Legal Notice

Responsible for the Content

ACS Solution AG
Hauptstrasse 29
8371 Busswil TG
Switzerland
+41 71 929 44 44
info@acs-solution·ch

TYPO3, HTML & Programming

Keel Marktideen AG
Hintere Davidstrasse 24
9000 St. Gallen, Switzerland
+41 71 250 20 50
info@marktideen·ch

 

GRAPHIC DESIGN
Martina Kunz
hello@martinakunz·ch

Privacy Policy for
ICS Automation AG & ACS Solution AG

Introduction
ICS Automation AG (referred to as ICS) and its subsidiary ACS Solution AG (referred to as ACS) are committed to protecting the privacy and personal data of individuals who are in contact with ICS or ACS. This privacy policy applies to ICS and ACS and describes how ICS and ACS process and protect personal data.

Principle
Protecting your privacy is important to us. In the following privacy policy, we explain which personal data we process when you visit our website or use our online services, or more generally when we provide services for you. We collect and process your personal data carefully, only for the purposes described in this privacy policy, only to the extent necessary and within the framework of the applicable legal provisions. We retain your personal data only to the extent and for as long as is necessary to provide our services or as required by law. In close cooperation with our IT partners and hosting providers, we do our utmost to protect the data against unauthorised access, loss, misuse or falsification. This privacy policy is also specifically aligned with the EU General Data Protection Regulation (GDPR). Although the GDPR is a regulation of the European Union, it is relevant to us. The Swiss Federal Act on Data Protection (FADP) is strongly influenced by EU law, and companies outside the European Union or the EEA are required to comply with the GDPR under certain circumstances.

Data Protection Officer
Responsible for compliance with the applicable data protection provisions within the meaning of the Swiss FADP, and controller within the meaning of the EU GDPR, is:

ICS Automation AG / ACS Solution AG
Hauptstrasse 29
CH-8371 Busswil TG
+41 71 955 04 50
info@ics-automation·com

Collection and Processing of Personal Data
ICS and ACS process in particular

  • Contract data
  • Payment data
  • Contact details (name, address, telephone, email, title, place of work, etc.)

for the purpose of providing contractual services, service and customer care, marketing, advertising, fulfilling legal obligations, managing business relationships, identifying customer needs, evaluating and improving our services and exchanging information on various topics. ICS and ACS do not operate an online shop, nor do we offer or sell products or services to private individuals in Switzerland or the EU. If individuals look for information about job vacancies on our website or apply for a position, these applications and any additional information submitted may be used to match their skills and interests with vacancies at ICS or ACS. When you contact ICS or ACS (e.g. by email, telephone, etc.), the details you provide are processed in order to handle and follow up your enquiry. For telephone conferences, online meetings, video conferences and/or webinars ("online meetings"), we use the "Microsoft Teams" service. The following data is processed in this context: user name, general information about service preferences, information about the device and the network and internet connection of each user, e.g. IP address(es), MAC address, other device IDs (UDID), device type, type and version of the operating system, client version, information about the use of or other interaction with "Microsoft" products ("usage information"), other information that the user uploads, provides or creates while using the service, and metadata used for maintaining the service provided. Where applicable, and as is common with collaborative tools, further personal data may also be exchanged between the participants, such as chat messages, images, files, audio or video recordings, contact details or metadata used for maintaining the service provided. Only a minimum of data is processed if you take part in a "Microsoft Teams" "online meeting" without registering. "Online meetings" are only recorded with prior notice, and recordings are generally stored locally. Further information on the processing of personal data by "Microsoft Teams" can be found in its privacy policy.

Purposes of Data Processing and Legal Basis
We only process personal data in which we have a legitimate interest corresponding to the purpose, or where there is a legal obligation, namely for the following purposes

  • Contract processing
  • Information on offers, services, websites and other platforms on which we are present;
  • Communication with third parties and processing of their enquiries (e.g. job applications, enquiries);
  • Collection of personal data from publicly accessible sources for the purpose of customer acquisition, insofar as our legitimate interests require it and it is legally permissible;
  • Advertising and information about our services and offers to existing customers, unless you have objected to the use of your data for this purpose (if we send you advertising as an existing customer, you can object to this at any time; we will then put you on a block list against further advertising mailings);
  • Assertion of legal claims and defence in connection with legal disputes and official proceedings;
  • Prevention and investigation of criminal offences and other misconduct (e.g. conducting internal investigations, data analyses to combat fraud);
  • Safeguarding our operations, in particular our IT, our websites and other platforms;
  • Measures for IT, building and facility security and for the protection of our employees and other persons and of assets belonging to or entrusted to us (e.g. access controls, visitor lists, network and mail scanners, telephone recordings);
  • Conducting "online meetings".

Where you have given us your consent to process your personal data for specific purposes, we process your personal data within the scope of and on the basis of this consent, insofar as we have no other legal basis and require one. Consent given can be withdrawn at any time; however, this has no effect on data processing that has already taken place. Where the processing of your personal data relates to the administration of industrial property rights, the law and ordinances specify which data we process and in what form. We are thus legally obliged to inform the public about the property rights valid in Switzerland and the associated personal data.

Cookies and Image Elements
Our websites may use "cookies" and similar technologies that can identify your browser or device. A cookie is a small file that is sent to your computer or automatically stored on your computer or mobile device by the web browser you are using when you visit our website. If you visit this website again, we can recognise you, even if we do not know who you are. In addition to cookies that are only used during a session and are deleted after your visit to the website ("session cookies"), cookies can also be used to store user settings and other information for a certain period of time (e.g. two years) ("permanent cookies"). However, you can set your browser to reject cookies, to store them only for one session or to delete them prematurely. Most browsers are set to accept cookies by default.

Newsletters and Marketing Emails
Receiving newsletters and other marketing emails requires your consent. You can withdraw this consent at any time by unsubscribing from the newsletter.

Google Maps
We occasionally embed maps from the Google Maps service on our websites. This is a third-party service whose providers may be located in any country in the world (in the case of Google Maps, Google LLC in the USA, www.google.com). The data processed may include, in particular, users' IP addresses and location data, which, however, are not collected without their consent (usually given via the settings of their mobile devices). Privacy policy: https://www.google.com/policies/privacy/

Plug-ins
Our websites may use so-called plug-ins from social networks such as Facebook, Twitter, Xing and LinkedIn. This is visible to you in each case (typically via corresponding icons). We have configured these elements so that they are deactivated by default. If you activate them (by clicking on them), the operators of the respective social networks can register that you are on our website and where, and can use this information for their own purposes. The processing of your personal data is then the responsibility of this operator in accordance with its data protection provisions. We do not receive any information about you from the operator.

Links to Other Websites
Our websites may contain links to other websites (including LinkedIn, Facebook, Instagram and YouTube) or to embedded websites. ICS and ACS are not responsible for the content of other companies' websites (third-party websites) or for the practices of these companies in collecting personal data. When visiting third-party websites, you should read the website operators' policies on the protection of personal data and any other relevant policies.

Hosting
Our website is hosted by Virtualtec AG in Zurich, Switzerland. For every access to this website, Virtualtec creates standard web server log files containing the following information: IP address, date and time including time zone, browser request including origin of the request (referer or referrer), operating system used including user interface and version, browser used including language and version, amount of data transferred.

Social Media
We have only limited influence on the data processing carried out by the operators of social media platforms (e.g. management of members and the information shared). Where we are able to exert influence, we work within the scope of the options available to us to ensure that the platform operator handles data in compliance with data protection law. In many cases, however, we cannot influence the data processing carried out by the platform operator and do not know exactly which data it processes.
The platform operator runs the entire IT infrastructure of the service, has its own data protection provisions and maintains its own user relationship with registered users. In addition, the operator is solely responsible for all questions concerning the data in your user profile, to which we as a company have no access. Further information on data processing by the platform provider and further options to object can be found in the provider's privacy policy:

When the platforms are used, personal data is generally also processed by the respective platform operator on servers in third countries, in particular in the USA and the United Kingdom.

Disclosure of Data to Third Parties
Personal data is only passed on or disclosed within the legally permissible framework:

  • If the recipient provides services on behalf of ICS or ACS, such as visa procurement, banks, insurance companies, etc.
  • To establish, exercise or defend our legal rights
  • If the data subject has previously consented to the disclosure of personal data
  • In the event of mergers, sales, joint ventures, succession arrangements, etc.

In general, your personal data will not be passed on, sold or otherwise transferred to third parties unless this is necessary for the purpose of processing the contract or fulfilling our legal obligations, or you have expressly consented to it. In addition, data may be transferred to third parties if we are obliged to do so by law or by an enforceable official or court order.
Some of the recipients of such data are located in Switzerland, but they may be anywhere in the world. If we transfer data to a country without adequate statutory data protection, we ensure an adequate level of protection by means of appropriate contracts, or we rely on the statutory exceptions of consent, contract performance, the establishment, exercise or enforcement of legal claims, overriding public interests, published personal data or because it is necessary to protect the integrity of the data subjects.
The "Microsoft Teams" service used for "online meetings" is provided by a provider based in the USA; personal data is therefore also processed in a third country. An adequate level of data protection is ensured by contract.
You can request information about the contractual guarantees mentioned from our data protection officer at any time. However, we reserve the right to redact copies for reasons of data protection or confidentiality, or to provide only excerpts.

Retention Period of Personal Data

  • General
    We process and store your personal data for as long as is necessary to fulfil our contractual and legal obligations or otherwise for the purposes pursued with the processing, i.e. for example for the duration of the entire business relationship (from initial contact and processing through to the termination of a contract or project) and beyond in accordance with statutory retention and documentation obligations. Once the purpose no longer applies, the personal data is irrevocably deleted, unless the data is subject to a statutory retention obligation or is needed to exercise or defend legal claims.
  • Customer data
    After termination of the contract, ICS and ACS retain personal data for marketing purposes for as long as the legitimate interests of ICS and ACS require and it is legally permissible.
  • Application documents
    Application documents are deleted no later than 12 months after completion of the application process. Exceptions:
    • The documents of a successful applicant are transferred to the employee file.
    • The applicant agrees to the application documents being stored or retained for longer.

Data Security
We use appropriate technical and organisational security measures to protect the data we manage against accidental or intentional manipulation, loss, destruction or access by unauthorised persons, taking into account the state of the art, the costs of implementation, the likelihood of occurrence and the severity of the risk to the rights and freedoms of natural persons. Our security measures are continuously improved in line with technological developments.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by restricting physical access to the data.

Obligation to Provide Personal Data
Within the scope of our business relationship, you must provide the personal data required for establishing and conducting a business relationship and for fulfilling the associated contractual obligations (as a rule, you are not legally obliged to provide us with data). Without this data, we will generally not be able to conclude or perform a contract with you (or the entity or person you represent) or to fulfil our legal obligations.

Profiling and Automated Decision-Making
Personal data is not used as the basis for automated decision-making. We do not carry out any profiling with personal data.

Rights of the Data Subject
Within the scope of the data protection law applicable to you and to the extent provided for therein (as in the case of the GDPR, for example), you have the right of access, rectification and erasure, the right to restriction of data processing and otherwise to object to our data processing, as well as the right to receive certain personal data for the purpose of transferring it to another body (so-called data portability). Please note, however, that we reserve the right to assert the restrictions provided for by law, for example if we are obliged to retain or process certain data, have an overriding interest in doing so (insofar as we are entitled to rely on this) or need the data to assert claims. If you incur any costs, we will inform you in advance. We have already provided information about the possibility of withdrawing your consent in the section "Purposes of Data Processing and Legal Basis". Please note that exercising these rights may conflict with contractual agreements and may have consequences such as early termination of the contract or costs. In such cases, we will inform you in advance where this is not already regulated by contract or by law.
Exercising such rights generally requires you to prove your identity clearly (e.g. by means of a copy of an identity document where your identity is otherwise not clear or cannot be verified). To assert your rights, you can contact us at the address given in the section "Data Protection Officer".
In addition, every data subject has the right to enforce their claims in court or to lodge a complaint with the competent data protection authority. The competent data protection authority in Switzerland is the Federal Data Protection and Information Commissioner (www.edoeb.admin.ch).

Changes
We may amend this privacy policy at any time without prior notice. The current version published on our website applies. Where appropriate, we will inform you of any update by email or in another suitable manner.