Data protection
Principles of processing and
protecting your personal data
Privacy Policy
Thank you for your interest in our company. Swiss Pension & Investment Group AG (hereinafter: “SPIG”) attaches great importance to data protection and therefore strives to put in place suitable security measures. In this Privacy Policy, we set out how and why we (a) collect your personal data when you visit our website www.spig.ch (“SPIG Website”) and (b) process this data (e.g. store, use, transfer, etc.) within the scope of our services, as well as your rights in this context under data protection legislation.

In principle, it is possible to use the SPIG Website without providing any personal details. However, if you would like to make use of certain services via our website, processing your personal data may be required. Personal data includes all details of personal or factual matters which relate to a specific or identifiable natural person (e.g. name, address, email address, etc.). In this Privacy Policy, we use the terms “your data” or “your personal data” to refer to this data. We are committed to treating your personal data responsibly.

Accordingly, we consider compliance with the Swiss Federal Act on Data Protection (Data Protection Act, “FADP”), the accompanying ordinance (Data Protection Ordinance, “DPO”) and any other Swiss data protection regulations that may apply as a matter of course. This Privacy Policy is intended to inform you of the most important aspects of data processing at SPIG and about your rights under data protection law. This Privacy Policy covers the collection of personal data both online and offline, including data which we have received from different sources, e.g. from websites, social media, customers, sales partners and third-party providers.

This Privacy Policy is divided into two sections: a general section on data processing and a section dedicated to the website. Please note that this Privacy Policy does not contain a comprehensive description of our data processing activities, and individual matters may, either in part or wholly, be governed through specific privacy policies, the General Terms and Conditions or similar documents (with or without reference in this Privacy Policy).
1 Controller
The data controller within the meaning of data protection legislation is the management company:

Swiss Pension & Investment Group AG (“SPIG” or “we”)
Dammstrasse 23
CH-6300 Zug
‍
Tel.: +41 58 411 11 99
Email: datenschutz@spig.ch  If you have any concerns or questions concerning data protection in relation to our website or this Privacy Policy, please contact us via: datenschutz@spig.ch.
1.1 External Data Protection Consultant
The contact information for our external data protection consultant is as follows:

Swiss Infosec AG
Centralstrasse 8A
6210 Sursee

Email: infosec@infosec.ch
2 General data protection
2.1 Personal data processed by us
SPIG processes various types of personal data. This includes, in particular, personal data:
  • that we receive as part of our business relationships from interested parties, service providers, sales partners or other persons involved in our business relationships;
  • that we receive via contact forms or other forms;
  • that we receive in the context of a power of authority;
  • that we are legally or contractually obliged to collect;
  • that we collect during use of our website;
  • that we receive from authorities and other third parties (e.g. address brokers, credit agencies).
Depending on the nature of the relationship, we process personal data pertaining to you such as:
  • Contact, inventory and identification data such as surname, first name, address, email address, telephone number;
  • Personal details  such as date of birth, sex, nationality, marital status, language;
  • Details on third parties  such as information about relatives;
  • Contractual data  such as contract type, contract content, type of products and services, applicable terms and conditions, contract start, contract term, billing data and information about other insurance policies;
  • Financial and operational data  such as account information, payment information, payment history, credit history information;
  • Metadata from telecommunications such as telephone number, date, time and duration of connection, type of connection, location data, IP address, device identification numbers such as MAC address;
  • Interaction and usage data: correspondence, preferences and target group information, end device type, device settings, operating system, software, information arising from the assertion of rights;
    Website information: IP address, cookie information, browser settings, frequency of visits to the website, duration of visits to the website, search terms, clicks on content, referring website.
2.2 Purposes for which we process personal data
We primarily collect and process your data when visiting our website in order that we can provide you with a user-friendly and secure website including its content and services. When you contact us via a suitable channel (e.g. by email, telephone or in person), we make a record of the communication between you and us and of the personal data transferred to us in this context, for the purposes of that communication.

Additionally, where permitted and where we consider it prudent, we also process personal data pertaining to you and other persons for the following purposes, in respect of which we (and occasionally also third parties) have a legitimate interest corresponding to the purpose:
  • Offering and further developing our services, website and other platforms on which we have a presence;
  • Communication and processing enquiries (e.g. via email, telephone, job applications);
  • Advertising and marketing, provided you have consented to the use of your data;
  • Market research, media monitoring;
  • Exercising legal rights and preparing a defence in relation to legal disputes and official proceedings;
  • Any corporate transactions affecting SPIG and the associated transfer of personal data;
  • Preventing and investigating criminal offences and other misconduct (e.g. carrying out internal investigations, data analyses for anti-fraud measures);
  • Complying with legal and regulatory obligations and internal SPIG directives;
  • Maintaining our operations, in particular IT, our website and other platforms.
2.3 Legal basis for processing
  • consent, provided you have granted us with this, to process your personal data for specific purposes. We process your personal data within the framework of and based upon this consent, provided we have no other basis and we require such a legal basis. Consent that has been granted can be revoked at any time; however, this has no impact on data processing activities that have already been carried out. Consent can be revoked by email to the (email) address specified in Section 1.
  • a statutory basis,
  • the conclusion or fulfilment of a contract,
  • a legal obligation (for example, in the case of evidence or information subject to a time-restricted retention obligation).
2.4 Third parties to which we disclose and transfer personal data
If your personal data is not processed by us, but by a processor or other controller, the third parties confirm to us that they comply fully with the legal provisions. Data is principally only disclosed to third parties if:
  • this is required to create the contract entered into with you,
  • disclosure is permitted due to a balancing of interests,
  • we are legally obligated to disclose data, or
  • you have granted us your consent.
Provided it is permitted and prudent, we also disclose personal data to third parties as part of our business activities and for the above-mentioned purposes, be that because these parties process the data for us (outsourcing of data processing) or because they intend to use the data for their own purposes (disclosure). These third parties include the following in particular (hereinafter collectively referred to as “recipients”):
  • service providers, including processors instructed by us to process and store your data (e.g. IT providers), send and receive emails, offer and develop certain functions in connection with our website and for research, analysis, maintenance and security services in connection with our website;
  • our auditor;
  • experts;
  • specialists and other service providers;
  • advisers instructed by us, such as our lawyers;
  • business partners (e.g. brokers and sales partners), logistics partners, debt collection partners, external mailing service providers;
  • authorities (supervisory and tax authorities);
  • insurers (e.g. for the reinsurance of risks);
  • banking institutions and payment service providers;
  • government offices and courts;
  • other parties in potential or actual legal proceedings.
Recipients are sometimes based domestically, but sometimes also based abroad. You must, in particular, anticipate that your data will be transferred to other European countries and the US where some of the IT service providers used by us are located. When we, by way of an exception, transfer data to a country in which there is no adequate level of statutory data protection (such as the US), we request that the Recipient implements adequate measures to protect personal data (e.g. through the agreement of so-called EU Standard Contractual Clauses, current version available here, other precautions or based on grounds of justification).
2.5 Duration of data processing
We process personal data for as long as required for the fulfilment of our contractual obligations or otherwise for the purposes pursued through the processing, for example for the entire duration of the business relationship (from acquisition, processing up to termination of a contract) and beyond as per statutory retention and documentation obligations. In this context, it is possible that personal data will be stored for as long as claims can be asserted against us and to the extent that we are otherwise legally obligated to do so or legitimate interests require this (e.g. for evidence and documentation purposes). As soon as your personal data is no longer required for the above-mentioned purposes, it will, in principle, be deleted or anonymised.
2.6 Place of processing
As a basic principle, we process personal data exclusively in Switzerland or, in exceptional cases, in an EU/EEA country or in another country which upholds adequate data protection.
3 Specific data protection provisions: visits to our website
As a general rule, you can use our website without the need to provide details about your person. This does not include areas and services which, by their very nature, require your name, address or other personal details, for example subscribing to the newsletter. Additionally, you may contact us voluntarily by email or telephone. Your personal details will be collected and transferred to us in the course of this. When you use the relevant features, we also process your personal data:
  • to contact you (e.g. arrange an appointment, deliveries, etc.)
  • for electronic mailing (e.g. receipt of information via email)
  • data storage via OneDrive
3.1  Server log files
When you visit our website, our servers save each access in server log files. The information collected includes, for example, your IP address, the date and time of your visit, the name of the file accessed, access status (successful, partially successful, unsuccessful, etc.), web browser used and operating system, as well as other similar information used to avert danger in the event of attacks on our information technology systems.

Before we store your IP address, this is anonymised and is not combined with other data. No analyses which would enable inferences to be made as to your identity are carried out, nor is your personal data in the server log files linked to any other personal data that may be stored about you. This information is processed in order to correctly display our website and its content and offers and to secure the data traffic, to optimise our website, content and offers, to continually guarantee the stability and security of our website and systems and to enable the investigation, prevention and prosecution of cyber attacks, spam and other illegal actions in relation to our website and systems and enforce claims in relation to these actions. We delete your personal data as soon as it is no longer required to achieve the purpose for which it was collected.

In the case of data which is recorded for the purpose of providing our website, this data is deleted once the relevant session ends. We may use third-party services based in Switzerland and abroad to host the website and carry out the above mentioned processing on our behalf. Our websites are currently hosted exclusively by Swiss hosting providers and on servers located in Switzerland.
3.2 Making contact

On our website, you have the option to contact us by email or by phone. When you contact us, the personal data transferred to us in the course of this contacting (e.g. email address, name, etc.) is recorded, stored and used to respond to your query.

We store your details to process and resolve your query and for the event there are any follow-up questions; your data is not disclosed to unauthorised third parties without your consent. As a matter of course, the same also applies to queries received by post. You may object to this data processing within the scope of the options available to you under statutory provisions.

Please send your objection to the (email) address specified in Section 1 and we will review your query. In such cases, your attempt to contact us will not be processed further. Your personal data will be deleted as soon as your query has been resolved. This is deemed the case when it can be ascertained from the circumstances that the issue in question has been conclusively resolved and deletion of the data does not conflict with any statutory retention obligations.
3.3 Cookies

We use cookies on our website. Cookies are small text files which are placed and stored on your end device (laptop, tablet, smartphone or similar) by means of your browser. They are designed to make both our website more user friendly and effective, and to ensure your visit to your website is as pleasant as possible. The majority of the cookies we use are known as session cookies. These are automatically deleted once you log out or close your browser.

Other cookies remain stored on your end device beyond each use of the website and enable us or our partner companies (third-party cookies) to recognise your browser on your next visit. Insofar as other cookies (e.g. cookies for analysing your surfing habits) are stored, these are addressed separately in this Privacy Policy (see subsection 3.4). You can configure your browser to notify you when cookies are enabled and to allow cookies to be accepted only on a case-by-case basis or to block them altogether. Please note that, in such cases, you may not be able to use all the features of our website.

3.4 Google services

Our website uses various services of Google LLC, headquartered in the US, or, if your usual place of residence is in the European Economic Area (EEA) or Switzerland, Google Ireland Ltd., headquartered in Ireland (“Google”). We use the following Google services on our websites:
  • Google Tag Manager
  • Google Analytics
  • Google Maps
Further information on the individual services is found below.

Google uses technologies such as cookies, web storage in the browser and tracking pixels, which enable an analysis of your use of our website. The resulting information generated about your use of our website may be transferred to a Google server in the US or other countries and stored there. You can find information about the locations of Google’s data centres here.

We use tools provided by Google which, according to Google, may process personal data in countries in which Google or its subcontractors maintain premises. In its “Data Processing Addendum for Products where Google is a Data Processor”, Google promises to guarantee an adequate level of data protection by making use of EU Standard Contractual Clauses. You can more detailed information on processing by Google and on privacy settings in Google’s Privacy Policy and privacy settings.

3.4.1. Google Tag Manager

Our websites use the Google Tag Manager. Google Tag Manager enables efficient management of website tags. Website tags are placeholders which are embedded in the source code of a website to track, for example, the inclusion of frequently used website elements, such as code for web analytics services. Google Tag Manager triggers other tags which may themselves collect data under certain circumstances. Google Tag Manager does not have access to this data. If deactivation has been carried out at domain or cookie level, this remains in effect for all tracking tags implemented using Google Tag Manager.

You can find more information in the Google Tag Manager Terms of Service.

3.4.2 Google Analytics

We use the web analytics service Google Analytics 4 to analyse our website and its visitors, as well as for marketing and advertising purposes. Google Analytics uses cookies which are stored on your end device (laptop, tablet, smartphone or similar) and enable an analysis of your use of our website. This enables us to evaluate user behaviour on our website and to make our offering more interesting based on the statistics/reports generated. We use the User ID feature. Using User ID, we can assign one or more sessions (and the activities carried out during these sessions) a unique, permanent ID and analyse user behaviour across devices. With Google Analytics 4, anonymisation of IP addresses is activated by default. This means that Google will truncate your IP address within Switzerland or the EU/EEA prior to transfer.

Only in exceptional cases will your full IP address be transferred to a Google server and truncated there. Google uses this information to evaluate your use of our website, compile reports on website activities and provide us with other services related to website and internet usage. According to Google, the IP address transmitted by your browser as part of the Google Analytics service is not combined with other data held by Google. When visiting our website, your user behaviour is recorded in the form of events (e.g. page views, interaction with the website or your “click path”) as well as other data like your approximate location (country and town/city), technical information about your browser and the end devices you use or the referrer URL, i.e. the website/advertisement via which you landed on our website.

You can prohibit the collection and transfer of the data generated by the cookie and relating to your use of our website (including your IP address) to Google and the processing of this data by Google by downloading and installing the Google Analytics Opt-Out Browser Add-On. If you would like to deactivate personalised advertising by Google, you can use the settings and opt-out options provided by Google. An overview of how the Google Analytics service uses data and the measures Google implements to protect your data can be found in the Google Analytics Help Center. You can find further information on the Google Analytics Terms of Service and Google’s Privacy Policy in the relevant documents.
3.4.3 Google Maps

This website uses the Google Maps API service, a map service from Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. This enables us to display interactive maps directly on the website and ensure convenient use of the map function. The legal basis for the processing is derived from your consent, based on voluntarily providing information to generate a route plan, and our legitimate interest in presenting our location and ensuring the location provided on our website is easy to find. It is possible for the use of Google Maps to result in information about the use of website, including your IP address, being sent to a Google server in the US and stored there. Google may transfer information obtained through Google Maps if this is stipulated by law or if third parties are to process this data on behalf of Google.

Under no circumstances will Google link your IP address with other data held by Google. Nevertheless, it is technically possible for Google to identify at least some individual users based on the data received. It is possible that Google may use personal data and user profiles of visitors to the website for other purposes, over which we have no control and cannot exert any influence. It is possible to deactivate Google Maps and prevent transfers of data to Google by deactivating JavaScript in your browser. However, please note that this will mean you are unable to use the map view. You can find more information on the purpose and scope of data collection and processing by Google as well as more details on your rights and settings options to protect your privacy here: https://policies.google.com/privacy.
3.5 Social media presence

We maintain a social media profile on LinkedIn.  

The data you provide on our social media profiles is published by the social media platform and is not used or processed by us for other purposes at any time. However, we reserve the right to delete content if so required. If necessary, we will communicate with you via the social media platform. Please be aware that the operator of the social media platform uses web tracking methods. Web tracking, over which we have no control, may also be carried out regardless of whether you are logged into or registered with the social media platform.

You can find more details on data processing and on your related rights and privacy protection settings options, as well as your right to object to the creation of user profiles by the provider of the social media platform, in the privacy policy of the relevant provider:

‍LinkedIn Corporation (USA)/LinkedIn Ireland Unlimited Company (Ireland) Privacy Policy
3.6 Link to third-party websites

Some links on this website lead to third-party websites. These websites are no longer under the control of SPIG. Consequently, SPIG accepts no responsibility for the accuracy, completeness and legality of the content of these websites and links to other websites as well as any offers, products and services contained on these websites. The user is responsible for the use of linked websites.

Please note that, when you click on a link to a website of a third-party provider (e.g. Google, social media platform or other websites), you will be directed to a website that we do not control, and our Privacy Policy is no longer applicable. Your surfing activities and interactions on another website are subject to the terms of use and privacy policies and notices of these third-party websites.

Moreover, we cannot guarantee that these links are correct and up to date. We recommend reading through the terms of use and privacy policies and notices of other websites carefully before transferring personal data via these websites. We are not responsible or liable for the information content and data processing on such third-party websites.
4 Data security
We implement state-of-the-art technical and organisational security measures to protect your personal data against manipulation, loss, destruction and access by unauthorised individuals.

Furthermore, we have embedded technologies within our website which ensure the confidentiality, integrity and authenticity of your data.

Together we external experts, we continually optimise our security measures in accordance with technological developments. Our employees and the service providers instructed by us are obligated to maintain confidentiality and to comply with data protection provisions. Moreover, these parties will only have access to your personal data if required.
5 Your rights
As a visitor to our website, as a basic principle you have a right of access, rectification, erasure, restriction, data handover and data portability, objection to processing and revocation of consent with regard to your personal data. However, please note that we reserve the right to assert limitations provided for by law, for example where we are obligated to retain or process certain data, have an overriding interest in doing so (insofar as we are permitted to invoke such interest) or require such data to assert legal claims.

Please note that exercising these rights may conflict with contractual arrangements, which can lead, for example, to the premature cancellation of the contract or to cost implications. In such cases, we will inform you in advance where this is not already contractually regulated. If you believe that the processing of your personal data is in breach of data protection law or your rights under data protection law have otherwise been breached, you can file a complaint with the Federal Data Protection and Information Commissioner (FDPIC; https://www.edoeb.admin.ch/en/).

Generally, any assertion of your rights under data protection law requires that you conclusively verify your identity (e.g. by providing a copy of your passport if your identity is otherwise not clear or cannot be verified). To assert your rights, please contact us via the (email) address specified in Section 1.

Swiss Infosec AG
Centralstrasse 8A
6210 Sursee

6 General Data Protection Ordinance (“GDPR”)
We process personal data in accordance with Swiss data protection law. To the extent that the GDPR is applicable, we also process personal data based on this legislation. In addition, this Section 6 applies exclusively for the purposes of the GDPR and the data processing activities covered by it.

In particular, we base the processing of your personal data on the fact that:
Please note that, in principle, we process your data for as long as our processing purposes (see subsection 2.2), statutory retention periods and our legitimate interests, in particular for documentation and evidence purposes, so require or for as long as storage is necessary for technical reasons (e.g. in the case of backups or document management systems).

If no legal or contractual obligations or technical reasons so preclude, we generally delete or anonymise your data upon expiry of the storage or processing period in the course of our usual processes and in accordance with our data retention guidelines. If you do not specify certain personal data, this may mean it is not possible to provide the related services or conclude a contract. We will generally indicate when the personal data we request is mandatory. The right as specified in Section 10 to object to the processing of your data applies in particular to data processing for direct marketing purposes. If you do not consent to the way in which we handle your rights or your data protection, please contact us (see contact details in Section 1).

If you are located in the EEA, you also have the right to file a complaint with the data protection supervisory authority in your country. A list of authorities in the EEA can be found here: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.

SPIG
‍Swiss Pension & Investment Group AG
Dammstrasse 23
6300 Zug
SWITZERLAND