LEGAL
Privacy Policy
Last updated: 2 August 2026
1. What is this Privacy Policy about?
Via Schweiz GmbH (also referred to below as “we” or “us”) collects and processes personal data relating to you or other persons (“third parties”). In this Privacy Policy, “data” means personal data.
This Privacy Policy describes what we do with your data when you use via-schweiz.ch or other websites operated by us (collectively, the “Website”), obtain consulting or other services from us, have a contractual relationship with us, communicate with us, or otherwise deal with us. Where necessary, we will inform you in good time and separately about additional processing not described here, for example in consent forms, contractual terms, additional privacy notices, forms, or other notices.
This Privacy Policy is designed to meet the requirements of the Swiss Federal Act on Data Protection (“FADP”) and the EU General Data Protection Regulation (“GDPR”). Whether and to what extent these laws apply depends on the individual case.
2. Who is responsible for processing your data?
Unless otherwise stated in an individual case, the controller responsible for the processing described in this Privacy Policy is:
Via Schweiz GmbH, Roosstrasse 53, 8832 Wollerau, Switzerland, email: info@via-schweiz.ch
You can contact us using the details above for privacy matters and to exercise your rights under section 11.
3. What data do we process?
We process different categories of data about you. The main categories are:
You provide many of these data to us yourself, for example through forms, when communicating with us, or in connection with a contract. Subject to individual cases, you are not obliged to provide them. However, if you wish to receive consulting services or enter into a contract with us, you must provide the data required to process your request and perform the contract. Processing technical data is unavoidable when merely using our Website.
Our employees’ access to these data is restricted through our CRM. Authorised employees may in particular see contact and profile details, interests, campaign information, consent, communication history, AI analysis, notes, processing status and, where available, contractual information.
- Technical data (visitor data): When you access our Website, our hosting and security providers process technically necessary connection data, in particular the IP address, page accessed and access time, browser and device details, language, approximate origin derived from the IP address, referring page, campaign parameters, and fraud and abuse detection signals. We do not store IP addresses in our own first-party analytics. In rate-limit records, the IP address is immediately converted into a pseudonymous keyed hash. First-party analytics is activated only after you consent to the Analytics category and uses pseudonymous identifiers. In individual cases, technical data may be linked with other data categories and therefore with you.
- Request and consulting data: If you request a consultation through our Website, we process the information you provide, including title, name, email address, telephone number and date of birth and, depending on the request, your interests, desired timeframe, household details, relevant canton, optional income information, free-text comments and privacy settings. Our system also generates lead and reference identifiers, an encrypted contact record, and hashes of your email address and telephone number to detect duplicate submissions.
- Communication data: When you contact us through a request or contact form, by email, telephone, post, or another channel, we record the content exchanged, your contact details, and communication metadata. Emails, attachments, and sender and recipient details are stored in the relevant mailboxes in our Google Workspace environment. Where we need to verify your identity, we collect suitable evidence.
- Processing and CRM data: To handle your request and manage the customer relationship, our CRM contains a processing history, including security-check results, processing status, timestamps, internal notes, the responsible person, actions taken, and communication history. We also create AI-assisted analyses; see section 6.
- Contract and financial data: If you enter into a contract with us, we process the related contract and financial data, such as details of the agreed service, performance of the contract, and financial administration.
4. For what purposes do we process your data?
We process your data for the purposes below. These also constitute our legitimate interests and, where applicable, those of third parties; further information on legal bases is provided in section 5.
For customer communications—including consultation confirmations, appointments, follow-up messages, messages from our advisers, and internal communications—we use the Gmail API and Google Workspace.
- Provision and security: Operating the Website, saving your privacy settings, and preventing spam, fraud, and abuse.
- Consulting and support: Receiving, assessing, and prioritising requests, validating contact information, providing consultations, and carrying out follow-up activities.
- Customer relationship management: Scheduling appointments, maintaining customer files, administering contracts, and financial administration.
- Measurement and optimisation: Measuring Website and business development and attributing campaigns where permitted.
- Legal obligations: Complying with legal requirements and establishing, exercising, or defending legal claims.
5. On what basis do we process your data?
Where we ask for consent to particular processing, such as the Analytics and Marketing technologies in section 12, we inform you separately about the relevant purposes. You may withdraw consent at any time with effect for the future, in writing or, unless stated otherwise, by email using the contact details in section 2; for online tracking, see section 12. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Where we do not ask for consent, we rely on the processing being necessary to take steps toward or perform a contract with you, or on our or third parties’ legitimate interests, particularly the purposes described in section 4. Our legitimate interests also include compliance with legal requirements where this is not already recognised as a separate legal basis.
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. The AI-assisted analysis under section 6 prepares and supports decisions made by our employees.
6. AI-assisted analyses
To process and prioritise requests efficiently, we use an artificial intelligence service (Google Vertex AI using the Gemini model). We have designed this processing so that only selected information is made available to the service.
Request analysis: Incoming requests are analysed to prioritise and prepare the consultation. Only interests, timeframe, household size, relevant canton, optional annual-income information, and campaign data are transmitted—not decrypted identity data or free-text comments. The output is a priority (high, medium, or low), reasoning, a short summary, a consultation briefing, and a recommended action, which are stored with the relevant lead.
Email-reply analysis: At the request of an authorised employee, the service may analyse an incoming email reply. The reply text is processed together with the lead profile and campaign data to produce a category, sentiment, urgency, summary, recommended action, and draft reply.
The analysis supports decisions; our employees make the substantive decisions (see section 5). The service is operated in the Netherlands (see section 8).
7. To whom do we disclose your data?
In connection with our services, the Website, legal obligations and the other purposes in section 4, we also disclose personal data to third parties, particularly the following recipient categories:
These recipients may themselves engage third parties, meaning your data may also become accessible to them. We can contractually restrict processing by certain third parties, such as IT providers, but not by others, such as authorities.
- Service providers: We work with service providers in Switzerland and abroad that process data on our behalf. Google is particularly important: we use its services for Website hosting, forms, backend, database and CRM, encryption, analytics, AI-assisted evaluation, email, and communication. Details are provided in section 12; for processing abroad, see section 8.
- Authorities: We may disclose personal data to public bodies, courts, and other authorities in Switzerland and abroad where legally required or permitted, or where this appears necessary to protect our interests.
- Other persons: This includes other situations in which involving third parties follows from the purposes set out in section 4.
- Debt collection agencies: In the event of non-payment or late payment, we reserve the right to transfer the claim to a debt collection agency.
8. Is your personal data transferred abroad?
Our core backend, CRM database, encryption keys, and first-party analytics are configured in Zurich, Switzerland. Processing nevertheless also occurs outside Switzerland through Firebase Hosting’s global infrastructure, Vertex AI operated in the Netherlands, Firebase Authentication operated in the United States, and Google’s international infrastructure and subprocessors. Your data may therefore also be processed in Europe and, in exceptional cases, other countries.
Where a recipient is located in a country without adequate statutory data protection, we contractually require compliance with applicable data-protection requirements. For this purpose, we use the European Commission’s Standard Contractual Clauses, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj, unless the recipient is already subject to a recognised framework or we can rely on a statutory exception, for example foreign legal proceedings, overriding public interests, contract performance, or your consent.
Please note that data exchanged over the internet is often routed through third countries. Your data may therefore be transferred abroad even where sender and recipient are located in the same country.
9. How long do we process your data?
We process your data for as long as required by the processing purposes, statutory retention duties, our legitimate interests—particularly documentation and evidence—or technical storage needs. We then delete or anonymise the data through our usual procedures. The following periods currently apply:
Individual data may be retained longer where required by legal duties, the establishment or defence of legal claims, or an ordered preservation hold. Non-personal or sufficiently anonymised or aggregated statistics may also be retained longer.
- Request, CRM, and AI data: Active requests and prospect files are retained for no more than 24 months after the last contact; where no contact occurred, the period begins upon submission. Rejected, lost, or cancelled requests from non-customers are deleted twelve months after closure. CRM notes and AI analyses follow the period for the related file.
- Customer files: Retained for the duration of the customer relationship and 24 months thereafter.
- Contract, accounting, and communication data: Contracts, invoices, and accounting records are retained for ten years after the end of the relevant financial year. Emails and attachments generally follow the period for the related request or customer file; contractually or financially relevant messages may be retained for up to ten years.
- Proof of consent: Retained for three years after the most recent selection or withdrawal.
- Technical and security logs: Application, technical, and configurable security logs are retained for 90 days. Audit logs mandatorily specified by Google may be stored for 400 days; we cannot change this period.
- Rate-limit records: Retained for 30 days after the most recent update.
- Backups: Created daily and retained on a rolling basis for no more than 90 days.
- Google and Meta conversion records: Where these connections are used, the related transmission records are deleted 90 days after final processing.
- Raw first-party Website analytics data: 90 days.
- Analytics-to-lead link: Up to 400 days; removed earlier after Analytics consent is withdrawn.
- Google Analytics: User and event data are retained for 14 months. This setting does not apply to standard aggregated reports, which may remain available for longer.
10. How do we protect your data?
We take appropriate technical and organisational security measures to protect the confidentiality, integrity, and availability of personal data and against unauthorised processing, loss, or accidental disclosure. These measures include encrypting contact records using Google Cloud KMS, hashing email addresses and telephone numbers, restricting employee access through the CRM and Firebase Authentication, and using reCAPTCHA to prevent spam and abuse.
11. What rights do you have?
Depending on the applicable data-protection law, you have the following rights in connection with our data processing:
To exercise these rights, contact us in writing or, unless otherwise stated, by email using the details in section 2. We must identify you to prevent misuse. These rights are subject to the conditions, exceptions, and restrictions under applicable data-protection law, for example to protect third parties or trade secrets.
If you are dissatisfied with how we handle your rights or data protection, please tell us (section 2). You also have the right to complain to the competent supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch).
- the right to ask whether and what data we process about you;
- the right to have inaccurate data corrected;
- the right to request deletion of data;
- the right to receive certain personal data in a commonly used electronic format or request its transfer to another controller;
- the right to withdraw consent where processing is based on consent;
- the right, upon request, to receive further information necessary to exercise these rights.
12. Do we use online tracking and advertising technologies?
On our Website, we use technologies that allow us and, in some cases, third parties we engage to recognise you during use. The main purpose is to distinguish your access from that of other users, ensure functionality and—within the scope of your consent—perform analyses. For this purpose, our servers or third-party servers assign a recognition number to your browser (a “cookie”). You can configure your browser to block or delete cookies; the Website may then no longer function fully.
You can use our consent tool to control which categories are allowed:
We do not use individual Website personalisation or session replay. If you consent to Marketing, personalised advertising and remarketing may, however, be used outside our Website. Analysis of forms and calculators does not capture the values you enter.
We currently use services from the following providers in particular:
Google (Firebase, GA4, reCAPTCHA): The provider is Google Ireland Ltd. (Ireland), which relies on Google LLC (United States) for these purposes (together, “Google”). Google provides Website hosting, backend, database and CRM, encryption, analytics, and reCAPTCHA and acts as our processor to that extent. For access from the EU, Switzerland, or the United Kingdom, Google uses the IP address to derive approximate location data and then deletes it before it is logged or stored in Google Analytics. Google may also use received data for its own purposes; by consenting to Analytics, you also consent to the related transfer of usage data, device information, and individual identifiers to the United States and other countries.
Google Ads and Meta (conversion measurement and remarketing): If you consent to Marketing and the relevant connection is active, we may use conversion technologies from Google Ads and Meta (Meta Platforms Ireland Ltd.) to measure which advertising led to a request or contract. With Google Ads, previous visitors to our Website may also be assigned to remarketing audiences so that personalised advertising can be shown to them later. Advertising and campaign identifiers and, for conversion measurement, hashed email or telephone values, campaign information, and the conversion or contract value may be transmitted. Where personal data is transferred to the United States, we rely on the safeguards described in section 8.
- Necessary: These technologies are always required to operate and secure the Website, for example to save your language and consent and to use reCAPTCHA. They are always active.
- Analytics: Disabled by default. With your consent, this activates first-party analytics and Google Analytics (GA4).
- Marketing: Disabled by default. With your consent, this may activate campaign attribution, signals for personalised advertising and remarketing, and Google Ads and Meta conversion measurement.
13. Can this Privacy Policy be changed?
This Privacy Policy does not form part of a contract with you. We may amend it if our data processing, services used, or legal requirements change. The version published at any given time applies from the stated date. We will provide appropriate notice of material changes. Where new processing requires consent, we will obtain it before that processing begins.
Last updated: 2 August 2026