Privacy Policy

Privacy Policy in accordance with the Swiss FADP and EU GDPR

Cavantis GmbH (hereinafter "Cavantis", "we", or "us") takes the protection of your personal data very seriously. This privacy policy informs you about which personal data we collect in the course of our business activities, for what purposes we process it, and what rights you have.

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP), the associated Data Protection Ordinance (DPO), and, where applicable, the General Data Protection Regulation of the European Union (GDPR).

  1. Data Controller

    Responsible for the processing of your personal data is:

    Cavantis GmbH
    Rodenbergstrasse 16
    CH-8253 Diessenhofen
    Kanton Thurgau, Schweiz

    UID
    CHE-498.742.251

    E-Mail
    info@cavantis.com

    Website
    www.cavantis.com

  2. What is Personal Data?

    Personal data is any information relating to an identified or identifiable natural person. This includes, for example, first and last name, email address, phone number, address, company name, role, or IP address. Data that cannot be linked to a person (e.g. fully anonymized data) does not constitute personal data.

  3. Collection and Processing of Personal Data

    3.1 Initiation and Performance of Mandates and Consulting Agreements

    In the course of our consulting, interim management, and business development activities, we collect and process personal data of our contacts at client companies, prospective clients, and other business partners.

    In particular, we process the following data:
    – Name, role, and company name
    – Business email address and phone number
    – Business address
    – Communication content (emails, meeting notes, presentations)
    – Contract data and invoicing information
    – Other project-related information provided to us in the course of the mandate

    Purpose of processing: Initiation, conclusion, and performance of consulting and mandate agreements, client relationship management, invoicing, communication, and compliance with legal obligations.

    Legal basis: Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures) as well as legitimate interests pursuant to Art. 6(1)(f) GDPR. Under the Swiss FADP: necessity for contract performance and safeguarding of overriding interests.

    3.2 Contact by Email or Phone

    If you contact us by email or phone, we process the data you provide (name, email address, phone number, content of the inquiry) exclusively to handle your inquiry.

    Legal basis: Art. 6(1)(f) GDPR (legitimate interest in handling inquiries). If the contact leads to the conclusion of a contract, Art. 6(1)(b) GDPR applies.

    Retention period: The data is deleted once the inquiry has been fully processed, unless a statutory retention obligation applies.

    3.3 Preparation of Offers and Contracts

    For the preparation of offers, service agreements, and contracts, we process contact and company data of the relevant contacts. This data is stored for the duration of the contractual relationship and for the statutory retention periods (generally 10 years under Swiss Code of Obligations).

    3.4 Use of Communication and Collaboration Tools

    In the course of providing our services, we use digital communication and collaboration tools (e.g. Microsoft 365, video conferencing solutions). Personal data of participants (name, email, IP address, connection data) may be processed by the respective providers. We ensure that the tools we use provide an adequate level of data protection.

  4. Confidentiality and Non-Disclosure

    In the course of our consulting mandates, we often gain access to confidential company information, trade secrets, and sensitive data of our clients. This information is subject to our strict duty of confidentiality. We process such data exclusively to fulfill our contractual obligations.

    At the client's request, separate non-disclosure agreements (NDAs) may be concluded in addition to the statutory duty of confidentiality.

  5. Recipients of Personal Data

    We disclose personal data only where legally permitted or required:
    – Associate partners or specialists engaged by us, who are subject to contractual confidentiality obligations and act exclusively under our instructions
    – Tax and legal advisors, to the extent necessary for contract performance or compliance with legal obligations
    – Authorities and government bodies, where there is a legal obligation to disclose
    – IT service providers and cloud providers acting as data processors, with whom corresponding data processing agreements have been concluded

    Personal data is not disclosed to third parties for marketing purposes, nor is it sold.

  6. International Data Transfers

    We generally process personal data in Switzerland or within the European Economic Area (EEA). Where personal data is transferred to countries outside Switzerland or the EEA (third countries), we ensure an adequate level of protection, in particular through:
    – An adequacy decision of the European Commission or the Swiss Federal Council
    – Standard Contractual Clauses of the EU Commission (SCCs) pursuant to Art. 46 GDPR
    – Other appropriate safeguards pursuant to Art. 46 GDPR

    In individual cases, a transfer may also be based on derogations pursuant to Art. 49 GDPR or the corresponding provisions of the Swiss FADP.

  7. Retention Period and Data Deletion

    We store personal data only for as long as necessary for the respective processing purposes or as required by statutory retention periods. Once the relevant periods have expired, the data is deleted or anonymized.

    Applicable retention periods:
    – Contract and invoicing records: 10 years (under Swiss Code of Obligations and accounting law)
    – Correspondence related to mandates: generally 5–10 years
    – Inquiry-related data without a resulting contract: up to 12 months after the communication has concluded

  8. Data Security

    Cavantis takes appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or destruction. These include, among others:
    – Encrypted data transmission (SSL/TLS)
    – Access controls and access rights management
    – Regular review of security measures
    – Confidentiality obligations for employees and engaged third parties

    Please note that data transmission over the internet (e.g. by email) may have security vulnerabilities, and complete protection against access by third parties cannot be guaranteed.

  9. Rights of Data Subjects

    As a data subject, you have the following rights vis-à-vis Cavantis GmbH. To exercise your rights, please contact us by email at: info@cavantis.com.

    Right of Access (Art. 25 FADP / Art. 15 GDPR)

    You have the right to request confirmation as to whether we process personal data concerning you. Where such processing takes place, you have the right to access that data as well as information on the purposes of processing, recipients, retention period, and your further rights.

    Right to Rectification (Art. 32 FADP / Art. 16 GDPR)

    You have the right to request the correction of inaccurate or incomplete personal data.

    Right to Erasure (Art. 32 FADP / Art. 17 GDPR)

    You have the right to request the deletion of your personal data, provided the processing is not based on a legal obligation or an overriding interest.

    Right to Restriction of Processing (Art. 18 GDPR)

    You have the right to request the restriction of processing of your personal data if the accuracy of the data is contested, the processing is unlawful, or you have objected to the processing.

    Right to Data Portability (Art. 20 GDPR)

    You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format, provided the processing is based on consent or a contract.

    Right to Object (Art. 21 GDPR)

    You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you that is based on Art. 6(1)(f) GDPR (legitimate interest).

    Right to Withdraw Consent

    Where processing is based on your consent, you have the right to withdraw it at any time with effect for the future. The lawfulness of processing carried out prior to the withdrawal remains unaffected.

    Right to Lodge a Complaint

    You have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where the GDPR applies, with the competent supervisory authority of your EU member state.

    FDPIC: www.edoeb.admin.ch

  10. No Automated Decision-Making

    Cavantis does not make decisions based solely on automated processing (including profiling) that produce legal effects concerning you or similarly significantly affect you.

  11. Changes to This Privacy Policy

    Cavantis reserves the right to update this privacy policy at any time to reflect legal requirements or changes in our business activities. The version published at any given time shall apply from the date of publication. We recommend that you review this policy regularly.