Privacy
Privacy Policy AFRISO AG
1. About this privacy policy
With this privacy policy, we, AFRISO AG (hereinafter AFRISO, we or us), explain how we collect and otherwise process personal data when you visit our website, purchase our products or services, when we enter into or manage a business relationship with you as a business partner or with your employer, or when you interact with us in any other way.
Under certain circumstances, additional privacy policies or other legal documents, such as general terms and conditions, may apply, which is why this document does not constitute an exhaustive description of our data processing in all cases.
Personal data is understood to mean all information relating to an identified or identifiable person. Processing comprises any handling of personal data, irrespective of the means and procedures applied, in particular, the retention, disclosure, procurement, collection, erasure, storage, modification, destruction and use of personal data.
If you provide us with personal data of other persons (e.g. data of employees or family members), we assume that you have ensured that these persons are aware of this privacy policy, that this personal data is correct and that you only disclose their personal data to us if you are permitted to do so.
We are generally subject to Swiss data protection law, which is why this privacy policy is primarily designed to comply with the Swiss Federal Act on Data Protection (FADP). However, whether the EU General Data Protection Regulation (GDPR) or other data protection laws are applicable depends on the specific individual case.
2. Controller
AFRISO AG, Bürerfeld 22a, 9245 Oberbüren is the controller responsible for the data processing described herein, unless otherwise specified in an individual case.
Should you have any concerns regarding data protection law, you are welcome to address them to the following contact address:
AFRISO AG
Bürerfeld 22a,
9245 Oberbüren
office@afriso.ch
+41 71 744 33 44
3. How do we collect your data?
In principle, we process personal data that we receive within the scope of our business relationship with our customers and other business partners (in particular, also suppliers) from them and other persons involved therein, or that we collect from their users during the operation of our websites and other applications, in particular, also during interactions with our profiles on social networks.
It is possible that we also extract certain data from publicly accessible sources (e.g. debt collection or commercial registers, land registers, the press, the internet) or receive such data from our business partners, from authorities and other third parties (such as credit reference agencies).
4. Which data do we process?
We process those data that you transmit directly to us in connection with the use of our offers and services (solutions for building automation, e.g. gateways, sensors for indoor climate, leakage protection etc., the AFRISOhome app and other modular measuring systems linked to the app) as well as our business relationship, for example personally, by telephone, via email or contact form (e.g. contact details as well as corresponding messages), or which result from the use of our offers and services or in connection with the handling of the business relationship (e.g. contract data). Furthermore, we process data from you that you make available to us in connection with an application.
In addition to this data, the categories of personal data that we may receive about you from third parties include, in particular
- Information in connection with your professional functions and activities (so that we can, for example, with your help, conclude and process business transactions with your employer);
- Information about you in correspondence and discussions with third parties;
- Information from public registers as well as from credit reports (insofar as we conduct business transactions with you personally);
- Information that we may learn in connection with official and judicial proceedings;
- Information about you given to us by persons in your environment (family, employer, advisors, legal representatives, etc.) so that we can conclude or process contracts with you or with your involvement (e.g. references, your address for deliveries, powers of attorney, information on compliance with legal requirements such as anti-money laundering and export restrictions, information from banks, insurance companies, sales and other contractual partners of ours regarding the utilisation or provision of services by you (e.g. payments made, purchases made));
- Information from the media and the internet regarding your person (insofar as this is indicated in the specific case, e.g. within the scope of an application, press review, marketing/sales, etc.), your addresses and, if applicable, interests and other socio-demographic data (for marketing);
- Information and data in connection with the use of the website or the social media used by us (e.g. IP address, MAC address of the smartphone or computer, details about your device and settings, cookies, date and time of the visit, pages and content accessed, functions used, referring website, location data).
5. Why do we process your data and what is the legal basis?
When we process personal data, our primary concern is to conclude and manage our contracts with our customers and business partners. This concerns, in particular, processing within the scope of our provision of services for our customers and the purchase of products and services from our suppliers and subcontractors (insofar as the GDPR is applicable, this concerns Art. 6 para. 1 lit. b GDPR). In this context, we process your data, in particular in order to
- communicate with you and to be able to provide you with optimal advice;
- conclude and process the assignment or order with you or your employer/client (in particular, for administrative purposes, such as invoicing, etc.);
- inform you about our offers and services;
- process our purchases from you or your employer/client as our business partner;
- expand our network.
It is possible that your personal data is also affected by this if you work for one of our customers or business partners (insofar as the GDPR is applicable, this concerns Art. 6 para. 1 lit. f GDPR). In these cases, our legitimate interest consists in managing the business relationship optimally and as efficiently as possible. We must also process certain data in order to comply with our legal obligations in Switzerland and abroad (insofar as the GDPR is applicable, this concerns Art. 6 para. 1 lit. c GDPR).
In addition, we process personal data, insofar as permitted and as it appears appropriate to us, also for the following purposes in which we (and in certain cases also third parties) have a legitimate interest corresponding to the purpose (insofar as the GDPR is applicable, this concerns Art. 6 para. 1 lit. f GDPR):
- Provision and further development of our offers, services and websites, apps and other platforms on which we are present;
- Communication with third parties and processing of their enquiries (e.g. applications, media enquiries, authorities etc.);
- Review and optimisation of procedures for needs analysis for the purpose of direct customer approach as well as collection of personal data from publicly accessible sources for the purpose of customer acquisition;
- Advertising and marketing (including the organisation of events and publication of customer magazines as well as catalogues), provided you have not objected to the use of your data (if we send you advertising as an existing customer of ours, you can object to this at any time, we will then place you on a Robinson/advertising suppression list against further advertising mailings);
- Market and opinion research, media monitoring;
- Assertion of legal claims and defence in connection with legal disputes and official proceedings;
- Prevention and clarification of criminal offences and other misconduct (e.g. conducting internal investigations, data analyses to combat fraud);
- Ensuring our operations, in particular, the IT, our websites, apps and other platforms;
- Video surveillance to safeguard property rights and other measures for IT, building and facility security and protection of our employees and other persons and assets belonging to or entrusted to us (such as access controls, visitor lists, network and mail scanners, telephone recordings);
- Purchase and sale of business divisions, companies or parts of companies and other corporate transactions and, associated therewith, the transfer of personal data as well as measures for business management and for compliance with legal and regulatory obligations as well as internal regulations of AFRISO AG.
Insofar as you have given us consent to process your personal data for specific purposes (for example, when you register to receive newsletters), we process your personal data within the scope of and based on this consent, insofar as we have no other legal basis and we require one (insofar as the GDPR is applicable, this concerns Art. 6 para. 1 lit. a GDPR). Consent granted can be withdrawn at any time, which, however, has no effect on data processing that has already taken place.
6. What happens to your data that is collected or processed in connection with the use of our website / social networks?
6.1 Website and Cookies
We use "cookies" and similar techniques on our website with which your browser or your device can be identified.
Cookies are text files that are placed on your terminal device (PC, laptop computer, tablet computer or smartphone). These text files are downloaded by your browser the first time you visit our website. When you visit a website again using the same device or browser, the cookie and the information stored therein are either sent back to the website that generated it (so-called first-party cookie) or sent to another website to which it belongs (so-called third-party cookie). As a result, the website recognises that this concerns the same user and adapts the display of content on the website. In addition to cookies that are merely used during a session and deleted after your website visit (so-called session cookies), cookies can also be used to store user settings and other information over a certain period of time (e.g. two years) (so-called permanent cookies).
You have the option to set your browser in principle so that it rejects cookies, only stores them for one session or otherwise deletes them prematurely. Most browsers are preset to accept cookies. We use permanent cookies so that we can better understand how you use our offers and content. Some of the cookies are set by us, some also by contractual partners with whom we cooperate. If you block cookies, it is possible that certain functionalities (such as language selection, shopping cart, ordering processes) will no longer function.
By using our website, you consent to the use of these techniques. If you do not wish this, you must set your browser accordingly.
6.2 Newsletters and Marketing E-Mails
In our newsletters and other marketing e-mails, we sometimes and, to the extent permitted, incorporate visible and invisible image elements, through the retrieval of which from our servers we can determine whether and when you opened the email, so that we can also measure and better understand how you use our offers and tailor them to you here. You can block this in your email program; most are preset to do so.
By consenting to receive newsletters and other marketing emails, you agree to the use of these techniques. If you do not wish this, you must set your email program accordingly.
6.3 Google Analytics
We may occasionally use Google Analytics or comparable services on our websites. This is a service provided by third parties, who may be located in any country worldwide (in the case of Google Analytics, it is Google Ireland (based in Ireland); Google Ireland relies on Google LLC (based in the USA) as a data processor (both "Google"), www.google.com), which enables us to measure and evaluate the use of the website (on a non-personal basis). For this purpose, permanent cookies set by the service provider are also used. We have configured the service in such a way that the IP addresses of visitors are truncated by Google in Europe before being forwarded to the USA, making them untraceable. We have disabled the "Data Sharing" and "Signals" settings. Although we can assume that the information we share with Google does not constitute personal data for Google, it is possible that Google may use this data for its own purposes to infer the identity of visitors, create personal profiles, and link this data to the Google accounts of these individuals. Insofar as you have registered with the service provider yourself, the service provider also knows your identity. The processing of your personal data by the service provider is then the responsibility of the service provider in accordance with its own privacy policy. The service provider merely informs us how our respective website is used (no information about you personally).
6.4 Social Networks
Furthermore, we have integrated so-called plug-ins of social networks such as Facebook, YouTube, LinkedIn, or Instagram on our website. This can be recognized by the respective symbols. We have configured these elements to be deactivated by default. When you click them, they are activated, and the operators of the respective social networks can record accordingly that you are on our website and, if applicable, from where you are accessing it. The operators of the respective social networks can record that you are on our website and, if applicable, from where you are accessing it. This information can be used by the network operators for their own purposes. The processing of your personal data is then the responsibility of this network operator, and its privacy policy applies. In principle, we do not receive any information about you from the network operators.
In addition to the plug-ins on the website, we are also present on these social networks in order to inform interested parties about our offers and, if applicable, to communicate with them. If you interact with our profiles on these social networks, we may process certain personal data belonging to you. When you use these social networks, however, the general terms and conditions, terms of use, privacy policies, and other provisions of the individual network operators also apply in each case.
7. To whom do we disclose your data?
Within the scope of our business activities and for the purposes specified in Section 5, we may also disclose your data to third parties, to the extent permitted and as it appears appropriate to us. This disclosure occurs either because these recipients process the data on our behalf (so-called data processors) or because they wish to use it for their own purposes. These include, in particular, the following categories of recipients:
- Service providers of ours (such as fiduciaries, printing companies, banks, potentially payment service providers, insurance companies, legal advisors, etc.), including data processors (such as IT and storage providers);
- Dealers, suppliers, subcontractors, and other business partners;
- Customers;
- Domestic and foreign authorities, official bodies, or courts;
- Media;
- The public, including visitors to websites and social media;
- Competitors, industry organizations, associations, organizations, and other bodies;
- Acquirers or parties interested in acquiring business units, companies, or other parts of the company;
- Other parties in potential or actual legal proceedings;
- Other affiliated companies of AFRISO AG, such as AFRISO-EURO-INDEX GmbH;
- We emphasize our membership in the global AFRISO Group with worldwide (production) locations.
In principle, these recipients are located in Switzerland and the European Economic Area (EEA), but they can also be located anywhere in the world. In particular, you must expect your data to be transferred to any countries where the service providers we use are located (such as Microsoft, Google).
If a recipient is located in a country without adequate statutory data protection, we contractually oblige the recipient to comply with the applicable data protection laws (for this purpose, we use the revised Standard Contractual Clauses of the European Commission, which are available here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?), unless the recipient is already subject to a legally recognized framework to ensure data protection or we can rely on an exemption. An exemption may apply, in particular, to legal proceedings abroad, but also in cases of overriding public interests, or if the performance of a contract requires such disclosure, if you have consented, or if the data has been made generally accessible by you and you have not objected to its processing.
8. How long do we retain your data?
Your personal data is processed and stored by us for as long as it is necessary for the fulfillment of our contractual and legal obligations or otherwise for the purposes pursued with the processing (e.g., for as long as there is an interest in our newsletter and you have not unsubscribed). For example, we process your personal data for the duration of the entire business relationship (from the initiation, execution, to the termination of a contract) as well as beyond that in accordance with statutory retention and documentation obligations. In this context, it is possible that personal data will be retained for the period during which claims can be asserted against our company and insofar as we are otherwise legally obliged to do so or legitimate business interests require this (e.g., for evidentiary and documentation purposes). As soon as your personal data is no longer required for the above-mentioned purposes, it will in principle and as far as possible be deleted or anonymized. For operational data (e.g., system logs, logs), generally shorter retention periods of twelve months or less apply.
9. How do we protect your data?
We take appropriate technical and organizational measures to protect your personal data. This applies, in particular, to protection against unauthorized access and misuse, such as the issuance of directives, training, IT and network security solutions, access controls and restrictions, encryption of data carriers and transmissions, pseudonymisation, and audits.
Despite these security precautions taken by us, the processing of personal data, especially when using the internet, is always associated with certain risks and security vulnerabilities – absolute data security can therefore not be guaranteed.
10. Why do you need to provide us with certain data?
Without certain personal data, it is generally not possible for us to enter into or manage the contractual relationship with you or the body or person you represent, and to fulfill our contractual or, in part, statutory obligations. Therefore, we rely on you providing us with certain personal data that is necessary for the initiation and execution of our contractual relationship and the fulfillment of the associated contractual obligations. Furthermore, the website cannot be used if certain information required to ensure data traffic (such as the IP address) is not disclosed.
11. Do we carry out profiling or do we make automated decisions?
We do not carry out profiling, nor do we engage in fully automated decision-making (such as regulated in Art. 22 GDPR).
12. What rights do you have in connection with your data?
Within the framework of the data protection law applicable to you and to the extent provided for therein (such as in the case of the GDPR), you have the right to access, rectification, erasure, the right to restriction of data processing, as well as the right to object to our data processing, in particular, processing for direct marketing purposes and other legitimate interests in processing, and the right to receive certain personal data for the purpose of transferring it to another entity.
Please note, however, that we reserve the right to assert the statutory restrictions on our part, for example if we are obliged to retain or process certain data, if we have an overriding interest therein (insofar as we are entitled to rely on it), or if we require the data for the assertion of claims.
If you incur costs as a result, we will inform you in advance. We have already informed you about the option to withdraw your consent in Section 5. Please note that the exercise of these rights may conflict with contractual arrangements and this may have consequences, such as premature termination of the contract or cost implications. In this case, we will inform you in advance, unless this is already contractually regulated.
If you wish to exercise these rights, we must identify you accordingly, for example by means of a copy of an identity document, unless your identity can be clearly verified otherwise.
To assert your rights, you can contact us at the address provided in Section 1.
In addition to asserting these rights directly with us, every data subject fundamentally has the right to enforce their claims through the courts or to lodge a complaint with the competent data protection authority. In Switzerland, the competent data protection authority is the Federal Data Protection and Information Commissioner (FDPIC): http://www.edoeb.admin.ch.
13. What else you should know …
We may adapt and supplement this privacy policy at any time without prior notice. The current version published on our website applies. Insofar as the privacy policy is part of an agreement with you, we will inform you of the change in the event of an update via e-mail or by other appropriate means, in particular, through publication on our website.