Effective date: October 1st, 2025
1. Controller
i2impact AG
Vorackerrain 3, 3073 Gümligen, Switzerland
Email: [email protected]
2. Scope and Purpose
This Privacy Policy explains how we process personal data when you use our website, in accordance with the Swiss Federal Act on Data Protection (revDSG) and, where applicable, the EU General Data Protection Regulation (GDPR).
3. Data We Collect
| Category | Examples | Purpose / Legal basis |
|---|---|---|
| Contact information | Name, email address, message content (from contact form) | To respond to your inquiries; legitimate interest (Art. 6 para. 1 lit. f GDPR / Art. 31 revDSG) or consent if required |
| Technical information | IP address, browser type, operating system, time of access | Website operation and security; legitimate interest |
| Cookies | Session cookies and functional cookies only | To ensure website functionality and improve user experience |
We do not use analytics, tracking, or advertising cookies.
4. Cookies
We use only technically necessary cookies that enable basic website functions (e.g. language preference, form submission).
You can control or delete cookies in your browser settings at any time. Disabling cookies may limit certain website features.
5. Disclosure to Third Parties
We share personal data only when:
- it is required to operate our website (e.g. hosting provider, email service);
- you have given consent;
- it is legally required; or
- we have a legitimate interest that does not override your rights.
If data is transferred abroad (e.g. to the EU or other countries), we ensure an adequate level of data protection through recognised safeguards such as Standard Contractual Clauses or adequacy decisions by the Swiss FDPIC or EU Commission.
6. Storage Period
Personal data are retained only as long as necessary for the stated purposes or as required by law. Afterwards, the data are securely deleted or anonymised.
7. Data Security
We apply appropriate technical and organisational measures (e.g. encryption, access controls) to protect your data against unauthorised access, loss, or misuse.
In the event of a data breach likely to result in a high risk to your rights and freedoms, we will notify the competent authority in accordance with revDSG and GDPR.
8. Your Rights
Depending on applicable law, you may exercise the following rights:
- Access to your personal data
- Rectification of inaccurate data
- Erasure (“right to be forgotten”)
- Restriction of processing
- Data portability
- Objection to processing
- Withdrawal of consent (where processing is based on consent)
- Right to lodge a complaint with a supervisory authority
To exercise your rights, please contact us using the details above.
9. Updates to This Policy
We may update this Privacy Policy from time to time to reflect legal or operational changes. The current version is published on this website. Significant updates will be communicated where appropriate.
10. Supervisory Authority
For Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC).
If the GDPR applies to you, you may also contact your local EU data protection authority.