Privacy Policy
With this Privacy Policy, we explain which personal data we process in connection with our activities and operations, including our
Additional privacy policies and other legal documents, such as General Terms and Conditions, Terms of Use or Conditions of Participation, may apply to individual or additional activities and operations.
1. Contact Details
Responsibility for processing personal data:
Madeleine Grieder
Vogesenplatz 1, 4056 Basel
We will indicate if other parties are responsible for processing personal data in individual cases.
2. Terms and Legal Basis
2.1 Terms
Personal data is any information relating to an identified or identifiable natural person. A data subject is a person whose personal data we process.
Processing includes any handling of personal data, regardless of the means and methods used, for example retrieving, comparing, adapting, archiving, retaining, reading, disclosing, obtaining, recording, collecting, deleting, revealing, arranging, organising, storing, modifying, distributing, linking, destroying and using personal data.
2.2 Legal Basis
We process personal data in accordance with Swiss data protection law, particularly the Federal Act on Data Protection (Data Protection Act, FADP) and the Data Protection Ordinance (DPO).
3. Nature, Scope and Purpose
We process the personal data that is required to carry out our activities and operations on a permanent, user-friendly, secure and reliable basis. Such personal data may, in particular, include master and contact data, browser and device data, content data, metadata, usage data, location data, sales data, as well as contractual and payment data.
We process personal data for the period required for the respective purpose or purposes or as required by law. Personal data that is no longer required will be anonymised or deleted.
We may have personal data processed by third parties. We may process personal data jointly with third parties or transmit it to third parties. Such third parties are, in particular, specialised service providers whose services we use. We also ensure data protection when working with such third parties.
As a general rule, we only process personal data with the consent of the data subjects. Where and to the extent that processing is permitted for other legal reasons, we may refrain from obtaining consent. For example, we may process personal data without consent in order to fulfil a contract, comply with legal obligations or protect overriding interests.
Within this framework, we process, in particular, information that a data subject voluntarily provides to us when contacting us – for example by post, email, instant messaging, contact form, social media or telephone – or when registering for a user account. We may store such information, for example, in an address book, a customer relationship management system (CRM system) or comparable tools. Where we receive data concerning other individuals, the persons providing the data are responsible for ensuring data protection in relation to those individuals and for ensuring that the personal data is accurate.
We also process personal data that we receive from third parties, obtain from publicly accessible sources or collect while carrying out our activities and operations, provided and to the extent that such processing is permitted for legal reasons.
4. Applications
We process personal data relating to applicants to the extent that it is required to assess their suitability for employment or for the subsequent performance of an employment contract. The required personal data is based, in particular, on the information requested, for example as part of a job advertisement. We also process personal data that applicants voluntarily provide or publish, particularly as part of cover letters, CVs and other application documents, as well as online profiles.
5. Personal Data Abroad
As a general rule, we process personal data in Switzerland. However, we may also disclose or export personal data to other countries, particularly in order to process it there or have it processed there.
We may disclose personal data to all countries and territories on Earth, as well as elsewhere in the universe, provided that the applicable law ensures an adequate level of data protection in accordance with the decision of the Swiss Federal Council.
We may disclose personal data to countries whose laws do not provide an adequate level of data protection, provided that suitable data protection is ensured for other reasons. Suitable data protection may be ensured, for example, through appropriate contractual agreements, standard data protection clauses or other appropriate safeguards. In exceptional cases, we may export personal data to countries without adequate or suitable data protection where the specific data protection requirements are met, for example where the data subjects have given their express consent or where the export is directly connected with the conclusion or performance of a contract. Upon request, we will gladly provide data subjects with information about any safeguards or supply them with a copy of such safeguards.
6. Rights of Data Subjects
6.1 Data Protection Rights
We grant data subjects all rights provided for under the applicable data protection law. In particular, data subjects have the following rights:
- Information: Data subjects may request information as to whether we process personal data concerning them and, if so, which personal data is involved. Data subjects also receive the information required to exercise their data protection rights and ensure transparency. This includes the personal data being processed as well as information concerning, among other things, the purpose of processing, the retention period, any disclosure or export of data to other countries and the origin of the personal data.
- Correction and restriction: Data subjects may have inaccurate personal data corrected, incomplete data completed and the processing of their data restricted.
- Deletion and objection: Data subjects may request the deletion of personal data (the “right to be forgotten”) and object to the processing of their data with effect for the future.
- Data release and data transfer: Data subjects may request the release of personal data or the transfer of their data to another controller.
We may postpone, restrict or refuse the exercise of data subjects’ rights within the limits permitted by law. We may inform data subjects of any requirements that must be met to exercise their data protection rights. For example, we may refuse to provide information in full or in part in order to protect business secrets or other individuals. We may also refuse to delete personal data in full or in part due to statutory retention obligations.
In exceptional cases, we may charge costs for the exercise of these rights. We will inform data subjects in advance of any applicable costs.
We are required to identify data subjects who request information or exercise other rights by taking appropriate measures. Data subjects are required to cooperate.
6.2 Right to Lodge a Complaint
Data subjects have the right to enforce their data protection rights through legal proceedings or to lodge a complaint with the competent data protection supervisory authority.
The data protection supervisory authority for private controllers and federal bodies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).
7. Data Security
We take appropriate technical and organisational measures to ensure a level of data security appropriate to the respective risk. However, we cannot guarantee absolute data security.
Access to our website is protected by transport encryption (SSL / TLS, particularly the Hypertext Transfer Protocol Secure, abbreviated as HTTPS). Most browsers indicate transport encryption by displaying a padlock in the address bar.
Like virtually all digital communication, our digital communication is subject to mass surveillance without cause or suspicion, as well as other forms of surveillance by security authorities in Switzerland, the rest of Europe, the United States of America (USA) and other countries. We have no direct influence over the processing of personal data by intelligence services, police authorities and other security agencies.
8. Use of the Website
8.1 Cookies
We may use cookies. Cookies – including our own cookies (first-party cookies) and cookies from third parties whose services we use (third-party cookies) – are data stored in the browser. Such stored data is not necessarily limited to traditional text-based cookies.
Cookies may be stored temporarily in the browser as “session cookies” or for a specified period as permanent cookies. “Session cookies” are automatically deleted when the browser is closed. Permanent cookies have a defined storage period. Cookies make it possible, in particular, to recognise a browser during a subsequent visit to our website and thereby, for example, measure the reach of our website. Permanent cookies may also be used for online marketing.
Cookies can be fully or partially disabled and deleted at any time in the browser settings. Without cookies, our website may not be fully available. Where and to the extent required, we actively request express consent for the use of cookies.
For cookies used for performance and reach measurement or advertising, a general objection (“opt-out”) is available for numerous services through AdChoices (Digital Advertising Alliance of Canada), the Network Advertising Initiative (NAI), YourAdChoices (Digital Advertising Alliance) or Your Online Choices (European Interactive Digital Advertising Alliance, EDAA).
8.2 Server Log Files
For each visit to our website, we may collect the following information, provided that it is transmitted by your browser to our server infrastructure or can be determined by our web server: date and time, including time zone, IP address, access status (HTTP status code), operating system including user interface and version, browser including language and version, the individual subpage of our website accessed including the amount of data transferred, and the website last accessed in the same browser window (referrer).
We store such information, which may also constitute personal data, in server log files. This information is required to provide our website permanently, reliably and in a user-friendly manner, as well as to ensure data security and, in particular, the protection of personal data – including through third parties or with the assistance of third parties.
8.3 Tracking Pixels
We may use tracking pixels on our website. Tracking pixels are also known as web beacons. Tracking pixels – including those from third parties whose services we use – are small images that are usually invisible and are automatically retrieved when our website is visited. Tracking pixels can collect the same information as server log files.
9. Notifications and Communications
We send notifications and communications by email and through other communication channels, such as instant messaging or SMS.
9.1 Performance and Reach Measurement
Notifications and communications may contain web links or tracking pixels that record whether an individual message has been opened and which web links have been clicked. Such web links and tracking pixels may also record the use of notifications and communications on a personalised basis. We require this statistical recording of usage for performance and reach measurement, so that notifications and communications can be sent effectively, permanently, securely, reliably and in a user-friendly manner based on the needs and reading habits of recipients.
9.2 Consent and Objection
As a general rule, you must expressly consent to the use of your email address and other contact details unless their use is permitted for other legal reasons. Wherever possible, we use the “double opt-in” procedure to obtain consent. This means that you receive an email containing a web link that you must click to confirm your consent, thereby preventing misuse by unauthorised third parties. We may record such consent, including the IP address, date and time, for evidentiary and security purposes.
As a general rule, you may object at any time to receiving notifications and communications such as newsletters. By making such an objection, you may also object to the statistical recording of usage for performance and reach measurement. Required notifications and communications connected with our activities and operations remain reserved.
9.3 Service Providers for Notifications and Communications
We send notifications and communications with the assistance of specialised service providers.
In particular, we use:
- Mailchimp: Communication platform; provider: The Rocket Science Group LLC, doing business as Mailchimp (USA), as a subsidiary of Intuit Inc. (USA); information about data protection: Intuit Privacy Statement, including “Country and Region-Specific Terms”, Mailchimp Privacy FAQs, Mailchimp and European Data Transfers, Security, Cookie Statement, Privacy Rights Requests, Legal Terms.
10. Social Media
We maintain a presence on social media platforms and other online platforms in order to communicate with interested individuals and provide information about our activities and operations. In connection with such platforms, personal data may also be processed outside Switzerland.
The General Terms and Conditions, Terms of Use, Privacy Policies and other provisions of the individual platform operators also apply. These provisions provide information, in particular, about the rights of data subjects in relation to the respective platform, including, for example, the right to information.
11. Third-Party Services
We use services provided by specialised third parties in order to carry out our activities and operations permanently, securely, reliably and in a user-friendly manner. Among other things, these services enable us to embed functions and content into our website. When such content is embedded, the services used collect users’ IP addresses at least temporarily for technical reasons.
For necessary security-related, statistical and technical purposes, third parties whose services we use may process data relating to our activities and operations in aggregated, anonymised or pseudonymised form. This may include, for example, performance or usage data required to provide the respective service.
In particular, we use:
- Google services: Providers: Google LLC (USA) / Google Ireland Limited (Ireland) for users in the European Economic Area (EEA) and Switzerland; general information about data protection: Privacy and Security Principles, Privacy Policy, Google’s commitment to complying with applicable data protection laws, Privacy Guide for Google Products, How Google uses information from sites or apps that use its services, Types of cookies and other technologies used by Google, Personalised Advertising (activation / deactivation / settings).
11.1 Digital Infrastructure
We use services from specialised third parties to provide the digital infrastructure required in connection with our activities and operations. This includes, for example, hosting and storage services from selected providers.
In particular, we use:
- Hostpoint: Hosting; provider: Hostpoint AG (Switzerland); information about data protection: Privacy Policy.
- WordPress.com: Blog hosting and website builder; providers: Automattic Inc. (USA) / Aut O’Mattic A8C Ireland Ltd. (Ireland) for users in Europe and elsewhere; information about data protection: Privacy Policy, Cookie Policy.
11.2 Contact Options
We use services from selected providers to communicate more effectively with third parties, such as potential and existing customers.
11.3 Appointment Scheduling
We use services from specialised third parties to arrange appointments online, for example for meetings. In addition to this Privacy Policy, any directly available terms of the services used, such as Terms of Use or Privacy Policies, also apply.
11.4 Maps
We use third-party services to embed maps into our website.
In particular, we use:
- Google Maps, including the Google Maps Platform: Mapping service; provider: Google; Google Maps-specific information: How Google Uses Location Information.
11.5 Fonts
We use third-party services to embed selected fonts, icons, logos and symbols into our website.
In particular, we use:
- MyFonts by Monotype: Fonts; providers: Monotype Imaging Holdings Inc. (USA) / MyFonts Inc. (USA); information about data protection: Your Privacy, Privacy Policy, Web Font Tracking Privacy Policy.
11.6 Advertising
We use the option of displaying targeted advertising for our activities and operations through third parties, such as social media platforms and search engines.
With such advertising, we particularly aim to reach individuals who are already interested in our activities and operations or who may be interested in them (remarketing and targeting). For this purpose, we may transmit corresponding information – which may also include personal data – to third parties that enable such advertising. We may also determine whether our advertising is successful, particularly whether it leads to visits to our website (conversion tracking).
Third parties with whom we advertise and where you are registered as a user may associate your use of our website with your profile on their platform.
In particular, we use:
- Facebook Advertising (Facebook Ads): Social media advertising; providers: Meta Platforms Ireland Limited (Ireland) and other Meta companies (including companies in the USA); information about data protection: remarketing and targeting, particularly using the Facebook Pixel and Custom Audiences, including Lookalike Audiences, Privacy Policy, Advertising Preferences (users must be signed in).
- Instagram Ads: Social media advertising; providers: Meta Platforms Ireland Limited (Ireland) and other Meta companies (including companies in the USA); information about data protection: remarketing and targeting, particularly using the Facebook Pixel and Custom Audiences, including Lookalike Audiences, Instagram Privacy Policy, Facebook Privacy Policy, Instagram Advertising Preferences (users must be signed in), Facebook Advertising Preferences (users must be signed in).
12. Website Extensions
We use extensions for our website in order to provide additional functions.
In particular, we use:
- CleanTalk: Spam protection for websites; provider: CleanTalk Inc. (USA); information about data protection: Privacy Policy.
- Jetpack: Various functions for the free WordPress blogging software in the form of modules; providers: Automattic Inc. (USA) / Aut O’Mattic A8C Ireland Ltd. (Ireland) for users in Europe and elsewhere; information about data protection: Privacy Notice for Visitors to Our Users’ Sites, Automattic Privacy Policy, Jetpack Privacy Centre, Jetpack Cookie Policy, Automattic Cookie Policy.
- ShortPixel: Image hosting and optimisation; provider: ID SCOUT SRL (Romania); information about data protection: Privacy Policy, Legal & Privacy.
13. Performance and Reach Measurement
We attempt to determine how our online services are used. Within this framework, we may, for example, measure the performance and reach of our activities and operations, as well as the impact of links from third parties to our website. We may also test and compare how different parts or versions of our online services are used (“A/B testing”). Based on the results of performance and reach measurement, we can, in particular, correct errors, strengthen popular content and improve our online services.
For performance and reach measurement, the IP addresses of individual users are stored in most cases. As a general rule, IP addresses are shortened (“IP masking”) in order to comply with the principle of data minimisation by means of pseudonymisation.
Cookies may be used and user profiles may be created as part of performance and reach measurement. Any user profiles created may include, for example, the individual pages visited or content viewed on our website, information about the size of the screen or browser window and the user’s approximate location. As a general rule, any user profiles are created exclusively in pseudonymised form and are not used to identify individual users. Individual third-party services with which users are registered may associate the use of our online services with the respective user account or user profile.
In particular, we use:
- Google Analytics: Performance and reach measurement; provider: Google; Google Analytics-specific information: measurement across different browsers and devices (cross-device tracking), Privacy, Google Analytics Opt-out Browser Add-on.
- WordPress.com Stats: Performance and reach measurement; providers: Automattic Inc. (USA) / Aut O’Mattic A8C Ireland Ltd. (Ireland) for users in Europe and elsewhere; information about data protection: a module of the Jetpack extension for the free WordPress blogging software, Privacy Notice for Visitors to Our Users’ Sites, Automattic Privacy Policy, Jetpack Privacy Centre, Cookie Policy.
14. Final Provisions
We created this Privacy Policy using the privacy policy generator provided by Datenschutzpartner.
We may amend and supplement this Privacy Policy at any time. We will provide information about such amendments and additions in an appropriate form, particularly by publishing the current version of the Privacy Policy on our website.