Privacy

1. Introduction

We recognize the importance of your privacy and of transparency in our processing of your personal data.

At DSS Sustainable Solutions Switzerland SA (we, our or dss+), we recognize the importance of your privacy and of transparency in our processing of your personal data.

This general privacy notice (General Privacy Notice) informs you about the personal data we collect and process in connection with the provision of our digital solutions (the Digital Solutions) and our services provided in this context (together with the Digital Solutions, our Services), which are listed in Section 15 of this General Privacy Notice (Service-Specific Information), as well as our general business activities.

We may have additional privacy notices (the Additional Privacy Notices) which apply in addition or instead of this General Privacy Notice in specific situations or for specific Services, in which case the terms of such Additional Privacy Notices will prevail over those of this General Privacy Notice.

By accessing and using our Services, or otherwise providing us your information, you expressly acknowledge that we may collect and process your personal data in accordance with this General Privacy Notice.




2. Summary of key points

The following is a summary of (but not a replacement for) this Privacy Notice:

  • DSS Sustainable Solutions Switzerland SA is in general responsible for the processing, as controller, of your personal data (see Section 3).
  • As part of our operation of the Services, we may collect personal data which is provided to us by you, your organization, and by third parties, or which we collect automatically when you interact with the Services (see Section 4).
  • We process such personal data in compliance with the laws applicable to us, mainly for the purpose of providing our Services to our customers, in particular to operate our Digital Service, in accordance with the contract between us and your organization, acting as a processor for your organization, or in some cases, as a controller for our legitimate business operations related to providing those Services (see Section 7, as well as Sections 5 and 6).
  • This General Privacy Notice does not address how your organization collects and uses your personal data or how we process your data when we act as processor for your organization. You must refer to your organization’s privacy policy for information about its processing activities (see Section 8).
  • We store your personal data in different regions depending notably on where you reside. We do not share it with third parties or transfer it abroad unless this is both necessary for the operation of the Services and permitted by applicable data protection laws. This may for instance be the case when we use service providers or must interact with third parties to conduct our professional activities. (see Sections 8 and 10);
  • We do not store your personal data for longer than necessary to fulfill the purposes set out in this Privacy Notice (see Section 11).
  • We apply commercially accepted security measures and take commercially reasonable efforts to protect your personal data. However, no IT infrastructure is completely secure and we cannot provide a full guarantee that our environment will never be compromised (see Section 12).
  • You may contact us (privacy@consultdss.com) to exercise your rights pertaining to your personal data (see Sections 14 and 15). However, you must contact your organization directly if your query regards our processing of your personal data on behalf of your organization (see Section 8).



3. Who is responsible for the processing of your personal data?

DSS Sustainable Solutions Switzerland SA, Chemin Jean-Baptiste Vandelle 3A, CH-1290 Versoix, Switzerland, is responsible for the processing, as controller, of your personal data. You will find our contact details below in Section 13.

However, some of the processing activities set out in this General Privacy Notice are undertaken by our group entities, which will then act as data controller. The exact split differs between group entities and over time. We can confirm which processing activities are undertaken by which entity, on request.

This General Privacy Notice only applies to processing undertaken by or on behalf of us. Whilst we may provide links to third-party websites, contents, or services, we are not responsible for your use or access to such websites or for their policies in relation to personal data. In such circumstances, the collection and use of your personal data are governed by the privacy policy of those third-party providers, which you should carefully review to learn more about their personal data processing practices.

As further detail in this General Privacy Notice, we may process your personal data in connection with the professional Services we provide to your employer, respectively the organization to which you are affiliated in any other way (each an Organization). This General Privacy Notice does not govern how your Organization process your personal data through the Services. You must refer to your Organization's policies. Please see Section 8 below for additional information in this respect.




4. How we collect your personal data

We collect the personal data that you or your organization provide to us.

We collect the personal data that you or your Organization provide to us when interacting with us and/or using our Services, for example when you use our Digital Solutions, communicate with us, create and/or manage your account, fill out website forms, subscribe to our newsletter, participate in a contest, promotion, survey or other promotion, participate in a blog or forum, contribute to market research we conduct, share information at a trade show or other event.

In particular, we may collect and process personal data about individuals with whom we interact, such as the name, title, position, company name, email and/or postal address and the professional fixed and/or mobile phone number. This information may either be directly provided by you or provided by your Organization (e.g. if you are the contact person designated by your employer to manage the relationship with us). We may also ask our third party partners to collect this information for us.

Some information is mandatory, and some is optional.

It is mandatory that you complete the data fields identified by an asterisk. If one or more mandatory data fields are not completed, we will not be able to provide access to our Services. You are not required to complete the optional data fields in order to access our Services.

Certain personal data are also collected in an automated manner.

We also automatically collect personal data, including by means of tools, web forms, cookies and other active elements, as further described in this General Privacy Notice.

You may define certain authorizations relating to the automatic collection of your personal data when you configure your device or your internet browser according to available functionalities. You may also define certain settings for the automated collection of your personal data through the cookies setting plug-in available on the Digital Solutions. For more detailed information, please see the cookie section below (Section 13).




5. How we process your personal data

We process your personal data by automated means for the purposes indicated in this General Privacy Notice and in accordance with applicable law.

We process your personal data in compliance with applicable law, in particular Swiss data protection law and, to the extent they apply to us, other data protection legislations, such as the EU General Data Protection Regulation (GDPR) or its equivalent in the United Kingdom, using computers or computer tools, in line with the purposes set out in this General Privacy Notice and any Additional Privacy Notice.

We may process your personal data to create a profile about you and provide you with more relevant information and services (profiling), for instance to show you more relevant information based on prior interactions with our Services. You may have the right to object to such activities, in accordance with applicable data protection laws (see Section 14 below for additional information on your rights).

We, however, do not make decisions exclusively on the basis of automated processing which has legal effects on the data subjects or affect them significantly (automated individual decision).

We may combine your personal data with other information (aggregate) or erase any information that allows us to identify you (anonymize), so that it is no longer considered personal data under applicable data protection law, in which case this General Privacy Notice will no longer apply and we may use such data for purposes not contemplated by this General Privacy Notice (e.g. for benchmarking or analytics purposes, or to develop and market new services). You may object to the anonymization or aggregation of your personal data for this purpose at any time (see Section 14 below for additional information on your rights).

We take the technical and organizational appropriate security measures to prevent unauthorized access, disclosure, modification, alteration or destruction of your personal data, as specified in Section 12 below.




6. On which legal ground do we process your personal data?

We process your personal data only if we have a valid legal ground to do so.

We will only process your personal data if we have a valid legal ground for doing so. Unless we must process your personal data for one of the reasons listed below, we will process your personal data as data processor for the providing of our Services to our customers (see Section 8).

Depending on the processing activity carried out, we may also process your personal data if:

  • The processing is necessary to fulfil our contractual obligations to you or to take pre-contractual steps at your request (Contractual Necessity), in particular in case processing your personal data is strictly required to provide you with the Services where your activities are not conducted on behalf of an Organization. When the GDPR applies, Contractual Necessity is based on Article 6(1)(b) GDPR.
  • The processing is necessary for the fulfilment of our legitimate business interests, and only to the extent that your interests or fundamental rights and freedoms do not require us to refrain from processing (Legitimate Interests). When the GDPR applies, Legitimate Interest is based on Article 6(1)(f) GDPR.
  • We have obtained your prior consent in a clear and unambiguous manner (Consent). When the GDPR applies, Consent is based on Article 6(1)(a) GDPR.
  • The processing is necessary to comply with our legal or regulatory obligations (Legal Obligation). When the GDPR applies, Legal Obligation is based on Article 6(1)(c) GDPR.



7. Purposes for which we process your personal data

We process your personal data for legitimate and clearly identified purposes.

Your personal data is collected and processed for the purpose of operating the Services and for the other legitimate purposes explicitly specified below or in the relevant Additional Privacy Notice, only to the extent relevant to achieve these purposes, and is not further processed in a manner that is incompatible with them.

We process your personal data for the following purposes:

To provide our Services to you or your Organization.

We mainly process your personal data to provide the requested Services to your Organization and you, including operating the Digital Solutions and providing the requested functionalities, in accordance with your Organization's instructions. In this case, our processing of your personal data in connection with the Services is governed by a contract between us and your Organization, and your use of the Services is subject to your Organization's policies.

If your use of our Services is not related to an Organization, our basis for processing the data is our Contractual Necessity.

You will find additional information about our activities in connection with the specific Services we provide in Section 15.

For our legitimate business operations related to the provision of the Services.

Furthermore, we may also process your personal data for our legitimate business operations related to the provision of the Services, which include (i) ensuring that our Services are provided in an efficient and secure way (e.g. through internal analysis of the Services’ stability and security, updates and troubleshooting, as well as support services); (ii) protecting the security of our IT systems, architecture and networks; (iii) managing our customers and suppliers; (iv) improving and developing the Services (including monitoring the use of our Services, and for statistical purposes); (iv) benefiting from cost-effective services (e.g. we may opt to use certain services offered by suppliers rather than undertaking the activity ourselves); and (v) achieving our corporate goals.

When doing so, we generally rely on our Legitimate Interests. We may also process your data we have obtained your prior unambiguous Consent. You may withdraw your consent, respectively object to such processing activities, at any time.

Additional Information

Additional information on the processing of your personal data for our legitimate business operations:

  • For ensuring that our Digital Solutions are provided in an efficient and secure way. In addition to the personal data which you or your Organization provide when logging-in to your account or interacting with the Digital Solutions (e.g. when you fill in forms or upload content to the Digital Solutions), we automatically collect technical information about your interactions with the Digital Solutions, such as IP address, the content that was accessed, date and time of access, information about your web browser, your preferences, or other information related to your interaction with the Digital Solutions, including your navigation details on the Digital Solutions. We process this data to establish a connection with your device over the internet, to identify you when you use the Digital Solutions, control the use of the Digital Solutions and for security purposes
  • For protecting the security of our IT systems, architecture and networks. We use data to protect the security of our IT systems, architecture, and networks, for instance to detect and disrupt the operation of malicious software by systematically scanning contents in an automated manner.
  • For Maintenance and support. We use data to maintain our Services, troubleshoot and diagnose problems, and to provide customer support services.
  • For internal analysis and statistical purposes in order to improve our Services. Unless you object to such processing, we may process your personal data, in particular data relating to your use of our Services and your habits and preferences (e.g. the content you accessed, date and time of access and your preferences), for internal analysis and statistical purposes, to better understand the needs of our users, to optimize their experience, and in general to improve the ergonomics and functionality of our Services. You may object to such processing activities at any time (see Section 14 below for additional information on your rights). We do not link this information to you or your account. In connection with our Digital Solutions, we use analytics tools provided by known market providers which provide to us only aggregated, non-identifiable data. The privacy policy of those service providers is applicable in this context. You will find additional information in Section 13 in relation to the use of cookies for this purpose.
  • For general customer or supplier management purposes. If we are in a business relationship with your Organization (or with you directly), or are in discussions to enter into one, we process the personal data that is necessary for our customer or supplier management, as well as for the following other related purposed, including (i) to carry out the transactions in which we are engaged, and to procure products and services from our suppliers and subcontractors; (ii) to interact with you, for instance to reply to your inquiries; (iii) to track our activities (measuring sales, our work time, etc.) and those of our suppliers; (iv) to manage our archiving and records; and (iv) for invoicing purposes. The personal data that we process in this context includes: (i) personal data about individuals with whom we interact, such as the name, title, position, company name, email and/or postal address and the professional fixed and/or mobile phone number; (ii) personal data relating to our interactions and the services provided; (iii) any other information provided to us by you, your Organization, or third parties.

To send you our newsletter and other advertising information:

If you subscribe to one of our newsletters, we will collect your contact details (name and email address) and use it to provide you with the requested newsletter, based on your Consent. You may unsubscribe from the newsletter service at any time, in which case your contact details will be deleted.

We also process the time of registration and your opt-in confirmation based on our Legal Obligation to demonstrate compliance. We also analyze your use of our newsletter, e.g. whether you have opened it or clicked on certain links, and process this data to optimize and improve our newsletter, based on our Legitimate Interest.

We use the services of third parties to send our newsletters, which will have access to the information strictly required to them in order to provide you with the service. Their privacy statements are applicable in connection with this.

Independently from your subscription to our newsletter, we may also contact you by email to inform you about our activities if you or your Organization have previously subscribed or purchased a similar Service from us, if you have not objected to the corresponding use of your email address. You can object to the use of your email address for this purpose at any time by contacting us (see contact detail in section 15). The legal basis for the corresponding processing of your data is our Legitimate Interest to advertise certain sales offers and activities relating to our previous interactions with you.

To provide you with targeted information or advertisements based on your interactions with the Digital Solutions:

Provided we have collected your valid Consent, we use as part of our operation of certain Digital Solutions the services of third parties, which may place cookies on your device in order to provide you with personalized advertisements based on your interaction with our Digital Solutions. The privacy policies of those providers are applicable in relation to their activities. You may withdraw your Consent at any time (see Section 14 below for additional information on your rights).

You will find additional information in Section 13 in relation to the use of cookies in connection with the operation of our Digital Solutions.

To comply with our other Legal Obligations or for other Legitimate Interests.

We may further process your personal data if we have a Legal Obligation to do so or for other Legitimate Interests. This will for instance be the case if we need to disclose certain information to public authorities or retain such information for tax or accounting purposes, or for the establishment, exercise or defense of legal claims. We retain the personal data for the duration of the legal obligation imposed on us.

If we have obtained your consent.

In addition to the above, we may process your personal data if we have obtained your prior unambiguous consent for specific purposes. Consent given can be withdrawn at any time, but this does not affect data processed prior to withdrawal.




8. Our Operations with Your Organization

If you are an end user of a Service we provide to your Organization, or if we process for any other reason your personal data on behalf of your Organization (for instance, if you are not a user, but your personal data is provided to us by your Organization), please read the following:

  • In the situations described above, our processing of your personal data is governed by a contract between us and your Organization. We will process your personal data as data processor for the providing of our Services to our customers, or in some cases, as a controller for our legitimate business operations related to providing those Services, as detailed in this General Privacy Notice
  • This General Privacy Notice does not address how your Organization collects and uses your personal data or how we process your data when we act as processor for your Organization. Please refer to your Organization’s privacy policy for information about its processing activities.
  • Some information about you may be provided to us directly by your Organization. If this is the case, it is your Organization which is responsible for ensuring that your personal data is collected and transferred to us in accordance with all privacy and data protection laws of all relevant jurisdictions, based on an appropriate legal ground.
  • If you would like to make any requests or queries regarding our processing of your personal data on behalf of your Organization, please contact your Organization directly. For example, if you wish to access, correct, amend, or delete inaccurate personal data that was originally transmitted by your Organization, please direct your query to your Organization. If we are requested by your Organization to remove your personal data, we will respond to such request in a timely manner upon verification and in accordance with applicable law (thirty (30) days under Swiss law or the GDPR).
  • If you have questions about our legitimate business operations in connection with providing Services to your Organization, please contact us as described in Section 15.



9. The circumstances in which we share your personal data with third parties

We may share your personal data with our affiliates or with third parties if this is necessary for the operation of our Services, if there is a legal obligation or permission to do so, or if there is another valid reason to do so.

We may share your personal data with our affiliate, with third parties in connection with the operation of the Services or business operations and with subcontractors such as IT service providers, cloud service providers, database providers, automated marketing solutions providers and consultants. You will find additional information on our use of subcontractors for specific Services in Section 15 below.

We may also enable you to use third-party services directly from the Digital Solutions, in particular through the social plug-ins and may enable you to use third-party services to log in to the Digital Solutions. In such cases, you acknowledge that the third-party operators of such services may access some of your personal data related to the Digital Solutions, in accordance with their own privacy practices.

We may share your personal data with your Organization to enable it to manage the Services.

If you use a Service provided by an Organization you are affiliated with, we share certain data, such as interaction data and diagnostic data to enable your Organization to manage the Services.

We may also disclose your personal data to third parties where we have a legal obligation to do so or a legitimate interest in doing so.

We may also disclose your personal data where we have a legitimate interest in doing so, for example (i) to respond to a request from a judicial authority or in accordance with a legal obligation; (ii) to bring or defend against a claim or lawsuit; or (iii) in the context of restructuring, in particular if we transfer our assets to another company.




10. International Transfers

Your personal data is in general stored near to the geographic location where you reside but may in certain circumstances be disclosed in other countries.

We generally store your personal data near to the geographic location where you reside (e.g. in the EU for EEA, UK and Swiss residents, and in the U.S. for U.S. residents). In certain circumstances, in particular in connection with the operations of our subcontractors, your personal data may, however, be made available to recipients located abroad. Please consult section 15 (Service-Specific Information) for additional information about international transfers.

In such cases, we will ensure that suitable safeguards are in place, in accordance with applicable data protection laws, for instance by relying on standard contractual clauses adopted by the European Commission.

If you transmit information and data to us, you are expressly deemed to acknowledge to such data transfers. You may request additional information in this regard and obtain a copy of the relevant safeguards upon request by sending a request to the contact address indicated in Section 15 below.




11. How long we store your personal data?

Your personal data will not be stored longer than necessary.

We will erase or anonymize personal data as soon as it is no longer necessary for us to fulfil the purposes set out in this General Privacy Notice. This period varies, depending on the type of data concerned and the applicable legal requirements. In view of the legal obligations incumbent upon us, certain information relating in particular to the contractual relationship must be retained for at least 10 years.

When we process your personal data as Processor for your Organization, we will retain your data for the duration of our contract with your Organization, plus any period thereafter during which we must retain it for a legal or technical reason (such as evidentiary or tax purposes). If you leave your Organization (e.g. in the event of change of employment), or if your Organization requests us to do so, your account and access to the Services will be removed. In this case, we will delete from our servers or anonymised any personal data associated with your account.

More information on each type of processing can be found in Section 15.




12. Security

We maintain physical, technical and procedural safeguards to keep secure your personal data.

We are committed to the security of your personal data, and have in place physical, administrative and technical measures designed to keep secure your personal data and to prevent unauthorized access to it. We restrict access to your personal data to those persons who need to know it for the purpose described in this General Privacy Notice. In addition, we use standard security protocols and mechanisms to exchange the transmission of sensitive data.

Although we take appropriate steps to protect your personal data, no IT infrastructure is completely secure. Therefore, we cannot guarantee that data you provide to us is safe and protected from all unauthorized third-party access and theft. We waive any liability in this respect.

The internet is a global environment. As a result, by sending information to us electronically, such data may be transferred internationally over the internet depending upon your location. Internet is not a secure environment, and this General Privacy Notice applies to our use of your personal data once it is under our control only. Given the inherent nature of the internet, all internet transmissions are done at your own risk.

If we have reasonable reasons to believe that your personal data have been acquired by an unauthorized person, and applicable law requires notification, we will promptly notify your Organization or you directly (depending on our contractual obligation toward your Organization, if any), of the breach by email (if we have it) and/or by any other channel of communication (including by posting a notice on the Digital Solutions).




13. How we use cookies or other analytical tools

We use Cookies, other analytical tools and similar technologies in connection with the Digital Solutions.

We use various types of cookies, other analytical tools or similar technologies (collectively, Cookies) in connection with our Digital Solutions, some of which are capable of automatically processing data on your electronic device and/or of transferring personal data about you to us or third parties.

These technologies are generally used to monitor and analyse your interactions with the Digital Solutions and/or to enable us to improve the Digital Solutions and their functionalities, including customizing the Digital Solutions and related services, depending on your interactions. We may also use Cookies to measure and monitor the traffic and use of the Digital Solutions and their performance.

Cookies are generally divided in four categories:

  1. Essential Cookies. Some cookies are placed on your electronic devices to make the Digital Solutions capable of being used, by providing basic features such as page browsing and accessing secure areas. The Digital Solutions cannot function properly without this type of Cookies.
  2. Functionality Cookies. Some Cookies enable the Digital Solutions to remember choices persons make, for example, username, and language or text size. These cookies are known as “functionality cookies” and help to improve a person's experience of the Digital Solutions by providing a more personalized service.
  3. Advertising Cookies. These cookies are used to better understand user interests and to display more relevant advertisements.
  4. Analytics/productivity Cookies. Analytics/productivity Cookies, such as those linked to Google Analytics, help understand how users interact with the Digital Solutions by anonymously collecting and reporting information.

Our use of cookies may vary depending on the section or functionalities of the Digital Solutions you access. You will find additional information for each Digital Solution which you use in Section 15.

You can manage Cookies through the settings of your web browser and/or electronic device, as well as through the interface available on the Digital Solutions.

If you do not want Cookies to be stored on your electronic device, you can configure your internet browser or electronic device to refuse and/or restrict them. You may also set the use of Cookies on the Cookie management page of the Digital Solutions if this functionality is available. However, some Cookies are essential to the functioning of the Digital Solutions, and they may operate differently if you refuse or completely restrict Cookies.

For more information, please visit the website http://www.allaboutcookies.org. You can also see the help section of your internet browser or electronic device for more specific instructions on how to manage Cookies.




14. Your rights with regard to the processing of your personal data

You have the right to access your personal data we process and may request without limitation that they be removed, updated, or rectified.

If you are using a Service provided by your Organization, you should direct your privacy inquiries relating to our use of your personal data on behalf of your Organization, including any requests to exercise your data protection rights, directly to your Organization’s contact person.

In other cases, you may contact us directly to exercise your rights. Unless otherwise provided by law, you have the right to know whether we are processing your personal data, to know the content of such personal data, to verify its accuracy, and to the extent permitted by law, to request that it be supplemented, updated, rectified or erased. You also have the right to ask us to cease any specific processing of personal data that may have been obtained or processed in breach of applicable law, and you have the right to object to any processing of personal data for legitimate reasons.

Where we rely on your consent to process your personal data, we will seek your freely given and specific consent by providing you with informed and unambiguous indications relating to your personal data. You may revoke at any time such consent (without such withdrawal affecting the lawfulness of processing made prior to).

The above does not restrict any other rights you might have pursuant to applicable data protection legislation under certain circumstances. In particular, if the GDPR applies to the processing of your personal data the GDPR grants you certain rights as a data subject if the respective requirements are met.

Additional Information

If you want to exercise any of your rights, or want additional information about them, please contact us using the contact detailed listed below (see Section 15).

You have the right to lodge a complaint with the competent authority.

If you are not satisfied with the way in which we process your personal data, you may lodge a complaint with the competent data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, in addition to the rights described above.

Although this is not required, we recommend that you contact us first, as we might be able to respond to your request directly.




15. Service-Specific Information

This section of the General Privacy Notice contains the information which is specific to certain Digital Solutions and other Services. It applies in addition to the other sections of this General Privacy Notice.




16. Contact Us

If you believe your personal data has been used in a way that is not consistent with this General Privacy Notice, or if you have any questions or queries regarding the collection or processing of your personal data, please contact us at privacy@consultdss.com.




17. Updates to this General Privacy Notice

This General Privacy Notice may be subject to amendments. Any changes or additions to the processing of personal data as described in this General Privacy Notice affecting you will be communicated to you through an appropriate channel, depending on how we normally communicate with you (including by email and/or via the Digital Solutions, e.g. banners, pop-ups or other notification mechanisms). If you do not agree to the changes made, you must stop accessing and/or using the impacted Services.




Last updated: February 27, 2022