Privacy Policy
With this Privacy Policy, the Swiss Industry Cybersecurity Association (SWICYBA) provides information about the processing of personal data in connection with our website under the domain name
Our website is a purely informational website. It does not offer any user accounts, online shop, payment, newsletter, comment function or registration form. Accordingly, we process only a minimum of personal data, as described below.
We have prepared this Privacy Policy in German. If it is published in another language, the German-language version shall remain authoritative.
For activities outside this website — in particular membership administration, events and association correspondence — separate information on data protection applies.
1. Controller and Contact Details
The controller within the meaning of data protection law is:
Swiss Industry Cybersecurity Association (SWICYBA)
4665 Oftringen, Switzerland
Email: office@swicyba.ch
Please use this address for any question relating to data protection or to exercise your rights as described in section 7.
2. Applicable Law
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and the Data Protection Ordinance (DPO). Where the EU General Data Protection Regulation (GDPR) applies to a specific processing operation, we also comply with the GDPR.
Personal data means any information relating to an identified or identifiable natural person. Processing means any handling of personal data, regardless of the means used.
3. Personal Data We Process
Through this website, we process only the following categories of personal data:
a) Server log data. Each time our website is accessed, our hosting provider automatically records technical access data: the IP address, the date and time of access, the HTTP status code, the pages retrieved and the volume of data transferred, and the browser type, version and operating system used. This data is technically necessary to deliver the website and to detect and prevent misuse and attacks.
b) Contact by email. If you contact us at the email address published on our website, we process the data contained in your message (in particular your name, your email address and the content of your enquiry) in order to handle your request.
We do not use tracking pixels or web beacons, we do not carry out performance or reach measurement, we do not create user profiles, we do not use personal data for advertising or online marketing, and we do not take any automated individual decisions. We do not process sensitive personal data through this website.
4. Purposes and Legal Bases
- Providing and securing the website (server log data): our legitimate interest in the permanent, reliable and secure operation of our website — Art. 31 para. 1 and 2 FADP; where applicable Art. 6 para. 1 lit. f GDPR.
- Responding to enquiries (email contact): our legitimate interest in communicating with the persons who contact us and, where relevant, in taking steps at your request prior to a possible membership — Art. 31 para. 1 and 2 FADP; where applicable Art. 6 para. 1 lit. f and lit. b GDPR.
- Compliance with legal obligations, where such obligations apply to us — Art. 31 para. 1 FADP; where applicable Art. 6 para. 1 lit. c GDPR.
Where we ask for your consent, the processing concerned is based on that consent, which you may withdraw at any time with effect for the future.
5. Cookies
Our website uses only technically necessary cookies and comparable storage in your browser, to the extent required to display the site correctly and to protect it. These cookies do not serve analysis, tracking or advertising purposes and no consent banner is therefore required.
You can disable, restrict or delete cookies at any time in your browser settings. Without cookies, our website may no longer be fully available.
6. Service Providers and Disclosure of Personal Data
We do not sell personal data and we do not disclose it to third parties for their own purposes. We disclose personal data only:
- to the service providers listed below, which process the data solely on our behalf and on our instructions;
- where we are legally obliged to do so, or where it is necessary to establish, exercise or defend legal claims.
The service providers we use for this website are:
Infomaniak: hosting of the website and the associated email; provider: INFOMANIAK NETWORK SA, Switzerland; the data is stored on servers in Switzerland.
Antispam Bee: spam protection, operated on our own hosting infrastructure and without cookies; developers: Pluginkollektiv.
The fonts, icons and other assets used on our website are hosted on our own infrastructure and are not retrieved from third-party servers.
7. Personal Data Abroad and Retention
Data abroad. As a general rule, we process personal data in Switzerland. Should a transfer abroad become necessary in an individual case, we will only transfer data to a country with an adequate level of data protection recognised by the Swiss Federal Council and by the European Commission, or on the basis of appropriate safeguards such as standard contractual clauses, a copy of which we will provide on request.
Retention. Server log data is deleted or anonymised after [insert retention period, e.g. 6 months], unless a specific incident requires longer retention for security or evidentiary purposes. Email correspondence is retained for as long as necessary to handle your request and thereafter in accordance with applicable statutory retention and limitation periods.
8. Data Security
We take appropriate technical and organisational measures to ensure a level of data security appropriate to the risk, in particular to protect the confidentiality, availability, traceability and integrity of the personal data processed. Access to our website is protected by transport encryption (SSL / TLS, i.e. HTTPS). No security measure can guarantee absolute protection.
9. Your Rights
Within the limits of applicable data protection law, you have the right to request information about the personal data we process about you, to have inaccurate data corrected and incomplete data completed, to request the erasure of your data, to request the restriction of processing, to object to processing based on legitimate interests, to receive your data in a portable format (data portability), and to withdraw any consent given, with effect for the future.
To exercise these rights, please contact us at office@swicyba.ch. We may ask you for information reasonably required to verify your identity. We may postpone, restrict or refuse the exercise of these rights to the extent permitted by law, in particular where statutory retention obligations, confidentiality obligations or the protection of other individuals apply.
You also have the right to lodge a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC). In the European Economic Area, you may lodge a complaint with the supervisory authority of your habitual residence, place of work or place of the alleged infringement.
10. Changes to this Privacy Policy
We may update this Privacy Policy at any time. The version published on our website is the applicable one.
Version of 2026.
