Privacy Policy
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to simply as "data") that we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications, and within external online presences such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Last updated: March 16, 2026
Table of Contents
- Preamble
- Controller
- Overview of Processing
- Applicable Legal Bases
- Security Measures
- Transfer of Personal Data
- International Data Transfers
- General Information on Data Storage and Deletion
- Rights of Data Subjects
- Provision of the Online Offering and Web Hosting
- Use of Cookies
- Contact and Inquiry Management
- Changes and Updates
- Definitions
Controller
.rotermund communication gmbh
Alte Landstrasse 22
8803 Rüschlikon, Switzerland
Email address: com@rotermund.com
Legal notice: rotermund.com/imprint
Overview of Processing
The following overview summarizes the types of data processed and the purposes of their processing and refers to the affected persons.
Types of data processed
- Contact data.
- Content data.
- Usage data.
- Meta, communication, and procedural data.
- Log data.
Categories of data subjects
- Communication partners.
- Users.
Purposes of processing
- Communication.
- Security measures.
- Organizational and administrative procedures.
- Feedback.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
Applicable Legal Bases
Applicable legal bases under the Swiss Data Protection Act: If you are located in Switzerland, we process your data based on the Swiss Federal Act on Data Protection (Swiss DPA). Unlike, for example, the GDPR, the Swiss DPA generally does not require that a legal basis be named for the processing of personal data, provided that the processing is carried out in good faith, is lawful, and is proportionate (Art. 6 para. 1 and 2 Swiss DPA). In addition, personal data is only collected by us for a specific purpose recognizable to the data subject and processed only in a manner compatible with that purpose (Art. 6 para. 3 Swiss DPA).
Security Measures
We take appropriate technical and organizational measures in accordance with legal requirements, considering the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.
These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as access, input, disclosure, safeguarding availability, and separation of data. Furthermore, we have established procedures that ensure the exercise of data subject rights, deletion of data, and responses to data threats. We also consider the protection of personal data during the development or selection of hardware, software, and processes according to the principle of data protection through technology design and privacy-friendly default settings.
Securing online connections through TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the Internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), thereby protecting the data from unauthorized access. TLS, the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. If a website is secured by an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL.
Transfer of Personal Data
As part of our processing of personal data, it may occur that this data is transmitted to or disclosed to other entities, companies, legally independent organizational units, or individuals. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content integrated into a website. In such cases, we comply with legal requirements and conclude appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.
International Data Transfers
Disclosure of personal data abroad: In accordance with the Swiss DPA, we only disclose personal data abroad if adequate protection of the data subjects is ensured (Art. 16 Swiss DPA). If the Swiss Federal Council has not determined that adequate protection exists (list: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we take alternative security measures.
For data transfers to the United States, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework through an adequacy decision by Switzerland on September 15, 2024. Additionally, we have concluded standard contractual clauses with the respective providers that were approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC) and establish contractual obligations to protect your data.
This dual safeguard ensures comprehensive protection of your data: the DPF forms the primary protection layer, while the standard contractual clauses serve as additional security. Should changes occur within the framework of the DPF, the standard contractual clauses act as a reliable fallback option.
For individual service providers, we inform you whether they are certified under the DPF and whether standard contractual clauses exist. The list of certified companies and further information about the DPF can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/.
For data transfers to other third countries, appropriate safeguards apply, including international agreements, specific guarantees, standard contractual clauses approved by the FDPIC, or internal data protection regulations previously recognized by the FDPIC or another competent data protection authority.
General Information on Data Storage and Deletion
We delete personal data that we process in accordance with legal requirements as soon as the underlying consents are withdrawn or no further legal bases for the processing exist. This applies to cases where the original processing purpose no longer applies or the data is no longer required. Exceptions to this rule exist if legal obligations or special interests require longer storage or archiving of the data.
In particular, data that must be retained for commercial or tax law reasons or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons must be archived accordingly.
Our privacy notices contain additional information on the retention and deletion of data that apply specifically to certain processing operations.
If several retention periods or deletion deadlines are specified for a date, the longest period always applies. Data that is no longer required for the originally intended purpose but must be retained due to legal requirements or other reasons will only be processed for the reasons justifying its retention.
Retention and deletion of data: The following general periods apply under Swiss law:
- 10 years – Retention period for books and records, annual financial statements, inventories, management reports, opening balances, accounting documents and invoices, as well as all necessary work instructions and other organizational documents (Art. 958f Swiss Code of Obligations).
- 10 years – Data required to consider potential claims for damages or similar contractual claims and rights as well as related inquiries are stored for the statutory limitation period of ten years unless a shorter period of five years applies in certain cases (Art. 127, 130 Swiss Code of Obligations).
Rights of Data Subjects
As a data subject, you have the following rights under the Swiss DPA:
- Right to information: You have the right to request confirmation as to whether personal data concerning you is being processed and to receive the information necessary to assert your rights under this law.
- Right to data delivery or transfer: You have the right to request that the personal data you have provided to us be delivered in a commonly used electronic format.
- Right to rectification: You have the right to request the correction of inaccurate personal data concerning you.
- Right to objection, deletion, and destruction: You have the right to object to the processing of your data and request that personal data concerning you be deleted or destroyed.
Provision of the Online Offering and Web Hosting
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.
- Processed data types: Usage data, meta and communication data, log data.
- Data subjects: Users (e.g. website visitors).
- Purpose: Provision of our online offering and IT infrastructure.
- Legal basis: Legitimate interests.
Use of Cookies
The term “cookies” refers to functions that store information on users’ devices and read information from them. Cookies may also be used for various purposes, such as functionality, security, and convenience of online services as well as for analyzing visitor flows.
We use cookies in accordance with legal regulations. Where necessary, we obtain users’ consent in advance. If consent is not required, we rely on our legitimate interests.
Types of cookies:
- Temporary cookies (session cookies): These are deleted at the latest when a user leaves an online service and closes their device.
- Permanent cookies: These remain stored even after the device is closed. They may be used to store login status or preferred content.
Contact and Inquiry Management
When contacting us (e.g. by post, contact form, email, telephone or via social media) the information provided by the inquiring persons is processed insofar as this is necessary to respond to the contact requests and any requested measures.
- Processed data types: Contact data, content data, meta and communication data.
- Data subjects: Communication partners.
- Purpose: Communication and administrative processes.
- Legal basis: Legitimate interests and contract fulfillment.
Changes and Updates
Please inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes in the data processing carried out by us make this necessary. We will inform you as soon as changes require your participation (e.g. consent) or other individual notification.
Definitions
This section provides an overview of the terminology used in this privacy policy.
- Content data: Data generated during the creation, editing, and publication of content.
- Contact data: Information that enables communication such as phone numbers, postal addresses, and email addresses.
- Meta, communication, and procedural data: Data describing how information is processed, transmitted, and managed.
- Usage data: Information about how users interact with digital services.
- Personal data: Any information relating to an identified or identifiable natural person.
- Log data: Information about events recorded in a system or network.
- Controller: The natural or legal person who determines the purposes and means of processing personal data.
- Processing: Any operation performed on personal data such as collection, storage, use, or deletion.
Created with the free Privacy Policy Generator by Dr. Thomas Schwenke