AWSMTECH

Privacy
policy

Designed to protect your data with the highest level of rigour, our privacy policy combines transparency, compliance and security. You focus on your business, we take care of protecting your information.

1 PREAMBLE

We attach great importance to the protection of privacy, including personal data. This document explains our policy regarding how we process personal data, the data we collect, the purposes and the legal basis for the processing. This privacy policy applies and forms an integral part of our contracts.

2 GENERAL

We are committed to complying with the Swiss Federal Act on Data Protection (FADP) or, where applicable, the standards of the EU General Data Protection Regulation (GDPR – EU 2016/679). We also recognise the importance of cooperating with our clients to fulfil all legal obligations, in particular by responding to requests from data subjects, providing access to personal data, cooperating with regulatory inspection and audit requests, and establishing additional agreements for international data transfers in order to protect personal data.

3 ACTING AS DATA CONTROLLER

When we act as data controller, we collect and manage certain personal data, generally referred to as "business information". This includes data that our clients share with us, such as name, phone number, address, e-mail address and role within the organisation. It may also include technical information, such as the relevant IP address, as well as bank details for payment purposes. We process this personal data solely to fulfil our contractual obligations, manage business relationships, process orders and contracts, provide products and services, invoice and provide support. Our data processing activities include implementing security and technical measures to protect personal data. We also process analytical and statistical data related to contractual obligations, quality, security, reporting and billing.

4 ACTING AS DATA PROCESSOR FOR OUR CLIENTS

As part of a managed services contract, we process the client's data as a processor of certain client data (including client content) while the client remains the data controller and owner of its client content. As a processor, we process personal data exclusively as the client's processor and in accordance with the contractual provisions or to the extent necessary to fulfil our contractual obligations. Client content data entrusted to us is neither read, modified nor evaluated by us without the client being informed. Technical and organisational security measures are implemented to protect it against unlawful access by third parties, although we have no influence over the security of data relating to client content when it is transferred over public networks. Where technically possible and at the client's request, specific security measures may be added to the usual services, such as data encryption. These measures are at the client's discretion and require the prior agreement of both parties. Upon expiry or termination of the services, we return, at the client's request, the client's content in a standard format and destroy the data relating to the client's content no later than 90 days after expiry or termination of the services. We only disclose client data to public authorities when we are legally required to do so. Unless otherwise stated in the contract, as a processor hosting your personal data, our data centre is located in Switzerland.

5 TOWARDS THIRD PARTIES

In certain cases, we may need to involve third parties in the performance of the services, which involves access to client data. In this case:

  • Third parties are granted limited and controlled access to the personal data necessary for business processes, for example to maintain the operation of information technologies,
  • We require third parties to handle data protection in accordance with applicable legislation,
  • We only disclose the information necessary, where applicable, for the provision of the services.

6 DATA CONTROLLER

The controller of the personal data collected through this website is AWSMTECH (Switzerland) SA, a Swiss public limited company, UID CHE-179.053.698, Av. Louis-Casaï 71, 1216 Cointrin, Switzerland — accounts@awsmtech.ch, +41 (0) 22 552 60 70.

Processing is subject to the Swiss Federal Act on Data Protection (nFADP). As the website also addresses visitors and clients located in the European Union, the General Data Protection Regulation (GDPR) applies where its conditions are met.

7 DATA COLLECTED ON THIS WEBSITE

  • Contact form data: last name, first name, e-mail address, phone number, service concerned and any additional notes you freely enter.
  • Technical data related to browsing, recorded by the hosting provider in its server logs: IP address, date and time, pages requested, browser.
  • Audience measurement data (Google Analytics 4), only if you accepted the “audience measurement” category in the cookie banner: page views, technical data and approximate location provided by the tool. No personal data from forms is sent to this tool.
  • Cookie consent choice: stored locally on your device, together with its date.

8 PURPOSES AND LEGAL BASES

  • Responding to your contact requests and preparing a possible contractual relationship — legal basis: pre-contractual measures and legitimate interest in handling incoming requests.
  • Performing service contracts and providing support — legal basis: performance of the contract.
  • Ensuring the security, availability and proper operation of the website — legal basis: legitimate interest.
  • Measuring website audience — legal basis: your consent, which can be withdrawn at any time.
  • Complying with our legal obligations, in particular accounting obligations — legal basis: legal obligation.

9 RECIPIENTS AND PROCESSORS

Your data is accessible to the employees of AWSMTECH (Switzerland) SA who need it, as well as to service providers acting on our behalf: the website host WeCode (Adamas Group SA, UID CHE-442.653.670, Route des Acacias 43, Atelier 35 (BAT43), 1227 Geneva), the e-mail provider used to receive contact requests, and Google Ireland Ltd for audience measurement when you have accepted it.

When we engage a new third party who may access a client’s personal data, we inform the client in writing beforehand. If a client disagrees with such an arrangement, both parties will explore other options, including a potential right of termination for the client if no satisfactory alternative is found.

No data is sold, rented or passed on for advertising purposes.

10 TRANSFERS OUTSIDE SWITZERLAND AND THE EU

Website hosting and the handling of contact requests take place in Switzerland and in the European Economic Area. The use of Google Analytics 4, subject to your consent, may involve a transfer of technical data to third countries, in particular the United States; such transfers rely on the standard contractual clauses and additional safeguards provided by Google. If you reject the “audience measurement” category, no such transfer takes place.

11 RETENTION PERIODS

  • Contact requests: retention period provisionally set at 12 months after the last exchange, pending confirmation by AWSMTECH and effective implementation. Until confirmed, no automatic deletion is applied.
  • Contractual data and accounting records: kept for the duration of the contract and then ten years, in accordance with Swiss law.
  • Hosting provider server logs: retention period to be confirmed with WeCode (30 days desired).
  • Audience measurement data: Google Analytics 4 retention setting to be verified (2 months targeted for user and event data).
  • Cookie consent choice: approximately 12 months on your device.

12 SECURITY

We implement appropriate technical and organisational measures to protect data against loss, unauthorised access, alteration and disclosure: encryption of communications, need-to-know access control, logging, backups and staff awareness. No transmission over the internet can, however, be guaranteed to be entirely secure.

13 YOUR RIGHTS

Within the limits of applicable law, you have the right to access your data, to have it rectified or erased, to restrict or object to processing, to data portability, and to withdraw your consent at any time, without affecting the lawfulness of processing carried out beforehand.

To exercise these rights, write to accounts@awsmtech.ch or to AWSMTECH (Switzerland) SA, Av. Louis-Casaï 71, 1216 Cointrin, Switzerland. We may ask you to prove your identity before replying.

14 COOKIES AND AUDIENCE MEASUREMENT

The cookies used, their categories and how to change your choice at any time are described in the Cookie policy, accessible from the footer. Audience measurement is disabled by default and is only activated after your explicit acceptance.

15 CONTACT AND SUPERVISORY AUTHORITY

For any question relating to personal data: accounts@awsmtech.ch, or by post at our company address.

You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland. If the GDPR applies to you, you may also contact the competent supervisory authority in your member state of residence.

For any questions relating to personal data, you can contact us at the following e-mail address: accounts@awsmtech.ch. You can also contact us by mail at our company address.