1. Purpose of this privacy policy
Data protection matters to us. We therefore process your data with great care and strictly in line with the applicable legal requirements. Transparency is a key element of effective privacy protection.
This privacy policy explains how and why we process your personal data. In particular, you will learn:
- what data we process and for which purposes;
- who has access to your data and when we disclose it;
- how long we store your data;
- which rights you have and how to exercise them;
- which cookies and tools we use on our websites.
2. When does this privacy policy apply?
This privacy policy applies to all processing of your personal data unless we inform you separately.
It notably covers the use of our websites and digital services, newsletter subscriptions, competitions, marketing communications and any time we interact with you.
3. Data controller
VitaSecura AG, Breitfeldstrasse 8, 9015 St. Gallen, Switzerland. FINMA ID: F01533362, VAT: CHE-383.540.040, info@vitasecura.ch.
4. Contact point for privacy matters
Please direct privacy enquiries to VitaSecura AG, Breitfeldstrasse 8, 9015 St. Gallen, Switzerland, info@vitasecura.ch.
EU representative: VGS Datenschutzpartner GmbH, Am Kaiserkai 69, 20457 Hamburg, Germany, info@datenschutzpartner.eu.
5. Your rights
5.1 Right of access: You may request information about the personal data we process about you at any time. Attach proof of identity. We may restrict access if legal obligations or overriding interests conflict.
5.2 Rectification and erasure: You may request that we correct or delete your data unless legal obligations or legitimate interests require us to retain it.
5.3 Remedies: You may enforce your rights in court or contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch.
6. Key definitions
Personal data refers to information relating to an identified or identifiable natural person. Sensitive personal data may cover health, religion or political beliefs.
Processing covers any handling of personal data. Disclosure means making personal data available to third parties. Anonymisation removes any personal reference, pseudonymisation replaces identifiers with a code.
7. Data we process and how we obtain it
We process data you provide to us (e.g. when you enquire or register). We also collect technical data automatically (such as IP addresses, usage data) and may receive information from partners or public registers.
8. Purposes of processing
We process personal data to perform contracts, communicate with you, send marketing information, and for other legitimate purposes such as research, security, compliance and internal administration.
For WhatsApp communication we use the WhatsApp Business Platform (API); please review WhatsApp’s privacy policy.
9. Legal bases
We process data under the Swiss Federal Act on Data Protection and, where applicable, the GDPR – based on consent, contract performance, legal obligations or legitimate interests.
10. Disclosure of personal data
We disclose data only when necessary for contract fulfilment, legal obligations or technical services. Typical recipients include insurance and finance partners, IT/hosting providers, and marketing or analytics vendors.
11. International data transfers
Data may be processed outside Switzerland or the EEA (e.g. by Meta, Google or WhatsApp). We ensure adequate safeguards, such as standard contractual clauses or equivalent guarantees.
12. Special categories of data
We process sensitive data (e.g. health information) only when required for our services or when you expressly consent.
13. Profiling
We may create pseudonymised profiles to tailor offerings and communications. Extended profiling across multiple data sources occurs only with your consent.
14. Automated decision-making
We do not make fully automated decisions with legal effect unless we notify you separately.
15. Retention period
We keep personal data only as long as necessary for the intended purpose or as required by law (e.g. ten years for accounting records).
16. Data security
We protect your data with appropriate technical and organisational measures, use SSL/TLS encryption and recommend our secure portal for confidential information.
17. Changes to this privacy policy
We may adapt this privacy policy at any time. The current version is published on our website; material changes will be communicated proactively.
19. Social media
We operate social media pages. Data collected there is subject to the providers’ privacy policies. We use it for communication, marketing and analytics.