DATA PROTECTION
Data protection declaration of Infusionen und Pflege GmbH
Infusionen und Pflege GmbH (hereinafter also "we", "us") collects and processes personal data that concerns you or other persons (so-called "third parties"). We use the term "data" here synonymously with "personal data" or "personally identifiable information".
This privacy policy is designed to meet the requirements of the EU General Data Protection Regulation ("GDPR"), the Swiss Data Protection Act ("DSG") and the revised Swiss Data Protection Act ("revDSG"). However, whether and to what extent these laws are applicable depends on the individual case.
Type of personal data
General personal data
We process general personal data about you.
Example: Your contact details to send you an invoice.
Financial data
We process your financial data.
Example: Your billing information and payment history for debt collection.
Source of personal data
Data provided
We process personal data that you provide to us.
Example: When you fill out a contact form or sign up for the newsletter.
Data collected
We process personal data that we collect about you.
Example: IP address when accessing the website.
Data received
We process personal data about you that we receive from third parties.
Example: From public registers such as the debt collection or commercial register.
Purpose of processing
marketing
We use your personal data for marketing and advertising.
Example: Sending a newsletter.
Product development
We use your personal data to develop and improve products and services.
Example: We evaluate data about click behavior on the website in order to improve user-friendliness.
Other purposes
We use your personal data for other purposes not related to the core service.
Example: For the creation of a contract.
Special processing
Profiling
We analyze your behavior and make assumptions about your interests and preferences.
Example: We assign your interests to a specific offer from us so that we can inform you about an update.
Disclosure to third parties
Data transfer
We share your personal information with other companies who can decide for themselves how to use the data.
Example: We hand over an unpaid invoice to a debt collection agency.
Place of processing
Switzerland
We only process your personal data in Switzerland.
Example: We use the services of a cloud provider from Switzerland.
Infusionen und Pflege GmbH, 8800 Thalwil, is responsible for the data processing described in this data protection declaration, unless otherwise communicated in individual cases.
You can contact us for your data protection concerns and to exercise your rights under section 11 as follows:
Infusions and Care GmbH
Personnel service provider Medical
In the Park 4
8800 Thalwil
We process different categories of data about you. The main categories are as follows:
- Technical data: When you use our website or other electronic services (e.g. free WiFi), we collect the IP address of your device and other technical data to ensure the functionality and security of these services. This data also includes logs that record the use of our systems. We generally store technical data for 12 months. To ensure the functionality of these services, we can also assign you or your device an individual code (e.g. in the form of a cookie, see section 12). The technical data itself does not allow any conclusions to be drawn about your identity. However, in the context of user accounts, registrations, access controls or the processing of contracts, it can be linked to other data categories (and thus possibly to you personally).
To the technical data includes, among other things, the IP address and information about the operating system of your device, the date, region and time of use, as well as the type of browser you use to access our electronic offerings. This can help us to provide the correct formatting of the website or, for example, to show you a website tailored to your region. Based on the IP address, we know which provider you use to access our offerings (and therefore also the region), but we cannot usually use this to determine who you are. This changes if, for example, you create a user account, because personal data can then be linked to technical data (we can see, for example, which browser you use to open an account on our website). Examples of technical data also include logs that are generated in our systems (e.g. the log of user logins on our website).
- Registration data: Certain offers, e.g. competitions and services (e.g. login areas of our website, newsletter dispatch, free WiFi access, etc.) can only be used with a user account or registration, which can be done directly with us or through our external login service providers. You must provide us with certain data and we collect data about the use of the offer or service. We generally retain registration data for 12 months after the end of use of the service or the cancellation of the user account.
To the Registration data includes the information you provide when you create an account on our website (e.g. user name, password, name, email). Registration data also includes the data we may require from you before you can use certain free services, such as our WiFi service, in this case: name, email and telephone number; or the redemption of vouchers, in this case: name, address, contact details, time of redemption. You must also register if you want to subscribe to our newsletter.
- Communication data: If you contact us via the contact form, by email, telephone, chat, letter or other means of communication, we record the data exchanged between you and us, including your contact details and the peripheral data of the communication. If we record or listen to telephone conversations or video conferences, e.g. for training and quality assurance purposes, we will draw your attention to this. Such recordings may only be made and used in accordance with our internal guidelines. You will be informed whether and when such recordings take place, e.g. by a display during the video conference in question. If you do not want a recording, please let us know or end your participation. If you simply do not want your image to be recorded, please switch off your camera. If we want or need to establish your identity, e.g. if you request information, apply for media access, etc., we collect data to identify you (e.g. a copy of an ID card). We generally keep this data for 12 months from the last exchange with you. This period may be longer if this is necessary for evidentiary reasons or to comply with legal or contractual requirements or for technical reasons. Emails in personal mailboxes and written correspondence are generally kept for at least 10 years.
Communication data are your name and contact details, the manner, place and time of communication and usually also its content (ie the content of emails, letters, chats, etc.). This data may also contain information about third parties. For identification purposes, we may also process your ID number or a password you have specified.
- Master data: We refer to master data as the basic data that we need in addition to the contract data (see below) for the processing of our contractual and other business relationships or for marketing and advertising purposes, such as name, contact details and information, e.g. about your role and function, your bank details, your date of birth, customer history, powers of attorney, signature authorizations and declarations of consent. We process your master data if you are a customer or other business contact or work for one (e.g. as a contact person for the business partner), or because we want to address you for our own purposes or the purposes of a contractual partner (e.g. in the context of marketing and advertising, with invitations to events, with vouchers, with newsletters, etc.). We receive master data from you yourself (e.g. when making a purchase or as part of a registration), from bodies for which you work, or from third parties such as our contractual partners, associations and address dealers and from publicly accessible sources such as public registers or the Internet (websites, social media, etc.). We can also process health data and information about third parties as part of master data. We can also collect master data from our shareholders and investors. We generally retain this data for 10 years from the last exchange with you, but at least from the end of the contract. This period may be longer if necessary for reasons of proof or to comply with legal or contractual requirements, or for technical reasons. For purely marketing and advertising contacts, the period is usually much shorter, usually no more than 2 years since the last contact.
To the Master data includes, for example, data such as name, address, email address, telephone number and other contact details, gender, date of birth, nationality, information about associated persons, websites, social media profiles, photos and videos, copies of ID cards; furthermore, information about your relationship with us (customer, supplier, visitor, service recipient, etc.), information about your status with us, allocations, classifications and distribution lists, information about our Interactions with you (possibly a history of it with corresponding entries), reports (e.g. from the media) or official documents (e.g. commercial register extracts, permits, etc.) that concern you. As Payment details For example, we collect your bank details, account number and credit card details. Consent or blocking notes are also part of the master data, as is information about third parties, e.g. contact persons, recipients of services, advertising recipients or representatives.
For contact persons and representatives of our Customers, suppliers and partners We process as master data e.g. name and address, information on role, function in the company, qualifications and, if applicable, information about superiors, employees and subordinates and information about interactions with these people.
Master data is not collected comprehensively for all contacts. Which data we collect in detail depends in particular on the purpose of processing.
- Contract data: This is data that arises in connection with the conclusion or processing of a contract, e.g. information about contracts and the services to be provided or provided, as well as data from the run-up to the conclusion of a contract, the information required or used for processing and information about reactions (e.g. complaints or information on satisfaction, etc.). This also includes health data and information about third parties, e.g. about hereditary diseases in the family. We usually collect this data from you, from contractual partners and from third parties involved in the processing of the contract, but also from third-party sources (e.g. providers of credit data) and from publicly accessible sources. We generally keep this data for 10 years from the last contractual activity, but at least from the end of the contract. This period may be longer if this is necessary for reasons of evidence or to comply with legal or contractual requirements, or for technical reasons.
To the Contract data include information about the Conclusion of contract, about your Contracts, e.g. type and date of conclusion of the contract, information from the application process (such as an application for our products or services) and information about the contract in question (e.g. its duration) and the processing and administration of the contracts (e.g. information related to invoicing, customer service, support with technical matters and the enforcement of contractual claims). Contract data also includes information about defects, complaints and adjustments to a contract, as well as information on customer satisfaction, which we can collect, for example, through surveys. Contract data also includes Financial data such as information about creditworthiness (i.e. information that allows conclusions to be drawn about the likelihood that claims will be settled), reminders and debt collection. We receive some of this data from you (e.g. when you make payments), but also from credit agencies and debt collection companies and from publicly accessible sources (e.g. a commercial register).
We will only provide you with certain services if you Registration data because we or our contractual partners want to know who is using our services or has accepted an invitation to an event, because it is technically necessary or because we want to communicate with you. If you or a person you represent (e.g. your employer) wants to conclude or fulfill a contract with us, we must Master, contract and communication data from you, and we process Technical data, if you want to use our website or other electronic services for this purpose. If you do not provide us with the data required to conclude and process the contract, you must expect that we will refuse to conclude the contract, that you will breach the contract or that we will not fulfil the contract. Likewise, we can only send you a response to a request from you if we have the relevant Communication data and – if you communicate with us online – possibly also Technical data The use of our website is also not possible without us Technical data receive.
We process your data for the purposes that we explain below. You can find further information for the online area in sections 12 and 13. These purposes or the objectives underlying them represent legitimate interests of ours and, where applicable, of third parties. You can find further information on the legal basis for our processing in section 5.
We process your data for purposes related to the Communication with you, in particular to answer inquiries and assert your rights (Section 11) and to contact you if you have any questions. For this purpose, we use communication data and master data in particular and, in connection with offers and services you use, also registration data. We store this data in order to document our communication with you, for training purposes, for quality assurance and for inquiries.
This concerns all purposes in connection with which you and we communicate, whether in customer service or advice, authentication in the event of use of the website or for training and quality assurance (e.g. in the area of customer service). We process communication data so that we can communicate with you by email and telephone, as well as messenger services, chat, social media, letter and fax. Communication with you usually takes place in connection with other processing purposes, e.g. so that we can provide services or respond to a request for information. Our data processing also serves to prove the communication and its content.
We process data for the recording, administration and processing of Contractual relationships.
We conclude contracts of various kinds with our business and private customers, with suppliers, subcontractors or other contractual partners such as partners in projects or with parties in legal disputes. In particular, we process master data, contract data and communication data and, depending on the circumstances, also registration data of the customer or the persons to whom the customer provides a service.
As part of the business initiation process, personal data - in particular master data, contract data and communication data - is collected from potential customers or other contractual partners (e.g. in an order form or contract) or results from communication. We also process data in connection with the conclusion of the contract to check creditworthiness and to open the customer relationship. In some cases, this information is checked to ensure compliance with legal requirements.
As part of the processing of contractual relationships, we process data to manage the customer relationship, to provide and demand contractual services (which also includes the involvement of third parties), for advice and for customer service. The enforcement of legal claims arising from contracts (debt collection, legal proceedings, etc.) is also part of the processing, as are bookkeeping, termination of contracts and public communication.
We process data for Marketing purposes and to Relationship maintenance, e.g. to send our customers services from us. This can be in the form of newsletters and other regular contacts (electronically, by post, by telephone), via other channels for which we have contact information from you, but also as part of individual marketing campaigns (e.g. events, competitions, etc.) and also include free services (e.g. invitations, vouchers, etc.). You can reject such contacts at any time (see the end of this section 4) or refuse or revoke your consent to be contacted for advertising purposes.
For example, with your consent, we will send you information and product offers from us in print, electronically or by telephone. To do this, we primarily process communication and registration data. Like most companies, we personalize communications so that we can send you individual information and make offers that meet your needs and interests. To do this, we link data that we process about you and determine preference data and use this data as the basis for personalization (see section 3).
Relationship management also includes addressing existing customers and their contacts - possibly personalized based on behavior and preference data. As part of relationship management, we can also operate a customer relationship management system ("CRM") in which we store the data required to maintain relationships with customers, suppliers and other business partners, e.g. about contact persons, relationship history (e.g. about products and services purchased or delivered, interactions, etc.), interests, wishes, marketing measures (newsletters, invitations to events, etc.) and other information.
All of these processes are important for us not only to promote our offers as effectively as possible, but also to make our relationships with customers more personal and positive, to focus on the most important relationships and to use our resources as efficiently as possible.
We will process your data for Market research, to Improving our services and operations and to Product development.
We strive to continually improve our products and services (including our website) and to be able to respond quickly to changing needs. We therefore analyse, for example, how you navigate through our website or which products are used by which groups of people in which way and how new products and services can be designed (for further details see section 12). This gives us information about the market acceptance of existing products and services and the market potential of new ones. To do this, we process master, behavioural and preference data in particular, but also communication data and information from customer surveys, polls and studies and other information, e.g. from the media, social media, the Internet and other public sources. Where possible, we use pseudonymised or anonymised information for these purposes. We may also use media monitoring services or carry out media monitoring ourselves and process personal data in order to carry out media work or to understand and respond to current developments and trends.
With your consent, we use non-anonymized location data to inform you about interesting offers and products nearby based on your location, to draw conclusions about your interests from the location data (length of stay) and to inform you which products and services other contractual partners with similar interests have used.
We may also use your data to Security purposes and for the Access control edit.
We continually check and improve the appropriate security of our IT and other infrastructure (e.g. buildings). Like all companies, we cannot completely rule out data security breaches, but we do our best to reduce the risks. We therefore process data for monitoring, checking, analyzing and testing our networks and IT infrastructures, for system and error testing, for documentation purposes and as part of backup copies. Access controls include, on the one hand, controlling access to electronic systems (e.g. logging into user accounts), but on the other hand also physical access control (e.g. building access).
We process personal data for Compliance with laws, instructions and recommendations from authorities and internal regulations («Compliance»).
This includes, for example, the implementation of health and safety concepts or the legally regulated fight against money laundering and terrorist financing. In certain cases, we may be obliged to carry out certain investigations about customers (“Know Your Customer”) or to report to authorities. The fulfilment of disclosure, information or reporting obligations, for example in connection with supervisory and tax law obligations, also requires or entails data processing, e.g. the fulfilment of archiving obligations and the prevention, detection and clarification of criminal offenses and other violations. This also includes the receipt and processing of complaints and other reports, the monitoring of communications, internal investigations or the disclosure of documents to an authority if we have sufficient reason to do so or are legally obliged to do so. Your personal data may also be processed in the event of external investigations, e.g. by a law enforcement or supervisory authority or a commissioned private body. For all of these purposes, we process in particular your master data, your contract data and communication data, but under certain circumstances also behavioral data and data from the category of other data. The legal obligations may be Swiss law, but also foreign regulations to which we are subject, as well as self-regulations, industry standards, our own corporate governance and official instructions and requests.
We also process data for the purposes of our Risk management and within the framework of a prudent Corporate management, including business organization and corporate development.
For these purposes, we process master data, contract data, registration data and technical data in particular, but also behavioral and communication data. For example, as part of our financial management, we must monitor our debtors and creditors, and we must avoid becoming victims of crimes and abuses, which may require the analysis of data for corresponding patterns. For these purposes and to protect you and us from criminal or abusive activities, we may also carry out profiling and create and edit profiles (see also section 6). As part of planning our resources and organizing our business, we must evaluate and process data on the use of our services and other offers or exchange information about them with others (e.g. outsourcing partners), which may also include your data. The same applies to services provided to us by third parties. As part of the company's development, we may sell businesses, business units or companies to or acquire them from others or enter into partnerships, which may also lead to the exchange and processing of data (including from you, e.g. as a customer or supplier or as a supplier representative).
We can use your data for further purposes process, e.g. as part of our internal procedures and administration.
To the extent that we ask you for your consent for certain processing consent ask, we will inform you separately about the purposes of the processing. You can revoke your consent at any time with effect for the future by sending us a written notification (by post) or, unless otherwise stated or agreed, by email; our contact details can be found in section 2. To revoke your consent for online tracking, see section 12. Where you have a user account, you can revoke your consent or contact us via the relevant website or other service. As soon as we have received notification of the revocation of your consent, we will no longer process your data for the purposes to which you originally consented, unless we have another legal basis for doing so. The revocation of your consent does not affect the legality of the processing carried out on the basis of the consent up to the time of revocation.
Where we do not ask for your consent to process your personal data, we base the processing of your personal data on the fact that the processing is necessary for the Initiation or execution of a contract with you (or the entity you represent) or that we or a third party legitimate interest in particular to pursue the purposes and associated objectives described above under section 4 and to be able to carry out corresponding measures. Our legitimate interests also include compliance with legal regulations, unless this is already recognized as a legal basis by the applicable data protection law (e.g. in the case of the GDPR, the law in the EEA and Switzerland).
In connection with our contracts, the website, our services and products, our legal obligations or otherwise to protect our legitimate interests and the other purposes listed in section 4, we also transmit your personal data to third parties, in particular to the following categories of recipients:
- Service providers: We work with service providers in Germany and abroad who process data about you on our behalf or under joint responsibility with us, or who receive data about you from us under their own responsibility. (e.g. IT providers, shipping companies, advertising service providers, login service providers, cleaning companies, security companies, banks, insurance companies, debt collection companies, credit agencies, or address checkers). This may also include health data.
- Contractual partners including customers: This primarily refers to our customers (e.g. service recipients) and other contractual partners, because this data transfer arises from these contracts. If you work for such a contractual partner, we can also transfer data about you to them in this context. This may also include health data. The recipients also include contractual partners with whom we cooperate.
- Authorities: We may pass on personal data to offices, courts and other authorities at home and abroad if we are legally obliged or authorized to do so or if this appears necessary to protect our interests. This may also include health data. The authorities process data about you that they receive from us under their own responsibility.
- Other people: This refers to other cases where the involvement of third parties arises from the purposes set out in section 4, e.g. service recipients, media and associations in which we participate or if they are part of one of our publications.
All of these categories of recipients can in turn involve third parties, so that your data can also be accessed by them. We can restrict processing by certain third parties (e.g. IT providers), but not that of other third parties (e.g. authorities, banks, etc.).
We reserve the right to disclose these data even if they secret data (unless we have expressly agreed with you that we will not pass this data on to certain third parties unless we are legally obliged to do so). Notwithstanding this, your data will continue to be subject to appropriate data protection even after disclosure in Switzerland and the rest of Europe. The provisions of Section 8 apply to disclosure in other countries. If you do not want certain data to be passed on, please let us know so that we can check whether and to what extent we can accommodate you (Section 2).
We also enable certain third parties, on our website and at events organized by us To collect personal data from you (e.g. media photographers, providers of tools that we have integrated into our website, etc.). Unless we are significantly involved in this data collection, these third parties are solely responsible for it. If you have any concerns or wish to assert your data protection rights, please contact these third parties directly. See section 12 for the website.
We process your data for as long as our processing purposes, the statutory retention periods and our legitimate interests in processing for documentation and evidence purposes require it, or if storage is technically necessary. Further information on the respective storage and processing periods can be found in the individual data categories in section 3 or in the cookie categories in section 12. If there are no legal or contractual obligations to the contrary, we will delete or anonymize your data after the storage or processing period has expired as part of our usual procedures.
Documentation and evidentiary purposes include our interest in documenting processes, interactions and other facts in the event of legal claims, disagreements, IT and infrastructure security purposes and proof of good corporate governance and compliance. Retention may be necessary for technical reasons if certain data cannot be separated from other data and we therefore have to store it with it (e.g. in the case of backups or document management systems).
We take appropriate security measures to protect the confidentiality, integrity and availability of your personal data, to protect it against unauthorized or unlawful processing and to counteract the risks of loss, accidental alteration, unwanted disclosure or unauthorized access.
Security measures of a technical and organizational nature may include measures such as the encryption and pseudonymization of data, logging, access restrictions, the storage of backup copies, instructions to our employees, confidentiality agreements and controls. We protect your data transmitted via our website during transport using suitable encryption mechanisms. However, we can only secure areas that we control. We also require our contract processors to take appropriate security measures. However, security risks cannot generally be completely ruled out; residual risks are unavoidable.
- The right to request information from us as to whether and which data we process about you;
- the right to have us correct data if it is inaccurate;
- the right to request the erasure of data;
- the right to request that we provide you with certain personal data in a common electronic format or to transmit them to another controller;
- the right to withdraw consent where our processing is based on your consent;
- the right to obtain, upon request, further information necessary to exercise these rights;
- Necessary cookies: Some cookies are necessary for the website to work as such or for certain functions to work. For example, they ensure that you can switch between pages without losing information entered in a form. They also ensure that you remain logged in. These cookies only exist temporarily ("session cookies"). If you block them, the website may not work. Other cookies are necessary so that the server can save decisions or entries you make beyond a session (i.e. a visit to the website) if you use this function (e.g. selected language, consent given, the function for automatic login, etc.). These cookies have an expiry date of up to 24 months.
- Performance cookies: In order to optimize our website and corresponding offers and to better tailor them to the needs of users, we use cookies to record and analyze the use of our website, possibly even beyond the session. We do this by using third-party analysis services. We have listed these below. Performance cookies also have an expiration date of up to 24 months. Please see the third-party websites for details.
- Page views
- First time visiting the website
- Start of session
- Your “click path”, interaction with the website
- Scrolls (whenever a user scrolls to the end of the page (90%))
- Clicks on external links
- internal search queries
- Interaction with videos
- File downloads
- Ads viewed / clicked
- Language setting
- Your approximate location (region)
- Your IP address (in abbreviated form)
- technical information about your browser and the devices you use (e.g. language settings, screen resolution)
- Your Internet provider
- the referrer URL (via which website/advertising medium you came to this website)
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (as processor according to Art. 28 GDPR)
- Google LLC, 1600 Amphitheater Parkway Mountain View, CA 94043, USA
- Alphabet Inc., 1600 Amphitheater Parkway Mountain View, CA 94043, USA
- Do not give your consent to the setting of the cookie or
- the browser add-on to deactivate Google Analytics HERE download and install.
We may operate pages and other online presences on social networks and other platforms operated by third parties ("fan pages", "channels", "profiles", etc.) and collect the data about you there as described in section 3 and below. We receive this data from you and the platforms when you come into contact with us via our online presence (e.g. when you communicate with us, comment on our content or visit our presence). At the same time, the platforms evaluate your use of our online presences and link this data with other data about you known to the platforms (e.g. about your behavior and preferences). They also process this data for their own purposes under their own responsibility, in particular for marketing and market research purposes (e.g. to personalize advertising) and to control their platforms (e.g. which content they show you).
We receive data about you when you communicate with us via online presences or view our content on the relevant platforms, visit our online presences or are active in them (e.g. publish content, make comments). These platforms also collect technical data, registration data, communication data, behavior and preference data from you or about you (for the terms, see section 3). These platforms regularly statistically evaluate the way in which you interact with us, how you use our online presences, our content or other parts of the platform (what you view, comment on, "like", share, etc.) and link this data with other information about you (e.g. information about age and gender and other demographic information). In this way, they also create profiles about you and statistics on the use of our online presences. They use this data and profiles to show you our or other advertising and other content on the platform in a personalized manner and to control the behavior of the platform, but also for market and user research and to provide us and other parties with information about you and the use of our online presence. We can partially control the evaluations that these platforms create regarding the use of our online presence.
We process this data for the purposes described in section 4, in particular for communication, for marketing purposes (including advertising on these platforms, see section 12) and for market research. You can find information on the relevant legal bases in section 5. We may further distribute content published by you (e.g. comments on an announcement) (e.g. in our advertising on the platform or elsewhere). We or the operators of the platforms may also delete or restrict content from or about you in accordance with the usage guidelines (e.g. inappropriate comments).
For further information on the processing carried out by the platform operators, please refer to the platform's data protection notices. There you will also find out in which countries they process your data, what information, deletion and other data subject rights you have and how you can exercise these or obtain further information.
For additional transparency, we use the privacy icons of the PRIVACY ICONS association.
Privacy Icons Terms
Last update: 14.09.2023