General Privacy Policy
With this Privacy Policy we, Sucsidia GmbH, describe how we collect and process personal data. This Data Protection Statement is not necessarily a comprehensive description of our data processing. It is possible that other data protection statements are applicable to specific circumstances.
In this Privacy Policy, the term «personal data» refers to any information that identifies or could reasonably be used to identify any natural person.
If you provide us with personal data of other individuals, please ensure that those individuals are aware of this Data Protection Statement. Only provide us with their data if you are authorized to do so and ensure that the personal data provided is accurate.
This Privacy Notice is in accordance with the EU General Data Protection Regulation («GDPR») and the Swiss Data Protection Act («DPA»). However, the application of these laws depends on each individual case.
I. Data Controller
The «controller» of data processing as described in this privacy policy is:
Sucsidia AG
Nasmannsbach 1
6373 Ennetbürgen
If you have any questions regarding how your personal data is processed or any other data protection concerns, you can contact us using the above-mentioned contact details.
II. Purpose of Data Processing and Legal Bases
We primarily use collected data to enter into and fulfill contracts with our clients and business partners, particularly in relation to providing services to our clients and procuring products and services from our suppliers and subcontractors. We also process personal data to comply with domestic and foreign legal obligations.
Additionally, in accordance with the applicable law and where appropriate, we may process personal data for the following purposes:
– Asserting legal claims and defending against legal disputes and official proceedings.
– Providing and developing our services and website(s) and other platforms in which we are involved.
– Prevention and investigation of criminal offenses and other misconduct.
– Ensuring the smooth operation of our IT systems, websites, apps, and other devices.
– Acquisition and sale of business divisions, companies, or parts of companies, and other corporate transactions involving the transfer of personal data. This includes measures for business management and compliance with legal and regulatory obligations, as well as internal company regulations.
– Communication with third parties and handling their requests.
If you have provided us with your consent to process your personal data for specific purposes (for example when registering to receive regular information), we will process your personal data within the scope of and based on this consent, unless we have another legal basis if one is required. You have the right to withdraw your consent at any time, but this does not affect the processing of data that occurred prior to the withdrawal.
III. Processing of and Collection of Personal Data
We primarily process personal data that we obtain from our business partners, and individuals in the context of our business relationships. Additionally, we collect data from users when operating our websites, apps, and other applications.
Where permitted, we may acquire certain personal data from public sources (e.g., credit rating agencies, debt registers, commercial registers, social media, press, internet) or receive such information from affiliated companies of Sucsidia GmbH, authorities, or other third parties (such as e.g. financial service provider). In addition to the data provided directly by you, the categories of data we receive from third parties include, but are not limited to: information from public registers, data received in administrative or court proceedings, information related to your professional role and activities (e.g., to conclude and fulfill contracts with your employer), information from correspondence and discussions with third parties, information provided by individuals associated with you (family, consultants, legal representatives, etc.) to conclude or process contracts with your involvement (e.g. powers of attorney), information regarding legal regulations such as anti-money laundering, bank details, information about you from media or internet sources (in specific cases, e.g. job applications, media reviews, marketing/sales, etc.), your address, and data related to your use of our websites (e.g., IP address, ID of your smartphone or computer, device and settings information, cookies, date and time of visit, accessed content and sites, used applications, referring website, localization data). In principle, we retain this data for 12 months after the completion of the processing purpose. However, this retention period may be extended if necessary for evidentiary reasons or to comply with legal or contractual obligations.
IV. Cookies / Tracking and other relevant Information regarding the use of our website
Technical Data
When you visit our website, we collect and evaluate user-specific data (e.g. IP address, web browser, operating system) and technical data (such as URLs of accessed pages, execution of search queries) in an anonymous manner.
The mentioned data is collected and processed for system security, stability, error and performance analysis, as well as for internal statistical purposes. This allows us to optimize our website.
For subscribing to our content or when submitting a contact form/customer login, we process the necessary data to provide the requested service. Depending on the specific service, the following data may be processed: email address, first name, last name, salutation, full address, subject matter, and message.
If you have given us your consent to process your personal data for specific purposes (for example, subscribing to a info mails or making an inquiry), we will process your personal data within the scope of and based on this consent, unless we have another legal basis, if required. You have the right to withdraw your consent at any time, but this does not affect the processing of data that occurred prior to the withdrawal.
Communication Data
If you contact us via the contact form, e-mail, chat function, phone, letter, or any other means of communication, we collect the exchanged data between you and us, including your contact details and relevant communication details. If we record or listen to phone conversations or video conferences, e.g. for training and quality assurance purposes, we will inform you of this practice. Any recordings will be made and used in accordance with our internal guidelines and applicable laws.
Generally, we retain this data for 12 months from the last interaction with you. However, this retention period may be extended if necessary for evidentiary reasons, to comply with legal or contractual requirements or for technical reasons. E-mails in personal mailboxes and written correspondence are generally retained for at least 10 years. Recordings of (video) conferences are usually retained for 24 months. Chats records are typically retained for 2 years.
Cookies and Their Use:
We use «Cookies» in some cases to customize our offering to better suit your needs. Cookies are small files that are stored on your computer or mobile device when you visit or use our websites. These cookies cannot perform any operations on their own. They save specific settings through your browser and collect data related to your interaction with the website. When a cookie is enabled, it is assigned an identification number that identifies your browser and allows the information stored in the cookie to be utilized. There are two primary types of cookies: temporary cookies and permanent cookies. We use temporary cookies, which are automatically deleted from your mobile device or computer at the end of the browser session.
We also use permanent cookies to save user settings, understand how you use our services and content, and show you personalized advertisements (including on websites of other companies; please note that such companies will not receive your identity from us; they will only know that the same user who visited their website had previously visited a specific website). Permanent cookies remain saved on your computer or mobile device for an extended period but are automatically disabled after a predetermined time.
Despite the above, you may configure your browser settings in a way that it rejects cookies, only saves them for one session or deletes them prematurely. Most browsers are preset to accept cookies. However, if you choose to block cookies, certain functions (such as, e.g., language settings) are no longer available to you.
Sucsidia GmbH allows partner companies that provide services for Sucsidia GmbH or which are integrated into our website to save cookies, as long as it is technically necessary and the use of cookies is proportionate. Sucsidia GmbH has no control over how cookies are used outside our website.
By continuing to use our website and / or agreeing to this privacy policy, you consent to the saving of cookies and the collection, storage and use of personal usage data, even after the browser session ends («permanent Cookies»). You can object to this at any time by changing the browser’s default setting to reject (third-party) cookies.
Google Analytics and Similar Services:
We may use Google Analytics or similar services on our website with the objective of designing and continuously optimizing our website to meet your needs. These services are provided by third parties, which may be located in any country worldwide (in the case of Google Analytics Google Ireland Ltd. (located in Ireland)). Google Ireland relies on Google LLC (located in the United States) as its sub-processor (both «Google», www.google.com). These services allow us to measure and evaluate the usage of our website on an anonymized basis. For this purpose, permanent cookies are used, which are set by the service provider. We have configured the service in a way that ensures IP addresses of visitors are truncated by Google within Europe before being transmitted to the United States, making it impossible to trace them back. We have also disabled the “Data sharing” and “Signals” options. Although we can assume that the information we share with Google does not constitute personal data for Google, it may be possible that Google may be able to draw conclusions about the identity of visitors based on the data collected, create personal profiles and link this data with the Google accounts of these individuals for its own purposes. If you have registered with the service provider, the service provider will also have knowledge of your identity. In this case, the processing of your personal data by the service provider will be conducted in accordance with its own data protection regulations. The service provider only provides us with data regarding the usage of the respective website, and no personal information about you is shared.
In the context of using our website, pseudonymized user profiles are created and, as previously mentioned, through the use of small text files that are stored on your computer. The information generated by such cookies regarding your usage of our website is transmitted to the servers of the service providers, where it is stored and processed on our behalf. In addition to the previously mentioned data, we may also receive the following information:
– The navigation path followed by a visitor on the website.
– The time spent on the website or subpage.
– The subpage from which you leave the website.
– The country, region or town / city from which access is made.
– The end device (type, version, color depth, resolution, width, and height of the browser window).
– Whether the visitor is a new or returning user.
The tools, programs, and instruments we use in the context of analyzing web behavior include Google Analytics, Google Tag Manager, Google Ads, YouTube (embedded videos), LinkedIn.
Information (including your IP address) generated by the cookie when using the aforementioned Google Analytics tool, is transmitted to a Google server in the USA. Google will use this information to evaluate website usage and compile reports on website activities for us as the website operator, as well as providing other services relating to website and internet use. Google may also transmit this information to third parties if required by law or if third parties process the data on Google’s behalf. Google will never associate your IP address with other Google data. You can prevent the installation of cookies by adjusting your browser settings. However, if you do so, you may not be able to use all the features on the website. By using this website, you consent to Google processing the collected data about you as described above and for the stated purpose.
V. Sharing Data with Third Parties and Transfer of Data Abroad
In the context of our business activities and in line with the purposes of the data processing outlined above, we may transfer data to third parties, insofar as such a transfer is permitted and deemed appropriate for them to process the data on our behalf or for their own purposes. In particular, the following categories of recipients may be concerned:
– Our service providers (e.g. IT-Provider, CRM-System)
Certain recipients are located within Switzerland, but others may be located in any country worldwide. In particular, you must anticipate your data to be transmitted to any country in which Sucsidia GmbH is represented by affiliates, branches or other offices as well as to other countries in Europe and the USA where our service providers are located (such as Microsoft).
If a recipient is located in a country without adequate statutory data protection, we require the recipient to commit to data protection compliance (for this purpose, we use the revised European Commission’s standard contractual clauses, which can be accessed here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?), unless the recipient is subject to a legally accepted set of rules to ensure data protection, or unless we cannot rely on an exception. An exception may apply for example in case of legal proceedings abroad, overriding public interest, contractual disclosure requirements, your consent, or if data has been publicly available and you have not objected to its processing.
F. Duration of data storage
Your data, which includes personal data, will be processed and stored only for as long as necessary to fulfil our contractual and legal obligations or for the purposes stated in the data processing activities. This may include the entire duration of the business relationship and beyond, based on legal retention requirements and documentation obligations. It is possible that personal data will be retained for the time in which claims can be asserted against our company and insofar as we are otherwise legally obliged to do so, or if legitimate business interests require it (e.g. for evidence and documentation purposes). Once your personal data is no longer required for the above-mentioned purposes, it will be erased or anonym
ized, to the extent possible. For operational data (e.g. system protocols, logs), shorter retention periods of 30 days or less apply.
VI. Data Security
We have taken technical and organizational security measures to protect your personal data against unauthorized access and misuse. These measures include issuing instructions, training, IT and network security solutions, access controls, Firewall and restrictions, encrypting passwords, data storage devices and transmissions, pseudonymization and controls.
We cannot guarantee the security of data transmission over the internet. When transmitting data by email, there is a certain risk of access by third parties.
VII. Your Rights
In accordance with and as far as provided by applicable law, you have the right to access, rectification and erasure of your personal data, the right to restriction of processing or to object to our data processing, in particular for direct marketing purposes, for profiling carried out for direct marketing purposes and for other legitimate interests in processing in addition to right to receive certain personal data for transfer to another controller (data portability). Please note, however, that we reserve the right to enforce statutory restrictions on our part, for example if we are obliged to retain or process certain data or if we have an overriding interest (insofar as we may invoke such interests) or need the data for asserting claims.
We have already informed you of the possibility to object/withdraw consent at any time. Please be aware that exercising your rights may have implications for your contractual obligations and this may result in consequences such as premature contract termination or associated costs. If this is the case, we will inform you in advance unless it has already been contractually agreed upon.
In general, exercising these rights requires that you are able to proof your identity (e.g., by a copy of identification documents where your identity is not evident otherwise or can be verified in another way). In order to assert these rights, please contact us via the details provided above.
In addition, every data subject has the right to enforce his/her rights in court or to lodge a complaint with the competent data protection authority. The competent data protection authority of Switzerland is the Federal Data Protection and Information Commissioner (http://www.edoeb.admin.ch).
IIX. Profiling
We may partially process your personal data automatically with the aim of evaluating certain personal aspects (profiling). In particular, profiling allows us to inform and advise you about products possibly relevant for you more accurately. For this purpose, we may use evaluation tools that enable us to communicate with you and advertise you as required, including market and opinion research.
While establishing and carrying out a business relationship, we generally do not use any fully automated individual decision-making (such as pursuant to article 22 GDPR). Should we use such procedures in certain cases, we will inform you separately and advise you of your relevant rights if required by law.
IX. Changes to this General Privacy Policy
We may amend this Privacy Policy at any time without prior notice. The current version published on our website shall apply. If the Privacy Policy is part of an agreement with you, we will notify you via e-mail or other appropriate means in case of an amendment.
Sucsidia AG - Together We Succeed
Nasmannsbach 1, 6373 Ennetbürgen, Switzerland
UID CHE-497.611.505 // CH-ID CH-150-4477739-4
Copyright © 2023 Sucsidia - Together We Succeed – All Rights Reserved