Privacy Policy of PEMA Innotech Swiss AG
Effective: July 2026
1. Data Controller
The entity responsible for the processing of personal data as defined in this Privacy Policy is: PEMA Innotech Swiss AG, Burghalde 7c, 5722 Gränichen, Switzerland. Email: info@pema-innotech.ch. Authorized representative: Peter Sturzenegger, CEO.
2. Scope and International Applicability
PEMA Innotech Swiss AG is a Swiss company with international operations. This Privacy Policy applies to the use of our website, contact with us, and related communications and business inquiries. This policy is based on the Swiss Data Protection Act. In addition, we comply with other data protection regulations to the extent they apply due to our international operations, in particular the GDPR for individuals in the EU/EEA, the Nigeria Data Protection Act for Nigeria, U.S. data protection regulations – including those of California – and the Chinese Personal Information Protection Law, to the extent their respective scopes of application apply.
3. Principles of Data Processing
We process personal data lawfully, proportionately, for specific purposes, transparently, and only to the extent necessary for the respective purpose. We ensure appropriate data security, restrict access to authorized individuals, and store personal data only for as long as necessary for the stated purposes, legal obligations, or legitimate business interests.
4. What Data We Process
In connection with our website, communications, and our business activities, the following categories of personal data, in particular, may be processed:
| Data Category | Examples |
|---|---|
| Technical Usage Data | IP address, date and time of access, pages visited, browser type, operating system, referrer URL, and technical connection data. |
| Contact and communication data | Name, company, email address, phone number, country, content of your message, and other voluntary information. |
| Cookie and website data | Technically necessary cookies and similar information, to the extent they are required for the operation of the website. |
| Business-Related Information | Information from inquiries regarding products, sales, partnerships, deliveries, or regulatory matters. |
5. Purposes of Processing
We process personal data in particular for the following purposes:
| Purpose | Description |
|---|---|
| Website Operation | Provision, security, maintenance, and technical optimization of our website. |
| Communication | Processing of contact requests, inquiries, and business communications. |
| Products and Sales | eview and processing of inquiries regarding products, sales, partnerships, and international markets. |
| Obligations and Documentation | Fulfillment of legal, regulatory, and contractual obligations, to the extent they apply in individual cases. |
| Legitimate Interests | Protection of legitimate interests, in particular security, traceability of communication, and protection against misuse. |
6. Legal Bases
Depending on the applicable data protection law, we base the processing of personal data in particular on the following grounds:
| Legal Framework / Basis | Significance for Data Processing |
|---|---|
| Swiss Data Protection Law | We process personal data in accordance with the principles of the Data Protection Act, in particular lawfully, in good faith, proportionately, for specific purposes, and transparently. |
| Contract or Pre- Contractual Inquiry | To the extent that the GDPR applies, we base such processing on Article 6(1)(b) of the GDPR, particularly in connection with inquiries, offers, orders, or contractual relationships. |
| Legitimate Interests | To the extent that the GDPR applies, we base processing on Article 6(1)(f) of the GDPR, in particular for the secure operation of the website, communication, prevention of misuse, and traceability of business transactions. |
| Legal Obligations | To the extent that a legal, regulatory, or documentation-related obligation exists, we base the processing—where the GDPR applies—on Article 6(1)(c) of the GDPR. |
| Consent | In exceptional cases where we obtain consent, processing is based on Article 6(1)(a) of the GDPR. Consent that has been given may be revoked with future effect. |
7. Hosting, Server Log Files, and Technical Security
For the technical operation of our website, hosting and server data are processed as follows:
| Category | Description |
|---|---|
| Hosting Provider | Our website is hosted by cyon GmbH, Brunngässlein 12, 4052 Basel, Switzerland. |
| Server Log Files | When you visit the website, technical data is processed, including, in particular, your IP address, the date and time of access, pages visited, browser type, operating system, referrer URL, and technical connection data. |
| Purpose | This processing is necessary to provide the website, ensure stability, perform error analysis, maintain technical security, and prevent misuse. |
| Retention Period | Log files are generally stored only for as long as necessary for operation, security, error analysis, and prevention of misuse. |
8. Contact Form and Email Communication
When you contact us via the contact form or email, we process the information you provide as follows:
| Category | Description |
|---|---|
| Information Collected | Name, company name, email address, phone number, country, subject line, message content, and any other information provided voluntarily. |
| Purpose | Processing your inquiry, responding to follow-up questions, and conducting business communication. |
| Disclosure | No disclosure to third parties without a legal basis, legitimate interest, contractual necessity, or your consent. |
| Retention | Storage for as long as necessary for processing, follow-up communication, documentation of business transactions, or to comply with legal retention requirements. |
9. Business, Product, and Sales Data
As a manufacturer and distributor of products, we process business, product, and sales data, specifically as follows:
| Category | Description |
|---|---|
| Business Contacts | Customers, prospective customers, retailers, distributors, suppliers, logistics service providers, laboratories, consultants, government agencies, and other business partners. |
| Data Types | Name, company, job title, business contact information, address, country, contract and order data, shipping and billing information, correspondence, technical inquiries, and product- and market-related information. |
| Business Purposes | Quotes, orders, shipments, invoices, payments, export, import, and customs processing, support for sales and project partners, and technical consulting. Product and Compliance Purposes Product information, safety data sheets, regulatory documents, quality management, product monitoring, complaints, safety reports, traceability, and recall measures. |
| Recipients and Retention | Period Disclosure to participating dealers, distributors, freight forwarders, payment service providers, insurance companies, laboratories, consultants, or government agencies, as necessary. Retention period based on purpose, contractual relationship, statutory retention obligations, product-related documentation requirements, and legitimate interests in quality assurance, traceability, and legal defense. |
10. Cookies and Analytics/Marketing Tools
As of now, the following applies to cookies and similar technologies:
| Category | Description |
|---|---|
| Technically Necessary Cookies | As of now, our website uses only technically necessary cookies to the extent that they are required for the website to function. |
| Analytics and Marketing | We use analytics or marketing cookies, tracking pixels, or similar technologies only if this is explicitly described and, where necessary, consent has been obtained. |
| Management | You can also manage or delete cookies through your browser settings. |
11. Recipients and Service Providers
Personal data may be disclosed to the following recipients or categories of recipients:
| Category | Description |
|---|---|
| Technical Service Providers | Service providers for websites, hosting, email communication, IT systems, maintenance, and technical support. |
| Business and Sales Partners | Retailers, distributors, suppliers, logistics service providers, payment service providers, laboratories, testing facilities, consultants, insurance companies, and other involved parties. |
| Government Agencies and Courts | Disclosure to government agencies, courts, or other authorities when required by law or necessary to protect our rights. |
| Protective Measures | Service providers and partners receive personal data only to the extent necessary and subject to appropriate contractual, organizational, and technical safeguards. |
12. International Data Transfers
We handle international data transfers in accordance with the following principles:
| Category | Description |
|---|---|
| Principle | Principle We do not actively transfer personal data to countries outside Switzerland, the EU, or the EEA, unless this is necessary for the operation of the website and the processing of your inquiry. |
| International Communication | Due to international communication, email correspondence, IT services, or business inquiries from other countries, data transfers to other countries cannot be completely ruled out for technical or organizational reasons. |
| Protective Measures | To the extent that such a transfer takes place, we ensure appropriate safeguards, recognized adequacy decisions, contractual protective measures, or other legally prescribed bases. |
13. Retention Period
We store personal data only for as long as is necessary for the respective purpose. The retention period is determined in particular by the following criteria:
| Data Category | Retention Period / Criteria |
|---|---|
| Technical Log Data | Generally stored only for a short period, to the extent necessary for operations, security, error analysis, and prevention of misuse. |
| Contact and Communication Data | Retained for as long as necessary to process the inquiry, facilitate subsequent communication, document business transactions, or comply with legal retention requirements. |
| Business, Product, and Sales Data | May be retained for a longer period to the extent necessary for contract fulfillment, accounting, export and import documentation, quality assurance, product monitoring, traceability, complaints, recalls, regulatory compliance, or legal defense. |
| Deletion or Anonymization | Once the purpose no longer applies or statutory retention periods have expired, personal data will be deleted or anonymized, provided that no further retention is required. |
14. Rights of Data Subjects
In accordance with the applicable data protection law, you have, in particular, the right to access your data, to have inaccurate data corrected, to have your data erased, to restrict processing, to object to certain processing activities, to receive a copy of your data or to request data portability, and to withdraw your consent with future effect. To the extent that the GDPR applies, you also have the right to lodge a complaint with a competent data protection supervisory authority. In Switzerland, data subjects may contact the Federal Data Protection and Information Commissioner.
15. Automated Decision-Making and Profiling
We do not make any automated individual decisions that produce legal effects for you or significantly affect you in a comparable manner. Likewise, we do not create user profiles via our website for advertising or analytical purposes.
16. Country-Specific Information
| Country / Region | Country-Specific Information |
|---|---|
| Switzerland | As a Swiss company, we primarily base our data processing on the Swiss Data Protection Act. In particular, we provide information about the data controller, the purposes of processing, the categories of data, recipients or categories of recipients, and any transfers of data abroad. |
| EU / EEA | To the extent that the GDPR applies, we also provide information regarding the respective legal basis, legitimate interests, recipients, retention period, rights of data subjects, avenues for filing complaints, and any transfers to third countries. Should our activities require us by law to appoint an EU representative or a data protection officer, we will supplement the relevant information accordingly. |
| Nigeria | To the extent that the Nigeria Data Protection Act applies to a specific processing activity, we respect the principles and rights set forth therein, in particular the rights to information, access, rectification, erasure, objection, restriction, data portability, withdrawal of consent, and protection against automated decision-making. In the event of expanded business activities in Nigeria, we will review additional local requirements, such as registration, representative, or compliance obligations. |
| United States / California | Our website is not specifically targeted at consumers in the United States. We do not sell personal data in the sense of a commercial data sale, nor do we share personal data for behavioral advertising. To the extent that U.S. data protection laws, in particular California regulations such as the CCPA/CPRA, are applicable in individual cases, we handle corresponding requests in accordance with legal requirements, particularly regarding access, deletion, correction, opt-out, restriction of sensitive data, and non-discrimination. |
| China | To the extent that the Chinese Personal Information Protection Law applies to the processing of personal data of individuals in China, we comply with the relevant requirements, in particular regarding transparent information, purpose limitation, appropriate data security, the rights of data subjects, and specific requirements for cross-border transfers of personal data. |
17. Data Security
We implement appropriate technical and organizational measures to protect personal data from loss, misuse, unauthorized access, alteration, or disclosure. These include, in particular, access restrictions, technical safeguards, and organizational controls. Please note that data transmission over the Internet, particularly via email, may involve security vulnerabilities.
18. Data Breaches
In the event of data breaches, we assess the legal reporting obligations and notify the relevant authorities or affected individuals to the extent required by applicable law. In Switzerland, a report is filed with the EDÖB if a data breach is likely to result in a high risk to the privacy or fundamental rights of the affected individuals. To the extent that the GDPR applies, the reporting obligations set forth therein apply.
19. Changes to This Privacy Policy
We may update this Privacy Policy as needed, particularly if we modify our website, introduce new services, expand our international operations, or if legal requirements change. The most recent version published on our website is the one that applies.
20. Contact for Data Protection Inquiries
If you have any questions regarding data protection or wish to exercise your rights, you may contact PEMA Innotech Swiss AG at any time: info@pema-innotech.ch.
