Zum Inhalt springen

Privacy Policy

1. Controller

The party responsible for data processing within the meaning of the Swiss Federal Act on Data Protection (FADP) is:
RaissigDeSiena GmbH
Flüelastrasse 23A
8047 Zurich
Switzerland
Email: mail@raissigdesiena.ch

2. Scope and processing principles

This Privacy Policy applies to the processing of personal data in connection with visits to our website and the provision of our services (brand strategy and brand positioning, brand design, brand guidance and enablement, brand experience and brand communication, and consulting). We process personal data in accordance with the principles of good faith, lawfulness, proportionality, purpose limitation, accuracy and data security.

3. Collection and processing of personal data

We process personal data that you provide to us when contacting us by email or telephone, or in the course of a collaboration on mandates and projects. This includes in particular first name, last name, email address, telephone number, company name and the content of your enquiry. Our website does not contain a contact form; personal data is not collected through input forms. Providing this data is voluntary. Without this information, we may be unable to provide certain services.

4. Purpose of data processing

We process your personal data exclusively for the following purposes:

  • Processing enquiries and contact requests
  • Carrying out and handling mandates, projects and contracts
  • Operation, maintenance and security of this website
  • Fulfilment of legal obligations
  • Improvement of our website and our services

5. Website operation and automatically collected data (server log files)

This website is operated on our own server in Switzerland. When you visit our website, our servers automatically collect what are known as log files. This includes in particular IP address, date and time of access, pages or resources accessed, amount of data transferred, browser type and version, operating system used and referrer URL. This data is used for technical operation, system security and the detection and prevention of attacks. We do not assign this data to specific individuals. Log files are deleted no later than after 6 months unless they are required for longer to investigate a specific security incident.

Our website does not embed any third-party services. The fonts used are served from our own server; no external font service is called. No analytics or tracking services, external scripts, maps, video players or social media elements are embedded. Simply visiting our website therefore transmits no data to third parties.

6. Cookies

This website uses Matomo for audience measurement, hosted on our own infrastructure in Switzerland; no data is shared with third parties. Without your consent, measurement runs without cookies. On your first visit a banner asks for your choice: «Only necessary» sets no cookies, «Accept» allows Matomo cookies to recognise returning visits. Your choice is stored locally in your browser and can be reset at any time by clearing the site data. In the protected editorial area a technically necessary session cookie is set after login; it serves the login only.

7. Disclosure to third parties and processors

We do not disclose your personal data to third parties except where this is necessary for the fulfilment of a contract, where we are legally obliged to do so, or where you have given us your express consent.

Where we engage service providers who process personal data on our behalf and according to our instructions (processors within the meaning of Art. 9 FADP), we have data processing agreements in place with them. These ensure that the processors process the data only as we ourselves would be permitted to, that they guarantee an appropriate level of data security, that they are bound by confidentiality and that they process personal data exclusively on our instructions and within the contractually defined purposes. Transferring the processing to further processors (sub-processors) is permitted only with our prior consent; the corresponding obligations are passed on to the sub-processors by contract.

8. Data processing in the context of mandates and projects

In the course of our services, we process data provided to us by customers within a mandate or project. In relation to such customer data, we generally act as processor for our customers. Responsibility for the lawfulness of the processing of this data remains with the respective customer as controller; we process it exclusively on their instructions and to fulfil the respective mandate. The details of the processing on behalf (subject matter, duration, nature and purpose of the processing, categories of personal data, technical and organisational measures) are governed by the respective data processing agreement with the customer.

9. Confidentiality

All customer data obtained in the course of a collaboration is treated as strictly confidential and used exclusively to fulfil the respective mandate. Confidentiality is ensured through contractual obligations (non-disclosure agreements / NDAs) as well as through internal instructions and technical measures. The confidentiality obligation continues beyond the end of the contractual relationship.

10. Disclosure of personal data abroad

Your data is generally processed in Switzerland and hosted on servers in Switzerland. Where personal data is disclosed to recipients or processors abroad, this is done only if the state concerned provides an adequate level of data protection within the meaning of the list of countries maintained by the Federal Council, or where suitable safeguards otherwise exist (in particular standard contractual clauses, a recognised adequacy mechanism such as the Swiss-US Data Privacy Framework, or another legally permissible basis). On request, we will name the recipient state and the safeguard relevant to the data transfer.

11. Data security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or alteration. These include in particular encrypted transmission (TLS), access controls, logging as well as regular security updates and backups. Our security measures are continuously adapted to the state of the art. In the event of a breach of data security that results in a high risk to the persons concerned, we inform the Federal Data Protection and Information Commissioner (FDPIC) and, where applicable, the persons concerned in accordance with Art. 24 FADP.

12. Retention period

We retain personal data only for as long as is necessary for the respective purpose or as required by statutory retention obligations (as a rule 10 years for contract-related and business-related data). Thereafter, the data is deleted or anonymised.

13. Your rights

Within the scope of applicable data protection law, you have the right at any time:

  • to information about the personal data we process
  • to rectification of inaccurate data
  • to deletion of your data, insofar as no statutory retention obligations prevent this
  • to disclosure or transfer of your data in a common electronic format (data portability)
  • to object to data processing and to withdraw consent you have given

To exercise your rights and for questions about data protection, you can reach us at: mail@raissigdesiena.ch. To process your request, we may require proof of identity.

14. Competent supervisory authority

Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland, www.edoeb.admin.ch

15. Changes

We reserve the right to amend this Privacy Policy at any time. The version published on the website at the time applies.

RDS – Privacy Policy