Privacy Policy of PEMA Innotech Swiss AG

Effective: July 2026

1. Data Controller

The entity responsible for the processing of personal data as defined in this Privacy Policy is: PEMA Innotech Swiss AG, Burghalde 7c, 5722 Gränichen, Switzerland. Email: info@pema-innotech.ch. Authorized representative: Peter Sturzenegger, CEO.

2. Scope and International Applicability

PEMA Innotech Swiss AG is a Swiss company with international operations. This Privacy Policy applies to the use of our website, contact with us, and related communications and business inquiries. This policy is based on the Swiss Data Protection Act. In addition, we comply with other data protection regulations to the extent they apply due to our international operations, in particular the GDPR for individuals in the EU/EEA, the Nigeria Data Protection Act for Nigeria, U.S. data protection regulations – including those of California – and the Chinese Personal Information Protection Law, to the extent their respective scopes of application apply.

3. Principles of Data Processing

We process personal data lawfully, proportionately, for specific purposes, transparently, and only to the extent necessary for the respective purpose. We ensure appropriate data security, restrict access to authorized individuals, and store personal data only for as long as necessary for the stated purposes, legal obligations, or legitimate business interests.

4. What Data We Process

In connection with our website, communications, and our business activities, the following categories of personal data, in particular, may be processed:

Data CategoryExamples
Technical
Usage Data
IP address, date and time of access, pages visited, browser type, operating system, referrer URL, and technical connection data.
Contact and communication
data
Name, company, email address, phone number, country, content of your message, and other voluntary information.
Cookie and
website data
Technically necessary cookies and similar information, to the extent they are required for the operation of the website.
Business-Related Information Information from inquiries regarding products, sales, partnerships, deliveries, or regulatory matters.

5. Purposes of Processing

We process personal data in particular for the following purposes:

Purpose Description
Website
Operation
Provision, security, maintenance, and technical optimization of our website.
Communication Processing of contact requests, inquiries, and business communications.
Products and
Sales
eview and processing of inquiries regarding products, sales, partnerships, and international markets.
Obligations
and
Documentation
Fulfillment of legal, regulatory, and contractual obligations, to the extent they apply in individual cases.
Legitimate
Interests
Protection of legitimate interests, in particular security, traceability of communication, and protection against misuse.

6. Legal Bases

Depending on the applicable data protection law, we base the processing of personal data in particular on the following grounds:

Legal Framework / BasisSignificance for Data Processing
Swiss Data Protection
Law
We process personal data in accordance with the principles of the Data Protection Act, in particular lawfully, in good faith, proportionately, for specific purposes, and transparently.
Contract or
Pre-
Contractual
Inquiry
To the extent that the GDPR applies, we base such processing on Article 6(1)(b) of the GDPR, particularly in connection with inquiries, offers, orders, or contractual relationships.
Legitimate
Interests
To the extent that the GDPR applies, we base processing on Article 6(1)(f) of the GDPR, in particular for the secure operation of the website, communication, prevention of misuse, and traceability of business transactions.
Legal
Obligations
To the extent that a legal, regulatory, or documentation-related obligation exists, we base the processing—where the GDPR applies—on Article 6(1)(c) of the GDPR.
ConsentIn exceptional cases where we obtain consent, processing is based on Article 6(1)(a) of the GDPR. Consent that has been given may be revoked with future effect.

7. Hosting, Server Log Files, and Technical Security

For the technical operation of our website, hosting and server data are processed as follows:

Category Description
Hosting
Provider
Our website is hosted by cyon GmbH, Brunngässlein 12, 4052 Basel, Switzerland.
Server Log Files When you visit the website, technical data is processed, including, in particular, your IP address, the date and time of access, pages visited, browser type, operating system, referrer URL, and technical connection data.
Purpose This processing is necessary to provide the website, ensure stability, perform error analysis, maintain technical security, and prevent misuse.
Retention
Period
Log files are generally stored only for as long as necessary for operation, security, error analysis, and prevention of misuse.

8. Contact Form and Email Communication

When you contact us via the contact form or email, we process the information you provide as follows:

Category Description
Information
Collected
Name, company name, email address, phone number, country, subject line, message content, and any other information provided voluntarily.
PurposeProcessing your inquiry, responding to follow-up questions, and conducting business communication.
DisclosureNo disclosure to third parties without a legal basis, legitimate interest, contractual necessity, or your consent.
RetentionStorage for as long as necessary for processing, follow-up communication, documentation of business transactions, or to comply with legal retention requirements.

9. Business, Product, and Sales Data

As a manufacturer and distributor of products, we process business, product, and sales data, specifically as follows:

Category Description
Business
Contacts
Customers, prospective customers, retailers, distributors, suppliers, logistics service providers, laboratories, consultants, government agencies, and other business partners.
Data TypesName, company, job title, business contact information, address, country, contract and order data, shipping and billing information, correspondence, technical inquiries, and product- and market-related information.
Business
Purposes
Quotes, orders, shipments, invoices, payments, export, import, and customs processing, support for sales and project partners, and technical consulting.
Product and Compliance Purposes Product information, safety data sheets, regulatory documents, quality management, product monitoring, complaints, safety reports, traceability, and recall measures.
Recipients
and
Retention
Period Disclosure to participating dealers, distributors, freight forwarders, payment service providers, insurance companies, laboratories, consultants, or government agencies, as necessary. Retention period based on purpose, contractual relationship, statutory retention obligations, product-related documentation requirements, and legitimate interests in quality assurance, traceability, and legal defense.

10. Cookies and Analytics/Marketing Tools

As of now, the following applies to cookies and similar technologies:

Category Description
Technically
Necessary
Cookies
As of now, our website uses only technically necessary cookies to the extent that they are required for the website to function.
Analytics
and
Marketing
We use analytics or marketing cookies, tracking pixels, or similar technologies only if this is explicitly described and, where necessary, consent has been obtained.
ManagementYou can also manage or delete cookies through your browser settings.

11. Recipients and Service Providers

Personal data may be disclosed to the following recipients or categories of recipients:

Category Description
Technical
Service
Providers
Service providers for websites, hosting, email communication, IT systems, maintenance, and technical support.
Business
and
Sales
Partners
Retailers, distributors, suppliers, logistics service providers, payment service providers, laboratories, testing facilities, consultants, insurance companies, and other involved parties.
Government
Agencies and
Courts
Disclosure to government agencies, courts, or other authorities when required by law or necessary to protect our rights.
Protective
Measures
Service providers and partners receive personal data only to the extent necessary and subject to appropriate contractual, organizational, and technical safeguards.

12. International Data Transfers

We handle international data transfers in accordance with the following principles:

CategoryDescription
PrinciplePrinciple We do not actively transfer personal data to countries outside Switzerland, the EU, or the EEA, unless this is necessary for the operation of the website and the processing of your inquiry.
International
Communication
Due to international communication, email correspondence, IT services, or business inquiries from other countries, data transfers to other countries cannot be completely ruled out for technical or organizational reasons.
Protective
Measures
To the extent that such a transfer takes place, we ensure appropriate safeguards, recognized adequacy decisions, contractual protective measures, or other legally prescribed bases.

13. Retention Period

We store personal data only for as long as is necessary for the respective purpose. The retention period is determined in particular by the following criteria:

Data CategoryRetention Period / Criteria
Technical
Log Data
Generally stored only for a short period, to the extent necessary for operations, security, error analysis, and prevention of misuse.
Contact and
Communication
Data
Retained for as long as necessary to process the inquiry, facilitate subsequent communication, document business transactions, or comply with legal retention requirements.
Business, Product, and
Sales Data
May be retained for a longer period to the extent necessary for contract fulfillment, accounting, export and import documentation, quality assurance, product monitoring, traceability, complaints, recalls, regulatory compliance, or legal defense.
Deletion or
Anonymization
Once the purpose no longer applies or statutory retention periods have expired, personal data will be deleted or anonymized, provided that no further retention is required.

14. Rights of Data Subjects

In accordance with the applicable data protection law, you have, in particular, the right to access your data, to have inaccurate data corrected, to have your data erased, to restrict processing, to object to certain processing activities, to receive a copy of your data or to request data portability, and to withdraw your consent with future effect. To the extent that the GDPR applies, you also have the right to lodge a complaint with a competent data protection supervisory authority. In Switzerland, data subjects may contact the Federal Data Protection and Information Commissioner.

15. Automated Decision-Making and Profiling

We do not make any automated individual decisions that produce legal effects for you or significantly affect you in a comparable manner. Likewise, we do not create user profiles via our website for advertising or analytical purposes.

16. Country-Specific Information

Country / RegionCountry-Specific Information
SwitzerlandAs a Swiss company, we primarily base our data processing on the Swiss Data Protection Act. In particular, we provide information about the data controller, the purposes of processing, the categories of data, recipients or categories of recipients, and any transfers of data abroad.
EU / EEATo the extent that the GDPR applies, we also provide information regarding the respective legal basis, legitimate interests, recipients, retention period, rights of data subjects, avenues for filing complaints, and any transfers to third countries. Should our activities require us by law to appoint an EU representative or a data protection officer, we will supplement the relevant information accordingly.
Nigeria To the extent that the Nigeria Data Protection Act applies to a specific processing activity, we respect the principles and rights set forth therein, in particular the rights to information, access, rectification, erasure, objection, restriction, data portability, withdrawal of consent, and protection against automated decision-making. In the event of expanded business activities in Nigeria, we will review additional local requirements, such as registration, representative, or compliance obligations.
United States /
California
Our website is not specifically targeted at consumers in the United States. We do not sell personal data in the sense of a commercial data sale, nor do we share personal data for behavioral advertising. To the extent that U.S. data protection laws, in particular California regulations such as the CCPA/CPRA, are applicable in individual cases, we handle corresponding requests in accordance with legal requirements, particularly regarding access, deletion, correction, opt-out, restriction of sensitive data, and non-discrimination.
China To the extent that the Chinese Personal Information Protection Law applies to the processing of personal data of individuals in China, we comply with the relevant requirements, in particular regarding transparent information, purpose limitation, appropriate data security, the rights of data subjects, and specific requirements for cross-border transfers of personal data.

17. Data Security

We implement appropriate technical and organizational measures to protect personal data from loss, misuse, unauthorized access, alteration, or disclosure. These include, in particular, access restrictions, technical safeguards, and organizational controls. Please note that data transmission over the Internet, particularly via email, may involve security vulnerabilities.

18. Data Breaches

In the event of data breaches, we assess the legal reporting obligations and notify the relevant authorities or affected individuals to the extent required by applicable law. In Switzerland, a report is filed with the EDÖB if a data breach is likely to result in a high risk to the privacy or fundamental rights of the affected individuals. To the extent that the GDPR applies, the reporting obligations set forth therein apply.

19. Changes to This Privacy Policy

We may update this Privacy Policy as needed, particularly if we modify our website, introduce new services, expand our international operations, or if legal requirements change. The most recent version published on our website is the one that applies.

20. Contact for Data Protection Inquiries

If you have any questions regarding data protection or wish to exercise your rights, you may contact PEMA Innotech Swiss AG at any time: info@pema-innotech.ch.