«In the event of doubt and the relevance of interpretation is called into question, the German version of the Privacy Statement will remain relevant and will take precedence.»
This policy describes how we process the personal data that we have received from you via a website or application. This policy applies exclusively to personal data collected by Rex-Royal AG, e.g. via websites, e-mail and other online tools and applications.
The Swiss Data Protection Act (DSG) and any additional applicable law from the European General Data Protection Regulation (GDPR) apply.
2. Processing of personal data; nature, purpose and use
When you visit our website, rex-royal.ch, information is temporarily stored in what are referred to as log files on our server. This is information which is automatically sent by the browser of your device. Specifically:
• IP address
• Date and time of the request
• Time zone difference relative to Greenwich Mean Time (GMT)
• Content of the request (specific page)
• Access status/HTTP status code
• Amount of data transferred in each case
• Website from which the request comes
• Operating system and its interface
• Language and version of the browser software
We process the aforementioned data for the following purposes:
Personal data is all information that relates to an identified or identifiable person. A data subject is a person whose personal data is processed. Processing includes any handling of personal data, irrespective of the means and procedures used, in particular the storage, disclosure, acquisition, deletion, storage, modification, destruction and use of personal data.
We process the personal data that is necessary to provide our services in an effective and user-friendly manner, as well as on an ongoing, secure and reliable basis. Part of the data is collected to ensure that the website is provided without errors. Other data can be used to analyse your user behaviour.
As a matter of principle, we process personal data only with the consent of the data subject, unless the processing is permissible for other reasons, for example to fulfil a contract with the data subject and for appropriate pre-contractual measures to protect our overriding legitimate interests, because the processing is clearly necessitated by the circumstances, or after giving prior information. In this context, we process in particular information that a data subject himself/herself submits when contacting us – for example by post, e-mail, contact form, telephone or social media – and we can store such information in a customer relationship management system (CRM system), in online shop software, the Rex-Royal Cloud telemetry solution (Wi-Fi / LAN or SIM) or with comparable tools.
We process personal data for the duration necessary for the respective purpose(s). In the event of longer-term storage obligations due to statutory and other obligations to which we are subject, we shall restrict processing accordingly.
We are present on social media platforms and other online platforms in order to communicate with customers and other interested parties and to inform them about our services. The General Terms and Conditions (GTC), privacy policies and other provisions of the respective operators apply in each case.
Legal basis for the processing of personal data
Processing of personal data
Rex-Royal AG collects and processes personal data from:
− Visitors to its websites, whether registered with Rex-Royal AG or not;
− Contact persons and employees of suppliers, dealers, vendors and suppliers of products and product parts from Rex-Royal AG;
− Customers, purchasers and recipients/beneficiaries or parties interested in the products and services of Rex-Royal AG or their contact persons and employees;
− Contact persons and employees of business partners and affiliated companies and other commercial and business partners;
− Recipients of the Rex-Royal AG newsletter;
− Participants in the market research and opinion polls conducted by Rex-Royal AG;
− Participants in the courses offered by Rex-Royal AG (especially commercial and technical training), seminars and other events;
− Users of the Wi-Fi offered by Rex-Royal AG in its business premises and other locations; (all together business partners).
The personal data of business partners is generally collected directly from the persons concerned in the course of using the websites, when requesting or using products or services, submitting reviews and reports, participating in market or other surveys, at events organised by Rex-Royal AG or in direct communication with Rex-Royal AG via e-mail, telephone or other means.
However, it may also be collected indirectly, namely when transactions are made for the benefit of a business partner or for delivery to one business partner by another business partner, on the recommendation of third parties (e.g. recommendation by acquaintances of the business partner) or by obtaining or purchasing additional information from third-party data sources (e.g. social media, address dealers).
In particular, Rex-Royal AG processes the following categories of personal data:
Personal data and contact information: This includes in particular, but not exclusively, first and last name, residential address, place of residence, telephone number, e-mail address, age, date of birth, gender, marital status, family members, any second contact details, photograph, details of the function, details of previous business dealings with these persons, details of business transactions, enquiries, offers, quotations, conditions and contracts, details of professional or other interests of the persons.
Data in connection with delivery and sale as well as purchase orders and purchase: This includes, but is not limited to, payment details, credit card details and other payment details, billing and delivery address, products and services delivered and sold as well as those ordered and purchased.
Data in connection with the marketing of products and services: This includes in particular, but not exclusively, information about marketing activities such as receipt of newsletters, newsletter opt-ins and opt-outs, documents received, invitations and participation in events and special activities, personal preferences and interests, etc.
Data in connection with the use of the websites: This includes, but is not limited to, IP address and other identifiers (e.g. user name in social media, MAC address of the smartphone or computer, cookies, web beacons, pixel tags, log files, local shared objects (flash cookies) or other technologies that automatically collect personal data), date and time of the visit or use of the websites, pages and content viewed, referring websites, etc.
Data related to communication: This includes, but is not limited to, the preferred channel of communication, correspondence, language of correspondence and communication with Rex-Royal AG (including records of communication), etc.
3. Transfer of data to third parties (incl. joint responsible persons and order data processors)
Your data will be transferred to our partners (third parties) as far as the order processing makes this necessary. If we pass on data to external service providers, technical and organisational measures are taken to ensure that the data is passed on in accordance with the legal provisions of data protection. If you provide us with personal or company-related data of your own accord, we will not use, process or pass on this data beyond the scope permitted by law or specified by you in a declaration of consent. In addition, we only pass on your data to external service providers as far as this is necessary for undertaking the contract, and if these external service providers have agreed to the corresponding confidentiality and due-diligence regulations. Furthermore, we will only pass on your data if we are obliged to do so by law or by official or court orders.
Cookies are used to log the frequency of use, number of users and behaviour on our website, to increase the security of website usage and to make our information offer user-friendly. You can configure your browser settings so that no cookies are stored on your computer.
In addition, we also use temporary cookies, which are stored on your device for a certain fixed period of time, to optimise user-friendliness. If you visit our site again to use our services, we will automatically recognise that you have already visited us before, and what entries and settings you have made, so that you do not have to enter them again.
If you deactivate cookies completely, this may mean that you will be unable to use all the functions of our website.
5. Analysis tools
5.1 Google Analytics
6. Social media plug-in
We use the following social plug-ins on our website to make our company better known. The publicity purpose behind this represents a legitimate interest in accordance with Art. 6 (1) (f) GDPR. The responsibility for data protection-compliant operation must be guaranteed by their respective providers. The data processing in connection with these plug-ins is carried out with your consent when you use these plug-ins.
If you use the services of these social networks independently or in connection with our website, the social networks will evaluate your use of the plug-in. In this case, information about the plug-in is forwarded to the social networks.
Our website uses plug-ins from the social network, Facebook, which is offered by Facebook Inc. The Facebook plug-ins are marked with a Facebook logo or the "Like" and "Share" supplements. An overview of the Facebook plug-ins and their appearance can be found at https://developers.facebook.com/docs/plugins.
When you call up a page of our website that contains such a plug-in, your browser establishes a direct connection to the Facebook servers. The content of the plug-in is transmitted by Facebook directly to your browser and integrated into the page.
Through this integration, Facebook receives the information that your browser has called up the corresponding page of our website, even if you do not have a Facebook profile or are not currently logged in to Facebook. This information (including your IP address) is transmitted by your browser directly to a Facebook server in the USA and stored there.
If you are logged in to Facebook, Facebook can immediately assign your visit to our website to your Facebook profile. If you interact with the plug-ins, for example, by clicking the "Like" button, this information is also transmitted directly to a Facebook server and stored there. The information is also published on your Facebook profile and displayed to your Facebook friends.
Plug-ins of the short message network, Twitter Inc., are integrated on our website. The Twitter plug-ins ("Tweet" button) can be recognised by the Twitter logo and the addition "Twitter". When you call up a page of our website that contains such a plug-in, a direct connection is established between your browser and the Twitter server. Twitter receives the information that you have visited our site with your IP address. If you click the Twitter button while logged in to your Twitter account, you can link the content of our pages on your Twitter profile. This allows Twitter to associate your visit to our site with your user account.
We would like to point out that we, as the provider of the pages, are not provided with any knowledge of the content of the transmitted data or its use by Twitter. You can find further information here: http://twitter.com/privacy.
Plug-ins of the social network, LinkedIn Corporation, USA, are installed on our website. You can recognise the LinkedIn plug-in ("LinkedIn Recommended" button) by the LinkedIn logo. When you call up a page of our website that contains such a plug-in, a direct connection is established between your browser and the LinkedIn server. LinkedIn receives the information that you have visited our site with your IP address. If you click the LinkedIn button while logged in to your LinkedIn account, you can link the content of our pages on your LinkedIn profile. This allows LinkedIn to associate your visit to our site with your user account. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by LinkedIn. You can find further information under: https://www.linkedin.com/legal/privacy-policy.
Plug-ins of the social network, XING SE, Germany, are installed on our website. You can recognise the Xing plug-in ("XING" button) by the XING logo. When you call up a page of our website that contains such a plug-in, a direct connection is established between your browser and the XING server. XING receives the information that you have visited our site with your IP address. If you click the XING button while logged in to your XING account, you can link the content of our pages on your XING profile. This allows XING to associate your visit to our site with your user account. We would like to point out that we, as the provider of the pages, have no knowledge of the content of the transmitted data or its use by XING. You can find further information under: https://www.xing.com/app/share?op=data_protection.
6.5 Google Maps
Google Maps services are used on our website (e.g. in-screen or via interfaces / API). Google LLC, USA, may therefore process information about your actual location. Google uses a variety of technologies to establish locations, including IP addresses, GPS and other sensors that provide Google with information about nearby devices, Wi-Fi access points, and mobile phone signal masts.
With your registration for our newsletter and your confirmation that you wish to receive the newsletter (double opt-in), the following personal data will be processed: Name, first name, e-mail address. The data is processed for the purpose of authenticating the subscriber at registration and sending a newsletter to the subscriber, to determine whether and when the subscriber has opened this newsletter and individual articles contained in it.
The data entered by you for the purpose of subscribing to the newsletter will be processed by MailXpert. The processing of this data is based exclusively on your consent. You can withdraw this consent at any time, e.g. via the "Unsubscribe" link in the newsletter. The data processing operations already carried out remain unaffected by this withdrawal of consent. When we send newsletters using MailXpert, we can determine whether a newsletter has been opened and which links have been clicked. MailXpert allows us to divide recipients into different categories. For further information, please contact https://www.mailxpert.ch/datenschutz.html. If you do not want to receive an analysis, you must unsubscribe from the newsletter.
8. Information, deletion and correction
You have the right to obtain information about the origin, recipient and purpose of your stored personal data at any time and free of charge. You also have the right to request the correction, blocking or deletion of this data. You can contact us at any time at the address given in the imprint regarding this and other questions on the subject of data protection. Furthermore, you have the right to appeal to the competent supervisory authority. You are of course also entitled at any time to revoke your consent to the use or processing of personal data with effect for the future. To do this, we kindly request that you send us an e-mail to firstname.lastname@example.org.
Stored data will be deleted by us when it is no longer required for the stated purpose.
With regard to the deletion of data, it should be noted that we are subject to certain legal obligations, which foresee an obligation to retain certain data. We have to comply with these obligations. If you wish data which is subject to the legal retention obligation to be deleted, the data will be blocked in our system and only used to fulfil the legal obligation to retain data. After expiry of the retention period, your request for deletion will be complied with.
9. Right to object
If your personal data is processed on the basis of legitimate interests or with your explicit consent, you have the right to object to the processing of your personal data if there are reasons relating to your specific situation or your objection to direct marketing. In the latter case, you have a general right of objection, which will be implemented by us without you having to refer to a special situation. An informal communication by e-mail to us is sufficient for this purpose. The legality of the data processing carried out up to the time of revocation remains unaffected by the revocation.
9.1 Right of appeal to the competent supervisory authority
In the event of violations of data protection law, the data subject has a right of appeal to the Federal Data Protection and Information Commissioner https://www.edoeb.admin.ch/edoeb/en/home.html.
10. Data security
We will keep your information secure and therefore take all reasonable steps to protect your information from loss, access, misuse or alterations. Our employees and contractual partners which have access to your data are contractually bound to secrecy and compliance with data protection regulations. In some cases, it may be necessary for us to pass on your enquiries to companies affiliated with us. Your data will be treated confidentially in these cases as well.
11. Contact details:
Person in charge:
Note on the person in charge: The person responsible for data processing on this website is: Rex-Royal AG, Peter L. Sager, Industriestrasse 34, Dällikon, CH-8108 Zurich, tel.: +41 44 847 5757, e-mail: email@example.com
Federal Data Protection and Information Commissioner , FDPIC, Feldeggweg 1, CH-3003 Bern
Dällikon, 29 June 2020, V1.3/MPE