top of page
Privacy Policy This privacy policy (Privacy Policy) informs our website visitors, customers, and business partners (or persons acting on behalf of our customers and business partners) (you) about how Optik Foto Rutz AG processes personal data (Data) in accordance with the Swiss Federal Act on Data Protection (FADP) and the European General Data Protection Regulation (GDPR) when you use our website, when you use one of our services/products (Services), when you supply us with services/products, or in any of the other situations set out in the section "Data Processed, Purpose, and Legal Basis." Within the scope of the GDPR, references to the GDPR in this Privacy Policy are to be understood as references to the corresponding provisions of the FADP. 1. Controller and Contact Information The controller responsible for processing your data is Optik Foto Rutz AG Email: optik@rutz-stmoritz.ch 2. Obligation to Provide Data and Your Disclosure of Data to Third Parties You are generally not obligated to provide us with data. However, if you do not provide the information mentioned in Section 3, we may not be able to process your request, contact you, or provide you with the services. If you disclose data about third parties to us (e.g., about your employer/employees, relatives, family members, colleagues, beneficial owners, etc.), we assume that this data is correct. By disclosing such data to us, you confirm that you are authorized to do so and that you have informed the data subjects about this privacy policy and our processing of their data. 3. Processed Data, Purpose and Legal Basis II. General Depending on the circumstances described below, we process various categories of data. Within the scope of the GDPR, we base the processing of your data on the following legal bases: the processing of your data is necessary for the conclusion or performance of the contract with you (GDPR 6.1.1.b; e.g., in relation to services/products provided by us); the processing of your data is necessary for compliance with legal obligations to which we are subject (GDPR 6.1.1.c; e.g., to comply with legal requirements, guidelines, and recommendations from authorities); The processing of your data is necessary to protect our legitimate interests or the legitimate interests of a third party, unless your interests or fundamental rights and freedoms, which require the protection of data, override those interests (GDPR 6.1.1.f; e.g., for security and access control purposes as well as for compliance with internal regulations, including purposes such as compliance, risk management, corporate governance, and business organization); and/or the legal bases specified below. 1.1 Use of the Website Data processing in connection with your use of our website is limited to data that is necessary for the operation, provision, and security of the website and the services offered on it (website usage data) and for web analytics purposes (website analytics data). Categories of data: When you access our website (and, via our website, the services), the following information about your device may be automatically collected: IP address, operating system, device type, browser name and version, date and time of access, address of the website from which you were referred to our website (if applicable), etc. We may analyze your use of our website using web analytics tools, including Google Analytics (with IP anonymization enabled). Further information about Google's data usage and configuration options can be found here: https://www.google.com/intl/en/policies/privacy/partners, http://www.google.com/analytics/learn/privacy.html and https://policies.google.com/privacy?hl=de/gl=de. Purpose and legal basis: The processing of data relating to the use of the website is based on our legitimate interest in operating and securing our website and our services, in particular for security reasons, to ensure the stability and integrity of our systems (GDPR 6.1.1.f). Furthermore, based on our legitimate interest (GDPR 6.1.1.f), we may conduct basic web analytics to optimize the website in terms of user-friendliness and to gain insights into the use of our website and our services. The collected data will not be combined with other data or shared with third parties. Extended web analytics using cookies is based on your consent under the GDPR (GDPR 6.1.1.a), see section 1.2 Cookies below. Website analytics data may also be collected through the use of cookies. Cookies are small files that are managed by your browser and stored directly on your device when you visit our website. You can disable the use of cookies in your browser settings, but this may prevent you from using all the features of our website or services, or prevent them from functioning correctly. Categories of data: Website usage data, website analytics data, and other data specified in the [Cookie Policy / Consent Management Tool]. Purpose and legal basis: We may use cookies on our website to ensure a user-friendly experience (e.g., session cookies), based on our legitimate interest (GDPR 6.1.1.f). Extended web analytics using cookies is based on your consent under the GDPR (GDPR 6.1.1.a). Further information can be found in our [Cookie Policy / Consent Management Tool]. 1.3 Communication We contact you through various channels, for example, when you fill out contact forms or similar forms on our website, send us emails, or use other electronic (or printed) means of communication through which data can be exchanged (communication data). Categories of data: When you fill out our contact forms, send us an email or other form of electronic message (or a message in paper form, e.g., a letter), we collect information such as your name, your email address (or another form of communication identifier, e.g., a messenger nickname), your telephone number, the subject, the content of the message, the associated metadata, and any other information you disclose in your communication with us. Purpose and legal basis: We use communication data to process your request and any further questions relating to the provision of our services (GDPR 6.1.1.b) and other related questions and matters based on the content of your communication with us (GDPR 6.1.1.a). We store this data to document our communication with you, for training purposes, quality assurance, follow-up requests (GDPR 6.1.1.f), and for regulatory purposes (GDPR 6.1.1.c). 1.4 Services: When you use our services, you may need to register, e.g. B. by opening an account or creating a login, and we collect other service-related data, including contract data (as in section 3.6), relating to the services (collectively, service data, including registration data and usage data, as defined below). Categories of data: When you register for our services, you may need to open an account or create a login, for which we need information such as first name, last name, username, password, email, etc. This may also include other information that we need from you to provide you with the services, e.g., Depending on the service, we may collect further information such as address, telephone number, date of birth, nationality, identification document details, occupation, role and function, financial information (such as income information, assets, and tax status), customer history, etc., including information from third parties and public sources (e.g., fraud prevention or government agencies, websites, and government registers) (Registration Data). Furthermore, when you use our services, we process transaction information (dates, currencies, branches, payer and payee details) and record calls, emails, text messages, social media messages, and other communications between you and us. We also analyze your use of our services to better understand you and tailor our services to your needs by collecting data about your behavior and preferences, including supplementing such data with information from third parties, including from public sources (collectively, Usage Data). Purpose and legal basis: In general, the Service Data is used to provide you with our services (GDPR 6.1.1.b) and to comply with applicable legal requirements and our internal regulations, including for the purposes of money laundering and fraud prevention (GDPR 6.1.1.c and 6.1.1.f). We also process service data to document the provision of our services, for training purposes or quality assurance, as well as for market research to improve our services and processes, and for product development, which is based on our legitimate interest (GDPR 6.1.1.f). 1.5 Contracts When we enter into a contract with you or conduct negotiations regarding such a contract, we collect data related to the conclusion and performance of such a contract (contract data). Generally, we collect this data from you or other contracting parties and from third parties involved in the performance of the contract, but we may also use data from third parties or from public sources (e.g., fraud prevention agencies and government registers). Categories of data: Contract data includes registration data, service data in general, and other information relating to, for example, the services to be provided, your preferences, or your feedback. This also includes your health data (e.g., refraction data, anatomical values). Purpose and legal basis: We use contract data for the preparation, conclusion, execution, and management of our contractual relationships, as well as for any questions or inquiries that may arise in this context (GDPR 6.1.1.b). Such processing may be necessary to comply with legal requirements and internal regulations, including Know Your Customer (KYC) processes (GDPR 6.1.1.c and 6.1.1.f). We retain this data to document our communication with you, for training purposes, quality assurance, and for follow-up inquiries (GDPR 6.1.1.f). 1.6 Profiling We use your data to automatically evaluate personal aspects relating to you (so-called profiling), but we will not use it for automated decision-making. Categories of data: Depending on the specific circumstances, the data categories listed in this section, "Data Processed, Purpose, and Legal Basis," may be used for profiling. Purpose and legal basis: Profiling may be carried out for the purposes set out in this Section 3, in particular to determine preferences, to detect misuse and security risks, to carry out statistical analyses, or for operational planning (GDPR 6.1.1.f). Profiling is used only to gain a better understanding of certain aspects and does not lead to automated individual decision-making. 2. Disclosure and transfer of data: We disclose your data to third parties in certain cases (see Section 4.1), which may also involve cross-border data transfers (see Section Cross-border data transfers). 2.1 Categories of Recipients We make your data available to the following recipients (in accordance with applicable legal provisions): our group companies; external service providers (e.g., IT service providers, etc.); contractual partners (insofar as disclosure arises from such contracts, e.g., if you use our services under a contract we have concluded with your employer); competent authorities, including tax authorities and courts (in Switzerland and abroad, if we are legally obligated or entitled to do so, or if it appears necessary to protect our interests); legal and professional advisors, including legal representatives, accountants, and auditors; transaction partners and advisors (e.g., in connection with mergers, acquisitions, or other business transactions in which we or our group companies are involved). 2.2 Cross-border transfer of data We transfer your data to countries within the EEA or the United Kingdom, as well as to the following countries outside Switzerland or the EEA/United Kingdom, provided that (a) these countries, according to the assessment of the competent authority, ensure an adequate level of data protection, (b) we ensure an adequate level of data protection on the basis of suitable safeguards, such as the EU Standard Contractual Clauses (EU-SCC), which have been adapted to Swiss law to the necessary extent (CH-SCC), or (c) the transfer is based on a legal exception: [...] . To obtain a copy of the EU-SCC / CH-SCC, please contact us using the contact details provided in the Controller and Contact Information section. 3. Retention Periods and Deletion We process and store data for as long as required by our processing purposes, statutory retention periods, and our legitimate interests in documentation, and within the scope of what is technically feasible. Except in the case of conflicting legal or contractual obligations, we will delete or anonymize your data after the retention or processing period has expired. With regard to specific purposes/data categories, we will generally retain your data as follows: Website usage data: Website usage data is processed for as long as necessary to enable the requested access and to ensure the stability and integrity of the systems. Website analytics data: Website analytics data is stored for as long as necessary to perform the analysis. Cookies: Cookies are stored on your device for the period necessary to achieve the relevant purpose, as well as in accordance with the further details in the [Cookie Policy / Consent Management Tool]. Communication data: Communication data is deleted after your request has been answered or processed, unless (a) we are legally obligated to retain this data (e.g., for billing or record-keeping purposes) or (b) we have an overriding legitimate interest in retaining this data for documentation, quality assurance, or similar business purposes, or for the assessment, assertion, or defense of legal claims. Usage data: We generally retain the data for as long as you access/use (or are entitled to access/use) our services, and this data will be deleted after termination of your contractual relationship and/or deletion of your account, unless (a) we are legally obliged to retain this data (e.g., for billing or documentation purposes), or (b) we have an overriding legitimate interest in retaining this data for documentation, quality assurance, or similar business purposes, or for the assessment, establishment, or defense of legal claims. Contract data: We generally retain contract data for the duration of the limitation period for contractual claims, calculated from the end of the contractual relationship, unless (a) we are legally obligated to retain this data for a longer period (e.g., for billing or document retention purposes) or (b) we have an overriding legitimate interest in retaining this data for documentation, quality assurance, or similar business purposes, or for assessing, asserting, or defending legal claims. 4. Your rights as a data subject: As a data subject, you have the following rights: Information, i.e., You can request information from us about whether we process data about you, and if so, you can request further information about this. Rectification, i.e., you can ask us to correct or supplement your data if it is incorrect or incomplete. Erasure, i.e., you can request the deletion of your data. We generally comply with a request for erasure, unless we are legally obligated to retain the data or have an overriding legitimate interest in retaining it. Objection, i.e., The right to object to the processing of your data based on our legitimate interest (GDPR 6.1.1.f) by stating your particular reasons and specific circumstances on which your objection is based. The right to restrict processing, i.e., you can request that we temporarily restrict the processing of your data. The right to data portability, i.e., you can request that we provide you with the data you have provided to us in electronic form (where technically feasible). The right to withdraw your consent, i.e., you can withdraw your consent if and to the extent that you have previously given your consent for a specific purpose of processing your data. This does not affect the lawfulness of processing carried out before the withdrawal (or processing based on a legal basis other than your consent) and may result in us no longer being able to provide you with our services. If you wish to exercise any of these rights, please contact us using the contact details provided in the Controller and Contact Information section. Before we respond to your request, we will ask you for proof of identity. This allows us to ensure that your data is not disclosed to unauthorized persons. Please note that your rights are subject to limitations, which we may invoke in individual cases. 5. Data Security We take appropriate technical and organizational security measures to protect your data from unauthorized access, alteration, disclosure, or destruction. Please note that these security measures cannot completely eliminate the security risks associated with data processing. 6. Complaints / Supervisory Authority If you believe that the processing of your data violates applicable data protection laws, you can lodge a complaint with the competent data protection authority. For Optik Foto Rutz AG, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland (https://www.edoeb.admin.ch). Depending on your place of residence, you also have the option of lodging a complaint with the data protection authority in your place of residence. 7. Changes to this Privacy Policy This Privacy Policy is not part of any contract with you, and we may change it at any time. The version published on our website is the currently valid version. Last updated: August 31, 2023
bottom of page
