Privacy policy Bruderer AG and E. Bruderer-Maschinenfabrik AG

Version 01, last updated: August 2024

Scope of the privacy policy

This privacy policy sets out the steps that Bruderer AG and E. Bruderer-Maschinenfabrik AG (hereinafter: "we" or "Bruderer") have taken to fulfil the data protection requirements under Swiss and EU law and other applicable laws governing the collection, storage, use and transfer ("processing") of personal data. 

In this privacy policy, we describe what we do with your information when you visit bruderer.com or other websites from us, purchase our services or products, otherwise engage with us under a contract, communicate with us or otherwise deal with us. Where appropriate, we will provide you with timely written notice of additional processing activities not mentioned in this Privacy Policy. In addition, we may inform you separately about the processing of your data, e.g. in declarations of consent, contractual terms, additional data protection declarations, forms and notices. 

If you transmit or disclose data to us about other persons such as colleagues, customers, suppliers, etc., we assume that you are authorised to do so and that this data is correct. By transmitting data about third parties, you confirm this. Please also ensure that these third parties have been informed about this privacy policy. 

We would like to point out that security gaps can occur during data transmission via the Internet, which cannot be prevented by the technical design of this website. Complete protection of personal data is not possible when using the Internet. 

The Swiss Federal Act on Data Protection ("FADP") and any additional applicable law from the European General Data Protection Regulation ("GDPR") shall apply.

Persons responsible

Bruderer AG and E. Bruderer-Maschinenfabrik AG
Egnacherstrasse 44
9320 Frasnacht
Switzerland

Tel.: +41 71 447 75 00
datenschutz@bruderer.com

Processing purpose

Personal data is any information relating to an identified or identifiable person. A data subject is a person whose personal data is processed. Processing covers any handling of personal data, regardless of the means and procedures used, in particular the retention, disclosure, obtaining, deletion, storage, modification, destruction, and use of personal data.

We process the personal data that is necessary in order to provide our service in an effective and user-friendly manner as well as on a permanent, secure, and reliable basis.

We may process personal data in the following situations and for the following purposes:

  • Communication: We may process personal data when you contact us, or when we contact you. In this case, we normally process name(s) and contact details as well as the content and time of the relevant communications. We may use this data to provide you with information, process your request, fulfil orders and instructions, process contracts and communicate with you. Messages may also be forwarded within the entire Bruderer Group.
  • Visiting websites: When you visit our website, we may automatically collect information such as your browser, the IP address of your computer, your internet service provider, the website from which you switched to our website, the duration of your visit to our website and what type of device you are using (such as a PC, smartphone or tablet and the corresponding operating system). We can then record which pages you have accessed during your visit to our website. This information may be used to improve the functioning of our website, for statistical purposes and as part of system administration. We may also use "cookies". These are small text files that are temporarily or permanently stored on your device when you visit our website. Cookies collect information about the number of visitors to the websites, the pages visited and the time spent on the websites. They are often necessary for the functionality of the website.
  • We may also use analytics services from external service providers, such as Google Analytics, which is provided by Google LLC (US). As part of these services, the service provider collects information about the use of the corresponding website, but often in a non-personally identifiable form.
  • Finally, we may use functions of service providers such as Facebook, Instagram, LinkedIn, Xing, etc., which may result in the service provider in question processing data about you. We recommend that you read the privacy policies of these external service providers.
  • Marketing: We may use your name and email address to send you notifications, updates, invitations to events and other information by email. However, we will first ask for your consent to do so, unless we have already received your contact details from you elsewhere in connection with our services. If you receive marketing communications from us and you no longer wish to receive them, you can unsubscribe at any time by following the link provided in these emails. We may use external service providers to find out whether you open our emails or click on the links they contain. You can prevent this by making the appropriate settings in your e-mail client.
  • Customer events: When we organise customer events (such as promotional events, sponsoring events, cultural events and in-house exhibitions), we may also process personal data. This data may include the name and address of participants or interested parties and - depending on the event - other data such as your date of birth. We may process this information for the purpose of organising customer events, but also to contact you and get to know you better.
  • Business partners: We work with various companies and business partners, such as suppliers, commercial customers of goods and services and service providers (e.g. IT service providers). We may process personal data about the contact persons of these companies, such as your name, function, title and nationality/residence permit. Depending on the area of activity, we may be obliged to scrutinise the company in question and/or its employees. If this is the case, we will notify you separately. We may then process personal data about you in order to improve our customer orientation, customer satisfaction and customer loyalty ("customer relationship management"), e.g. by using customer satisfaction surveys.
  • Administration: We may process personal data for our internal administration. For example, we may process personal data in connection with IT or property management. We may also process personal data for accounting and archiving purposes and generally for the review and improvement of internal processes.
  • Job applications: When you apply for a job with us, we first receive the personal data you provide in your application file. We then process this data for the purpose of checking your application, carrying out the application procedure and, if your application is successful, preparing and concluding a corresponding employment contract. In addition to the personal data you send us, we may also obtain additional publicly accessible data about you, e.g. from job-related social networks, the Internet, the media and from references, if you have voluntarily provided us with these in your application dossier and consent to us contacting you so that we can obtain the relevant references about you. Data processing in connection with any subsequent employment relationship with us is regulated in a separate internal privacy policy.
  • Protection of rights: In order to protect our rights, we may process personal data in various circumstances, for example to assert claims in or out of court or to defend claims against us. For example, we may have the prospects of litigation clarified or submit documents to an authority. In addition, authorities may oblige us to disclose documents containing personal data.

Group of persons affected

You are affected by these provisions as a customer, supplier, interested party or applicant.

Categories of personal data

  • Personal data and contact information: This includes in particular, but is not limited to, first and last name, residential address, place of residence, telephone number, e-mail address, age, date of birth, gender, marital status, family members, details of any secondary contact, photo, details of function, details of previous business dealings with these persons, details of business transactions, enquiries, offers, quotations, conditions and contracts, details of professional or other interests of the persons;
  • Data in connection with delivery and sales as well as orders and purchases: This includes in particular, but is not limited to, payment details, credit card details and other payment details, billing and delivery address, products and services delivered and sold as well as ordered and purchased;
  • Data in connection with the marketing of products and services: This includes in particular, but is not limited to, information about marketing activities such as receipt of newsletters, newsletter opt-ins and opt-outs, documents received, invitations and participation in events and special activities, personal preferences and interests, etc.;
  • Data in connection with the use of the websites: This includes in particular, but is not limited to, IP address and other identifiers (e.g. user name on social media, MAC address of the smartphone or computer, cookies, web beacons, pixel tags, log files, local shared objects (flash cookies) or other technologies that automatically collect personal data), date and time of the visit or use of the websites, pages and content accessed, referring websites, etc.;
  • Data in connection with communication: This includes in particular, but is not limited to, preferred communication channel, correspondence, correspondence language and communication with us (including keeping records of communication), etc. For e-mail traffic, the Bruderer Group uses the Microsoft Exchange Online service, which is operated in the Microsoft Azure Cloud in Western Europe. The stored contact data is therefore synchronised with the Microsoft cloud service Azure Active Directory (AAD). The data and information that must be transmitted to Bruderer Group in connection with e-mail is treated as strictly confidential. Bruderer only uses the data that is necessary for communication by e-mail. The data protection guidelines of Microsoft and Microsoft Azure can be found under the following links:

Legal basis for the processing of personal data

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and other applicable data protection laws (e.g. GDPR).

With regard to the GDPR, we process personal data based on the following principles:

  • for the performance of a contract (Art. 6, para. 1 (b) GDPR);
  • on the basis of legitimate interests (Art. 6 para. 1 (d), (f) GDPR); These include, for example, the interest in customer care and communication with customers outside of a contractual relationship, for marketing activities, to get to know our customers and other persons better, to improve and develop new products and services, to combat fraud and to prevent and investigate criminal offences, to protect customers, staff and other persons and data, secrets and the assets of the Bruderer Group, to ensure IT security, in particular in connection with the use of websites, apps and other IT system and infrastructure, to secure and organise business processes, including the operation and further development of websites and other systems, for management and further development and in the enforcement of or defence against legal claims;
  • on the basis of consent (Art. 6 para. 1 (a) and Art. 9 para. 2 (a) GDPR), if this is obtained separately, and
  • compliance with legal and regulatory obligations.

In general, you are not obliged to disclose personal data to us. However, we must collect and process certain data in order to conclude and fulfil a contract and for other purposes.

Data transmission abroad

We process and store personal data mainly and, where possible, in Switzerland and otherwise in the European Economic Area (EEA). However, it is also possible that data may be processed or transferred to any country in the world. In particular to the Bruderer Group's subsidiaries operating throughout the world.

On our website and as part of our services, we use various service providers who provide us with different technologies and tools. Some of these service providers transfer personal data to countries outside the European Union or the European Economic Area (e.g. the US, China), where there may not be an adequate level of data protection or a level of data protection that is fundamentally equivalent to Swiss or European data protection law. The associated transfer of personal data must be permitted in accordance with Art. 16 et seq. FADP or Art. 44 et seq. GDPR.

From the EU's perspective, there is an adequacy decision for the US within the meaning of Art. 45 para. 3 GDPR and Art. 16 para. 1 FADP. This means that personal data can be transferred from the EU to companies and organisations in the US that have certified themselves for the EU-U.S. Data Privacy Framework without the need for further protective measures. This adequacy decision serves as the basis for the transfer of data to the service providers we use in the US.

If there is no adequacy decision within the meaning of Art. 45 para. 3 GDPR or Art. 16 para. 1 FADP, or the company or organisation in the US has not certified itself for the EU-U.S. Data Privacy Framework, we conclude standard data protection clauses issued by the EU Commission within the meaning of Art. 46 para. 2 (c) GDPR or Art. 16 para. 2 (c) FADP with the respective service providers to protect your data. Where possible, we also agree additional guarantees to ensure that adequate data protection is guaranteed in the US or other third countries.

If a service provider maintains so-called approved Binding Corporate Rules (BCR), which ensure that the company complies with European data protection standards, we do not agree any separate standard contractual clauses with the service providers subject to the respective BCR.

Nevertheless, despite contractual and technical protective measures, the level of data protection in the third country may not correspond to that of Switzerland or the EU. In these cases, we ask for your consent in accordance with Art. 49 para. 1 (a) GDPR or Art. 17 para. 1 (a) FADP for the transfer of personal data to a third country.

Disclosure of data to third parties

(including joint controllers and data processors)

Your data will be passed on to our partners (third parties) if this is necessary for order processing. If we pass on data to external service providers, technical and organisational measures are taken to ensure that the data is passed on in accordance with the statutory data protection provisions. If you provide us with personal or company-related data of your own accord, we will not use, process or pass on this data beyond the scope permitted by law or specified by you in a declaration of consent. In addition, we will only pass on your data to external service providers if this is necessary for contract processing and they have agreed to the corresponding confidentiality and due diligence provisions. Furthermore, we only pass on your data if we are obliged to do so by law or by official or court orders.

Rights of data subjects

With regard to data protection and the processing of your personal data, you have the following rights in particular under applicable law:

  • the right to information about the processing of your personal data;
  • the right to have incorrect personal data corrected;
  • the right to request the deletion of personal data;
  • the right to object to data processing (this applies in particular to data processing for the purpose of direct marketing);
  • the right to request the disclosure of certain personal data in a commonly used electronic format or its transfer to another controller. 

If you wish to exercise one or more of the aforementioned rights against us, please contact us directly: datenschutz@bruderer.com

Stored data will be deleted by us when it is no longer required for the stated purpose.

With regard to the deletion of data, it should be noted that we are subject to certain legal obligations, which stipulate an obligation to retain certain data. We must fulfil this obligation. If you request the deletion of data that is subject to the statutory requirement to preserve records, the data will be blocked in our system and only used to fulfil the statutory requirement. After the retention period has expired, your request for deletion will be complied with.

We would like to inform you that we will ask you to identify yourself in advance (by means of your ID or passport, or a copy thereof) so that we can prevent misuse. Please note that conditions, exceptions or restrictions may apply to these rights (e.g. to protect third parties or business secrets or due to professional confidentiality obligations). We reserve the right to black out copies for reasons of data protection or confidentiality or to supply only extracts.

Cookies

We use cookies (session cookies as well as temporary and permanent cookies) on our website. These are small files that your browser automatically creates and that are stored on your end device (laptop, tablet, smartphone, etc.) when you visit our website. A cookie does not always mean that we can identify you.

Cookies are used on the one hand to record the frequency of use, number of users and behaviour on our website, to increase the security of website use and to make our information offering more user-friendly. As soon as you leave the website, these cookies are automatically deleted.

In addition, we also use temporary cookies to optimise user-friendliness, which are stored on your end device for a specified period of time. If you visit our site again to use our services, it is automatically recognised that you have already visited us and which entries and settings you have made so that you do not have to enter them again.

You can configure your browser settings so that no cookies are stored on your computer. The complete deactivation of cookies may mean that you cannot use all the functions of our website.

By continuing to use our website and/or agreeing to this privacy policy, you consent to cookies being set by us and thus to personal usage data being collected, stored and used, even beyond the end of the browser session. You can revoke this consent at any time by activating the browser setting to refuse third-party cookies.

Google Analytics

This website uses Google Analytics, a web analytics service provided by Google Ireland Ltd. ('Google'). Google Analytics uses 'cookies', which are text files placed on your computer, to help the website analyse how users use the site. The information generated by the cookie about your use of this website (including your IP address, which is anonymised before being saved using the _anonymizeIp() method so that it can no longer be assigned to a connection) is transmitted to a Google server in the US and stored there. The following data is collected: Address and title of the page visited or of downloaded files, screen resolution, browser type, browser version, browser window size, colour depth, browser language, is the Java plug-in activated or not, flash version and information about the referrer. This list may be extended by Google and only reflects the current knowledge of the analysis. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will not associate your IP address with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website. By using this website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.

You can object to the collection of data by Google Analytics with effect for the future by installing a deactivation add-on for your browser: tools.google.com/dlpage/gaoptout?hl=en

Social media plug-ins

We use the social plug-ins listed below on our website to publicise our company. The underlying advertising purpose is to be regarded as a legitimate interest within the meaning of Art. 6 para. 1 (f) GDPR. Responsibility for data protection-compliant operation must be guaranteed by the respective provider. Data processing in connection with these plug-ins takes place with your consent when you use these plug-ins.

If you use the services of these social networks independently of or in connection with our website, the social networks will analyse your use of the plug-in. In this case, information about the plug-in is forwarded to the social networks.

YouTube

Our Internet pages contain at least one plug-in from YouTube, operated by Google Ireland Limited. As soon as you visit a page of our website equipped with a YouTube plug-in, a connection to the YouTube servers is established. The YouTube server is informed which specific page of our website you have visited. If you are also logged into your YouTube account, you would enable YouTube to assign your surfing behaviour directly to your personal profile. You can prevent this assignment by logging out of your account beforehand. Further information on the collection and use of your data by YouTube can be found in the privacy policy at policies.google.com/privacy?hl=en.

Facebook / Instagram

Our website may use plug-ins from the social networks Facebook and Instagram, which are offered by Meta Platforms Ireland Ltd. The Facebook plug-ins are labelled with a Facebook logo or the addition "Like" or "Share". An overview of the Facebook plug-ins and their appearance can be found at developers.facebook.com/docs/plugins.

When you access a page on our website that contains such a plug-in, your browser establishes a direct connection to the Facebook servers. The content of the plug-in is transmitted by Facebook directly to your browser and integrated into the page.

Through this integration, Facebook receives the information that your browser has accessed the corresponding page of our website, even if you do not have a Facebook profile or are not currently logged in to Facebook. This information (including your IP address) is transmitted directly from your browser to a Facebook server in the US and stored there.

If you are logged in to Facebook, Facebook can directly associate your visit to our website with your Facebook profile. If you interact with the plug-ins, for example by clicking the "Like" button, this information is also transmitted directly to a Facebook server and stored there. The information is also published on your Facebook profile and displayed to your Facebook friends.

The purpose and scope of the data collection and the further processing and use of the data by Meta as well as your rights in this regard and setting options to protect your privacy can be found in Meta's data protection information: facebook.com/privacy/policy.

X (formerly Twitter)

Plug-ins of the short message network X Corp. may be integrated on our website. You can recognise the X plug-ins by the X logo. When you visit a page of our website that contains such a plug-in, a direct connection is established between your browser and the X server. X then receives the information that you have visited our site with your IP address. If you click on the X button while you are logged into your X account, you can link the content of our pages to your X profile. This allows X to associate your visit to our website with your user account.

We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by X. Further information on this can be found here x.com/en/privacy.

LinkedIn

Plug-ins from the social network LinkedIn Corporation, USA, may be installed on our website. You can recognise the LinkedIn plug-in ("LinkedIn Recommended" button) by the LinkedIn logo. When you visit a page on our website that contains such a plug-in, a direct connection is established between your browser and the LinkedIn server. LinkedIn receives the information that you have visited our site with your IP address. If you click on the LinkedIn button while you are logged into your LinkedIn account, you can link the content of our pages to your LinkedIn profile. This allows LinkedIn to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by LinkedIn. Further information can be found at linkedin.com/legal/privacy-policy and, if you're located in the EU, EEA, UK, or Switzerland: linkedin.com/legal/privacy/eu.

XING

Plug-ins from the social network XING SE, Germany, may be installed on our website. You can recognise the Xing plug-in ("XING" button) by the XING logo. When you visit a page of our website that contains such a plug-in, a direct connection is established between your browser and the XING server. Xing then receives the information that you have visited our site with your IP address. If you click on the XING button while you are logged into your XING account, you can link the content of our pages to your XING profile. This allows XING to associate your visit to our pages with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by XING. Further information can be found at privacy.xing.com/en/privacy-policy.

TikTok

Plug-ins from the social network TikTok, operated by Beijing Bytedance Technology Ltd., may be installed on our website. For Europe, the contact is TikTok Technology Limited Ireland, and for the UK TikTok Information Technologies UK Limited. You can recognise the TikTok plug-in by the TikTok logo. When you visit a page of our website that contains such a plug-in, a direct connection is established between your browser and the TikTok server. TikTok then receives the information that you have visited our site with your IP address.

We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by TikTok. Further information can be found at tiktok.com/legal/page/row/privacy-policy/en, where you can select your region (U.S. or EEA, UK and Switzerland, or Other regions).

Google Maps

Google Maps services are used on our website (e.g. in-screen or via interfaces / API). Google LLC, USA, may therefore process information about your actual location. Google uses various technologies to determine your location, such as IP addresses, GPS and other sensors that provide Google with information about nearby devices, Wi-Fi access points or mobile phone masts, for example.

The purpose and scope of the data collection and the further processing and use of the data by Google as well as your rights in this regard and setting options to protect your privacy can be found in Google's data protection information at policies.google.com/privacy?hl=en.

Newsletter

By registering for the newsletter and confirming receipt of the newsletter (double opt-in), the following personal data is processed: Mandatory fields: e-mail address, language. Optional fields: title, first name, company, country, sector, interests. The data is processed for the purpose of authenticating the subscriber upon registration and sending the subscriber a newsletter, determining whether and when the subscriber has opened the newsletter and individual articles in it.

The data you enter for the purpose of subscribing to the newsletter will be processed externally by Mailchimp/Mandrill. This data is processed exclusively on the basis of your consent. You can revoke this consent at any time, for example via the "unsubscribe from this list" link in the newsletter. The data processing operations that have already taken place remain unaffected by the cancellation. If we send newsletters with the help of Mailchimp/Mandrill, we can determine whether a newsletter has been opened and which links have been clicked on. Mailchimp/Mandrill allows us to categorise recipients according to different categories. You can find more information at: mailchimp.com/legal/terms/. If you do not wish to be analysed, you must unsubscribe from the newsletter.

Data security

We will store your data securely and therefore take all reasonable measures to protect your data from loss, access, misuse or alteration. Our employees and contractual partners who have access to your data are contractually obliged to maintain confidentiality and comply with data protection regulations. In some cases, it will be necessary for us to pass on your enquiries to our affiliated companies. Your data will also be treated confidentially in these cases.

Supervisory authority

Federal Data Protection and Information Commissioner, FDPIC
Feldeggweg 1
3003 Bern
Switzerland
edoeb.admin.ch/edoeb/en/home.html 

If you are in the EEA, you also have the right to lodge a complaint with the data protection supervisory authority in your country. You can find a list of authorities in the EEA here: edpb.europa.eu/about-edpb/about-edpb/members_en.

Up-to-dateness and amendment of this privacy policy

Changes to this privacy policy will be published on this page. In this way, you can find out at any time what data we store and how we collect and use it.

The current privacy policy can be found at bruderer.com/en/privacy-policy