Privacy Policy.
Convenience translation for information purposes. The German version is legally binding.
1Controller
The controller responsible for the data processing described in this privacy policy is:
Adivera AG · Dufourstrasse 49 · 8008 Zurich · Switzerland
Telephone: 044 748 44 44 · E-mail: info@adivera.com · Website: www.adivera.com
Contact person for data protection matters (data protection advisor within the meaning of art. 10 FADP): Roberto Hellmich, reachable via the above contact details or the contact form on the website.
2Scope and Applicable Law
This privacy policy explains how we process personal data when you visit our website, contact us, use our services or apply for a position with us.
We process personal data in accordance with Swiss data protection law, in particular the Federal Act on Data Protection (FADP) and the Data Protection Ordinance (DPO). To the extent that the EU General Data Protection Regulation (GDPR) is applicable in an individual case, we additionally process personal data in accordance with its requirements.
3Definitions
Personal data means any information relating to an identified or identifiable natural person. Processing covers any handling of personal data, irrespective of the means and procedures applied, in particular the collection, storage, retention, use, alteration, disclosure, archiving, deletion or destruction of personal data. A data subject is a natural person about whom personal data is processed.
4Principles and Legal Bases
We process personal data in accordance with the principles of art. 6 FADP, namely lawfully, in good faith, proportionately and for specified purposes.
To the extent that the GDPR is applicable, we base the processing on the following legal grounds: the consent of the data subject (art. 6 para. 1 lit. a GDPR), the performance of a contract or the implementation of pre-contractual measures (art. 6 para. 1 lit. b GDPR), compliance with legal obligations (art. 6 para. 1 lit. c GDPR), the protection of vital interests (art. 6 para. 1 lit. d GDPR) or the pursuit of legitimate interests (art. 6 para. 1 lit. f GDPR), such as the secure and economical operation of our online offering, the maintenance of customer relationships and communication with business partners.
5Categories of Data Processed and Purposes
5.1Visiting the Website (Server Log Files)
When you visit our website, the web server automatically collects technical data, namely the IP address, date and time of access, pages and files accessed, browser type and version, operating system used, referrer URL and the host name of the accessing device. This data is processed to provide the website, to ensure system security and stability and for internal statistical purposes, and is not combined with other data sources. We reserve the right to analyse the log data retrospectively if there are concrete indications of unlawful use. The log data is deleted after six months, unless longer retention is required to preserve evidence.
5.2Contact Form and E-mail Contact
If you contact us via the contact form or by e-mail, we process the information you provide (in particular your name, contact details and the content of the enquiry) to handle the enquiry and for any follow-up questions. Please note that data transmission by unencrypted e-mail may present security gaps.
5.3Customer and Supplier Data
In the course of our business activities, we process personal data of contact persons at customers, prospects, suppliers and partners (in particular name, function, business contact details, correspondence and contract data) for the initiation, conclusion and performance of contracts, for invoicing, for maintaining the business relationship and for complying with statutory obligations.
5.4Job Applications
In the case of job applications, we process the application documents submitted to us exclusively for the purpose of conducting the application procedure. Where application documents contain sensitive personal data (e.g. health data), we process such data only to the extent necessary for the application procedure or to fulfil obligations under employment and social insurance law. After completion of the procedure, we delete the documents within six months, unless you have consented to longer retention (talent pool) or an employment relationship is established.
5.5Adivera Ventures – Interested Parties and Principals
In the Adivera Ventures division we process personal data of interested parties, principals, partners and their contact persons in order to present opportunities, verify qualification, release documentation and make introductions.
Interested parties: We process name, contact details, information on the person or company, the source of introduction, the self-declaration of qualification (including whether the criteria of a high-net-worth retail client are met), where applicable proof of sufficient means (confirmation from a bank or adviser, without account statements or balances), the signed non-circumvention and non-disclosure agreement, and a record of which documents were released for which opportunity. The legal basis is the initiation of a contractual relationship and our legitimate interest in qualifying interested parties and protecting the confidentiality of our principals.
Disclosure to principals and partners: To make the introduction we disclose name, contact details and — where required for the opportunity — confirmation of qualification to the principal or the partner handling the mandate. Proof of means is disclosed only with the interested party's consent or where the principal requires it to continue discussions. Principals and partners may be located abroad; section 8 applies.
Principals and partners: We process name, contact details, contract data and information on the opportunity and commission in order to perform the brokerage or cooperation agreement.
Retention: We delete qualification evidence and self-declarations twelve months after the last contact regarding the relevant opportunity if no contract is concluded. Signed non-circumvention and non-disclosure agreements are retained for the term agreed therein and thereafter until the expiry of limitation periods.
6Cookies and Consent Management
Our website uses cookies and comparable technologies. Cookies are small text files stored on your device. We distinguish between technically necessary cookies, which are required for the operation of the website, and optional cookies for statistical and analytical purposes.
We use technically necessary cookies on the basis of our legitimate interest in providing a functional website. We use optional cookies only if you have consented via the cookie consent banner displayed when the website is accessed. You can adjust or withdraw your consent at any time with effect for the future via the cookie settings on our website. The consent declaration is stored in order to be able to prove it and to avoid repeating the request; the storage period is up to two years. You can also deactivate or delete cookies via your browser settings; this may limit the functionality of the website.
7Disclosure of Personal Data
We disclose personal data to third parties to the extent necessary to fulfil our contractual or statutory obligations, where we are legally entitled or obliged to do so, or where you have consented. Recipients may include, in particular, IT and hosting service providers, payment and financial service providers, authorities and advisors.
Where we engage service providers as processors, we conclude contracts with them that meet the requirements of art. 9 FADP (or art. 28 GDPR) and ensure the protection of your data.
In the Adivera Ventures division we disclose interested-party data to principals and partners (section 5.5).
8Disclosure Abroad
We generally process and store personal data in Switzerland and the European Economic Area (EEA). Individual service providers may also process personal data in other countries, in particular in the USA.
Disclosure abroad takes place only if the recipient country has an adequate level of data protection pursuant to Annex 1 of the Data Protection Ordinance (DPO) (this applies, among others, to the EEA states and the Principality of Monaco). For the USA, this applies to companies certified under the Swiss-U.S. Data Privacy Framework (DPF); the certified companies can be looked up in the public DPF list (www.dataprivacyframework.gov). In other cases, we base the disclosure on appropriate safeguards, in particular the standard data protection clauses approved or recognised by the competent supervisory authority, or on a statutory exemption (e.g. your express consent or the necessity for the performance of the contract).
9Third-Party Services Used
The fonts used on our website are hosted locally on our own servers; no data is transmitted to third-party providers.
9.1Google Analytics 4
We use Google Analytics 4, a web analytics service provided by Google Ireland Limited. Google Analytics uses cookies and similar technologies that enable an analysis of the use of our website. By default, Google Analytics 4 does not store visitors' IP addresses; they are used only for coarse geolocation and are truncated or discarded before storage. The information generated in the course of use may be transferred to Google servers, including in the USA. Google LLC is certified under the Swiss-U.S. Data Privacy Framework. Google Analytics is used exclusively with your consent via our cookie banner; you can withdraw your consent at any time with effect for the future via the cookie settings. Further information: https://policies.google.com/privacy
10Data Security
We take appropriate technical and organisational measures in accordance with art. 8 FADP and art. 1 et seq. DPO to protect your personal data against unauthorised access, loss, misuse or falsification. These include, in particular, the control of physical and electronic access, encryption, logging and ensuring the confidentiality, integrity and availability of the systems. Our website uses SSL/TLS encryption, recognisable by the «https://» and the padlock symbol in your browser's address bar. However, complete protection of data against access by third parties is not possible during transmission over the internet.
11Retention Period
We process and store personal data for as long as this is necessary for the respective purpose, statutory retention obligations exist (in particular the ten-year retention obligation for business records under art. 958f of the Swiss Code of Obligations) or retention is necessary to safeguard legal claims. Once the purpose has lapsed or the periods have expired, the data is deleted or anonymised.
For qualification evidence and confidentiality agreements in the Adivera Ventures division, the periods in section 5.5 apply.
12Rights of Data Subjects
Under the applicable data protection law, you have in particular the following rights:
Access (art. 25 FADP): You may request information as to whether and which personal data we process about you.
Rectification (art. 32 FADP): You may request the rectification of inaccurate personal data.
Deletion: You may request the deletion of your personal data, unless overriding interests or statutory obligations preclude deletion.
Data portability (art. 28 FADP): Subject to the statutory requirements, you may request the release of your personal data in a common electronic format or its transfer to another controller.
Objection: You may object to a processing of your personal data.
Withdrawal of consent: You may withdraw any consent given at any time with effect for the future; the lawfulness of the processing carried out until withdrawal remains unaffected.
To the extent that the GDPR is applicable, you additionally have the rights under art. 15 to 21 GDPR (access, rectification, erasure, restriction of processing, data portability, objection).
To exercise your rights, you may contact the contact person named in clause 1 at any time. We may request proof of identity. We generally provide information within 30 days.
You also have the right to lodge a complaint with the competent supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern (www.edoeb.admin.ch).
13Changes to this Privacy Policy
We may amend this privacy policy at any time. The current version published on our website applies. We will communicate material changes in an appropriate manner.
14Questions about Data Protection
If you have any questions about data protection, please contact the contact person named in clause 1 or write to us at info@adivera.com.