Privacy policy
In this privacy policy, we provide information about the processing of personal data in connection with our activities and operations, including our website under the domain names www.sse-sga.ch / www.sagw.ch/sga. In particular, we set out what personal data we process, for what purpose, in what manner and where. We also provide information on the rights of individuals whose data we process. We have drafted this privacy policy in German. Should it be published in another language, the German-language privacy policy shall prevail.
We may publish further privacy policies or other information on data protection for specific or additional activities and operations.
Contact details
The data controller is:
Frank Burose
Thomas-Bornhauser-Strasse 14
8570 Weinfelden
Switzerland
office@sse-sga.ch
In individual cases, third parties may be responsible for the processing of personal data, or there may be joint responsibility with third parties. We are happy to provide data subjects with information regarding the relevant responsibility upon request.
Definitions and legal basis
Definitions
- Data subject: A natural person in respect of whom we process personal data.
- Personal data: Any information relating to an identified or identifiable natural person.
- Sensitive personal data: data relating to trade union, political, religious or philosophical views and activities; data relating to health, sexual life or membership of an ethnic or racial group; genetic data; biometric data that uniquely identifies a natural person; data relating to criminal or administrative sanctions or proceedings; and data relating to social welfare measures.
- Processing: Any handling of personal data, regardless of the means and procedures used, for example, the retrieval, comparison, adaptation, archiving, retention, extraction, disclosure, collection, recording, erasure, organisation, storage, alteration, dissemination, linking, destruction and use of personal data.
Legal basis
We process personal data in accordance with Swiss law, in particular the Federal Act on Data Protection (Data Protection Act, DSG) and the Ordinance on Data Protection (Data Protection Ordinance, DSV).
Nature, scope and purpose of the processing of personal data
We process the personal data necessary to enable us to carry out our activities and operations on a long-term basis, in a people-centred, secure and reliable manner. The personal data processed may include, in particular, the following categories: browser and device data, content data, communication data, metadata, usage data, master data (including customer and contact details), location data, transaction data, contractual data and payment data. The personal data may also constitute special categories of personal data.
We also process personal data that we receive from third parties, obtain from publicly available sources or collect in the course of our activities and operations, insofar as such processing is permitted.
We process personal data, where necessary, with the consent of the data subjects. In many cases, we may process personal data without consent, for example to fulfil legal obligations or to safeguard overriding interests. We may also ask data subjects for their consent even where such consent is not required.
We process personal data for as long as is necessary for the respective purpose. We anonymise or delete personal data, in particular in accordance with statutory retention periods and limitation periods.
Disclosure of personal data
We may disclose personal data to third parties, have it processed by third parties, or process it jointly with third parties. Such third parties may, for example, be specialist service providers whose services we use. These third parties may, in turn, disclose personal data to other third parties. In the course of our activities and operations, we may disclose personal data in particular to banks and other financial service providers, public authorities, educational and research institutions, advisers and solicitors, accountancy and fiduciary service providers, debt collection agencies, interest groups, IT service providers, cooperation partners, credit and business information agencies, logistics and shipping companies, marketing and advertising agencies, media organisations, parent companies, sister companies and subsidiaries, organisations and associations, social institutions, telecommunications companies, insurance companies and payment service providers.
Communication
We process personal data in order to communicate with individuals, as well as with public authorities, organisations and companies. In particular, we process data that a data subject provides to us when contacting us, for example by post or email. We may store such data in an address book or using similar tools.
Third parties who provide us with data relating to other individuals are legally obliged to ensure the data protection of those data subjects themselves. In particular, they must ensure that they are authorised to provide such data and must also guarantee the accuracy of the data provided.
Data security
We take appropriate technical and organisational measures to ensure a level of data security commensurate with the respective risk. In particular, our measures ensure the confidentiality, availability, traceability and integrity of the personal data processed; however, we cannot guarantee absolute data security.
Access to our website and our other digital presence is secured via transport encryption (SSL/TLS, in particular using the Hypertext Transfer Protocol Secure, abbreviated to HTTPS). Most browsers issue a warning before visiting a website without transport encryption.
Our digital communications – like all digital communications in general – are subject to mass surveillance without cause or suspicion by security authorities in Switzerland, the rest of Europe, the United States of America (USA) and other countries. We have no direct influence over the processing of personal data by intelligence services, police forces and other security authorities. Nor can we rule out the possibility that a data subject may be subject to targeted surveillance.
Personal data abroad
As a general rule, we process personal data in Switzerland. However, we may also disclose or export personal data to other countries, in particular in order to process it there or have it processed there.
We may disclose personal data to any country on Earth or elsewhere in the universe, provided that the law of that country guarantees an adequate level of data protection in accordance with a decision by the Swiss Federal Council.
We may disclose personal data to countries whose laws do not guarantee an adequate level of data protection, provided that an appropriate level of data protection is ensured for other reasons, in particular on the basis of standard data protection clauses or other suitable safeguards. In exceptional cases, we may export personal data to countries without adequate or appropriate data protection if the specific data protection requirements are met, for example, the explicit consent of the data subjects or a direct connection to the conclusion or performance of a contract. We are happy to provide data subjects, upon request, with information about any safeguards in place or to supply a copy of such safeguards.
Rights of data subjects
Data protection rights
We grant data subjects all rights in accordance with applicable law. In particular, data subjects have the following rights:
- Access: Data subjects may request information as to whether we process personal data relating to them and, if so, what personal data is involved. Data subjects shall also receive the information necessary to exercise their data protection rights and to ensure transparency. This includes the personal data being processed as such, as well as, amongst other things, details of the purpose of processing, the duration of storage, any disclosure or export of data to other countries, and the origin of the personal data.
- Rectification and restriction: Data subjects may have inaccurate personal data rectified, incomplete data completed, and the processing of their data restricted.
- Opportunity to express one’s own viewpoint and request human review: Data subjects may, in the case of decisions based solely on the automated processing of personal data which have legal consequences for them or significantly affect them (automated individual decisions), express their own viewpoint and request a review by a human being.
- Deletion and objection: Data subjects may have personal data deleted (right to be forgotten’) and object to the processing of their data with effect for the future.
- Data disclosure and data portability: Data subjects may request the disclosure of personal data or the transfer of their data to another data controller.
We may defer, restrict or refuse the exercise of data subjects’ rights within the limits permitted by law. We may inform data subjects of any conditions that must be met in order for them to exercise their data protection rights. For example, we may refuse to provide information, in whole or in part, on the grounds of confidentiality obligations, overriding interests or the protection of other individuals. We may also, for example, refuse to delete personal data, in whole or in part, in particular by reference to statutory retention obligations.
In exceptional cases, we may charge a fee for the exercise of these rights. We will inform data subjects in advance of any such costs.
We are obliged to take reasonable measures to verify the identity of data subjects who request information or exercise other rights. Data subjects are obliged to cooperate.
Legal protection
Data subjects have the right to enforce their data protection rights through the courts or to lodge a report or complaint with a data protection supervisory authority.
The data protection supervisory authority for private data controllers and federal bodies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).
Use of the website
Cookies
We may use cookies. Cookies – both our own (first-party cookies) and those from third parties whose services we use (third-party cookies) – are data stored in the browser. Such stored data need not be limited to traditional text-based cookies.
Cookies may be stored temporarily in the browser as session cookies’ or for a specific period as so-called persistent cookies’. Session cookies’ are automatically deleted when the browser is closed. Persistent cookies have a specific retention period. In particular, cookies enable us to recognise a browser the next time you visit our website and, for example, to measure the reach of our website. However, persistent cookies may also be used for online marketing, for example.
Cookies can be disabled, restricted or deleted, either in full or in part, at any time via the browser settings. Browser settings often also allow for the automated deletion and other management of cookies. Without cookies, our website may no longer be available in its entirety. We actively seek – at least where and to the extent required by applicable law – your explicit consent to the use of cookies.
For cookies used to measure performance and reach, or for advertising purposes, many services offer a general opt-out’ option via AdChoices (Digital Advertising Alliance of Canada), the Network Advertising Initiative (NAI), YourAdChoices (Digital Advertising Alliance) or Your Online Choices (European Interactive Digital Advertising Alliance, EDAA).
Logging
For every visit to our website and our other digital presence, we may log at least the following information, provided that this is automatically collected or transmitted to our digital infrastructure during such visits: date and time, including time zone; IP address; access status (HTTP status code); operating system, including user interface and version; browser, including language and version; individual sub-pages of our website accessed, including the volume of data transferred; and the last webpage accessed in the same browser window (referrer).
We record such information, which may also constitute personal data, in log files. This information is necessary to ensure that our digital presence can be provided on a permanent, user-friendly and reliable basis. It is also required to ensure data security – including through third parties or with the assistance of third parties.
Tracking pixels
We may incorporate tracking pixels into our digital presence. Tracking pixels are also known as web beacons. Tracking pixels – including those from third parties whose services we use – are usually small, invisible images or scripts written in JavaScript that are automatically retrieved when our digital presence is accessed. Tracking pixels can be used to collect at least the same information as is recorded in log files.
Notifications and communications
Performance and reach measurement
Notifications and communications may contain web links or tracking pixels that record whether an individual message has been opened and which web links were clicked whilst doing so. Such web links and tracking pixels may also track the use of notifications and communications on a personal basis. We require this statistical tracking of usage for performance and reach measurement in order to be able to send notifications and communications effectively and in a user-friendly manner, as well as sustainably, securely and reliably, based on the needs and reading habits of the recipients.
Consent and Objection
You must, in principle, consent to the use of your email address and other contact details, unless such use is permitted on other legal grounds. We may use the double opt-in’ procedure to obtain double-confirmed consent where necessary. In this case, you will receive a message containing instructions for double confirmation. We may log the consent obtained, including IP addresses and timestamps, for evidential and security purposes.
In principle, you may object at any time to receiving notifications and communications, such as newsletters. By doing so, you may also object to the statistical recording of usage for the purposes of measuring success and reach. This is without prejudice to any necessary notifications and communications relating to our activities and operations.
Service providers for notifications and communications
We send out notifications and communications with the help of specialist service providers. In particular, we use:
- CleverReach: email marketing platform; provider: CleverReach GmbH & Co. KG (Germany); information on data protection: Privacy Policy, Data Security’.
Third-party services
We use services provided by specialist third parties to enable us to carry out our activities and operations in a sustainable, user-friendly, secure and reliable manner. These services allow us, amongst other things, to embed functions and content into our website. When such embedding takes place, the services used collect users’ IP addresses, at least temporarily, for technically necessary reasons. For necessary security-related, statistical and technical purposes, third parties whose services we use may process data relating to our activities and operations in an aggregated, anonymised or pseudonymised form. This includes, for example, performance or usage data required to provide the relevant service.
Digital infrastructure
We use services provided by specialist third parties to access the necessary digital infrastructure in connection with our activities and operations. These include
, for example, hosting and storage services from selected providers. In particular, we use:
- Hostpoint: Hosting; Provider: Hostpoint AG (Switzerland); Information on data protection: Privacy Policy.
Measuring success and reach
We seek to measure the success and reach of our activities and operations. As part of this, we may also measure the impact of third-party recommendations or assess how different parts or versions of our digital presence are used (the A/B testing’ method). Based on the results of these success and reach measurements, we can, in particular, rectify errors, enhance popular content or make improvements.
In most cases, the IP addresses of individual users are recorded for the purposes of measuring success and reach. In such cases, IP addresses are generally truncated (IP masking’) in order to comply with the principle of data minimisation through appropriate pseudonymisation.
Cookies may be used for performance and reach measurement, and user profiles may be created. Any user profiles created may include, for example, the individual pages visited or content viewed on our digital platform, details of the screen size or browser window, and the user’s location (at least approximately). In principle, any user profiles are created exclusively in pseudonymised form and are not used to identify individual users. Certain third-party services with which users are registered may, where applicable, link the use of our online service to the user’s account or profile with the respective service.
In particular, we use:
- Fathom Analytics: performance and reach measurement; provider: Conva Ventures Inc. (Canada); data protection information: a privacy-friendly alternative to Google Analytics with anonymisation of all data and no cookies; privacy policy, Our data journey’.
Final notes on the privacy policy
We have drawn up this privacy policy using the privacy policy generator provided by Datenschutzpartner.
We may update this privacy policy at any time. We will notify you of any updates by publishing the latest version of the privacy policy on our website.