Privacy Policy

Contact Information

Responsibility for the processing of personal data:

Source 10
Lara Holzer
Quellenweg 10
3652 Hilterfingen

info@quelle10.ch

We will notify you if, in specific cases, there are other parties responsible for processing personal data.

Data Protection Officer or Data Protection Consultant

We have designated the following data protection officer or data protection advisor as the point of contact for data subjects and government agencies regarding inquiries related to data protection:

Source 10
Lara Holzer
Quellenweg 10
3652 Hilterfingen

info@quelle10.ch

Data Protection Representative in the European Economic Area (EEA)

We have appointed the following data protection representative in accordance with Article 27 of the GDPR:

‍VGS Datenschutzpartner GmbH

Am Kaiserkai 69,
, 20457 Hamburg,
, Germany

info@datenschutzpartner.eu‍

The Data Protection Representative serves as an additional point of contact for data subjects and public authorities in the European Union (EU) and the rest of the European Economic Area (EEA) for inquiries related to the GDPR.

Terms and Legal Basis

Terms

Personal data refers to any information relating to an identified or identifiable natural person. A data subject is a person whose personal data we process. Processing encompasses any handling of personal data, regardless of the means and methods used, such as retrieving, comparing, modifying, archiving, retaining, reading, disclosing, obtaining, recording, collecting, deleting, revealing, classifying, organizing, storing, altering, disseminating, linking, destroying, and using personal data.

The European Economic Area (EEA) comprises the member states of the European Union (EU) as well as the Principality of Liechtenstein, Iceland, and Norway. The General Data Protection Regulation (GDPR) refers to the handling of personal data as the processing of personal data.

Legal Basis

We process personal data in accordance with Swiss data protection law, in particular the Federal Act on Data Protection (Data Protection Act, DSG) and the Ordinance on Data Protection (Data Protection Ordinance, DSV).

We process personal data—to the extent that the General Data Protection Regulation (GDPR) applies—in accordance with at least one of the following legal bases:

  • Article 6(1)(b) of the GDPR for the processing of personal data necessary to fulfill a contract with the data subject and to take steps prior to entering into a contract.
  • Article 6(1)(f) of the GDPR for the processing of personal data necessary to safeguard our legitimate interests or those of third parties, unless the fundamental freedoms and rights, as well as the interests, of the data subject take precedence. Legitimate interests include, in particular, our interest in being able to conduct our activities and operations in a sustainable, user-friendly, secure, and reliable manner and to communicate about them; ensuring information security; protecting against misuse; enforcing our own legal claims; and complying with Swiss law.
  • Article 6(1)(c) of the GDPR for the processing of personal data necessary to comply with a legal obligation to which we are subject under the applicable law of Member States in the European Economic Area (EEA).
  • Article 6(1)(e) of the GDPR for the necessary processing of personal data to perform a task carried out in the public interest.
  • Article 6(1)(a) of the GDPR for the processing of personal data with the consent of the data subject.
  • Article 6(1)(d) of the GDPR for the processing of personal data necessary to protect the vital interests of the data subject or another natural person.

Nature, Scope, and Purpose

We process the personal data necessary to carry out our activities and operations in a sustainable, user-friendly, secure, and reliable manner. Such personal data may include, in particular, the following categories: account and contact information, browser and device data, content data, metadata or ancillary data, usage data, location data, sales data, and contract and payment data.

We process personal data for as long as is necessary for the respective purpose(s) or as required by law. Personal data that is no longer needed for processing is anonymized or deleted.

We may have third parties process personal data. We may process personal data jointly with third parties or transfer it to third parties. Such third parties include, in particular, specialized service providers whose services we use. We ensure data protection even when such third parties are involved.

As a general rule, we process personal data only with the consent of the individuals concerned. If and to the extent that processing is permitted for other legal reasons, we may refrain from obtaining consent. For example, we may process personal data without consent in order to fulfill a contract, to comply with legal obligations, or to protect legitimate interests.

In this context, we process, in particular, information that a data subject voluntarily provides to us when contacting us—for example, by mail, email, instant messaging, contact form, social media, or telephone—or when registering for a user account. We may store such information, for example, in an address book, in a customer relationship management (CRM) system, or using similar tools. If we receive data about other individuals, the parties transmitting the data are obligated to ensure data protection for those individuals and to verify the accuracy of their personal data.

We also process personal data that we receive from third parties, obtain from publicly available sources, or collect in the course of our activities and operations, provided that such processing is permitted by law.

Personal Data Abroad

We generally process personal data in Switzerland and within the European Economic Area (EEA). However, we may also export or transfer personal data to other countries, in particular to process it there or have it processed there.

We may export personal data to any country or territory on Earth, as well as elsewhere in the universe, provided that the law of that jurisdiction, in accordance with a decision by the Swiss Federal Council, ensures an adequate level of data protection and — provided that and to the extent that the General Data Protection Regulation (GDPR) applies — ensures an adequate level of data protection in accordance with a decision by the European Commission.

We may transfer personal data to countries whose laws do not provide adequate data protection, provided that data protection is ensured for other reasons, in particular on the basis of standard data protection clauses or other appropriate safeguards.

In exceptional cases, we may export personal data to countries without adequate or appropriate data protection if the specific requirements under data protection law are met, such as the explicit consent of the data subjects or a direct connection to the conclusion or performance of a contract. Upon request, we are happy to provide data subjects with information about any safeguards in place or to supply a copy of such safeguards.

Rights of Data Subjects

Data Protection Claims

We grant data subjects all rights under applicable data protection law.

Data subjects have the following rights in particular:

  • Right of Access: Data subjects may request information regarding whether we process personal data about them and, if so, what personal data is involved. Data subjects will also receive the information necessary to assert their rights under data protection law and to ensure transparency. This includes the personal data being processed as such, as well as, among other things, details regarding the purpose of processing, the retention period, any disclosure or export of data to other countries, and the origin of the personal data.
  • Correction and Restriction: Data subjects may have inaccurate personal data corrected, incomplete data supplemented, and the processing of their data restricted.
  • Deletion and Objection: Data subjects may request the deletion of their personal data (“right to be forgotten”) and object to the processing of their data with future effect.
  • Data Disclosure and Data Transfer: Data subjects may request the disclosure of their personal data or the transfer of their data to another data controller.

We may defer, restrict, or deny the exercise of data subjects’ rights to the extent permitted by law. We may inform data subjects of any prerequisites that must be met in order to exercise their rights under data protection law. For example, we may refuse to provide information, in whole or in part, citing trade secrets or the protection of other individuals. We may also, for example, refuse to delete personal data, in whole or in part, citing statutory retention obligations.

In exceptional cases, we may charge a fee for the exercise of these rights. We will inform the individuals concerned in advance of any such fees.

We are required to take reasonable measures to identify data subjects who request access to their personal information or exercise other rights. Data subjects are required to cooperate.

Right to File a Complaint

Data subjects have the right to enforce their data protection rights through legal action or to file a complaint with a competent data protection supervisory authority.

The data protection supervisory authority for private data controllers and federal agencies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC). Data subjects have the right—provided that the General Data Protection Regulation (GDPR) applies—to lodge a complaint with a competent European data protection supervisory authority.

Data Security

We take appropriate technical and organizational measures to ensure data security commensurate with the respective risk. However, we cannot guarantee absolute data security.

Access to our website is secured using transport encryption (SSL/TLS, specifically the Hypertext Transfer Protocol Secure, abbreviated as HTTPS). Most browsers indicate transport encryption with a padlock icon in the address bar. Our digital communications—like all digital communications in general—are subject to mass surveillance without cause or suspicion, as well as other forms of surveillance by security agencies in Switzerland, the rest of Europe, the United States of America (USA), and other countries. We have no direct influence over the processing of personal data by intelligence agencies, police departments, and other security authorities.

Use of the Website

Cookies

We may use cookies. Cookies—including our own cookies (first-party cookies) and cookies from third parties whose services we use (third-party cookies)—are data stored in the browser. Such stored data is not necessarily limited to traditional text-based cookies.

Cookies can be stored temporarily in the browser as “session cookies” or for a specific period of time as so-called permanent cookies. “Session cookies” are automatically deleted when the browser is closed. Persistent cookies have a specific retention period. In particular, cookies make it possible to recognize a browser the next time you visit our website and, for example, to measure the reach of our website. However, persistent cookies can also be used for online marketing, for example.

Cookies can be disabled entirely or partially, or deleted, at any time in your browser settings. Without cookies, however, you may not be able to use our website to its full extent. We actively request your explicit consent to the use of cookies—at least to the extent necessary.

For cookies used to measure performance and reach or for advertising, many services offer a general opt-out option through AdChoices (Digital Advertising Alliance of Canada), the Network Advertising Initiative (NAI), YourAdChoices (Digital Advertising Alliance), or Your Online Choices (European Interactive Digital Advertising Alliance, EDAA).

Server Log Files

For each visit to our website, we may collect the following information, provided that it is transmitted by your browser to our server infrastructure or can be determined by our web server: date and time, including time zone; Internet Protocol (IP) address; access status (HTTP status code); operating system, including user interface and version; browser, including language and version; specific subpages of our website accessed, including the amount of data transferred; and the last webpage accessed in the same browser window (referrer).

We store such information, which may also constitute personal data, in server log files. This information is necessary to ensure that our website is available on a long-term basis, is user-friendly, and operates reliably, as well as to ensure data security and, in particular, the protection of personal data—including through third parties or with the assistance of third parties.

Pixel counter

We may use tracking pixels on our website. Tracking pixels are also known as web beacons. Tracking pixels—including those from third parties whose services we use—are small, typically invisible images that are automatically loaded when you visit our website. Tracking pixels can be used to collect the same information as server log files.

Notifications and Announcements

We send notifications and messages via email and through other communication channels, such as instant messaging or text messages.

Measuring Success and Reach

Notifications and messages may contain web links or tracking pixels that track whether an individual message has been opened and which web links were clicked within it. Such web links and tracking pixels may also track the use of notifications and messages on a personal basis. We require this statistical tracking of usage to measure effectiveness and reach so that we can send notifications and communications in a way that is effective, user-friendly, sustainable, secure, and reliable, based on the needs and reading habits of the recipients.

Consent and Objection

As a general rule, you must expressly consent to the use of your email address and other contact information, unless such use is permitted for other legal reasons. When obtaining consent, we use the “double opt-in” procedure whenever possible; this means you will receive an email containing a web link that you must click to confirm, thereby preventing misuse by unauthorized third parties. We may log such consents, including the Internet Protocol (IP) address as well as the date and time, for evidentiary and security purposes. You may generally opt out of receiving notifications and communications, such as newsletters, at any time. By objecting in this way, you may also object to the statistical tracking of your usage for the purpose of measuring performance and reach. This does not apply to necessary notifications and communications related to our activities and operations.

Service Provider for Notifications and Communications

We send notifications and messages through specialized service providers.

Social Media

We maintain a presence on social media platforms and other online platforms to communicate with interested individuals and provide information about our activities and operations. In connection with such platforms, personal data may also be processed outside of Switzerland and the European Economic Area (EEA). The General Terms and Conditions (GTC), Terms of Use, privacy policies, and other provisions of the individual operators of such platforms also apply in each case. These provisions provide information, in particular, about the rights of data subjects directly vis-à-vis the respective platform, including, for example, the right of access.

We are jointly responsible with Meta Platforms Ireland Limited (Ireland) for our social media presence on Facebook, including what are known as Page Insights—to the extent that the General Data Protection Regulation (GDPR) applies. Meta Platforms Ireland Limited is part of the Meta group of companies (including those in the U.S.). Page Insights provide information about how visitors interact with our Facebook presence. We use Page Insights to ensure that our social media presence on Facebook is effective and user-friendly.

Further information regarding the nature, scope, and purpose of data processing, details on the rights of data subjects, and the contact information for Facebook and Facebook’s Data Protection Officer can be found in Facebook’s Privacy Policy. We have entered into the so-called“Addendum for Controllers”with Facebook and have thereby specifically agreed that Facebook is responsible for ensuring the rights of data subjects. For the so-called Page Insights, the relevant information can be found on the “Information about Page Insights” page, including “Information about Page Insights Data.”

Third-Party Services

We use services provided by specialized third parties to ensure that our activities and operations are sustainable, user-friendly, secure, and reliable. These services allow us, among other things, to embed features and content into our website. When content is embedded in this way, the services used collect users’ Internet Protocol (IP) addresses—at least temporarily—for technically necessary reasons.

For necessary security-related, statistical, and technical purposes, third parties whose services we use may process data related to our activities and operations in an aggregated, anonymized, or pseudonymized form. This includes, for example, performance or usage data necessary to provide the respective service.

In particular, we use:

Digital Infrastructure

We use services provided by specialized third parties to access the digital infrastructure we need in connection with our activities and operations. These include, for example, hosting and storage services from selected providers.

In particular, we use:

Ways to Contact Us

We use services from selected providers to better communicate with third parties, such as potential and existing customers.

Scheduling

We use services provided by specialized third parties to enable online scheduling of appointments, such as for meetings. In addition to this Privacy Policy, any terms and conditions directly applicable to the services used—such as terms of use or privacy policies—also apply.

Social Media Features and Social Media Content

We use third-party services and plugins to embed features and content from social media platforms and to enable the sharing of content on social media platforms and through other channels.

In particular, we use:

Maps

We use third-party services to embed maps on our website.

In particular, we use:

Fonts:

We use third-party services to embed selected fonts, icons, logos, and symbols on our website.

In particular, we use:

Advertisement

We take advantage of the opportunity to display targeted advertisements for our activities and services on third-party platforms, such as social media platforms and search engines. With such advertising, we aim in particular to reach people who are already interested in our activities and services or who might be interested in them (remarketing and targeting). To this end, we may transmit relevant information—which may include personal data—to third parties that facilitate such advertising. We may also determine whether our advertising is successful, specifically whether it leads to visits to our website (conversion tracking).

Third parties with whom we advertise and where you are registered as a user may, in some cases, associate your use of our website with your profile on their platform.

In particular, we use:

Measuring Success and Reach

We seek to determine how our online offerings are used. In this context, we can, for example, measure the success and reach of our activities and initiatives, as well as the impact of third-party links on our website. However, we can also, for example, test and compare how different parts or versions of our online offerings are used (the “A/B testing” method). Based on the results of these success and reach measurements, we can, in particular, fix errors, highlight popular content, or make improvements to our online offerings.

In most cases, the Internet Protocol (IP) addresses of individual users are stored for the purpose of measuring success and reach. In this context, IP addresses are always truncated (“IP masking”) in order to comply with the principle of data minimization through the corresponding pseudonymization.

Cookies may be used to measure success and reach, and user profiles may be created. Any user profiles created may include, for example, the individual pages visited or content viewed on our website, information about the size of the screen or browser window, and the user’s location (at least approximately). As a general rule, any user profiles created are exclusively pseudonymized and are not used to identify individual users. Certain third-party services with which users are registered may, in some cases, associate the use of our online offering with the user’s account or profile on the respective service.

In particular, we use:

  • Google Analytics: Performance and reach measurement; Provider: Google; Google Analytics-specific information: Tracking also takes place across different browsers and devices (cross-device tracking) and uses pseudonymized Internet Protocol (IP) addresses, which are only transmitted in full to Google in the U.S. in exceptional cases; see “Data Protection” and “Browser Add-on to Disable Google Analytics.”
  • Google Tag Manager: Integration and management of other services for measuring performance and reach, as well as other services from Google and third parties; Provider: Google; Google Tag Manager-specific information: “Data collected via Google Tag Manager”; additional information on data protection can be found in the documentation for the individual integrated and managed services.

Final Provisions

We created this Privacy Policy using the privacy policy generator from Datenschutz-Partner. We may amend and supplement this Privacy Policy at any time. We will provide notice of such modifications and additions in an appropriate manner, in particular by publishing the most current privacy policy on our website. Through this privacy policy, we explain what personal data we process in connection with our activities and operations, including our www.latviaplan.ch-Website. In particular, we explain for what purposes, how, and where we process which personal data. We also provide information about the rights of individuals whose data we process. Additional privacy policies and other legal documents, such as General Terms and Conditions (GTC), Terms of Use, or Terms of Participation, may apply to specific or additional activities and operations. We are subject to Swiss data protection law as well as any applicable foreign data protection laws, such as, in particular, those of the European Union (EU) under the General Data Protection Regulation (GDPR). The European Commission recognizes that Swiss data protection law ensures an adequate level of data protection.