Terms and Conditions
PRIVACY POLICY
1. Controller and content of this privacy policy
We, GRISSMANN GmbH (Vogelsangstrasse 17, 8307 Illnau-Effretikon, Switzerland), are the operator of the website www.grissmanninterier.ch (hereinafter "website") and your contractual partner and, unless otherwise stated, are responsible for the data processing specified in this privacy policy.
Please take note of the following information so that you know what personal data we collect from you and for what purposes we use it. In terms of data protection, we are primarily guided by the legal requirements of Swiss data protection law, in particular the Federal Act on Data Protection ("FADP"), as well as the EU General Data Protection Regulation ("GDPR"), the provisions of which may be applicable in individual cases.
2. Contact person for data protection
If you have any questions about data protection or would like to exercise your rights, please contact our contact person for data protection by sending an email to the following address: info@grissmanninterier.ch
Alternatively, you can also write to us by post:
GRISSMANN GmbH
Data protection
Vogelsangstrasse 17
8307 Illnau-Effretikon
Switzerland
3. When you visit our website (log file data)
When you visit our website, the servers of our hosting provider Wix.com Ltd, Nemal St. 40, 6350671 Tel Aviv, Israel store every access in a log file for a maximum period of 12 months. The following data is recorded and stored by us until it is automatically deleted
the IP address of the requesting computer
the date and time of access
the name and URL of the retrieved file
the website from which the access was made, if applicable with the search term used
the operating system of your computer and the browser you are using (incl. type, version and language setting)
Device type in the case of access via mobile phones
the city or region from which the access was made and
the name of your internet access provider
This data is processed for the purpose of enabling the use of our website, ensuring system security and stability in the long term and analysing errors and performance. It also enables us to optimise our website.
In the event of an attack on the network infrastructure of the website or in the event of suspicion of other unauthorised or abusive website use, the IP address and other data are evaluated for clarification and defence purposes and, if necessary, used in the context of criminal proceedings for identification and for civil and criminal proceedings against the users concerned.
Our legitimate interest in data processing within the meaning of Art. 6 para. 1 lit. f GDPR lies in the purposes described above.
4. Use of one of our contact options
If you contact us via our contact addresses and channels (e.g. by e-mail, telephone or contact form), your personal data will be processed. The data that you have made available to us, e.g. your name or e-mail address and your enquiry, will be processed. In addition, the time of receipt of the enquiry is documented. Mandatory information is marked accordingly in contact forms (e.g. with an asterisk).
We process this data exclusively in order to answer your enquiry in the best possible way. The legal basis for this data processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in answering your enquiry or, if your enquiry is aimed at the conclusion or execution of a contract, the execution of the contract within the meaning of Art. 6 para. 1 lit. b GDPR.
5. Opening a customer account
If you open a customer account on our website, we collect the following data, whereby mandatory information is marked accordingly (e.g. with an asterisk):
Personal details:
Surname
First name
Login data
E-mail address
Password
We use the personal details to establish your identity and to check the requirements for registration. The e-mail address and password together serve as login data and thus ensure that the correct person is using the website under your details. We also need your e-mail address to verify and confirm the opening of your account and for future communication with you required for contract fulfilment. In addition, this data is stored in the customer account for future contract conclusions.
We also use the data to provide an overview of the bookings made and the existing subscriptions as well as a simple way to manage your personal data, to administer our website and the contractual relationships, i.e. to establish, organise the content of, process and amend the contracts concluded with you via your customer account.
The legal basis for the processing of your data for the aforementioned purpose is your consent in accordance with Art. 6 para. 1 lit. a GDPR. You can withdraw your consent at any time by removing the information from your customer account or deleting your customer account or having it deleted by notifying us.
To prevent misuse, we recommend that you always treat your login data confidentially and close the browser window when you have finished communicating with us.
6. Processing of bookings, subscriptions and other services
We carry out the services you request from us (e.g. bookings made and subscriptions purchased). We collect the following data, among others, to fulfil the order:
-
Contact details (such as company, surname, first name, e-mail)
-
Billing and, if applicable, delivery address
-
Telephone number
-
Customer
-
Other contract data
-
We use this data to fulfil your booking, subscription or order in the best possible way for the purpose of executing the contract, to administer the booking, subscription or order and for billing and delivery. We also need your e-mail address to confirm the booking, subscription or order and for future communication with you necessary for the fulfilment of the contract.
-
If this is necessary for the fulfilment of the contract, we will also pass on the required information to any third-party service providers (e.g. transport companies).
-
The legal basis for this processing is the fulfilment of the contract within the meaning of Art. 6 para. 1 lit. b GDPR.
7. Central data storage in the CRM system
If a clear assignment to your person is possible, we will store and link the data described in this privacy policy, i.e. in particular your personal details, your contacts, your contract data and your surfing behaviour on our website, in a central database. This serves the efficient management of customer data and allows us to respond to your requests appropriately and enables the efficient provision of the services you have requested and the processing of the associated contracts. The legal basis for this data processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in the efficient management of user data. We use the software of Wix.com Ltd, Nemal St. 40, 6350671 Tel Aviv, Israel and Google Analytics for this purpose. The legal basis for this processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in using the services of third-party providers.
We analyse this data in order to further develop our services in line with requirements. The legal basis for this data processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in the implementation of marketing measures.
8. Cookies
Cookies are information files that your web browser stores on the hard drive or memory of your end device when you visit our website. Cookies are assigned identification numbers that identify your browser and allow the information contained in the cookie to be read.
Among other things, cookies help to make your visit to our website easier, more pleasant and more meaningful. We use cookies for various purposes that are technically necessary for your desired use of the website. For example, cookies perform other technical functions necessary for the operation of the website, such as load balancing, i.e. the distribution of the performance load of the site to various web servers in order to reduce the load on the servers. Finally, we also use cookies as part of the design and programming of our website, e.g. to enable the uploading of scripts or codes.
The legal basis for this data processing is our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in providing a user-friendly and up-to-date website.
Most Internet browsers accept cookies automatically. However, when you access our website, we ask for your consent to the cookies we use that are not technically necessary, in particular when using third-party cookies for marketing purposes. You can make your desired settings using the corresponding buttons in the cookie banner. Details on the services and data processing associated with the individual cookies can be found in the following sections of this privacy policy.
You may also be able to configure your browser so that no cookies are stored on your computer or so that a message always appears when you receive a new cookie. On the following pages you will find explanations of how you can configure the processing of cookies in selected browsers.
Google Chrome
Apple Safari
If you deactivate cookies, you may not be able to use all the functions of our website.
9. Tracking and web analysis tools
9.1 General information on tracking
We use the web analysis services listed below for the purpose of designing and continuously optimising our website to meet your needs. In this context, pseudonymised user profiles are created and cookies are used. The information generated by the cookie about your use of this website is usually transmitted to a server of the service provider together with the log file data listed in section 3, where it is stored and processed. this may also involve transmission to servers abroad, e.g. in the USA.
By processing the data, we receive the following information, among other things:
-
Navigation path that a visitor takes on the site (incl. content viewed and products selected or purchased)
-
Time spent on the website or subpage
-
the subpage on which the website is left
-
the country, region or city from which access is made
-
end device (type, version, colour depth, resolution, width and height of the browser window) and
-
Returning or new visitor
-
The provider will use this information on our behalf to analyse the use of the website, to compile reports on website activity for us and to provide other services relating to website activity and internet usage for the purposes of market research and the needs-based design of these websites.
The legal basis for this processing with the following tools is your consent within the meaning of Art. 6 para. 1 lit. a GDPR. You can revoke your consent or refuse processing at any time by rejecting or switching off the relevant cookies in the settings of your web browser or by making use of the service-specific options described below.
For further processing of the data by the respective provider as the (sole) controller under data protection law, in particular any disclosure of this information to third parties such as authorities due to national legal regulations, please refer to the provider's data protection information.
9.2 Google Analytics
We use the web analytics service Google Analytics from Google Ireland Limited (Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland) or Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) ("Google").
The data described in section 9.1 about the use of the website may be transmitted to Google's servers in the USA for the processing purposes explained. The IP address is shortened by activating IP anonymisation (‘anonymizeIP’) on this website before transmission within Switzerland, member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.
Users can prevent Google from collecting the data generated by the cookie and relating to the use of the website by the user concerned (including the IP address) and from processing this data by Google by downloading and installing the browser plug-in .
Further information on data protection at Google can be found here.
9.3 Google Maps
We use Google Maps API (Application Programming Interface, "Google Maps") from Google on our website to visually display geographical information (site plans). By using Google Maps, information about the use of our website, including your IP address, is transmitted to a Google server in the USA and stored there.
It is possible to deactivate the Google Maps service and prevent the transfer of data to Google by deactivating JavaScript in your browser. However, we would like to point out that you will not be able to use the map display in this case.
You can find more information about the collection, processing and use of your data by Google and your rights in this regard in the privacy policy and in the additional terms of use for Google Maps and Google Earth.
9.4 Google reCaptcha
We use reCaptcha from Google on our website. The purpose of reCaptcha is to check whether the data input on our website (e.g. when logging in) is made by a human or by an automated programme. For this purpose, reCaptcha analyses the behaviour of the website visitor based on various characteristics. This analysis begins automatically as soon as the website visitor enters our website. To analyse this, reCaptcha evaluates various pieces of information (e.g. IP address, time spent on the website by the website visitor or mouse movements made). The data collected during the analysis is forwarded to Google.
The data is stored and analysed on the basis of our legitimate interest within the meaning of Art. 6 para. 1 lit. f GDPR in protecting our website from abusive automated spying and spam.
For more information about reCaptcha, please refer to the Google Privacy Policy and the Google Terms of Service.
9.5 Google Sign-In
On our website, you can log in to create a customer account or register using the ‘Google Sign-In’ social plugin from Google as part of the so-called single sign-on technology if you have a Google account. You can recognise Google's social plugins by a button with the Google logo and the words ‘Sign in with Google’.
By using this Google button on our website, you have the option of logging in or registering on our website using your Google user data. Only if you give your express consent in accordance with Art. 6 para. 1 lit. a GDPR before the registration process on the basis of a corresponding notice about the exchange of data with Google, we will receive the general and publicly accessible information stored in your profile when using the Google button from Google, depending on your personal data protection settings at Google. This information includes the user ID, name, profile picture, age and gender.
The data transmitted by Google will be stored and processed by us to create a user account with the necessary data, if you have authorised Google to do so (title, first name, surname, address data, country, email address, date of birth). Conversely, data (e.g. information about your surfing or purchasing behaviour) may be transferred from us to your Google profile on the basis of your consent.
You can revoke your consent at any time with effect for the future.
The purpose and scope of the data collection and the further processing and use of the data by Google as well as your rights in this regard and setting options to protect your privacy can be found in Google's data protection information.
If you do not want Google to associate the data collected via our website directly with your Google profile, you must log out of Google before visiting our website.
10. Unsere Social Media Präsenzen
On our website you will find links to our presence on the following social networks: LinkedIn Unlimited Company, Wilton Place, Dublin 2, Ireland. If you click on the social network icons, you will automatically be redirected to our profile on the respective network. This establishes a direct connection between your browser and the server of the respective social network. This informs the network that you visited our website using your IP address and clicked on the link. If you click on a link to a network while logged into your user account on the respective network, the content of our website can be linked to your profile, allowing the network to directly associate your visit to our website with your account. If you want to prevent this, you should log out before clicking on the corresponding links. A connection between your access to our website and your user account is always established when you log in to the respective network after clicking on the link. The respective provider is responsible for the associated data processing under data protection law. Please therefore refer to the information on the network’s website.
Rechtsgrundlage für eine gegebenenfalls uns zugerechnete Verarbeitung ist unser berechtigtes Interesse im Sinne von Art. 6 Abs. 1 lit. f DSGVO an der Nutzung und Bewerbung von unseren Social Media Präsenzen.
11. Transfer of data to third parties Without the support of other companies, we would not be able to provide our services in the desired form. In order to use the services of these companies, it is necessary to transfer your personal data to a certain extent. Such transfer will occur specifically to the extent necessary to fulfill the contract you have requested. The legal basis for this transfer is the fulfillment of the contract within the meaning of Art. 6 (1) (b) GDPR. Data will also be transferred to selected service providers and only to the extent necessary to provide the service. Various third-party service providers are already explicitly mentioned in this privacy policy. These include, for example, IT service providers (such as software solution providers), advertising agencies, and consulting firms. The legal basis for this data transfer is our legitimate interest in obtaining third-party services within the meaning of Art. 6 (1) (f) GDPR.
In addition, your data may be passed on, in particular to authorities, legal advisors, or debt collection agencies, if we are legally obliged to do so or if this is necessary to protect our rights, in particular to enforce claims arising from our relationship with you. Data may also be passed on if another company intends to acquire our company or parts of it, and such a transfer is necessary to conduct a due diligence review or to complete the transaction. We also transmit your data to companies affiliated with us (i.e., other companies in the group). The legal basis for this data transfer is our legitimate interest within the meaning of Art. 6 (1) (f) GDPR in safeguarding our rights and complying with our obligations or the sale of our company.
12. Transfer of Personal Data Abroad We are entitled to transfer your personal data to third parties abroad if this is necessary to carry out the data processing described in this Privacy Policy. In doing so, we will of course comply with the legal regulations regarding the disclosure of personal data to third parties. If the country in question does not have an adequate level of data protection, we guarantee through contractual arrangements that your data is adequately protected by these companies.
13. Retention Periods We only store personal data for as long as necessary to carry out the processing explained in this Privacy Policy within the scope of our legitimate interest. For contractual data, storage is required by statutory retention periods. Requirements that oblige us to retain data arise from accounting and tax law regulations. According to these regulations, business communications, concluded contracts, and accounting documents must be retained for up to 10 years. The data will be deleted or anonymized as soon as there is no longer a retention obligation and no legitimate interest in retaining it.
14. Data security
We use appropriate technical and organizational security measures to protect your personal data stored with us against loss and unlawful processing, particularly unauthorized access by third parties. Our employees and the service providers we engage are obligated to maintain confidentiality and protect data privacy. Furthermore, these individuals are only granted access to personal data to the extent necessary to perform their duties. Our security measures are continuously adapted in line with technological developments. However, the transmission of information via the Internet and electronic means of communication always involves certain security risks, and we cannot provide an absolute guarantee for the security of information transmitted in this way.
15. Your Rights
Provided the legal requirements are met, you, as a data subject, have the following rights: Right to information: You have the right to request access to your personal data stored by us at any time and free of charge. This gives you the opportunity to check which personal data we process about you and to ensure that we use it in accordance with applicable data protection regulations. Right to rectification: You have the right to have inaccurate or incomplete personal data rectified and to be informed of the rectification. In this case, we will inform the recipients of the data concerned of the adjustments made, unless this is impossible or involves disproportionate effort.
-
Right to erasure: You have the right to have your personal data erased under certain circumstances. In individual cases, particularly in cases of statutory retention periods, the right to erasure may be excluded. In this case, blocking of the data may take place instead of erasure under certain conditions. Right to restriction of processing: You have the right to request that the processing of your personal data be restricted. Right to data portability: You have the right to receive the personal data you have provided to us free of charge in a readable format. Right of objection: You can object to data processing at any time. Right of revocation: You generally have the right to revoke your consent at any time. However, revocation of your consent does not render processing activities based on your consent in the past unlawful.
-
Right to lodge a complaint: You have the right to lodge a complaint with a competent supervisory authority, e.g. against the way in which your personal data is processed.