Privacy policy
Dübendorf, March 16 2022
The Familie Wiesner Gastronomie AG, Food Point AG and FWG (Management) AG with its registered office at Zürichstrasse 131 in 8600 Dübendorf, hereinafter "the responsible parties", collect, process, store and protect the data of persons, hereinafter "data subject", who access the websites fwg. ch, fwg-management.ch, fwg-kk.ch, fwg-foundation.ch, kitchen-republic.ch, negishi.ch, nooch.ch, miss-miu.ch, gypsy-rose.ch, butcher.ch, butcherdaughter.ch, pokenation.ch, outback-lodge.ch, angry-chicken.ch, wahaca.ch or dumpling-brothers.ch, hereinafter "websites". By means of this data protection declaration, the responsible parties would like to inform the public about the type, scope and purpose of the personal data collected, used and processed. Furthermore, data subjects are informed of their rights by means of this data protection declaration.
The use of the websites of the responsible persons is basically possible without any indication of personal data, except for IP addresses. However, if a data subject wishes to use special services via the websites, processing of personal data could become necessary. If the processing of personal data is necessary and there is no legal basis for such processing, the consent of the data subject will generally be obtained.
The processing of personal data (for example, name, e-mail address) of a data subject shall always be in accordance with the law. The responsible parties are subject to the Swiss Data Protection Act.
Furthermore, companies outside the European Union must comply with the European Data Protection Regulation DSGVO (EU/2016/679) under certain circumstances. Since the latter partly stipulates more far-reaching rights and obligations in favor of the data subject, we have decided to align this data protection declaration as a whole with the DSGVO.
1. Integral part
The data protection declaration is an integral part of the General Terms and Conditions (GTC) of the responsible parties and is published on the websites. By clicking on the checkbox relating to the GTC, the data subjects declare their consent to this data protection declaration.
2. name and address of the data controller and its representative
The controller of the Websites is Familie Wiesner Gastronomie AG with the following contact details:
Familie Wiesner Gastronomie AG
Data protection officers:
Manuel Wiesner and Marc Lauper
Zurichstrasse 131
CH-8600 Dübendorf
Tel.: +41 44 510 50 00
E-mail: privacy@fwg.ch
Website: fwg.ch
In all matters concerning data protection, the responsible parties within the European Union are represented by:
VGS Datenschutzpartner UG
Am Kaiserkai 69
DE-20457 Hamburg
E-mail: info@datenschutzpartner.eu
3. cookies
The websites use cookies. Cookies are text files that are placed and stored on a computer system via an Internet browser. Numerous Internet pages and servers use cookies. By means of a cookie, the information and offers on the website of the responsible parties can be optimized in the sense of the users. Cookies enable the responsible parties to recognize the users of their website. The purpose of this recognition is to make it easier for users to use the website.
Those who choose not to turn off cookies agree to the websites use of cookies.
The data subject can prevent the setting of cookies by websites of the responsible parties at any time by means of an appropriate setting of the Internet browser used and thus permanently object to the setting of cookies. Furthermore, cookies that have already been set can be deleted at any time via an Internet browser or other software programs.
It is possible that the websites will not function correctly without cookies.
4. collection of general data and information
The websites of the responsible parties collect a series of general data and information with each call of the Internet pages by a data subject or an automated system. This general data and information is stored in the log files of the server. Collected can be:
• the browser types and versions used,
• the operating system used by the accessing system,
• the website from which an accessing system arrives at the website of the responsible party,
• the sub-websites that are accessed via an accessing system to the website of the responsible party,
• the date and time of an access to the Internet site,
• an Internet protocol address (IP address),
• the Internet service provider (ISP) of the accessing system and
• other similar data and information that serve to avert danger in the event of attacks on information technology systems of the responsible parties.
When using these general data and information, the responsible persons do not draw any conclusions about the data subject. Rather, this information is required in order to:
• to correctly deliver the contents of the website,
• optimize the contents of the website as well as the advertising for the same,
• to ensure the long-term functionality of the information technology systems and the technology of the website, and
• to provide law enforcement authorities, in the event of a cyber attack, with the information necessary for prosecution.
Therefore, the data and information collected through pseudonymization are evaluated by the controller, on the one hand, statistically and, on the other hand, with the aim of increasing data protection and data security within the controller's enterprise so as to ultimately ensure an optimal level of protection for the personal data processed by the controller. The anonymous data of the server log files are stored separately from any personal data provided by a data subject.
5. Registration on the websites
The data subject has the possibility to register on the websites of the data controller by providing personal data. Registration is necessary, among other things, to subscribe to newsletters, to deposit credit card data or to benefit from designated marketing campaigns. Which personal data is transmitted to the responsible parties in the process is determined by the respective input mask used for the registration. Unless explicitly stated otherwise, the personal data entered by the data subject will be collected and stored exclusively for the data subject's own use (e.g. own marketing purposes) by the data controller and its order partners for order processing. By registering, visitors declare that their personal data is correct.
By registering on the websites of those responsible, the IP address assigned by the Internet service provider (ISP) of the person concerned, the date as well as the time of registration are also stored. The storage of this data takes place against the background that only in this way can the misuse of the services be prevented and, if necessary, this data makes it possible to clarify criminal offences that have been committed. As a matter of principle, this data is not passed on to third parties unless there is a legal obligation to pass it on or the passing on serves the purpose of criminal prosecution.
The registration of the data subject by voluntarily providing personal data serves the responsible parties to offer the data subject content or services which, due to the nature of the matter, can only be offered to registered users. Registered persons are free to change the personal data provided during registration at any time or to have it completely deleted from the data stock of the persons responsible.
In the context of a transfer from an asset deal or asset transfer, the data subject gives his consent for the transfer of data if the restaurant continues with the same concept. The data subject would be informed accordingly and has the possibility to unsubscribe at any time.
6. use of personal data for promotional purposes.
In addition to processing personal data for the purpose of processing a purchase on the websites, the data controllers also use personal data to communicate with the data subject about orders, specific products or marketing campaigns and to recommend products or services that may interest the data subject. Data subjects may object to the use of personal data for advertising purposes at any time, either in its entirety or for individual measures, without incurring any costs other than the transmission costs according to the prime rates. A notification to the contact data mentioned in section 2 (e.g. e-mail, letter or telephone) is sufficient for this purpose. The further receipt of individual newsletters or SMS can also be objected to at any time by clicking on the "unsubscribe" link (opt-out).
7. use of Google Analytics
The websites of the responsible parties use Google Analytics, a web analysis service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, hereinafter "Google". Google Analytics uses "cookies", which are text files placed on the data subject's computer, to help the website analyze how users use the site. The information generated by the cookies about the use of this website by the data subject is usually transmitted to a Google server in the USA and stored there. In the event that IP anonymization is activated on this website, however, Google will truncate the IP address beforehand within member states of the European Union or in other contracting states to the Agreement on the European Economic Area.
Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. The IP address transmitted by the data subject's browser as part of Google Analytics will not be merged with any other data held by Google.
Google is certified under the EU-U.S. and Swiss-U.S. Privacy Shield agreements and thereby offers a guarantee of compliance with European and Swiss data protection law.
https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI[&]status=Active
The data subject may prevent the installation of cookies by selecting the appropriate settings on the browser software. The responsible parties point out that in this case the data subject may not be able to use all functions of the website to their full extent. By using this website, the data subject consents to the processing of data about him or her by Google in the manner and for the purposes set out above.
8. use of Facebook Pixel, Custom Audiences and Facebook Conversion
Within the online offer of the responsible parties, the so-called "Facebook pixel" of the social network Facebook, which is operated by Facebook Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, hereinafter "Facebook", is used due to the legitimate interests in analysis, optimization and economic operation of the online offer and for these purposes.
Facebook is certified under the EU-U.S. and Swiss-U.S. Privacy Shield agreements and thereby offers a guarantee of compliance with European and Swiss data protection law: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC[&]status=Active.
With the help of the Facebook pixel, it is possible for Facebook to determine the visitors of the online offer as a target group for the display of advertisements, so-called "Facebook ads". Accordingly, the Responsible Parties use the Facebook pixel to display the Facebook ads only to those Facebook users who have also shown an interest in the online offer of the Responsible Parties or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited), which we transmit to Facebook (so-called "Custom Audiences"). With the help of the Facebook pixel, we also want to ensure that Facebook ads of the responsible parties correspond to the potential interest of the users and do not have a harassing effect. With the help of the Facebook pixel, we can also track the effectiveness of the Facebook ads for statistical and market research purposes by seeing whether users were redirected to the website of the responsible party after clicking on a Facebook ad (so-called "conversion").
The processing of the data by Facebook takes place within the framework of Facebook's data usage policy. Accordingly, the notes on the display of Facebook ads, in Facebook's data usage policy at https://www.facebook.com/policy.php apply.
The data subject can obtain specific information and details on the Facebook pixel and how it works in Facebook's help section: https://www.facebook.com/business/help/651294705016616
The data subject may object to the collection by the Facebook pixel and use of his or her data to display Facebook ads. In order to set which types of advertisements are displayed to the data subject within Facebook, the data subject can visit the page set up by Facebook and follow the instructions there on the settings for usage-based advertising: https://www.facebook.com/settings?tab=ads.
The settings are made platform-independent, i.e. they are adopted for all devices, such as desktop computers or mobile devices. The data subject can further object to the use of cookies used for reach measurement and advertising purposes via the Network Advertising Initiative deactivation page at http://optout.networkadvertising.org/ and additionally the U.S. website at http://www.aboutads.info/choices or the European website at http://www.youronlinechoices.com/uk/your-ad-choices/.
9. use of Vimeo
The responsible parties may embed the videos of the platform "Vimeo" of the provider Vimeo Inc, Attention: Legal Department, 555 West 18th Street New York, New York 10011, USA. The data subject can find the Vimeo privacy policy at https://vimeo.com/de/features/video-privacy.
The responsible parties point out that Vimeo Google Analytics may be used and refer to Google's privacy policy as well as to the opt-out options for Google Analytics http://tools.google.com/dlpage/gaoptout?hl=de or Google's settings for data use for marketing purposes https://adssettings.google.com/.
10. use of youtube
The responsible parties integrate the videos of the platform "YouTube" of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The data subject can find the privacy policy of Youtube at https://policies.google.com/privacy?hl=de[&]gl=de.
Opt-out: https://adssettings.google.com/authenticated
11. use of Google Maps
The responsible parties integrate the maps of the service "Google Maps" of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The processed data may include, in particular, IP addresses and location data of the users, which, however, are not collected without their consent (usually executed in the context of the settings of their mobile devices). The data may be processed in the USA. The data subject can find the privacy policy of Google Maps at https://policies.google.com/privacy?hl=de[&]gl=de.
Opt-out: https://adssettings.google.com/authenticated
12. use of Linkedin Insights
Our website uses the "LinkedIn Insight Tag" conversion tool provided by LinkedIn Ireland Unlimited Company. This tool creates a cookie in your web browser, which enables the collection of, among other things, the following data: IP address, device and browser properties and page events (e.g. page views). This data is encrypted, anonymized within seven days, and the anonymized data is deleted within 90 days. LinkedIn does not share any personal data with the responsible parties, but offers anonymized reports on website audience and display performance. In addition, LinkedIn offers the possibility of retargeting via the Insight Tag. The responsible parties can use this data to display targeted advertising outside of their website without identifying you as a website visitor. More detailed information on data protection at LinkedIn can be found in the LinkedIn privacy notices.
LinkedIn members can control the use of their personal data for advertising purposes in their account settings. To deactivate the Insight tag on our websites ("opt-out"), data subjects click here.
13. use of personyze
The Responsible Parties use Personyze to better understand user needs and optimize the service and customer experience. Personyze is a technology service that helps to better understand the user experience (e.g., how much time is spent on which pages, which links are clicked, what users do and don't do, etc.) and enables Responsible Parties to build and maintain the Services with user feedback. Personyze uses cookies and other technologies to collect data about the behavior of users and their devices (in particular, device IP addresses, which are collected and stored only in anonymized form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display the Websites. The information collected from cookies is used only in connection with the use of our services and services and is not shared with third parties. Information on opting out can be found by data subjects here.
14. use of processors
For processing purposes, the Controllers may arrange for the transfer to one or more processors (e.g. MailChimp, NoTime, SAP Electronics, Datatrans, etc.) who also use the Personal Data exclusively for an internal use attributable to the Controllers. The following processors process personal data in third countries of the Controllers (partly outside Switzerland and outside the European Union):
a) MailChimp
The newsletter is sent using MailChimp, a newsletter sending platform of the US provider Rocket Science Group, LLC, 675 Ponce de Leon Ave NE #5000, Atlanta, GA 30308, USA. The email addresses of the subscribers to the newsletter of the person responsible as well as their other data described in the context of this privacy policy are stored on the servers of MailChimp in the USA.
MailChimp uses this information to send and evaluate the newsletter on behalf of the responsible parties. Furthermore, according to its own information, MailChimp may use this data to optimize or improve its own services. However, MailChimp does not use the data of the recipients, of the newsletters of the responsible parties to write to them themselves or to pass them on to third parties. MailChimp is certified under the EU-U.S. and Swiss-U.S. data protection agreements and thus undertakes to comply with the basic data protection regulation. https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG[&]status=Active
Data subjects can find MailChimp's privacy policy at: https://mailchimp.com/legal/privacy/
b) NoTime
As part of the ordering process in the delivery and or take away offer on the websites of the responsible parties, contact, order and transaction data are transmitted to NoTime for route planning, for sending FollowMe SMS, for contacting by telephone if the data subject is not available, for collection and, if necessary, for billing, comments and ratings as well as signatures for confirmation of receipt. Furthermore, according to its own information, NoTime may use this data to optimize or improve its own services. NoTime is an offer of notime AG, Birmensdorferstrasse 94, 8003 Zurich, Switzerland. The data transmitted to NoTime is stored on servers of Microsoft Ireland, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland. Microsoft Privacy Policy. The Responsible Parties entered into an IT Privacy and Data Protection Agreement with NoTime on April 9, 2017. Further information about NoTime can be found at http://notime.ch/PrivacyPolicy.
c) Datatrans
Should the data subject decide to make a payment with the online payment service provider Datatrans as part of the ordering process (e.g. when paying by credit card, PostFinance, TWINT, etc.), contact, order and transaction data will be transmitted to Datatrans and its card issuer as part of the order triggered in this way. Datatrans is an offer of Datatrans AG, Kreuzbühlstrasse 26, 8008 Zurich, Switzerland. The Controllers entered into an Order Data Processing Agreement with Datatrans on May 23, 2018 with the purpose of ensuring adequate protection of Personal Data in situations where such data is transferred by the Controllers to Datatrans as a Processor for the purpose of processing such data on behalf of the Controllers. Furthermore, this Agreement assists the Parties in complying with the regulations applicable in Switzerland and the European Union regarding the processing of Personal Data, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, applicable as of 25 May 2018 ("GDPR").
d) Lunchgate AG - Foratable
In the case of an online reservation (table reservation) via the websites of the Responsible Parties, the recorded contact data according to the input mask (e.g. name, telephone number, e-mail address, etc.) are transmitted to the reservation system "Foratable" and stored. Foratable is operated by Lunchgate AG, Badenerstrasse 255, 8003 Zurich, Switzerland. By making a reservation, the data subject agrees to the terms of use of the reservation system Foratable.
e) SAP Electronic AG
As part of the ordering process, contact, order and transaction data are transmitted to the cash register system of the responsible parties. The POS system is operated by SAP Electronic AG, Weissenbrunnenstrasse 39, 8903 Birmensdorf, Switzerland. The following data is transmitted to SAP Electronic AG during the ordering process and stored in a plain text file:
- Name, first name
- Street address
- Zip code and city
- Phone number
- Pickup/delivery time
- Payment method, no credit data information
- Products
The log files on the individual cash registers (plain text file) are automatically deleted once a week, on the following, same weekday of the bookings. The software of the cash register system automatically creates a daily journal with this data as well as a weekly backup, in which it creates a complete backup of the cash register and stores it on the server of the responsible persons.
f) Poinz Inc.
When opening a "Poinz account" (for collecting loyalty points) on the websites of the Responsible Parties, the collected contact data according to the input mask (e.g. name, telephone number, e-mail address, date of birth, etc.) are transmitted to the loyalty point system "Poinz" and stored anonymously. Poinz is operated by Poinz AG, Manessestrasse 170, 8045 Zurich, Switzerland. By opening a "Poinz account", the data subject agrees to the terms of use of Poinz AG.
g) TextMagic Ltd
When subscribing to the newsletter or directly to the news via SMS on the websites of the responsible persons, the collected contact data according to the input mask (e.g. name, telephone number, profile picture, e-mail address, date of birth, etc.) as well as traffic data such as the message dispatch are transmitted to TextMagic Ltd based in Cambridge, England and stored anonymously. TextMagic LTD certifies its compliance with the GDPR here.
h) Twilio
As part of the ordering process on the websites of the Responsible Parties, contact, order and transaction data is stored for advertising purposes in the CRM tool OroCRM and processed for further use (e.g. for automated newsletter or SMS campaigns). SMS campaigns are processed via Twilio's SMS service. Twilio is certified under the EU-U.S. and Swiss-U.S. data protection agreements and is thus committed to comply with the General Data Protection Regulation. https://www.privacyshield.gov/participant?id=a2zt0000000TNLbAAO[&]status=Active
i) Click Labs Inc
As part of the order process in the delivery service on the websites of the Responsible Parties, contact, order and transaction data are transmitted to Tookan for route planning, for sending SMS, for contacting by telephone if the Data Subject is not available, for collection and, if necessary, for billing, comments and ratings, as well as signatures for confirmation of receipt. Tookan is an offering of Click Labs Inc, 4830 West Kennedy Blvd, Suite 600, Tampa, Florida, 33609 USA. Click Labs Inc certifies its compliance with the GDPR here.
j) OroCRM
As part of the ordering process on the websites of the Responsible Parties, contact, order and transaction data is stored for promotional purposes in the CRM tool OroCRM and processed for further use (e.g. for automated newsletter or SMS campaigns). OroCRM is hosted by Ethersys, 35 B bd des Récollets, 31400 Toulouse, France. OroCRM is certified under the EU-U.S. and Swiss-U.S. data protection agreements and is thus committed to comply with the General Data Protection Regulation. https://www.privacyshield.gov/participant?id=a2zt00000008XnDAAU[&]status=Active
k) adfocus GmbH
The responsible parties use "conversion optimization technology" to improve targeted communication with data subjects. With this technology, the responsible parties record online store usage and can, for example, remind data subjects when they visit our online store of forgotten orders and point out special offers or enable data subjects to subscribe to notifications and communications such as newsletters in particular, to make use of support and to have their shopping cart sent to them. The responsible parties use e-mail, instant messaging and other communication channels for this purpose. The Controllers require such "conversion optimization technology" in order to be able to operate the websites effectively and in a user-friendly manner in the long term. Legal bases according to DSGVO - if and to the extent applicable - are Art. 6 para. 1 lit. a, b and f DSGVO.
Data subjects can object here to the use of "conversion optimization technology" on our website. The objection is noted with a corresponding cookie in the currently used browser.
For the use of this technology, the responsible parties integrate Getback of the Swiss adfocus GmbH on the websites. adfocus processes data of the data subjects exclusively on our behalf. adfocus stores data within the scope of Getback exclusively in Switzerland and Germany. Further information can be found in the privacy policy of adfocus.
15. social plugins
The websites uses social plugins, hereinafter "plugins" from various social networks. With the help of these plugins, the data subject can, for example, share content or recommend products.
If these plugins are activated, the browser establishes a direct connection with the servers of the respective social network as soon as the data subject calls up a web page of the website of the responsible party. The content of the plugin is transmitted directly to the browser by the social network and integrated into the website by the browser. By integrating the plugins, the social network receives the information that the data subject has called up the corresponding page of the website of the responsible party. If the data subject is logged in to the social network, the latter can assign the visit to the account of the data subject. If the data subject interacts with the plugins, for example by clicking the Facebook "Like" button or posting a comment, the corresponding information is transmitted directly from the browser to the social network and stored there.
The purpose and scope of the data collection and the further processing and use of the data by social networks, as well as the related rights and settings options for the protection of privacy, can be found by the data subject in the privacy notices of the respective networks or websites. The links to this are listed below.
Even if the data subject is not logged into the social networks, data can be sent to the networks by websites with active social plugins. An active plugin sets a cookie with an identifier each time the website is called up. Since the browser sends this cookie without being asked every time it connects to a network server, the network could in principle use it to create a profile of which websites the user belonging to the identifier has called up. And it would then also be quite possible to assign this ID to a person again later - for example, when logging on to the social network at a later time. The following plugins are used on the websites of the responsible parties: Facebook, Instagram, Twitter, Google Plus, LinkedIn, Jivochat and Pinterest.
If the data subject does not want social networks to collect data about him or her via active plugins, the data subject can select the "Block third-party cookies" function in the browser settings. Then the browser does not send cookies to the server for embedded content from other providers. However, with this setting, in addition to the plugins, other cross-page functions may also no longer work.
The posts, likes, etc. made by the data subject on the social media of the responsible parties. Posts, etc. are not subject to the area of responsibility and accountability of the responsible parties.
a) Facebook Plugins
The Responsible Parties use plugins of the social network facebook.com, which is operated by Facebook Inc, 1601 S. California Ave, Palo Alto, CA 94304, USA, hereinafter "Facebook". Privacy policy of Facebook can be found by the data subject at https://www.facebook.com/about/privacy/
b) Instagram plugins
The Responsible Parties use plugins of the social network instragram.com, which is operated by Instagram LLC, 1601 Willow Rd, Menlo Park CA 94025, USA, hereinafter "Instagram". The link to Instagram's privacy policy can be found by the data subject at https://help.instagram.com/155833707900388
c) Twitter plugins
The responsible parties use plugins of the social network Twitter, which is operated by Twitter Inc., 795 Folsom St., Suite 600, San Francisco, CA 94107, USA, hereinafter "Twitter". The link to the privacy policy of Instagram can be found by the data subject at https://twitter.com/de/privacy.
d) Google Plus Plugins
The responsible parties use plugins of the social network Google Plus, which is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, hereinafter "Google". The link to Instagram's privacy policy can be found by the data subject at https://policies.google.com/privacy?hl=de.
e) LinkedIn Plugins
The Responsible Parties use plugins of the social network LinkedIn, which is operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland, hereinafter "LinkedIn". The link to the privacy policy of LinkedIn can be found by the data subject at https://www.linkedin.com/legal/privacy-policy
f) Pinterest Plugins
The Responsible Parties use plugins of the social network Pinterest, which is operated by Pinterest Inc, 635 High Street, Palo Alto, CA, USA, hereinafter "Pinterest". The link to Instagram's privacy policy can be found by the data subject at https://policy.pinterest.com/de/privacy-policy
g) Live chat plugins
The Responsible Parties use plugins of the live chat provider JivoSite, which is operated by JivoSite Inc, 1811 Silverside Road, Wilmington, Delaware 19810, USA, hereinafter "JivoSite". The data subject can find the link to JivoSite's privacy policy at https://www.jivochat.com/privacy/. JivoSite is certified under the EU-U.S. and Swiss-U.S. Privacy Shield Agreements (Privacy Shield Framework) and thereby offers a guarantee of compliance with European and Swiss data protection law: https://www.privacyshield.gov/participant?id=a2zt00000008TXvAAM[&]status=Active
16. contact possibility via the website
The websites of the responsible parties contain a quick electronic contact facility. If a data subject contacts the data controller by e-mail or via a contact form, the personal data transmitted by the data subject will be stored automatically. Such personal data transmitted on a voluntary basis by a data subject to the persons responsible will be stored for the purpose of processing or contacting the data subject.
17. applications
Online applications are processed by systems of our partner REFLINE AG. By submitting an online application, the data subject accepts the privacy policy of REFLINE AG. Applications which the
responsible via other channels (mail, e-mail, etc.) are also processed by systems of our partner REFLINE AG. By submitting an application via these channels, the data subject accepts the privacy policy of REFLINE AG.
18. Routine deletion and blocking of personal data
The responsible parties process and store personal data of the data subject only for the period of time required to achieve the purpose of storage or if this has been provided for by legal requirements to which the responsible parties are subject.
If the storage purpose ceases to apply or if any storage period set by law expires, the personal data will be routinely blocked or deleted in accordance with the statutory provisions.
19. Legal basis for processing
No data will be processed without a legal basis. The legal basis is:
consent (for subscribing to the newsletter, the use of regular customer data and for the transfer of data to third countries),
the fulfillment of a contract or pre-contractual measures,
the legal obligations or the protection of vital interests of the data subject or another natural person,
the protection of a legitimate interest of the responsible parties (e.g. economic interests) or a third party, in accordance with the Swiss Data Protection Act DSG or Art. 6 of the General Data Protection Regulation.
20. profiling and automated individual decisions
"Profiling" or "profiling" means a process by which Personal Data is processed in an automated manner to evaluate, analyze or predict personal aspects, such as job performance, economic situation, health, personal preferences, interests, reliability, behavior, location or change of location. We often perform profiling, e.g., when analyzing user behavior, selecting job applicants, screening contractors, etc.
"Automated case-by-case decision" refers to decisions that are automated, i.e. without relevant human influence, and that have negative legal effects towards you or other similar negative effects. We will inform you separately if we use automated individual case decisions in individual cases and if this is required by law.
21. rights of the data subject
a) Right to information
Every data subject has the right to be informed in a transparent, clearly understandable and comprehensive manner about how we process their personal data and what rights they have in connection with the processing of their personal data. We comply with this obligation with the present data protection declaration. If a data subject wishes to receive further information, he or she can contact the employees of the persons responsible at any time.
b) Right to confirmation and information
Every data subject has the right to obtain confirmation from the data controllers as to whether personal data in question are being processed. Furthermore, every data subject has the right to obtain from the persons responsible, at any time and free of charge, information about the personal data stored about him or her and a copy of this information. In particular, information will be provided about:
• the purposes of processing,
• the categories of personal data processed,
• the recipients or categories of recipients to whom the personal data have been or will be disclosed
• whether personal data have been transferred to a third country or to an international organization and, if so, whether appropriate safeguards are in place in connection with the transfer
• the planned storage period or, if this is not possible, the criteria for determining this period,
• the existence of a right to rectification or erasure of the personal data concerning them or to restriction of processing by the controller, or the existence of a
• Right to object to such processing,
• the existence of a right of appeal to a supervisory authority,
• the origin of the personal data if it is not collected from the data subject,
• the existence of automated decision-making, including profiling, and meaningful information about the logic involved and the scope and intended effects of such processing for the data subject.
In individual cases, the right to information may be restricted or excluded, in particular:
• if we have doubts about the identity of a data subject and he or she cannot identify himself or herself;
• for the protection of other persons (e.g., to safeguard confidentiality obligations or the data protection rights of third parties);
• in the event of excessive exercise of the right to information (alternatively, we may in this case charge a fee for the information); or
• if a full disclosure would generate disproportionate effort.
If a data subject wishes to exercise this right of access, he or she may at any time contact the staff of the controller or the contact details specified in Section 2.
c) Right to rectification
Any person affected by the processing of personal data has the right to request the immediate rectification of inaccurate personal data concerning him or her and, taking into account the purposes of the processing, the completion of incomplete personal data. If a data subject wishes to exercise this right of rectification, he or she may, at any time, contact the staff of the controller or the contact details specified in Section 2.
d) Right to erasure (right to be forgotten).
Any person affected by the processing of personal data has the right to obtain from the data controllers the erasure without delay of personal data concerning him or her, where one of the following grounds applies and insofar as the processing is not necessary:
• the personal data were collected or otherwise processed for such purposes for which they are no longer necessary;
• the data subject withdraws the consent on which the processing was based and there is no other legal basis for the processing;
• the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
• the erasure of the personal data is necessary for compliance with a legal obligation;
• the personal data belongs to a child who has not yet reached the age of 16 or for whom there is no consent from the holder of parental authority.
If one of the aforementioned reasons applies, and a data subject wishes to arrange for the erasure of personal data stored by the controller, he or she may, at any time, contact the controller's employees or the contact details specified in Section 2.
In individual cases, the right to erasure may be excluded, in particular if the processing is necessary:
• for the exercise of freedom of expression;
• for the fulfillment of a legal task or in the public interest;
• for the exercise of legal claims.
If the personal data have been made public by the data controller and the data controller is obliged to erase the personal data, the data controller shall, taking into account the available technology and the cost of implementation, implement reasonable measures, including technical measures, to inform other data controllers which process the published personal data, that the data subject has requested from those other data controllers to erase all links to the personal data or copies or replications of the personal data, unless the processing is necessary.
e) Right to restriction of processing
Any person concerned by the processing of personal data has the right to obtain from the controllers the restriction of processing where one of the following conditions is met:
• the accuracy of the personal data is contested by the data subject for a period enabling the controller to verify the accuracy of the personal data;
• the processing is unlawful, the data subject objects to the erasure of the personal data and requests instead the restriction of the use of the personal data;
• the controller no longer needs the personal data for the purposes of processing, but the data subject needs it for the establishment, exercise or defense of legal claims;
• the data subject has objected to the processing and it is not yet clear whether the legitimate grounds of the controller, override those of the data subject.
If one of the aforementioned conditions is met, and a data subject wishes to request the restriction of personal data stored by the controller, he or she may, at any time, contact the controller's employees or the contact details specified in Section 2.
f) Right to data portability
A person affected by the processing of personal data has the right to receive the personal data concerning him or her, which has been provided by the data subject to the data controllers, in a structured, common and machine-readable format, provided that
• the specific data processing is based on the consent of the data subject or is necessary for the performance of a contract; and
• the processing is carried out with the help of automated procedures.
He or she also has the right to transmit this data to another data processor without hindrance from the data controllers to whom the personal data have been provided, provided that the processing is based on consent or on a contract and that the processing is carried out with the aid of automated procedures, unless the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. Furthermore, the data subject may request that the personal data be transferred directly from one data processor to another data processor, insofar as this is technically feasible and insofar as this does not adversely affect the rights and freedoms of other persons.
In order to assert the right to data portability, the data subject may at any time contact the controller's employees or the contact details specified in Section 2.
g) Right to object
For the reasons provided for in Article 21 of the GDPR, data subjects concerned by the processing of personal data have the right to object at any time to the processing of personal data relating to them. This also applies to profiling based on these provisions. The data controller shall no longer process the personal data in the event of the objection, unless compelling legitimate grounds for the processing can be demonstrated which override the interests, rights and freedoms of the data subject, or the processing serves the purpose of asserting, exercising or defending legal claims. If the controller processes personal data for the purposes of direct marketing, the data subject shall have the right to object to the controller at any time. If the data subject objects to the operators to the processing for direct marketing purposes, the operators will no longer process the personal data for these purposes.
In order to exercise the right to object, the data subject may directly contact the staff members of the Controllers or the contact details specified in Section 2.
h) Automated decisions in individual cases, including profiling.
Any person concerned by the processing of personal data has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her, unless the decision is necessary for the conclusion or performance of an agreement between the parties.
• is not necessary for entering into, or the performance of, a contract between the data subject and the controller, or
• is made with the express consent of the data subject.
If the decision is necessary for entering into, or the performance of, a contract between the data subject and the controller, or if it is made with the data subject's explicit consent, the controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, which include at least the right to obtain the data subject's involvement on the part of the controller, to express his or her point of view and to contest the decision.
If the data subject wishes to exercise the rights concerning automated decisions, he or she may, at any time, contact any employee of the controller or any of the contact persons mentioned in paragraph 2.
i) Right to withdraw consent under data protection law.
Any person affected by the processing of personal data has the right to withdraw consent to the processing of personal data at any time. However, processing activities based on consent in the past do not become unlawful as a result of its revocation.
If the data subject wishes to exercise his or her right to withdraw consent, he or she may do so at any time by contacting the staff of the data controller or by using the contact details provided in Section 2.
j) Right to lodge a complaint with a supervisory authority
Every person affected by the processing of personal data has the right to lodge a complaint with the local supervisory authority responsible for the data protection of citizens regarding the data protection violations of the data controller.
[nbsp]
22. other
The responsible parties inform data subjects that the storage and provision of personal data is sometimes required by law (e.g., due to tax regulations) or may also result from contractual provisions (e.g., for information about the contractual partner). Sometimes, in order to conclude a contract, it may be necessary for a data subject to provide personal data to the data controllers, which must subsequently be processed by the data controllers. For example, the data subject is obliged to provide the data controllers with personal data if the data controllers conclude a contract with the data subject. Failure to provide the personal data would mean that the contract with the data subject could not be concluded.
The websites of the Responsible Parties link to other websites, for the content of which the Responsible Parties are not liable.
The responsible parties may amend, supplement or replace the provisions of this data protection declaration in whole or in part at any time and without prior notice. The version of this data protection declaration in force at the time of visiting the websites or visiting one of the associated websites shall apply.
Long-term backups cannot be cleaned up in part due to technical limitations, but these are always stored in encrypted form.
[nbsp]
This text has been translated automatically. You can find our original privacy policy here