Data Policy
Privacy Policy
The responsible party within the meaning of the data protection laws, in particular the EU General Data Protection Regulation (GDPR), is:
ENTHUSIASTIC
APPROVAL, Heike Schmitz-Esser
Etzelstrasse 31
8038 Zürich
Schweiz
Email: heike@schmitz-esser.ch
Persons
Heike Schmitz-Esser
Dr. Valerio Schmitz-Esser
Company Name: ENTHUSIASTIC
APPROVAL, Heike Schmitz-Esser
Data protection officer:
Heike Schmitz-Esser
+ 41 79 206 38 50
heike@schmitz-esser.ch
General / Introduction
Based on Article 13 of the Swiss Federal Constitution and the data protection
provisions of the Swiss Confederation (Data Protection Act, DSG), every person
has the right to protection of their privacy as well as protection against
misuse of their personal data. The operators of these pages take the protection
of your personal data very seriously. We treat your personal data
confidentially and in accordance with the legal data protection regulations as
well as this privacy policy.
In cooperation with our hosting providers, we make every effort to protect the
databases as well as possible against unauthorized access, loss, misuse or
falsification.
We would like to point out that data transmission on the Internet (e.g.
communication by e-mail) can have security gaps. A complete protection of data
against access by third parties is not possible.
By using this website, you consent to the collection, processing and use of
data in accordance with the following description. This website can generally
be visited without registration. Data such as pages accessed or names of files
accessed, date and time are stored on the server for statistical purposes
without this data being directly related to your person. Personal data, in
particular name, address or e-mail address are collected as far as possible on
a voluntary basis. Without your consent, the data will not be passed on to
third parties.
Processing of personal data
Personal data is any information that relates to an identified or identifiable
person. A data subject is a person about whom personal data is processed.
Processing includes any handling of personal data, regardless of the means and
procedures used, in particular the storage, disclosure, acquisition, deletion,
storage, modification, destruction and use of personal data.
We process personal data in accordance with Swiss data protection law.
Furthermore, to the extent and insofar as the EU GDPR is applicable, we process
personal data in accordance with the following legal bases in connection with
Art. 6 (1) GDPR:
lit. a) Processing of personal data with the consent of the data subject.
lit. b) Processing of personal data for the fulfillment of a contract with the
data subject as well as for the implementation of corresponding pre-contractual
measures.
lit. c) Processing of personal data for the fulfillment of a legal obligation
to which we are subject under any applicable law of the EU or under any
applicable law of a country in which the GDPR is applicable in whole or in
part.
lit. d) Processing of personal data in order to protect the vital interests of
the data subject or another natural person.
lit. f) Processing of personal data to protect the legitimate interests of us
or of third parties, unless the fundamental freedoms and rights and interests
of the data subject are overridden. Legitimate interests include, in
particular, our business interest in being able to provide our website,
information security, the enforcement of our own legal claims and compliance
with Swiss law.
We process personal data for the duration required for the respective purpose
or purposes. In the case of longer-term retention obligations due to legal and
other obligations to which we are subject, we restrict processing accordingly.
Cookies
This website uses cookies. These are small text files that make it possible to
store specific information related to the user on the user's terminal device
while the user is using the website. Cookies make it possible, in particular,
to determine the frequency of use and number of users of the pages, to analyze
behavior patterns of page use, but also to make our offer more
customer-friendly. Cookies remain stored beyond the end of a browser session
and can be retrieved when you visit the site again. If you do not wish this to
happen, you should set your Internet browser so that it refuses to accept
cookies.
A general objection to the use of cookies used for online marketing purposes
can be declared for a large number of the services, especially in the case of
tracking, via the U.S. site http://www.aboutads.info/choices/ or the EU site
http://www.youronlinechoices.com/. Furthermore, the storage of cookies can be
achieved by disabling them in the browser settings. Please note that in this
case not all functions of this online offer can be used.
With SSL/TLS encryption
This website uses SSL/TLS encryption for security reasons and to protect the
transmission of confidential content, such as requests that you send to us as
the site operator. You can recognize an encrypted connection by the fact that
the address line of the browser changes from "http://" to
"https://" and by the lock symbol in your browser line.
If SSL or TLS encryption is activated, the data you transmit to us cannot be
read by third parties.
Server Log-Files
The provider of this website automatically collects and stores information in
so-called server log files, which your browser automatically transmits to us.
These are:
Browser type and Browser version
Operating system used
referrer URL
Host name of the accessing computer
Time of the server request
This data cannot be assigned to specific persons. This data is not merged with
other data sources. We reserve the right to check this data retrospectively if
we become aware of specific indications of illegal use.
Third party services
This website may use Google Maps for embedding maps, Google Invisible reCAPTCHA
for protection against bots and spam, and YouTube for embedding videos.
These services of the American Google LLC use cookies, among other things, and
as a result, data is transferred to Google in the USA, although we assume that
no personal tracking takes place in this context solely through the use of our
website.
Google has undertaken to ensure adequate data protection in accordance with the
US-European and the US-Swiss Privacy Shield.
Further information can be found in Google's privacy policy.
Contact form
If you send us inquiries via the contact form, your data from the inquiry form
including the contact data you provided there will be stored by us for the
purpose of processing the inquiry and in case of follow-up questions. We do not
pass on this data without your consent.
Newsletter
If you would like to receive the newsletter offered on this website, we require
an e-mail address from you as well as information that allows us to verify that
you are the owner of the specified e-mail address and agree to receive the
newsletter. Further data will not be collected. We use this data exclusively
for sending the requested information and do not pass it on to third parties.
You can revoke your consent to the storage of the data, the e-mail address and
their use for sending the newsletter at any time, for example via the
"unsubscribe link" in the newsletter.
Data Subject Rights
Right to confirmation
Every data subject has the right to request confirmation from the website
operator as to whether personal data concerning him or her are being processed.
If you wish to exercise this right of confirmation, you may, at any time,
contact the Data Protection Officer.
Right of access
Every person affected by the processing of personal data has the right to
receive information free of charge from the operator of this website at any
time about the personal data stored about him or her and a copy of this
information. Furthermore, information may be provided about the following, if
applicable:
the purposes of processing
the categories of personal data processed
the recipients to whom the personal data have been or will be disclosed
if possible, the planned duration for which the personal data will be stored
or, if this is not possible, the criteria for determining this duration
the existence of a right to obtain the rectification or erasure of personal
data concerning him or her, or the restriction of processing by the controller,
or a right to object to such processing
the existence of a right of appeal to a supervisory authority
if the personal data are not collected from the data subject: Any available
information about the origin of the data.
Furthermore, the data subject has the right to be informed whether personal
data have been transferred to a third country or to an international
organization. If this is the case, the data subject also has the right to obtain
information about the appropriate safeguards in connection with the transfer.
If you would like to make use of this right to information, you can contact our
data protection officer at any time.
Right to rectification
Every person affected by the processing of personal data has the right to
demand the immediate correction of incorrect personal data concerning him or
her. Furthermore, the data subject has the right, taking into account the
purposes of the processing, to request that incomplete personal data be
completed, including by means of a supplementary declaration.
If you wish to exercise this right of rectification, you may contact our data
protection officer at any time.
Right to erasure (right to be forgotten)
Any person concerned by the processing of personal data has the right to obtain
from the controller of this website the erasure without delay of personal data
concerning him or her, where one of the following grounds applies and insofar
as the processing is no longer necessary:
The personal data have been collected or otherwise processed for such purposes
for which they are no longer necessary.
The data subject revokes the consent on which the processing was based and
there is no other legal basis for the processing
The data subject objects to the processing on grounds relating to his or her
particular situation and there are no overriding legitimate grounds for the
processing, or the data subject objects to the processing in the case of direct
marketing and related profiling
The personal data have been processed unlawfully
The erasure of the personal data is necessary for compliance with a legal
obligation under Union or Member State law to which the controller is subject
The personal data has been collected in relation to information society
services provided directly to a child
If one of the above reasons applies and you wish to arrange for the deletion of
personal data stored by theoperator of this website, you can contact our data
protection officer at any time. The data protection officer of this website
will arrange for the erasure request to be complied with immediately.
Right to restriction of processing
Any person concerned by the processing of personal data has the right to obtain
from the controller of this website the restriction of processing if one of the
following conditions is met:
The accuracy of the personal data is contested by the data subject, for a
period enabling the controller to verify the accuracy of the personal data
The processing is unlawful, the data subject objects to the erasure of the
personal data and requests instead the restriction of the use of the personal
data
The controller no longer needs the personal data for the purposes of the
processing, but the data subject needs it for the assertion, exercise or
defense of legal claims
The data subject has objected to the processing on grounds relating to his or
her particular situation, and it is not yet clear whether the legitimate
interests of the controller override those of the data subject
If one of the aforementioned conditions is met, you can request the restriction
of personal data stored by the operator of this website at any time by
contacting our data protection officer. The data protection officer of this
website will arrange the restriction of the processing.
Right to data portability
Every person affected by the processing of personal data has the right to
receive the personal data concerning him or her in a structured, common and
machine-readable format. He or she also has the right to have this data
transferred to another controller if the legal requirements are met.
Furthermore, the data subject has the right to obtain that the personal data be
transferred directly from one controller to another controller, insofar as this
is technically feasible and insofar as this does not adversely affect the
rights and freedoms of other persons.
To assert the right to data portability, you may at any time contact the data
protection officer appointed by the operator of this website.
Right of objection
Any person affected by the processing of personal data has the right to object
at any time, on grounds relating to his or her particular situation, to the
processing of personal data concerning him or her.
The operator of this website shall no longer process the personal data in the
event of the objection, unless we can demonstrate compelling legitimate grounds
for the processing which override the interests, rights and freedoms of the
data subject, or if the processing serves the purpose of asserting, exercising
or defending legal claims.
To exercise the right to object, you may directly contact the Data Protection
Officer of this website.
Right to revoke consent granted under data protection law
Every person affected by the processing of personal data has the right to
revoke a given consent to the processing of personal data at any time.
If you wish to exercise your right to revoke consent, you may contact our data
protection officer at any time.
Contradiction email marketing
The use of contact data published within the framework of the imprint
obligation to send advertising and information materials not expressly
requested is hereby prohibited. The operators of the pages expressly reserve
the right to take legal action in the event of the unsolicited sending of advertising
information, such as spam e-mails.
Chargeable services
For the provision of chargeable services, we request additional data, such as
payment details, in order to be able to execute your order. We store this data
in our systems until the statutory retention periods have expired.
Copyrights
The copyright and all other rights to the content, images, photos or other
files on the website belong exclusively to the operator of this website or the
specifically named copyright holders. For the reproduction of all files, the
written consent of the copyright holder must be obtained in advance.
Anyone who commits a copyright infringement without the consent of the
respective copyright holder may be liable to prosecution and possibly to
damages.
Disclaimer
All information on our website has been carefully checked. We make every effort
to ensure that the information we provide is up-to-date, correct and complete.
Nevertheless, the occurrence of errors can not be completely excluded, so we
can not guarantee the completeness, accuracy and timeliness of information,
including journalistic-editorial nature. Liability claims regarding damage
caused by the use of any information provided, including any kind of
information which is incomplete or incorrect, will therefore be rejected.
The publisher may change or delete texts at his own discretion and without
notice and is not obliged to update the contents of this website. The use of or
access to this website is at the visitor's own risk. The publisher, its clients
or partners are not responsible for damages, such as direct, indirect,
incidental, consequential or punitive damages, allegedly caused by the visit of
this website and consequently assume no liability for such damages.
The publisher also accepts no responsibility or liability for the content and
availability of third-party websites that can be accessed via external links on
this website. The operators of the linked sites are solely responsible for
their content. The publisher thus expressly distances itself from all
third-party content that may be relevant under criminal or liability law or
that may offend common decency.
Google Maps
This website uses the offer of Google Maps. This allows us to display
interactive maps directly on the website and enables you to comfortably use the
map function. By visiting the website, Google receives the information that you
have accessed the corresponding subpage of our website. This occurs regardless
of whether Google provides a user account through which you are logged in or
whether there is no user account. If you are logged in to Google, your data
will be directly assigned to your account. If you do not want the assignment
with your profile at Google, you must log out before activating the button.
Google stores your data as usage profiles and uses them for the purposes of
advertising, market research and/or demand-oriented design of its website. Such
an evaluation is carried out in particular (even for users who are not logged
in) to provide needs-based advertising and to inform other users of the social
network about your activities on our website. You have the right to object to
the creation of these user profiles, whereby you must contact Google to
exercise this right. For more information on the purpose and scope of data collection
and processing by Google, as well as further information on your rights in this
regard and settings options for protecting your privacy, please visit:
www.google.de/intl/de/policies/privacy.
Google WebFonts
This website uses so-called web fonts provided by Google for the uniform
display of fonts. When you call up a page, your browser loads the required web
fonts into its browser cache in order to display texts and fonts correctly. If
your browser does not support web fonts, a standard font is used by your
computer.
You can find more information on Google Web Fonts at
https://developers.google.com/fonts/faq and in Google's privacy policy:
https://www.google.com/policies/privacy/
Instagram
Functions of the Instagram service are integrated on our website. These
functions are offered by Instagram Inc., 1601 Willow Road, Menlo Park, CA,
94025, USA. If you are logged into your Instagram account, you can link the
content of our pages to your Instagram profile by clicking on the Instagram
button. This allows Instagram to associate the visit to our pages with your
user account. We would like to point out that we, as the provider of the pages,
have no knowledge of the content of the transmitted data or its use by
Instagram.
For more information, please see the privacy policy of Instagram:
http://instagram.com/about/legal/privacy/
LinkedIn
We use the marketing services of the social network LinkedIn of LinkedIn
Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland
("LinkedIn") within our online offer.
These use cookies, i.e. text files that are stored on your computer. This
enables us to analyze your use of the website. For example, we can measure the
success of our ads and show users products in which they were previously
interested.
For example, information on the operating system, the browser, the website you
previously visited (referrer URL), which websites the user visited, which
offers the user clicked on, and the date and time of your visit to our website
is collected.
The information generated by the cookie about your use of this website is
transferred pseudonymously to a LinkedIn server in the USA and stored there.
LinkedIn therefore does not store the name or email address of the respective
user. Rather, the above-mentioned data is only assigned to the person for whom
the cookie was generated. This does not apply if the user has allowed LinkedIn
to process without pseudonymization or has a LinkedIn account.
You may refuse the use of cookies by selecting the appropriate settings on your
browser, however please note that if you do this you may not be able to use the
full functionality of this website. You can also object to the use of your data
directly at LinkedIn:
https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.
We use LinkedIn Analytics to analyze and regularly improve the use of our
website. The statistics obtained allow us to improve our offer and make it more
interesting for you as a user. All LinkedIn companies have adopted the standard
contractual clauses to ensure that the data traffic to the USA and Singapore
necessary for the development, implementation and maintenance of the services
takes place in a lawful manner. If we ask users for consent, the legal basis
for processing is Art. 6 (1) lit. a DSGVO. Otherwise, the legal basis for the
use of LinkedIn Analytics is Art. 6 para. 1 p. 1 lit. f DSGVO.
Third-party provider information: LinkedIn Ireland Unlimited Company Wilton
Place, Dublin 2 Ireland; User Agreement and Privacy Policy.
Sending newsletters - Mailchimp
The newsletter is sent using the mailing service provider 'MailChimp', a
newsletter mailing platform of the US provider Rocket Science Group, LLC, 675
Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA. You can view the privacy
policy of the mailing service provider here. The Rocket Science Group LLC d/b/a
MailChimp is certified under the Privacy Shield agreement and thereby offers a
guarantee of compliance with the European level of data protection
(PrivacyShield). The shipping service provider is used on the basis of our
legitimate interests pursuant to Art. 6 para. 1 lit. f DSGVO and an order
processing agreement pursuant to Art. 28 para. 3 p. 1 DSGVO.
The dispatch service provider may use the data of the recipients in
pseudonymous form, i.e. without assignment to a user, to optimize or improve
its own services, e.g. to technically optimize the dispatch and presentation of
the newsletters or for statistical purposes. However, the dispatch service
provider does not use the data of our newsletter recipients to write to them
itself or to pass the data on to third parties.
Contractual services
We process the data of our contractual partners and interested parties as well
as other clients, customers, clients or contractual partners (uniformly
referred to as "contractual partners") in accordance with the data
protection provisions of the German Federal Data Protection Act
(Datenschutzgesetz, DSG) and the EU-DSGVO pursuant to Art. 6 Para. 1 lit. b.
DSGVO, in order to provide them with our contractual or pre-contractual
services. The data processed in this context, the type, scope and purpose and
the necessity of their processing, are determined by the underlying contractual
relationship.
The data processed includes the master data of our contractual partners (e.g.
names and addresses), contact data (e.g. e-mail addresses and telephone
numbers) as well as contractual data (e.g. services used, contract content,
contractual communication, names of contact persons) and payment data (e.g.
bank details, payment history).
As a matter of principle, we do not process special categories of personal
data, unless these are components of a commissioned or contractual processing.
We process data that are required for the justification and fulfillment of
contractual services and point out the necessity of their disclosure, unless
this is evident to the contractual partners. Disclosure to external persons or
companies is made only if it is necessary in the context of a contract. When
processing data provided to us in the context of an order, we act in accordance
with the instructions of the client as well as the legal requirements.
In the context of the use of our online services, we may store the IP address
and the time of the respective user action. The storage is based on our
legitimate interests, as well as the interests of users in protection against
misuse and other unauthorized use. In principle, this data is not passed on to
third parties, unless it is necessary for the pursuit of our claims pursuant to
Art. 6 para. 1 lit. f. DSGVO or there is a legal obligation to do so pursuant
to Art. 6 para. 1 lit. c. DSGVO.
The deletion of the data takes place when the data is no longer required for
the fulfillment of contractual or legal duties of care as well as for dealing
with any warranty and comparable obligations, whereby the necessity of keeping
the data is reviewed at irregular intervals. In all other respects, the
statutory retention obligations shall apply.
Administration FIBU etc.
We process data in accordance with the data protection regulations of the
Federal Republic of Germany (Data Protection Act, DSG) and the EU-DSGVO in the
context of administrative tasks as well as organization of our operations,
financial accounting and compliance with legal obligations, such as archiving.
In doing so, we process the same data that we process in the course of
providing our contractual services. The processing bases are Art. 6 para. 1
lit. c. DSGVO, Art. 6 para. 1 lit. f. DSGVO. Customers, interested parties,
business partners and website visitors are affected by the processing. The
purpose and our interest in the processing lies in the administration,
financial accounting, office organization, archiving of data, i.e. tasks that
serve the maintenance of our business activities, performance of our tasks and
provision of our services. The deletion of data with regard to contractual
services and contractual communication corresponds to the data mentioned in
these processing activities.
In this context, we disclose or transfer data to the tax authorities,
consultants, such as tax advisors or auditors, as well as other fee offices and
payment service providers.
Furthermore, based on our business interests, we store information on
suppliers, event organizers and other business partners, e.g. for the purpose
of contacting them at a later date. This data, most of which is
company-related, is generally stored permanently.
Data transfer to the USA
Among other things, tools from companies based in the USA are integrated on our
website. If these tools are active, your personal data may be transferred to
the US servers of the respective companies. We would like to point out that the
USA is not a safe third country in the sense of EU data protection law. US
companies are obliged to hand over personal data to security authorities
without you as a data subject being able to take legal action against this. It
can therefore not be ruled out that US authorities (e.g. intelligence services)
process, evaluate and permanently store your data located on US servers for
monitoring purposes. We have no influence on these processing activities.
Changes
We may amend this privacy policy at any time without prior notice. The current
version published on our website applies. Insofar as the data protection
declaration is part of an agreement with you, we will inform you of the change
by e-mail or other suitable means in the event of an update.
Disclaimer
The author assumes no liability for the correctness, accuracy, timeliness,
reliability and completeness of the information.
Liability claims against the author for material or immaterial damage resulting
from access to, use or non-use of the published information, from misuse of the
connection or from technical malfunctions are excluded.
All offers are non-binding. The author expressly reserves the right to change,
add to, or delete parts of the pages or the entire offer without prior notice,
or to temporarily or permanently cease publication.
Source: BrainBox Solutions
Zurich, 30.08.2023
Usage analysis (Matomo)
In order to be able to offer our web presence in a user-friendly, effective and reliable form for the visitors to our website, we use the web analysis service Matomo on the basis of our legitimate interests (i.e. interest in the analysis, optimisation and economic operation of our web presence pursuant to Art. 6 Par. 1 Letter f [GDPR]) without the usage of cookies. The information acquired in this way about the usage of this website is saved on servers of our website provider. Before it is saved, your IP address will be anonymised so that it is not possible to draw any direct conclusions regarding your person. When you visit our site, we will store: the website from which you visited us from, the pages of our site you visit, the date and duration of your visit, your anonymised IP address, information from the device (device type, operating system, screen resolution, language, and web browser type) you used during your visit.
Apart from us and our website provider, no third party has access to these data.
Our website provider has its registered office in Germany and is thus obligated to comply with data protection law. A contract for processing has been concluded with our website provider that regulates the processing of the collected and anonymised data. Our website provider uses this information on our behalf in order to be able to carry out technical maintenance services and optimisations so that the operation of this online presence remains safe and effective and in order to provide other services for us that are associated with the usage of this online presence and the Internet usage.
You can prevent the saving of the above mentioned information by a corresponding „do not track“ setting of your browser software or the option mentioned below.