Data protection provisions
Principle and scope of application
This data protection information relates to the processing of personal data in connection with visits to the websites at espressa.ch. In order to use our websites and the associated online services or online applications (collectively referred to as services), we process your personal data (hereinafter also referred to as 'data'). Please note that this data protection information does not apply to websites of other providers to which our website may be linked.
Personal data refers to information that relates to an identified or identifiable natural person. Certain categories of particularly sensitive personal data, such as health data, are specially protected by specific legal provisions. The term processing covers all processes in connection with your data, including collection, storage, utilisation, forwarding, archiving or deletion. When processing data, we comply with the Federal Act on Data Protection (FADP), the corresponding Implementing Ordinance (DPO) and other applicable data protection laws (e.g. the European General Data Protection Regulation, GDPR), insofar as these are applicable.
In the following, we would like to explain what data we collect, for what purpose we use it and what rights you have in relation to your data. If you provide us with data about third parties, we assume that you are authorised to do so and that the data provided is correct. We therefore ask you to inform the third parties concerned about the processing of their data by us and to provide them with a copy of this data protection information or the relevant product information. If we draw your attention to an updated version of these documents, please also pass on these new versions.
Our employees are regularly trained in data protection issues and are subject to a duty of confidentiality. In addition, compliance with data protection regulations is monitored by our data protection department.
Responsible offices and contact
The controller responsible for the data processing described in this privacy policy is:
Espressa GmbH
Birchwiesstrasse 4
8114 Dänikon
For questions and concerns regarding the processing of your data and your data protection rights vis-à-vis us, please contact:
Espressa GmbH
Data Protection Office
Birchwiesstrasse 4
8114 Dänikon
Processed data
We attach great importance to the protection of your personal data. When you use our website and services, we primarily process the data that you provide to us and the information that we collect directly (see below).
When you use our website and services, we collect metadata such as information about your browser (type and version), your device type (e.g. smartphone or tablet) and your IP address. We also collect access data, also known as log data. This includes the name of the website accessed, the date and time of access, the amount of data transferred, notification of successful access, information on the operating system and details of the last website visited.
We only store and process further personal data if you provide it to us when using services and tools (e.g. contact form). Further information relevant to data protection for specific tools can be found further down in this privacy policy if applicable.
Purpose
We process your data exclusively for the purposes that we communicated to you when collecting your data and for other purposes compatible with these purposes. Further information about the basis of our data processing can be found below in this privacy policy.
Processing of the data
We process your data for various purposes in connection with communication with you. In particular, this includes responding to enquiries, asserting your rights and contacting you in the event of queries. We primarily use communication data and master data, as well as registration data in relation to offers and services used by you. This data may be stored for documentation purposes, training, quality assurance and enquiries.
We also process data for marketing purposes and to maintain the customer relationship. We may send general or personalised information about our offer to our users, for example in the form of irregular contacts by e-mail, post or telephone, as well as via other channels for which we have contact information from you. You have the option at any time to decline such contacts or to refuse or revoke your consent to be contacted for advertising purposes. With your consent, we can tailor our online offering more specifically to the needs of our users.
We may also use your data for market research, to improve our online offering, our services and, if necessary, for product development.
Finally, we may also store and process your data for security reasons and to control access to our website.
Log files
We mainly use data to create server log files in order to carry out statistical evaluations for the operation of the website, to ensure the security of the IT systems and to optimise the website. We primarily use log data for this purpose. The legal basis for this data processing is our legitimate interest in offering you a secure and smooth user experience at all times. We also reserve the right to check the log data retrospectively if there are concrete indications of unlawful use.
Contact form
If you contact us via the contact form, we collect your contact details in order to process your enquiry and answer any follow-up questions. This data is transmitted in encrypted form.
If you have provided us with your email address or contacted us directly by email, we may also send you information by email relating to the processing of your enquiry and questions.
The legal basis for processing your data is based on our legitimate interest in being able to process your online enquiry efficiently and effectively. If the aim of the email contact is to conclude a contract, the data processing is based on the initiation of this contractual relationship.
Newsletter
On our websites, you have the option of subscribing to our newsletter to receive regular information about us and our offers and services. If you subscribe to the newsletter, your contact details from the input form will be transmitted to us. By subscribing to the newsletter, you give us your consent and at the same time take note of our data protection information.
The legal basis for processing your data is based on our legitimate interest in actively providing you with up-to-date information about us based on the interest you have expressed by registering. You can revoke your consent to receive the newsletter at any time with effect for the future. To do so, you can simply click on the corresponding link at the end of each newsletter sent to you.
Double opt-in
In order to guarantee the security of your data, we use the double opt-in procedure. This means that after you subscribe to the newsletter, we will send you an email to the email address you have provided with a confirmation link. The address will only be released for the newsletter distribution list after you click on this link. Subscription to the newsletter therefore requires your consent.
Marketing
Your data may be used by us to inform you occasionally about news, new products, services or other services of interest to you from us and possibly our partners.
If you do not wish to consent to the use of your data for marketing purposes, you can inform us accordingly or refuse or revoke your consent to receive marketing information.
Cookie preferences
We provide you with the option of adapting the use of cookies on our website to your needs or revoking your consent to the use of cookies via the Cookie Preference Centre. In addition, most browsers allow you to be warned/informed when cookies are set or to prohibit cookies completely. If you would like to receive a complete and up-to-date overview of all third-party access to your browser, specific browser plug-ins provide you with this function.
Our website or other online publications from us may include third-party content, such as maps from Google Maps, fonts from Google Fonts or videos from Vimeo. As a result, your IP address will be communicated to these providers. Certain external services may only be activated after your explicit confirmation.
This external content is integrated by us in order to provide you with useful information or functions or to optimise your user experience. We do not process any further data. Our legitimate interest in offering you this content or functions is therefore the legal basis for this data processing.
We endeavour to integrate only those external providers where your IP address is used exclusively to deliver the content. However, we have no influence on the possible storage and processing of your IP address by the third-party providers. For this reason, we refer you to the privacy policy of the relevant service for data processing by the respective third-party provider. You can find further information on individual setting options relating to your privacy here.
Google Fonts
We may use Google Fonts on our website to display selected fonts, icons and symbols on our website. This is a service provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
Further information on Google Fonts can be found at the following link: developers.google.com/fonts/faq/privacy?hl=en
User accounts
We can create user accounts for users on our website.
Google Analytics
We may use Google Analytics and Google Tag Manager on our website. This is a web analysis service and a supporting tool provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
Google Analytics uses cookies to analyse your use of our website. The usage data generated by the service is transmitted by default to servers in a Google data centre and stored there. It is possible that additional personal data may be collected via Google Analytics and Google Tag Manager and that this data may be passed on to third parties by Google if this is required by law or if third parties process the data on behalf of Google. We ourselves do not pass on any personal data to Google without your consent.
The legal basis for the processing of your data is based on our legitimate interest in analysing user behaviour to optimise our website. Further information on Google Analytics and Google Tag Manager can be found at the following link: support.google.com/tagmanager/?hl=en#topic=3441530
IP anonymisation
Your IP address is anonymised by default on our website before it is transmitted to Google. This is done by only transmitting your address in truncated form. In exceptional cases, your address may be transmitted in full and only shortened in Google's data centre.
Google Ads conversion tracking
We may use Google Ads in conjunction with Google Conversion Tracking on our website. This service is provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), a subsidiary of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). If you access our website via a Google advert, Google Ads places a cookie on your device. If you visit certain pages of our website, Google and we use the cookie to recognise that you have clicked on the ad and have been redirected to the corresponding page. Each Google Ads customer receives their own cookie, but this is not used for personal identification.
The information collected by the conversion cookie is used to generate conversion statistics for Google Ads customers and to analyse your surfing behaviour for marketing purposes. This allows us to customise our advertising offers to your interests. However, no personal information is transmitted with which you can be directly identified.
The legal basis for the processing of your data is based on our legitimate interest in better tailoring our advertising offers to our users. Further information on conversion tracking and general details on Google Ads and the Google Marketing Platform can be found at the following links:
- support.google.com/google-ads/answer/6095821?hl=en
- ads.google.com/home/
- marketingplatform.google.com/about/
Google Remarketing
We can integrate remarketing services from Google on our website. These services are provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), a subsidiary of Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
Google Remarketing uses cookies to present you with interest-based adverts when you visit our website as part of the Google advertising network. This allows you to be shown adverts on other websites that are also connected to the Google advertising network that are related to content that you have previously viewed on our website. If you do not wish to use Google's remarketing function, you can deactivate it by making the appropriate settings in Google. We do not pass on any personal data to Google without your consent.
The legal basis for the processing of your data is based on our legitimate interest in better tailoring our advertising offers to our users. Further information on Google Remarketing can be found at the following link: support.google.com/google-ads/answer/2453998?hl=en
Hotjar
We may use features of the web analytics service of Hotjar Ltd (Level 2, St Julian's Business Centre, 3, Elia Zammit Street, St Julian's STJ 1000, Malta) on our website to gain a better understanding of your needs and to optimise the offer and customer experience on this website.
By using Hotjar technology, we gain insights into your experiences (e.g. usage time of certain content or attractiveness).
In order to generate data on the use of our website, Hotjar uses cookies and other data points (anonymised IP address, screen size and resolution, browser details, geographical position, etc.). Hotjar then generates and stores an anonymised user profile. If you do not want the data described to be collected and transferred to Hotjar, you can prevent this by using a browser plugin. You can find the corresponding plugin under the following link: hotjar.com/en/legal/policies/do-not-track/
The legal basis for processing your data is based on our legitimate interest in analysing user behaviour to optimise our offering. Further information about Hotjar can be found at the following link hotjar.com/privacy
Social media plugins
We can integrate services from various social media on our website, which are usually recognisable by the corresponding company or network logos.
When you use these services, your IP address is communicated to their providers. The providers may be able to link your data to your social media user account via the IP address if you are logged in at the time. It is also possible that your IP address will be stored by the providers even if you are logged out or do not have a corresponding social media account.
The legal basis for the processing of your data is based on our legitimate interest in providing you with attractive tools in connection with social media on our website.
Facebook Pixel
We may use the Facebook Pixel and Facebook Retargeting from Facebook Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland), a subsidiary of Facebook Inc. (1 Hacker Way, Menlo Park, CA 94025, USA) on our website.
The Facebook Pixel stores a tracking cookie in the user's browser, which allows us to track your behaviour during your visit to our website. In addition, interest-based adverts (Facebook retargeting) can be displayed and user profiles (profiling) can be created. If you have a Facebook account and do not want the data described to be collected and transferred to Facebook, you can deactivate this function by clicking on the following link: facebook.com/ads/preferences/?entry_product=ad_settings_screen
The legal basis for processing your data is based on our legitimate interest in analysing user behaviour to optimise our offering and, if necessary, to better tailor our advertising offers to our users. Further information on Facebook Pixel can be found at the following link facebook.com/about/privacy/.
Your rights
You have the following rights in accordance with the applicable data protection law in accordance with the applicable data protection regulations and under certain conditions:
Right of access: You can request information from us as to whether we process your personal data and, if so, what data this is.
Right to rectification: You can request that we correct incorrect data or complete incomplete data.
Right to erasure: You can request the erasure of your data. Please note, however, that certain legal provisions or legitimate interests may restrict our obligation to erase.
Right to data portability: Under certain conditions, you can request that we provide you with the data you have provided to us in a structured, commonly used and machine-readable format.
Right to withdraw consent: If the data processing is based on your consent, you can withdraw this consent at any time. Please note that the withdrawal does not affect the lawfulness of the data processing carried out before the withdrawal.
Right to object: Under certain circumstances, you have the right to object to the processing of your data, in particular for the purposes of direct marketing or legitimate interests.
Right to lodge a complaint: If you do not agree with our handling of your data, you have the right to contact our data protection officer or the competent data protection supervisory authority at edoeb.admin.ch.
Please note that these rights are subject to legal requirements and that exceptions and restrictions may apply. To exercise your rights, you can contact us in writing or by email at the address below.
Espressa GmbH
Data Protection Office
Birchwiesstrasse 4
8114 Dänikon
SSL
Due to the technical structure of the Internet as an open network, secure transmission of your data cannot be guaranteed in all cases. If you send your personal data to us, you always do so at your own risk.
In order to ensure the protection of your transmitted data, we use encryption mechanisms in accordance with the current security standards (Transport Layer Security, TLS). TLS is a protocol for secure data transmission on the internet and is supported by most browsers. It uses the public key method, in which data is encrypted with a publicly accessible key and can only be decrypted again with a specific private key. Most browsers use a key symbol or padlock to indicate whether a connection is secure.
We take various technical and organisational security precautions to ensure the protection of your data within our system. Nevertheless, we would like to point out that despite these measures, there is a risk of data loss, unauthorised access to or manipulation of data by third parties. Please also note that certain network sections and your computer are outside our controllable security area. As a user, you are responsible for informing yourself about the necessary security precautions and taking the necessary measures within your sphere of influence. Any liability on our part for damage caused to you as a result of data loss or manipulation is excluded.
Storage of the data
We only store your data for as long as is necessary for the purposes stated by us or as long as we are legally or contractually obliged to do so. Data that is no longer required for the stated purposes will be deleted by us as part of our regular data maintenance or alternatively anonymised.
Update
This data protection information is not part of the contract and can be amended by us at any time. The version published here applies in each case.
Last updated on 11 March, 2024