Impunix AG Privacy Policy

Personal data that we collect on our websites can be found in the section on websites, social media and cookie notices.
Version 2.6 dated 22 July 2026
Valid from: 22 July 2026

In this privacy policy, we, Impunix AG, provide information on the collection and processing of personal data. Personal data refers to any information relating to an identified or identifiable natural person. Please note that other privacy policies, general terms and conditions, terms of participation and similar documents govern specific matters.

We take measures to ensure comprehensive data protection. These include, amongst other things, drawing up a record of processing activities, providing regular training for our staff on data protection, and ensuring they are bound by data protection obligations. Furthermore, we carefully vet our service providers and enter into data processing agreements with them, carry out annual data security assessments, review data transfers abroad and obtain the necessary assurances for these.

1. Data controller
2. Purpose of data processing in connection with our services and offers
3. Website, social media and cookie notices
4. Source of personal data
5. Data sharing and data transfers abroad
6. We, in our capacity as the contract processor
7. Retention period for personal data
8. Data security
9. Preferences and automated individual decision-making
10. Rights of data subjects
11. Changes to this privacy policy
12. Copyright and Licence
13. Categories of personal data

1. Data controller

The data controller within the meaning of the Swiss Federal Act on Data Protection (DSG) for the data processing operations described here is:

Impunix AG
Unterer Graben 27
8400 Winterthur
privacy@impunix.ch
www.impunix.ch

If you have any questions or concerns regarding data protection or the exercise of your rights, please contact this office.

2. Purpose of data processing in connection with our services and offers

We process personal data in order to provide our services in the fields of information security, data protection and risk management for small and medium-sized enterprises (SMEs) in Switzerland. This includes comprehensive data protection solutions, from design and implementation through to ongoing support; the preparation and review of data protection documentation; contractual safeguards in the context of data processing; the certification of data protection-compliant processes, support in facilitating data subjects’ rights, and assistance with reporting data protection incidents to the relevant authorities. Subcontractors may also be engaged in the provision of these services. Further information on the processing activities and their purposes can be found in the following sections.

2.1 Data Protection Advice

We process personal data in order to develop and implement data protection solutions for various sectors. In doing so, we take into account sector-specific requirements, recommendations from trade associations and industry standards in the field of data protection and information security. We primarily process contact details, company data, sector-specific process information and documentation.

2.2 Information security services

We process personal data for the purpose of providing information security services. This includes the analysis and assessment of security risks, the delivery of awareness-raising initiatives for staff, security testing in collaboration with partners, the development of security policies, and support with the planning and implementation of protective and emergency measures. In doing so, we primarily process contact details, IT system information, security logs, access credentials and documentation.

2.3 Phishing simulations

To raise staff awareness of cyber security, we offer a controlled phishing simulation. If you receive a phishing email as part of this simulation, it means your organisation has provided us with your contact details, such as your surname, first name and work email address. We use this information to send so-called phishing emails to the email address provided.
We then analyse the percentage of recipients who open the email, click on the link it contains and whether data is entered in the form fields on the landing pages. At no time, however, are access data transmitted to us in plain text. The results of the phishing campaign are processed and presented to the client, and a personal reference can be made.

2.4 E-learning courses

We offer e-learning courses to sensitise employees to data protection and cyber security. If you participate in one of these e-learning courses, your organisation has provided us with your contact details such as your surname, first name and email address. We use this information to invite you to the relevant courses by e-mail. We then analyse how many participants start and complete the course and pass the corresponding tests. The results of the e-learning courses are processed and presented to the client, and a personal reference can be made.

2.5 Meetings, training sessions and webinars

To take part in online meetings, training sessions and webinars, we use Microsoft services such as MS Teams and Stream for audio and video conferencing to communicate with you online. Please refer to Microsoft’s privacy policies, which are listed below.

You will be notified before a recording begins. It is recommended that you set your video conferencing tools to «off» for both the camera and microphone by default. Please also remember to enable a virtual background to prevent unauthorised people or information from being recorded.

We process your personal data, including contact details (salutation, title, first and last name, address, e-mail address, telephone number) and professional data (company, position/function), for the purpose of invitations, answering questions before and after the event and for advertising purposes. In addition, we process your contact data in order to enquire about your satisfaction after participation or to send you certificates of participation.

Among other things, Microsoft processes the following data: user data (display name, account (where applicable), profile picture (where applicable), email address, preferred language), internet protocol data (date, time, meeting ID, telephone numbers, location) and content data (text, audio and video data, as well as other interaction data), provided that you supply such data (e.g. via the chat function) or where it is generated through the use of a microphone and video camera.

The scope of the content data that is processed when using Microsoft Teams depends on the information provided by the participant during the session. The participant is advised that text entries and chat content are logged when using Microsoft Teams and can be viewed by both the organiser and other participants during the use of the chat function in a webinar, or may also be accessible to third parties in the case of a recording.

Once you have registered for the webinar, you will receive our newsletter containing a summary of the content. You will also be automatically subscribed to future newsletters. If you do not wish to receive these, you can unsubscribe via the relevant button in the newsletter.

2.6 Operation of our customer platform

We process personal data to enable our customers to access our platform. This is used for the documentation and management of data protection processes, the provision of documents and templates, the delivery of training, the handling of data subject requests, and the management of service providers. In doing so, we primarily process contact details, usage data, documentation, training records and contractual information.

2.7 Contract management and customer communication

We process personal data in order to fulfil contracts with business partners and to ensure communication with customers. This includes handling enquiries, preparing quotations, conducting contract negotiations and concluding contracts, invoicing and processing payments, as well as providing ongoing support and advice to our customers. In doing so, we primarily process contact details, contractual information, correspondence, and invoicing and payment data.

2.8 Training and awareness-raising

We process personal data in order to offer and deliver training courses and awareness programmes. This includes digital learning resources on data protection and information security, management training, webinars, face-to-face events and the issuing of certificates of attendance. In doing so, we primarily process contact details, participant lists, learning progress data, training records and certificate information.

2.9 Compliance with legal obligations

We process personal data in order to comply with legal obligations. This includes reporting data protection and security incidents to the relevant authorities, as well as fulfilling archiving, retention and disclosure obligations towards government bodies. In doing so, we primarily process contact details, transaction data and reporting documents.

2.10 Websites and online services

We use websites and other online services to provide our services and market our products and services. When you access our website, we collect usage data. In some cases, we also collect contact details, as well as information about your interests and preferences. Further information about the website can be found in the relevant section.

2.11 Marketing

We process your contact details for marketing purposes relating to our products and services. This includes postal mailings, competitions, events, new product launches, personalised advertising based on your customer profile, market research and newsletters.

2.12 Newsletter

We also use your contact details – whether you are an interested party, a customer or a potential customer – to send you information about our products, services and events via our newsletter. If you no longer wish to receive newsletters or be informed via other channels, you can unsubscribe via the link in our email newsletter or contact us using the email address published on the website.

In our newsletters and other marketing emails, we sometimes include visible andinvisible elements, which allow us to determine, when the email is opened, whether and when you have opened it, so that we can better understand whether and how our offers are being used and tailor them to your needs. You can block this in your email programme; most email programmes are set up this way by default.

We reserve the right to work with third parties to send out newsletters and to pass on your contact details for this purpose. Further information can be found in their privacy policies; links to the relevant websites are provided in Chapter 1.

2.13 Job application

In order to assess your application and suitability for employment, we process the personal data we have received from you as part of the application process. This may also include extracts from criminal records and debt collection registers, or similar documents that you have provided to us.

If you have provided references, we may contact them to obtain information about you. You have the right to know what information has been provided to us. Tests designed to objectively assess your suitability for the post in question may form part of the application process. Where the aim is to assess your suitability for a managerial role, the test may also relate to your personality.

Should the documents submitted not yet provide a complete and reliable picture, we reserve the right to use publicly available sources that are suitable for assessing specific professional suitability – such as Xing or LinkedIn, but also Google in general – for our research. We do not carry out research on private social media platforms such as Facebook or Instagram.

If there are any objective reasons relating to you personally that limit your suitability for the relevant employment relationship or disqualify you from it, you are obliged to disclose these to us. This may also involve a medical examination. Any information provided to us must comply with the relevant legal framework.

Please note that application documents sent to us by email may, due to the nature of our system, be stored in our backups. These backups cannot be individually purged without disproportionate effort. If you do not wish your application to be stored in our systems, please send us your documents by post.

3. Website, social media and cookie notices

This privacy policy applies to all websites operated by us, including:
• https://www.impunix.ch/
https://www.isds-schule.ch/

Usage data is collected via the websites and automatically stored in so-called server log files, which your browser automatically transmits to us. We are unable to link this data to specific individuals. This data is not combined with other data sources. However, we reserve the right to review this data retrospectively if we receive concrete evidence of unlawful use of the websites.

For security reasons and to protect the confidential content transmitted – such as enquiries you send to us as the website operator – SSL/TLS encryption is used on the websites.

The websites may contain links to other websites that are beyond our control and are therefore not covered by this privacy policy. If you use these links to access other websites, the operators of those websites may collect information about you.

3.1 Contact form

If you send us enquiries via the contact form, we will store the information provided in the form, including the contact details you have supplied. This is to process your enquiry and enables us to get in touch with you should we have any further questions. We will not pass this data on to third parties without your consent.

3.2 Online appointment booking

You can book an appointment directly via our online appointment booking tool (Microsoft Bookings), for example for a no-obligation consultation. Personal data is processed for the purpose of arranging and confirming the appointment. To this end, we collect your contact details and your preferred appointment date.

3.3 Social media, including plugins and pixels

We maintain a presence on social media and other platforms operated by third parties, and in this context we process data relating to you. You can contact us via these platforms, and we receive data from them, such as statistics. The platform providers may analyse your usage and use the data about you for their own purposes, such as marketing and market research. In doing so, the platform providers act as independent data controllers.

Furthermore, we may also use so-called plugins or pixels from social networks such as Meta (formerly Facebook), X (formerly Twitter), LinkedIn, Pinterest or Instagram on our websites. You will be able to recognise these plugins. If they are activated, the operators of the respective social networks may record that you are visiting our website. When pixel technologies are used, corresponding codes are implemented on our website to enable the transmission of your usage data. These are used to measure the reach of our social media campaigns. The processing of your personal data is the responsibility of the respective operator in accordance with their privacy policy.

Most of these providers are based outside Switzerland. For further information on the transfer of data abroad, please refer to the relevant section.

3.4 WhatsApp

Although we do not actively use WhatsApp as a means of communication, we would like to point out that it is possible to contact us via WhatsApp. Please note that when using WhatsApp, your address book is usually shared, which means that personal data is transferred to WhatsApp Inc. in the USA. Further information on how and for what purpose WhatsApp processes your data can be found in WhatsApp’s privacy policy.

3.5 Persistent cookies or other tracking technologies

On our websites, we use cookies and similar technologies to identify your browser or device and to understand your preferences on the website. A cookie is a small file that is automatically sent to your computer by the web browser you are using when you visit our website, or stored on your computer or mobile device. When you visit this website again, we can recognise you, even though we do not know who you are. In Switzerland, Article 45c of the Telecommunications Act (FMG) governs the use of cookies on websites. Unlike in the EU, Switzerland does not require a cookie banner with a selection or opt-out function; instead, it is sufficient to state that cookies and other technologies are used and to explain how to configure your web browser to prevent the acceptance of cookies, etc. An opt-out option does not have to be provided. In addition to cookies that are only used during a session and are deleted after visiting the website («session cookies»), cookies may also be used to store user settings and other information for a specific period («persistent cookies»). However, you can configure your browser to reject cookies, store them only for a single session, or delete them early. Most browsers are set by default to accept cookies. We use permanent cookies, amongst other things, to store user settings (e.g. language, auto-login), to better understand how you use our services and content, and to be able to display offers and adverts tailored to you (which may also be the case on websites operated by other companies). Some cookies are set by us, whilst others are set by contractual partners with whom we collaborate. If you block cookies, some functions (e.g. language selection, shopping basket, checkout process) may no longer work. If you do not wish this to happen, you must adjust the settings in your browser or email programme accordingly.

3.5.1 2B Advice Consent Manager (2B Advice GmbH, 2b-advice.com)

We use the „2B Advice Consent Manager“ service to record and store consent and settings relating to cookies and similar technologies. In doing so, personal data such as your choice in the cookie banner, timestamps and certain technical information about your device are processed and transmitted to 2B Advice GmbH (with server locations in the EU and, where applicable, other countries). Where personal data is disclosed to countries outside Switzerland, we ensure an adequate level of protection through contractual safeguards.

3.5.2 ShortPixel (ID SCOUT SRL, shortpixel.ai)

We use the ShortPixel service to optimise and deliver compressed images. When such images are accessed, personal data such as IP addresses and technical access data are transmitted to ID SCOUT SRL and processed on their servers. Processing takes place mainly within the EU and, depending on the infrastructure, also in other countries. Where personal data is disclosed to countries without an adequate level of data protection, we put contractual safeguards in place.

3.5.3 Microsoft Services (Microsoft Corporation, microsoft.com / cloud.microsoft / static.microsoft)

We integrate various technical services from Microsoft, in particular scripts, fonts and other cloud components. In doing so, personal data such as IP addresses and technical access data are transmitted to Microsoft Corporation and processed in log files and, where applicable, in cookies or web storage. This processing takes place via Microsoft data centres in the EU, Switzerland and other countries, in particular the USA. Where personal data is transferred to countries without an adequate level of data protection, we implement contractual safeguards and technical and organisational protective measures.

3.5.4 Microsoft Azure (Microsoft Corporation, azureedge.net)

We use the „Microsoft Azure“ content delivery network to deliver static content (e.g. scripts and style sheets). When this content is accessed, personal data such as IP addresses and technical access data is transmitted to Microsoft and processed in log files on Azure servers. This processing takes place via a global network of data centres, including those in the USA and other countries outside Switzerland. We rely on contractual safeguards for such transfers abroad.

3.5.5 Microsoft Bookings (Microsoft Corporation, outlook.office365.com/owa/calendar)

We use „Microsoft Bookings“ for online appointment booking. When you book an appointment, personal data such as your name, contact details, preferred appointment time and any messages you provide are transmitted to Microsoft and processed as part of the Office 365 services. This processing takes place in Microsoft data centres, including in countries outside Switzerland, in particular in the EU and the USA. We put contractual safeguards in place for data transfers to countries without an adequate level of data protection.

3.5.6 Pipedrive (Pipedrive OÜ, pipedrive.com)

We use the CRM service „Pipedrive“ to manage contact enquiries and sales-related processes. In doing so, personal data such as your name, contact details, the content of your enquiry and interaction data is transferred to Pipedrive OÜ and stored there. Data processing takes place within the EU and, depending on the infrastructure, in other countries as well. Where personal data is transferred to countries without an adequate level of data protection, we employ contractual safeguards and technical protection measures.

3.5.7 unpkg (UNPKG.com, unpkg.com)

We use the „unpkg“ content delivery network to provide certain JavaScript libraries and static resources. When this content is accessed, personal data such as IP addresses and technical access data is transmitted to UNPKG.com’s servers and processed in log files. This processing takes place on servers in the USA and, where applicable, in other countries. We put contractual safeguards in place for this transfer of data abroad.

3.5.8 Google Hosted Libraries (Google LLC, ajax.googleapis.com)

We integrate „Google Hosted Libraries“ to provide technical libraries (e.g. JavaScript libraries). When these libraries are loaded, personal data such as IP addresses and technical metadata (e.g. browser information) are transmitted to servers operated by Google LLC and processed there. Personal data may be processed in the USA and other countries outside Switzerland. For these transfers abroad, we use contractual safeguards and technical protection measures to ensure an adequate level of data protection.

3.5.9 Cloudflare (Cloudflare, Inc., cloudflare.com)

We use the Cloudflare service for security functions and to deliver our website via a content delivery network. In doing so, personal data such as IP addresses and technical access data are transmitted to Cloudflare, Inc. and processed there in log files and technically necessary cookies. This processing takes place via server locations worldwide, in particular in the USA. We put contractual safeguards in place for the transfer of personal data to countries without an adequate level of data protection.

3.5.10 jsDelivr (Volentio JSD Limited, jsdelivr.net)

We use the „jsDelivr“ content delivery network to deliver external scripts and libraries. In doing so, personal data such as IP addresses and technical access data is transmitted to Volentio JSD Limited and processed in log files. Processing takes place via a global CDN with servers in the EU, the USA and other countries. Where personal data is disclosed to countries without an adequate level of data protection, we employ contractual safeguards and additional technical protection measures.

3.5.11 Matomo Cloud (Matomo / InnoCraft Ltd., matomo.cloud)

We use „Matomo Cloud“ to analyse the usage of our website for statistical purposes. The purpose of processing is to analyse usage data such as IP addresses (anonymised in accordance with our configuration), page views and interactions. This personal data is transferred to Matomo / InnoCraft Ltd. and processed there. Depending on the chosen data centre, the data may be transferred to countries outside Switzerland and the EU, in particular to New Zealand. We use contractual safeguards for such data transfers.

3.5.12 Cookie Notice for the GDPR & CCPA (Local server: isds-schule.ch, Hu-manity.co)

On our website, we use the „Cookie Notice for GDPR & CCPA“ tool, which is hosted locally on our server under the domain isds-schule.ch and is provided by Hu-manity.co. The purpose of processing is to display information about cookies and similar technologies and to store basic settings relating to the use of cookies. In doing so, personal data such as your choice in the cookie notice and certain technical information about your device is processed. Personal data is primarily processed on our own systems; where Hu-manity.co gains access for maintenance or support purposes and processes data in countries outside Switzerland, we ensure through contractual safeguards that an adequate level of protection is maintained.

3.5.13 Other technical scripts from 2B Advice and third-party providers

In addition to the services mentioned above, further technical scripts from the provider 2B Advice and other third-party providers are used, which are necessary for the operation of the consent manager and the technical provision of our website. In doing so, personal data such as IP addresses and technical access data are transferred to these third-party providers and processed there. Where data is transferred to countries without an adequate level of data protection, we ensure an adequate level of protection for your personal data through contractual guarantees and appropriate safeguards.

4. Source of personal data

In most cases, the data we process comes from you, for example in connection with the provision of our services, the use of our website or communication with us. If you wish to enter into contracts with us or use our services, you must provide us with certain data. This also applies to the use of our website. Furthermore, you are obliged to provide data in order to comply with legal obligations. Otherwise, you are free to decide whether or not to provide us with data about yourself.

We may also receive data from third parties, in particular from our service providers or contractual partners. In addition, we may obtain data from publicly available sources such as websites, company registers, land registers, commercial registers, credit reference agencies, address brokers, trade associations, telephone directories and web analytics services.

5. Data sharing and data transfers abroad

As part of our business activities and in accordance with the purposes set out above, we may share information with service providers or third parties, in particular with the following categories of recipients:

• Service providers: We work with service providers who process data on our behalf or under joint responsibility, such as marketing agencies, IT service providers, other suppliers or subcontractors, and business partners;
• Public authorities: We may also disclose data to public authorities in this country and abroad, government departments or courts if we are legally obliged to do so;
• Financial service providers and insurance companies: In connection with insurance services, we work with credit reference agencies, banks and insurance companies;
• Other third parties: All other third parties with whom we collaborate to fulfil the stated purposes. These may include, for example, the media, the general public – including visitors to websites and social media – competitors, industry organisations, associations, organisations and other bodies. In addition, this may also include parties involved in a corporate transaction, such as a merger, a sale of assets or shares, a restructuring, a financing, a change of control or the acquisition of all or part of our business.

These categories of recipients may include third parties to whom personal data is disclosed. We may contractually oblige service providers and certain contractual partners acting on our behalf not to use the data for their own purposes. Other third parties, such as financial service providers, insurance companies or public authorities, use the data for their own purposes, e.g. to comply with legal requirements, which is why we cannot restrict this processing.

We process your personal data primarily in Switzerland. However, personal data may also be disclosed to recipients abroad, in particular in the following countries: Germany, Belgium, Estonia, the Netherlands, Sweden, Ireland and the USA. Furthermore, the data may be transferred to other countries within the European Economic Area. Given today’s global interconnectedness and the presence of multinational corporations, it is also possible that data may be processed anywhere in the world. If a recipient is located in a country without an adequate level of statutory data protection, we will contractually oblige our suppliers or partners, the recipients, to comply with the applicable data protection standards, unless they are already subject to a legally recognised framework for ensuring data protection and we are unable to invoke an exemption.

6. Retention period for personal data

We process and store your personal data for as long as is necessary to fulfil our contractual and legal obligations or for the purposes for which the processing is carried out; this means, for example, for the duration of the entire business relationship (from the initiation and execution of a contract through to its termination) and beyond, in accordance with statutory retention and documentation requirements. In this context, it is possible that personal data may be retained for the period during which claims may be brought against our company, and to the extent that we are otherwise legally obliged to do so or where legitimate business interests so require (e.g. for evidential and documentation purposes).

7. Data security

We implement appropriate technical and organisational security measures to protect your personal data. In doing so, we take into account the state of the art, the risk associated with the processing, and the investment costs, and we base our approach on the Swiss Data Protection Act and the Data Protection Ordinance. These measures are designed to prevent data breaches, such as unauthorised access to and misuse of data. We also instruct the data processors to whom we transfer data to implement appropriate technical and organisational security measures.

Contact us by email
We offer you the option of communicating with us via encrypted email using S/MIME technology. Communication via email is not usually encrypted. There is a risk that data may be lost or intercepted and/or manipulated by third parties, for example to falsify its authenticity. We implement appropriate technical and organisational security measures to prevent this within the system. Nevertheless, the confidentiality of data cannot be guaranteed when any data is transmitted via email. This applies in particular to the transmission of sensitive personal data; please do not send us such data by email, but contact us in advance to arrange a secure channel. External access devices (end-users’ PCs, smartphones, etc.) and parts of the infrastructure involved in the transmission between the sender and the recipient are beyond our control. We accept no liability for any consequences or damage that may arise from the electronic exchange of information and, in particular, from any misuse of the email system. We reserve the right to be indemnified against any intentional damage incurred by us as a result of business dealings with the person concerned via the electronic exchange of information. Furthermore, we reserve the right, in individual cases, not to reply by email or to require an additional form of confirmation – such as a signed form – for orders or information received via email.

8. Preferences and automated individual decision-making

As a general rule, we do not use fully automated decision-making processes for the purposes of establishing and conducting our business relationship, or for any other purposes. Should we use such processes in individual cases, we will inform you of this separately, provided that this is required by law, and we will explain your rights in this regard.

9. Rights of data subjects

As a data subject, you have the rights provided for by law in relation to the processing of your personal data. In particular, you have the right to request information about your stored personal data. You may also request that your personal data be corrected, supplemented, restricted or erased. If you have set up a customer account, you have the option to delete it or have it deleted. Furthermore, you are free to object to the use of your data for marketing purposes. You may withdraw your consent at any time with effect for the future. In addition, you have the right to request the transfer of your data to other data controllers.

We would, however, like to point out that we reserve the right to invoke statutory restrictions, for example where we are obliged to retain or process certain data, have a legitimate interest in doing so, or require the data to assert legal claims. Where legal obstacles prevent deletion, the data will be blocked instead. Please note that exercising these rights may conflict with contractual agreements and may result in consequences such as early termination of the contract or financial implications. In such cases, we will inform you in advance, unless this is already covered by the contract.

Exercising these rights generally requires you to provide clear proof of your identity (e.g. by submitting a copy of your identity document if your identity is otherwise unclear or cannot be verified). To exercise your rights, you may contact the data protection officer named in Chapter 1.

Any data subject also has the right to pursue their claims through the courts or to lodge a complaint with the relevant data protection authority. The relevant data protection authority in Switzerland is the Federal Data Protection and Information Commissioner (https://www.edoeb.admin.ch).

10. Changes to this privacy policy

We may amend this privacy policy at any time without prior notice. This privacy policy does not form part of any contract with you. The current version published on our website shall always apply.

11. Copyright and Licence

This privacy policy has been drawn up by impunix AG. If you have any questions or comments, please feel free to contact us using the contact details provided in Section 1. This privacy policy is intended exclusively for customers of our full-service data protection package.

12. Categories of personal data

Depending on the business transaction, we process one or more of the following categories of personal data listed in the table below (in alphabetical order).

Personal data requiring special protection (are collected and processed with restraint): Ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, medical certificates, health data, data relating to criminal offences or suspected criminal offences, and data concerning social assistance measures.
Creditworthiness and bank details: Salary, housing costs, disposable income, payment history, balance sheets, data from credit reference agencies, credit scores, financial circumstances, bank account details, credit card number, etc.;
Interests and preferences: Information you have provided or which has been collected regarding your areas of interest;
Contact details: Name, address, telephone number, email address;
Contact details updated: Information on spouse or children, marital status, portrait photograph, voluntary work, job title, career history, length of service, responsibilities, duties, qualifications, appraisals, certificates, etc.;
Work contact details: Surname, first name, title, address, email address, telephone number, mobile number, employer, role, department, responsibilities, etc.;
Website and app usage data: The IP address, browser type and version, operating system and device type used, referrer URL (the previous website from which you accessed our site), the internet service provider, the hostname of the accessing computer, the time of the server request, etc. You also provide us with information about how you use the website. We explain the data processing involved in using the website and the app, including tracking via cookies, in the website information.;
Online account details: Account details, customer and prospect portals, payment details you have provided (e.g. credit card number);
Technical specifications: Access details, user ID, permissions, login times, IP address, key number, emails, video recordings, usage data relating to mobile devices, etc.
Contract details: Business relationship details, customer number, insurance number, quotations and products purchased, contract date, purchase price, special requests, warranties, goodwill gestures, etc.;
Video recordings: Visual and (rarely) audio recordings, etc.;
Payment and transaction details: Information on payment methods, purchases of products and services, discounts, etc.