Skip to main content Skip to search Skip to main navigation

Privacy Policy

This privacy policy provides information on the processing of personal data in connection with our activities and operations, including our website at the domain name schirme.ch. In particular, we explain what personal data we process, for what purpose, in what manner and where. We also provide information on the rights of individuals whose data we process.

We have drafted this privacy policy in German. In the event of publication in another language, the German-language privacy policy shall prevail.

We may publish further privacy notices or other information on data protection for specific or additional activities and operations.

1. Contact details

The data controller within the meaning of data protection law is:

Strotz AG
Herrenackerstrasse 16
8730 Uznach

info@strotz.ch

In specific cases, third parties may be responsible for the processing of personal data, or there may be joint responsibility with third parties. We are happy to provide data subjects with information regarding the respective responsibility upon request.

2. Definitions and legal basis

2.1 Definitions

Data subject: A natural person in respect of whom we process personal data.

Personal data: Any information relating to an identified or identifiable natural person.

Sensitive personal data: Data relating to trade union, political, religious or philosophical views and activities; data relating to health, private life or membership of an ethnic or racial group; genetic data; biometric data that uniquely identifies a natural person; data relating to criminal or administrative sanctions or proceedings, and data relating to social welfare measures.

Processing: Any handling of personal data, regardless of the means and procedures used, for example, retrieving, matching, adapting, archiving, storing, reading out, disclosing, obtaining, collecting, collection, erasure, disclosure, classification, organisation, storage, alteration, dissemination, linking, destruction and use of personal data.

2.2 Legal basis

We process personal data in accordance with Swiss law, in particular the Federal Act on Data Protection (Data Protection Act, DSG) and the Ordinance on Data Protection (Data Protection Ordinance, DSV).

3. Nature, scope and purpose of the processing of personal data

We process the personal data necessary to enable us to carry out our activities and operations on a sustainable, people-centred, secure and reliable basis. The personal data processed may include, in particular, the following categories: browser and device data, content data, communication data, metadata, usage data, master data (including customer and contact details), location data, transaction data, contractual data and payment data. The personal data may also constitute special categories of personal data.

We also process personal data that we receive from third parties, obtain from publicly available sources or collect in the course of our activities and operations, insofar as such processing is permitted.

We process personal data, where necessary, with the consent of the data subjects. In many cases, we may process personal data without consent, for example to comply with legal obligations or to safeguard legitimate interests. We may also ask data subjects for their consent even where their consent is not required.

We process personal data for as long as is necessary for the respective purpose. We anonymise or delete personal data, in particular in accordance with statutory retention and limitation periods.

4. Disclosure of personal data

We may disclose personal data to third parties, have it processed by third parties, or process it jointly with third parties. Such third parties may, for example, be specialist service providers whose services we use. Such third parties may, in turn, disclose personal data to other third parties.

As part of our activities and operations, we may disclose personal data in particular to banks and other financial service providers, public authorities, educational and research institutions, consultants and solicitors, accountancy and fiduciary service providers, debt collection agencies, interest groups, IT service providers, cooperation partners, credit and business information agencies, logistics and delivery companies, marketing and advertising agencies, media, parent companies, sister companies and subsidiaries, organisations and associations, social institutions, telecommunications companies, insurance companies and payment service providers.

5. Communication

We process personal data in order to be able to communicate with individuals as well as with public authorities, organisations and companies. In doing so, we process, in particular, data that a data subject provides to us when making contact, for example by post or email. We may store such data in an address book or using similar tools.

Third parties who provide us with data relating to other individuals are legally obliged to ensure the data protection of those data subjects themselves. In particular, they must ensure that they are authorised to transmit such data and must also guarantee the accuracy of the data transmitted.

6. Data security

We take appropriate technical and organisational measures to ensure data security commensurate with the respective risk. Through our measures, we ensure, in particular, the confidentiality, availability, traceability and integrity of the personal data processed, without, however, being able to guarantee absolute data security.

Access to our website and our other digital platforms is secured via transport encryption (SSL/TLS, in particular using the Hypertext Transfer Protocol Secure, abbreviated to HTTPS). Most browsers issue a warning before visiting a website without transport encryption.

Our digital communications – like all digital communications in general – are subject to mass surveillance without cause or suspicion by security authorities in Switzerland, the rest of Europe, the United States of America (USA) and other countries. We have no direct influence over the processing of personal data by intelligence services, police forces and other security authorities. Nor can we rule out the possibility that a data subject may be specifically monitored.

7. Personal data abroad

We generally process personal data in Switzerland. However, we may also disclose or export personal data to other countries, in particular to process it there or have it processed there.

We may disclose personal data to any country on Earth or elsewhere in the universe, provided that the law of that country guarantees an adequate level of data protection in accordance with a decision by the Swiss Federal Council.

We may disclose personal data to countries whose laws do not guarantee an adequate level of data protection, provided that an appropriate level of data protection is ensured for other reasons, in particular on the basis of standard data protection clauses or other suitable safeguards. In exceptional cases, we may transfer personal data to countries without adequate or appropriate data protection if the specific data protection requirements are met, such as the explicit consent of the data subjects or a direct link to the conclusion or performance of a contract. We are happy to provide data subjects, upon request, with information about any safeguards in place or to supply a copy of such safeguards.

8. Rights of data subjects

8.1 Data protection rights

We grant data subjects all rights in accordance with applicable law. In particular, data subjects have the following rights:

  • Right of access: Data subjects may request information as to whether we process personal data concerning them and, if so, what personal data is involved. Data subjects shall also receive the information necessary to exercise their data protection rights and to ensure transparency. This includes the personal data being processed as such, but also, amongst other things, details of the purpose of processing, the duration of storage, any disclosure or export of data to other countries, and the origin of the personal data.
  • Rectification and restriction: Data subjects may have inaccurate personal data rectified, incomplete data supplemented, and the processing of their data restricted.
  • Right to express one’s own point of view and to a human review: Data subjects may, in the case of decisions based solely on the automated processing of personal data which produce legal effects concerning them or significantly affect them (automated individual decisions), set out their own point of view and request a review by a human being.
  • Erasure and objection: Data subjects may request the erasure of personal data (‘right to be forgotten’) and object to the processing of their data with effect for the future.
  • Data disclosure and data portability: Data subjects may request the disclosure of personal data or the transfer of their data to another data controller.

We may defer, restrict or refuse the exercise of data subjects’ rights to the extent permitted by law. We may inform data subjects of any conditions that must be met in order for them to exercise their data protection rights. For example, we may refuse to provide information, in whole or in part, on the grounds of confidentiality obligations, overriding interests or the protection of other individuals. We may, for example, also refuse to erase personal data, in particular by reference to statutory retention obligations, either in full or in part.

In exceptional cases, we may charge a fee for the exercise of these rights. We will inform data subjects in advance of any such costs.

We are obliged to take reasonable measures to identify data subjects who request information or exercise other rights. Data subjects are obliged to cooperate.

8.2 Legal redress

Data subjects have the right to enforce their data protection claims through the courts or to lodge a report or complaint with a data protection supervisory authority.

The data protection supervisory authority for private data controllers and federal bodies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).

9. Use of the website

9.1 Cookies

We may use cookies. Cookies – both our own cookies (first-party cookies) and cookies from third parties whose services we use (third-party cookies) – are data stored in the browser. Such stored data need not be limited to traditional text-based cookies.

Cookies may be stored temporarily in the browser as ‘session cookies’ or for a specific period as so-called ‘persistent cookies’. ‘Session cookies’ are automatically deleted when the browser is closed. Persistent cookies have a specific retention period. In particular, cookies enable us to recognise a browser the next time you visit our website and, for example, to measure the reach of our website. However, persistent cookies can also be used for online marketing, for instance.

Cookies can be disabled, restricted or deleted, either in full or in part, at any time via your browser settings. Browser settings often also allow for the automatic deletion and other management of cookies. Without cookies, our website may no longer be available in its entirety. We actively seek your express consent to the use of cookies – at least where and to the extent required by applicable law.

For cookies used to measure performance and reach, or for advertising, a general ‘opt-out’ is available for many services via AdChoices (Digital Advertising Alliance of Canada), the Network Advertising Initiative (NAI), YourAdChoices (Digital Advertising Alliance) or Your Online Choices (European Interactive Digital Advertising Alliance, EDAA).

9.2 Logging

For every visit to our website and our other digital presence, we may log at least the following information, provided that this is automatically collected or transmitted to our digital infrastructure during such visits: date and time, including time zone; IP address; access status (HTTP status code); operating system, including user interface and version; browser, including language and version; individual sub-pages of our website accessed, including the volume of data transferred; the last webpage accessed in the same browser window (referrer).

We record such information, which may also constitute personal data, in log files. This information is necessary to ensure that our digital presence is available on a permanent, user-friendly and reliable basis. The information is also required to ensure data security – including through third parties or with the assistance of third parties.

9.3 Web beacons

We may incorporate tracking pixels into our digital presence. Tracking pixels are also known as web beacons. Tracking pixels – including those from third parties whose services we use – are usually small, invisible images or JavaScript scripts that are automatically retrieved when our digital presence is accessed. Tracking pixels can be used to collect at least the same information as is recorded in log files.

10. Notifications and communications

10.1 Performance and Reach Measurement

Notifications and communications may contain web links or tracking pixels that record whether an individual message has been opened and which web links were clicked on. Such web links and tracking pixels may also record the use of notifications and communications on a personal basis. We require this statistical tracking of usage for performance and reach measurement in order to be able to send notifications and communications effectively and in a user-friendly manner, as well as sustainably, securely and reliably, based on the needs and reading habits of the recipients.

10.2 Consent and Objection

You must, in principle, consent to the use of your email address and other contact details, unless such use is permitted on other legal grounds. We may use the ‘double opt-in’ procedure to obtain double-confirmed consent where necessary. In this case, you will receive a message containing instructions for the double confirmation. We may log the consent obtained, including the IP address and timestamp, for evidential and security reasons.

In principle, you may object at any time to receiving notifications and communications such as newsletters. By doing so, you may also object to the statistical recording of usage for the purposes of measuring success and reach. This is without prejudice to any necessary notifications and communications relating to our activities and operations.

10.3 Service providers for notifications and communications

We send out notifications and communications with the help of specialist service providers.

In particular, we use:

11. Social Media

We maintain a presence on social media platforms and other online platforms in order to communicate with interested parties and to provide information about our activities and operations. In connection with such platforms, personal data may also be processed outside Switzerland.

The General Terms and Conditions (GTC) and Terms of Use, as well as the privacy policies and other provisions of the individual operators of such platforms, also apply in each case. These provisions provide information, in particular, on the rights of data subjects directly vis-à-vis the respective platform, including, for example, the right of access.

12. Third-party services

We use services provided by specialist third parties to enable us to carry out our activities and operations in a sustainable, user-friendly, secure and reliable manner. These services allow us, amongst other things, to embed functions and content into our website. When such embedding takes place, the services used collect users’ IP addresses, at least temporarily, for technically necessary reasons.

For necessary security-related, statistical and technical purposes, third parties whose services we use may process data relating to our activities and operations in an aggregated, anonymised or pseudonymised form. This includes, for example, performance or usage data required to provide the relevant service.

In particular, we use:

12.1 Digital infrastructure

We use services provided by specialist third parties to access the digital infrastructure required in connection with our activities and operations. These include, for example, hosting and storage services from selected providers.

In particular, we use:

12.2 Online collaboration

We use third-party services to facilitate online collaboration. In addition to this privacy policy, any terms and conditions directly applicable to the services used – such as terms of use or privacy policies – shall also apply.

In particular, we use:

12.3 Digital content

We use services provided by specialised third parties to embed digital content on our website. Digital content includes, in particular, images and video material, music and podcasts.

In particular, we use:

12.4 Payments

We use specialist service providers to process payments securely and reliably. The legal documents of the individual service providers, such as General Terms and Conditions (GTC) or privacy policies, also apply to the processing of payments.

In particular, we use:

12.5 Advertising

We make use of the option to display targeted advertising for our activities and operations on third-party platforms, such as social media platforms and search engines.

In particular, we aim to use such advertising to reach people who are already interested in our activities and operations or who might be interested in them (remarketing and targeting). To this end, we may transfer relevant information – which may include personal data – to third parties that facilitate such advertising. We may also determine whether our advertising is successful; in particular, whether it leads to visits to our website (conversion tracking).

Third parties through whom we advertise and with whom you, as a user, have an account may, where applicable, link your use of our website to your profile on their platform.

In particular, we use:

13. Website extensions

We use website extensions to enable additional functions. We may use selected services from suitable providers or implement such extensions on our own digital infrastructure.

In particular, we use:

14. Measuring success and reach

We endeavour to measure the success and reach of our activities and operations. As part of this, we may also measure the impact of third-party content or test how different parts or versions of our digital presence are used (the ‘A/B testing’ method). Based on the results of these success and reach measurements, we can, in particular, rectify errors, enhance popular content or make improvements.

In most cases, the IP addresses of individual users are collected for the purposes of performance and reach measurement. In this case, IP addresses are always truncated (‘IP masking’) in order to comply with the principle of data minimisation through appropriate pseudonymisation.

Cookies may be used and user profiles created when measuring success and reach. Any user profiles created may include, for example, the individual pages visited or content viewed on our digital platform, details of the screen size or browser window size, and the user’s location – at least approximately. In principle, any user profiles created are exclusively pseudonymised and are not used to identify individual users. Certain third-party services with which users are registered may, where applicable, link the use of our online service to the user’s account or profile with the respective service.

In particular, we use:

15. Final notes on the privacy policy

We may update this privacy policy at any time. We will notify you of any updates by publishing the latest version of the privacy policy on our website.

Loading...
Upload in progress, please be patient ...