Privacy policy
Contact details of the responsible person:
SECURIX AG
Aarburgerstrasse 7
4600 Olten
E-Mail: datenschutz@securix.swiss
Controller and Contact
The controller responsible for the processing of personal data collected on this website is SECURIX AG, Aarburgerstrasse 7, 4600 Olten, Switzerland (“we”, “us”). You can contact us with any questions relating to data protection at datenschutz@securix.swiss.
The controller within the meaning of the Swiss Federal Act on Data Protection is SECURIX AG. Where the EU General Data Protection Regulation (GDPR) applies in an individual case, SECURIX AG is also the controller within the meaning of Art. 4(7) GDPR.
Scope of this Privacy Notice
This Privacy Notice applies to the website available at www.securix.swiss, including subpages such as the Careers page, as well as to the blog available at blog.securix.swiss. Where the processing differs from a technical or legal perspective, this is specified separately in the relevant sections.
General Principles of Data Processing
Personal data means any information relating to an identified or identifiable individual. Processing includes any operation performed on personal data, in particular the collection, storage, alteration, disclosure, retention and deletion of personal data.
We process personal data in accordance with the principles of good faith, proportionality, purpose limitation and transparency. We collect only the data necessary for the respective purposes and retain such data only for as long as required for the relevant purpose or by statutory retention obligations.
Legal Bases
Swiss Data Protection Law
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP), in the version in force since 1 September 2023 (“revised FADP”), as well as the associated ordinances, in particular the Data Protection Ordinance (DPO).
EU General Data Protection Regulation
Where the GDPR applies, we base the processing on the following legal bases pursuant to Art. 6(1) GDPR:
- a: Consent of the data subject, e.g. for non-essential cookies and the services described in Sections 8–11
- b: Performance of a contract or steps taken at the request of the data subject prior to entering into a contract, e.g. the contact form
- c: Compliance with a legal obligation
- f: Legitimate interests, e.g. the operation, security and further development of the website, provided that these interests are not overridden by the fundamental rights of the data subject
Collection of Data When Visiting the Website (Server Log Files)
When you access our website, the web server automatically collects technical information transmitted by your browser: IP address, date and time of the request, page accessed, referring URL, browser used and operating system. This data is temporarily stored in log files and subsequently deleted automatically.
Purpose: To ensure the technically error-free provision of the website as well as system security and stability.
Legal basis: Art. 31 para. 1 FADP or Art. 6(1)(f) GDPR (legitimate interest in secure operation).
Contact Form
If you use our contact form, we process the information you provide, including at least your email address and any additional information provided voluntarily, solely for the purpose of handling your enquiry.
The data will be deleted once your enquiry has been fully processed, unless statutory retention obligations require otherwise.
Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract) or your consent.
The form is technically provided through HubSpot; see Section 9.
Cookies and Consent Management
General Information
We use cookies and comparable technologies on our website and blog. A distinction is made between technically necessary cookies, e.g. cookies required for the basic functionality of the website, and non-essential cookies used for statistics, marketing or social media purposes.
Consent Banner and Google Consent Mode
When you first visit our website, a cookie banner appears, technically provided through HubSpot, which allows you to grant or refuse consent by category.
Until you actively make a choice, all non-essential categories are disabled by default (“Privacy by Default”). This is implemented through Google Consent Mode v2, with the default values analytics_storage, ad_storage, ad_user_data and ad_personalization set to “denied” for visitors from Switzerland, the EEA and the United Kingdom.
The non-essential services described in Sections 8–11 — Google Analytics 4, HubSpot marketing cookies, YouTube embeds and the social media plugins on the blog — are technically loaded only after you have consented to the relevant category.
Withdrawal of Consent
You may withdraw consent previously given at any time with effect for the future by reopening the cookie settings through the corresponding link in the website footer and adjusting your selections.
Google Analytics 4
We use Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA), to statistically analyse the use of our website.
The information collected includes, among other things, pages accessed, time spent on the website, approximate location (country/city), technical device information and the source from which the website was accessed. The IP address is truncated before being stored (IP anonymisation).
Google Analytics 4 is loaded only after you have consented to the “Statistics” category in the cookie banner.
Legal basis: Your consent pursuant to Art. 6(1)(a) GDPR or Art. 31 para. 1 FADP.
Retention period: User-related event data is automatically deleted after 14 months. Aggregated, non-personal analyses may be retained indefinitely.
Transfers to third countries: Data is also processed on servers in the USA. Google Ireland Limited and/or Google LLC is certified under the EU-U.S. Data Privacy Framework. Transfers from Switzerland are additionally covered by the Swiss-U.S. Data Privacy Framework, which has been in force since 15 September 2024 and ensures an adequate level of data protection within the meaning of Art. 16 FADP.
You may withdraw your consent at any time through the cookie settings. Alternatively, you may use the browser add-on for deactivating Google Analytics:
https://tools.google.com/dlpage/gaoptout
HubSpot (CRM, Marketing, Forms and Blog Hosting)
We use the platform provided by HubSpot Ireland Limited, HubSpot House, 1 Sir John Rogerson’s Quay, Dublin 2, D02 CR67, Ireland (parent company: HubSpot, Inc., USA) for various purposes.
Form Functionality
The technical provision of our contact form, see Section 6, is provided through HubSpot. This functionality is necessary for the operation of the form and is loaded irrespective of your cookie consent.
Marketing and Tracking Cookies
For lead tracking, email marketing and the assignment of form responses to contact profiles, HubSpot uses additional cookies, including hubspotutk, __hstc and __hssc.
These cookies are non-essential and are loaded only after you have consented to the “Statistics”/“Marketing” category.
Retention period: Up to 13 months (HubSpot default).
Transfers to Third Countries
We have entered into a Data Processing Agreement with HubSpot. Transfers of data to the USA are based on Standard Contractual Clauses or, insofar as HubSpot is certified accordingly, on the EU-U.S. or Swiss-U.S. Data Privacy Framework.
YouTube Embeds
On individual pages, such as the Careers page, we embed videos from the YouTube platform (provider: Google Ireland Limited; see Section 8).
The videos are embedded using YouTube’s enhanced privacy mode or behind a preview image. A connection to YouTube/Google servers is established only when you actively click on the video. At that point, cookies may be set and usage data, including your IP address, may be transmitted to Google.
Legal basis: Your consent pursuant to Art. 6(1)(a) GDPR.
Subsequent processing of data by Google is subject to Google’s Privacy Policy:
https://policies.google.com/privacy
Transfers of data to the USA are based on the EU-U.S. or Swiss-U.S. Data Privacy Framework.
Social Media Links and Plugins
Links on the Main Website (securix.swiss)
In the footer of our main website, we provide a link to our LinkedIn company profile:
https://www.linkedin.com/company/securix-ag
This is a simple hyperlink. Merely visiting our website does not result in any data being transmitted to LinkedIn. Only when you click the link do you leave our website, at which point LinkedIn’s privacy policy applies.
Social Plugins on the Blog (blog.securix.swiss)
On our blog, we use plugins provided by the following providers to display “Follow” and “Share” functionality:
- Facebook — Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
- LinkedIn — LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland
- X/Twitter — X Corp., USA
These plugins load the respective providers’ scripts directly from their servers. In doing so, your IP address and device information may be transmitted to the providers even if you do not have an account with the respective service.
The plugins are loaded only after you have consented to the “Marketing/Social Media” category in the cookie banner.
Legal basis: Your consent pursuant to Art. 6(1)(a) GDPR.
Transfers of data to the USA are based on Standard Contractual Clauses or, where the relevant provider is certified, on the applicable Data Privacy Framework.
Further information:
- Meta: https://www.facebook.com/privacy/policy/
- LinkedIn: https://www.linkedin.com/legal/privacy-policy
- X: https://twitter.com/en/privacy
Fonts Used
We exclusively use self-hosted fonts on our website. Accordingly, no connection is established with external font providers such as Google Fonts or Adobe Fonts for this purpose.
An exception may arise in connection with an embedded YouTube video; see Section 10. Following your consent, the YouTube player may load its own fonts from Google servers. This takes place outside our sphere of influence.
TLS Encryption
To protect the transmission of confidential content, such as information submitted through forms, our website uses TLS encryption.
You can recognise an encrypted connection by the https:// prefix and the padlock symbol in your browser’s address bar.
Overview of Services Used
The following table summarises the services described above. The respective sections above govern in relation to further details.
| Service | Provider | Category | Legal Basis | Country / Third-Country Basis | Retention Period |
|---|---|---|---|---|---|
| Server log files | SECURIX AG / Hosting Provider | Necessary | Art. 31 FADP / Art. 6(1)(f) GDPR | Switzerland | Short-term; automatically deleted |
| Contact form (form functionality) | HubSpot Ireland Ltd. | Necessary | Art. 6(1)(b) GDPR | USA (SCC / DPF) | Until the enquiry has been resolved |
| Google Analytics 4 | Google Ireland Ltd. | Statistics | Consent, Art. 6(1)(a) GDPR | USA (EU-U.S. / Swiss-U.S. DPF) | 14 months |
HubSpot Marketing Cookies (hubspotutk, __hstc, etc.) |
HubSpot Ireland Ltd. | Marketing | Consent, Art. 6(1)(a) GDPR | USA (SCC / DPF) | Up to 13 months |
| YouTube embeds | Google Ireland Ltd. | Marketing | Consent, Art. 6(1)(a) GDPR | USA (EU-U.S. / Swiss-U.S. DPF) | Session-related |
| Facebook Social Plugin (Blog) | Meta Platforms Ireland Ltd. | Marketing | Consent, Art. 6(1)(a) GDPR | USA (SCC) | In accordance with Meta’s policies |
| LinkedIn Widget (Blog) | LinkedIn Ireland Unlimited Company | Marketing | Consent, Art. 6(1)(a) GDPR | USA (SCC) | In accordance with LinkedIn’s policies |
| X/Twitter Widget (Blog) | X Corp. | Marketing | Consent, Art. 6(1)(a) GDPR | USA | In accordance with X’s policies |
Disclosure of Personal Data to Third Parties
Your personal data is disclosed to third parties only within the scope of the data processing arrangements described in this Privacy Notice, see Sections 8–11, on the basis of your express consent, for the purpose of complying with a legal obligation, or where such disclosure is necessary for the establishment, exercise or defence of legal claims.
International Data Transfers
Certain services we use process data, including in the USA; see the overview in Section 14.
Depending on the provider, we rely for such transfers on an adequacy decision — the EU-U.S. Data Privacy Framework in force since 10 July 2023 or the Swiss-U.S. Data Privacy Framework in force since 15 September 2024 — or on Standard Contractual Clauses recognised by the European Commission or the Swiss Federal Data Protection and Information Commissioner (FDPIC).
Retention Period
We process personal data only for as long as necessary for the respective purpose.
Where statutory retention obligations apply, we restrict processing accordingly once the original purpose has been fulfilled.
Specific retention periods for individual services are set out in Sections 8–11 and in the overview in Section 14.
Rights of Data Subjects
Under the FADP and, where applicable, the GDPR, you have the following rights:
- Right of access: The right to obtain information about the personal data we process, the purposes of processing, the categories of personal data and the recipients
- Right to rectification: The right to have inaccurate personal data corrected or incomplete personal data completed
- Right to erasure: The right to have your personal data deleted unless statutory retention obligations or overriding interests prevent deletion
- Right to restriction of processing
- Right to data portability: The right to receive the data you have provided in a commonly used, machine-readable format
- Right to object to processing based on a legitimate interest
- Right to withdraw consent: The right to withdraw consent previously given at any time with effect for the future
To exercise any of these rights, it is sufficient to send an informal request to:
Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority.
In Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern:
Data subjects residing in the EU may additionally lodge a complaint with the data protection supervisory authority at their habitual place of residence.
Data Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or intentional manipulation, loss, destruction or unauthorised access.
Our security measures are continuously reviewed and improved in line with technological developments.
Amendments to this Privacy Notice
We amend this Privacy Notice whenever this becomes necessary due to the further development of our website, changes to the services we use or changes in applicable legal requirements.
The version of the Privacy Notice available on the website at the time of your visit shall apply.
Whistleblowing
Prevention and Combating of Corruption
At SECURIX, it is important to us that our employees are able to work in a safe, fair and transparent environment.
We encourage everyone — including employees, customers, suppliers and other stakeholders — to contact us if they suspect inappropriate activities or misconduct within any SECURIX company.
All reports are treated confidentially, and the whistleblower remains anonymous throughout the entire process.
How can I submit an anonymous report?
You can submit your report easily and securely by following the instructions in the form.
After submitting your report, an ID and password will be displayed on the screen. Please store these securely. You will remain anonymous throughout this dialogue.
If you become aware of potential data protection breaches or other violations, we encourage you to report them without delay. Please use our secure online form, which allows you to submit reports anonymously.
Anonymity and Protection Against Retaliation
We take the protection of whistleblowers seriously and ensure that your identity is treated confidentially.
We expressly prohibit any form of retaliation against individuals who report violations in good faith.
Processing and Investigation
All reported violations are carefully investigated, and appropriate measures are taken to remedy the issue and prevent future violations.
The whistleblowing service is provided by an external partner, WhistleB, Whistleblowing Centre, in order to ensure anonymity. The communication channel is encrypted and password-protected.
Your cooperation in maintaining our high data protection standards is important to us. Thank you for helping us keep our community safe and uphold high ethical standards.
Whistleblowing portal:
https://report.whistleb.com/en/message/securix
Use of AI-Powered Meeting Assistance Tools
We may use AI-supported tools and digital applications in connection with meetings held while providing our services and conducting our business activities. Depending on the AI tool used and the nature of the meeting, this may include the preparation of meeting minutes, summaries, transcriptions, action points and follow-up actions, as well as the recording and transcription of meetings and the processing of audio, video and voice data. We use these tools solely to facilitate the follow-up of meeting outcomes, support project management, ensure internal quality assurance and provide our services more efficiently. Unless expressly stated otherwise, information processed through these tools is not used to train publicly available AI models.
Where we use AI service providers to process personal data on our behalf, including outside Switzerland, we implement appropriate contractual, technical and organisational safeguards in accordance with the applicable data protection legislation. This includes, where appropriate, access controls, confidentiality measures, data security safeguards, retention and deletion measures and safeguards relating to international data transfers.
Where meetings are recorded and/or transcribed using AI-powered tools, we will inform you in advance of the intended processing, including the purpose of the recording and/or transcription, and obtain your consent before any recording or AI-assisted transcription begins. If you choose not to provide your consent, the meeting will proceed without the use of AI-powered recording and/or transcription tools.
Unless otherwise specified in this section, the provisions of this Privacy Notice relating to the recipients of personal data, international transfers (where applicable), retention of personal data and your rights apply equally to the processing activities described above.
This document was updated on 14.08.2026