ONESTRA TREUHAND + BERATUNG

Onestra AG

Data Protection

Scroll

Data Protection

This text is a translation of the German text "Datenschutz" on this website. Please note that only the German text is legally binding. In case of doubt please refer to the German version.

 

1. General

This privacy policy explains how we, Onestra AG (hereinafter referred to as "we", "us" or the like) collect and process personal data within the context of the operation and use of our website.

Handling data in a responsible and legally compliant manner is important to us. We comply at all times with applicable law, in particular with Swiss data protection law and all applicable foreign data protection laws, such as the EU General Data Protection Regulation (EU GDPR), upon which this privacy policy is based.

 

If you act on behalf of a company, we may assume that you are authorized to act on behalf of the company in connection with the acceptance of this data protection declaration (prima facie power of attorney), irrespective of internal regulations or relationships of this company and commercial register entries and without further verification of authorization. Whenever we refer to "you", "your" or the like in this privacy Policy, this always refers to the company and the employees of the company on whose behalf you are acting.

 

2. Collection and processing of personal data

Personal data is any information that relates to an identified or identifiable person. A data subject is a person about whom personal data is processed. Processing includes any handling of personal data, in particular its collection, storage, retention, use, modification, disclosure and deletion.

 

We primarily process personal data that we receive from you or collect about you in connection with the operation and use of our website and associated applications. The submission of personal or business data on our website is voluntary.

 

In addition to the personal data that you provide to us directly (e.g., when creating or updating a user account, registering for a newsletter, or using a contact or feedback form), the categories of personal data that we receive about you from third parties include, in particular, information from public registers (e.g., debt enforcement registers or commercial registers);      creditworthiness information (if we conduct business with you); your interests and other socio-demographic data (for marketing purposes), if applicable; data in connection with the use of our website (e.g., IP address, MAC address, settings and other information of the device used, cookies, date and time of visit, web pages and content accessed, functions used, referring website, location information).

 

If you provide us with personal data of other persons (e.g., family members, work colleagues), you must ensure that these persons have consented to such provision and have taken note of the contents of this privacy policy.

 

3. Purpose of data processing and legal basis

We process personal data primarily for the following purposes:

- Administration of your user account

- Preparing and processing contracts for services or products that you order on our website

- Ensuring the operation of our website and related applications

- Responding to inquiries you send to us via contact and feedback forms on our website

- Fulfilling our legal obligations at home and abroad

In addition, we process personal data of you and other persons – to the extent legally permissible and deemed appropriate – also for the following purposes in which we have a legitimate interest corresponding to the purpose:

- Further development of our website and related applications, as well as our offers and services

- Marketing (e.g., sending newsletters), unless you have objected to this use of your personal data

- Assertion of legal claims and defense in connection with legal disputes and official proceedings.

 

We process personal data in accordance with Swiss data protection law and, if and to the extent applicable, with the EU GDPR. With reference to the EU GDPR, we process personal data with the consent of the data subject (Art. 6 para. 1 lit. a EU GDPR), for the performance of a contract with the data subject as well as for the implementation of corresponding precontractual measures (Art. 6 para. 1 lit. b EU GDPR), to fulfill a legal obligation to which we are subject under any applicable law of the EU or under any applicable law of a country in which the EU GDPR applies in whole or in part (Art. 6 para. 1 lit. c EU GDPR), as well as to protect the legitimate interests of us or of third parties, unless the fundamental freedoms and rights and interests of the data subject override these. Legitimate interests are, in particular, our business interest in being able to operate our website, information security, the enforcement of our own legal claims and compliance with Swiss law (Art. 6 para. 1 lit. f EU-GDPR).

 

Insofar as you have given us consent to process your personal data for certain purposes (e.g., when registering for a newsletter), we process your personal data within the scope of and based on this consent, insofar as we have no other legal basis and we require such a basis. Consent given can be revoked at any time, but this has no effect on data processing that has already taken place.

 

4. Duration of storage of personal data

We process your personal data for as long as is necessary for processing purposes or for the fulfillment of our contractual and legal obligations, as well as beyond that in accordance with legal retention and documentation obligations.

 

We may retain personal data for the period during which claims may be asserted against our company (i.e., in particular, during the statutory limitation period) and to the extent that we are otherwise required to do so by law, or legitimate business interests so require (e.g., for evidentiary and documentation purposes). As soon as your personal data is no longer required for the above-mentioned purposes, we will delete or anonymize it as a matter of principle and as far as possible. In case of longer-term retention obligations, we will restrict processing as far as possible.

 

5. Disclosure of personal data

Withing the scope of the purposes mentioned in section 3 and our business activities, we disclose your personal data to third parties, in particular to our service providers, suppliers and auxiliary persons (e.g., hosting providers, IT service providers, providers of newsletter services, debt collection service providers, banks, legal advisors/lawyers) as well as to authorities, official agencies or courts in Switzerland and abroad, to the extent that this is legally permissible and deemed appropriate.

 

If we transfer data to a country lacking adequate legal data protection, we ensure an adequate level of protection as provided by law by using appropriate contracts, or rely on the legal exceptions, in particular the exceptions of consent, contract execution and the establishment, exercise or enforcement of legal claims.

 

6. Services of third parties

6.1 Hosting

We host our website with Cyon in Basel, Switzerland. At Cyon, standard web server log files containing the following information are created for each access to this website: IP address, date and time including time zone, browser request including origin of the request (referer), operating system used including user interface and version, browser used including language and version, amount of data transferred. The log files are used to detect technical problems as well as to ensure security and for statistical analysis of the use of our website with the open source software AWStats, which is used by Cyon.

 

6.2 Other third party services

Google Analytics:

We use Google Analytics on our website. This service provided by Google LLC in Mountain View, USA ("Google") enables us to measure and evaluate the use of our website on a non-personal basis. The service uses permanent cookies that Google sets. Google does not receive any personal data from us (and does not retain any IP addresses), but it can track your use of the website, combine this information with data from other websites that you have visited and which are also tracked by Google, and use this knowledge for its own purposes (e.g., controlling advertising). Insofar as you have registered with Google yourself, Google also knows you. The processing of your personal data by Google is the responsibility of Google in accordance with their privacy policy. Google only informs us how our website is used, without providing any information about you personally. Google is committed to ensuring adequate data protection in accordance with the US-European and the US-Swiss Privacy Shield. For more information, please see Google's Privacy Policy.

 

Google Maps and Google Invisible reCAPTCHA:

We use Google Maps for embedding maps and Google Invisible reCAPTCHA for protection against bots and spam. These services of Google LLC in Mountain View, USA ("Google") use cookies, among other things, and data is transferred to Google in the USA, although we assume that no personal tracking takes place in this context solely through the use of our website. Google has undertaken to ensure adequate data protection in accordance with the U.S.-European Privacy Shield and the U.S.-Swiss Privacy Shield. For more information, please see Google's Privacy Policy.

 

7. Rights of the data subjects

Individuals about whom we process personal data have the right to request confirmation from us as to whether personal data is being processed by us and, if so, information about our processing of their personal data. Furthermore, data subjects may, if provided for under the data protection law applicable to them (in particular the EU GDPR), have the processing of their personal data restricted, exercise their right to data portability, have their personal data corrected, deleted ("right to be forgotten") or blocked, revoke consent given and object to the processing of their personal data.

 

The exercise of the aforementioned rights generally requires that you clearly prove your identity. For this purpose, please provide us with a copy of your ID if your identity is otherwise not clear or cannot be verified (e.g., by asserting your rights via the forms provided on our website after having logged in to your user account).

 

We reserve the right to enforce the restrictions provided for by law, for example if we are obliged to retain or process certain personal data, have an overriding interest in doing so (insofar as we are entitled to invoke this) or require it for the assertion of claims. If there are any costs for you, we will inform you in advance. Please note that the exercise of the aforementioned rights may conflict with contractual agreements between you and us (e.g., regarding the provision of services that you ordered via our website) and this may lead to consequences such as the early termination of the contract or costs. In such cases, we will inform you in advance.

 

In addition, persons about whom we process personal data have the right to enforce their claims in court and the right to lodge a complaint with a competent supervisory authority for data protection. The supervisory authority for data protection in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).

 

Data subjects and supervisory authorities can contact us by e-mail or by postal mail at the addresses provided in section 8.

 

8. Responsibility

Onestra AG is responsible for the data processing described in this privacy policy. If you have any data protection concerns, you can contact our data protection officer by e-mail or letter post (Art. 37 EU-GDPR) as follows:

 

Onestra AG

Rothusstrasse 23

Postfach

6331 Hünenberg

 

info@onestra.ch

 

9. Data security

We take appropriate technical and organizational security measures to protect your personal data from unauthorized access and misuse (e.g., encryption of data carriers and data transfers, access restrictions). Access to our website is via SSL/TLS encryption.

 

10. Change

We may amend this privacy policy at any time without prior notice. The current version published on this website shall apply.

We use cookies to provide you with an optimal user experience. Some cookies are necessary for the operation of the site, others are used for statistical purposes, comfort settings, or to display personalized content. You can decide for yourself which cookies you want to allow. Please note that due to your settings, not all functionalities of the site may be available. For more information, please see our Privacy Policy and Cookie Policy.
Show details