further processing) of visitor data used to generate the „Page Insights» (statistics) for our LinkedIn profiles. This data includes information about the types of content that users view or interact with, as well as the actions they take. In addition, details of the devices used are collected, such as IP addresses, operating system, browser type, language settings and cookie data, as well as information from user profiles, such as job title, country, sector, hierarchical level, company size and employment status. Information on data protection relating to the processing of user data by LinkedIn can be found in LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy.
    We have entered into a specific agreement with LinkedIn Ireland („Page Insights Joint Controller Addendum», https://legal.linkedin.com/pages-joint-controller-addendum), which sets out, in particular, the security measures that LinkedIn must observe and in which LinkedIn has agreed to uphold the rights of data subjects (i.e. users may, for example, submit requests for access or erasure directly to LinkedIn). Users’ rights (in particular the right of access, erasure, objection and the right to lodge a complaint with the competent supervisory authority) are not restricted by the agreements with LinkedIn. Joint responsibility is limited to the collection and transfer of data to LinkedIn Ireland Unlimited Company, a company based in the EU. Further processing of the data is the sole responsibility of LinkedIn Ireland Unlimited Company, in particular as regards the transfer of data to the parent company, LinkedIn Corporation, in the USA; Service provider: LinkedIn Ireland Unlimited Company, Wilton Plaza, Dublin 2, Ireland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://www.linkedin.com; Privacy Policy: https://www.linkedin.com/legal/privacy-policy; Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.linkedin.com/legal/privacy-policy), Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.linkedin.com/legal/privacy-policy). Right to object (opt-out): https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
  • X: Social network; Service provider: X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://x.com. Privacy Policy: https://x.com/de/privacy.

Plug-ins, embedded features and content

We incorporate functional and content elements into our online service that are sourced from the servers of their respective providers (hereinafter referred to as „third-party providers»). These may include, for example, graphics, videos or city maps (hereinafter collectively referred to as „content»).

This integration always requires the third-party providers of this content to process users„ IP addresses, as they would be unable to send the content to users» browsers without them. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only content where the respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also known as „web beacons») for statistical or marketing purposes. These ‘pixel tags’ enable information, such as visitor traffic on the pages of this website, to be analysed. This pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical details about the browser and operating system, referring websites, the time of the visit and further details regarding the use of our online service; it may also be linked to such information from other sources.

Notes on the legal basis: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is that consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. our interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.

  • Types of data processed: Usage data (e.g. page views and time spent on pages, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved). Location data (information on the geographical position of a device or a person).
  • People affected: Users (e.g. website visitors, users of online services).
  • Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; audience measurement (e.g. traffic statistics, identification of returning visitors); tracking (e.g. interest-based or behavioural profiling, use of cookies); audience segmentation. Marketing.
  • Retention and deletion: Deletion in accordance with the information set out in the section «General information on data storage and deletion». Cookies may be stored for up to two years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).

Further information on processing procedures, methods and services:

  • Google Fonts (local hosting): We use what are known as Google Fonts to ensure consistent font display. The fonts are stored locally on our server and are delivered directly from there. No connection is made to Google’s servers, and no data (in particular, no IP addresses) is transmitted to Google; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
  • Google Maps: We embed maps from the «Google Maps» service provided by Google. The data processed may include, in particular, users’ IP addresses and location data; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://mapsplatform.google.com/; Privacy Policy: https://business.safety.google/privacy/. Basis for transfers to third countries: Data Privacy Framework (DPF), Data Privacy Framework (DPF).
  • YouTube videos: Video content; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Article 6(1), first sentence, point (a) of the GDPR); Website: https://www.youtube.com; Privacy Policy: https://business.safety.google/privacy/; Basis for transfers to third countries: Data Privacy Framework (DPF), Data Privacy Framework (DPF). Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of adverts: https://myadcenter.google.com/personalizationoff.
  • ReviewForest (Review Forest widget): We embed a review widget from ReviewForest GmbH, which is loaded via JavaScript and displays our customer reviews as well as the number of trees planted. According to the provider, no cookies are set, no external fonts are loaded, and IP addresses are anonymised immediately after collection. Cloudflare’s Content Delivery Network is used to ensure rapid global delivery; depending on the visitor’s location, processing may take place outside Switzerland or the EU; Service provider: ReviewForest GmbH, Grossbeerenstrasse 11, 10963 Berlin, Germany; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://reviewforest.org; Privacy Policy: https://de.reviewforest.org/company/privacy-policy-reviewforest-widget; Basis for transfers to third countries: Data Privacy Framework (DPF).

Cloudflare Turnstile

To protect our contact form from automated submissions and spam, we use Cloudflare Turnstile, a service provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Turnstile uses technical characteristics to check whether an entry has been made by a human or an automated programme.

When you use the form, data such as your IP address, information about your browser and device, and interaction signals are transmitted to Cloudflare, where they are processed for the purpose of bot detection. The legal basis for this is our legitimate interest in preventing misuse and ensuring the security of our website (Article 6(1)(f) of the GDPR and the corresponding provisions of the Swiss Data Protection Act (DSG)). Cloudflare processes the data on the basis of standard contractual clauses and the EU-US Data Privacy Framework.

Further information can be found in Cloudflare’s privacy policy at https://www.cloudflare.com/privacypolicy/.

Amendments and updates

We ask that you review the content of our privacy policy regularly. We will update the Privacy Policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any other individual notification.

Where we provide addresses and contact details for companies and organisations in this privacy policy, please note that these details may change over time, and we would ask you to check them before making contact.

Definitions of terms

This section provides an overview of the terms used in this privacy policy. Where these terms are defined by law, their statutory definitions shall apply. The explanations below, however, are intended primarily to aid understanding.

  • Stock data: Master data comprises essential information required for the identification and management of contractual partners, user accounts, profiles and similar assignments. This data may include, amongst other things, personal and demographic details such as names, contact details (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data forms the basis for any formal interaction between individuals and services, organisations or systems by enabling unique mapping and communication.
  • Contents: Content data comprises information generated during the creation, editing and publication of all types of content. This category of data may include text, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not limited to the actual content itself, but also includes metadata that provides information about the content, such as tags, descriptions, author details and publication dates
  • Contact details: Contact details are essential pieces of information that enable communication with individuals or organisations. They include, amongst other things, telephone numbers, postal addresses and email addresses, as well as means of communication such as social media handles and instant messaging identifiers.
  • Meta, communication and procedural data: Meta-data, communication data and procedural data are categories that contain information about the way in which data is processed, transmitted and managed. Meta-data, also known as data about data, comprises information that describes the context, origin and structure of other data. It may include details such as file size, creation date, the author of a document and revision histories. Communication data records the exchange of information between users via various channels, such as email correspondence, call logs, social media messages and chat histories, including the individuals involved, timestamps and transmission routes. Process data describes the processes and procedures within systems or organisations, including workflow documentation, transaction and activity logs, and audit logs used to track and verify operations.
  • Usage data: Usage data refers to information that tracks how users interact with digital products, services or platforms. This data encompasses a wide range of information that reveals how users utilise applications, which features they prefer, how long they spend on specific pages, and the paths they take when navigating through an application. Usage data may also include frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. Furthermore, usage data plays a crucial role in identifying trends, preferences and potential problem areas within digital offerings
  • Personal data: «Personal data» means any information relating to an identified or identifiable natural person (hereinafter referred to as the «data subject»); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or one or more specific characteristics that reflect the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Profiles containing user-related information: The processing of «profiles containing user-related information», or «profiles» for short, encompasses any form of automated processing of personal data which consists of using such personal data to identify certain personal characteristics relating to a natural person (depending on the nature of the profiling, this may include various information relating to demographics, behaviour and interests, such as interaction with websites and their content, etc.), or to predict them (e.g. interests in specific content or products, clicking behaviour on a website or location). Cookies and web beacons are frequently used for profiling purposes.
  • Log data: Log data is information about events or activities that have been logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details regarding the use or operation of a system. Log data is often used to analyse system issues, for security monitoring or to generate performance reports.
  • Range measurement: Audience measurement (also known as web analytics) is used to analyse visitor traffic to an online service and may include the behaviour or interests of visitors with regard to specific information, such as website content. With the help of audience analysis, operators of online services can, for example, identify at what times users visit their websites and what content they are interested in. This enables them, for example, to better tailor the content of their websites to the needs of their visitors. For the purposes of reach analysis, pseudonymous cookies and web beacons are frequently used to recognise returning visitors and thus obtain more accurate analyses of how an online service is used.
  • Location details: Location data is generated when a mobile device (or any other device capable of determining its location) connects to a mobile network cell, a Wi-Fi network or similar technical means and location-determination functions. Location data is used to indicate the geographically identifiable position on Earth at which the device in question is located. Location data can, for example, be used to display map functions or other location-dependent information.
  • Tracking: The term «tracking» is used when users’ behaviour can be tracked across several online services. As a rule, information about behaviour and interests relating to the online services used is stored in cookies or on the servers of the providers of the tracking technologies (known as ‘profiling’). This information can then be used, for example, to display adverts to users that are likely to match their interests.
  • Data controller: The term «controller» refers to the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • Processing: «Processing» means any operation or set of operations which is carried out on personal data, whether or not by automated means. The term is broad and covers virtually any handling of data, whether it be collection, analysis, storage, transmission or erasure.
  • Contract details: Contract data is specific information relating to the formalisation of an agreement between two or more parties. It documents the terms under which services or products are provided, exchanged or sold. This data category is essential for the management and fulfilment of contractual obligations and encompasses both the identification of the contracting parties and the specific terms and conditions of the agreement. Contract data may include the start and end dates of the contract, the nature of the agreed services or products, pricing arrangements, payment terms, termination rights, renewal options and any special conditions or clauses. It serves as the legal basis for the relationship between the parties and is crucial for clarifying rights and obligations, enforcing claims and resolving disputes.
  • Payment details: Payment data comprises all the information required to process payment transactions between buyers and sellers. This data is of crucial importance for e-commerce, online banking and any other form of financial transaction. It includes details such as credit card numbers, bank account details, payment amounts, transaction dates, verification numbers and billing information. Payment data may also include information on payment status, chargebacks, authorisations and fees.
  • Target group identification: The term «Custom Audiences» is used when target groups are defined for advertising purposes, such as the display of adverts. For example, based on a user’s interest in certain products or topics on the internet, it can be inferred that this user would be interested in adverts for similar products or the online shop where they viewed those products. The term «Lookalike Audiences» (or similar target groups) is used when content deemed suitable is displayed to users whose profiles or interests are presumed to correspond to those of the users on whose profiles the Lookalike Audience was based. Cookies and web beacons are generally used for the purpose of creating Custom Audiences and Lookalike Audiences.