Privacy Policy
With this Privacy Policy, we inform you about the processing of personal data in connection with our activities and operations, including our website under the domain name www.pay-attention.ch. In particular, we explain which personal data we process, for what purposes, how and where we process it. We also provide information about the rights of individuals whose data we process.
We have prepared this Privacy Policy in German. If this Privacy Policy is published in another language, the German-language version shall prevail. The English version has been machine-translated.
For individual or additional activities and operations, we may publish further privacy policies or other information relating to data protection.
We are subject to Swiss law and, where applicable, foreign law, in particular the law of the European Union (EU), including the European Union General Data Protection Regulation (GDPR).
By decision of 26 July 2000, the European Commission recognised that Swiss data protection law provides an adequate level of data protection. In its report of 15 January 2024, the European Commission confirmed this adequacy decision.
1. Contact Addresses
The controller responsible for data protection is:
Pay Attent!on Association
Dolderstrasse 17
8032 Zurich
Switzerland
In individual cases, third parties may be responsible for the processing of personal data, or joint responsibility with third parties may exist. Upon request, we will be happy to provide data subjects with information regarding the respective responsibility.
2. Definitions and Legal Bases
2.1 Definitions
Data subject: A natural person whose personal data we process.
Personal data: Any information relating to an identified or identifiable natural person.
Sensitive personal data: Data relating to trade union, political, religious or philosophical views or activities; data concerning health, intimate life or affiliation with a race or ethnicity; genetic data; biometric data that uniquely identifies a natural person; data concerning criminal and administrative sanctions or prosecutions; and data concerning measures of social assistance.
Processing: Any operation performed on personal data, regardless of the means and procedures applied, such as requesting, comparing, adapting, archiving, retaining, retrieving, disclosing, obtaining, recording, collecting, deleting, revealing, arranging, organising, storing, modifying, disseminating, linking, destroying and using personal data.
European Economic Area (EEA): The Member States of the European Union (EU), as well as the Principality of Liechtenstein, Iceland and Norway.
2.2 Legal Bases
We process personal data in accordance with Swiss law, in particular the Federal Act on Data Protection (Data Protection Act, FADP) and the Ordinance on Data Protection (Data Protection Ordinance, DPO). The English-language information provided by the Swiss Federal Data Protection and Information Commissioner (FDPIC) on the applicable legal framework is available here.
Where and to the extent that the European General Data Protection Regulation (GDPR) applies, we process personal data on the basis of at least one of the following legal bases:
Art. 6(1)(b) GDPR for the processing of personal data necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
Art. 6(1)(f) GDPR for the processing of personal data necessary for the purposes of our legitimate interests or those of a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Such interests include, in particular, the long-term, people-friendly, secure and reliable operation of our activities and operations, ensuring information security, protection against misuse, enforcement of our own legal claims and compliance with Swiss law.
Art. 6(1)(c) GDPR for the processing of personal data necessary for compliance with a legal obligation to which we are subject under applicable law of Member States of the European Economic Area (EEA).
Art. 6(1)(e) GDPR for the processing of personal data necessary for the performance of a task carried out in the public interest.
Art. 6(1)(a) GDPR for the processing of personal data based on the consent of the data subject.
Art. 6(1)(d) GDPR for the processing of personal data necessary to protect the vital interests of the data subject or another natural person.
Art. 9(2) et seq. GDPR for the processing of special categories of personal data, in particular based on the consent of the data subjects.
The European General Data Protection Regulation (GDPR) refers to the processing of personal data as the "processing of personal data" and to the processing of sensitive personal data as the "processing of special categories of personal data" (Art. 9 GDPR).
3. Nature, Scope and Purpose of the Processing of Personal Data
We process those personal data that are necessary to enable us to carry out our activities and operations on a long-term, people-friendly, secure and reliable basis. The personal data processed may in particular fall into the categories of browser and device data, content data, communication data, metadata, usage data, master data including inventory and contact data, location data, transaction data, contract data and payment data. Personal data may also constitute sensitive personal data.
We also process personal data that we receive from third parties, obtain from publicly accessible sources or collect in the course of our activities and operations, insofar as such processing is permitted.
Where necessary, we process personal data with the consent of the data subjects. In many cases, we may process personal data without consent, for example in order to comply with legal obligations or to safeguard overriding interests. We may also request consent from data subjects where such consent is not legally required.
We process personal data for as long as necessary for the respective purpose. In particular, we anonymise or delete personal data depending on statutory retention and limitation periods.
4. Disclosure of Personal Data
We may disclose personal data to third parties, have personal data processed by third parties, or process personal data jointly with third parties. Such third parties may include specialised service providers whose services we use. Such third parties may in turn disclose personal data to other third parties.
In connection with our activities and operations, we may in particular disclose personal data to banks and other financial service providers, authorities, educational and research institutions, consultants and lawyers, accounting and fiduciary service providers, debt collection agencies, interest groups and representative organisations, IT service providers, cooperation partners, credit and business information agencies, logistics and shipping companies, marketing and advertising agencies, media organisations, parent, sister and subsidiary companies, organisations and associations, social institutions, telecommunications companies, insurers and payment service providers.
5. Communication
We process personal data in order to communicate with individuals as well as with authorities, organisations and companies. In particular, we process data provided to us by a data subject when contacting us, for example by postal mail or email. We may store such data in an address book or using comparable tools.
Third parties who provide us with data concerning other individuals are legally obliged to independently ensure the data protection of those data subjects. In particular, they must ensure that they are permitted to provide such data and must also ensure the accuracy of the data provided.
6. Data Security
We take appropriate technical and organisational measures to ensure a level of data security appropriate to the respective risk. In particular, our measures ensure the confidentiality, availability, traceability and integrity of the personal data processed, although absolute data security cannot be guaranteed.
Access to our website and our other digital presence is protected by transport encryption (SSL / TLS, in particular using Hypertext Transfer Protocol Secure, abbreviated HTTPS). Most browsers warn users when visiting a website without transport encryption.
Our digital communications are subject—as is generally the case with digital communications—to indiscriminate mass surveillance without cause or suspicion by security authorities in Switzerland, elsewhere in Europe, in the United States of America (USA) and in other countries. We cannot directly influence the corresponding processing of personal data by intelligence services, police authorities or other security authorities. We also cannot rule out the possibility that a data subject may be subject to targeted surveillance.
7. Personal Data Abroad
As a general rule, we process personal data in Switzerland and in the European Economic Area (EEA). However, we may also export or transfer personal data to other countries, in particular for the purpose of processing such data there or having them processed there.
We may export personal data to any country on Earth and elsewhere in the universe, provided that the applicable law ensures an adequate level of data protection in accordance with a decision by the Swiss Federal Council and—where and to the extent that the GDPR applies—in accordance with a decision by the European Commission.
We may transfer personal data to countries whose laws do not ensure an adequate level of data protection if data protection is ensured for other reasons, in particular on the basis of standard data protection clauses or other appropriate safeguards. In exceptional cases, we may export personal data to countries without adequate or appropriate data protection if the specific data protection requirements for such transfers are met, for example based on the explicit consent of the data subjects or where the transfer is directly related to the conclusion or performance of a contract. Upon request, we will be happy to provide data subjects with information about any safeguards in place or provide a copy of such safeguards.
8. Rights of Data Subjects
8.1 Data Protection Rights
We grant data subjects all rights provided for under applicable law. In particular, data subjects have the following rights:
Right of access: Data subjects may request information as to whether we process personal data concerning them and, if so, which personal data are involved. Data subjects may also obtain the information necessary to exercise their data protection rights and to ensure transparency. This includes the personal data themselves and, among other things, information about the purpose of processing, the retention period, any disclosure or export of data to other countries, and the source of the personal data.
Rectification and restriction: Data subjects may request that inaccurate personal data be rectified, incomplete data be completed, and the processing of their data be restricted.
Right to express their own point of view and to obtain human review: Data subjects may express their own point of view and request human review of decisions based solely on automated processing of personal data which produce legal effects concerning them or similarly significantly affect them ("automated individual decisions").
Erasure and objection: Data subjects may request the deletion of personal data ("right to be forgotten") and may object to the processing of their data with effect for the future.
Data disclosure and data portability: Data subjects may request the disclosure of personal data or the transfer of their data to another controller.
We may postpone, restrict or refuse the exercise of data subjects' rights to the extent permitted by law. We may inform data subjects of any requirements that must be met to exercise their data protection rights. For example, we may refuse access, in whole or in part, by reference to confidentiality obligations, overriding interests or the protection of other persons. We may also refuse the deletion of personal data, in whole or in part, particularly by reference to statutory retention obligations.
In exceptional cases, we may charge fees for exercising rights. We will inform data subjects in advance of any applicable fees.
We are required to take reasonable measures to identify data subjects who request access or exercise other rights. Data subjects are required to cooperate with us in this regard.
8.2 Legal Remedies
Data subjects have the right to enforce their data protection rights through legal proceedings or to submit a notification or complaint to a data protection supervisory authority.
The supervisory authority responsible for private controllers and federal bodies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC). Information about the FDPIC and its supervisory activities is available here.
European data protection supervisory authorities are organised as members of the European Data Protection Board (EDPB). In some Member States of the European Economic Area (EEA), data protection supervisory authorities are structured on a federal basis, particularly in Germany.
9. Use of the Website
9.1 Cookies
We may use cookies. Cookies—including our own cookies (first-party cookies) and cookies from third parties whose services we use (third-party cookies)—are data stored in the browser. Such stored data need not be limited to traditional text-based cookies.
Cookies may be stored temporarily in the browser as "session cookies" or for a specific period as so-called permanent cookies. Session cookies are automatically deleted when the browser is closed. Permanent cookies have a defined storage period. Cookies enable, in particular, a browser to be recognised when our website is visited again and thereby allow, for example, the reach of our website to be measured. Permanent cookies may also be used for online marketing.
Cookies can be completely or partially disabled, restricted or deleted at any time in the browser settings. Browser settings often also allow cookies to be deleted automatically and otherwise managed. Without cookies, our website may no longer be fully available. We actively request explicit consent to the use of cookies, at least where and to the extent required under applicable law.
For cookies used for performance and reach measurement or advertising, a general objection ("opt-out") is possible for numerous services via AdChoices, the Network Advertising Initiative (NAI), YourAdChoices or Your Online Choices.
9.2 Logging
For each access to our website and our other digital presence, we may log at least the following information, insofar as such information is routinely determined or transmitted to our digital infrastructure during such access: date and time including time zone, IP address, access status (HTTP status code), operating system including user interface and version, browser including language and version, individual subpage of our website accessed including the amount of data transferred, and the website most recently accessed in the same browser window (referrer).
We record such information, which may also constitute personal data, in log files. This information is necessary to provide our digital presence on a long-term, people-friendly and reliable basis. It is also necessary to ensure data security, including through third parties or with the assistance of third parties.
9.3 Tracking Pixels
We may incorporate tracking pixels into our digital presence. Tracking pixels are also known as web beacons. Tracking pixels—including those provided by third parties whose services we use—are usually small, invisible images or scripts written in JavaScript that are automatically retrieved when our digital presence is accessed. Tracking pixels can collect at least the same information as logging in log files.
10. Notifications and Communications
10.1 Performance and Reach Measurement
Notifications and communications may contain web links or tracking pixels that record whether an individual communication has been opened and which web links have been clicked. Such web links and tracking pixels may also record the use of notifications and communications on a personal basis.
We require this statistical recording of usage for performance and reach measurement in order to send notifications and communications effectively and in a people-friendly manner, on a long-term, secure and reliable basis, taking into account the needs and reading habits of recipients.
10.2 Consent and Objection
As a general rule, you must consent to the use of your email address and other contact addresses unless their use is permitted for other legal reasons. If applicable, we may use the "double opt-in" procedure to obtain confirmation of consent. In this case, you will receive a communication containing instructions for confirming your consent twice. We may record consents obtained, including the IP address and timestamp, for evidentiary and security purposes.
As a general rule, you may object to receiving notifications and communications, such as newsletters, at any time. By objecting, you may also object to the statistical recording of usage for performance and reach measurement. Required notifications and communications relating to our activities and operations remain unaffected.
10.3 Service Providers for Notifications and Communications
We send notifications and communications with the assistance of specialised service providers.
In particular, we use:
Mailchimp: Communication platform; provider: The Rocket Science Group LLC DBA Mailchimp (USA), a subsidiary of Intuit Inc. (USA). Information on data protection is available in Mailchimp's legal policies, including its Global Privacy Statement, country- and region-specific provisions, privacy FAQs, information on European data transfers, security information, cookie statement, data subject rights requests and legal
11. Social Media
We maintain a presence on social media platforms and other online platforms in order to communicate with interested individuals and provide information about our activities and operations. In connection with such platforms, personal data may also be processed outside Switzerland and the European Economic Area (EEA).
The respective general terms and conditions, terms of use, privacy policies and other provisions of the individual operators of such platforms also apply. These provisions provide information in particular about the rights of data subjects directly vis-à-vis the respective platform, including, for example, the right of access.
For our social media presence on Facebook, including the so-called Page Insights, we are, where and to the extent that the GDPR applies, jointly responsible with Meta Platforms Ireland Limited (Ireland). Meta Platforms Ireland Limited is part of the Meta group of companies, including companies in the USA. Page Insights provide information about how visitors interact with our Facebook presence. We use Page Insights in order to provide our social media presence on Facebook effectively and in a people-friendly manner.
Further information about the nature, scope and purpose of data processing, information about the rights of data subjects and the contact details of Facebook and its data protection officer can be found in Facebook's privacy policy. We have entered into the so-called "Controller Addendum" with Facebook and have thereby agreed, in particular, that Facebook is responsible for ensuring the rights of data subjects. The corresponding information regarding Page Insights can be found on the page concerning Page Insights data.
12. Third-Party Services
We use services provided by specialised third parties in order to operate our activities and operations on a long-term, people-friendly, secure and reliable basis. Such services may include embedding functions and content into our website. When such content is embedded, the services used may, for technically necessary reasons, collect users' IP addresses at least temporarily.
For necessary security-related, statistical and technical purposes, third parties whose services we use may process data relating to our activities and operations in aggregated, anonymised or pseudonymised form. This may include performance or usage data required to provide the respective service.
In particular, we use:
Google services: Providers: Google LLC (USA) / Google Ireland Limited (Ireland), partly for users in the European Economic Area (EEA) and Switzerland. General information on data protection is available in
Google's Privacy Policy, including information on how Google handles privacy, how Google uses personal data, Google's data protection obligations, the Google products privacy guide, how Google uses data from websites or apps that use its services, its cookie policy and personalised advertising settings.
12.1 Digital Infrastructure
We use services provided by specialised third parties in order to make the digital infrastructure required for our activities and operations available. These include, for example, hosting and storage services provided by selected providers.
In particular, we use:
METANET: Hosting; provider: METANET AG (Switzerland). Information on data protection is available in METANET's privacy policy and legal information, including information on technical and organisational measures.
12.2 Digital Content
We use services provided by specialised third parties to integrate digital content into our website. Digital content includes, in particular, images and video material, music and podcasts.
In particular, we use:
Vimeo: Video platform; provider: Vimeo Inc. (USA). Information on data protection is available in Vimeo's Privacy Policy.
YouTube: Video platform; provider: Google. YouTube-specific information is available in Your Data in YouTube, including information about privacy settings and controls.
13. Performance and Reach Measurement
We seek to measure the success and reach of our activities and operations. In this context, we may also measure the impact of references from third parties or analyse how different parts or versions of our digital presence are used ("A/B testing"). Based on the results of performance and reach measurement, we may in particular correct errors, strengthen popular content or make improvements.
For performance and reach measurement, the IP addresses of individual users are recorded in most cases. In such cases, IP addresses are generally shortened ("IP masking") in order to comply with the principle of data minimisation through the corresponding pseudonymisation.
Cookies may be used and user profiles may be created as part of performance and reach measurement. Any user profiles created may include, for example, individual pages visited or content viewed on our digital presence, information about the size of the screen or browser window and the user's approximate location. As a general rule, any user profiles are created exclusively in pseudonymised form and are not used to identify individual users. Individual third-party services with which users are logged in may potentially associate the use of our online offering with the user's account or profile with the respective service.
In particular, we use:
Google Marketing Platform: Performance and reach measurement, in particular using Google Analytics; provider: Google. Google Marketing Platform-specific information includes measurement across different browsers and devices (cross-device tracking) using pseudonymised IP addresses, which are only exceptionally transmitted to Google in the USA in full. Further information is available in Google's Privacy Policy and Google's information on data controls in Google Analytics.
Google Tag Manager: Integration and management of services provided by Google and third parties, in particular for performance and reach measurement; provider: Google. Information specific to Google Tag Manager is available in Google's information on data privacy and security for Tag Manager.
14. Final Information Regarding this Privacy Policy
We created this Privacy Policy using the privacy policy generator provided by Datenschutzpartner.
We may update this Privacy Policy at any time. We will inform you of updates by publishing the current version of this Privacy Policy on our website.