DATA PROTECTION TOWARDS CUSTOMERS

INTRODUCTION

With this data protection declaration we inform you about how we process your personal data (“personal data”). Personal data is all information that relates to you as a person or with which you can be personally identified.

General
personal data

allg icon

Financial data

finanzdaten icon

Location data

standortdaten icon

Data provided

ueberlassene icon

Data collected

erhobene icon

Data received

erhaltene icon

Marketing

marketing icon

Product development

produktentwicklung icon

Other purposes

zwecke icon

Profiling

profiling icon

Data sharing

datenweitergabe icon

Worldwide

weltweit icon

1. WHAT IS THIS DATA PROTECTION DECLARATION USED FOR AND WHAT DO WE PROVIDE INFORMATION ABOUT?

Data protection is an important concern for us. We therefore only process your data with great care and in accordance with the applicable legal requirements. Transparent information is part of effective data protection. With this data protection declaration we inform you about how and why we process your personal data. In particular you will find out:

  • what data we process and for what purpose;
  • who has access to your data and with whom we share your data;
  • how long we keep your data;
  • what rights you have and how you can exercise these rights;
  • which cookies and other tools we use on our websites.

2. WHEN IS THIS PRIVACY POLICY APPLICABLE?

This data protection declaration applies to all processes in which we process your personal data, unless we inform you about them separately. This data protection declaration applies in particular to the following processes:

  • You visit our websites;
  • You shop in our stores or online shops;
  • You use our online offerings, our platform, our portal or apps;
  • You subscribe to one of our newsletters;
  • You contact us;
  • You receive information or marketing communications from us;
  • You take part in our competitions or competitions;
  • You will receive market research, opinion or customer surveys from us.
  • You take part in our member get member program.

3. WHO IS RESPONSIBLE FOR PROCESSING PERSONAL DATA?

alletta sales platform ag is responsible for data processing in accordance with this data protection declaration

4. WHERE CAN YOU CONTACT US IF YOU HAVE QUESTIONS ABOUT DATA PROTECTION?

If you have any concerns or questions about data protection, you can contact alletta:

We walk you through every option so you can confidently take out the right policy for you.

[email protected]

for the EU territory. Below you will find the contact details of the EU representative:

VGS Data Protection Partner GmbH
At Kaiserkai 69
20457 Hamburg
Germany
[email protected]

5. WHAT RIGHTS DO YOU HAVE?

5.1 RIGHT OF PROVIDING INFORMATION

You can request information about the personal data we process about you at any time. We ask you to send us your request for information along with proof of identity.

We may restrict or refuse to provide information if this information conflicts with our legal obligations, legitimate own or public interests or the interests of a third party. The same applies if the request for information is abusive. If the effort is disproportionate, we can demand a share of the costs, which we will inform you about in advance.

The processing of your application is subject to the statutory processing period of 30 days. However, we may extend this deadline due to a high volume of inquiries, for legal or technical reasons or because we need further information from you. You will be informed about the extension of the deadline in a timely manner, at least in text form.

5.2 DELETION AND CORRECTION

You have the option to request the deletion or correction of your personal data at any time. We ask you to send us deletion notices along with proof of identity.

We can reject the request if legal regulations require us to retain the data for a longer period of time or without changes or if there is a permission requirement that conflicts with your request.

Please note that exercising your rights may conflict with contractual agreements and have corresponding effects on the performance of the contract (e.g. early termination of the contract or cost consequences).

5.3 LEGAL RECOURSE

If you are affected by the processing of personal data, you have the option of asserting your rights in court or submitting a report to the responsible supervisory authority. The responsible supervisory authority in Switzerland is the Federal Data Protection and Information Commissioner: http://www.edoeb.admin.ch.

6. WHICH TERMS DO WE USE IN THIS DATA PROTECTION DECLARATION?

We use certain terms in this privacy policy that have legal meaning. Below we explain the meaning of the most important terms.

6.1 PERSONAL DATA

Personal data includes all information that relates to a specific or identifiable natural person. This includes, for example, name, address, date of birth, email address or telephone number. Data about personal preferences such as leisure activities or memberships also count as personal data.

6.2 PERSONAL DATA THAT IS PARTICULARLY SENSITIVE TO PROTECTION

Personal data that is particularly worthy of protection is data about religious, ideological, political or trade union views or activities; Data on health and, if applicable, information on administrative or criminal prosecutions and sanctions as well as data on social assistance measures. If necessary and appropriate, we can request and process particularly sensitive personal data. In this case, their processing is subject to strict confidentiality.

6.3 EDITING PERSONAL DATA

Processing means any handling of personal data, regardless of the means and procedures used, in particular the acquisition, storage, retention, use, modification, disclosure, archiving, deletion or destruction of data.

6.4 DISCLOSURE OF PERSONAL DATA

Disclosure is the transmission or making available of personal data, for example publication or disclosure to a third party.

6.5 ANONYMIZATION

Anonymization refers to the process in which personal data is changed so that no conclusions can be drawn about the corresponding natural person. In contrast to pseudonymization, anonymization cannot be reversed.

6.6 PSEUDONYMIZATION

The pseudonymization of personal data describes the process of making personal data unrecognizable. For this purpose, personal identifying data (e.g. name, date of birth, place of residence) is replaced by a pseudonym (e.g. a code). Anyone who has the key information can use it to assign the data to a specific person (so-called depseudonymization or re-identification ).

7. WHAT PERSONAL DATA DO WE PROCESS AND WHERE DOES IT COME FROM?

We process your personal data that is necessary to fulfill the relevant purposes. You can find more detailed information about the personal data processed under the individual purposes (see Section 8).

Normally you provide us with your personal data, e.g. B. by sending it to us or when you communicate with us.

In certain cases we also collect data about you ourselves or automatically, e.g. B. when you use our platform, our portal or our app or surf our websites. This includes, in particular, behavioral and transaction data, online identifiers, online tracking and traffic data (see Section 8.3). In certain cases we can also derive the data from existing data, e.g. B. evaluate the transaction or behavioral data (see point 13).

We may also receive your personal data from third parties. It can be e.g. B. the following third parties:

  • People from your environment (e.g. address for mail, powers of attorney);
  • Banks or other contractual partners (e.g. for payouts);
  • credit reporting agencies (e.g. for obtaining credit reports);
  • Online service providers (e.g. analysis services) and address retailers (e.g. for address updates);
  • authorities (e.g. in connection with legal proceedings);
  • public sources (e.g. public registers, media, internet).
  • The personal data we receive from third parties may include the following categories:
  • Personal master data (name, address, dates of birth, etc.);
  • Contact details (mobile phone number, email address, etc.);
  • Financial data (e.g. account details);
  • Online identifiers (e.g. cookie identifiers, IP addresses);
  • location and traffic data;
  • sound and image recordings;
  • profile data or personal preference data (e.g. product or service preferences);
  • particularly sensitive data (e.g. biometric data or information about your health).

8. FOR WHAT PURPOSES DO WE PROCESS YOUR PERSONAL DATA?

We may process your personal data for several purposes. We primarily process these in order to be able to provide our services to you.

8.1 FULFILLMENT OF CONTRACT

In order for us to conclude and process contracts with you, we normally have to process your personal data. This is e.g. This is the case, for example, if you take out new insurance via our platform or trigger a cashback payout. When fulfilling the contract, the following categories of personal data in particular may be processed:

  • Personal master data (e.g. title, first name, last name, date of birth, gender, customer number, user name);
  • Contact information (e.g. home address, email address, telephone number, shipping address);
  • Financial data (e.g. payment details, credit reports);
  • Transaction data (e.g. insurance conclusion);
  • Customer history (e.g. interaction on the portal, information on how to handle defects or complaints).

For the purpose of fulfilling the contract, we can carry out all processing that is necessary for initiating the contract, concluding the contract, processing the contract or enforcing the contract. For example, we can obtain credit information about you before concluding a contract (with data on your solvency and payment history) in order to decide whether or in what form we will enter into a contract with you. For products for which there is an age requirement, we may require proof of your date of birth using a copy of your passport or ID or verify your age using your passport or ID number. check automatically. For example, in order to submit an insurance application, your data will be passed on to the insurance company, and in the case of additional insurance you will also pass on particularly sensitive data about your health. For payment processing, there is also an exchange with the relevant payment service provider. We may also process your data in connection with your inquiries about the product, to correct defects, to deal with complaints or to evaluate the product.

8.2 COMMUNICATION

In order for us to communicate with you and respond to your request, we need to process your personal data. This may be the case if you use a contact form from us, contact us by email, post, telephone, via digital channels (e.g. WhatsApp Business Platform and WhatsApp Flows) or in any other way when we contact you, or for customer care.

In particular, we process the following data for this purpose:

  • Name and contact details (e.g. name, address, email address, telephone number);
  • Content of the communication (e.g. letter, email, chat, WhatsApp message, comments on the website, telephone conversations);
  • Marginal data of the communication (e.g. information on the type, time or, if applicable, location of the communication).

We can carry out all processing operations necessary for communication with you. In particular, we can respond to your inquiries or contact you if we have any questions. We may also use the communication data for quality assurance and training purposes. In this case, the data will be pseudonymized or anonymized as far as possible. We may record or listen in on telephone calls or video conferences for quality assurance and training purposes. If you do not want your image to be recorded, you can turn off your camera.

Communication in connection with other purposes such as contract fulfillment, marketing, or market research may also be covered by this. Additional information can be found in the respective purpose description.

We also use the WhatsApp Business Platform (API) and WhatsApp Flows for communication. If you contact us via WhatsApp or interact with an automated flow, your name, phone number, and the content you send will be processed. Data is transferred via WhatsApp Ireland Limited. Data may also be processed outside Switzerland or the EEA. We recommend that you do not send any particularly sensitive personal data (e.g., health data) via WhatsApp. For more information, please refer to WhatsApp's privacy policy:
https://www.whatsapp.com/legal/privacy-policy-eea

In certain cases, we also use pre-approved message templates (known as templates) via the WhatsApp Business platform to contact you proactively. This includes, for example, service information, reminders about insurance changes, queries about ongoing consultations, or personalized offers. Such messages will only be sent if you have given your consent or if there is a legitimate interest, such as in the context of an existing customer relationship.

You can give us your consent in various ways:

  • By clicking on a checkbox when contacting us or registering on our website alletta.ch.
  • By sending the message 'START' to us via WhatsApp.
  • By replying to a template message from us.
  • As part of the registration process on the alletta.ch platform.

By agreeing to receive WhatsApp messages, you confirm that you are at least 16 years old.

alletta sales platform ag will send you contract and consultation information as well as occasional marketing offers (max. once a week) via WhatsApp. The messages are sent via WhatsApp, partly automatically or using pre-approved WhatsApp templates.

You can object to being contacted via WhatsApp at any time by writing “STOP” or “No more WhatsApp” directly in a WhatsApp chat. Once we receive your objection, your number will be blocked from receiving further proactive messages.

8.3 MARKETING AND INFORMATION

So that we can make you attractive and suitable offers and provide you with interesting information about products, services, events, etc., we may process your personal data for marketing purposes. This is e.g. This is the case, for example, if you take out insurance on our portal, if you use your cashback for a donation or find out about offers on our website. For marketing purposes, we may process the following data about you in particular:

  • Personal master data (e.g. title, first name, last name, date of birth, gender, user name);
  • Contact information (e.g. home/shipping address, email address, telephone number);
  • behavioral and transactional data (e.g. purchase details, purchasing behavior, participation in competitions, participation in events, information about subscribed services);
  • online identifiers (e.g. cookie identifiers, IP addresses);
  • Online tracking and traffic data (e.g. surfing behavior, click behavior when receiving newsletters);
  • Profile data or personal preference data (e.g. preferences regarding products or services).

The marketing purpose includes all processing that enables us to provide you with information about our offers. We may send you written and electronic information or offers. This includes, for example, the electronic dispatch of newsletters, emails, push notifications in apps, or other electronic communications, as well as the postal dispatch of advertising brochures, magazines, or other printed materials. This also includes digital advertising messages such as search, display, video, or social ads (e.g., on Google, YouTube, Facebook, Instagram, and TikTok). In addition, we may send you vouchers or invite you to events, prize draws, and competitions. We may also show you recommendations for products or services on our websites, our apps, and the Member Get Member program, or notify you of interrupted consultation processes.

We can also personalize the relevant offers and information based on the data we have about you so that, as far as possible, you only receive information and offers that are relevant and interesting to you. To do this, we may carry out appropriate evaluations and create profiles (see section 13). We also measure and evaluate the effectiveness of our advertising measures.

We may also commission third-party providers to place advertising measures, advertising campaigns, and measure conversions and carry out corresponding evaluations (e.g., using third-party cookies; see Sections 18.2 and 18.3).

You can unsubscribe from marketing communications at any time. You will find a corresponding unsubscribe link in each email communication. The relevant information on preventing marketing cookies (which lead to personalized ads, for example) can be found in the cookie policy (Section 18.2).

8.4 OTHER PURPOSES

We may also process your personal data for other purposes. These include:

Market and opinion research: We can process your personal data so that we can continually develop and improve our offerings. For example, we carry out customer surveys or surveys after you have purchased a product or service from us or have used a service. Corresponding surveys or surveys can e.g. B. via email, SMS, app or via a website. For this purpose, we normally only use pseudonymized or anonymized data. Under certain circumstances, we can evaluate and use the information to send you personalized offers (see sections 8.3 and 13). We can also use online reviews of products in advertising the products and show your review there (possible in both online and print media).

Asserting legal claims: In order for us to be able to assert legal claims or defend against unjustified claims, we may need to process your personal data. This may concern different categories of personal data, depending on the case concerned.

Compliance with legal requirements and prevention and investigation of criminal offenses or other misconduct: We may be obliged to check compliance with legal requirements and to cooperate with the authorities in the event of legal violations. Personal data may be processed for these purposes. This can affect all relevant personal data. This is e.g. B. in the case of enforcing regulatory requirements, disclosing information or documents to authorities if we are legally obliged to do so, or assisting in an official investigation (e.g. law enforcement or supervisory authority) if there is a legal obligation to do so.

Security: In order for us to ensure your security and the security of our business, we may need to process your personal data. This can affect all of your personal data. This includes carrying out spot checks to check the correct processing of transactions, analyzing behavioral and transaction data to identify suspicious behavior patterns or evaluating and analyzing the use of our systems.

Other purposes: We may process your personal data for other purposes, e.g. B. as part of our internal processes and administration. These other purposes include, for example: B. administrative purposes (such as the management of master data, accounting, data archiving as well as the testing, management and ongoing improvement of IT infrastructure) and the evaluation and improvement of internal processes. This also includes, for example, analyzing usage behavior on our apps and websites in order to optimize them (see also section 18). In order to improve certain services, we may also need artificial intelligence (AI) to analyze and evaluate user data. In these cases, the AI evaluation serves the sole purpose of optimizing the corresponding service. The protection of other legitimate interests is also one of the other purposes that cannot be named exhaustively. And this also includes processing the data to improve and train the AI we use

9. ON WHAT LEGAL BASIS DO WE COLLECT AND PROCESS YOUR PERSONAL DATA?

The legal basis for collecting and processing your personal data depends on the respective purpose of data processing in each individual case. The following principles apply:

We process your data in good faith and for the purposes set out in this data protection declaration (see Section 8). We ensure that processing is transparent and proportionate.

If, in exceptional cases, we are unable to comply with these principles, data processing may still be lawful because there is a justification. The following can be considered as justification:

  • your consent;
  • the implementation of a contract or pre-contractual measures;
  • compliance with legal requirements;
  • our legitimate interests, provided that your interests do not prevail.
  • Any consent you may have given can be revoked at any time. To this end, we have created an opt -out option for certain processing operations. An informal message via email is also sufficient. The legality of the data processing that has already taken place remains unaffected by the revocation.
  • The following reasons in particular come into question as legitimate interests:
  • the offering and further development of our offers, services, websites, apps and other platforms on which we are present;
  • communicating with third parties and processing their inquiries (e.g. to take out insurance);
  • the examination and optimization of procedures for needs analysis for the purpose of direct customer contact;
  • the implementation of advertising and marketing activities as well as the conduct of market and opinion research;
  • combating fraud and complying with legal regulations.

10. Communication via WhatsApp and messenger services

By submitting contact forms on our website or providing your mobile phone number, you expressly consent to Hoi Versicherung AG contacting you via the instant messaging service “WhatsApp” (a service provided by WhatsApp Ireland Limited, Ireland, parent company Meta Platforms, Inc., USA) and to the exchange of data.

10.1 Notice on Data Processing

We use WhatsApp to process your inquiries quickly and conveniently. Please note that when using WhatsApp, personal data (e.g. your phone number, name, communication metadata) is processed on servers operated by Meta, which may also be located in the USA. Despite encryption, it cannot be completely ruled out that third parties or government authorities in the USA may gain access to this data.

10.2 Revocation

You may revoke this consent at any time with effect for the future by sending us a short message (e.g. "Stop WhatsApp").

11. To whom do we pass on your personal data?

We may disclose your personal data to third parties if this is necessary for the performance of the contract (e.g., to the insurance company for the purpose of taking out insurance, to the distribution partner responsible for your contract with alletta, or to the institution responsible for credit checks) or in order to make use of necessary technical or organizational services. Such third parties are contractually obliged to process your personal data on our behalf, in accordance with our instructions and in compliance with their own data protection regulations. In addition, third parties must ensure the security of your personal data by means of appropriate technical and organizational measures. Service providers in the following areas may be affected by such order processing:

  • Advertising and marketing (e.g. sending newsletters, postcards, display advertising, surveys, competitions)
  • Organization and implementation of events
  • Combating fraud
  • Company administration and trusteeship
  • Payment processing and debt collection
  • IT services and hosting
  • Consulting and support services.

We walk you through every option so you can confidently take out the right policy for you.

12. CAN WE PASS ON YOUR PERSONAL DATA ABROAD?

Where possible, we process your personal data in Switzerland or the European Economic Area (EEA). Under certain circumstances, your personal data may be transferred to service providers abroad as part of order processing (see Section 10.2). The transmission can take place worldwide.

If there is no adequate data protection in the third country in question, data will only be transferred to a third country if the processor has provided guarantees that are considered appropriate by the legislature to ensure data protection (e.g. EU standard contractual clauses). A transfer based on standard contractual clauses only takes place after a prior risk assessment. If the risk assessment shows that the processor cannot comply with the standard contractual clauses, we will ensure that additional technical measures are taken to protect the integrity and confidentiality of the transmitted personal data.

13. DO WE PROCESS PARTICULARLY SENSITIVE PERSONAL DATA?

We only process particularly sensitive personal data (see Section 6.2) if this is absolutely necessary to provide the service and you have provided us with the relevant data or consented to the processing. Such processing occurs, for example, when you fill out the health declaration for a supplementary health insurance application.

14. HOW DO WE USE PROFILING?

Profiling involves automatically processing and combining people's purchase and behavioral data into profiles that may reflect your interests and preferences. These profiles form the basis so that we can show you products that interest you and are relevant to you. For this purpose, personal data such as personal master data (see Section 8.1), contract data (see Section 8.1), communication data (see Section 8.2), behavioral and transaction data, online identifiers or online tracking and traffic data (see Section 8.2) are used. Section 8.3) evaluated and combined with one another on the basis of recognized mathematical-statistical procedures and logic.

We use such reviews in particular to provide you with targeted information and advice about certain services or products. Thanks to profiling , we can continually improve our offers and adapt them to individual needs, communicate information and offers to you as needed or provide you with better support. Profiling also enables us to only send you information and offers that are actually relevant to you . For example, you will receive individual content in newsletters, apps and on alletta's websites (e.g. order of posts tailored to you) as well as advertising that is only of interest to you.

We carry out profiling with which we can also link personal data from different sources. We only carry out such profiling if you have given your consent. This is the case when you register on our portal. Thanks to this profiling, we can respond even better to your needs. You can object to the use of the corresponding evaluations for marketing purposes within the Coop group in your account. If you do not register on the portal, no corresponding profiling will take place .

15. DO WE USE AUTOMATED INDIVIDUAL DECISIONS?

We speak of automated individual decisions when decisions that have legal consequences for the person concerned or significantly affect them in another way are carried out completely automatically, i.e. without human influence.

We do not normally use automated individual decisions. If we do, you will be informed separately.

16. How long do we store your data?

We only retain personal data for as long as necessary to fulfill the individual purposes for which the data was collected, or if we are required by law to retain it for longer periods.

In particular, we must store business communications, concluded contracts and booking documents for up to 10 years (see in particular Art. 958f of the Swiss Code of Obligations [CO]). If we no longer need such data from you to carry out the services, the data will be blocked. We then only use it for accounting and tax purposes.

17. How we protect your data

We keep your personal data secure and take appropriate technical and organizational measures to protect your personal data from loss, access, misuse or alteration. Our contractual partners and employees who have access to your personal data are obliged to comply with data protection regulations.

Our website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential information (e.g. your insurance applications). You can recognize an encrypted connection by the browser address bar changing from 'http://' to 'https://' and by the lock symbol in your browser bar. Payment transactions using common payment methods (e.g. Visa/MasterCard etc.) are carried out exclusively via an encrypted SSL or TLS connection.

Since complete data security cannot be guaranteed for communication via email, we recommend choosing secure transmission via the portal for confidential information.

18. CHANGES TO THIS PRIVACY POLICY

We may change this privacy policy over time, for example if processing or the legal situation changes. If this is possible with reasonable effort, you will be notified separately in the event of significant changes.

19. WEBSITE AND COOKIE INFORMATION

The following information shows you how we process personal data or other data in connection with our websites or apps. This is done in particular through cookies or similar technologies. The following provisions apply to both our websites and apps, even if we are only talking about one website at a time.

19.1 PROVIDING THE WEBSITE AND CREATING LOG FILES

What information do we receive and how do we use it?

When you visit our website, certain data is automatically stored on our servers or on servers of services and products that we purchase and/or have installed. This is done for the purposes of system administration, backup, tracking or for statistical evaluations. This involves the following data:

  • the name of your internet service provider;
  • your IP address (possibly);
  • the version of your browser software;
  • the operating system of the computer used to access our website;
  • the date and time of access;
  • the website you previously visited;
  • the search words you used to find our website;
  • browser type;;
  • Host name of the computer;
  • access type;;
  • Login status.

How can you prevent data collection?

We walk you through every option so you can confidently take out the right policy for you.

19.2 COOKIES

How do cookies work and what are they used for?

Cookies are text files that are stored on your device's operating system using the browser when you access a website. Cookies contain a unique identification number (ID) that allows us to distinguish individual visitors from others. As a rule, you will not be identified. Cookies do not cause any damage to your computer and do not contain viruses. They also serve to significantly improve user interaction so that certain settings are saved for you, and are essential for some technical controls (e.g. session or shopping cart management).

What types of cookies are there?

Most of the cookies we use are so-called “session cookies” which are automatically deleted at the end of your visit.

Other cookies remain stored on your device until you delete them (although they are normally deleted after 2 years at the latest). The purpose of these cookies is to store your preferences (e.g. language and location settings), to provide the website content quickly and attractively (e.g. through the use of fonts and content delivery networks), and to analyze the use of this website for statistical evaluation as well as for continuous improvements and for marketing purposes (usually using third-party cookies, see below).

We can also use similar technologies such as: B. Use pixel tags, fingerprints or other technologies to store data in the browser. Pixel tags can be used to provide the server operator with certain information (e.g. whether and when a website was visited) through small, normally invisible images or program code that are loaded from a server. Fingerprints collect information about the configuration of your device or browser when you visit the website in order to distinguish your device from other devices. Most browsers also support additional technologies (e.g. web storage ) that we can also use.

Which cookies or similar technologies do we use?

We may use the following types of cookies or similar technologies:

Necessary cookies: These include cookies that are necessary for a website and its functions to be used. These cookies provide e.g. This ensures, for example, that when you switch between pages, form data that has already been entered is not deleted and shopping cart contents are not lost.

Performance and performance cookies: Performance cookies enable us to perform analytics by collecting information about how a website is used. This allows us to see, for example, how visitors move on a website. We may also measure loading times or website behavior across different browser types. Thanks to performance and performance cookies, we can always improve our websites and the user experience.

Functional cookies: Thanks to these cookies, we can store certain data that you enter on our websites so that you do not have to enter it again (e.g. location, language, form data, etc.). This allows us to increase the user-friendliness of our websites.

Marketing cookies: Marketing cookies allow us (or our marketing partners) to show you advertisements on our websites (or third-party websites) that are tailored to your browsing habits and that are of interest to you.

Do we use third-party cookies?

We may also use third-party cookies. In this case, the cookies are not stored by us when you visit the website, but by the third party provider. Such providers can also be based outside the European Economic Area (EEA), in which case data protection is ensured with appropriate measures (see Section 11).

Third-party cookies can be , for example, analysis services, but also tracking and retargeting measures. These enable us to target you with advertisements on our websites or on the websites of third parties and to measure the effectiveness of those advertisements. Third parties may record your use of our websites and may combine data collected on other websites. The relevant provider can also use this data for their own purposes, e.g. B. for personalized advertising on its own websites or other websites for which it serves advertisements. If the provider can identify you (e.g. because you have a customer account), they can assign the user data to you. The corresponding processing is carried out in accordance with the third-party provider's data protection regulations. The most important third parties are Google and Facebook. Below you will find a description of the most important tools we use (see section 18.3).

How can you prevent data collection via cookies?

The cookies are stored on your computer. You therefore have full control over the use of cookies. You can delete these completely or deactivate or restrict transmission by changing your browser settings. You can also block tracking by certain third parties using a browser extension. You can find further information about the use of cookies on the help pages of your browser. After deactivating cookies, you may no longer be able to use all functions of the website to their full extent.

Below you will find instructions for the most common browsers:

  • Google Chrome
  • Safari (Apple)
  • Microsoft Edge
  • Mozilla Firefox

('opt -out') is usually required for numerous services via the Network Advertising Initiative (NAI), YourAdChoices (Digital Advertising Alliance) or Your Online Choices (European Interactive Digital Advertising Alliance, EDAA) possible.

What other online advertising methods do we use?

In addition to third-party marketing and cookies, we use other techniques to control online advertising on other websites and thereby prevent wastage. For example, we can pass on our users' email addresses to third-party companies in a pseudonymized form (so-called hashing ) (see Section 6.6 for definition). By comparing the database, the advertising company (usually a social media provider) recognizes the contact details that already exist in its own database and can show you advertisements tailored to your interests (see, for example, the cookies used under Section 18.3). The third-party companies do not receive personal email addresses from people who are not already known. You can prevent personalized advertising from being displayed using the appropriate cookie settings (see above).

Can we include offers from third parties on our website?

We can integrate additional offers from third parties on our websites, in particular from social media providers. These offers are disabled by default. As soon as you activate this (e.g. by clicking a switch), the relevant providers can determine that you are on our website. If you have an account with this social media provider, it can assign this information to you and thus track your use of online offerings. The social media providers process this data on their own responsibility..

19.3 TRACKING TOOLS

We can use tracking tools on our websites and apps to help us evaluate the use of our online offerings and target visitors with marketing measures. Below you will find a list including an explanation of the most important tracking tools we use.

a. Google Analytics

How does Google Analytics work?

Our website uses Google Analytics, a service provided by Google Ireland Ltd. (Google Building Gordon House, Barrow St, Dublin 4, Ireland). Google uses cookies that are stored on your device and enable analysis of website usage. The information generated by the cookie about your use of the website is normally transmitted to a Google server in the USA and stored there. We have added the code “ anonymizeIP ” to Google Analytics. This ensures that all data is collected anonymously. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there.

Why do we use Google Analytics?

Google evaluates the data collected on our behalf so that we can get an idea of visits and user behavior on our websites. This allows us to improve our services and website content and design.

What additional functions do we use?

We also use cookies for remarketing campaigns. This function makes it possible to link the advertising target groups created with Google Analytics Remarketing with the cross-device functions of Google AdWords and Google DoubleClick . In this way, interest-based, personalized advertising messages that have been adapted to you depending on your previous usage and surfing behavior on one device (e.g. smartphone) can also be displayed on another of your devices (e.g. tablet or PC). become. If you have given Google your consent, Google will link your web and app browsing history to your Google account for this purpose. This means that the same personalized advertising messages can be displayed on every device on which you log in with your Google account. To support this feature, Google Analytics collects Google authenticated user IDs, which are temporarily linked to our Google Analytics data to define and create audiences for cross-device advertising.

How can you prevent your data from being collected via Google Analytics?

You can prevent the storage of cookies by adjusting the settings in your browser accordingly (see section 18.2). You can opt out of Google Analytics by downloading and installing the Google Browser add-on.

b. Google Ads Conversion Tracking or similar services from other providers

With Google Ads Conversion Tracking or comparable services from other providers (including those relevant to YouTube ads), a cookie is set on your computer if you have reached one of our websites via a corresponding ad. This is done for the purpose of tracking and performance measurement. No information is collected that could be used to identify the user. Our legitimate interests in determining performance serve as the legal basis. The cookies are automatically deleted after 30 days.

Right to object

If you do not wish to participate in the tracking process, you can prevent the required cookies from being set in your browser settings.

You can find more information about Google Ads and Google Conversion Tracking in Google's privacy policy at https://www.google.de/policies/privacy.

c. Google Customer Match

So that we are able to place personalized advertisements via Google's services, we can forward lists of encrypted and pseudonymized personal data of our customers (e.g. email address) to Google (see also Section 8.3). . This data is then compared so that advertising can be shown via the Google network to people whom Google can identify. Through this process, Google does not obtain any new personal data that can be used for its own purposes.

If you have a Google account, you can deactivate personalized ads here. Without a Google account, you can achieve personalized advertising by deactivating cookies (see section 18.2).

d. Meta Pixel and Custom Audience

How does Meta Pixel and Custom Audience work ?

Facebook's visitor action pixel ( Meta.) to measure conversions Platforms Ireland Ltd., Harbor 4, Grand Canal Quay, Grand Canal Bridge, Dublin 2, Ireland). Meta Pixel allows us to track your behavior after you have been redirected to our website by clicking on a Facebook ad . The data collected is anonymous for us as the operator of this website and therefore does not allow any conclusions to be drawn about you personally.

Why do we use Meta Pixel?

We use Meta Pixel to evaluate the effectiveness of Facebook advertisements for statistical and market research purposes and to optimize future advertising measures.

We also use Custom Audience so that our Facebook ads are only shown to those people who are already interested in our offers or have similar interests). For this purpose , we can transmit email addresses to Facebook in encrypted and pseudonymized form (so-called hashing ) so that they can be compared with the database and identical users can be identified (see also section 8.3 above). Through this process, Facebook does not obtain new email addresses that can be used for its own purposes.

If you do not want personalized ads from Facebook, you can set this accordingly in the settings.

Who is responsible for data processing?

for exchanging data that Facebook collects or receives via Meta Pixel or comparable functions, for displaying advertising information that corresponds to visitors, for improving ad delivery and personalizing functions and content . You can therefore address requests for information or other data protection concerns directly to Facebook.

We are not responsible for any further data processing. Your data may be processed by Facebook in this regard. In particular, a connection to your respective user profile is possible and Facebook can use the data collected for its own advertising purposes.

e. Facebook SDK

Where and for what purpose do we use Facebook SDK?

Some of our apps use the so-called Facebook Software Development Kit (Facebook SDK). Provider is Meta Platforms Ireland Ltd., Harbor 4, Grand Canal Quay, Grand Canal Bridge, Dublin 2, Ireland . Facebook SDK is used to measure Facebook Ads that we run on Facebook. Facebook SDK serves as an interface for the transmission of information for the display of advertising on end devices. To identify our apps, we send Facebook an ID via this interface. Furthermore, no other user data is transmitted to Facebook via the SDK. However, Facebook SDK itself is able to collect various data and send it to Facebook.

The data that the Facebook SDK logs can be found on the Facebook website under 'What data does Facebook collect with the SDK?' visible.

How can you limit transmissions to Facebook?

You can restrict the transmission of data through the Facebook SDK by activating the 'Restrict Facebook SDK' option in the app. With the restriction, only the following data will be transmitted:

  • a Facebook app ID, which identifies the app to Facebook;
  • the version of Facebook SDK;
  • the language set on the device;
  • the platform (iOS/Android);
  • the version of the operating system.

f. TikTok Pixel and Custom Audience

How do TikTok Pixel and Custom Audience work?

Our websites use the TikTok Pixel from TikTok Technology Limited (10 Earlsfort Terrace, Dublin, D02 T380, Ireland) or TikTok Inc (5800 Bristol Parkway, Culver City, CA 90230, USA) to measure conversions. The TikTok Pixel enables us to track your behavior after you have been redirected to our website or app by clicking on a TikTok ad. The data collected is anonymous to us as the operator of this website/app and therefore does not allow any conclusions to be drawn about your person.

Why do we use TikTok Pixel?

We use TikTok Pixel to evaluate the effectiveness of TikTok advertisements for statistical and market research purposes and to optimize future advertising measures. We also use Custom Audience so that our TikTok ads are only displayed to people who are already interested in our offers or have similar interests. For this purpose, we can transmit e-mail addresses to TikTok in encrypted and pseudonymized form (so-called hashing) so that a comparison can be made with the database and identical users can be identified (see also section 8.3 above). This process does not provide TikTok with new email addresses that can be used for its own purposes. If you do not wish to receive personalized advertisements from TikTok, you can set this accordingly in the settings.

Who is responsible for data processing?

We are jointly responsible with TikTok for the exchange of data that TikTok collects or receives via TikTok Pixel or comparable functions, for the display of advertising information that corresponds to the visitors, for the improvement of ad delivery and the personalization of functions and content. You can therefore also address requests for information or other data protection concerns directly to TikTok. We are not responsible for any other data processing. Your data may be processed by TikTok in this regard. In particular, a connection to your respective user profile is possible and TikTok may use the data collected for its own advertising purposes. Further information can be found in TikTok's privacy policy: https://www.tiktok.com/legal/privacy-policy

g. WhatsApp Business Platform (API) and Flows

How do the WhatsApp Business Platform and WhatsApp Flows work?

We use the WhatsApp Business Platform (API) from Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) to communicate with you efficiently and personally via WhatsApp to offer services and exchange information. We also use WhatsApp Flows, a function that enables us to integrate structured experiences (e.g. forms, interactive menus, product presentations) directly into WhatsApp chats. We can use the API to send and receive messages, process customer inquiries, arrange appointments, provide product information or fulfill other service and marketing purposes.

How do we obtain your consent (opt-in) for WhatsApp messages?

We only send WhatsApp messages with your express consent. We obtain this in various ways:

  • By clicking on a checkbox when contacting us or registering on our website alletta.ch.
  • By sending the message 'START' to us via WhatsApp.
  • By replying to a template message from us.
  • As part of the registration process on the alletta.ch platform.

What information do you receive in the opt-in process?

By agreeing to receive WhatsApp messages, you confirm that you are at least 16 years old. We also inform you that alletta Sales Platform AG will send you contract and advisory information as well as occasional marketing offers (max. 1x/month) via WhatsApp.

Can messages be automated?

Yes, we would like to point out that the messages sent via WhatsApp can be partially automated or sent via pre-approved WhatsApp templates.

What data is processed?

If you communicate with us via WhatsApp or use WhatsApp Flows, we process your telephone number, your WhatsApp user name, the content of your messages and any other information that you provide to us as part of the Flows (e.g. your answers in forms, selection of options). We store this communication data in our customer database to process your requests and improve our services.

How long do we store WhatsApp chat content?

We store WhatsApp chat content that is required to fulfill our communication and service purposes for a maximum period of 24 months. After this period has expired, the data will be deleted or anonymized, provided that there are no legal retention obligations to the contrary or further storage is necessary for the fulfillment of the contract.

Why do we use the WhatsApp Business Platform and Flows?

It is used for efficient and modern customer communication, the provision of support services, the provision of information and, if you have given your consent, also for marketing purposes (e.g. sending offers or updates). WhatsApp Flows enables us to communicate in a more interactive and user-friendly way.

Who is responsible for data processing?

We are responsible for the content of the communication we have with you via the WhatsApp Business Platform. As the operator of WhatsApp, Meta Platforms processes data as part of the provision of the WhatsApp Business Platform and WhatsApp Flows under its own responsibility. This includes technical data for the transmission of messages and data required to comply with WhatsApp's terms of use.

Further information

Please note that Meta Platforms may also process your data for its own purposes (e.g., to improve its services, for security purposes, or for marketing) in accordance with its privacy policy. The data may also be processed by Meta in countries outside Switzerland and the EEA where there is no comparable level of data protection. For more information about Meta Platforms' data processing and your rights, please consult WhatsApp's privacy policy:
https://www.whatsapp.com/legal/privacy-policy and https://www.whatsapp.com/legal/terms-of-service

h. Access rights of the apps

In order to provide the services in our apps, we may require the access rights listed below, which enable us to access certain functions of your device:

Location data up to the level of your exact location: Location data is collected, for example, to display the correct language version. The data is not stored.

Photos, videos: This data is collected, for example, to ensure the fast use of functions such as Google Maps. Photos and videos may be used elsewhere to supplement entries you have created yourself (for example, for your photo in the Member get Member program).

Notifications (iOS only): This data is collected to regulate the receipt of push notifications.

Camera: This data is collected to enable us to read personal data (on ID cards, policies, etc.) and take photos and videos (e.g., your photo in the Member get Member program).

Calendar (iOS only): This data is collected to enable us to set appointments in the calendar (e.g., reminders for contract expirations).

Disable sleep mode (Android only): Data is collected to enable you to receive push notifications.

Reading Google service configuration: Data is collected, for example, to enable the linked use of Google Maps.

Vibration function: Data is collected, for example, to confirm the photographing of an ID card with a vibration.

Retrieving a network connection: This data is collected to determine the presence of a network connection.

All networks / Use mobile data: This data is collected to enable access to the Internet (e.g., for data updates, logins).

Light indicator (flash): This data is collected to enable the flash to be turned on when using the camera.

Wi-Fi connection information: This data is collected to enable Wi-Fi connections to be retrieved and the Wi-Fi status to be displayed.

Siri and Search (iOS only): This data is collected to enable suggestions to be made when you enter text in the app.

Background updates (iOS only): This data is collected to enable the app to update in the background.

i. SEMrush

Semrush is the only software which enables marketing professionals to build, manage, and measure campaigns across all channels to improve their online visibility. Semrush is your digital team member—your analytics buddy, your mentor, your safety net, and a compass to new markets

j. Hotjar

Hotjar helps users understand how users behave on their site, what they need, and how they feel.

In 2014, they started with a simple beta version of Hotjar, collected feedback from hundreds of testers (they consider them their ‘Founding Members’), and kept improving through iterative changes.

Jumping forward to now, Hotjar is the leading solution for product teams who want to go beyond traditional web and product analytics so they can empathize with and understand their users—to connect the dots between what's happening and why it happens, so they can improve the user experience (UX) and create customer delight.

k. Mouseflow

We use Mouseflow, a web analytics service provided by Mouseflow ApS (Denmark), to analyze user behavior on our website. Mouseflow enables so-called session replays, which anonymously record mouse and scroll behavior, clicks, and interactions on the website. The data helps us to improve user-friendliness. No personal information (e.g., in form fields) is stored.

Further information can be found at:https://mouseflow.com/legal/visitor

You can deactivate Mouseflow tracking at any time:https://mouseflow.com/opt-out

19.4 WHAT DATA DO WE PROCESS ON OUR SOCIAL NETWORK PAGES?

We may operate pages on social networks and other third-party platforms such as Facebook, Instagram, and TikTok, as well as other online presences (“fan pages,” “channels,” “profiles,” etc.), where we collect the data about you described in Section 7 and below. We receive this data from you and the platforms when you contact us via one of our online presences (e.g., when you communicate with us, comment on our content, or visit our presence). At the same time, the platforms evaluate your use of our online presences and link this data to other data about you known to the platforms (e.g., about your behavior and preferences). This may also be the case for our presences on Facebook, Instagram, and TikTok. The platforms also process this data on their own responsibility for their own purposes, in particular for marketing and market research purposes (e.g., to personalize advertising) and to control their platforms (e.g., what content they display to you).

We process this data for the purposes described in section 8, in particular for communication, for marketing purposes (including advertising on these platforms, see section 18.2) and for market research. We may redistribute content that you publish yourself (e.g., comments on an announcement) (e.g., in our advertising on the platform or elsewhere). We or the platform operators may also delete or restrict content from or about you in accordance with the terms of use (e.g., inappropriate comments).

For further information on the processing of data by the platform operators, please refer to the privacy policies of the respective platforms. There you will also find information on the countries in which they process your data, your rights to information, deletion and other rights of data subjects, and how you can exercise these rights or obtain further information.

Last update: December 2024