Privacy policy
With this privacy policy we inform you about the processing of personal data in connection with our activities and operations including our website under the domain name
We have written this privacy policy in German. If it is published in another language, the German privacy policy remains the applicable one.
For individual or additional activities and operations, we may publish further privacy policies or other information on data protection.
We are subject to Swiss law and, where applicable, to foreign law such as in particular that of the European Union (EU) with the European Data Protection Regulation (GDPR).
The European Commission recognized with a decision of 26. July 2000 that Swiss data protection law ensures adequate data protection. With a report of 15. January 2024 the European Commission confirmed this adequacy decision.
Table of contents
- 1. Contact details
- 2. Terms and legal bases
- 3. Type, scope and purpose of the processing of personal data
- 4. Disclosure of personal data
- 5. Communication
- 6. Applications
- 7. Data security
- 8. Personal data outside the country
- 9. Rights of data subjects
- 10. Use of the website
- 11. Notifications and messages
- 12. Social Media
- 13. Services of third parties
- 14. Extensions for the website
- 15. Video surveillance
- 16. Final notes on the privacy policy
1. Contact details
The party responsible in the sense of data protection law is:
Synaedge AG
Badenerstrasse 808
8048 Zurich
Switzerland
In individual cases, third parties may be responsible for the processing of personal data or joint responsibility with third parties may exist. We will be happy to provide data subjects with information about the respective responsibility upon request.
Data protection representative in the European Economic Area (EEA)
We have the following data protection representative in accordance with Article. 27 GDPR:
Synaedge Deutschland GmbH
Bunsenstr. 5
D-51647 Gummersbach
The data protection representative serves data subjects and authorities in the European Union (EU) and the rest of the European Economic Area (EEA) as an additional point of contact for requests relating to the GDPR.
2. Terms and legal bases
2.1 Terms
Data subject: Natural person about whom we process personal data.
Personal data: Any information relating to a specific or identifiable natural person.
Personal data requiring special protection: Data about trade union, political, religious or philosophical beliefs and activities, data about health, the intimate sphere or membership of an ethnic group or race, genetic data, biometric data that uniquely identify a natural person, data about criminal and administrative-law sanctions or prosecutions, and data about measures of social assistance.
Processing: Any handling of personal data, regardless of the means and procedures used, for example retrieving, comparing, adjusting, archiving, storing, reading, disclosing, obtaining, collecting, recording, erasing, making available, structuring, organizing, storing, altering, distributing, linking, destroying and using personal data.
European Economic Area (EEA): Member states of the European Union (EU) as well as the Principality of Liechtenstein, Iceland and Norway.
2.2 Legal bases
We process personal data in accordance with Swiss law, in particular the Federal Act on Data Protection (Data Protection Act, DSG) and the Ordinance on Data Protection (Data Protection Ordinance, DSV).
We process – where and to the extent that the European Data Protection Regulation (GDPR) is applicable – personal data in accordance with at least one of the following legal bases:
- Article. 6(1)(b) GDPR for the processing of personal data required to fulfil a contract with the data subject and to carry out pre-contractual measures.
- Article. 6(1)(f) GDPR for the processing of personal data required to safeguard legitimate interests – including those of third parties – provided that the fundamental freedoms and rights and interests of the data subject do not override. Such interests include, in particular, the permanent, people-friendly, secure and reliable performance of our activities and operations, ensuring information security, protection against misuse, asserting our own legal claims and compliance with Swiss law.
- Article. 6(1)(c) GDPR for the processing of personal data required to fulfil a legal obligation to which we are subject under any applicable law of Member States in the European Economic Area (EEA).
- Article. 6(1)(e) GDPR for the processing of personal data required to perform a task carried out in the public interest.
- Article. 6(1)(a) GDPR for the processing of personal data with consent of the data subject.
- Article. 6(1)(d) GDPR for the processing of personal data required to protect vital interests of the data subject or another natural person.
- Article. 9(2) ff. GDPR for processing special categories of personal data, in particular with consent of the data subjects.
The European Data Protection Regulation (GDPR) refers to the processing of personal data as processing of personal data and the processing of special categories of personal data as processing of special categories of personal data (Article 9 GDPR).
3. Type, scope and purpose of the processing of personal data
We process those personal data that are required in order to be able to carry out our activities and operations permanently, people-friendly, securely and reliably. The processed personal data may in particular fall into the categories of browser and device data, content data, communication data, metadata, usage data, master data including inventory and contact data, location data, transaction data, contract data and payment data. Furthermore, the personal data may represent special categories of personal data requiring special protection.
We also process personal data that we obtain from third parties, source from publicly accessible sources or collect when carrying out our activities and operations, insofar as such processing is permitted.
We process personal data to the extent required with consent of the data subject. In many cases, we can process personal data without consent, for example in order to fulfil legal obligations or to safeguard overriding interests. We can also request the data subject’s consent if their consent is not required.
We process personal data for the duration required for the respective purpose. We anonymize or delete personal data in particular depending on statutory retention periods and limitation periods.
4. Disclosure of personal data
We may disclose personal data to third parties, have them processed by third parties or process them together with third parties. Such third parties may include, for example, specialized providers whose services we use. Such third parties may in turn disclose personal data to other third parties.
In the context of our activities and operations, we may disclose personal data in particular to banks and other financial service providers, authorities, educational and research institutions, consultants and lawyers, accounting and fiduciary service providers, debt collection companies, interest representatives, IT service providers, cooperation partners, credit and financial information agencies, logistics and shipping companies, marketing and advertising agencies, media, parent, sister and subsidiary companies, organizations and associations, social institutions, telecommunications companies, insurers and payment service providers.
5. Communication
We process personal data in order to communicate with individual persons as well as with authorities, organizations and companies. In doing so, we in particular process data that a data subject provides to us when making contact, for example by postal mail or email. We may store such data in an address book or with comparable aids.
Third parties who transmit data to us about other people are legally required to ensure data protection for these data subjects independently. In particular, they must ensure that they are allowed to transmit such data, but also that the transmitted data is accurate.
We use selected services from suitable providers in order to enable and improve communication with individual persons and other communication partners. With such services, we can also manage the data of the data subjects beyond direct communication and process them otherwise, for example in connection with orders, services, projects and resource planning.
6. Applications
We process personal data about applicants to the extent that it is required to assess suitability for an employment relationship or for the later performance of an employment contract. The required personal data result in particular from the information requested, for example as part of a job advertisement. We may publish job advertisements with the help of suitable third parties, for example in electronic and printed media or at job portals and job platforms.
We also process those personal data that applicants voluntarily provide or publish, in particular as part of cover letters, CVs and other application documents as well as as part of online profiles.
We process – where and to the extent the GDPR is applicable – personal data about applicants in particular in accordance with Article. 9(2)(b) GDPR.
7. Data security
We take appropriate technical and organizational measures to ensure data security appropriate to the respective risk. With our measures, we in particular ensure the confidentiality, availability, traceability and integrity of the processed personal data, without being able to guarantee absolute data security.
Access to our website and our other digital presence is carried out using transport encryption (SSL / TLS, in particular with the Hypertext Transfer Protocol Secure, abbreviated as HTTPS). Most browsers warn against visiting a website without transport encryption.
Our digital communications are subject – like in principle any digital communication – to mass surveillance without cause or suspicion by security authorities in Switzerland, the rest of Europe, the United States of America (USA) and other countries. We have no direct influence over the corresponding processing of personal data by intelligence services, police authorities and other security authorities. We also cannot rule out that a data subject is specifically monitored.
8. Personal data outside the country
We process personal data in principle in Switzerland and the European Economic Area (EEA). However, we may also export or transfer personal data to other states, in particular in order to process them there or have them processed.
We can export personal data to all countries on Earth and elsewhere in the Universe if the law there ensures adequate data protection according to a decision of the Swiss Federal Council and – where and to the extent the GDPR is applicable – also according to a decision of the European Commission.
We may transfer personal data to states whose law does not ensure adequate data protection if data protection is ensured for other reasons, in particular on the basis of standard data protection clauses or with other suitable safeguards. As an exception, we may export personal data to states without adequate or suitable data protection if the special data protection legal requirements are met, for example the explicit consent of the data subjects or a direct connection with the conclusion or performance of a contract. Upon request, we will be happy to provide data subjects with information about possible safeguards or provide a copy of possible safeguards.
9. Rights of data subjects
9.1 Claims under data protection law
We grant data subjects all claims under the applicable law. In particular, data subjects have the following rights:
- Information: Data subjects may request information as to whether we process personal data about them and, if so, what personal data it concerns. Data subjects are also provided with the information required in order to assert their claims under data protection law and to ensure transparency. This includes the processed personal data as such, but among other things also information on the processing purpose, the retention period, any disclosure and/or any export of data to other states and the origin of the personal data.
- Correction and restriction: Data subjects may request that inaccurate personal data be corrected, that incomplete data be completed and that processing of their data be restricted.
- Option for one’s own position and human review: Where decisions are based exclusively on automated processing of personal data and have legal effects for them or significantly affect them (automated individual decisions), data subjects may present their own position and request review by a human being.
- Deletion and objection: Data subjects may have personal data deleted (“right to be forgotten”) and may object to the processing of their data with effect for the future.
- Data portability and transfer of data: Data subjects may request the provision of their personal data or the transfer of their data to another controller.
We may postpone, restrict or refuse the exercise of the rights of data subjects within the legally permissible scope. We may inform data subjects of any requirements that must be met in order to exercise their data protection rights. For example, we may refuse information in whole or in part by referring to confidentiality obligations, overriding interests or the protection of other persons. For example, we may also refuse deletion of personal data, in particular by referring to statutory retention obligations, in whole or in part.
We may, exceptionally, provide costs for the exercise of the rights as applicable. We inform data subjects in advance about any costs.
We are obliged to identify data subjects who request information or assert other rights by means of appropriate measures. Data subjects are required to cooperate.
9.2 Legal remedies
Data subjects have the right to enforce their claims under data protection law by legal action or to file a complaint or report with a data protection supervisory authority.
The data protection supervisory authority for private controllers and federal bodies in Switzerland is the Federal Commissioner for Data Protection and Freedom of Information (FCDP).
European data protection supervisory authorities are organized as members in the European Data Protection Board (EDPB). In some Member States in the European Economic Area (EEA) the data protection supervisory authorities are structured federally, in particular in Germany.
10. Use of the website
10.1 Cookies
We may use cookies. With cookies – both our own cookies (first-party cookies) and cookies from third parties whose services we use (third-party cookies) – these are data stored in the browser. Such stored data does not have to be limited to traditional cookies in text form.
Cookies may be stored in the browser temporarily as “session cookies” or for a specific period as so-called persistent cookies. “Session cookies” are automatically deleted when the browser is closed. Persistent cookies have a specific retention period. Cookies enable, in particular, a browser to be recognized again during your next visit to our website and thereby for example to measure the reach of our website. However, persistent cookies can also be used for online marketing.
Cookies can be disabled, limited or deleted completely or partially at any time in the browser settings. Browser settings often also enable automated deletion and other management of cookies. Without cookies, our website may no longer be available in full scope. We request – at least insofar as and to the extent required under the applicable law – the explicit consent to the use of cookies.
For cookies used for success and reach measurement or for advertising, for many services a general objection (“opt-out”) is possible via the AdChoices (Digital Advertising Alliance of Canada), the Network Advertising Initiative (NAI), YourAdChoices (Digital Advertising Alliance)or Your Online Choices (European Interactive Digital Advertising Alliance, EDAA).
10.2 Logging
For each access to our website and our other digital presence we may at least log the following information, insofar as it is collected or transmitted to our digital infrastructure as standard in such accesses: date and time including time zone, IP address, access status (HTTP status code), operating system including user interface and version, browser including language and version, the individual subpage of our website accessed including transferred data volume, the webpage last accessed in the same browser window (referer or referrer).
We log such information, which may also constitute personal data, in log files. The information is required in order for us to provide our digital presence permanently, people-friendly and reliably. The information is also required to be able to ensure data security – including by third parties or with the help of third parties.
10.3 Counting pixels
We may embed counting pixels into our digital presence. Counting pixels are also referred to as web beacons. With counting pixels – including those from third parties whose services we use – these are typically small, not visible images or scripts written in JavaScript that are automatically retrieved when accessing our digital presence. With counting pixels, at least the same information as with logging in log files can be collected.
11. Notifications and messages
11.1 Success and reach measurement
Notifications and messages may contain web links or counting pixels that record whether an individual message was opened and which web links were clicked. Such web links and counting pixels can also record the use of notifications and messages in a person-related manner. We need this statistical recording of usage for success and reach measurement in order to be able to send notifications and messages effectively and people-friendly as well as permanently, securely and reliably according to the needs and reading habits of the recipients.
11.2 Consent and objection
You must in principle consent to the use of your email address and your other contact details, unless the use is permitted for other legal reasons. For obtaining any double-confirmed consent, we can use the “double opt-in” process. In this case, you will receive a message with instructions for double confirmation. We can log obtained consents including IP address and timestamp for evidentiary and security reasons.
You can in principle object at any time to receiving notifications and messages such as newsletters. With such an objection, you can simultaneously object to the statistical recording of usage for success and reach measurement. Notifications and messages required in connection with our activities and operations remain reserved.
12. Social Media
We are present on social media platforms and other online platforms in order to communicate with interested persons and to inform them about our activities and operations. In connection with such platforms, personal data may also be processed outside Switzerland and the European Economic Area (EEA).
The respective General Terms and Conditions (AGB) and terms of use as well as privacy policies and other provisions of the respective operators of such platforms apply in each case. These provisions inform in particular about the rights of data subjects directly vis-à-vis the respective platform, which includes, for example, the right to information.
13. Services of third parties
We use services from specialized third parties in order to be able to carry out our activities and operations permanently, people-friendly, securely and reliably. With such services, we can embed functions and content into our website, among other things. In the event of such embedding, the services used, for technically necessary reasons, collect at least temporarily the IP addresses of users.
For necessary security-related, statistical and technical purposes, third parties whose services we use may process data in connection with our activities and operations in an aggregated, anonymized or pseudonymized manner. These are for example performance or usage data in order to be able to offer the respective service.
In particular, we use:
- Google services: Providers: Google LLC (USA) / Google Ireland Limited (Ireland) partly for users in the European Economic Area (EEA) and in Switzerland; General information on data protection: “Handling data protection”, privacy policy, “How Google uses personal data”, “Google is committed to complying with the applicable data protection laws”, “Data protection guide for Google products”, “How we use data from websites or apps where our services are used”, Cookie Policy, “Advertising you can influence” (settings for personalized advertising).
- Microsoft services: Providers: Microsoft Ireland Operations Limited (Ireland) for users in the European Economic Area (EEA), in Switzerland and in the United Kingdom / Microsoft Corporation (USA) for users in the rest of the world; General information on data protection: “Data protection at Microsoft”, “Data protection and privacy”, privacy policy, “Data and data protection settings”.
13.1 Digital infrastructure
We use services from specialized third parties in order to be able to access the required digital infrastructure in connection with our activities and operations. This includes, for example, hosting and storage services from selected providers.
In particular, we use:
- WordPress.com: Website builder; Providers: Automattic Inc. (USA) / Aut O’Mattic A8C Ireland Ltd. (Ireland) for users in particular in Europe; Information on data protection: privacy policy, Cookie Policy.
13.2 Online collaboration
We use services of third parties to enable online collaboration. In addition to this privacy policy, any conditions directly visible for the services used also apply, such as terms of use or privacy policies.
In particular, we use:
- Microsoft Teams: Platform for productive collaboration, in particular with audio and video conferences; Provider: Microsoft; Teams-specific information: “Security and compliance in Microsoft Teams”, in particular “data protection”.
13.3 Advertising
We use the option to have targeted advertising by third parties such as social media platforms and search engines displayed for our activities and operations.
With such advertising, we aim in particular to reach people who are already interested in our activities and operations or might become interested (remarketing and targeting). For this purpose, we may transmit relevant – possibly also person-related information to third parties that enable such advertising. We can also determine whether our advertising is successful, that is in particular whether it leads to visits to our website (conversion tracking).
Third parties where we advertise and where you are logged in as a user may possibly associate the use of our website with your profile there.
In particular, we use:
- Google Ads: Search engine advertising; Provider: Google; Google Ads-specific information: advertising among other things based on search queries, whereby various domain names – in particular doubleclick.net, googleadservices.com and googlesyndication.com – are used for Google Ads, Privacy policy for advertising, “Manage embedded ads directly through ad settings”.
- LinkedIn Ads: Social media advertising; Providers: LinkedIn Corporation (USA) / LinkedIn Ireland Unlimited Company (Ireland); Data protection information: Remarketing and targeting in particular with the LinkedIn Insight Tag, “Data protection”, privacy policy, Cookie Policy, Objection to personalized advertising.
- Meta advertising (Meta Ads): Social media advertising on Facebook and Instagram; Providers: Meta Platforms Ireland Limited (Ireland) and other Meta companies (among other things in the USA); Data protection information: targeting, also retargeting, in particular with the Meta Pixel and with Custom Audiences, including Lookalike Audiences, privacy policy, “Advertising preferences” (registration as a user required).
14. Extensions for the website
We use extensions for our website in order to use additional functions. We may use selected services from suitable providers or use such extensions on our own digital infrastructure.
In particular, we use:
- Google reCAPTCHA: Bot protection (distinguishing between desired human activities and undesired bot activities); Provider: Google; Google reCAPTCHA-specific information: “What is reCAPTCHA?”.
15. Video surveillance
We use video surveillance for the prevention of criminal offences, to secure evidence in the event of criminal offences, to exercise and enforce our own legal claims, to defend against others’ legal claims and to exercise our right of ownership of the premises. In doing so – where and to the extent that the GDPR is applicable – this concerns overriding legitimate interests in accordance with Article. 6(1)(f) GDPR, and for personal data requiring special protection with reference to Article. 9(2)(f) GDPR.
We in principle store no recordings from our video surveillance. We may exceptionally store recordings if necessary for the limited period if the storage is required for evidence securing or another specified purpose.
We may secure recordings from our video surveillance and transmit them to competent authorities such as in particular courts or criminal prosecution authorities, provided that the transmission is required for a specified purpose, in our other overriding legitimate interest or due to statutory obligations.
16. Final notes on the privacy policy
We created this privacy policy with the Data Protection Generator by Data Protection Partner .
We can update this privacy policy at any time. We will inform you about updates by publishing the respective current privacy policy on our website.

