Privacy Policy

This privacy policy provides you with information about the type, scope and purpose of the processing of personal data (hereinafter “data”) within our online services and the websites, functions and content connected with them as well as our external online presence, such as our social media profiles. (hereinafter collectively “online services”). For the terms used, such as “personal data” or its “processing”, we refer you to the definitions in Art. 4 of the General Data Protection Regulation (GDPR).

Controller and data protection officer:

Types of data processed:

  • Base data (e.g. names and addresses).
  • Contact data (e.g. email and telephone numbers).
  • Content data (e.g. text, photographs and videos).
  • Contract data (e.g. subject of the contract, term and customer category).
  • Payment data (e.g. bank details and payment history).
  • Usage data (e.g. websites visited, interest in content, and access times).
  • Meta/communication data (e.g. device information and IP addresses).

Processing of special categories of data (Art. 9(1) GDPR):

  • No special categories of data are processed.
  • No special categories of data are processed unless they are provided for processing by the users, e.g. entered in online forms.

Categories of data subjects affected by the processing:

  • Customers, interested parties, and suppliers.
  • Visitors and users of the online services.

In the rest of the policy we also refer to data subjects collectively as “users”.

Purpose of the processing:

  • To make the online services, their content and functions available.
  • To provide contractual and other services as well as customer care.
  • To respond to contact enquiries and communicate with users.
  • For market, advertise and conduct market research.
  • Security measures.

Last revised: 10/08/2021

In accordance with Art. 13 GDPR, we need to inform you about the legal basis for our data processing. If the legal basis is not stated in the privacy policy, the following applies. The legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR, the legal basis for processing to perform our services, implement contractual measures and respond to enquiries is Art. 6(1)(b) GDPR, the legal basis for processing to fulfil our legal obligations is Art. 6(1)(c) GDPR, and the legal basis for processing to protect our legitimate interests is Art. 6(1)(f) GDPR. Where it is necessary to process personal data because of the vital interests of the data subject or another natural person, Art. 6(1)(d) GDPR serves as the legal basis.

We recommend regularly reviewing the content of our privacy policy. We will modify the privacy policy as soon as it becomes necessary because of any changes in the data processing we carry out. We will immediately notify you if your cooperation is required as a result of the changes (e.g. consent) or you specifically need to be otherwise notified.

We take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk in accordance with Article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the varying probability and severity of the risk to the rights and freedoms of natural persons; the principal measures include safeguarding the confidentiality, integrity and availability of data by controlling physical access to the data, as well as the access to, input, disclosure, safeguarding of availability and segregation of the data. We have also established procedures to ensure data subjects’ rights can be exercised, data erased and a response can be taken if data is compromised. We also already take the protection of personal data into account when developing and selecting hardware, software and processes, in accordance with the principle of data protection through technology design and through data protection-friendly default settings (Art. 25 GDPR).

The main security measures include the encrypted transmission of data between your browser and our server. As with any connection to a web server, the server of our web hosting provider cyon in Basel, Switzerland, logs and stores certain technical data. This data includes the IP address and the operating system of your device, the data, the access time, the type of browser and the browser request including the origin of the request (referrer). This is necessary for technical reasons so we can make our website available to you. cyon protects this data from unauthorised access by a variety of technical and organisational measures and does not pass the data on to third parties. Where we process personal data in this context, we do so based on our interest in providing you with the best possible user experience and to safeguard the security and stability of our systems.

If, in the course of our processing, we disclose data to other persons and companies (processors or third parties), transmit it to them or otherwise grant them access to the data, we will do so only if this is legally permissible (e.g. if the transmission of the data to third parties, such as to payment service providers, is necessary to perform the contract pursuant to Art. 6(1)(b) GDPR), you have consented, or a legal obligation provides for this or on the basis of our legitimate interests (e.g. when using agents, web hosts, etc.).

If we appoint third parties to process data on the basis of a “processing agreement”, we will only do so pursuant to Art. 28 GDPR.

If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or do so in the context of using third-party services or disclosing, or transmitting data to third parties, we will do so only if this is done to fulfil our (pre-)contractual obligations, on the basis of your consent, due to a legal obligation or on the basis of our legitimate interests. Subject to legal or contractual permission, we will process or permit the processing of data in a third country only if the special requirements of Art. 44 et seq. GDPR apply. This means that processing is carried out, for example, on the basis of special guarantees, such as official acknowledgement that the level of data protection corresponds to that of the EU (e.g. in the case of the USA through the “Privacy Shield”) or compliance with officially recognised special contractual obligations (“standard contractual clauses”).6.

You have the right to request confirmation as to whether the data in question is being processed, to access this data, and to obtain further information and a copy of the data under Art. 15 GDPR.

You have the right under Art. 16 GDPR to request that your data is completed or that any errors in your data are rectified.

Under Art. 17 GDPR, you have the right to obtain the erasure of the data in question without delay or, alternatively, to demand restriction of the processing of the data under Art. 18 GDPR.

You have the right to request to receive the data concerning you that you have provided to us under Art. 20 GDPR and to request its transmission to other data controllers.

You also have the right to lodge a complaint with the competent supervisory authority under Art. 77 GDPR.

You have the right to withdraw consent granted in accordance with Art. 7 (3) GDPR with effect for the future.

You may object at any time to the future processing of your data under Art. 21 GDPR. The objection can be made in particular with respect to processing of your data for the purpose of direct advertising.

We use temporary and permanent cookies, i.e. small files that are stored on users’ devices (for an explanation of this term and its function, see the last section of this privacy policy). The cookies are partly used for security purposes, or to ensure we can operate our online services (e.g. to display the website) or to save the user’s decision when confirming the cookie banner. We or our technology partners also use cookies for measuring reach and for marketing purposes, which users are informed about in the privacy policy.

You can declare your general objection to the use of cookies for online marketing purposes for a large number of services, especially those used for tracking purposes, by using the US site or the EU site You may also prevent cookies from being stored by deactivating them in your browser settings. Please note that you may then not be able to use all the functions of these online services.

The data we process will be erased or its processing restricted under Art. 17 and 18 GDPR. Unless expressly stated within the scope of this privacy policy, the data we store will be erased as soon as it is no longer required for its intended purpose and its erasure does not conflict with any statutory retention obligations. If the data is not erased because it is required for other and legally permissible purposes, its processing will be restricted. This means the data will be blocked and not processed for other purposes. This applies, for example, to data that must be retained due to commercial or tax law.

In accordance with legal requirements, all bookkeeping and business correspondence is kept for 10 years pursuant to Art. 957 to 963 of the Swiss Code of Obligations. (commercial ledgers, inventories, opening balance sheets, annual financial statements, commercial letters, accounting documents, books, records, management reports, accounting documents, commercial and business letters, electronic data traffic, documents relevant for taxation, etc.).

We process base data (e.g. names and addresses and contact data of users) and contract data (e.g. services used, names of contact persons and payment information) for the purpose of fulfilling our contractual obligations and services under Art. 6(1)(b) GDPR. The fields marked as mandatory in online forms are required for the contract to be entered into.

Users may at their discretion create a user account in which they can view their orders and perform other functions. During the registration process, users are provided with the required mandatory information. The user accounts are not public and cannot be indexed by search engines. If users have cancelled their user account, their data relating to the user account will be deleted, subject to mandatory retention for the purposes of commercial or tax law in accordance with Art. 6(1)(c) GDPR. It is the responsibility of the users to back up their data prior to the end of the contract where notice of termination has been given. We may irretrievably delete all of the user’s data stored during the term of the contract.

When users register, log back in or use our online services, we store the IP address and the time and date of the respective user action. We store this information based on our legitimate interests and those of the users to protect against misuse and other unauthorised use. This data is not passed on to third parties unless this is necessary for us to assert any claims that we may have or there is a legal obligation to do so under Art. 6(1)(c) GDPR.

We process usage data (e.g. the web pages of our online services visited or interest in our products) and content data (e.g. entries in the contact form or user profile) in a user profile for advertising purposes, e.g. in order to display product information to users based on the services they have used to date.

We delete this data after statutory warranty and comparable obligations expire. We review every three years the need to keep the data; in the case of statutory archiving obligations, we delete the data once these obligations expire (10 years); information is kept in the customer account until it is deleted.

When we are contacted (via the contact form or by email), the user’s details are processed for the purpose of dealing with the request for contact and its handling pursuant to Art. 6(1)(b) GDPR.

Users’ details may be stored in our customer relationship management system (“CRM system”) or comparable enquiry-handling system.
We use the “Gravity Forms” system provided by Rocket Genius, Inc. (1620 Centerville Turnpike, Suite 102, Virginia Beach VA 23464-6500, United States) on the basis of our legitimate interests (efficient and fast processing of user requests).

We delete the requests if they are no longer necessary. We review this necessity every two years; we permanently store requests from customers who have a customer account and refer the customer account details for deletion. Where statutory archiving obligations apply, we delete the data once these obligations expire (10 years).

If users compose comments or other contributions their IP-addresses will be saved for seven days within the scope of our legitimate interest according to article 6, paragraph 1 lit. f GDPR.

This is done as a safety measurement, should someone contribute illegal commentaries or contributions (insults, forbidden political propaganda, etc.). In such a case we can be held accountable for the respective comment or contribution and are thus interested in the identity of the author.

Within the range of our online products and services and especially in our blog we use the service Gravatar from Automattic, Inc. Inc. 132 Hawthorne Street San Francisco, CA 94107, USA.

Gravatar is a service where users can register and store profile pictures and their email addresses. If users leave posts or comments on other online presences (especially blogs) with the respective email address, their profile pictures can be displayed next to the posts or comments. For this purpose, the email address provided by the user is transmitted to Gravatar in encrypted form for the purpose of checking whether it already belongs to a profile. This is the sole purpose of the transmission of the email address and it will not be used for any other purpose, but will be deleted afterwards.

Gravatar is used based on our legitimate interests within the meaning of article 6, paragraph 1, lit. f GDPR, as we use Gravatar to offer contributors and commentators the opportunity to personalise their posts with a profile picture.

Automattic is certified under the Privacy Shield agreement and thereby offers a guarantee of compliance with European data protection law (

By displaying the images, Gravatar obtains the IP address of the user, as this is necessary for communication between a browser and an online service. More information on the collection and use of data by Gravatar can be found in Automattic’s privacy policy:

If users do not want a user image linked to their Gravatar email address to appear in the comments, they should use an email address that is not stored with Gravatar to comment. We would also like to point out that it is also possible to use an anonymous email address or no email address at all if users do not want their own email address to be sent to Gravatar. Users can completely prevent the transmission of data by not using our commenting system.

We collect access data each time the server on which this service is located (server log files) is accessed and do so on the basis of our legitimate interests in accordance with Art. 6(1)(f) GDPR. The access data includes the name of the website accessed, file, date and time of access, amount of data transferred, notification that the website has been successfully accessed, browser type and version, user’s operating system, referrer URL (page previously visited), IP address and the requesting provider.

Log file information is stored for security reasons (e.g. to clarify if misuse or fraud has occurred) for a maximum of seven days and then deleted. Data that needs to be stored for evidentiary purposes is exempt from deletion until the respective incident has been conclusively clarified.

We maintain an online presence on social networks and platforms on the basis of our legitimate interests in accordance with Art. 6(1)(f) GDPR in order to be able to communicate with customers, interested parties and users active there and to inform them about our services. When accessing the respective networks and platforms, the terms and conditions and data processing policies of their respective operators apply.

Unless otherwise stated in our privacy policy, we process the data of users if they communicate with us within the social networks and platforms, e.g. write posts on our online presence or send us messages.

Cookies are items of information that are transmitted from our web server or third-party web servers to the users’ web browsers and deposited there for later retrieval. Cookies may be small files or other types of stored information.

We use session cookies which are only stored for the duration of your current visit to our online presence (e.g. to save your login status or the shopping cart function so you are able to use our online services). A randomly generated unique identification number known as a session ID is stored in a session cookie. A cookie also contains information about its origin and how long it has been stored. These cookies cannot store any other data. Session cookies are deleted when you have finished using our online services and log out or close the browser, for example.

This privacy policy informs users of the ways in which cookies are used to measure reach in pseudonymous form.

If users do not want cookies to be stored on their computer, they should deactivate the respective option in their browser’s system settings. Stored cookies can be deleted in the browser’s system settings. Excluding cookies may lead to restrictions in the functionality of these online services.

You can object to the use of cookies used for measuring reach and for advertising purposes via the Network Advertising Initiative opt-out page( or the US website ( or the European website (

We use Google Analytics, a web analytics service provided by Google LLC (“Google”), based on our legitimate interests (i.e. interest in the analysis, optimisation and economically efficient operation of our online services in accordance with Art. 6(1)(f) GDPR). Google uses cookies. The information collected by the cookie about the use of the online services by the user is usually transmitted to a Google server in the USA and stored there.

Google is certified under the Privacy Shield agreement and therefore provides a guarantee of compliance with European data protection law (

Google will use this information on our behalf to evaluate the use of our online services by users, to compile reports on the activities within these online services and to provide us with additional services related to the use of these online services and the use of the internet. Pseudonymous user profiles can be created from the processed data.

We use Google Analytics to display the ads placed within Google’s advertising services and those of its partners only to users who have also shown an interest in our online services or who have certain characteristics (e.g. interests in certain topics or products determined on the basis of the websites visited), which we transmit to Google (“remarketing”, or “Google Analytics audiences”). With the help of remarketing audiences, we also want to make sure our ads match the potential interest of the users and are not a nuisance.

We only use Google Analytics with IP anonymisation activated. This means that the IP address of the user is shortened by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.

18.6. The IP address transmitted by the user’s browser will not be combined with any other data held by Google. Users can prevent cookies from being stored by setting their browser software accordingly; users can also prevent the data generated by the cookie relating to their use of the online services from being collected and sent to and processed by Google by downloading and installing the browser plugin available at the following link:

You can find out more information about Google’s use of data, settings options and what the options to object are on the Google website:  (“Data use by Google when you use our partners’ websites or apps”),  (“Data use for advertising purposes”), (“Managing information Google uses to display ads to you”).

Based on our legitimate interests (interest in the analysis, optimisation and the successful operation of our online service according to article 6, paragraph 1 lit. GDPR) we use the marketing and remarketing services (in short “Google marketing services”) of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, (“Google”).

Google is certified under the Privacy Shield agreement and thereby offers a guarantee of compliance with European data protection law (

Google’s marketing services allow us to target advertisements for and on our website to show users only ads that potentially match their interests. For example, if users are shown ads for products they were interested in on other websites, this is called “remarketing”. For these purposes, when our website and other websites on which Google marketing services are active are called up, a code is executed directly by Google and so-called (re)marketing tags (invisible graphics or code, also known as “web beacons”) are integrated into the website. With their help, an individual cookie, i.e. a small file, is stored on the user’s device (comparable technologies can also be used instead of cookies). The cookies can be set by various domains, including,,,, or This file records which websites users have visited, what content they are interested in and which offers they have clicked on, as well as technical information on the browser and operating system, referring websites, the time of the visit and other information on the use of the online offer. The IP address of the user is also recorded, whereby we inform you within the framework of Google Analytics that the IP address is shortened within Member States of the European Union or in other contracting states of the Agreement on the European Economic Area and only in exceptional cases is transmitted in full to a Google server in the USA and shortened there. The IP address is not merged with user data within other Google services. Google may also combine the above information with information from other sources. When users subsequently visit other websites, they can be shown ads tailored to their interests.

The users’ data is processed pseudonymously within the scope of Google marketing services. This means that Google does not store and process the name or email address of the user, for example, but processes the relevant data in a cookie-related manner within anonymised profiles. This means that from Google’s perspective, the ads are not managed and displayed for a specifically identified person, but for the cookie holder, regardless of who this cookie holder is. This does not apply if the users have expressly allowed Google to process the data without this anonymisation. The information collected by Google marketing services about users will be transmitted to Google and stored on Google’s servers in the USA.

The Google marketing services we use include the online advertising programme “Google Ads”. In the case of Google Ads, each Ads customer receives a different “conversion cookie”. Cookies can therefore not be tracked across Ads customers’ websites. The information collected through the cookie is used to create conversion statistics for Ads customers who have opted in to conversion tracking. The Ads clients learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information with which users can be personally identified.

We may include third party advertisements based on the Google marketing service “DoubleClick”. DoubleClick uses cookies to enable Google and its partner websites to serve ads based on users’ visits to this website or other websites on the internet.

We may integrate third-party advertisements based on the Google marketing service “AdSense”. AdSense uses cookies to enable Google and partner websites to display ads based on users’ visits to this website or other websites on the internet.

We can also use the “Google Optimizer” service. Google Optimizer allows us to track the effects of various changes to a website (e.g. changes to the input fields, the design, etc.) as part of so-called “A/B testing”. For these testing purposes, cookies are stored on the users’ devices. Only pseudonymous data of the users is processed.

Furthermore, we may use the “Google Tag Manager” to integrate and manage Google analytics and marketing services on our website.

For more information on Google’s use of data for marketing purposes, please visit the overview page: Google’s privacy policy is available at

If you wish to object to interest-based advertising by Google marketing services, you can use the settings and opt-out options provided by Google:

Below we provide you with details about the contents of our newsletter, the registration, delivery and statistical evaluation procedure, and your rights to object. By subscribing to our newsletter, you agree to receive it and to the procedures described.

Content of the newsletter: we send newsletters, emails and other electronic notifications with promotional information (hereinafter “newsletter”) only with the consent of the recipients or if this is legally permissible. If the contents of the newsletter are specifically described when you register, the user is deemed to have granted their consent. Our newsletters also contain information about our products, services, promotions, and our company.

Subscriptions to the newsletter are logged in order to be able to provide evidence of the subscription process in accordance with legal requirements. This includes the storage of the login and confirmation time, and IP address. Similarly, changes to your data stored with the delivery service provider are logged.

Based on its own information, the delivery service provider may also use this data in pseudonymous form, i.e. without assigning it to a user, to optimise or improve its own services, e.g. to technically optimise the delivery and presentation of the newsletter or for statistical purposes in order to determine which countries the recipients are from. However, the delivery service provider does not use our newsletter recipients’ data to write to them itself or pass it on to third parties.

Registration data: to sign up for the newsletter, all you need to do is enter your email address. Optionally, we ask you to enter a name in the newsletter so that we can address you personally.

Measuring performance: the newsletters contain a web beacon, i.e. a pixel-sized file that is retrieved from the server of the delivery service provider when the newsletter is opened. When this is retrieved, technical information, such as information on the browser and your system, your IP address and the time and date of the retrieval are initially collected. This information is used to improve the technology of the services based on the technical data or the target groups, and their reading behaviour based on their retrieval locations (which can be determined using the IP address) or the access times. The statistical surveys also include information about whether the newsletters are opened, when they are opened and which links are clicked on. For technical reasons, this information may be assigned to the individual newsletter recipients. However, it is neither our nor the delivery service provider’s intention to monitor individual users. We use the evaluations instead to determine the reading habits of our users and to adapt our content to them or to deliver different content based on the interests of our users.

The newsletter is delivered and its success is measured on the basis of the recipients’ consent pursuant to Art. 6(1)(a), Art. 7 GDPR in conjunction with section 7(2) no. 3 of the Federal Act on Unfair Competition (UCA) or on the basis of legal permission pursuant to section 7(3) UCA.
16.8. The registration process is logged on the basis of our legitimate interests under Art. 6(1)(f) GDPR and serves as proof of consent to receive the newsletter.

Cancellation/revocation: newsletter recipients can cancel receipt of our newsletter at any time, i.e. revoke their consent. You can find a link to cancel the newsletter at the end of each newsletter. Your consent to measure performance will lapse simultaneously. As it is unfortunately not possible to separately revoke measurement of performance, the entire newsletter subscription must be cancelled in this case. When you unsubscribe from the newsletter, your personal data will be deleted unless its retention is legally required or justified, in which case its processing will be limited to these exceptional purposes only. In particular, we may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them for the purposes of delivering newsletters in order to be able to demonstrate consent had previously been granted. The processing of this data is limited to the purpose of averting any claims asserted against us. It is possible at any time to make an individual request for deletion, provided that it is confirmed at the same time that consent was previously granted.

Within our online services, we use the content or services of third-party providers on the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and economically efficient operation of our online services in accordance with Art. 6(1)(f) GDPR) in order to integrate their content and services, such as videos or fonts (hereinafter uniformly “content”). This always presupposes that the third-party providers of this content are aware of the IP address of the users as without the IP address they would not be able to deliver the content to their browser. The IP address is thus required to display this content. We endeavour to only use content whose respective providers use the IP address solely to deliver the content. Third-party providers may also use pixel tags (invisible graphics, also known as web beacons) for statistical or marketing purposes. These pixel tags can be used to evaluate information such as visitor traffic on the pages of this website. Pseudonymous information may also be stored in cookies on the user’s device and may contain, among other things, technical information about the browser and operating system, referring websites, date and time of visit and other information about the use of our online services, and may also be linked to such information from other sources.

The following links provide an overview of third-party providers and their content, together with links to their privacy policies, which contain additional information on the processing of data and the opt-out rights, some of which have already been described here:

External fonts from Google, LLC.,“Google Fonts”). Google Fonts is usually integrated by a server request to Google (usually in the USA). Privacy policy: and opt-out:

Maps provided by the “Google Maps” service of the third-party provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: and opt-out:

Videos from the “YouTube” platform of the third-party provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: and opt-out:

Within our online offer, we use the marketing functions (so-called “LinkedIn Insight Tag”) of the LinkedIn network. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. Each time one of our pages containing LinkedIn functions is accessed, a connection to LinkedIn servers is established. LinkedIn is informed that you have visited our web pages with your IP address. With the help of the LinkedIn Insight Tag, we can analyse the success of our campaigns within LinkedIn or determine target groups for them based on the interaction of the users with our online offer. If you are registered with LinkedIn, it is possible for LinkedIn to assign your interaction with our online offer to your account. Even if you click the LinkedIn “Recommended” button and are logged into your LinkedIn account, it is possible for LinkedIn to associate your visit to our website with you and your account. LinkedIn is certified under the Privacy Shield agreement and thereby offers a guarantee of compliance with European data protection law ( Privacy policy:, Opt-Out:

We use functions of the XING network. The provider is XING AG, Dammtorstrasse 29-32, 20354 Hamburg, Germany. Each time one of our pages containing Xing functions is accessed, a connection to Xing servers is established. As far as we are aware, no personal data is stored in this process. In particular, no IP addresses are stored or usage behaviour analysed. Privacy policy:

External code of the JavaScript framework “jQuery”, provided by the third-party provider jQuery Foundation,