1. Introduction
Based on Article 13 of the Swiss Federal Constitution and the data protection provisions of the Federal Data Protection Act (DSG) and the EU General Data Protection Regulation (GDPR), every person has the right to privacy and protection from the misuse of their personal data. Protecting your personal data is important to us. You can expect us to handle your data with sensitivity and care and to ensure a high level of data security.
This privacy policy explains the collection and further processing of personal data by Westlake epi GmbH, unless it is evident from the circumstances or legally regulated.
2. Name and address of the controller
The responsible entity within the meaning of the Swiss Data Protection Act (DSG) and the EU General Data Protection Regulation (GDPR) is:
Westlake epi GmbH
Türlihof 1b
CH-6414 Oberarth SZ
Phone: +41 four one 850 51 41
Email: info (at) westlake-epi.com
Website: www.westlake-epi.ch
Westlake epi GmbH has not appointed a Data Protection Officer (DPO) within the meaning of Art. 10 DSG or Art. 37 GDPR. Any inquiries, claims, or requests related to data protection should be directed to the contact details above.
3. Categories of processed personal data
We may process the following categories of personal data in connection with our services:
- Master data: Basic information required to handle contractual and business relationships or for marketing purposes, such as first name, last name, gender, and place of residence.
- Communication data: Information exchanged via contact forms, email, phone, or other communication means, including phone numbers, email addresses, and the content of communications.
- Contract data: Information related to contracts, such as transaction details, orders, and complaints.
- Financial data: Payment information, billing, and shipping addresses.
- Marketing data: Information regarding marketing activities, such as receipt of newsletters, opt-ins, and event participation.
- Website usage data: IP addresses, user identifiers (e.g., cookies, social media usernames), and activity logs.
- Registration data: Data provided during registration for specific services, such as free Wi-Fi access.
- Behavioral and preference data: Information about your behavior and preferences that help us tailor our services to you.
- Voluntary data: Additional data provided voluntarily by you.
- Third-party data: Information provided by you regarding third parties, such as employees or subcontractors.
We collect personal data from the following groups (hereinafter referred to as "business partners"):
- Registered and non-registered visitors to our website.
- Contact persons and employees of manufacturers, suppliers, sellers, and customers.
- Recipients of newsletters, survey participants, and event attendees.
- Users of Wi-Fi services at our business locations.
4. Purpose of data processing and legal basis
We process business partners’ data—where permitted by applicable law—for the following purposes, including but not limited to:
- Contract execution and fulfillment: For the performance of contracts and handling of inquiries or orders (Art. 30 and Art. 31 para. 1 and 2(a) DSG / Art. 6 para. 1(b) GDPR).
- Website operation: For the management of website users and ensuring the security and performance of the website (Art. 30 and Art. 31 para. 1 and 2(b) DSG / Art. 6 para. 1(b) and (f) GDPR).
- Process and offer optimization: To improve our products, services, and internal processes (Art. 30 and Art. 31 para. 1 and 2(e) DSG / Art. 6 para. 1(a) and (f) GDPR).
- Marketing and advertising: For customer acquisition, customer loyalty programs, and market research (Art. 30 and Art. 31 para. 1 DSG / Art. 6 para. 1(a) and (f) GDPR).
- Security and access control: To ensure the security of our IT infrastructure and access control (Art. 30 and Art. 31 para. 1 DSG / Art. 6 para. 1(a) and (f) GDPR).
- Internal administration: For the efficient administration of the Westlake epi GmbH group (Art. 30 and Art. 31 para. 1 DSG / Art. 6 para. 1(b) and (f) GDPR).
- Compliance with legal and regulatory requirements: To fulfill our legal obligations, such as tax or record-keeping requirements (Art. 30 and Art. 31 para. 1 DSG / Art. 6 para. 1(c) GDPR).
- Business transactions: For the sale or acquisition of business units or parts of companies (Art. 30 and Art. 31 para. 1 DSG / Art. 6 para. 1(f) GDPR).
We process personal data for purposes other than those described only if permitted by law or with your consent.
5. Categories of data recipients
Your personal data may be shared with the following recipients without your prior consent:
- Group companies: A list of group companies can be found on our website.
- Public authorities: Where necessary to investigate unlawful activities or fulfill legal obligations.
- Contract processors: We rely on third parties for certain services, such as IT support, logistics, and payment processing. These processors are carefully selected and are contractually obligated to protect your data.
- Suppliers: Data related to orders may be shared with our suppliers.
6. Data transfer abroad
Your personal data is primarily processed in Switzerland. However, it may be transferred to trusted recipients in third countries (both within and outside Europe). Such transfers are based on appropriate safeguards, such as EU Standard Contractual Clauses, or where permissible by applicable law.
Please note that data transferred over the internet may pass through third countries even when both sender and recipient are located in the same country.
7. Retention period
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected or as required by law. This includes a retention period of up to 10 years for financial records, such as accounting documents and invoices.
8. Automated data collection and processing on our website
Our website uses the following technologies and tools, enabling us and third-party providers to recognize you during your visit and potentially track your activities:
- Cookies: Our website uses cookies to store specific information related to the user during their visit. Cookies allow us to analyze the usage of our website and improve our offerings. You can manage cookies via your browser settings.
- SSL/TLS encryption: For secure transmission of data, such as inquiries made through the website.
- Contact forms: Information provided through our contact forms is used to respond to inquiries.
- Google services (Maps, Ads, reCAPTCHA, Analytics): These services may collect and process data such as IP addresses and user interactions.
- Social media integration (LinkedIn, XING): For marketing and user tracking purposes.
- Mailchimp: For the delivery of newsletters.
- YouTube and Vimeo: To display video content.
- SurveyMonkey: For customer feedback and surveys.
- Microsoft Clarity: For website analysis and improvement.
- Google Fonts: To enhance the visual appearance of our website using web fonts.
- Google Tag Manager: To manage and deploy website tags efficiently.
9. Copyright
All copyrights and other rights to content, images, or data on our website belong to Westlake epi GmbH or the specifically named rights holders. Reproduction of any files requires prior written consent.
10. Disclaimer
We take great care to ensure the accuracy and completeness of the information on our website, but errors cannot be completely ruled out. We do not guarantee the accuracy, completeness, or timeliness of the information provided. We are not liable for any damages resulting from the use of the information provided unless there is proven intent or gross negligence.
11. Your rights
You have the following rights regarding your personal data:
- Right of access
- Right to rectification
- Right to restriction of processing
- Right to erasure
- Right to withdraw consent
- Right to data portability
- Right to object to data processing
You can exercise these rights by contacting us at the provided address or email.
12. Changes to this privacy policy
We reserve the right to update this privacy policy at any time. The current version published on our website applies.
13. Questions about data protection
For questions regarding data protection, please contact us via email or at the address provided at the beginning of this privacy policy.