PRIVACY POLICY

Your security is important to us

Our Commitment to Privacy

The protection of your data is very important to us! Therefore we follow the legal regulations for data protection (GDPR) and do everything possible to protect your data. The person responsible within the meaning of the Basic Data Protection Regulation and other national data protection laws of the member states of the European Union (EU) and other data protection regulations is the:

MARBELL AG
Luzernstrasse 1
6343 Rotkreuz
Switzerland

The internal data protection officer of the company is:

Mr. Martin Wyss
Email: datenschutz@marbell.com

Introduction

The protection of your data is very important to us! Therefore we follow the legal regulations for data protection and do everything possible to protect your data.

This data protection declaration is intended to give you as a customer or interested party a detailed overview of how and to what extent your data is collected, stored, processed, passed on and transmitted by us when you sites visit us or use our services. In addition, we want you to get an overview of the data protection measures we have in place and the options available to you when you site visit us and use our services.

In order to ensure the protection of your data in the future as well, in particular in accordance with new legal requirements and technical developments, it is essential that this data protection declaration be adapted from time to time. We therefore recommend that you read our information and notes on data processing at regular intervals.

We have tried to distance ourselves as much as possible from legal phrases in the preparation of this privacy statement to ensure that non-lawyers understand everything. If references to the legal text appear in some places, this is solely due to completeness. If sections are not understandable, please let us know so that we can revise the relevant section.

However, it has proven to be very difficult to draft a privacy statement that is on the one hand site transparent, comprehensible and complete and on the other hand site does not overwhelm the reader because of its length. We have therefore decided to give you an overview in a general part first, which you can deepen in the further part of the privacy policy. Please take a moment to read this privacy policy at your leisure. Should you have any further questions regarding data protection, please do not hesitate to contact our data protection officer Martin Wyss.

What data is processed?

If we talk about data processing, we always mean your personal data. In the art. 4 no. 1, these GDPR are defined as information relating to an identified or identifiable person. This means all data that is directly or indirectly related to you, e.g. first name, last name, addresses, e-mail addresses, user behaviour, etc. Information collected in connection with online sites or services that we do not own or control is not covered by this privacy statement. Websites or services of other MARBELL customers are also excluded.

Why do we process personal data?

For one thing, there's no getting around it: In order to conclude a contract with us it is absolutely necessary to know your master data. On the other hand, we want to provide you as a customer with the best possible user experience and are therefore always striving to optimize our services. We process personal data only in compliance with the statutory provisions. This means that the data will only be processed if a legal permission is available. In particular, if the data processing is necessary for the provision of our contractual services or for the use or online services or is required by law. In addition, we process data if we have your consent or if we have a legitimate interest in processing it (e.g. interest in the analysis, optimization, economic operation, security of our online offer, especially in measuring the range, creation of profiles for advertising and marketing purposes as well as the collection of access data and the use of the services of third parties. In the second section, "In depth: cookies and other technologies", we give you a comprehensive overview of the use and application of these.

When and what extent do we process personal data?

In the following you will find an overview of all processes in which your personal data are processed. You can find a more detailed description here.

For the provision of contractual services/ registration

We process inventory data and contract data in order to be able to fulfil our contractual obligations and services. (Article 6 lit. 1 b GDPR)

Making contact

If you contact us by e-mail, the information will be processed to the extent necessary to answer your questions. The contact via our live chat is made via the services of Intercom. You can find further information on this under the point "In depth: Cookies and other technologies".

Visiting our website

If you use our website, services or messaging features, we or our authorized service providers may use cookies or similar technologies. The information collected in this way helps us to better adapt our services to the needs of our customers, to make them better and faster and, above all, even more secure. They also serve advertising purposes.

General note

Based on Article 13 of the Swiss Federal Constitution and the data protection regulations of the Swiss Confederation (Data Protection Act, DSG), every person is entitled to protection of his or her privacy and protection against misuse of his or her personal data. The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and according to the legal data protection regulations as well as this privacy policy.

We make every effort to protect the databases as well as possible against unauthorized access, loss, misuse or forgery.

We would like to point out that data transmission over the Internet (e.g. communication by e-mail) can have security gaps. A complete protection of data against access by third parties is not possible.

By using this website and services, you agree to the collection, processing and use of data in accordance with the following description. This website can be visited without registration. Data such as pages called up or the name of the file called up, date and time are stored on the server for statistical purposes without these data being directly related to your person. Personal data, in particular name, address or e-mail address are collected on a voluntary basis as far as possible. The data will not be passed on to third parties without your consent.

Processing of personal data

Personal data is all information that relates to an identified or identifiable person. A data subject is a person about whom personal data are processed. Processing includes any handling of personal data, irrespective of the means and procedures used, in particular the storage, disclosure, procurement, deletion, storage, modification, destruction and use of personal data.

We process personal data in accordance with Swiss data protection law. In addition, we process personal data - insofar and to the extent that the EU-DSGVO is applicable - in accordance with the following legal principles in connection with Art. 6 Para. 1 DSGVO:

lit. a) Processing of personal data with the consent of the person concerned.
lit. b) Processing of personal data for the purpose of fulfilling a contract with the data subject and for the implementation of appropriate pre-contractual measures.
lit. c) Processing of personal data for the fulfilment of a legal obligation to which we are subject under any applicable law of the EU or under any applicable law of a country in which the DPA is fully or partially applicable.
lit. d) Processing of personal data to protect vital interests of the data subject or of another natural person.
lit. f) Processing of personal data to protect the legitimate interests of us or of third parties, except where such interests are overridden by fundamental freedoms and rights or by the interests of the data subject. Legitimate interests are in particular our business interest in being able to provide our website, information security, the enforcement of our own legal claims and compliance with Swiss law.
We process personal data for as long as is necessary for the respective purpose or purposes. In the event of longer-term storage obligations due to legal and other obligations to which we are subject, we will limit the processing accordingly.

Privacy policy for SSL/TLS encryption

This website uses SSL/TLS encryption for reasons of security and to protect the transmission of confidential content, such as the requests you send to us as site operator. You can recognize an encrypted connection by the fact that the address line of your browser changes from "http://" to "https://" and by the lock symbol in your browser line.

If the SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Privacy policy for server log files

The provider of this website automatically collects and stores information in so-called server log files, which your browser automatically sends to us. These are:

- Browser type and version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request

These data cannot be assigned to specific persons. A consolidation of this data with other data sources is not carried out. We reserve the right to check these data subsequently if we become aware of concrete indications of illegal use.

Privacy policy for contact form

If you send us inquiries via the contact form, your details from the inquiry form, including the contact data you provide there, will be stored by us for the purpose of processing the inquiry and in the event of follow-up questions. We will not pass on this data without your consent.

Privacy policy for newsletter data

If you would like to receive the newsletter offered on this website, we need an e-mail address from you as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter. Further data will not be collected. We use these data exclusively for sending the requested information and do not pass them on to third parties.

You can revoke your consent to the storage of the data, the e-mail address as well as its use for sending the newsletter at any time, for example by using the "unsubscribe link" in the newsletter.

Chargeable services

In order to provide services that are subject to a charge, we ask for additional data, such as payment details, in order to be able to carry out your order. We store this data in our systems until the legal retention periods have expired.

Use of Google Maps

This website uses the offer of Google Maps. This allows us to display interactive maps directly on the website and enables you to use the map function conveniently. By visiting the website, Google receives the information that you have called up the corresponding subpage of our website. This happens regardless of whether Google provides a user account through which you are logged in or whether no user account exists. If you are logged in at Google, your data will be assigned directly to your account. If you do not want the assignment with your profile at Google, you have to log out before activating the button. Google stores your data as user profiles and uses them for the purposes of advertising, market research and/or demand-oriented design of its website. Such an evaluation is carried out in particular (even for users who are not logged in) to provide need-based advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, whereby you must contact Google to exercise this right. Further information on the purpose and scope of data collection and its processing by Google, along with further information on your rights in this regard and setting options to protect your privacy, can be found at: www.google.de/intl/de/policies/privacy

Google AdWords

This website uses Google Conversion Tracking. If you have reached our website via an advertisement placed by Google, Google Adwords will place a cookie on your computer. The cookie for conversion tracking is set when a user clicks on an ad placed by Google. These cookies expire after 30 days and are not used for personal identification. If the user visits certain pages on our site and the cookie has not expired, we and Google can recognize that the user clicked on the ad and was redirected to that page. Each Google AdWords customer receives a different cookie. As a result, cookies cannot be tracked through the websites of AdWords customers. The information collected through the conversion cookie is used to compile conversion statistics for advertisers who have opted in to conversion tracking. Customers are told the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, they do not receive information that personally identifies users.

If you do not wish to participate in tracking, you may refuse to accept cookies by selecting the appropriate settings on your browser, such as turning off automatic cookie submission or setting your browser to block cookies from the "googleleadservices.com" domain.

Please note that you may not delete the opt-out cookies unless you wish to record measurement data. If you have deleted all your cookies in your browser, you have to set the respective opt-out cookie again.

Use of Google Remarketing

This website uses the remarketing function of Google Inc. to present interest-related advertisements to website visitors within the Google advertising network. A so-called "cookie" is stored in the website visitor's browser, which makes it possible to recognize the visitor when he or she visits websites that belong to the Google advertising network. On these pages, the visitor may be presented with advertisements relating to content that the visitor has previously viewed on websites that use Google's remarketing function.

According to its own statements, Google does not collect any personal data during this process. If you still do not wish to use Google's remarketing function, you can deactivate it by making the appropriate settings at http://www.google.com/settings/ads. Alternatively, you can deactivate the use of cookies for interest-based advertising via the advertising network initiative by following the instructions at http://www.networkadvertising.org/managing/opt_out.asp.

Use of Google reCAPTCHA

This website uses the service reCAPTCHA of Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google"). The purpose of the query is to distinguish whether the input is made by a human being or by automated, machine processing. The query includes the sending of the IP address and any other data required by Google for the reCAPTCHA service to Google. For this purpose, your input will be transmitted to Google and used there. Your IP address will, however, be shortened by Google within member states of the European Union or in other signatory states of the Agreement on the European Economic Area before being used. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of this service. The IP address transmitted by your browser in the context of reCaptcha is not combined with other data from Google. Your data may also be transferred to the USA. For data transmissions to the USA, an adequacy decision of the European Commission, the "Privacy Shield", is in place. Google participates in the "Privacy Shield" and has submitted to the requirements. By clicking on the query, you consent to the processing of your data. The processing is carried out on the basis of Art. 6 (1) lit. a DSGVO with your consent. You may revoke your consent at any time without affecting the legality of the processing carried out on the basis of the consent until revocation.

Further information on Google reCAPTCHA and the corresponding data protection declaration can be found at: https://policies.google.com/privacy?hl=de

Privacy policy for Google Analytics

This website uses Google Analytics, a web analysis service of Google Ireland Limited. If the person responsible for data processing on this website is located outside the European Economic Area or Switzerland, Google Analytics data processing is carried out by Google LLC. Google LLC and Google Ireland Limited are hereinafter referred to as "Google".

We can use the statistics obtained to improve our offer and make it more interesting for you as a user. This website also uses Google Analytics for a cross-device analysis of visitor flows, which is performed using a user ID. If you have a Google user account, you can deactivate the cross-device analysis of your usage in the settings there under "My data", "Personal data".

The legal basis for the use of Google Analytics is Art. 6 para. 1 p. 1 lit. f DS-GVO. The IP address transmitted by your browser in the context of Google Analytics is not merged with other data from Google. We would like to point out that on this website Google Analytics has been extended by the code "_anonymizeIp();" in order to ensure anonymous collection of IP addresses. This means that IP addresses are further processed in a shortened form, thus excluding the possibility of personal references. If the data collected about you contains a personal reference, this is immediately excluded and the personal data is immediately deleted.

Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on the website activities and to provide further services to the website operator in connection with the use of the website and the Internet. For the exceptional cases in which personal data is transferred to the USA, Google has subjected itself to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.

Google Analytics uses cookies. The information generated by the cookie about your use of this website is usually transferred to a Google server in the USA and stored there. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link: deactivate Google Analytics.

You can also prevent the use of Google Analytics by clicking on this link: Deactivate Google Analytics. This will cause a so-called opt-out cookie to be stored on your data carrier, which prevents the processing of personal data by Google Analytics. Please note that if you delete all cookies on your end device, these opt-out cookies will also be deleted, which means that you will have to set the opt-out cookies again if you want to continue to prevent this form of data collection. The opt-out cookies are set per browser and computer/device and must therefore be activated separately for each browser, computer or other device.

Privacy policy for Google Ads

This website uses the online marketing tool Google Ads from Google ("Google Ads"). Google Ads uses cookies to serve ads relevant to users, to improve campaign performance reports, or to prevent a user from seeing the same ads more than once. Google uses a cookie ID to help identify which ads are shown in which browser and to prevent them from being shown more than once. Google may also use cookie IDs to track conversions related to ad requests. This is the case, for example, when a user sees a Google Ads ad and later visits the advertiser's website using the same browser and makes a purchase. According to Google, Google Ads cookies contain no personal information.

Due to the marketing tools used, your browser automatically establishes a direct connection with the Google server. Through the integration of Google Ads, Google receives the information that you have called up the corresponding part of our website or clicked on an advertisement from us. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or have not logged in, it is possible that Google will find out and save your IP address.

You can prevent this tracking procedure in various ways:

by setting your browser software accordingly, in particular the suppression of third-party cookies means that you will not receive any ads from third-party providers;

by disabling cookies for conversion tracking by setting your browser to block cookies from the domain "www.googleadservices.com", https://adssettings.google.com, although this setting will be cleared when you delete your cookies;

by disabling interest-based ads from providers that are part of the About Ads self-regulatory campaign through the https://www.aboutads.info/choices link, this setting will be cleared when you clear your cookies;

by permanently deactivating them in your Firefox, Internet Explorer or Google Chrome browsers via the link https://www.google.com/settings/ads/plugin. We would like to point out that in this case you may not be able to use all functions of this offer to their full extent.

The legal basis for the processing of your data is a weighing of interests, according to which the processing of your personal data described above is not opposed by any predominant contrary interests on your part (Art. 6 para. 1 sentence 1 lit. f DSGVO). Further information on Google Ads by Google can be found at https://ads.google.com/intl/de_DE/home/, as well as on data protection at Google in general: https://www.google.de/intl/de/policies/privacy. Alternatively, you can visit the website of the Network Advertising Initiative (NAI) at https://www.networkadvertising.org.

Privacy policy for the use of Google Web Fonts

This website uses so-called web fonts, which are provided by Google, for the uniform display of fonts. When you call up a page, your browser loads the required web fonts into its browser cache to display texts and fonts correctly. If your browser does not support Web Fonts, a standard font from your computer will be used.

For more information about Google Web Fonts, visit https://developers.google.com/fonts/faq and Google's privacy policy: https://www.google.com/policies/privacy/

Google Tag Manager

Google Tag Manager is a solution with which we can manage so-called website tags via an interface and thus integrate e.g. Google Analytics and other Google marketing services into our online offering. The Tag Manager itself, which implements the tags, does not process any personal data of the users. With regard to the processing of users' personal data, we refer to the following information on Google services. Usage guidelines: https://www.google.com/intl/de/tagmanager/use-policy.html.

External payment service providers

This website uses external payment service providers, through whose platforms the users and we can make payment transactions. For example via

PostFinance (https://www.postfinance.ch/de/detail/rechtliches-barrierefreiheit.html)

Visa (https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html)

Mastercard (https://www.mastercard.ch/de-ch/datenschutz.html)

American Express (https://www.americanexpress.com/de/content/privacy-policy-statement.html)

Paypal (https://www.paypal.com/de/webapps/mpp/ua/privacy-full)

Bexio AG (https://www.bexio.com/de-CH/datenschutz)

Payrexx AG (https://www.payrexx.ch/site/assets/files/2592/datenschutzerklaerung.pdf)

Apple Pay (https://support.apple.com/de-ch/ht203027)

Stripe (https://stripe.com/ch/privacy)

Klarna (https://www.klarna.com/de/datenschutz/)

Skrill (https://www.skrill.com/de/fusszeile/datenschutzrichtlinie/)

Giropay (https://www.giropay.de/rechtliches/datenschutz-agb/) etc.

Within the framework of the fulfilment of contracts, we appoint payment service providers on the basis of the Swiss Data Protection Ordinance and, where necessary, Art. 6 para. 1 lit. b. EU-DSGVO. Furthermore, we use external payment service providers on the basis of our legitimate interests in accordance with the Swiss Data Protection Ordinance and, where necessary, Art. 6 para. 1 lit. f. EU-DSGVO in order to offer our users effective and secure payment options.

The data processed by the payment service providers include inventory data, such as name and address, bank data, such as account or credit card numbers, passwords, TANs and checksums as well as contract, sum and recipient related data. The information is required to complete the transactions. However, the data entered is only processed by the payment service providers and stored by them. We as the operator do not receive any information about (bank) account or credit card, but only information to confirm (accept) or reject the payment. Under certain circumstances, the payment service providers may transfer the data to credit agencies. The purpose of this transmission is to check identity and creditworthiness. In this regard, we refer to the general terms and conditions and data protection notices of the payment service providers.

For payment transactions, the terms and conditions and the data protection information of the respective payment service providers apply, which can be accessed within the respective website or transaction applications. We also refer to them for further information and the assertion of rights of revocation, information and other rights of affected persons.

Privacy policy for YouTube

On this website, functions of the "YouTube" service are integrated. "YouTube" is owned by Google Ireland Limited, a company incorporated and operated under the laws of Ireland, with its registered office at Gordon House, Barrow Street, Dublin 4, Ireland, which operates the Services in the European Economic Area and Switzerland.

Your legal agreement with "YouTube" consists of the terms and conditions set out at the following link: https://www.youtube.com/static?gl=de&template=terms&hl=de. These Terms constitute a legally binding agreement between you and "YouTube" with respect to your use of the Services. Google's Privacy Policy explains how "YouTube" treats your personal information and protects your privacy when you use the service.

Order processing in the online store with customer account

We process the data of our customers in accordance with the data protection regulations of the Federal Republic of Germany (Data Protection Act, DSG) and the EU-DSGVO, within the framework of the ordering processes in our online store, in order to enable them to select and order the selected products and services, as well as to enable payment and delivery or execution.

To the processed data belong master data (inventory data), communication data, contract data, payment data and to the persons affected by the processing belong our customers, prospective customers and other business partners. The processing is carried out for the purpose of providing contractual services within the operation of an online store, billing, delivery and customer services. For this purpose we use session cookies, e.g. for storing the contents of the shopping cart, and permanent cookies, e.g. for storing the login status.

The processing is based on art. 6 para. 1 lit. b (execution of order processes) and c (legally required archiving) DSGVO. The information marked as required is required for the justification and fulfilment of the contract. We disclose the data to third parties only within the scope of delivery, payment or within the scope of the legal permissions and obligations. The data will only be processed in third countries if this is necessary for the fulfilment of the contract (e.g. on customer request for delivery or payment).

Users have the option of creating a user account, in which they can view their orders in particular. During the registration process, the required mandatory data will be provided to the users. The user accounts are not public and cannot be indexed by search engines, e.g. Google. If users have terminated their user account, their data will be deleted with regard to the user account, subject to their safekeeping is necessary for reasons of commercial or tax law in accordance with Art. 6 para. 1 lit. c DSGVO. Data in the customer account will remain until their deletion with subsequent archiving in case of a legal obligation. It is the responsibility of the users to save their data in case of termination before the end of the contract.

Within the scope of registration and renewed logins and use of our online services, we store the IP address and the time of the respective user action. The storage is based on our legitimate interests, as well as the user's need for protection against misuse and other unauthorized use. This data will not be passed on to third parties unless it is necessary to pursue our claims or there is a legal obligation to do so in accordance with Art. 6 Para. 1 lit. c DSGVO.

Deletion is carried out after the expiration of legal warranty and comparable obligations, the necessity of data storage is checked at irregular intervals. In the case of legal archiving obligations, deletion takes place after the expiry of these obligations.

General disclaimer of liability

All information on our website has been carefully checked. We make every effort to ensure that the information we offer is up-to-date, correct and complete. Nevertheless, the occurrence of errors cannot be completely ruled out, which means that we cannot guarantee the completeness, correctness and topicality of information, including journalistic and editorial information. Liability claims arising from material or non-material damage caused by the use of the information provided are excluded, unless there is evidence of wilful intent or gross negligence.

The publisher can change or delete texts at his own discretion and without notice and is not obliged to update the contents of this website. The use or access to this website is at the visitor's own risk. The publisher, his clients or partners are not responsible for damages, such as direct, indirect, accidental, in advance concretely to be determined or consequential damages, which are allegedly caused by the visit of this website and therefore assume no liability.

The publisher also accepts no responsibility or liability for the content and availability of third-party websites that can be accessed via external links on this website. The content of linked sites is the sole responsibility of their operators. The publisher thus expressly distances itself from all third-party content that may be relevant under criminal or liability law or that is contrary to public decency.

Changes

We may change this privacy policy at any time without notice. The current version published on our website applies. If the data protection declaration is part of an agreement with you, we will inform you of the change by e-mail or other suitable means in the event of an update.

Questions to the data protection officer

If you have any questions regarding data protection, please send us an e-mail or contact the person responsible for data protection in our organization listed at the beginning of this privacy statement.

Rotkreuz, 30.10.2020