Privacy Policy
With this Privacy Policy, we provide information about the processing of personal data in connection with our activities and operations, including our website under the domain name www.bestag.ch. In particular, we explain which personal data we process, for what purposes, in what manner and at which locations. We also provide information about the rights of persons whose data we process.
We have drafted this Privacy Policy in German. If it is published in another language, the German-language Privacy Policy shall remain authoritative.
For individual or additional activities and operations, we may publish further privacy policies or other information relating to data protection.
Table of Contents
-
Contact Addresses
- Terms and Legal Bases
- Nature, Scope and Purpose of Processing Personal Data
- Automation and Artificial Intelligence (AI)
- Disclosure of Personal Data
- Communication
- Data Security
- Personal Data Abroad
- Rights of Data Subjects
- Use of the Website
- Notifications and Messages
- Social Media
- Third-Party Services
- Website Extensions
- Performance and Reach Measurement
- Final Notes on the Privacy Policy
1. Contact Addresses
The controller under data protection law is:
Patrice ChoffatRenggerstrasse 43
8038 Zürich
info@bestag.ch
In individual cases, third parties may be responsible for processing personal data, or joint responsibility with third parties may exist. Upon request, we will gladly provide data subjects with information about the respective responsibility.
2. Terms and Legal Bases
2.1 Terms
Data subject: A natural person about whom we process personal data.
Personal data: Any information relating to an identified or identifiable natural person.
Sensitive personal data: Data relating to trade union, political, religious or philosophical views and activities; data relating to health, the intimate sphere, or affiliation with an ethnic group or race; genetic data; biometric data that uniquely identifies a natural person; data relating to criminal and administrative sanctions or proceedings; and data relating to social assistance measures.
Processing: Any handling of personal data, regardless of the means and procedures used, for example retrieving, comparing, adapting, archiving, retaining, reading, disclosing, obtaining, recording, collecting, deleting, revealing, classifying, organising, storing, modifying, disseminating, linking, destroying and using personal data.
2.2 Legal Bases
We process personal data in accordance with Swiss law, in particular the Federal Act on Data Protection (Data Protection Act, FADP) and the Ordinance on Data Protection (DPO).
3. Nature, Scope and Purpose of Processing Personal Data
We process the personal data required to carry out our activities and operations on a permanent basis in a user-friendly, secure and reliable manner. The personal data processed may, in particular, fall into the categories of browser and device data, content data, communication data, metadata, usage data, master data including inventory and contact data, location data, transaction data, contractual data and payment data. Personal data may also constitute sensitive personal data.
We also process personal data that we receive from third parties, obtain from publicly accessible sources or collect in the course of carrying out our activities and operations, insofar as such processing is permitted.
Where necessary, we process personal data with the consent of the data subjects. In many cases, we may process personal data without consent, for example in order to comply with legal obligations or safeguard overriding interests. We may also request consent from data subjects even where their consent is not required.
We process personal data for as long as necessary for the respective purpose. In particular, we anonymise or delete personal data depending on statutory retention and limitation periods.
4. Automation and Artificial Intelligence (AI)
We may process personal data automatically or use artificial intelligence to process personal data.
We may use profiling to automatically assess certain personal aspects relating to data subjects. Profiling serves, for example, to analyse or predict interests, behaviour or personal preferences.
In individual cases, we provide information about decisions that are based exclusively on automated processing of personal data and that have legal consequences for the data subjects or significantly affect them (automated individual decisions).
5. Disclosure of Personal Data
We may disclose personal data to third parties, have it processed by third parties or process it jointly with third parties. Such third parties may, for example, be specialised providers whose services we use. These third parties may in turn disclose personal data to other third parties.
Within the scope of our activities and operations, we may disclose personal data in particular to banks and other financial service providers, authorities, educational and research institutions, consultants and lawyers, accounting and fiduciary service providers, debt collection companies, interest groups, IT service providers, cooperation partners, credit and business information agencies, logistics and shipping companies, marketing and advertising agencies, media, parent companies, sister companies and subsidiaries, organisations and associations, social institutions, telecommunications companies, insurers and payment service providers.
6. Communication
We process personal data in order to communicate with individuals as well as with authorities, organisations and companies. In doing so, we process in particular data that a data subject provides to us when contacting us, for example by postal mail or email. We may store such data in an address book or by using comparable tools.
Third parties who transmit data about other persons to us are legally obliged to independently ensure the protection of the data of those data subjects. In particular, they must ensure that they are permitted to transmit such data and must also guarantee the accuracy of the transmitted data.
We use selected services from suitable providers to enable and improve communication with individuals and other communication partners. With such services, we may also manage and otherwise process the data of data subjects beyond direct communication, for example in connection with assignments, services, projects and resource planning.
In particular, we use:
- Pipedrive: Customer relationship management (CRM); provider: Pipedrive OÜ (Estonia); information on data protection: Privacy Policy, “Data Controller and Data Processor”.
7. Data Security
We take appropriate technical and organisational measures to ensure a level of data security appropriate to the respective risk. Through our measures, we ensure in particular the confidentiality, availability, traceability and integrity of the personal data processed, although we cannot guarantee absolute data security.
Access to our website and our other digital presence is secured by transport encryption (SSL / TLS, in particular using Hypertext Transfer Protocol Secure, abbreviated HTTPS). Most browsers warn users before visiting a website without transport encryption.
Like digital communication in general, our digital communication is subject to mass surveillance without cause or suspicion by security authorities in Switzerland, elsewhere in Europe, in the United States of America (USA) and in other countries. We have no direct influence over the corresponding processing of personal data by intelligence services, police agencies and other security authorities. Nor can we rule out the possibility that a data subject is specifically monitored.
8. Personal Data Abroad
As a general rule, we process personal data in Switzerland. However, we may also disclose or export personal data to other countries, in particular in order to process it there or have it processed there.
We may disclose personal data to all countries on Earth and elsewhere in the Universe, provided that the law applicable there ensures adequate data protection in accordance with a decision of the Swiss Federal Council.
We may disclose personal data to countries whose law does not ensure adequate data protection, provided that appropriate data protection is ensured for other reasons, in particular on the basis of standard data protection clauses or other suitable safeguards. As an exception, we may export personal data to countries without adequate or appropriate data protection where the special requirements under data protection law are fulfilled, for example the express consent of the data subjects or a direct connection with the conclusion or performance of a contract. Upon request, we will gladly provide data subjects with information about any safeguards or supply a copy of such safeguards.
9. Rights of Data Subjects
9.1 Data Protection Rights
We grant data subjects all rights available under applicable law. Data subjects have, in particular, the following rights:
- Access: Data subjects may request information as to whether we process personal data about them and, if so, which personal data is involved. Data subjects also receive the information required to assert their rights under data protection law and to ensure transparency. This includes the processed personal data itself as well as, among other things, information about the purpose of processing, the retention period, any disclosure or export of data to other countries and the origin of the personal data.
- Rectification and restriction: Data subjects may have inaccurate personal data corrected, incomplete data completed and the processing of their data restricted.
- Opportunity to state their own position and request human review: In the case of decisions based exclusively on automated processing of personal data that have legal consequences for them or significantly affect them (automated individual decisions), data subjects may state their own position and request review by a human being.
- Erasure and objection: Data subjects may have personal data erased (“right to be forgotten”) and object to the processing of their data with effect for the future.
- Data release and data transfer: Data subjects may request the release of personal data or the transfer of their data to another controller.
Within the limits permitted by law, we may postpone, restrict or refuse the exercise of data subject rights. We may inform data subjects of any requirements that must be met in order to exercise their rights under data protection law. For example, we may refuse access in whole or in part by invoking confidentiality obligations, overriding interests or the protection of other persons. We may also refuse the erasure of personal data in whole or in part, in particular by invoking statutory retention obligations.
In exceptional cases, we may charge costs for the exercise of rights. We inform data subjects in advance of any such costs.
We are obliged to identify data subjects who request access or exercise other rights by means of appropriate measures. Data subjects are obliged to cooperate.
9.2 Legal Protection
Data subjects have the right to enforce their data protection claims through legal proceedings or to submit a report or complaint to a data protection supervisory authority.
The data protection supervisory authority for private controllers and federal bodies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).
10. Use of the Website
10.1 Cookies
We may use cookies. Cookies, whether our own cookies (first-party cookies) or cookies from third parties whose services we use (third-party cookies), are data stored in the browser. Such stored data does not have to be limited to traditional text-based cookies.
Cookies may be stored temporarily in the browser as “session cookies” or for a specified period as permanent cookies. Session cookies are automatically deleted when the browser is closed. Permanent cookies have a defined storage period. Cookies make it possible, in particular, to recognise a browser on its next visit to our website and thereby, for example, measure the reach of our website. Permanent cookies may also be used for online marketing.
Cookies can be wholly or partially disabled, restricted or deleted at any time in the browser settings. Browser settings often also allow automatic deletion and other management of cookies. Without cookies, our website may no longer be fully available. We actively request express consent to the use of cookies, at least where and to the extent required by applicable law.
For cookies used for performance and reach measurement or advertising, a general objection (“opt-out”) is possible for numerous services via AdChoices (Digital Advertising Alliance of Canada), the Network Advertising Initiative (NAI), YourAdChoices (Digital Advertising Alliance) or Your Online Choices (European Interactive Digital Advertising Alliance, EDAA).
10.2 Logging
For each access to our website and our other digital presence, we may log at least the following information, provided it is routinely determined or transmitted to our digital infrastructure during such access: date and time including time zone, IP address, access status (HTTP status code), operating system including user interface and version, browser including language and version, individual subpage of our website accessed including the amount of data transferred, and the web page most recently accessed in the same browser window (referrer).
We log such information, which may also constitute personal data, in log files. The information is required in order to make our digital presence permanently available in a user-friendly and reliable manner. The information is also required to ensure data security, including through third parties or with the assistance of third parties.
10.3 Tracking Pixels
We may integrate tracking pixels into our digital presence. Tracking pixels are also referred to as web beacons. Tracking pixels, including those from third parties whose services we use, are generally small, invisible images or scripts written in JavaScript that are automatically retrieved when our digital presence is accessed. Tracking pixels can collect at least the same information as is recorded in log files.
11. Notifications and Messages
11.1 Performance and Reach Measurement
Notifications and messages may contain web links or tracking pixels that record whether an individual message has been opened and which web links were clicked. Such web links and tracking pixels may also record the use of notifications and messages on a personal basis. We require this statistical recording of use for performance and reach measurement so that we can send notifications and messages effectively, in a user-friendly, permanent, secure and reliable manner, based on the needs and reading habits of recipients.
11.2 Consent and Objection
As a general rule, you must consent to the use of your email address and your other contact addresses unless such use is permitted for other legal reasons. To obtain consent confirmed twice, where applicable, we may use the “double opt-in” procedure. In this case, you will receive a message with instructions for double confirmation. For evidentiary and security purposes, we may log consent obtained, including the IP address and timestamp.
As a general rule, you may object at any time to receiving notifications and messages such as newsletters. By making such an objection, you may at the same time object to the statistical recording of use for performance and reach measurement. Required notifications and messages in connection with our activities and operations remain reserved.
11.3 Service Providers for Notifications and Messages
We send notifications and messages with the assistance of specialised service providers.
In particular, we use:
- Mailchimp: Communication platform; provider: The Rocket Science Group LLC DBA Mailchimp (USA), a subsidiary of Intuit Inc. (USA); information on data protection: Privacy Statement (Intuit), including “country- and region-specific provisions”, “Frequently Asked Questions about Privacy at Mailchimp”, “Mailchimp and European Data Transfers”, “Security”, Cookie Statement, “Privacy Rights Requests”, “Legal Terms”.
12. Social Media
We maintain a presence on social media platforms and other online platforms in order to communicate with interested persons and provide information about our activities and operations. In connection with such platforms, personal data may also be processed outside Switzerland.
The general terms and conditions, terms of use, privacy policies and other provisions of the individual platform operators also apply. These provisions provide information in particular about the rights of data subjects directly vis-à-vis the respective platform, including, for example, the right of access.
Users of social media platforms have the option of logging in to or registering for our online services using their corresponding user account (“Social Login”). The respective terms of the social media platforms concerned apply.
13. Third-Party Services
We use services from specialised third parties in order to carry out our activities and operations on a permanent basis in a user-friendly, secure and reliable manner. Among other things, such services allow us to embed functions and content into our website. For technical reasons, the services used collect at least temporarily the IP addresses of users when such content is embedded.
For necessary security-related, statistical and technical purposes, third parties whose services we use may process data in connection with our activities and operations in aggregated, anonymised or pseudonymised form. This may include, for example, performance or usage data required to provide the respective service.
In particular, we use:
- Google services: Providers: Google LLC (USA) / Google Ireland Limited (Ireland), in part for users in the European Economic Area (EEA) and Switzerland; general information on data protection: “Privacy Practices”, Privacy Policy, “How Google Uses Personal Data”, “Google Is Committed to Complying with Applicable Data Protection Laws”, “Guide to Privacy in Google Products”, “How We Use Data from Sites or Apps That Use Our Services”, Cookie Policy, “Ads You Can Control” (personalised advertising settings).
- Microsoft services: Providers: Microsoft Ireland Operations Limited (Ireland) for users in the European Economic Area (EEA), Switzerland and the United Kingdom / Microsoft Corporation (USA) for users in the rest of the world; general information on data protection: “Privacy at Microsoft”, “Data Protection and Privacy”, Privacy Statement, “Data and Privacy Settings”.
13.1 Digital Infrastructure
We use services from specialised third parties in order to make use of the digital infrastructure required in connection with our activities and operations. This includes, for example, hosting and storage services from selected providers.
In particular, we use:
- Amazon Web Services (AWS): Storage space and other infrastructure; provider: Amazon Web Services Inc. (USA); information on data protection: Privacy Notice, “Data Privacy Center”, “Data Privacy FAQ”.
- Google Cloud including Google Cloud Platform (GCP): Storage space and other infrastructure; Google Cloud-specific providers: national or regional Google companies depending on the country and region; Google Cloud-specific information: “Privacy Center”, “Google Cloud and Common Privacy Principles”, “Google Cloud Privacy Notice”, “Privacy”.
- Hostpoint: Hosting; provider: Hostpoint AG (Switzerland); information on data protection: Privacy Policy.
- Infomaniak: Hosting; provider: INFOMANIAK NETWORK SA (Switzerland); information on data protection: “Infomaniak and the Protection of Your Personal Data”, Privacy Policy, Cookie Policy, “Certifications and Labels”.
13.2 Automation and Integration of Apps and Services
We use specialised platforms to integrate and connect existing third-party apps and services. We may also use such “no-code” platforms to automate processes and activities involving third-party apps and services.
In particular, we use:
- Zapier: Automation and integration of apps and services; provider: Zapier Inc. (USA); information on data protection: Privacy Policy, “Data Privacy at Zapier”, “Data Privacy & Security FAQ”, “Security and Compliance”.
13.3 Appointment Scheduling
We use services from specialised third parties to enable online appointment scheduling, for example for meetings. In addition to this Privacy Policy, any directly visible terms of the services used, such as terms of use or privacy policies, also apply.
In particular, we use:
- Calendly: Appointment automation platform; provider: Calendly LLC (USA); information on data protection: Privacy Notice, “Security”.
- Google Calendar: Online appointment scheduling; provider: Google; Google Calendar-specific information: “Appointment Scheduling with Google Calendar”, “Privacy in Google Calendar”.
13.4 Audio and Video Conferences
We use specialised services for audio and video conferences in order to communicate online. For example, we can hold virtual meetings or conduct online classes and webinars. Participation in audio and video conferences is additionally subject to the legal texts of the individual services, such as privacy policies and terms of use.
Depending on the circumstances, we recommend keeping the microphone muted by default when participating in audio or video conferences and blurring the background or displaying a virtual background.
In particular, we use:
- Google Meet: Video conferencing; provider: Google; Google Meet-specific information: “Google Meet – Security and Privacy for Users”.
- Zoom: Platform for collaborative work, in particular with video conferencing; provider: Zoom Video Communications Inc. (USA); information on data protection: “Privacy at Zoom”, Privacy Statement, “Compliance at Zoom”.
13.5 Online Collaboration
We use third-party services to enable online collaboration. In addition to this Privacy Policy, any directly visible terms of the services used, such as terms of use or privacy policies, also apply.
In particular, we use:
- Miro: Whiteboard platform; provider: RealtimeBoard Inc. (USA); information on data protection: Privacy Policy, “Miro Trust Center”, “Security and Compliance at Miro: Frequently Asked Questions”.
- Notion: Team collaboration platform; provider: Notion Labs Inc. (USA); information on data protection: Privacy Policy, “Security & Privacy”, Cookie Notice.
- Slack: Platform for productive collaboration, in particular by chat; providers: Slack Technologies LLC (USA) for users in Canada and the USA / Slack Technologies Limited (Ireland) for users in the rest of the world; information on data protection: Privacy Policy, “Trust Center”, “Privacy FAQ”, “Data Management: Transparency and Visibility”, Cookie Policy.
13.6 Social Media Functions and Social Media Content
We use third-party services and plugins to embed functions and content from social media platforms and to enable content to be shared on social media platforms and by other means.
In particular, we use:
- Facebook (Social Plugins): Embedding Facebook functions and Facebook content, for example “Like” or “Share”; providers: Meta Platforms Ireland Limited (Ireland) and other Meta companies (including in the USA); information on data protection: Privacy Policy.
- Instagram Platform: Embedding Instagram content; providers: Meta Platforms Ireland Limited (Ireland) and other Meta companies (including in the USA); information on data protection: Privacy Policy (Instagram), Privacy Policy (Facebook).
- LinkedIn Consumer Solutions Platform: Embedding LinkedIn functions and content, for example using plugins such as the “Share Plugin”; provider: Microsoft; LinkedIn-specific information: “Privacy”, Privacy Policy, Cookie Policy, Cookie management / objection to LinkedIn email and SMS communications, objection to interest-based advertising.
13.7 Maps
We use third-party services to embed maps in our website.
In particular, we use:
- Google Maps, including Google Maps Platform: Mapping service; provider: Google; Google Maps-specific information: “How Does Google Use Location Information?”.
13.8 Digital Content
We use services from specialised third parties to integrate digital content into our website. Digital content includes in particular images and video material, music and podcasts.
In particular, we use:
- Vimeo: Video platform; provider: Vimeo Inc. (USA); information on data protection: Privacy Policy, “Private Video Hosting”.
- YouTube: Video platform; provider: Google; YouTube-specific information: “Privacy and Safety Center”, “Your Data on YouTube”.
13.9 Documents
We use third-party services to embed documents in our website. Such documents may include PDF files, presentations, spreadsheets and text documents. This may allow not only viewing, but also editing or commenting on such documents.
In particular, we use:
- Google Docs: Documents, presentations and spreadsheets; provider: Google; Google Docs-specific information: “Privacy in Google Docs, Google Sheets and Google Slides”.
13.10 Advertising
We use the possibility of displaying targeted advertising for our activities and operations through third parties such as social media platforms and search engines. With such advertising, we aim in particular to reach persons who are already interested or may be interested in our activities and operations (remarketing and targeting). For this purpose, we may transmit corresponding information, which may also be personal, to third parties that enable such advertising. We may also determine whether our advertising is successful, in particular whether it leads to visits to our website (conversion tracking).
Third parties with whom we advertise and with whom you are registered as a user may be able to associate your use of our website with your profile on their platform.
In particular, we use:
- Google Ads: Search engine advertising; provider: Google; Google Ads-specific information: Advertising based, among other things, on search queries, with various domain names, in particular doubleclick.net, googleadservices.com and googlesyndication.com, being used for Google Ads; Privacy Information for Advertising; “Manage Ads Directly Through the Ads Shown”.
- Meta Ads: Social media advertising on Facebook and Instagram; providers: Meta Platforms Ireland Limited (Ireland) and other Meta companies (including in the USA); information on data protection: Targeting, including retargeting, in particular using the Meta Pixel and Custom Audiences, including Lookalike Audiences; Privacy Policy; “Ad Preferences” (login as a user required).
14. Website Extensions
We use extensions for our website in order to make additional functions available. We may use selected services from suitable providers or operate such extensions on our own digital infrastructure.
In particular, we use:
- Google reCAPTCHA: Bot protection (distinguishing between desired human activity and undesired bot activity); provider: Google; Google reCAPTCHA-specific information: “What Is reCAPTCHA?”.
15. Performance and Reach Measurement
We try to measure the performance and reach of our activities and operations. In this context, we may also measure the impact of third-party references or examine how different parts or versions of our digital presence are used (“A/B testing”). Based on the results of performance and reach measurement, we may in particular correct errors, strengthen popular content or make improvements.
In most cases, the IP addresses of individual users are recorded for performance and reach measurement. In such cases, IP addresses are generally shortened (“IP masking”) in order to comply with the principle of data minimisation through corresponding pseudonymisation.
Cookies may be used and user profiles may be created for performance and reach measurement. Any user profiles created may include, for example, the individual pages visited or content viewed on our digital presence, information about the size of the screen or browser window and the at least approximate location. As a general rule, any user profiles are created exclusively in pseudonymised form and are not used to identify individual users. Individual third-party services with which users are logged in may be able to associate use of our online services with the user account or user profile held with the respective service.
In particular, we use:
- Google Marketing Platform: Performance and reach measurement, in particular using Google Analytics; provider: Google; Google Marketing Platform-specific information: Measurement across different browsers and devices (cross-device tracking) using pseudonymised IP addresses, which are transferred in full to Google in the USA only in exceptional cases; Privacy Information for Google Analytics; “Browser Add-on for Disabling Google Analytics”.
- Google Tag Manager: Integration and management of Google and third-party services, in particular for performance and reach measurement; provider: Google; Google Tag Manager-specific information: Privacy Information for Google Tag Manager; further information on data protection can be found with the individual integrated and managed services.
- Hotjar: Recording of user behaviour; provider: Hotjar Ltd. (Malta); information on data protection: Recording without reference to individual website visitors, for example in relation to movements and clicks with a mouse or another input method; “Privacy and Hotjar”; “Privacy”; Privacy Policy; Cookie Information; “Security”.
- Mouseflow: Evaluation of movements, input and other behaviour of website visitors without personal reference; providers: Mouseflow ApS (Denmark) / Mouseflow Inc. (USA); information on data protection: Privacy Policy; “Privacy & Security Overview”; opt-out option.
16. Final Notes on the Privacy Policy
We created this Privacy Policy using the Privacy Policy Generator from Datenschutzpartner.
We may update this Privacy Policy at any time. We provide information about updates by publishing the current version of the Privacy Policy on our website.