Privacy Policy

With this Pri­vacy Policy, the Swiss Industry Cyber­se­cur­ity Asso­ci­ation (SWICYBA) provides inform­a­tion about the pro­cessing of per­son­al data in con­nec­tion with our web­site under the domain name swicyba.ch.

Our web­site is a purely inform­a­tion­al web­site. It does not offer any user accounts, online shop, pay­ment, news­let­ter, com­ment func­tion or regis­tra­tion form. Accord­ingly, we pro­cess only a min­im­um of per­son­al data, as described below.

We have pre­pared this Pri­vacy Policy in Ger­man. If it is pub­lished in anoth­er lan­guage, the Ger­man-lan­guage ver­sion shall remain author­it­at­ive.

For activ­it­ies out­side this web­site — in par­tic­u­lar mem­ber­ship admin­is­tra­tion, events and asso­ci­ation cor­res­pond­ence — sep­ar­ate inform­a­tion on data pro­tec­tion applies.

1. Controller and Contact Details

The con­trol­ler with­in the mean­ing of data pro­tec­tion law is:

Swiss Industry Cyber­se­cur­ity Asso­ci­ation (SWICYBA)
4665 Oftrin­gen, Switzer­land

Email: office@swicyba.ch

Please use this address for any ques­tion relat­ing to data pro­tec­tion or to exer­cise your rights as described in sec­tion 7.

2. Applicable Law

We pro­cess per­son­al data in accord­ance with the Swiss Fed­er­al Act on Data Pro­tec­tion (FADP) and the Data Pro­tec­tion Ordin­ance (DPO). Where the EU Gen­er­al Data Pro­tec­tion Reg­u­la­tion (GDPR) applies to a spe­cif­ic pro­cessing oper­a­tion, we also com­ply with the GDPR.

Per­son­al data means any inform­a­tion relat­ing to an iden­ti­fied or iden­ti­fi­able nat­ur­al per­son. Pro­cessing means any hand­ling of per­son­al data, regard­less of the means used.

3. Personal Data We Process

Through this web­site, we pro­cess only the fol­low­ing cat­egor­ies of per­son­al data:

a) Serv­er log data. Each time our web­site is accessed, our host­ing pro­vider auto­mat­ic­ally records tech­nic­al access data: the IP address, the date and time of access, the HTTP status code, the pages retrieved and the volume of data trans­ferred, and the browser type, ver­sion and oper­at­ing sys­tem used. This data is tech­nic­ally neces­sary to deliv­er the web­site and to detect and pre­vent mis­use and attacks.

b) Con­tact by email. If you con­tact us at the email address pub­lished on our web­site, we pro­cess the data con­tained in your mes­sage (in par­tic­u­lar your name, your email address and the con­tent of your enquiry) in order to handle your request.

We do not use track­ing pixels or web beacons, we do not carry out per­form­ance or reach meas­ure­ment, we do not cre­ate user pro­files, we do not use per­son­al data for advert­ising or online mar­ket­ing, and we do not take any auto­mated indi­vidu­al decisions. We do not pro­cess sens­it­ive per­son­al data through this web­site.

4. Purposes and Legal Bases

  • Provid­ing and secur­ing the web­site (serv­er log data): our legit­im­ate interest in the per­man­ent, reli­able and secure oper­a­tion of our web­site — Art. 31 para. 1 and 2 FADP; where applic­able Art. 6 para. 1 lit. f GDPR.
  • Respond­ing to enquir­ies (email con­tact): our legit­im­ate interest in com­mu­nic­at­ing with the per­sons who con­tact us and, where rel­ev­ant, in tak­ing steps at your request pri­or to a pos­sible mem­ber­ship — Art. 31 para. 1 and 2 FADP; where applic­able Art. 6 para. 1 lit. f and lit. b GDPR.
  • Com­pli­ance with leg­al oblig­a­tions, where such oblig­a­tions apply to us — Art. 31 para. 1 FADP; where applic­able Art. 6 para. 1 lit. c GDPR.

Where we ask for your con­sent, the pro­cessing con­cerned is based on that con­sent, which you may with­draw at any time with effect for the future.

5. Cookies

Our web­site uses only tech­nic­ally neces­sary cook­ies and com­par­able stor­age in your browser, to the extent required to dis­play the site cor­rectly and to pro­tect it. These cook­ies do not serve ana­lys­is, track­ing or advert­ising pur­poses and no con­sent ban­ner is there­fore required.

You can dis­able, restrict or delete cook­ies at any time in your browser set­tings. Without cook­ies, our web­site may no longer be fully avail­able.

6. Service Providers and Disclosure of Personal Data

We do not sell per­son­al data and we do not dis­close it to third parties for their own pur­poses. We dis­close per­son­al data only:

  • to the ser­vice pro­viders lis­ted below, which pro­cess the data solely on our behalf and on our instruc­tions;
  • where we are leg­ally obliged to do so, or where it is neces­sary to estab­lish, exer­cise or defend leg­al claims.

The ser­vice pro­viders we use for this web­site are:

Infomaniak: host­ing of the web­site and the asso­ci­ated email; pro­vider: INFOMANIAK NETWORK SA, Switzer­land; the data is stored on serv­ers in Switzer­land.

Anti­s­pam Bee: spam pro­tec­tion, oper­ated on our own host­ing infra­struc­ture and without cook­ies; developers: Plu­ginkollekt­iv.

The fonts, icons and oth­er assets used on our web­site are hos­ted on our own infra­struc­ture and are not retrieved from third-party serv­ers.

7. Personal Data Abroad and Retention

Data abroad. As a gen­er­al rule, we pro­cess per­son­al data in Switzer­land. Should a trans­fer abroad become neces­sary in an indi­vidu­al case, we will only trans­fer data to a coun­try with an adequate level of data pro­tec­tion recog­nised by the Swiss Fed­er­al Coun­cil and by the European Com­mis­sion, or on the basis of appro­pri­ate safe­guards such as stand­ard con­trac­tu­al clauses, a copy of which we will provide on request.

Reten­tion. Serv­er log data is deleted or anonymised after [insert reten­tion peri­od, e.g. 6 months], unless a spe­cif­ic incid­ent requires longer reten­tion for secur­ity or evid­en­tiary pur­poses. Email cor­res­pond­ence is retained for as long as neces­sary to handle your request and there­after in accord­ance with applic­able stat­utory reten­tion and lim­it­a­tion peri­ods.

8. Data Security

We take appro­pri­ate tech­nic­al and organ­isa­tion­al meas­ures to ensure a level of data secur­ity appro­pri­ate to the risk, in par­tic­u­lar to pro­tect the con­fid­en­ti­al­ity, avail­ab­il­ity, trace­ab­il­ity and integ­rity of the per­son­al data pro­cessed. Access to our web­site is pro­tec­ted by trans­port encryp­tion (SSL / TLS, i.e. HTTPS). No secur­ity meas­ure can guar­an­tee abso­lute pro­tec­tion.

9. Your Rights

With­in the lim­its of applic­able data pro­tec­tion law, you have the right to request inform­a­tion about the per­son­al data we pro­cess about you, to have inac­cur­ate data cor­rec­ted and incom­plete data com­pleted, to request the eras­ure of your data, to request the restric­tion of pro­cessing, to object to pro­cessing based on legit­im­ate interests, to receive your data in a port­able format (data port­ab­il­ity), and to with­draw any con­sent giv­en, with effect for the future.

To exer­cise these rights, please con­tact us at office@swicyba.ch. We may ask you for inform­a­tion reas­on­ably required to veri­fy your iden­tity. We may post­pone, restrict or refuse the exer­cise of these rights to the extent per­mit­ted by law, in par­tic­u­lar where stat­utory reten­tion oblig­a­tions, con­fid­en­ti­al­ity oblig­a­tions or the pro­tec­tion of oth­er indi­vidu­als apply.

You also have the right to lodge a com­plaint with a super­vis­ory author­ity. In Switzer­land, this is the Fed­er­al Data Pro­tec­tion and Inform­a­tion Com­mis­sion­er (FDPIC). In the European Eco­nom­ic Area, you may lodge a com­plaint with the super­vis­ory author­ity of your habitu­al res­id­ence, place of work or place of the alleged infringe­ment.

10. Changes to this Privacy Policy

We may update this Pri­vacy Policy at any time. The ver­sion pub­lished on our web­site is the applic­able one.

Ver­sion of 2026.