Privacy Policy

This Privacy Policy provides information on the processing of personal data in connection with our activities and operations, including our website at the domain name ww.sagw.ch/sgks. In particular, we explain which personal data we process, for what purpose, in what manner and where. We also provide information on the rights of individual data we process.

We have drafted this Privacy Policy in German. In the event of publication in another language, the German-language Privacy Policy shall prevail.

For specific or additional activities and operations, we may publish further privacy policies or other information relating to data protection.

We are subject to Swiss law and, where applicable, any relevant foreign law, such as, in particular, that of the European Union (EU) with the European General Data Protection Regulation (GDPR).

In its decision of 26 July 2000, the European Commission recognised that Swiss data protection law ensures an adequate level of data protection. In a report dated 15 January 2024, the European Commission confirmed this adequacy decision.


1 Contact details

The data controller for the purposes of data protection law is:

Swiss Society for Cultural Theory and Semiotics (SGKS)
Prof. Dr. Hans Georg von Arburg (President)
UNIL-Chamberonne Campus
Anthropole Building
CH-1015 Lausanne
hg.vonarburg@unil.ch

In individual cases, third parties may be responsible for the processing of personal data, or there may be joint resposibility with third parties. We are happy to provide data subjects with information regarding the respectiv responsibility upon request.

2.1 Definitions

Data subject: A natural person in respect of whom we process personal data.

Personal data: Any information relating to an identified or identifiable natural person.

Sensitive personal data: Data relating to trade union, political, religious
or philosophical views and activities; data relating to health, sexual life
or membership of an ethnic group or race; genetic data; biometric data
that uniquely identifies a natural person; data relating to criminal and
administrative sanctions or proceedings; and data relating to social welfare measures.

Processing: Any handling of personal data, regardless of the means
and procedures used, for example, the retrieval, comparison, adaptation,
archiving, retention, extraction, disclosure, acquisition, collection, erasure, organisation, storage, alteration, dissemination, linking, destruction and use of personal data.

European Economic Area (EEA): Member States of the European Union (EU) as well as the Principality of Liechtenstein, Iceland and Norway.

2.2 Rechtsgrundlagen

We process personal data in accordance with Swiss law, in particular the Federal Act on Data Protection (Data Protection Act, DSG) and the Ordinance on Data Protection (Data Protection Ordinance, DSV).

We process – insofar as the European General Data Protection Regulation (GDPR) is applicable – personal data in accordance with at least one of the following legal bases:

  • Article 6(1)(b) of the GDPR for the processing of personal data necessary for the performance of a contract with the data subject and for the implementation of pre-contractual measures.
  • Article 6(1)(f) of the GDPR for the processing of personal data necessary to safeguard legitimate interests – including the legitimate interests of third parties – provided that the fundamental freedoms and rights, as well as the interests, of the data subject do not take precedence. Such interests include, in particular, the sustainable, people-centred, secure and reliable conduct of our activities and operations, ensuring information security, protection against misuse, the enforcement of our own legal claims and compliance with Swiss law.
  • Article 6(1)(c) of the GDPR for the necessary processing of personal data to fulfil a legal obligation to which we are subject under any applicable law of Member States within the European Economic Area (EEA).
  • Article 6(1)(e) of the GDPR for the necessary processing of personal data to the performance of a task carried out in the public interest.
  • Article 6(1)(a) of the GDPR for the processing of personal data with the consent of the data subject.
  • Article 6(1)(d) of the GDPR for the necessary processing of personal data to protect the vital interests of the data subject or of another natural person.
  • Article 9(2) et seq. of the GDPR concerning the processing of special categories of personal data, in particular where the data subjects have given their consent.


The European General Data Protection Regulation (GDPR) defines the handling of personal data as the processing of personal data and the handling of personal data requiring special protection as the processing of special categories of personal data (Article 9 of the GDPR).


3 Nature, scope and purpose of the processing of personal data

We process the personal data necessary to enable us to carry out our activities and operations on a sustainable, people-centred, secure and reliable basis. The personal data processed may fall, in particular, into the categories of browser and device data, content data, communication data, metadata, usage data, master data – including registration and contact details, location data, transaction data, contractual data and payment data. The personal data may also constitute special categories of personal data.

We also process personal data that we receive from third parties, obtain from publicly accessible sources or collect whilst carrying out our activities and operations, insofar as such processing is permitted.

We process personal data, where necessary, with the consent of the data subjects. In many cases, we may process personal data without consent, for example to comply with legal obligations or to safeguard overriding interests. We may also seek the consent of data subjects even where their consent is not required.

We process personal data for as long as is necessary for the respective purpose. We anonymise or delete personal data, in particular in accordance with statutory retention and limitation periods.


4 Disclosure of personal data

We may disclose personal data to third parties, have it processed by third parties, or process it jointly with third parties. Such third parties may, for example, be specialist providers whose services we use. Such third parties may, in turn, disclose personal data to other third parties.

In the course of our activities and operations, we may disclose personal data in particular to banks and other financial service providers, public authorities, educational and research institutions, consultants and solicitors, accountancy and fiduciary service providers, debt collection agencies, interest groups, IT service providers, cooperation partners, credit and business information agencies, logistics and shipping companies, marketing and advertising agencies, the media, parent companies, sister companies and subsidiaries, organisations and associations, social institutions, telecommunications companies, insurance companies and payment service providers.


5 Communication

We process personal data in order to be able to communicate with individuals, as well as with public authorities, organisations and companies. In doing so, we process, in particular, data provided to us by a data subject when they contact us, for example by post or email. We may store such data in an address book or using similar tools.

Third parties who provide us with data relating to other individuals are legally obliged to ensure the data protection of those data subjects themselves. In particular, they must ensure that they are authorised to provide such data and must also guarantee the accuracy of the data provided.


6 Data security

We take appropriate technical and organisational measures to ensure a level of data security commensurate with the respective risk. Through these measures, we ensure, in particular, the confidentiality, availability, traceability and integrity of the personal data processed; however, we cannot guarantee absolute data security.

Access to our website and our other digital presence is secured by means of transport encryption (SSL/TLS, in particular using the Hypertext Transfer Protocol Secure, abbreviated to HTTPS). Most browsers issue a warning before visiting a website without transport encryption.

Our digital communications are subject – as is generally the case with all digital communications –to mass surveillance without cause or suspicion by security authorities in Switzerland, the rest of Europe, the United States of America (USA) and other countries. We have no direct influence over the processing of personal data by intelligence services, police forces and other security authorities. Nor can we rule out the possibility that a data subject may be specifically monitored.


7 Personal data abroad

We generally process personal data in Switzerland and within the European Economic Area (EEA). However, we may also export or transfer personal data to other countries, in particular to process it there or have it processed there.

We may export personal data to any country on Earth and elsewhere in the universe, provided that the law of that country guarantees an adequate level of data protection in accordance with a decision by the Swiss Federal Council and – where and to the extent that the General Data Protection Regulation (GDPR) applies – also in accordance with a decision by the European Commission.

We may transfer personal data to countries whose laws do not guarantee an adequate level of data protection, provided that data protection is guaranteed for other reasons, in particular on the basis of standard data protection clauses or other suitable safeguards.

In exceptional cases, we may export personal data to countries without adequate or appropriate data protection if the specific data protection requirements are met, for example the explicit consent of the data subjects or a direct connection to the conclusion or performance of a contract. We are happy to provide data subjects, upon request, with information about any safeguards or to supply a copy of any such safeguards.


8 Rights of data subjects

8.1 Rights under data protection law

We grant data subjects all rights in accordance with applicable law. Data subjects have, in particular, the following rights:

  • Right of access: Data subjects may request information as to whether we are processing personal data relating to them and, if so, what personal data is being processed. Data subjects shall furthermore receive the information necessary to exercise their data protection rights and to ensure transparency. This includes the personal data being processed as such, but also, amongst other things, details of the purpose of processing, the retention period, any disclosure or export of data to other countries, and the origin of the personal data.
  • Rectification and restriction: Data subjects may have inaccurate personal data rectified, incomplete data completed, and the processing of their data restricted.
  • Right to express one’s own point of view and to request human review: Data subjects may, in the case of decisions based solely on the automated processing of personal data which have legal consequences for them or significantly adversely affect them (automated individual decisions), set out their own point of view and request a review by a human being.
  • Erasure and objection: Data subjects may have personal data erased (right to be forgotten’) and object to the processing of their data with effect for the future.
  • Disclosure and transfer of data: Data subjects may request the disclosure of personal data or the transfer of their data to another data controller.

We may defer, restrict or refuse the exercise of data subjects’ rights within the limits permitted by law. We may inform data subjects of any conditions that must be met in order for them to exercise their data protection rights. For example, we may refuse to provide information, in whole or in part, on the grounds of confidentiality obligations, overriding interests or the protection of other individuals. We may also, for example, refuse to erase personal data, in whole or in part, in particular on the grounds of statutory retention obligations.

In exceptional cases, we may charge a fee for the exercise of these rights. We shall inform data subjects in advance of any such costs.

We are obliged to take reasonable measures to identify data subjects who request access to their data or assert other rights. Data subjects are obliged to cooperate.

8.2 Legal redress

Data subjects have the right to enforce their data protection rights through the courts or to lodge a report or complaint with a data protection supervisory
authority.

The data protection supervisory authority for private data controllers and federal bodies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).

European data protection supervisory authorities are organised as members of the European Data Protection Board (EDPB). In some Member States of the European Economic Area (EEA), the data protection supervisory authorities have a federal structure, particularly in Germany.


9 Use of the website

9.1 Cookies

We may use cookies. Cookies – both our own (first-party cookies) and cookies from third parties whose services we use (third-party cookies) – are data that is stored in the browser. Such stored data need not be limited to traditional text-based cookies.

Cookies can be stored temporarily in the browser as session cookies’ or for a specific period as so-called permanent cookies. Session cookies’ are automatically deleted when the browser is closed. Permanent cookies have a specific storage period. In particular, cookies enable us to recognise a browser the next time it visits our website and thereby, for example, measure the reach of our website. However, permanent cookies can also be used, for example, for online marketing purposes.

Cookies can be disabled, restricted or deleted, either in full or in part, at any time via the browser settings. Browser settings often also allow for the automated deletion and other management of cookies. Without cookies, our website may no longer be available in its entirety. We actively seek – at least where and to the extent required under applicable law – your express consent to the use of cookies.

9.2 Logging

For every visit to our website and our other digital presence, we may log at least the following information, provided that this is determined or transmitted by default during such visits to our digital infrastructure: date and time including time zone, IP address, access status (HTTP status code), operating system including user interface and version, browser including language and version, individual subpages of our website accessed, including the volume of data transferred, and the last webpage accessed in the same browser window (referrer).

We log such information, which may also constitute personal data, in log files. This information is necessary to enable us to provide our digital presence on a permanent, user-friendly and reliable basis. The information is also necessary to ensure data security – including through third parties or with the assistance of third parties.

9.3 Web beacons

We may incorporate web beacons into our digital presence. Tracking pixels are also known as web beacons. Tracking pixels – including those from third parties whose services we use – are usually small, invisible images or scripts written in JavaScript that are automatically retrieved when our digital presence is accessed. Tracking pixels can capture at least the same information as is recorded in log files.


10 Third-party services

We use services provided by specialist third parties to enable us to carry out our activities and operations in a sustainable, user-friendly, secure and reliable manner. These services enable us, amongst other things, to embed functions and content into our website. When such embedding takes place, the services used collect, for technically necessary reasons, at least temporarily, the IP addresses of users.

For necessary security-related, statistical and technical purposes, third parties whose services we use may process data relating to our activities and operations in an aggregated, anonymised or pseudonymised form. This includes, for example, performance or usage data, in order to be able to provide the respective service.

Digital infrastructure

We use services provided by specialist third parties in order to utilise the necessary digital infrastructure in connection with our activities and operations. These include, for example, hosting and storage services from selected providers.


11 Final notes on the privacy policy

We have created this privacy policy using the privacy policy generator from Datenschutzpartner.

We may update this privacy policy at any time. We will notify you of any updates by publishing the latest version of the privacy policy on our website.