Data Protection

1. General information on data processing

1.1. Purpose of the privacy policy
When you contact us, personal data is also processed which falls under the Data Protection Act (DSG) and the Data Protection Ordinance (DSV). This data includes, in particular, your name, address, email address, telephone number and personal information relating to contractual relationships with us. Technical data that can be linked to an individual (e.g. website cookies) is also considered to be personal data.

This Privacy Policy is intended to inform you about the nature, scope and purpose of our processing of personal data and to outline your rights.

1.2. Scope of the Privacy Policy
This Privacy Policy applies to all processing of personal data in connection with the activities described below.

1.3. Legal basis
The legal basis for our data processing is the Data Protection Act (DSG; SR 235.1) and the European General Data Protection Regulation (GDPR).

1.4. Data Protection-Compliant Organisation
To protect the data we manage against manipulation, loss, destruction or access by unauthorised persons, in accordance with the current state of the art, we implement appropriate technical and organisational measures and continuously improve them.

2. Data processing

2.1. Principles of our data processing
We process data exclusively in the manner prescribed by the relevant legal provisions. In particular, we observe the principles of lawfulness, proportionality and transparency in data processing and process data only within the scope of the intended purposes.

2.2. Data Processed
The personal data we process comprises all information worthy of protection that relates to an identified or identifiable natural person. Primarily, this consists of data which we receive in the course of our business relationships with customers, other business partners and other persons involved therein, or which we collect from users whilst operating our website(s), apps and other applications.

We process special categories of personal data within the meaning of Article 5(c) of the DSG only on a case-by-case basis and following the provision of the relevant consent (e.g. extracts from debt collection registers, credit reports, etc.).

Where permitted and necessary for our purposes, we also obtain certain data from publicly accessible sources (e.g. land registers, commercial registers, the press, the internet, etc.) or receive such data from public authorities and other third parties.

2.3. Purposes of data processing
We use the personal data we collect primarily to conclude and execute our contracts and transactions with you (our customers and business partners), in particular within the scope of our business purpose, and to process the associated procurement of products and services from our suppliers and subcontractors, as well as to comply with our legal obligations both domestically and abroad.

Furthermore, we process personal data relating to you and other individuals, to the extent permitted and where we deem it appropriate, for the following purposes, in which we (and occasionally third parties) have a legitimate interest commensurate with the purpose:

  • Offering and further developing our products, services and websites, apps and other platforms on which we are present;
  • Communicating with third parties and processing their enquiries (e.g. job applications, media enquiries);
  • Reviewing and optimising procedures for analysing needs for the purpose of directly addressing customers, as well as collecting personal data from publicly available sources for the purpose of customer acquisition;
  • Advertising and marketing (including the organisation of events), provided you have not objected to the use of your data (see right to object);
  • Market and opinion research, media monitoring;
  • Asserting legal claims and defending ourselves in connection with legal disputes and regulatory proceedings;
  • Prevention and investigation of criminal offences and other misconduct;
  • Ensuring the smooth running of our operations, in particular our IT systems, websites, apps and other platforms

Where you have given us your consent to process your personal data for specific purposes, we will process your personal data within the scope of and on the basis of this consent, provided that we have no other legal basis and that such a basis is required. Consent that has been given may be withdrawn at any time; however, this has no effect on data processing that has already taken place (see Right of Withdrawal).

2.3.4. Contractual Relationship
In the context of a contractual relationship with us, your personal data is collected in your capacity as a client to the extent necessary for the process. By providing personal data as the data subject, you consent to the processing of that data.

Personal data and documents relating to the contractual relationship are retained for ten years from the date of data collection, although we reserve the right to retain them for longer in individual cases, particularly in the event of legal disputes.

2.3.5. Job Applications
Your application documents and all personal data disclosed to us in this context will be treated as strictly confidential, will not be disclosed to any third party, and will be processed solely for the purpose of assessing your application for employment with us. Unless you consent otherwise, your application file will be either returned to you or deleted/destroyed once the application process has been completed, provided it is not subject to a statutory retention obligation. The legal bases for the processing of your data are your consent, the performance of the contract with you and our legitimate interests.

In particular, we process the following information:

  • Contact details (e.g. surname, first name, address, telephone number, email)
  • Personal information (e.g. occupation, role, title, employer)
  • Application documents (e.g. cover letter, certificates, diplomas, CV)
  • Assessment information (e.g. HR consultant evaluations, reference checks, assessments)

2.3.8. Cooperation with third parties / Disclosure of data abroad
We work with a wide range of partners to provide our services. A condition of this cooperation is that the data processors (third parties) must be in compliance with the DSG or GDPR. In individual cases, the relevant data protection provisions may differ from our own.

The disclosure of personal data to cooperation partners takes place within the scope and for the purpose of fulfilling our services and to the extent necessary for this. In particular, these are the following recipients:

  • Our service providers (both internal and external to the company, e.g. banks, insurance companies), including data processors (e.g. IT providers);
  • Retailers, suppliers, subcontractors and other business partners;
  • Customers;
  • Domestic and foreign authorities, government bodies or courts;
  • Competitors, industry organisations, associations and other bodies;
  • Purchasers or parties interested in acquiring business divisions, companies or other parts of the organisation;
  • Other parties involved in potential or actual legal proceedings.

These recipients may be located both domestically (in Switzerland) and abroad. If a recipient is located in a country without adequate data protection, we shall contractually oblige the recipient to comply with the applicable data protection regulations (for this purpose, we use the European Commission’s revised Standard Contractual Clauses) insofar as they are not already subject to a legally recognised framework for ensuring data protection and we cannot rely on an exemption. Such an exception may arise, in particular, from your consent, from disclosure required by legal proceedings abroad, or from the performance of a contract with you or third parties.

2.3.9. Customer Relationship Management (CRM)
Personal data in our CRM system comprises only the information necessary for contact or the business relationship (in particular, name, address, telephone number, email address).

2.3.10. Email correspondence
We retain our email correspondence with you for the duration of our business relationship and for a further ten years thereafter, unless a longer retention period is required. If it is merely an enquiry that does not result in a business or contractual relationship, we store our email correspondence with you for one year from the date of receipt of the last email in the thread.

2.3.11. Mailings by post and social media
For addressed advertising mailings sent by post, we use the personal data (name, address) that you have provided to us. The data may be passed on to a third party (advertising agency, printing company, etc.) for this purpose. By providing your personal data, we assume that you have given your consent. However, you may withdraw your consent at any time (see Right of Withdrawal).

For paid posts on social media (Facebook, Instagram, etc.), we use the contact details provided by the respective platforms.

2.3.12. Website
In addition to the domain “brunaplast.ch”, our website also includes project-related websites and services provided by service partners. Visitors to the website are not obliged to provide personal data unless we specifically indicate this in individual cases.

2.3.13. Server log files
Every time our website is accessed, we automatically collect a range of technical data which constitutes personal data. This includes, in particular:

  • IP address;
  • Name of the website or file accessed;
  • Date and time of access;
  • Confirmation of successful retrieval;
  • Browser type and version;
  • User’s operating system;
  • referrer URL (the page visited previously).

Server log files are not combined with other personal data. We collect server log files for the purpose of administering and improving the website, and to detect and prevent unauthorised access. Server log files are collected and analysed by our contractors (IT service providers).

The server log files containing the data mentioned above are deleted after 6 months at the latest, unless there is a legitimate interest or a service-related requirement. We reserve the right to store the server log files for longer if there are facts suggesting unauthorised access.

2.3.14. Cookies
We typically use cookies and similar technologies on our websites to identify your browser or device. Cookies are data stored by our websites via the browser on the user’s device. In addition to cookies that are only used during a session and are deleted after your visit to the website (so-called session cookies), we also use cookies to store user settings and other information for a specific period, which in individual cases does not exceed two years (so-called persistent cookies). In addition, we may also use so-called third-party cookies, which are managed by third parties in order to provide certain services.

The cookies we use serve, on the one hand, to enhance and improve the user-friendliness of our websites; on the other hand, they help us to collect statistical data on website usage and to use the data obtained in this way for analytical and advertising purposes.

You can control the use of cookies. Most browsers have an option that allows you to restrict or completely prevent the storage of cookies. However, please note that the use of our website, and in particular the user experience, will be limited without cookies. Furthermore, you can adjust the use of cookies when visiting our website via the relevant notice.

2.3.15. Data backups
For data security purposes, we regularly create backups of our business data, which are stored and retained on data storage media and cloud services provided by our IT service providers. The frequency of these backups is determined in accordance with their relevant recommendations.

2.4. Retention period for personal data
As a general rule, we process and store your personal data for as long as is necessary to fulfil our contractual and legal obligations or for the purposes otherwise pursued by the processing (in particular for the duration of the entire business relationship and beyond, in accordance with statutory retention and documentation obligations).

In doing so, we may retain personal data for as long as claims can be brought against our company, other legal obligations require us to do so, or legitimate business interests necessitate it.

As soon as your personal data is no longer required for the purposes stated, it will, as a general rule and where possible, be deleted or anonymised (see retention provisions for the individual processing purposes listed).

Shorter retention periods apply to operational data.

3. Your rights and obligations

  • Right to access the personal data we hold about you, the purpose of the processing, the source of the data, and the recipients or categories of recipients to whom the personal data is disclosed.
  • Right to rectification if your data is incorrect or incomplete.
  • Right to restriction of processing of your personal data
  • Right to request the erasure of the processed personal data
  • Right to data portability
  • Right to object to the processing of personal data or to withdraw consent to the processing of personal data at any time without giving reasons.
  • Right to lodge a complaint with a competent supervisory authority, where provided for by law.

To exercise these rights, please contact us at the address given above.

Please note, however, that we reserve the right to invoke the restrictions provided for by law, for example, if we are obliged to retain or process certain data, have an overriding interest in doing so (insofar as we are permitted to invoke this) or require it to assert claims. Should any costs be incurred by you, we will inform you in advance.

4. Changes

We may amend this Privacy Policy at any time and without prior notice. The current version published on our website shall apply.

21 August 2025