Privacy Policy
July 2025
Data protection, data security, and the responsible handling of personal data are important concerns for Exista AG, Mettlenbachstrasse 23, 8617 Mönchaltorf, Switzerland (“Exista,” “we,” “us”). In most cases, our processing of personal data is subject to the provisions of the Swiss Data Protection Act (DSG) and the associated ordinance (DSV). For some occasional processing operations, the provisions of the EU General Data Protection Regulation (GDPR) may also apply directly.
In this privacy policy, we describe how we collect and process personal data (information that relates to a person and identifies them directly or indirectly) when you visit our website, use our applications, comment on our blog posts, enter into contracts with us, use our services, or otherwise interact with us.
1. General Data Protection
Based on Article 13 of the Swiss Federal Constitution and the federal data protection provisions (Data Protection Act, DSG), every person is entitled to protection of their privacy and protection against misuse of their personal data. The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
In cooperation with our hosting providers, we strive to protect the databases as best as possible against unauthorized access, loss, misuse, or falsification.
We would like to point out that data transmission over the Internet (e.g. when communicating by email) may be subject to security vulnerabilities. It is not possible to completely protect data from access by third parties.
By using this website, you consent to the collection, processing, and use of data as described below. This website can generally be visited without registration. Data such as pages accessed or names of files accessed, date, and time are stored on the server for statistical purposes without this data being directly related to your person. Insofar as personal data (e.g. name, address or email addresses) is collected on our website, this is always done on a voluntary basis as far as possible. This data will not be passed on to third parties without your express consent.
2. Collection and Storage of Personal Data, as well as the Nature and Purpose of its Use
a) When visiting the website
When you visit our website, the browser used on your device automatically sends information to our website server. This information is temporarily stored in a log file. The following information is collected without your intervention and stored until it is automatically deleted:
- Name of the file accessed
- Date and time of retrieval
- Amount of data transferred
- Message indicating whether the retrieval was successful
- Description of the type of web browser used
- Operating system used
- The previously visited page
- Provider
- Your IP address
We process the aforementioned data for the following purposes:
- Ensuring smooth connection to the website
- Ensuring convenient use of our website
- Evaluation of system security and stability
- as well as for other administrative purposes.
The legal basis for data processing is Art. 6 (1) lit. f GDPR. Our legitimate interest follows from the purposes listed above for data collection. Under no circumstances do we use the collected data for the purpose of drawing conclusions about your person.
In addition, we use cookies and analysis and marketing services when you visit our website. You can find more detailed information on this in sections 4–9 of this privacy policy.
b) Use of our contact/enquiry form
If you have any questions, you can contact us using the form provided on the website. You will need to provide your name and a valid email address so that we know who the enquiry is from and can respond to it. Further details can be provided voluntarily.
Data processing for the purpose of contacting us is carried out in accordance with Art. 6 (1) (b) GDPR on the basis of your specific request.
3. Disclosure of Data
Your personal data will not be transferred to third parties for purposes other than those listed below. We will only disclose your personal data to third parties if:
- You have given your explicit consent to this in accordance with Art. 6 (1) (a) GDPR,
- the transfer is necessary pursuant to Art. 6 (1) (f) GDPR and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data in the event that there is a legal obligation to transfer the data pursuant to Art. 6 (1) (c) GDPR,
- as permitted by law and as required under Art. 6(1)(b) GDPR for the performance of contractual relationships with you.
4. Cookies
We use cookies in some areas of our website. These file elements allow your computer to be identified as a technical unit during your visit to this website in order to make it easier for you to use our services, even on repeat visits.
You can usually set your Internet browser to notify you when cookies are used, allowing you to accept or reject them, or delete existing cookies.
Please use the help function of your Internet browser to obtain information on how to change these settings. Please note that individual functions of our website may not work if you have deactivated the use of cookies.
Cookies do not allow a server to read private data from your computer or data stored by another server. They do not cause any damage to your computer and do not contain viruses.
We base the use of cookies on Art. 6 (1) lit. f GDPR: processing is carried out to improve the functionality of our website. It is therefore necessary to safeguard our legitimate interests.
5. Use of Google Analytics
We use Google Analytics, a web analytics service provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google is certified under the Privacy Shield Agreement and thus offers a guarantee that it will comply with European data protection law (see https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active).
Google Analytics uses so-called “cookies”, text files that are stored on your computer and enable analysis of your use of the website. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there. However, due to the activation of IP anonymization on this website, your IP address will be truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there. On our behalf, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide us with other services related to website activity and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. You can prevent the storage of cookies by adjusting your browser software settings accordingly; however, we would like to point out that in this case you may not be able to use all functions of this website to their full extent.
You can also prevent Google from collecting the data generated by the cookie and relating to your use of the website (including your IP address) and from processing this data by Google by clicking on the following link (http://tools.google.com/dlpage/gaoptout?hl=en), downloading and installing the available browser plugin.
Further information on terms of use and data protection can be found at http://www.google.com/analytics/terms/de.html and https://support.google.com/analytics/answer/6004245?hl=en&sjid=3949073399020389736-EU.
We base the use of the aforementioned analysis tool on Art. 6 (1) (f) GDPR: processing is carried out for the purpose of analyzing usage behavior and is therefore necessary to safeguard our legitimate interests.
6. Use of Google Marketing Services
We use the marketing and remarketing services (hereinafter referred to as “Google marketing services”) provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Marketing Services uses cookies that are stored on your computer and enable us to display advertisements for and on our website in a more targeted manner, so that users are only shown ads that potentially match their interests. If, for example, you are shown ads for products that you have shown interest in on other websites, this is referred to as “re-marketing.” For these purposes, when you visit our website and other websites where Google Marketing Services are active, a code from Google is executed directly by Google and so-called (re)marketing tags are integrated into the website.
The information generated by the cookie or the tag about your use of this website is usually transferred to a Google server in the USA and stored there. However, due to the activation of IP anonymization on this website, your IP address will be truncated by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area. User data is therefore generally processed pseudonymously within the framework of Google marketing services. This means that Google does not store and process the name or email address of users, for example, but processes the relevant data in relation to cookies within pseudonymous user profiles. This means that, from Google's perspective, the ads are not managed and displayed for a specifically identified person, but for the cookie owner, regardless of who that cookie owner is. This does not apply if a user has expressly permitted Google to process the data without this pseudonymization. The information collected by Google marketing services about users is transmitted to Google and stored on Google's servers in the United States.
The Google marketing services we use include the online advertising program “Google AdWords.” In the case of Google AdWords, each AdWords customer receives a different “conversion cookie.” Cookies cannot therefore be tracked across the websites of AdWords customers. The information collected using the cookie is used to generate conversion statistics for AdWords customers who have opted for conversion tracking. AdWords customers learn the total number of users who clicked on their ad and were redirected to a page tagged with a conversion tracking tag. However, they do not receive any information that can be used to personally identify users.
We may integrate third-party advertisements based on the Google marketing service “DoubleClick.” DoubleClick uses cookies that enable Google and its partner websites to display advertisements based on users' visits to this website or other websites on the Internet.
Furthermore, we may use Google Tag Manager to integrate and manage Google analytics and marketing services on our website.
For more information about Google's use of data for marketing purposes, please visit the overview page: https://policies.google.com/technologies/ads?hl=en, Google's privacy policy is available at https://policies.google.com/privacy?hl=en.
If you wish to object to interest-based advertising by Google marketing services, you can use the settings and opt-out options provided by Google: www.google.com/ads/preferences.
We base the use of the aforementioned marketing service on Art. 6 (1) (f) GDPR: processing is carried out for the purpose of improving our products and designing target group-specific advertising and is therefore necessary to safeguard our legitimate interests.
7. LinkedIN
Our website incorporates plugins from the social network LinkedIn, operated by LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA (hereinafter referred to as “LinkedIn”). You can recognize the LinkedIn plugins by the LinkedIn logo or the “Recommend” button on our website. When you visit our pages, the plugin establishes a direct connection between your browser and the LinkedIn server. LinkedIn thereby receives the information that you have visited our site with your IP address. If you click on the LinkedIn “Recommend” button while you are logged into your LinkedIn account, you can link the content of our pages to your LinkedIn profile. This allows LinkedIn to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the data transmitted or its use by LinkedIn. Details on data collection (purpose, scope, further processing, use) as well as your rights and setting options can be found in LinkedIn's privacy policy. This policy can be found at: http://www.linkedin.com/legal/privacy-policy
8. YouTube
We use a plug-in from YouTube, which is owned by Google Inc. LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. As soon as you visit a page on our website that has a YouTube plug-in, a connection to the YouTube servers is established. The YouTube server is informed which page of our website you have visited. If you are logged in with your YouTube account, this would enable YouTube to assign your surfing behavior to your personal account. Further information on the collection and use of your data by YouTube can be found at https://policies.google.com/privacy?hl=en
9. Live Chat-Support
Exista uses a live chat service provided by Userlike UG (limited liability), Probsteigasse 44-46, 50670 Cologne, Germany, on its website userlike.com. You can use the live chat like a contact form to chat with our employees in near real time. Personal data is collected when you start the chat.
- Date and time of access,
- Browser type/version,
- IP-Address,
- Operating system used,
- URL of the previously visited website,
- Amount of data sent,
- First Name, Name
- E-Mail Address
Depending on the course of the conversation with our employees, further personal data may be collected in the chat, which you enter yourself. The type of data collected depends largely on your enquiry or the need you describe to us.
All our employees have been and continue to be trained in data protection and instructed in the secure and trustworthy handling of customer data. All our employees are bound to confidentiality and have signed a confidentiality and data protection clause in their employment contracts.
By visiting the website www.exista.ch the chat widget is loaded from AWS Cloudfront in the form of a JavaScript file. The chat widget essentially represents the source code that runs on your computer and enables chat.
In addition, Exista stores the history of live chats. This serves the purpose of saving you from having to provide extensive details about the history of your request and to ensure consistent quality control of our live chat service. If you do not wish this to happen, please let us know using the contact details listed below. We will then delete the stored live chats immediately.
10. Newsletter and Mailchimp
If you would like to subscribe to the newsletter offered on the website, we require your email address and information that allows us to verify that you are the owner of the email address provided and that you agree to receive the newsletter. No further data is collected. We use this data exclusively for sending the requested information and do not pass it on to third parties. You can revoke your consent to the storage of data, your email address, and its use for sending the newsletter at any time, for example via the “Unsubscribe” link in the newsletter.
When you subscribe to the newsletter, you provide your email address and can enter your name. In addition, your IP address and the date of registration are also stored during registration, the latter only for evidence purposes in the event of misuse. We use the list provider MailChimp to send our newsletter. MailChimp is a service provided by The Rocket Science Group, LLC, 512 Means Street, Suite 404, Atlanta, GA 30318 (“Rocket”). The data required for sending the newsletter is transmitted to Rocket in encrypted form and stored by Rocket. Furthermore, MailChimp offers various analysis options on how the newsletters sent are opened and used, e.g., how many users an email was sent to, whether emails were rejected, and whether users unsubscribed from the list after receiving an email. We do not use these analyses for individual evaluation. MailChimp also uses the Google Analytics analysis tool from Google, Inc. and may integrate it into the newsletters. Further details on MailChimp's data protection policy www.mailchimp.com/legal/privacy/.
11. SSL Encryption
This site uses SSL encryption for security reasons and to protect the transmission of confidential content, such as requests you send to us as the site operator. You can recognize an encrypted connection by the fact that the address line of the browser changes from “http://” to “https://” and by the lock symbol in your browser line.
12. Rights of Affected Persons
You have the following rights as an affected person (data subject):
a) Right to Information
You have the right to request confirmation from us as to whether personal data concerning you is being processed.
b) Correction/deletion/restriction of Processing of Data
Furthermore, you have the right to request that
- incorrect personal data concerning you is corrected immediately (right to rectification)
- personal data concerning you is deleted immediately (right to erasure)
- processing is restricted (right to restriction of processing).
c) Right to Data Portability
You have the right to receive personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format and to transmit this data to another controller.
d) Right of Withdrawal
You have the right to withdraw your consent at any time. Withdrawing your consent does not affect the lawfulness of processing based on consent before its withdrawal.
e) Right to Object
If the processing of personal data concerning you is necessary for the performance of a task carried out in the public interest (Art. 6 (1) (e) GDPR) or to safeguard our legitimate interests (Art. 6 (1) (f) GDPR), you have the right to object.
f) Right of appeal
If you perceive that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, without prejudice to any other legal remedies.
13. Changes to the Privacy Policy
We reserve the right to amend this privacy policy in the event of any changes to the legal situation, the service, or data processing. However, this only applies to statements regarding data processing. If user consent is required or if parts of the privacy policy contain provisions governing the contractual relationship with users, changes will only be made with the consent of the users.
Users can regularly check this privacy policy for any changes.
14. Contact
Our company data protection officer can be contacted at the official address or at the following email address: datenschutzbeauftragter@exista.ch.