Privacy policy
This privacy policy provides information on the processing of personal data in connection with our activities and operations, including our website at the domain name www.fluechtlingshilfe.ch. In particular, we provide information on which personal data we process, for what purpose, in which manner and at which location. We also provide information on the rights of individuals whose data we process.
We have drafted this privacy policy in the German language. If this privacy policy should be published in another language, the German-language version shall remain the authentic text.
We may publish further privacy policies or other information on data protection for individual or additional activities and operations.
We are subject to Swiss law and, where applicable, to foreign law, such as in particular that of the European Union (EU) with the European General Data Protection Regulation (GDPR).
In its decision of 26 July 2000the European Commission acknowledged that Swiss data protection law ensures an adequate level of data protection. The European Commission confirmed this adequacy decision in its report dated 15 January 2024.
1. Contact addresses
The following organization is the controller for data protection purposes:
Swiss Refugee Council, SRC
Weyermannsstrasse 10
P.O. Box
3001 Bern
Switzerland
Third parties may act as controllers for the processing of personal data in individual cases, or else third parties may be joint data controllers. We will be pleased to provide data subjects with information on the respective responsibility upon request.
Data Protection Officer and/or Data Protection Adviser
We have appointed the following Data Protection Officer or Data Protection Adviser as the contact point for data subjects and authorities in the event of inquiries relating to data protection:
Thomas Rudin
Swiss Refugee Council SRC
Weyermannsstrasse 10
P.O. Box
3001 Bern
dataprotection@fluechtlingshilfe.ch
2. Definitions and legal bases
2.1 Definitions
Data subject: a natural person about whom we process personal data.
Personal data: all details relating to an identified or identifiable natural person.
Personal data requiring special protection: data relating to trade union, political, religious or philosophical views and activities; data relating to health, privacy or membership of an ethnic or racial group; genetic data; biometric data that uniquely identifies a natural person; data relating to criminal and administrative sanctions or proceedings; and data relating to social welfare measures.
Processing: any handling of personal data, regardless of the means and procedures employed, for example, the retrieval, comparison, adaptation, archiving, storage, reading out, disclosure, acquisition, recording, collection, deletion, publication, classification, organization, saving, alteration, dissemination, linking, destruction and use of personal data.
European Economic Area (EEA): Member States of the European Union (EU) as well as the Principality of Liechtenstein, Iceland and Norway.
2.2 Legal bases
We process personal data in accordance with Swiss law, such as in particular the Federal Act on Data Protection (Data Protection Act, DSG) and the Ordinance on Data Protection (Data Protection Ordinance, DSV).
Where and to the extent that the European General Data Protection Regulation (GDPR) is applicable, we process person-specific or personal data in accordance with at least one of the following legal bases:
- Art. 6 para. 1 b) of the GDPR for the processing of personal data that is necessary for the performance of a contract with the data subject and for the implementation of measures prior to entering into a contract.
- Art. 6 para. 1 f) of the GDPR for the processing of personal data that is necessary to safeguard legitimate interests – including the legitimate interests of thirdparties – unless the fundamental freedoms and rights, as well as the interests, of the data subject, are overridden. Such interests are, in particular, the sustained, user-friendly, secure and reliable conduct of our activities and operations; ensuring information security; protection against misuse; the enforcement of our own legal claims; and compliance with Swiss law.
- Art. 6 para. 1 c) of the GDPR for the processing of personal data that isnecessary to comply with a legal obligation to which we are subject under the law of Member States that may be applicable inthe European Economic Area (EEA).
- Art. 6 para. 1 e) of the GDPR for the processing of personal data that is necessary for the performance of a task that is in the public interest.
- Art. 6 para. 1 a) of the GDPR for the processing of personal data with the consent of the data subject.
- Art. 6 para. 1 d) of the GDPR for the processing of personal data that is necessary to protect vital interests of the data subject or of another natural person.
- Art. 9 para. 2 seq. of the GDPR for the processing of special categories of personal data, in particular with the consent of the data subjects.
The European General Data Protection Regulation (GDPR) defines the processing of personal data as the processing of person-related data and the processing of personal data requiring special protection as the processing of special categories of personal data (Art. 9 GDPR).
3. Nature, scope and purpose of the processing of personal data
We process the personal data that is necessary to enable us to carry out our activities and operations in a sustainable, user-friendly, secure and reliable manner. The personal data processed may come under the following categories in particular: browser and device data, content data, communication data, metadata, usage data, master data including customer and contact details, location data, transaction data, contractual data and payment data. The personal data may also constitute categories of personal data requiring special protection.
We also process personal data that we receive from third parties, obtain from publicly accessible sources or collect in the course of our activities and operations, insofar as such processing is permitted.
We process personal data, where necessary, with the consent of the data subjects. In many cases, we may process personal data without consent, for example in order to comply with legal obligations or to safeguard overriding interests. We may also seek the consent of data subjects even when their consent is not required.
We process personal data for as long as it is necessary for the respective purpose. We anonymize or delete personal data, in particular in accordance with statutory storage and limitation periods.
4. Disclosure of personal data
We may disclose personal data to third parties, have it processed by third parties, or process it jointly with third parties. Such third parties may, for example, be specialist service providers whose services we use. Such third parties may, in turn, disclose personal data to other third parties.
In the course of our activities and operations, we may disclose personal data in particular to banks and other financial service providers, public authorities, educational and research institutions, consultants and attorneys-at-law, accountancy and fiduciary service providers, debt collection agencies, interest groups, IT service providers, cooperation partners, credit and business information agencies, logistics and shipping companies, marketing and advertising agencies, media organizations, parent companies, sister companies and subsidiaries, organizations and associations, social welfare institutions, telecommunications and insurance companies and payment service providers.
5. Communication
We process personal data in order to be able to communicate with individuals, as well as with public authorities, organizations and companies. In doing so, we process in particular data provided to us by a data subject when they contact us, for example by post or e-mail. We may store such data in an address book or by using comparable tools.
Third parties who transfer to us data relating to other individuals are legally obliged to ensure the data protection of those data subjects by themselves. In particular, they must ensure that they are authorized to provide such data but they must also guarantee the accuracy of the data transferred.
We use selected services from suitable providers to make possible, and improve, communication with individuals and other communication partners. When using such services, we may also manage, and otherwise process, the data of the data subjects beyond the scope of direct communication, for example in connection with orders, services, projects and resource planning.
We use in particular:
- Jira Service Management: customer service; providers: Atlassian Pty Ltd (Australia) / Atlassian Inc. (USA); data protection information: Privacy Policy, Cookie and Tracking Policy.
6. Data security
We take appropriate technical and organizational measures to ensure a level of data security commensurate with the respective risk. With our measures, we ensure, in particular, the confidentiality, availability, traceability and integrity of the personal data processed, although we cannot guarantee absolute data security.
Access to our website and our other digital presence is secured by means of transport encryption (SSL / TLS, in particular by using the Hypertext Transfer Protocol Secure, abbreviated to HTTPS). Most browsers issue a warning before a user visits a website without transport encryption.
Our digital communications – like any digital communications in general – are subject to mass surveillance without reason or suspicion by security authorities in Switzerland, the rest of Europe, the United States of America (USA) and in other countries. We cannot exert any direct influence over the corresponding processing of personal data by intelligence services, police forces and other security authorities. Nor can we rule out the possibility that a data subject may be specifically monitored.
7. Personal data abroad
As a general rule, we process personal data in Switzerland and within the European Economic Area (EEA). However, we may also export or transfer personal data to other countries, in particular for the purpose of processing it, or having it processed, there. We may export personal data to any country on the Earth and elsewhere in the Universe, provided that the law there guarantees an adequate level of data protection in accordance with a decision of the Swiss Federal Council and – where and to the extent that the General Data Protection Regulation (GDPR) is applicable – also in accordance with a decision of the European Commission.
We may transfer personal data to countries whose laws do not guarantee an adequate level of data protection, provided that data protection is guaranteed on other grounds, in particular on the basis of standard data protection clauses or with other suitable guarantees.
In exceptional cases, we may export personal data to countries without adequate or appropriate data protection if the specific data protection requirements to do so are met, for example, the explicit consent of the data subjects or a direct connection with the conclusion or performance of a contract. We are pleased to provide data subjects, upon request, with information on any such guarantees or to provide a copy of any guarantees.
8. Rights of data subjects
8.1 Data protection claims
We grant data subjects all claims in accordance with the applicable law. Data subjects have the following rights in particular:
- Information: data subjects may request information as to whether we process personal data on them and, if so, which personal data is involved. In addition, data subjects shall receive the information necessary to exercise their data protection claims and to ensure transparency. This includes the processed personal data as such, but also, among other things, details of the purpose of processing, the duration of storage, any disclosure or any export of data to other countries and the origin of the personal data.
- Rectification and restriction: data subjects may have incorrect personal data rectified, incomplete data completed, and the processing of their data restricted.
- Possibility of expressing one’s own views and review by a human being: data subjects may express their own point of view, and request a review by a human being, in the case of decisions based solely on automated processing of personal data and which have legal consequences for them or which are significantly detrimental to them (automated individual decisions).
- Deletion and opposition: data subjects may request that personal data be deleted (“right to be forgotten”) and oppose the processing of their data with effect for the future.
- Data disclosure and data transfer: data subjects may request the disclosure of personal data or the transfer of their data to another data controller.
We may defer, restrict or refuse the exercise of data subjects’ rights within the limits permitted by law. We may inform data subjects of any prerequisites that must be met in order for them to exercise their data protection claims. For example, we may refuse to provide information, in whole or in part, on the grounds of confidentiality obligations, overriding interests or the protection of other individuals. We may also, for example, refuse to delete personal data, in whole or in part, in particular on the grounds of statutory storage obligations.
In exceptional cases, we may charge a fee for the exercise of these rights. We will inform data subjects in advance of any such costs.
We are obliged to take appropriate measures to identify data subjects who request information or exercise other rights. Data subjects are obliged to cooperate.
8.2 Legal protection
Data subjects have the right to enforce their data protection claims through the law courts or to file a report to, or lodge a complaint with, a data protection supervisory authority.
The data protection supervisory authority for private data controllers and federal bodies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).
The European data protection supervisory authorities are organized as Members of the European Data Protection Board (EDPB). In some Member States of the European Economic Area (EEA), the data protection supervisory authoritieshave a federal structure, particularly in Germany.
9. Using the website
9.1 Cookies
We may use cookies. Cookies – both our own cookies (first-party cookies) and those from third parties whose services we use (third-party cookies) – are data that are stored in the browser. Such stored data do not have to be limited to traditional, text-based cookies.
Cookies can be stored temporarily in the browser as “session cookies” or for a specific period of time as so-called persistent cookies. “Session cookies” are automatically deleted when the browser is closed. Persistent cookies have a specific storage period. Cookies enable us in particular to recognize a browser the next time it visits our website and thereby, for example, to measure the reach of our website.
Cookies can be disabled, restricted or deleted, either fully or partially, at any time in the browser settings. The browser settings often also allow for automated deletion of cookies and other ways of managing them. Without cookies, our website may at best no longer be available in its full scope. We actively request your explicit consent to the use of cookies – at least to the extent required by the applicable law.
For cookies used to measure performance and reach, or for advertising purposes, a general opt-out is possible for many services via AdChoices (Digital Advertising Alliance of Canada), the Network Advertising Initiative (NAI), YourAd-Choices (Digital Advertising Alliance)or Your Online Choices (European Interactive Digital Advertising Alliance, EDAA).
9.2 Logging
For every visit to our website and for our other digital presence, we may log at least the following details, provided that they are collected or transferred as a standard operation during such access to our digital infrastructure: date and time, including time zone; IP address; access status (HTTP status code); operating system, including user interface and version; browser, including language and version; individual subpages of our website viewed, including the volume of data transferred; the last webpage viewed in the same browser window (referer or referrer) .
We log such details, which may also constitute personal data, in log files. These details are necessary to enable us to provide our digital presence in a sustainable, user-friendly and reliable manner. The details are also necessary to be able to ensure data security – including through third parties or with the assistance of third parties.
9.3 Web beacons
We may incorporate tracking pixels into our digital presence. Tracking pixels are also known as web beacons. Web beacons – including those from third parties whose services we use – are usually small, invisible images or scripts written in JavaScript that are automatically retrieved when our digital presence is accessed. Web beacons can be used to collect at least the same details as those logged in log files.
10. Notifications and communications
10.1 Performance and Reach Measurement
Notifications and communications may contain web links or tracking pixels that record whether an individual communication has been opened and which web links were clicked on in doing so. Such web links and web beacons may also track the use of notifications and communications on a personal basis. We need this statistical tracking of usage to measure performance and reach, so that we can send notifications and communications in a way that is effective, user-friendly, sustainable, secure and reliable, based on the recipients’ needs and reading habits.
10.2 Consent and objection
You must, as a genera l rule, consent to the use of your e-mail address and your other contact details, unless such use is permitted on other legal grounds. We may use the “double opt-in” procedure to obtain double-confirmed consent where this is necessary. In this case, you will receive a message containing instructions for double confirmation. We may log the consents obtained, including the IP addressand time-stamp, for proof and security reasons.
You may, as a general rule, object at any time to receiving notifications and communications, such as newsletters. By submitting such an objection, you may at the same time object to the statistical recording of your usage for performance and reach measurement purposes. This is without prejudice to any notifications and communications that may be necessary in connection with our activities and operations.
10.3 Service Providers for notifications and communications
We send out notifications and communications with the help of specialist service providers.
We use in particular:
- ActiveCampaign: a marketing-automation platform, specializing in e-mail marketing; provider ActiveCampaign LLC (USA); data protection information: Privacy policy.
11. Social Media
We are present on social media platforms and other online platforms in order to be able to communicate with interested parties and to provide information about our activities and operations. Personal data may also be processed outside of Switzerland and the European Economic Area (EEA) in connection with such platforms.
The General Terms and Conditions (GTC) and the Terms of Use, as well as the privacy policies and other provisions of the individual operators of such platforms, shall also apply in each case. These provisions provide information on, in particular, the rights of data subjects in their direct dealings with the respective platform, including, for example, the right to information.
We are joint controllers, together with Meta Platforms Ireland Limited (Ireland) for our social media presence on Facebook, including what are known as Page In-sights – insofar as the General Data Protection Regulation (GDPR) is applicable. Meta Platforms Ireland Limited is part of the Meta group of companies (inter alia, in the USA). Page Insights provide information on how visitors interact with our Facebook presence. We use Page Insights to be able to provide a social media presence on Facebook that is effective and user-friendly.
Further details on the nature, scope and purpose of data processing information on data subjects’ rights, and the contact details of Facebook and Facebook’s Data Protection Officer can be found in Facebook’s Privacy Policy. We have entered into the so-called “Controller Addendum” with Facebook and have thereby specifically agreed that Facebook is responsible for ensuring data subjects’ rights. For what are known as Page Insights, the relevant information can be found on the “Information about Page Insights”page, including “Information about Page Insights Data”.
12. Third-party services
We use services provided by specialist third parties to be able to conduct our activities and operations in a sustainable, user-friendly, secure and reliable manner. These services enable us to embed functions and content into our website, among other things. When such embedding takes place, the services utilized collect users’ IP addresses, at least temporarily, for technically essential reasons.
Third parties whose services we use may process data relating to our activities and operations in an aggregated, anonymised or pseudonymised form for necessary security-related, statistical and technical purposes. The data concerned is, for example, performance or usage data required to be able to provide the service concerned.
We use in particular:
- Googleservices:Providers: Google LLC (USA) / Google Ireland Limited (Ireland), in some cases for users in the European Economic Area (EEA) and Switzerland; General information on data protection: “Managing Data Protection”, Privacy Policy, “Learn more about how Google processes personal information”, “Google is committed to complying with the applicable data protection laws”, “Google Product Privacy Guide” , ”How Google uses information from sites or apps that use our services”, Cookies policy, “Advertising you can control” (personalized advertising settings).
- Microsoſtservices:Providers: Microsoft Ireland Operations Limited (Ireland) for users in the European Economic Area (EEA), Switzerland and the United Kingdom / Microsoft Corporation (USA) for users in the rest of the world; General information on data protection: “Privacy at Microsoft”, “Data protection and privacy”, Privacy Policy, “Data protection and privacy settings”.
12.1 Digital infrastructure
We use services provided by specialist third parties to be able to use the digital infrastructure required in connection with our activities and operations. They include, for example, hosting and storage services from selected providers.
We use in particular:
- Cyon: hosting; provider: Cyon AG (Switzerland); information on data protection: ”Data Protection”, Privacy Policy.
- Nine Internet Solutions: Managed cloud and container solutions; provider: Nine Internet Solutions AG (Switzerland); Information on data protection: Privacy Policy, “Our Commitment to Data Protection”
12.2 Automation and integration of apps and services
We use specialist platforms to integrate and connect existing third-party apps and services. We can also use such “no-code” platforms to automate processes and operations with third-party apps and services.
We use in particular:
▪ Microsoſt Power Automate including Microsoſt Power Platform: integrated application platform; provider: Microsoft; data protection information specific to Microsoft Power Platform: “Compliance and Data Privacy”, “Data Storage and Governance”, “Security”.
12.3 Map material
We use third-party services to be able to embed maps into our website.
We use in particular:
▪ Google Maps including Google Maps Platform: map service; provider: Google; information specific to Google Maps: “How does Google use location information?”
12.4 Digital content
We use services provided by specialist third parties to be able to integrate digital content into our website. Digital content includes, in particular, image and video material, music and podcasts.
We use in particular:
- YouTube: video platform; provider: Google; YouTube-specific details: “Privacy and Safety Center”, “Your Data in YouTube”
12.5 Payments
We use specialist service providers to ensure that payments are processed securely and reliably. The legal documents of the individual service providers, for example General Terms and Conditions (GTC) or privacy policies, also apply in addition to the processing of payments.
We use in particular:
- RaiseNow: a fundraising platform; providers: RaiseNow AG (Switzerland) / RaiseNow GmbH (Germany); data protection information: Privacy Policy, “Cooperation Guidelines: ethical and sustainable action”, Certification in accordance with the Payment Card Industry Data Security Standard (PCI DSS).
12.6 Advertising
We make use of the opportunity to have targeted advertising for our activities and operations displayed on third-party platforms, such as social media platforms and search engines.
With such advertising, we aim in particular to reach people who are already interested in our activities and operations, or who might be interested in them (remarketing and targeting). To this end, we may transfer relevant details – which may include personal data – to third parties who make such advertising possible. We may also determine whether our advertising is successful; that is, in particular, whether it leads to visits to our website (conversion tracking).
Third parties through whom we advertise and with whom you are registered as a user may, where applicable, link your use of our website to your profile with them.
We use in particular:
- Google Ads: search engine advertising; provider: Google; details specific to Google Ads: advertising based on, among other things, search queries, whereby various domain names – in particular doubleclick.net, googleadservices.com and googlesyndication.com – are used for Google Ads; Advertising Privacy Policy, “Manage in-stream advertising directly via ads”.
- Meta ads: Social media advertising on Facebook and Instagram; providers: Meta Platforms Ireland Limited (Ireland) and other Meta companies (inter alia in the USA); data protection information: targeting, including retargeting, in particular using the Meta Pixel and Custom Audiences including Lookalike Audiences, Privacy Policy; “Advertising Preferences” (user registration required).
13. Website extensions
We use extensions for our website so as to be able to use additional functions. We may use selected services from suitable providers or utilize such extensions on our own digital infrastructure.
We use in particular:
- Google reCAPTCHA: Bot protection (differentiates between wanted human activity and unwanted bot activity); provider: Google; Google reCAPTCHA-specific information: “What is reCAPTCHA?”
14. Performance and Reach Measurement
We endeavour to measure the performance and reach of our activities and operations. In this context, we may also measure the impact of third-party links or assess how different parts or versions of our digital presence are used (the “A/B testing” method). Based on the results of the performance and reach measurements, we are able, in particular, to rectify errors, enhance popular content or make improvements.
In most cases, the IP addresses of individual users are recorded for the purpose of measuring performance and reach. In this case, IP addresses are generally truncated (“IP masking”) in order to comply with the principle of data minimization through appropriate pseudonymisation.
Cookies may be used for performance and reach measurement, and user profiles may be created. Any user profiles created comprise, for example, the individual pages visited or the content viewed on our digital presence, details of the screen size or the browser window size, and the (at least approximate) location.
As a general rule, any user profiles created are exclusively pseudonymised and are not used to identify individual users. Individual third-party services with which users are registered may, where applicable, link the use of our online service to the user’s account or profile with the respective service.
We use in particular:
- Google Marketing Platform: Performance and reach measurement, in particular with Google Analytics; provider: Google; details specific to the Google Marketing Platform: tracking across different browsers and devices (cross-device tracking) using pseudonymised IP addresses, which are only transferred in full to Google in the USA in exceptional cases; Google Analytics Privacy Policy; “Browser add-on to disable Google Analytics”.
- Google Tag Manager: integration and management of services provided by Google and third parties, in particular for performance and reach measurement; provider: Google; details specific to Google Tag Manager: Google Tag Manager Privacy Policy; further details on data protection can befound in the individual integrated and managed services.
15. Concluding remarks on the privacy policy
We have drafted this privacy policy using the Privacy policy generator of Data protection partners.
We may update this privacy policy at any time. We will inform you of updates by publishing the latest version of the privacy policy on our website.