Effective Date: 28/02/2025
1. Introduction
Digiverse.ch (hereinafter “we,” “us,” or “our”) is committed to protecting the privacy of visitors to our website and users of our services. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the General Data Protection Regulation (GDPR) of the European Union. We operate under Swiss law. We respect your privacy and strive to be transparent about our data practices.
2. Data Controller
The data controller responsible for the processing of your personal data is:
Digiverse.ch
Sonnengasse 28
CH-5313 Klingnau
3. Data Protection Officer (DPO)
[If you have a DPO, include their name and contact information here. Under the revised FADP, you are required to designate a DPO if: (a) your core activity consists of processing particularly sensitive personal data on a large scale; (b) your core activity consists of processing personal data on a large scale that requires regular and systematic monitoring; or (c) you process personal data of at least ten persons and you delegate the processing to a third party. If you do not have a DPO, state that clearly. For Example:]
“We are not required to appoint a Data Protection Officer under the FADP/GDPR. For any data privacy inquiries, please contact us at [email protected].”
4. Types of Data We Collect
We collect the following types of personal data:
- Information you provide directly:
- Contact Information: Name, email address, phone number, postal address (when you contact us, subscribe to a newsletter, or create an account).
- Account Information: Username, password (if you create an account).
- Payment Information: Credit card details, billing address (if you make a purchase). We use secure payment gateways; we do not store your full credit card details on our servers.
- Content you submit: Comments, forum posts, reviews, or other content you upload or submit to our website.
- Communications: Records of your correspondence with us (emails, chat logs, etc.).
- Job Application Information: CV, cover letter, qualifications (if you apply for a job).
- Information collected automatically:
- Log Data: IP address, browser type, operating system, referring website, pages visited, date and time of access.
- Cookies and Similar Technologies: We use cookies and similar tracking technologies to collect information about your browsing behavior on our website. This may include information about your device, browsing patterns, and preferences. (See Section 8 for more details.)
- Analytics Data: We use analytics tools (e.g., Google Analytics) to collect aggregated and anonymized data about website usage. This data helps us understand how visitors use our website and improve its performance.
- Information from Third Parties:
- Social Media Data: If you connect your social media account to our website, we may collect information from your profile (depending on your privacy settings).
- Third-Party Services: We may receive data from third-party service providers (e.g., payment processors, marketing platforms) who process data on our behalf.
5. Purposes of Data Processing
We process your personal data for the following purposes:
- Providing and Improving our Services:
- To operate and maintain our website.
- To provide you with access to our services and features.
- To personalize your experience on our website.
- To improve our website and services based on your feedback and usage.
- Communication and Customer Support:
- To respond to your inquiries and requests.
- To provide customer support.
- To send you important notices and updates about our services.
- To send you marketing communications (with your consent, where required).
- Account Management:
- To create and manage your account.
- To process your orders and payments.
- To verify your identity.
- Marketing and Advertising:
- To send you promotional emails and newsletters (with your consent).
- To display targeted advertisements on our website and other platforms.
- To analyze the effectiveness of our marketing campaigns.
- Legal Compliance:
- To comply with applicable laws and regulations.
- To respond to legal requests and court orders.
- To protect our rights and interests.
- Security:
- To protect our website and services from fraud, abuse, and security threats.
- To monitor and investigate security incidents.
6. Legal Basis for Processing
We process your personal data based on one or more of the following legal bases:
- Consent: We will obtain your explicit consent before processing your personal data for specific purposes (e.g., sending you marketing emails). You have the right to withdraw your consent at any time.
- Contract: We process your personal data when it is necessary to fulfill a contract with you (e.g., to provide you with our services).
- Legitimate Interests: We may process your personal data based on our legitimate interests, provided that your rights and interests are not overridden. Our legitimate interests include:
- Improving our website and services.
- Personalizing your experience.
- Marketing our products and services.
- Preventing fraud and abuse.
- Ensuring the security of our systems.
- Legal Obligation: We may process your personal data when it is necessary to comply with a legal obligation.
- Public Interest: In rare cases, processing may be necessary for a task carried out in the public interest.
7. Data Sharing and Disclosure
We may share your personal data with the following categories of recipients:
- Service Providers: We use third-party service providers to help us operate our website and provide our services (e.g., hosting providers, payment processors, marketing platforms, analytics providers). These service providers are contractually obligated to protect your personal data and only process it according to our instructions.
- Business Partners: We may share your data with business partners if you have requested services from them via our platform or if the processing is related to a specific partnership agreement.
- Legal Authorities: We may disclose your personal data to legal authorities if required by law or legal process.
- Affiliates: We may share your data with our affiliated companies (if applicable) for internal business purposes.
- Other Users: If you use features that allow you to share information with other users (e.g., forums, comments), your information may be visible to those users.
- In connection with a business transaction: If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction.
- Other Parties with Your Consent: We may share your data with other parties if you have given us your explicit consent to do so.
8. Cookies and Similar Technologies
We use cookies and similar technologies (e.g., web beacons, pixels) to collect information about your browsing behavior on our website.
- What are cookies? Cookies are small text files that are stored on your device when you visit a website. They are used to remember your preferences, track your activity, and personalize your experience.
- Types of cookies we use:
- Essential cookies: These cookies are necessary for the operation of our website. They enable you to navigate the website and use its features.
- Performance cookies: These cookies collect information about how you use our website, such as which pages you visit most often. This information helps us improve the performance of our website.
- Functionality cookies: These cookies allow our website to remember your preferences (e.g., language, region) and provide enhanced features.
- Targeting/advertising cookies: These cookies are used to deliver advertisements that are relevant to you and your interests. They may also be used to track the effectiveness of our advertising campaigns.
- Third-party cookies: We may use third-party cookies on our website (e.g., Google Analytics cookies, social media cookies). These cookies are subject to the privacy policies of the respective third parties.
- Your Cookie Choices: You can control cookies through your browser settings. You can block cookies, delete existing cookies, or configure your browser to notify you when a cookie is being placed. Please note that blocking cookies may affect your ability to use certain features of our website.
- Cookie Consent: We will obtain your consent to use cookies (except for essential cookies) when you first visit our website. You can withdraw your consent at any time by changing your cookie settings.
Your Cookie Choices: You can control cookies through your browser settings. You can block cookies, delete existing cookies, or configure your browser to notify you when a cookie is being placed. Please note that blocking cookies may affect your ability to use certain features of our website. - Cookie Consent: We will obtain your consent to use cookies (except for essential cookies) when you first visit our website. You can withdraw your consent at any time by:
- Using our Cookie Settings Page: [If you have a dedicated cookie settings page on your website, include the link here. Example: “clicking the ‘Cookie Settings’ link in the footer of our website.”]
- Changing your Browser Settings: As described above, you can also manage your cookie preferences directly in your browser settings.
- [If applicable, mention your Cookie Consent Management Platform (CMP) and how users can manage preferences through it.]
- Explanation and Best Practices:
- Direct Link: Providing the chrome://settings/cookies link is convenient for Chrome users.
- Manual Instructions: It’s also helpful to provide manual navigation instructions because users might be hesitant to click direct links, or the link might change in future versions of Chrome.
- Other Browsers: Give users direction how to find the setting for other browsers.
- Cookie Settings Page: If you implement a dedicated cookie settings page on your website (which is highly recommended, especially if you use a CMP), include the link to that page. This provides users with a centralized and user-friendly way to manage their cookie preferences specifically for your website. A CMP handles the implementation of this settings page in the most legally compliant way.
- Example Cookie Settings Page Text (for your website’s settings page):
- “You can use the settings below to manage your cookie preferences for Digiverse.ch. Essential cookies are required for the website to function properly and cannot be disabled. For all other cookies, you can choose to enable or disable them. Your preferences will be saved for future visits.” [Then provide a clear interface (usually provided by your CMP) for toggling different categories of cookies on/off.]
9. International Data Transfers
Your personal data may be transferred to and processed in countries outside of Switzerland and the European Economic Area (EEA) that may not have data protection laws equivalent to those in Switzerland or the EU. This is particularly relevant if you use cloud services hosted outside Switzerland.
- Safeguards: We will take appropriate safeguards to protect your personal data when it is transferred internationally, such as:
- Data Transfer Agreements: Entering into data transfer agreements with recipients based on the Swiss Federal Data Protection and Information Commissioner’s (FDPIC) approved clauses or the EU Standard Contractual Clauses (SCCs).
- Adequacy Decisions: Transferring data to countries that have been deemed to provide an adequate level of data protection by the Swiss FDPIC or the European Commission.
- Binding Corporate Rules (BCRs): Implementing Binding Corporate Rules for transfers within our group of companies (if applicable).
- Derogations: Relying on derogations provided under applicable data protection laws (e.g., your explicit consent, necessity for the performance of a contract).
- Transparency: We will inform you about the potential risks of transferring your personal data to countries outside of Switzerland and the EEA that may not have equivalent data protection laws.
10. Data Security
We have implemented appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption: Using encryption to protect your data in transit and at rest. For example, using HTTPS for website traffic.
- Access Controls: Restricting access to your personal data to authorized personnel only.
- Firewalls: Using firewalls to protect our systems from unauthorized access.
- Regular Security Audits: Conducting regular security audits to identify and address vulnerabilities.
- Data Minimization: Only collecting and retaining the personal data that is necessary for the purposes described in this Privacy Policy.
- Employee Training: Providing regular training to our employees on data protection best practices.
- Physical Security: Implementing physical security measures to protect our data centers and offices.
While we strive to protect your personal data, no method of transmission over the Internet or method of electronic storage is completely secure. Therefore, we cannot guarantee the absolute security of your personal data. In the event of a data breach, we will notify you and the relevant authorities as required by applicable law.
11. Data Retention
We will retain your personal data for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Specific Retention Periods:
- Account Information: We will retain your account information as long as your account is active. If you close your account, we may retain your information for a reasonable period of time to comply with legal obligations or resolve disputes.
- Contact Information: We will retain your contact information as long as we have a legitimate business interest in communicating with you (e.g., sending you newsletters, providing customer support).
- Payment Information: We will retain your payment information for as long as necessary to process your transactions and comply with financial regulations.
- Log Data: We will retain log data for a limited period of time for security and analytics purposes.
- Criteria for Determining Retention Periods: We will consider the following factors when determining how long to retain your personal data:
- The nature and sensitivity of the personal data.
- The purpose for which the personal data was collected.
- Applicable legal and regulatory requirements.
- The potential risk of harm from unauthorized access to or disclosure of the personal data.
When we no longer need your personal data, we will securely delete or anonymize it.
12. Your Rights
You have the following rights regarding your personal data:
- Right to Access: You have the right to request access to your personal data that we hold.
- Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal data.
- Right to Erasure (Right to be Forgotten): You have the right to request that we delete your personal data, under certain circumstances.
- Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data, under certain circumstances.
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.
- Right to Object: You have the right to object to the processing of your personal data, under certain circumstances, including processing for direct marketing purposes.
- Right to Withdraw Consent: If we are processing your personal data based on your consent, you have the right to withdraw your consent at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe that we have infringed your data protection rights. In Switzerland, the supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC). In the EU, it is the data protection authority in your country of residence.
- Right to Information: You have the right to be informed about the processing of your personal data.
How to Exercise Your Rights:
To exercise your rights, please contact us at [Your Email Address] or [Your Postal Address]. We will respond to your request within a reasonable timeframe and in accordance with applicable law. We may require you to verify your identity before we can process your request.
13. Third-Party Websites
Our website may contain links to third-party websites. This Privacy Policy does not apply to those websites. We encourage you to review the privacy policies of those websites before providing them with your personal data. We are not responsible for the privacy practices of third-party websites.
14. Children’s Privacy
Our website is not directed to children under the age of [Specify Age, e.g., 16]. We do not knowingly collect personal data from children without parental consent. If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us at [Your Email Address] and we will take steps to delete the information.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices or applicable law. We will post the updated Privacy Policy on our website and indicate the effective date. We encourage you to review this Privacy Policy periodically. If we make material changes to this Privacy Policy, we will provide you with notice as required by law.
16. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
Digiverse.ch
Sonnengasse 28
CH-5313 Klingnau
Important Considerations and Customization:
- Swiss Specifics: This template incorporates references to the FADP. Ensure you’re up-to-date on the revised FADP, which came into effect in 2023. Pay close attention to the principles of data minimization and purpose limitation.
- GDPR Applicability: If you target EU residents (e.g., by offering services in EU languages or shipping products to the EU), the GDPR will apply, even though you are based in Switzerland. This template covers the core requirements.
- Cookie Consent Management Platform (CMP): Implementing a CMP is highly recommended to manage cookie consent in a user-friendly and legally compliant manner. Popular CMPs include OneTrust, CookieYes, and Usercentrics.
- Website Analytics: If you use Google Analytics, be sure to anonymize IP addresses and comply with Google’s terms of service. Consider using a privacy-focused analytics alternative like Matomo.
- Embedded Content: If you embed content from third-party platforms (e.g., YouTube videos, social media feeds), be aware that those platforms may track users even if they don’t click on the content. Consider using privacy-enhancing alternatives or obtaining user consent before loading embedded content.
- Language: Make sure the privacy policy is available in all languages that your website supports.
- Accessibility: Ensure your privacy policy is easily accessible from your website’s homepage and in a prominent location.
- Regular Review: Review and update your privacy policy regularly to ensure it remains accurate and compliant with applicable law.