Privacy Policy of Alpinamed AG

1. What is this privacy policy about?

Alpinamed AG (hereinafter also «we», «us») collects and processes personal data relating to you or to other persons (so-called «third parties»). We use the term «data» here as synonymous with «personal data».

«Personal data» means data relating to an identified or identifiable person, i.e. data from which conclusions can be drawn about that person's identity, either from the data itself or in combination with additional data. «Particularly sensitive personal data» is a category of personal data that is given special protection under applicable data protection law. Particularly sensitive personal data includes, for example, data revealing racial or ethnic origin, as well as health data, information on religious or philosophical beliefs, biometric data used for identification purposes, and information on trade union membership. Section 3 provides information on the data we process in connection with this privacy policy. «Processing» means any handling of personal data, e.g. collecting, storing, using, modifying, disclosing, and deleting.

In this privacy policy we describe what we do with your data when you use www.alpinamed.ch and other websites of ours (collectively referred to below as the «website»), when you obtain our services or products, when you are otherwise in a contractual relationship with us, when you communicate with us, or when you otherwise have dealings with us. Where applicable, we will inform you in good time in writing about additional processing activities not mentioned in this privacy policy. We may also inform you separately about the processing of your data, for example in declarations of consent, contract terms, additional privacy notices, forms, and notices.

If you transmit or disclose to us data about other persons, such as family members, work colleagues, etc., we assume that you are authorised to do so and that this data is correct. By transmitting data about third parties, you confirm this. Please also ensure that these third parties have been informed of this privacy policy.

This privacy policy is designed to meet the requirements of the EU General Data Protection Regulation («GDPR»), the Swiss Federal Act on Data Protection («FADP»), and the revised Swiss Federal Act on Data Protection («revFADP»). Whether and to what extent these laws apply, however, depends on the individual case.

2. Who is responsible for processing your data?

For the data processing described in this privacy policy, Alpinamed AG, 9306 Freidorf (the «Alpinamed») is responsible under data protection law, unless otherwise communicated in a specific case, for example in other privacy notices, on forms, or in contracts.

For each data processing activity, there is one or more bodies responsible for ensuring that the processing complies with the requirements of data protection law. This body is called the controller. It is responsible, for example, for responding to access requests (section 11) or ensuring that personal data is secured and not used unlawfully.

Other bodies may also be jointly responsible for the data processing described in this privacy policy where they participate in determining the purpose or means of the processing. If you would like information about the individual controllers responsible for a particular data processing activity, you may request this information from us under your right of access (section 11). Alpinamed AG remains your primary point of contact, even where other joint controllers exist.

Sections 3, 7, and 12 contain further information about third parties with whom we cooperate and who are themselves responsible for their own processing. If you have questions or wish to exercise your rights against these third parties, please contact them directly.

You can reach us regarding your data protection concerns and to exercise your rights under section 11 as follows:

Alpinamed AG

Alte Landstrasse 11

9306 Freidorf

admin(at)alpinamed.ch

3. What data do we process?

We process various categories of data about you. The most important categories are as follows:

Technical data: When you use our website or other electronic offerings, we collect the IP address of your device and other technical data in order to ensure the functionality and security of these offerings. This data also includes logs recording the use of our systems. We generally retain technical data for 6 months. In order to ensure the functionality of these offerings, we may also assign an individual code to you or your device (for example in the form of a cookie, see section 12). On their own, technical data generally do not allow any conclusions to be drawn about your identity. However, in connection with user accounts, registrations, access controls, or the handling of contracts, they may be linked to other categories of data (and thus, where applicable, to you as a person). When you visit our webshop, we additionally process technical information required to provide the shop functions. This includes shopping cart contents, session data, IP address, and log data on access and security-relevant events.

Technical data includes, among other things, the IP address and information about your device's operating system, the date, region, and time of use, as well as the type of browser you use to access our electronic offerings. This can help us to deliver the correct formatting of the website or to display, for example, a website adapted to your region. Based on the IP address, we know which provider you use to access our offerings (and thus also the region), but we generally cannot deduce from this who you are. This changes if, for example, you create a user account, because personal data can then be linked with technical data (for example, we see which browser you use to access an account via our website). Examples of technical data also include logs generated in our systems (for example, the log of user logins on our website).

Registration data: Certain offerings, for example competitions and services (such as login areas on our website, newsletter dispatch, etc.), can only be used with a user account or registration, which may take place directly with us or via our external login service providers. In doing so, you must provide us with certain data, and we collect data on the use of the offering or service. When the user account or registration is deleted, the corresponding data is also deleted.

Within our webshop, users can create a customer account or place orders as a guest. In doing so, we process the following registration data: first name, last name, e-mail address, password (for customer accounts), and voluntary information such as gender and date of birth. This data is used to manage the customer account, process orders, communicate with customers, and provide the services offered.

 

Registration data includes, among other things, the information you provide when creating an account on our website. Registration data also includes any data we may require from you before you can use certain free services; you must also register if you wish to subscribe to our newsletter. In connection with access controls, we may need to register you with your data (access codes on badges) (see the category «other data» in this regard).

Communication data: When you are in contact with us via the general e-mail address admin@alpinamed.ch, other e-mail or telephone contacts, by letter, or via other means of communication, we record the data exchanged between you and us, including your contact details and the metadata of the communication. If we record or listen in on telephone calls or video conferences, for example for training and quality assurance purposes (including staff training), we will specifically inform you of this. Such recordings may only be made and used in accordance with our internal guidelines. You will be informed at the start of the conference whether and when such recordings will take place. If you do not wish to be recorded, please let us know or end your participation. If you merely wish to avoid your image being recorded, please switch off your camera. When we want or need to establish your identity, for example in the case of an access request you have made, an application for media access, etc., we collect data to identify you (for example a copy of an identity document). We generally retain this data for 12 months from the last exchange with you. This period may be longer where necessary for evidentiary reasons or to comply with legal or contractual requirements, or for technical reasons. E-mails in personal mailboxes and written correspondence are generally retained for at least 10 years. Recordings of (video) conferences are generally retained for 24 months.

Communication data is your name and your contact details, the manner, place, and time of the communication, and, as a rule, also its content (i.e. the content of e-mails, letters, chats, etc.). This data may also contain information about third parties. For identification purposes, we may also process your identity document number, a password you have set, or your press card. For secure identification, the following mandatory information must be provided in the case of media inquiries: publisher, name of the publication, salutation, first name, last name, postal address, e-mail address, and telephone number of the reporting person.

Master data: We refer to master data as the basic data that we require, in addition to the contract data (see below), in order to conduct our contractual and other business relationships or for marketing and advertising purposes, such as name, contact details, and information, for example about your role and function, your bank details, your date of birth, customer history, powers of attorney, signing authority, and declarations of consent. We process your master data when you are a customer or other business contact, or act on behalf of such a contact (for example as the contact person of a business partner), or because we wish to approach you for our own purposes or those of a contractual partner (for example in connection with marketing and advertising, invitations to events, vouchers, newsletters, etc.). We receive master data from you yourself (for example when making a purchase or in connection with a registration), from bodies for which you work, or from third parties such as our contractual partners, associations, and address brokers, and from publicly accessible sources such as public registers or the internet (websites, social media, etc.). In connection with our webshop we process first name, last name, billing and delivery address, e-mail address, telephone number (if provided), and voluntary information such as gender and date of birth. This data is used for customer administration, order processing, delivery of goods, and communication in connection with an order.

We generally retain this data for 10 years from the last exchange with you, but at least until the end of the contract. This period may be longer where necessary for evidentiary reasons or to comply with legal or contractual requirements, or for technical reasons. For purely marketing and advertising contacts, the period is normally significantly shorter, usually not more than 2 years since the last contact.

 

Master data includes, for example, data such as name, address, e-mail address, telephone number, and other contact details, gender, date of birth, nationality, information about associated persons, websites, social media profiles, photos and videos, copies of identity documents; furthermore, information about your relationship with us (customer, supplier, visitor, service recipient, etc.), information about your status with us, assignments, classifications, and distribution lists, information about our interactions with you (possibly a history of these with corresponding entries), reports (for example from the media) or official documents (for example commercial register extracts, permits, etc.) relating to you. As payment information, we collect, for example, your bank details, account number, and credit card data. Consent or blocking notations also form part of master data, as does information about third parties, for example contact persons, recipients of services, advertising recipients, or representatives.

For contact persons and representatives of our customers, suppliers, and partners, we process as master data, for example, name and address, information about their role, their function within the company, qualifications, and, where applicable, information about superiors, colleagues, and subordinates, and information about interactions with these persons.

Master data is not comprehensively collected for all contacts. Which data we specifically collect depends in particular on the purpose of the processing.

Contract data: This is data that arises in connection with the conclusion or performance of a contract, for example information about contracts and the services to be provided or already provided, as well as data from the period before the conclusion of a contract, information required or used for performance, and information about responses (for example complaints or satisfaction feedback, etc.). We generally collect this data from you, from contractual partners, and from third parties involved in the performance of the contract, but also from third-party sources (for example providers of creditworthiness data) and from publicly accessible sources. We generally retain this data for 10 years from the last contractual activity, but at least until the end of the contract. This period may be longer where necessary for evidentiary reasons or to comply with legal or contractual requirements, or for technical reasons.

In connection with orders placed through our webshop, we process order, delivery, and payment information. This includes information about the products ordered, order number, order date, order value, delivery and billing address, shipping status, and information about payment processing. Customer data collected via the webshop is processed by us for the provision and administration of the webshop, for processing customer inquiries, for contract performance, and to comply with statutory retention obligations. The data may be stored and further processed in our own systems.

Delivery of the ordered products is carried out by Falken Drogerie as our shipping and distribution partner. For this purpose, the personal data required for order processing (name, first name, e-mail address, and date of birth and gender (if voluntarily provided)) is transmitted to Falken Drogerie. Falken Drogerie processes this data for order fulfilment, invoicing, delivery, and for handling customer inquiries relating to the order.

Contract data includes information about the conclusion of the contract, about your contracts, for example the type and date of conclusion of the contract, information from the application process (such as an application for our products or services), and information about the relevant contract (for example its duration) as well as the performance and administration of contracts (for example information relating to invoicing, customer service, support with technical matters, and the enforcement of contractual claims). Contract data also includes information about defects, complaints, and amendments to a contract, as well as information about customer satisfaction, which we may collect, for example, by means of surveys. Contract data furthermore includes financial data such as information about creditworthiness (i.e. information allowing conclusions to be drawn about the likelihood that claims will be settled), reminders, and debt collection. We receive this data partly from you (for example when you make payments), but also from credit reporting agencies and debt collection companies, and from publicly accessible sources (for example a commercial register).

Behavioural and preference data: Depending on the relationship we have with you, we try to get to know you better in order to tailor our products, services, and offerings more closely to your needs. For this purpose, we collect and use data about your behaviour and preferences. We do this by evaluating information about your behaviour within our sphere, and we may also supplement this information with data from third parties – including from publicly accessible sources. Based on this, we can, for example, calculate the likelihood that you will use certain services or behave in a certain way. The data processed for this purpose is in part already known to us (for example when you use our services), or we obtain this data by recording your behaviour (for example how you navigate our website). We anonymise or delete this data once it is no longer meaningful for the purposes pursued, which, depending on the type of data, may be the case after up to 24 months (for product and service preferences). This period may be longer where necessary for evidentiary reasons or to comply with legal or contractual requirements, or for technical reasons. We describe how tracking works on our website in section 12.

 

Behavioural data is information about specific actions, for example your response to electronic communications (for example whether and when you opened an e-mail) or your location, as well as your interaction with our social media profiles and your participation in prize draws, competitions, and similar events. We may, for example, collect your location data wirelessly using unique codes emitted by your mobile phone or when you use our website.

Preference data provides us with insight into your needs, which products or services might be of interest to you, or when and how you are likely to respond to messages from us. We obtain this information from the analysis of existing data such as behavioural data, so that we can get to know you better, tailor our advice and offerings to you more precisely, and generally improve our offerings. To improve the quality of our analyses, we may combine this data with additional data that we also obtain from third parties such as address brokers, government agencies, and publicly accessible sources such as the internet, for example information about your household size, income bracket and purchasing power, purchasing behaviour, and contact details of relatives, as well as anonymous data from statistical offices.

Behavioural and preference data may be evaluated on a personalised basis (for example to show you personalised advertising), but also on a non-personalised basis (for example for market research or product development). Behavioural and preference data may also be combined with other data.

Other data: We also collect data about you in other situations. In connection with administrative or court proceedings, for example, data arises (such as files, evidence, etc.) that may also relate to you. For reasons of health protection, we may also collect data (for example as part of protection plans). We may obtain or create photos, videos, and audio recordings in which you may be recognisable (for example on company tours, training courses, via security cameras, etc.). We may also collect data on who enters certain buildings and when, or who holds corresponding access rights (including in connection with access controls, based on registration data or visitor lists, etc.), who participates in which events or actions (for example competitions) and when, or who uses our infrastructure and systems and when. The retention period for this data depends on the purpose and is limited to what is necessary. This ranges from just a few days for many security cameras, and generally a few weeks for contact tracing data, through visitor data, which is generally retained for 3 months, to reports of events with images, which may be retained for several years or longer.

Much of the data referred to in this section 3 is provided to us by you yourself (for example via forms, in the course of communicating with us, in connection with contracts, when using the website, etc.). You are not obliged to provide it, subject to certain individual cases, for example in connection with binding protection plans (statutory obligations). If you enter into contracts with us or wish to make use of services, you must also provide us with data as part of your contractual obligation under the relevant contract, in particular master, contract, and registration data. When using our website, the processing of technical data is unavoidable. If you wish to obtain access to certain systems or buildings, you must provide us with registration data. With regard to behavioural and preference data, however, you generally have the option of objecting or withholding consent.

We only make certain services available to you if you provide us with registration data, because we or our contractual partners want to know who is using our services or has accepted an invitation to an event, because it is technically necessary, or because we wish to communicate with you. If you, or a person you represent (for example your employer), wish to conclude or perform a contract with us, we must collect corresponding master, contract, and communication data from you, and we process technical data if you wish to use our website or other electronic offerings for this purpose. If you do not provide us with the data required to conclude and perform the contract, you must expect that we will refuse to conclude the contract, that you will be in breach of contract, or that we will not perform the contract. Similarly, we can only send you a reply to an inquiry from you if we process the corresponding communication data and, where you communicate with us online, where applicable also technical data. The use of our website is likewise not possible without us receiving technical data.

To the extent this is not unlawful, we also obtain data from publicly accessible sources (for example debt enforcement registers, land registers, the commercial register, the media, or the internet including social media) or receive data from other companies within our group, from authorities, and from other third parties (such as credit reporting agencies, address brokers, associations, contractual partners, internet analytics services, etc.).

The categories of personal data that we receive from third parties about you include, in particular, information from public registers, information we learn in connection with administrative and court proceedings, information relating to your professional functions and activities (so that, for example, we can conclude and carry out business with your employer with your assistance), information about you in correspondence and meetings with third parties, credit information (to the extent we conduct business with you personally), information about you provided by people in your circle (family, advisors, legal representatives, etc.) so that we can conclude or perform contracts with you or involving you (for example references, your address for deliveries, powers of attorney, information about compliance with legal requirements such as combating fraud, money laundering and terrorism, and export restrictions), information from banks, insurers, and distribution and other contractual partners about your use or provision of services (for example payments, purchases, etc.), information from the media and the internet about you (to the extent indicated in the specific case, for example in connection with a job application, marketing/sales, etc.), your address and, where applicable, interests and other socio-demographic data (in particular for marketing and research purposes), data relating to the use of third-party websites and online offerings, where such use can be attributed to you, and data we receive from distribution, shipping, or payment partners in connection with the processing of orders.

4. For what purposes do we process your data?

We process your data for the purposes explained below. Further information for the online domain can be found in sections 12 and 13. These purposes, and the underlying objectives, constitute legitimate interests of ours and, where applicable, of third parties. Further information on the legal bases for our processing can be found in section 5.

We process your data for purposes relating to communication with you, in particular to respond to inquiries and to assert your rights (section 11) and to contact you if we have any questions. For this purpose, we use in particular communication data and master data, and, in connection with offerings and services used by you, also registration data. We retain this data in order to document our communication with you, for training purposes, for quality assurance, and for follow-up inquiries.

This covers all purposes in connection with which you and we communicate, whether in customer service or advisory contexts, during authentication when using the website, or for training and quality assurance purposes (for example in the customer service area). We further process communication data so that we can communicate with you by e-mail and telephone, as well as via messaging services, chat, social media, letter, and fax. Communication with you usually takes place in connection with other processing purposes, for example so that we can provide services or respond to an access request. Our data processing also serves to document communication and its content.

We process data for the establishment, administration, and performance of contractual relationships. This includes the operation of our webshop, the processing of orders, the administration of customer accounts, the provision of customer service, the organisation of shipping, the execution of payments, and the handling of returns, complaints, and warranty claims.

We conclude contracts of various kinds with our business and private customers, with suppliers, or with contractual partners such as partners in projects or parties to legal disputes. In doing so, we process in particular master data, contract data, and communication data, and, depending on the circumstances, also registration data of the customer or of persons to whom the customer provides a service.

In the course of establishing business relationships, personal data – in particular master data, contract data, and communication data – is collected from potential customers or other contractual partners (for example in an order form or contract) or results from communication. Also in connection with the conclusion of the contract, we process data for checking creditworthiness and for opening the customer relationship. This information is in part checked to ensure compliance with legal requirements.

In connection with the performance of contractual relationships, we process data for managing the customer relationship, for providing and enforcing contractual services (which also includes involving third parties, such as logistics companies, security services, advertising service providers, banks, insurers, or credit reporting agencies, which may in turn provide us with data), for advisory purposes, and for customer support. In connection with orders placed through our webshop, we process personal data for order processing, organising shipping, carrying out and documenting payment transactions, and handling returns, complaints, and warranty claims. To the extent necessary for processing orders, payments, and shipping, personal data may be passed on to commissioned service providers.

The enforcement of legal claims arising from contracts (debt collection, court proceedings, etc.) also forms part of contract performance, as does bookkeeping, the termination of contracts, and public communication.

We process data for marketing purposes and for relationship management, for example to send our customers and other contractual partners personalised advertising for our products and services. This may take place, for example, in the form of newsletters and other regular contact (electronic, postal, telephone), via other channels for which we have your contact information, but also as part of individual marketing campaigns (for example events, competitions, etc.), and may also include free-of-charge services (for example invitations, vouchers, etc.). You may decline such contact at any time (see section 11) or refuse or withdraw consent to being contacted for advertising purposes. With your consent, we can target our online advertising on the internet more precisely at you (see section 12 in this regard).

We evaluate order and usage data from our webshop in order to further develop our product range, services, website, and marketing measures, and to adapt them to the needs of our customers.

For example, with your agreement, we send you information, advertising, and product offers from us and from third parties within and outside the group (for example advertising contractual partners), in print, electronic, or telephone form. For this purpose, we mainly process communication and registration data. Like most companies, we personalise communications so that we can send you individual information and offers that correspond to your needs and interests. For this purpose, we link the data we process about you, determine preference data, and use this data as the basis for personalisation (see section 3 in this regard). We also process data in connection with competitions, prize draws, and similar events.

Relationship management also includes the – where applicable, personalised based on behavioural and preference data – approach to existing customers and their contacts. As part of relationship management, we may also operate a Customer Relationship Management system («CRM»), in which we store the data necessary for maintaining the relationship with customers, suppliers, and other business partners, for example about contact persons, relationship history (for example about products and services purchased or delivered, interactions, etc.), interests, wishes, marketing measures (newsletters, invitations to events, etc.), and other information.

All of this processing is important to us not only in order to promote our offerings as effectively as possible, but also to make our relationships with customers and other third parties more personal and positive, to focus on our most important relationships, and to use our resources as efficiently as possible.

We also process your data for market research, for the improvement of our services and our operations, and for product development.

We strive to continuously improve our products and services (including our website) and to be able to react quickly to changing needs. We therefore analyse, for example, how you navigate our website or which products are used by which groups of people and in what way, and how new products and services can be designed (see section 12 for further details). This gives us insights into the market acceptance of existing products and services and the market potential of new ones. For this purpose, we process in particular master, behavioural, and preference data, but also communication data and information from customer surveys, polls, and studies, as well as other information, for example from the media, social media, the internet, and other public sources. Where possible, we use pseudonymised or anonymised data for these purposes. We may also use media monitoring services or carry out our own media monitoring, processing personal data in the process, in order to conduct media relations work or to understand and respond to current developments and trends.

We may also process your data for security purposes and for access control.

We continuously review and improve the appropriate security of our IT and other infrastructure (for example buildings). Like all companies, we cannot rule out data security breaches with absolute certainty, but we do what we can to reduce the risks. We therefore process data, for example, for monitoring, checks, analysis, and testing of our networks and IT infrastructure, for system and error checks, for documentation purposes, and as part of backups. Access control includes, on the one hand, control of access to electronic systems (for example logging into user accounts) and, on the other hand, physical access control (for example building access). For security purposes (both preventive and for investigating incidents), we also keep access logs or visitor lists and use surveillance systems (for example security cameras). We inform you of surveillance systems at the relevant locations by means of appropriate signage.

We process personal data to comply with laws, directives, and recommendations of authorities, as well as internal regulations («compliance»).

This includes, for example, the implementation of health and safety plans or the statutory measures to combat money laundering and terrorist financing. In certain cases, we may be required to carry out certain checks on customers («Know Your Customer») or to report to authorities. The fulfilment of disclosure, information, or reporting obligations, for example in connection with regulatory and tax law duties, also requires or entails data processing, for example the fulfilment of archiving obligations and the prevention, detection, and investigation of criminal offences and other violations. This also includes receiving and processing complaints and other reports, monitoring communications, internal investigations, or disclosing documents to an authority where we have sufficient grounds or a legal obligation to do so. Personal data about you may also be processed in the context of external investigations, for example by a law enforcement or supervisory authority or a commissioned private body. For all of these purposes, we process in particular your master data, your contract and communication data, and, in certain circumstances, also behavioural data and data from the categories of other data. These legal obligations may arise under Swiss law but also under foreign provisions to which we are subject, as well as self-regulation, industry standards, our own corporate governance, and instructions and requests from authorities.

We also process data for the purposes of our risk management and as part of prudent corporate governance, including operational organisation and business development.

For these purposes, we process in particular master, contract, registration, and technical data, but also behavioural and communication data. For example, as part of our financial management, we must monitor our debtors and creditors, and we must avoid becoming victims of offences and misuse, which may require the evaluation of data according to corresponding patterns. For these purposes, and to protect you and us against fraudulent or abusive activities, we may also carry out profiling and create and process profiles (see also section 6 in this regard). As part of the planning of our resources and the organisation of our operations, we must evaluate and process data on the use of our services and other offerings, or exchange information about this with others (for example outsourcing partners), which may also include your data. The same applies to services provided to us by third parties.

We may process your data for further purposes, for example within the framework of our internal processes and administration or for training and quality assurance purposes.

These further purposes include, for example, training and educational purposes, administrative purposes (such as managing master data, bookkeeping and data archiving, and reviewing, administering, and continuously improving IT infrastructure), the preservation of our rights (for example to assert claims in court, before, or out of court, and before authorities in Switzerland and abroad, or to defend ourselves against claims, for example by preserving evidence, obtaining legal advice, and participating in court or administrative proceedings), and the evaluation and improvement of internal processes. We may use recordings of (video) conferences for training and quality assurance purposes. The preservation of other legitimate interests also forms part of these further purposes, which cannot be exhaustively listed.

5. On what basis do we process your data?

Where we ask you for your consent for certain processing activities (for example the processing of particularly sensitive personal data or for advertising targeting and behavioural analysis on the website), we will inform you separately about the corresponding processing purposes. You may withdraw your consent at any time with effect for the future, by written communication (by post) or, unless otherwise stated or agreed, by e-mail; our contact details can be found in section 2. For withdrawing your consent to online tracking, see section 12. Where you have a user account, withdrawal or contacting us may, where applicable, also be carried out via the relevant website or service. As soon as we have received notification of the withdrawal of your consent, we will stop processing your data for the purposes to which you originally consented, unless we have another legal basis for doing so. Withdrawal of your consent does not affect the lawfulness of processing carried out on the basis of consent prior to withdrawal.

Where we do not ask for your consent for a particular processing activity, we base the processing of your personal data on the fact that the processing is necessary for the establishment or performance of a contract with you (or the body you represent) or that we or third parties have a legitimate interest in doing so, in particular in order to pursue the purposes described in section 4 above and the objectives associated with them, and to be able to carry out corresponding measures. Our legitimate interests also include compliance with statutory provisions, to the extent this is not already recognised as a legal basis under the applicable data protection law (for example, under the GDPR, the law within the EEA and in Switzerland). This also includes the marketing of our products and services, the interest in better understanding our markets, and in leading and developing our company, including its operational business, in a secure and efficient manner.

Where we receive sensitive data (for example health data, information on political, religious, or philosophical views, or biometric data for identification purposes), we may also process your data on other legal bases, for example in the case of disputes, on the basis of the necessity of the processing for possible legal proceedings or for the assertion or defence of legal claims. In individual cases, other legal grounds may apply, which we will communicate to you separately where necessary.

6. What applies to profiling and automated individual decisions?

For the purposes set out in section 4, we may evaluate certain of your personal characteristics on the basis of your data (section 3) in an automated manner («profiling»), where we wish to determine preference data, but also to identify risks of misuse and security risks, to carry out statistical evaluations, or for operational planning purposes. For the same purposes, we may also create profiles, i.e. we may combine behavioural and preference data, as well as master and contract data and technical data associated with you, in order to better understand you as a person with your various interests and other characteristics.

If you are a customer of ours, we can, for example, use «profiling» based on your purchases to determine which further products you are likely to be interested in. We can also use this to check your creditworthiness before offering you a purchase on account. An automated evaluation of data may also, for your protection, check the probability that a particular transaction is fraudulent. This allows us to stop the transaction for clarification. This should be distinguished from «profiles». This refers to the linking of various data in order to draw, from this data as a whole, insights into significant aspects of your personality (for example, what you like or how you behave in certain situations). Profiles may also be used, for example, for marketing purposes, but also for security purposes.

We use anonymous movement profiles in a non-personalised way, for example to provide our contractual partners with recommendations for avoiding peak times. For personalised movement profiles, we use personal data, for example to draw your attention to interesting offers and products in your vicinity, to infer your interests from location data (dwell time), and to inform you which products and services other contractual partners with similar interests have used, or, for example, where health protection plans call for contact tracing.

In both cases, we pay attention to the proportionality and reliability of the results and take measures against the misuse of these profiles or of profiling. Where these may have legal effects or result in significant disadvantages for you, we generally provide for a manual review.

In certain situations, for reasons of efficiency and consistency of decision-making processes, it may be necessary for us to automate discretionary decisions concerning you that have legal effects or may result in significant disadvantages («automated individual decisions»). In this case, we will inform you accordingly and provide for the measures required under applicable law.

An example of an automated individual decision is the automatic acceptance of orders by an online shop. Pure if-then decisions are not covered by this (for example, where the computer allows you to access your user account after checking your password), but rather discretionary decisions (for example, the decision to conclude a contract). We will inform you on a case-by-case basis where an automated decision leads to negative legal consequences or a comparable significant impairment for you. If you disagree with the outcome of such a decision, you will be able to communicate with a human being who will review the decision.

7. To whom do we disclose your data?

In connection with our contracts, the website, our services and products, our legal obligations, or otherwise to safeguard our legitimate interests and the further purposes set out in section 4, we also transmit your personal data to third parties, in particular to the following categories of recipients:

Service providers: We work with service providers in Switzerland and abroad who process data about you on our behalf or under joint responsibility with us, or who receive data about you from us under their own responsibility (for example IT providers, shipping companies, advertising service providers, login service providers, cleaning companies, security companies, banks, insurers, debt collection firms, credit reporting agencies, or address verification services). This may also include health data. For service providers involved in relation to the website, see section 12. Our central IT service providers are Microsoft and Vidyo GmbH as hosting and webshop service provider.

 

In order to provide our products and services efficiently and to focus on our core competencies, we obtain services from third parties in numerous areas. These services relate, for example, to IT services, the dispatch of information, marketing, sales, communication, or printing services, building management, security, and cleaning, the organisation and holding of events and receptions, debt collection, credit reporting agencies, address verification services (for example to update address records in the event of relocations), fraud prevention measures, and services provided by consulting firms, lawyers, banks, insurers, and telecommunications companies. We disclose to these service providers the data necessary for their services, which may also relate to you. For the operation of our website and our webshops, we work in particular with IT, hosting, shipping, logistics, and payment service providers. These process the personal data required to provide the webshop and to process orders, shipping, and payment.

In connection with orders placed through our webshop, the personal data required for delivery and processing of the order is transmitted to Falken Drogerie. This concerns order, contact, billing, and delivery data.

These service providers may also process such data under their own responsibility under data protection law, in particular where they are required to do so under statutory requirements or need the data for their own purposes, for example fraud prevention, compliance with regulatory requirements, billing, or the improvement of their services. Further information on such data processing can be found in the respective privacy policies of the service providers concerned.

Where necessary, we conclude agreements with our service providers to ensure the protection of personal data and compliance with applicable data protection provisions. Further information on how Microsoft processes data can be found here: privacy.microsoft.com/en-us/privacystatement; for the use of Microsoft Teams in particular here: docs.microsoft.com/en-us/microsoftteams/teams-privacy.

Webshop and order processing: In connection with orders placed through our webshop, personal data may be transmitted to involved partners and service providers, to the extent necessary for order, payment, and shipping processing. Delivery of the ordered products is carried out via Falken Drogerie. For this purpose, order, contact, billing, and delivery data may in particular be passed on to Falken Drogerie.

For carrying out online payments, we use the payment service provider Saferpay of Worldline Schweiz AG. The data required for payment processing is transmitted to the payment service provider and processed by it in accordance with the data protection provisions applicable to it. For the technical operation and hosting of the webshop, we work with ViDYO GmbH. It may obtain access to personal data as part of its hosting and support services.

Contractual partners including customers: This refers primarily to customers (for example service recipients) and other contractual partners of ours, since this data transmission results from these contracts. They receive, for example, registration data on vouchers issued and redeemed, invitations, etc. If you yourself act on behalf of such a contractual partner, we may also transmit data about you to it in this context. Recipients also include contractual partners with whom we cooperate or who advertise on our behalf and to whom we therefore transmit data about you for analysis and marketing purposes (these may again be service recipients, but also, for example, sponsors and providers of online advertising). We require these partners to send you advertising or display it based on your data only if you have consented to this (for the online domain, see section 12).

If you act as an employee on behalf of a company with which we have concluded a contract, performance of that contract may result in our informing the company, for example, of how you have used our service. Cooperation and advertising contractual partners receive selected master, contract, behavioural, and preference data from us, so that, on the one hand, they can carry out non-personalised evaluations in their own area (for example on the number of our customers who have viewed their advertising), and, on the other hand, so that they can also use the data for advertising purposes (including targeted outreach to you). For example, advertising contractual partners should have the opportunity to communicate with other matching customers of ours and to send them advertising.

Authorities: We may disclose personal data to government offices, courts, and other authorities in Switzerland and abroad, where we are legally obliged or entitled to do so or where this appears necessary to safeguard our interests. Authorities process, under their own responsibility, the data about you that they receive from us.

 

Examples of application include criminal investigations, police measures (for example health protection plans, combating violence, etc.), regulatory requirements and investigations, court proceedings, reporting obligations, pre-litigation and out-of-court proceedings, as well as statutory duties to inform and cooperate. Disclosure of data may also occur where we wish to obtain information from public bodies, for example to justify an interest in obtaining information or because we need to state about whom we require information (for example from a register).

Other persons: This refers to other cases where the involvement of third parties results from the purposes set out in section 4, for example service recipients, media, and associations in which we participate, or where you are part of one of our publications.

 

Other recipients include, for example, delivery addressees other than yourself or third-party payment recipients, other third parties also within the context of representative relationships (for example where we send your data to your lawyer or your bank), or persons involved in administrative or court proceedings. If we work with the media and transmit material to them (for example photos), you may, in certain circumstances, be affected as well. The same applies to the publication of content (for example photos, interviews, quotes, etc.), for instance on the website or in other publications of ours. As part of business development, we may sell or acquire businesses, business units, assets, or companies, or enter into partnerships, which may also result in the disclosure of data (including about you, for example as a customer or supplier or as a representative of a supplier) to the persons involved in these transactions. Data relating to you may also be exchanged in the context of communication with our competitors, industry organisations, associations, and other bodies.

All these categories of recipients may in turn engage third parties, so that your data may also become accessible to them. We can restrict the processing carried out by certain third parties (for example IT providers), but not that of other third parties (for example authorities, banks, etc.).

We reserve the right to make such data disclosures even where they concern confidential data (unless we have expressly agreed with you that we will not disclose such data to certain third parties, unless we are legally required to do so). Notwithstanding this, your data continues to be subject to appropriate data protection after disclosure within Switzerland and the rest of Europe. For disclosure to other countries, the provisions of section 8 apply. If you do not want certain data to be disclosed, please let us know so that we can examine whether and to what extent we can accommodate your wishes (section 2).

In many cases, the disclosure of confidential data is also necessary in order to perform contracts or provide other services. Confidentiality agreements also generally do not exclude such data disclosures, nor does disclosure to service providers. However, in line with the sensitivity of the data and other circumstances, we take care to ensure that these third parties handle the data appropriately. We cannot comply with your objection to data disclosure where the disclosures in question are necessary for our business activities.

We also enable certain third parties to collect personal data about you themselves on our website and at our events (for example media photographers, providers of tools that we have integrated into our website, etc.). To the extent that we are not decisively involved in these data collections, these third parties are solely responsible for them. For inquiries and to exercise your data protection rights, please contact these third parties directly. See section 12 for the website.

8. Does your personal data also go abroad?

As explained in section 7, we also disclose data to other bodies. These are not located exclusively in Switzerland. Your data may therefore be processed both in Europe and in Switzerland; in exceptional cases, also in any country in the world.

Where a recipient is located in a country without adequate statutory data protection, we contractually oblige the recipient to comply with applicable data protection standards (for this purpose we use the revised standard contractual clauses of the European Commission, available here: eur-lex.europa.eu/eli/dec_impl/2021/914/oj?), unless it is already subject to a legally recognised framework ensuring data protection and we cannot rely on an exemption provision. An exemption may apply in particular in the case of legal proceedings abroad, but also in cases of overriding public interest or where performance of a contract requires such disclosure, where you have consented, or where the data in question has been made generally accessible by you and you have not objected to its processing.

Many states outside Switzerland and the EU/EEA currently do not have laws that, from the perspective of the FADP or the GDPR, guarantee an adequate level of data protection. The contractual arrangements mentioned above can partly offset this weaker or absent statutory protection. However, contractual arrangements cannot eliminate all risks (in particular risks of access by state authorities abroad). You should be aware of these residual risks, even though the risk in an individual case may be low and we take further measures (for example pseudonymisation or anonymisation) to minimise it.

Please also note that data exchanged over the internet is frequently routed through third countries. Your data may therefore also end up abroad even where the sender and recipient are located in the same country.

9. For how long do we process your data?

We process your data for as long as required by our processing purposes, statutory retention periods, and our legitimate interests in processing for documentation and evidentiary purposes, or for as long as storage is technically necessary. Further information on the respective storage and processing periods can be found for the individual categories of data in section 3, and for the cookie categories in section 12. Where no legal or contractual obligations prevent this, we delete or anonymise your data after expiry of the storage or processing period, as part of our usual processes.

Documentation and evidentiary purposes include our interest in documenting transactions, interactions, and other facts in case of legal claims or disputes, for IT and infrastructure security purposes, and to demonstrate good corporate governance and compliance. Storage may be technically necessary where certain data cannot be separated from other data and must therefore be retained together with it (for example in the case of backups or document management systems).

10. How do we protect your data?

We take appropriate security measures to safeguard the confidentiality, integrity, and availability of your personal data, to protect it against unauthorised or unlawful processing, and to counteract the risks of loss, unintended alteration, unwanted disclosure, or unauthorised access.

Technical and organisational security measures may include, for example, measures such as the encryption and pseudonymisation of data, logging, access restrictions, the storage of backup copies, instructions to our staff, confidentiality agreements, and controls. We protect your data transmitted via our website in transit using suitable encryption mechanisms. However, we can only secure areas that we control. We also require our processors to take appropriate security measures. Security risks can generally not be entirely excluded, however; residual risks are unavoidable.

11. What rights do you have?

Applicable data protection law grants you, under certain circumstances, the right to object to the processing of your data, in particular processing for direct marketing purposes, profiling carried out for direct advertising, and other legitimate interests in the processing.

To make it easier for you to control the processing of your personal data, you also have, depending on the applicable data protection law, the following rights in connection with our data processing:

The right to request from us information as to whether and which data we process about you;

the right to have us correct data if it is incorrect;

the right to request the deletion of data;

the right to request from us the provision of certain personal data in a common electronic format, or its transfer to another controller;

the right to withdraw consent, to the extent our processing is based on your consent;

the right, upon request, to receive additional information required for the exercise of these rights;

the right, in the case of automated individual decisions (section 6), to state your position and to request that the decision be reviewed by a natural person.

If you wish to exercise the above rights against us, please contact us in writing, in person on-site, or, unless otherwise stated or agreed, by e-mail; our contact details can be found in section 2. In order to rule out misuse, we must identify you (for example by means of a copy of an identity document, insofar as this is not possible otherwise).

Please note that these rights are subject to conditions, exceptions, or restrictions under applicable data protection law (for example to protect third parties or trade secrets). We will inform you accordingly where applicable.

In particular, we may need to continue processing and storing your personal data in order to perform a contract with you, to safeguard our own legitimate interests, such as the assertion, exercise, or defence of legal claims, or to comply with legal obligations. To the extent permitted by law, in particular to protect the rights and freedoms of other data subjects and to safeguard legitimate interests, we may therefore also reject a data subject request, wholly or in part (for example by redacting certain content relating to third parties or our trade secrets).

If you disagree with our handling of your rights or of data protection, please let us know. In particular, if you are located in the EEA, the United Kingdom, or Switzerland, you also have the right to lodge a complaint with the data protection supervisory authority of your country. A list of the authorities in the EEA can be found here: edpb.europa.eu/about-edpb/board/members_en. The UK supervisory authority can be reached here: ico.org.uk/global/contact-us/. The Swiss supervisory authority can be reached here: https://www.edoeb.admin.ch/edoeb/en/home/adresse.html

12. Do we use online tracking and online advertising techniques?

On our website, we use various techniques with which we and third parties engaged by us can recognise you when you use the site and, in certain circumstances, also track you across multiple visits. In this section we inform you about this.

The core purpose is to be able to distinguish your access (via your system) from access by other users, so that we can ensure the functionality of the website and carry out evaluations and personalisation. We do not seek to determine your identity in doing so, even though we could do so where we or third parties engaged by us are able to identify you by combining this with registration data. Even without registration data, the techniques used are designed so that you are recognised as an individual visitor on each page visit, for example by our server (or the servers of third parties) assigning you or your browser a particular identification number (a so-called «cookie»).

Cookies are individual codes (for example a serial number) that our server, or a server of our service providers or advertising contractual partners, transmits to your system when connecting to our website, and which your system (browser, mobile device) receives and stores until the pre-programmed expiry date. On each subsequent access, your system transmits these codes back to our server or the third party's server. In this way you are recognised, even though your identity remains unknown.

Further techniques may also be used with which you are recognised with a greater or lesser degree of probability (i.e. distinguished from other users), for example «fingerprinting». Fingerprinting combines your IP address, the browser you use, screen resolution, language selection, and further information that your system communicates to each server, resulting in a more or less unique fingerprint. This makes it possible to dispense with cookies.

Whenever you access a server (for example when using a website or an app, or because an image, visible or invisible, is embedded in an e-mail), your visits can thus be «tracked». Where we integrate offerings from an advertising contractual partner or a provider of an analytics tool on our website, this party can track you in the same way, even where you cannot be identified in an individual case.

We use such techniques on our website and permit certain third parties to do so as well. You can configure your browser so that it blocks or spoofs certain cookies or alternative technologies, or deletes existing cookies. You can also extend your browser with software that blocks tracking by certain third parties. Further information on this can be found on your browser's help pages (usually under «privacy») or on the websites of the third parties listed below.

The following cookies are distinguished (techniques with comparable functionality, such as fingerprinting, are also included here):

Necessary cookies: Some cookies are necessary for the website to function as such, or for certain functions. They ensure, for example, that you can switch between pages without losing information entered in a form. They also ensure that you remain logged in. These cookies exist only temporarily («session cookies»). If you block them, the website may not function properly. Other cookies are necessary so that the server can store decisions or entries made by you beyond a session (i.e. a visit to the website), where you make use of this function (for example the language selected, consent given, the automatic login function, etc.). These cookies generally have an expiry date of 24 months.

In connection with our webshop, we additionally use technically necessary cookies to enable functions such as the shopping cart, the ordering process, logging into customer accounts, and storing user settings.

Performance cookies: In order to optimise our website and related offerings and better tailor them to users' needs, we use cookies to record and analyse the use of our website, in certain circumstances also beyond the session. We do this by using analytics services provided by third-party providers. We have listed these below. Before we use such cookies, we ask for your consent. You can withdraw this at any time via the cookie settings in your browser settings. Performance cookies also have an expiry date of up to 24 months. Details can be found on the websites of the third-party providers.

Marketing cookies: We and our advertising contractual partners have an interest in targeting advertising precisely, i.e. in displaying it, wherever possible, only to those we wish to reach. We have listed our advertising contractual partners below. For this purpose, we and our advertising contractual partners also use – where you consent – cookies with which content viewed or contracts concluded can be recorded. This enables us and our advertising contractual partners to display advertising which we can assume is of interest to you, on our website but also on other websites that display advertising from us or our advertising contractual partners. Depending on the circumstances, these cookies have an expiry period ranging from a few days to 12 months. If you consent to the use of these cookies, corresponding advertising will be displayed to you. If you do not consent to these cookies, you will not see less advertising, just different advertising.

In addition to marketing cookies, we use further techniques to control online advertising on other websites and thereby reduce wastage. We may, for example, transmit the e-mail addresses of our users, customers, and other persons to whom we wish to show advertising to operators of advertising platforms (for example social media). Where such persons are registered there with the same e-mail address (which the advertising platforms determine by matching), the operators show these persons the advertising we have placed in a targeted manner. Operators do not receive personal e-mail addresses of persons not already known to them in this process. For known e-mail addresses, however, they learn that these persons are in contact with us and which content they have accessed.

We may also embed further third-party offerings on our website, in particular from social media providers. These offerings are deactivated by default. Once you activate them (for example by clicking a switch), the relevant providers can determine that you are on our website. If you have an account with the social media provider, it can associate this information with you and thereby track your use of online offerings. These social media providers process this data under their own responsibility.

We currently use the offerings of the following service providers and advertising contractual partners (to the extent these use data about you or cookies placed on your device for advertising targeting):

Google Analytics: Google Ireland (headquartered in Ireland) is the provider of the «Google Analytics» service and acts as our processor. Google Ireland relies for this purpose on Google LLC (headquartered in the United States) as its own processor (together «Google»). Google thereby tracks, using performance cookies (see above), the behaviour of visitors on our website (duration, frequency of pages visited, geographic origin of access, etc.) and creates reports on the use of our website for us on this basis. We have configured the service so that visitors' IP addresses are truncated by Google within Europe before being forwarded to the United States, so that they cannot be traced back. We have disabled the «data sharing» and «signals» settings. Although we can assume that the information we share with Google does not constitute personal data for Google, it is possible that Google may, from this data and for its own purposes, draw conclusions about the identity of visitors, create personalised profiles, and link this data to the Google accounts of these persons. If you consent to the use of Google Analytics, you explicitly consent to such processing, which also includes the transfer of personal data (in particular usage data relating to the website and app, device information, and individual IDs) to the United States and other countries. Information on the data protection practices of Google Analytics can be found here: https://support.google.com/analytics/answer/6004245, and where you have a Google account, further information on processing by Google can be found here: https://policies.google.com/technologies/partner-sites?hl=en.

Information on further partners such as Facebook, LinkedIn, Instagram, YouTube, Mailchimp, Shopify, and Surveymonkey can be found in the corresponding privacy notices on the websites of these partners.

13. What data do we process on our pages within social networks?

We may operate pages and other online presences («fan pages», «channels», «profiles», etc.) on social networks and other platforms operated by third parties, and collect the data about you described in section 3 and below there. We receive this data from you and from the platforms when you make contact with us via our online presence (for example when you communicate with us, comment on our content, or visit our presence). At the same time, the platforms analyse your use of our online presences and link this data with further data known to the platforms about you (for example about your behaviour and preferences). They also process this data for their own purposes and under their own responsibility, in particular for marketing and market research purposes (for example to personalise advertising) and to steer their platforms (for example which content to show you).

We receive data about you when you communicate with us via online presences or view our content on the relevant platforms, visit our online presences, or are active on them (for example publishing content, leaving comments). These platforms also collect, among other things, technical data, registration data, communication data, and behavioural and preference data from you or about you (for the definitions, see section 3). These platforms regularly statistically analyse the way you interact with us, how you use our online presences, our content, or other parts of the platform (what you view, comment on, «like», share, etc.) and link this data with further information about you (for example information on age and gender and other demographic information). In this way, they also create profiles about you and statistics on the use of our online presences. They use this data and these profiles to show you our or other advertising and other content on the platform in a personalised manner and to steer platform behaviour, but also for market and user research, and to provide us and other bodies with information about you and the use of our online presence. We can partly control the analyses that these platforms create regarding the use of our online presences.

We process this data for the purposes described in section 4, in particular for communication, for marketing purposes (including advertising on these platforms, see section 12), and for market research. Information on the corresponding legal bases can be found in section 5. We may further disseminate content published by you yourself (for example comments on an announcement) (for example in our advertising on the platform or elsewhere). We, or the operators of the platforms, may also delete or restrict content by or about you in accordance with the terms of use (for example inappropriate comments).

Further information on the processing carried out by the operators of the platforms can be found in the privacy notices of the platforms. There you will also find out in which countries they process their data, what rights of access, deletion, and other rights as a data subject you have, and how you can exercise them or obtain further information. We currently use the following platforms:

LinkedIn, Facebook, Instagram, YouTube, Mailchimp, Rapid-Mail, Shopify, Surveymonkey

14. Can this privacy policy be amended?

This privacy policy does not form part of any contract with you. We may amend this privacy policy at any time. The version published on this website is the version currently in force.

Last updated: 31.07.2026 / Translation by an AI tool

Return to the Home Page