1. Introduction

This privacy notice serves to inform you about how we handle the personal data collected, processed and stored through our website.

This privacy notice applies to the website of Artifiche AG. We assume no responsibility for the data protection regulation compliance of other websites linked on ours.

We reserve the right to change the contents of this privacy notice, especially if we offer new or modified services or if changes in the applicable legislation or legal precedents make modifications necessary or useful, as long as the user can reasonably be expected to accept them taking into account our legitimate interests.


2. General information on data processing

2.1. Scope of processing of personal data

We collect and process personal data of our users insofar as necessary for providing a functioning website and delivering our content and services.

The collection and processing of our users’ personal data take place regularly only with the user’s consent. An exception applies to cases in which prior consent cannot be obtained for reasons of fact and the processing of the data is permitted by law.

2.2. Legal basis

Generally, the Swiss Federal Act on Data Protection (FADP) serves as the legal basis for this privacy notice. In addition, the EU General Data Protection Regulation (GDPR), which is frequently mentioned in this notice, applies for users from EU member states.

2.3. Data deletion and storage duration

A user’s personal data are deleted or blocked as soon as the purpose of storage ceases to apply. Storage can also occur if provided for by the European or national legislator in EU regulations, laws or other legislation to which the controller is subject.

Blocking or deletion of data also occurs when a storage period prescribed by the aforementioned legislation expires, unless there is a need for further storage of data for the conclusion or fulfilment of a contract.

3. Provision of the website and creation of log files

3.1. Description and scope of data processing

Our website can be visited without provision of any personal data. For every access query to our website, our system automatically collects data transmitted by the user’s web browser.

The following data are collected in this process:

  • Browser type, version and language
  • Operating system and language setting used
  • Activated browser plugins
  • Screen resolution
  • Address of the website visited previously (referrer URL)
  • Hostname of the user’s computer (IP address)
  • Date and time of access
  • Name of the file being requested
  • Volume of data transmitted
  • Report on successful data retrieval

These data are compiled in log files and saved on our server. No further personal data are stored together with the log file data.

3.2. Legal basis

EU: Art. 6 para. 1 lit. f GDPR

3.3. Purpose

The temporary storage of the IP address by our system is necessary for granting the user’s system access to our website. For this purpose, the user’s IP address must be stored for the duration of the session.

Data storage in log files is required to ensure the functioning of the website. Furthermore, the data allows us to optimise the website and ensure the security of our IT systems. No data analysis for marketing-related purposes is performed in this context.

These purposes correspond to the legitimate interests in data processing in accordance with the abovementioned legal basis.

3.4. Duration of storage

The data are deleted as soon as they are no longer needed to fulfil the purpose for which they were collected. In the case of data collection for the purpose of providing the website, this is the case as soon as the session ends. In the case of data storage in logfiles, this is the case after 10 weeks. In the case of statistical information, this is the case after 12 months.

3.5. Ability to object and delete

The collection of data for the provision of the website and the storage of data in logfiles is necessary for the operation of the website. The website user therefore has no ability to object to the processing of their data.

4. Use of cookies

4.1. Description and scope of data processing

Our website uses cookies. Cookies are text files saved in the web browser or on the user’s computer system by the web browser. Whenever a user accesses a website, a cookie may be saved on the operating system. The cookie contains a distinctive sequence of characters which enables the website to correctly identify the user’s browser when the site is visited again.

We only use cookies which are technically necessary.

4.2. Legal basis

EU: Art. 6 para. 1 lit. f GDPR

4.3. Purpose

The purpose of using technically necessary cookies is to make it easier for the user to use the website. Some features on our website cannot be offered without cookies. Such features require the browser to be identified after a page change.

Cookies are required for the following applications:

  • Displaying the website in the correct language

The user data collected with technically necessary cookies are not used for creating user profiles.

These purposes correspond to the legitimate interests in processing personal data in accordance with the abovementioned legal basis.

4.4. Duration of storage and ability to object and delete

Cookies are saved on the user’s computer, which transmits them to our website. Consequently, as the user, you have complete control over the use of cookies.

By changing the settings in your web browser, you can deactivate or restrict the transmission of cookies. Cookies saved on your system can be deleted at any time. This can also be done automatically. If cookies are deactivated for our website, it may prevent you from making full use of all the website’s features.

5. Newsletter

5.1. Description and scope of data processing

The users of our website have the possibility of subscribing to a free newsletter. When the user registers to subscribe, the data entered in the subscription form are transmitted to our newsletter provider, “MailChimp”.

The following data are collected in the newsletter subscription form:

  • Email address
  • First name (optional)
  • Last name (optional)

In addition, the following data are collected in the registration process:

  • IP address of the querying computer
  • Date and time of registration
  • Language of the user’s browser

As part of the registration process, the user is asked to consent to have their data processed and is informed of this privacy notice.

A link provided in each newsletter allows users to edit their first name, last name and email address at any time.

5.2. Legal basis

EU: Art. 6 para. 1 lit. a GDPR

5.3. Purpose

The user’s email address is collected for the purpose of delivering the newsletter. It also serves to prevent reregistration of users who have unsubscribed.

Other personal data collected during registration serves to prevent the improper use of our services or the provided email address.

5.4. Duration of storage

The data are deleted as soon as they are no longer needed to fulfil the purpose for which they were collected.

5.5. Ability to object and delete

The newsletter subscription can be cancelled by the user at any time. For this purpose, a cancellation link is embedded in every newsletter.

When a user unsubscribes using the link in the newsletter, their personal data remain in storage in order to prevent reregistration. There is currently no possibility to delete these data.

Users who have not unsubscribed using the link in the newsletter can have their stored data deleted completely by placing a corresponding request with us through appropriate channels. They will receive confirmation that their data have been deleted.

6. Newsletter tracking

6.1. Description and scope of the processing of personal data

Our newsletter contains a “web beacon” for tracking as well as links which record part of the user’s behaviour in connection with the newsletter.

The following data are collected by these means:

  • IP address of the querying computer
  • Type of email application
  • Browser type
  • Date and time at which the newsletter was opened
  • Date and time at which each link in the newsletter was clicked

As part of the registration process, the user is asked to consent to have their data collected and processed and is informed of this privacy notice.

6.2. Legal basis

EU: Art. 6 para. 1 lit. a GDPR

6.3. Purpose

We use these data to make our newsletter more user-friendly.

6.4. Duration of storage

The data are deleted as soon as they are no longer needed to fulfil the purpose for which they were collected.

6.5. Ability to object and delete

When unsubscribing from the newsletter via email, telephone, post or face-to-face, users can object to the newsletter tracking at any time. The stored personal data will subsequently be deleted. Only those data which do not allow the identification of a specific individual will be retained for statistical purposes. However, this does not apply to subscription cancellations effected by using the link in the newsletter.

7. Forms

7.1. Description and scope of the processing of personal data

Our website contains two types of webforms: one can be used for contacting us or inquiring about poster prices, and the other can be used to subscribe to our newsletter.

The following data are collected in the contact form:

  • First name
  • Last name
  • Organisation (optional)
  • Street
  • Postal code, city
  • Telephone number
  • Email address
  • Message

The following data are collected in the newsletter subscription form:

  • Email address
  • First name (optional)
  • Last name (optional)
  • Language

In addition, the following data are collected:

  • The computer’s IP address
  • Date and time of submission
  • For price inquiries: poster number

As part of the registration process, the user is asked to consent to have their data collected and processed and is informed of this data protection policy.

The data entered in the form are transmitted to us by email and stored on our webserver.

7.2. Legal basis

EU: Art. 6 para. 1 lit. a GDPR

7.3. Purpose

The data entered by the user are needed to answer the contact request or price inquiry or to deliver the newsletter. The additional data are necessary to ensure the safety of the forms.

Data are stored in order to process inquiries even when they could not be successfully transmitted by email.

7.4. Duration of storage

The data are deleted after one year at the latest.

7.5. Ability to object and delete

Senders can object to the storage and further processing of their data at any time by notifying us through appropriate channels.

8. Email contact

8.1. Description and scope of the processing of personal data

On our website, users can personally contact us via email by using the email address provided. In this case, the sender’s personal data transmitted along with the email message are stored.

These data are:

  • Email address
  • Name

In addition, further data commonly used for email messages are transmitted and stored, such as:

  • Subject
  • Message content and email attachments
  • Sender’s IP address
  • Hostname of the mail server
  • Hostnames of the relaying servers
  • Date and time of submission
  • Email application used

8.2. Legal basis

EU: Art. 6 para. 1 lit. a, b and f GDPR

8.3. Purpose

The data are used only to process the communication. This corresponds to the legitimate interests in processing personal data.

8.4. Duration of storage

The data are deleted as soon as they are no longer needed to fulfil the purpose for which they were collected. For personal data transmitted by email, this is the case after 10 years at the latest.

8.5. Ability to object and delete

The user has the possibility to withdraw their consent to have their personal data processed at any time. When the user contacts us by email, they can object to the storage of their personal data at any time. In such a case, we can no longer communicate with the user.

In this case, all personal data stored in the communication process will be deleted.

9. Disclosure of data to third parties

9.1. Description and scope of the processing of personal data

We may disclose our users’ personal data collected through our website to third parties in order to carry out our activities or fulfil contracts.

The following data may be disclosed:

  • Logfiles, web analysis data and newsletter addresses may be disclosed to our hoster and webmaster in Switzerland

The scope of the data is described above.

When a user contacts us in writing or by telephone or is in a customer relationship with us, we may also disclose personal data to the following third parties for the following purposes:

  • To Swiss IT providers: for the address book and orders (data scope: contact data, orders)
  • To “MailChimp” (newsletter provider): for the newsletter and newsletter tracking
  • To a Swiss bank: for payments (data scope: payment information)
  • To tax authorities: to fulfil tax obligations (data scope: invoice data)

9.1.1. Unencrypted emails

Due to the open nature of the email service, it cannot be ruled out that data transmitted by email are viewed by third parties, in particular when emails are unencrypted.

9.1.2. Data retention

Data transmitted over the internet may be viewed, stored and processed by third parties such as internet providers or state institutions. According to the Swiss Federal law on the surveillance of post and telecommunications traffic (BÜPF), Swiss internet providers are obliged to store internet metadata (this is called “data retention”). Similar regulations may apply in other states.

9.2. Legal basis

EU: Art. 6 para. 1 lit. f GDPR

CH: Data retention: Federal law on the surveillance of post and telecommunications traffic (BÜPF)

9.3. Purpose

The purpose of the collection, storage, transmission and processing of these data is mentioned above.

9.4. Duration of storage

The duration of storage is mentioned in the paragraph on the respective data collection context. The storage of personal data in a customer relationship depends on the duration of the customer relationship. In tax matters, the retention period stipulated by the legislator is applicable (10 years at most).

9.5. Ability to object and delete

The possibilities described in the paragraph on the respective data collection context apply. You can have address data stored with us deleted at any time, which generally ends the customer relationship.

10. Rights of the data subject

If your personal data are processed, you are a data subject as contemplated by the GDPR (EU) or the FADP (Switzerland).

If you are a data subject as contemplated by the GDPR, you have various rights in relation to the controller (right to information, right to rectification, right to restriction of processing, right to erasure, right to notification, right to data portability, right to object, right to withdraw consent, right to lodge a complaint). You can find more details in chapter III of the GDPR at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679

11. Controller

Artifiche AG
Beatrice Müller
Feldeggstrasse 19
CH-8008 Zurich

You can find further contact information on the Contact page.

Last updated: 24 July 2018