Privacy Policy
This privacy policy informs you about the processing of personal data in connection with our activities and operations , including our website under the domain name rmc-group-switzerland.com. In particular, we inform you which personal data we process, for what purpose, how, and where. We also inform you about the rights of individuals whose data we process.
We have written this privacy policy in German. If it is published in another language, the German version of the privacy policy remains authoritative.
For individual or additional activities and operations, we may publish further data protection declarations or other information on data protection.
We are subject to Swiss law as well as any applicable foreign law, in particular that of the European Union (EU) with the European General Data Protection Regulation (GDPR).
The European Commission recognized in its decision of 26 July 2000 that Swiss data protection law guarantees an adequate level of data protection. In its report of 15 January 2024, the European Commission confirmed this adequacy decision.
Table of contents
1. Contact addresses
Data Protection Representation in the European Economic Area (EEA)
2. Terms and legal bases
2.1 Terms
2.2 Legal basis
3. Type, scope and purpose of the processing of personal data
4. Automation and Artificial Intelligence (AI)
5. Disclosure of personal data
6. Communication
7. Data security
8. Personal data abroad
9. Rights of data subjects
9.1 Data protection claims
9.2 Legal protection
10. Use of the website
10.1 Cookies
10.2 Logging
10.3 counting pixels
11. Third-party services
11.1 Digital Infrastructure
11.2 Automation and integration of apps and services
11.3 Scheduling
11.4 Audio and video conferences
11.5 Online Collaboration
11.6 Fonts
12. Success and reach measurement
13. Final notes on the privacy policy
1. Contact addresses
The responsible party in the sense of data protection law is:
Aelmans, Nicolaas
RMC Bern
Talstrasse 4
CH-3122 Kehrsatz - Switzerland
RMC Apeldoorn
Minden 60
7327 AW Apeldoorn - The Netherlands
Email: info@rmc-group-switzerland.com
Website: www.rmc-group-switzerland.com
In individual cases, third parties may be responsible for processing personal data, or joint responsibility with third parties may exist. We will gladly provide data subjects with information about the respective responsibility upon request.
Data Protection Representation in the European Economic Area (EEA)
We have the following data protection representative in accordance with Art. 27 GDPR :
VGS Datenschutzpartner GmbH
Am Kaiserkai 69
20457 Hamburg
Germany
The Data Protection Representation serves as an additional point of contact for data subjects and authorities in the European Union (EU) and the rest of the European Economic Area (EEA) for inquiries relating to the GDPR.
2. Terms and legal bases
2.1 Terms
Data subject: Natural person whose personal data we process.
Personal data: All information relating to an identified or identifiable natural person.
Particularly sensitive personal data: data concerning trade union, political, religious or philosophical views and activities, data concerning health, privacy or ethnicity or race, genetic data, biometric data that uniquely identifies a natural person, data concerning criminal and administrative sanctions or prosecutions, and data concerning social assistance measures.
Processing: Any handling of personal data, regardless of the means and procedures used, such as querying, comparing, adapting, archiving, storing, retrieving, disclosing, obtaining, recording, collecting, deleting, disclosing, arranging, organizing, storing, altering, disseminating, linking, destroying and using personal data.
European Economic Area (EEA): Member States of the European Union (EU) plus the Principality of Liechtenstein, Iceland and Norway.
2.2 Legal basis
We process personal data in accordance with Swiss law, in particular the Federal Act on Data Protection ( Data Protection Act, DSG) and the Ordinance on Data Protection ( Data Protection Ordinance, DSV).
We process personal data – insofar as and to the extent that the European General Data Protection Regulation (GDPR) is applicable – in accordance with at least one of the following legal bases:
Article 6 paragraph 1 letter b GDPR for the necessary processing of personal data for the performance of a contract with the data subject and for the implementation of pre-contractual measures.
Article 6 paragraph 1 letter f of the GDPR provides the legal basis for the processing of personal data necessary to protect legitimate interests – including the legitimate interests of third parties – unless the fundamental rights and freedoms and interests of the data subject override those interests. Such interests include, in particular, the sustainable, humane, secure and reliable conduct of our activities and operations, ensuring information security, protection against misuse, the enforcement of our own legal claims and compliance with Swiss law.
Article 6 paragraph 1 letter c GDPR for the processing of personal data necessary for the fulfillment of a legal obligation to which we are subject under the applicable law of Member States in the European Economic Area (EEA).
Article 6 paragraph 1 letter e GDPR for the processing of personal data necessary for the performance of a task carried out in the public interest.
Article 6 paragraph 1 letter a GDPR for the processing of personal data with the consent of the data subject.
Article 6 paragraph 1 letter d GDPR for the processing of personal data necessary to protect the vital interests of the data subject or of another natural person.
Article 9 paragraph 2 et seq. GDPR for the processing of special categories of personal data, in particular with the consent of the data subjects.
The European General Data Protection Regulation (GDPR) refers to the processing of personal data as processing of personal data and the processing of particularly sensitive personal data as processing of special categories of personal data (Art. 9 GDPR) .
3. Type, scope and purpose of the processing of personal data
We process personal data that is necessary to carry out our activities and operations in a sustainable, user-friendly, secure, and reliable manner. The personal data processed may fall into the categories of browser and device data, content data, communication data, metadata, usage data, master data (including inventory and contact data), location data, transaction data, contract data, and payment data. This personal data may also include particularly sensitive personal data.
We also process personal data that we receive from third parties, obtain from publicly accessible sources, or collect in the course of our activities and operations, insofar as such processing is permissible.
We process personal data with the consent of the data subjects where necessary. In many cases, we may process personal data without consent, for example, to comply with legal obligations or to protect overriding legitimate interests. We may also request the consent of data subjects even when their consent is not required.
We process personal data for the duration necessary for the respective purpose. We anonymize or delete personal data, in particular depending on statutory retention and limitation periods.
4. Automation and Artificial Intelligence (AI)
We can process personal data automatically or use artificial intelligence for processing personal data.
We can use profiling to automatically evaluate certain personal aspects relating to individuals. Profiling serves, for example, to analyze or predict interests, behaviors, or personal preferences.
We will inform you on a case-by-case basis about decisions that are based solely on automated processing of personal data and have legal consequences for the data subjects or significantly affect them (automated individual decisions).
5. Disclosure of personal data
We may disclose personal data to third parties , have it processed by third parties, or process it jointly with third parties. Such third parties may include, for example, specialized service providers whose services we use. These third parties may, in turn, disclose personal data to other third parties.
We may disclose personal data in the course of our activities and operations, in particular to banks and other financial service providers, authorities, educational and research institutions, consultants and lawyers, accounting and trust service providers, debt collection agencies, interest groups, IT service providers, cooperation partners, credit and business information agencies, logistics and shipping companies, marketing and advertising agencies, media, parent, sister and subsidiary companies, organizations and associations, social institutions, telecommunications companies, insurance companies and payment service providers.
6. Communication
We process personal data to communicate with individuals as well as with authorities, organizations, and companies. In particular, we process data that a data subject provides to us when contacting us, for example, by mail or email. We may store such data in an address book or using similar tools.
Third parties who transmit data about other individuals to us are legally obligated to independently ensure the data protection of these individuals. In particular, they must guarantee that they are permitted to transmit such data, but also that the data transmitted is accurate.
We use selected services from suitable providers to enable and improve communication with individuals and other communication partners. With such services, we can also manage and process the data of the data subjects beyond direct communication, for example, in connection with orders, services, projects, and resource planning.
7. Data security
We take appropriate technical and organizational measures to ensure a level of data security commensurate with the respective risk. In particular, our measures guarantee the confidentiality, availability, traceability, and integrity of the personal data processed, although we cannot guarantee absolute data security.
Access to our website and other digital presence is secured using transport encryption ( SSL/TLS , specifically Hypertext Transfer Protocol Secure, abbreviated HTTPS ). Most browsers warn users before visiting a website without transport encryption.
Our digital communication – like all digital communication in principle – is subject to mass surveillance without cause or suspicion by security authorities in Switzerland, the rest of Europe, the United States of America (USA), and other countries. We have no direct influence on the processing of personal data by intelligence services, police forces, and other security authorities. We also cannot rule out the possibility that an individual may be targeted for surveillance.
8. Personal data abroad
We generally process personal data in Switzerland and the European Economic Area (EEA). However, we may also export or transfer personal data to other countries, in particular to process it there or have it processed there.
We can export personal data to all countries on Earth and elsewhere in the universe , provided that the law there guarantees an adequate level of data protection in accordance with the decision of the Swiss Federal Council and – insofar as the General Data Protection Regulation (GDPR) is applicable – also in accordance with the decision of the European Commission .
We may transfer personal data to countries whose laws do not guarantee an adequate level of data protection, provided that data protection is ensured for other reasons, in particular on the basis of standard data protection clauses or with other suitable safeguards. In exceptional cases, we may export personal data to countries without adequate or suitable data protection if the specific data protection requirements are met, for example, the explicit consent of the data subjects or a direct connection to the conclusion or performance of a contract. Upon request, we will gladly provide data subjects with information about any safeguards or provide a copy of any such safeguards.
9. Rights of data subjects
9.1 Data protection claims
We grant affected individuals all rights under applicable law. In particular, affected individuals have the following rights:
Information: Data subjects can request information about whether we process personal data concerning them, and if so, what personal data is involved. Data subjects also receive the information necessary to assert their data protection rights and to ensure transparency. This includes the processed personal data itself, but also information on the purpose of the processing, the storage period, any disclosure or export of data to other countries, and the origin of the personal data.
Correction and restriction: Data subjects can have inaccurate personal data corrected, incomplete data completed, and the processing of their data restricted.
Opportunity for own viewpoint and human review: In the case of decisions that are based exclusively on automated processing of personal data and have legal consequences for them or significantly affect them (automated individual decisions), data subjects can express their own viewpoint and request a review by a human.
Deletion and objection: Data subjects can have their personal data deleted ("right to be forgotten") and object to the processing of their data with effect for the future.
Data disclosure and data transfer: Data subjects may request the disclosure of their personal data or the transfer of their data to another controller.
We may, within the legally permissible framework, postpone, restrict, or refuse the exercise of data subjects' rights. We may inform data subjects of any prerequisites that may need to be met to exercise their data protection rights. For example, we may refuse to provide information, in whole or in part, citing confidentiality obligations, overriding interests, or the protection of other persons. We may also refuse to delete personal data, in whole or in part, particularly citing statutory retention obligations.
In exceptional cases, we may charge fees for exercising your rights . We will inform affected individuals in advance about any such costs.
We are obligated to identify data subjects who request information or assert other rights, using appropriate measures. Data subjects are obligated to cooperate.
9.2 Legal protection
Data subjects have the right to enforce their data protection rights through legal action or to file a complaint with a data protection supervisory authority.
The data protection supervisory authority for private controllers and federal bodies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC) .
European data protection authorities are organized as members of the European Data Protection Board ( EDPB ). In some member states of the European Economic Area (EEA), the data protection authorities are structured federally, particularly in Germany .
10. Use of the website
10.1 Cookies
We may use cookies. Cookies – both our own (first-party cookies) and cookies from third parties whose services we use (third-party cookies) – are data stored in the browser. Such stored data is not limited to traditional text-based cookies.
Cookies can be stored temporarily in the browser as "session cookies" or for a specific period as so-called persistent cookies. Session cookies are automatically deleted when the browser is closed. Persistent cookies have a specific storage duration. Cookies make it possible, in particular, to recognize a browser on the next visit to our website and thus, for example, to measure the reach of our website. Persistent cookies can also be used for online marketing purposes.
Cookies can be completely or partially disabled, restricted, or deleted at any time in your browser settings. Browser settings often also allow for the automated deletion and other management of cookies. Without cookies, our website may not be fully functional. We actively request – at least where and to the extent required by applicable law – your explicit consent to the use of cookies.
For cookies used for performance and reach measurement or for advertising, a general objection ("opt-out") is possible for numerous services via AdChoices (Digital Advertising Alliance of Canada) , the Network Advertising Initiative (NAI) , YourAdChoices (Digital Advertising Alliance) or Your Online Choices (European Interactive Digital Advertising Alliance, EDAA) .
10.2 Logging
For each access to our website and other digital presence, we may log at least the following information, provided that this information is determined or transmitted to our digital infrastructure as a standard procedure during such access: date and time including time zone, IP address , access status (HTTP status code) , operating system including user interface and version, browser including language and version, individual subpage of our website accessed including the amount of data transferred, and the last website accessed in the same browser window (referrer) .
We log such information, which may also constitute personal data, in log files. This information is necessary to ensure the continuous, user-friendly, and reliable provision of our digital presence. Furthermore, this information is necessary to guarantee data security – including through or with the assistance of third parties.
10.3 counting pixels
We can integrate tracking pixels into our digital presence. Tracking pixels are also known as web beacons. These pixels—including those from third parties whose services we use—are typically small, invisible images or scripts written in JavaScript that are automatically retrieved when our digital presence is accessed. Tracking pixels can collect at least the same information as is collected through logging in log files.
11. Third-party services
We use services from specialized third parties to ensure that our activities and operations are carried out sustainably, user-friendly, securely, and reliably. These services allow us, among other things, to embed functions and content into our website. For technically essential reasons, these services collect users' IP addresses, at least temporarily, when such content is embedded.
For necessary security-related, statistical, and technical purposes, third parties whose services we use may process aggregated, anonymized, or pseudonymized data related to our activities and operations. This includes, for example, performance or usage data, in order to provide the respective service.
We use in particular:
Google services: Providers: Google LLC (USA) / Google Ireland Limited (Ireland), partially for users in the European Economic Area (EEA) and Switzerland; General information on data protection: "How we handle data" , Privacy Policy, " How Google uses personal data", " Google is committed to complying with applicable data protection laws", " Guide to privacy in Google products", " How we use data from websites or apps where our services are used", CookieAds you can control" (Personalized advertising settings) .
Microsoft services: Providers: Microsoft Ireland Operations Limited (Ireland) for users in the European Economic Area (EEA), Switzerland and the United Kingdom / Microsoft Corporation (USA) for users in the rest of the world; General information on data protection: "Data protection at Microsoft" , "Data protection and privacy" , Privacy statement, " Data and privacy settings" .
MailChimp: Data protection declaration for newsletter data:
If you would like to receive the newsletter offered on this website, we need an email address
from you as well as information that allows us to verify that you are the owner of the email
address provided and that you agree to receive the newsletter. Further data is not collected.
We only use this data to send the requested information and do not pass it on to third parties.
You can revoke your consent to the storage of the data, the email address and its use for
sending the newsletter at any time, for example via the "unsubscribe" link in the newsletter.
11.1 Digital Infrastructure
We use services from specialized third parties to access the necessary digital infrastructure related to our activities and operations. This includes, for example, hosting and storage services from selected providers.
We use in particular:
METANET: Hosting; Provider: METANET AG (Switzerland); Data protection information: Privacy policy, " Legal " including "Technical and organizational measures" .
11.2 Automation and integration of apps and services
We use specialized platforms to integrate and connect existing third-party apps and services. These "no-code" platforms also allow us to automate processes and activities with third-party apps and services.
11.3 Scheduling
We use services from specialized third parties to enable online appointment scheduling, for example, for meetings. In addition to this privacy policy, any directly visible terms and conditions of the services used, such as terms of use or privacy policies, also apply.
11.4 Audio and video conferences
We use specialized audio and video conferencing services to communicate online. This allows us, for example, to hold virtual meetings or conduct online classes and webinars. Participation in audio and video conferences is also subject to the legal terms and conditions of the individual services, such as privacy policies and terms of use.
Depending on your life situation, we recommend that when participating in audio or video conferences you mute your microphone by default and blur your background or display a virtual background.
We use in particular:
Google Meet: Video conferencing; Provider: Google; Google Meet-specific information: «Google Meet – Security and privacy for users» .
Zoom: Platform for collaborative work, especially with video conferencing; Provider: Zoom Video Communications Inc. (USA); Information on data protection: «Data protection at Zoom» , Privacy policy, « Compliance at Zoom» .
11.5 Online Collaboration
We use third-party services to enable online collaboration. In addition to this privacy policy, any directly apparent terms and conditions of the services used, such as terms of use or privacy policies, also apply.
We use in particular:
Microsoft Teams: Platform for productive collaboration, especially with audio and video conferencing; Provider: Microsoft; Teams-specific information: "Security and compliance in Microsoft Teams", in particular "Data protection" .
11.6 Fonts
We use third-party services to embed selected fonts, icons, logos and symbols into our website.
We use in particular:
Google Fonts: Fonts; Provider: Google; Google Fonts-specific information: «Your privacy and Google Fonts» , «Data protection and data collection» (Google Fonts) .
12. Success and reach measurement
We strive to measure the success and reach of our activities. This includes measuring the impact of third-party feedback and examining how different parts or versions of our digital presence are used (A/B testing). Based on the results of these success and reach measurements, we can, in particular, correct errors, strengthen popular content, or implement improvements.
For performance and reach measurement, the IP addresses of individual users are recorded in most cases . In this case, IP addresses are generally shortened ("IP masking") to adhere to the principle of data minimization through appropriate pseudonymization.
Cookies may be used and user profiles created for performance and reach measurement. Any user profiles created may include, for example, the individual pages visited or content viewed on our digital platform, information about screen or browser window size, and the user's location (at least approximate). As a general rule, any user profiles are created exclusively using pseudonyms and are not used to identify individual users. Individual third-party services with which users are registered may, at best, associate the use of our online services with the user's account or profile on the respective service.
We use in particular:
Google Marketing Platform: Success and reach measurement, especially with Google Analytics ; Provider: Google; Google Marketing Platform-specific information: Measurement also across different browsers and devices (cross-device tracking) , Privacy policy for Google Analytics , "Browser add-on to deactivate Google Analytics" .
Google Tag Manager: Integration and management of services from Google and third parties, especially for measuring success and reach; Provider: Google; Google Tag Manager-specific information: Privacy policy for Google Tag Manager ; further information on data protection can be found with the individual integrated and managed services.
13. Final notes on the privacy policy
We created this privacy policy using the privacy policy generator from Datenschutzpartner .
We may update this privacy policy at any time. We will inform you of any updates by publishing the current privacy policy on our website.
Contact details
Should you have any concerns or questions regarding our data protection
guidelines, please feel free to contact us at info@rmc-group-switzerland.com.
Kehrsatz, July 7, 2026