Privacy policy

IMPORTANT NOTE: The German version of this document is the authoritative version governing our relationship. This translation is provided for convenience only and does not alter the German version in any way

In this Privacy Policy, we, smacer ag (referred to as “we” or “us” hereafter), describe how we collect and process personal data. This document is not exhaustive; specific matters may be governed by other terms, conditions, or similar documents. Personal data is defined as any information that pertains to an identified or identifiable individual.

If you provide us with personal data about other individuals (e.g., family members, work colleagues), please ensure that these individuals are aware of this Privacy Policy and that you are authorized to share their personal data with us, ensuring its accuracy.

This Privacy Policy is intended to comply with the EU General Data Protection Regulation (GDPR), the Swiss Data Protection Act (DPA), and the revised Swiss Data Protection Act (revDPA). However, the applicability of these laws depends on the specific circumstances.

1. Responsible Person / Data Protection Officer / Representative

The person responsible for the data processing activities described herein, as well as the representative in the EEA under Article 27 GDPR, is:

Joel Gischig
Staldenbachstrasse 30
8808 Pfäffikon SZ, Switzerland
info@smacer.com

For any data protection concerns, please contact us at the address provided above.

2. Collection and Processing of Personal Data

We primarily process the personal data that we receive from our customers and business partners during our business relationships with them, as well as from other individuals involved in these interactions, or that we collect from their users while operating our websites, apps, and other applications.

Where permitted, we may also obtain certain data from publicly available sources (e.g., debt registers, land registries, commercial registers, media, Internet) or receive such data from other companies within our group, from authorities, or from third parties (such as credit agencies, address providers). Besides the data you provide directly to us, the categories of personal data we receive from third parties about you may include, among other things, information from public registers, details gathered during official and legal proceedings, information related to your professional roles and activities (to facilitate the conclusion and processing of transactions with your employer through your assistance), information about you from correspondence and meetings with third parties, creditworthiness details (in cases where we transact with you directly), data provided by individuals close to you (such as family members, advisors, legal representatives) so we can conclude or process contracts involving you (e.g., references, delivery addresses, powers of attorney, information related to compliance with legal requirements like anti-money laundering and export restrictions), data from banks, insurance companies, vendors, and other contractual partners concerning services you use or provide (e.g., payments made, purchases completed), as well as information about you from the media and the Internet (where relevant, such as in the context of job applications, press reviews, marketing, or sales activities), and your addresses, interests, and other sociodemographic data (for marketing purposes), as well as data linked to website usage (e.g., IP address, MAC address of smartphones or computers, device and settings information, cookies, date and time of visit, pages viewed, functions used, referring websites, location data).

3. Purposes of Data Processing and Legal Basis

The primary purpose of collecting personal data is to enable us to conclude and execute contracts with our customers and business partners, particularly in the context of M&A transactions, as well as to manage the purchase of products and services from our suppliers and subcontractors, and to meet our legal obligations both domestically and internationally. If you work for one of these customers or business partners, your personal data may also be processed in this context.

Additionally, we process personal data about you and others, as allowed and as deemed appropriate, for the following purposes, where we (and occasionally third parties) have a legitimate interest consistent with the intended purpose:

  1. Offering and enhancing our services, products, websites, apps, and other platforms;
  2. Communicating with third parties and handling their inquiries (e.g., job applications, media queries);
  3. Reviewing and optimizing procedures for needs analysis to facilitate direct customer engagement, as well as gathering personal data from publicly accessible sources for customer acquisition purposes;
  4. Advertising and marketing activities (including organizing events), unless you have opted out (existing customers may opt out of marketing communications at any time, and we will place you on a no-contact list for future mailings);
  5. Conducting market and opinion research, as well as media monitoring;
  6. Asserting legal claims and defending against legal disputes and administrative proceedings;
  7. Preventing and investigating crimes and other misconduct (e.g., conducting internal investigations, data analysis for fraud prevention);
  8. Ensuring the security and functionality of our operations, particularly IT systems, websites, apps, and other platforms.

If you have provided consent for us to process your personal data for specific purposes (e.g., subscribing to newsletters or undergoing background checks), we will process your data within the scope of that consent, provided no other legal basis applies. Consent can be revoked at any time, although this will not affect any processing that has already occurred.

4. Cookies / Tracking and Other Technologies Related to the Use of Our Website

We do not use “cookies” or similar technologies on our websites to identify your browser or device.

However, some of our newsletters and marketing emails may include visible and invisible image elements, where permitted, that allow us to determine whether and when you have opened an email by retrieving these images from our servers. This helps us measure and better understand how you engage with our offers, allowing us to tailor them accordingly. You can block this feature in your email program; most are preset to do so. By using our websites and consenting to receive newsletters and marketing emails, you agree to the use of these techniques. If you do not wish for this to occur, please adjust your browser or email program settings accordingly.

5. Data Disclosure and International Transfer

In the course of our business activities and for the purposes outlined in section 3, we may share data with third parties as permitted and deemed appropriate, either because they process the data on our behalf or because they wish to use it for their own purposes. This includes the following entities:

  1. Service providers within our group and externally, such as banks, insurance companies, and order processors (e.g., IT providers);
  2. Dealers, suppliers, subcontractors, and other business partners;
  3. Customers;
  4. Domestic and foreign authorities, official agencies or courts;
  5. Media;
  6. The public, including visitors to websites and social media platforms;
  7. Competitors, industry organizations, associations, and other bodies;
  8. Potential acquirers or parties interested in acquiring business units, companies, or other parts of the group;
  9. Other parties in potential or ongoing legal proceedings;
  10. Other companies within the group.

All of the above together are called recipients.

These recipients may be located domestically or abroad. You should particularly expect your data to be transferred to all countries where the group has operations through group companies, branches, or other offices, as well as to other countries in Europe and the USA, where some of our service providers are based (such as Microsoft, HubSpot, etc.).

If a recipient is based in a country without adequate legal data protection, we require them to contractually comply with applicable data protection laws (using the European Commission’s revised standard contractual clauses, available here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj), unless they are already subject to a recognized framework ensuring data protection, or if we can rely on an exemption. An exemption might apply, for example, in the case of foreign legal proceedings or if overriding public interests are at stake, or if such disclosure is necessary to fulfill a contract, you have consented to it, or if it concerns data that you have made publicly available and have not objected to its processing.

6. Duration of the Retention of Personal Data

We process and retain your personal data as long as necessary to fulfill our contractual and legal obligations or to achieve the purposes for which the data was collected, such as the duration of the entire business relationship (from initiation through processing to termination of a contract) and beyond, in accordance with legal retention and documentation requirements. This may include retaining personal data for the period during which claims can be made against our company and where we are otherwise legally obligated or where legitimate business interests require it (e.g., for evidence and documentation purposes). Once your personal data is no longer needed for these purposes, it will be deleted or anonymized as a matter of principle, and where possible. For operational data (e.g., system logs), shorter retention periods of twelve months or less typically apply.

7. Data Security

We implement appropriate technical and organizational security measures to protect your personal data from unauthorized access and misuse, including issuing instructions, providing training, implementing IT and network security solutions, enforcing access controls and restrictions, encrypting data carriers and transmissions, using pseudonymization, and conducting regular controls.

8. Obligation to Provide Personal Data

As part of our business relationship, you are required to provide the personal data necessary to establish and conduct the business relationship and fulfill the associated contractual obligations (although there is generally no legal obligation to provide data to us). Without this data, we will generally be unable to conclude or process a contract with you (or the entity or person you represent). Additionally, the website cannot be used without providing certain information necessary for the traffic (e.g., IP address).

9. Profiling and Automated Decision Making

We partially process your personal data automatically with the goal of evaluating certain personal aspects (profiling). For example, we may use profiling in the following scenarios:

  • Fulfilling legal and regulatory obligations related to anti-money laundering and fraud prevention;
  • Assessing certain personal aspects (such as income and financial circumstances, personal interests) to determine creditworthiness, provide personalized offers and advice, and offer targeted products and services;
  • Processing data to determine your potential interest in our products and services. We also use methods that enable us to identify potential fraud cases or security risks by analyzing usage behavior data.

Additionally, we will notify you if and when we use automated decision-making in specific cases and provide further information if required by law.

10. Rights of the Data Subject

Under the applicable data protection laws and as provided therein (e.g., under GDPR), you have the right to request information, correction, deletion, or restriction of data processing, as well as the right to object to our processing of your data and to request the transfer of certain personal data to another entity (so-called data portability). Please note, however, that we reserve the right to enforce the legal restrictions applicable to us, such as when we are required to retain or process certain data, have an overriding interest in doing so (where we are allowed to invoke it), or need it to assert claims. We will inform you in advance of any costs that may arise from your requests.

We have already informed you of your right to revoke consent in Section 3. Please be aware that exercising these rights may conflict with contractual agreements, potentially resulting in consequences such as premature termination of the contract or financial implications. We will inform you of any such consequences in advance if they are not already contractually regulated.

Furthermore, each data subject has the right to assert their claims in court or lodge a complaint with the competent data protection authority. In Switzerland, the data protection authority is the Federal Data Protection and Information Commissioner (http://www.edoeb.admin.ch).

 

11. Changes

We may modify this Privacy Policy at any time without notice. The current version published on our website applies.

If the Privacy Policy is part of an agreement with you, we will notify you of any changes by email or other appropriate means in the event of an update.