Privacy Policy
General
This Privacy and Security Policy governs and explains how Exxas AG, hereinafter referred to as Exxas, manages and handles your personal information and data. We appreciate your trust, which is why we strive to present our privacy policy in clear language.
Unless otherwise stated, this Privacy and Security Policy applies to all products, services, and websites offered by Exxas. These products, services, and websites are collectively referred to as "Services" in this policy. All services are provided in Switzerland.
Your Data
Your data belongs to you. Furthermore, we treat your data as private data that may not be used, modified, evaluated, or viewed without your consent. We do not sell your data to others, nor do we use your data for our own purposes or for purposes unrelated to you, except under very limited circumstances (e.g., if we are compelled by judicial subpoenas, etc., or if you have given us permission to do so).
We keep your data secure. All data and communication between you and Exxas are secured with state-of-the-art encryption methods. We protect your data from unauthorized access as much as possible. This includes security measures such as internal two-factor authentication, access logging, named users, firewalls, redundant systems, physical security measures, backups, and much more.
Your data is stored on servers in Switzerland. Therefore, Swiss law applies. This protects you from foreign laws that do not apply in Switzerland (e.g., the Patriot Act from the United States).
Providing Services
To provide customer care, support, and other services, we need access to your information and data. Access is limited to the extent necessary for service delivery. For example, for system adjustments, troubleshooting, or technical questions. With your questions, inquiries, orders, and confirmations, you allow us to access the data and information necessary for processing, answering, or resolving.
Data Storage and Rights
To provide and operate the various services, Exxas, and you as a customer when using these services, store company and personal data in databases and file systems. The data collected, created, or generated by you remain your property during the use of our services and beyond. Exxas provides you with functions so that you can download your data at any time and use it independently of the use of Exxas services. This right to your data does not include the provision or making available of necessary programs and systems to read or process the exported data (e.g., office applications, databases, etc.).
Your Obligations
To meet our high standards for data protection and security, we need your cooperation. Secure your computers with strong passwords, ensure that no unauthorized persons can use your computer, use up-to-date antivirus programs, and keep passwords safe. Only grant access to your systems and Exxas systems to authorized persons. Regulate in your company which persons are allowed to use Exxas services and features.
Privacy Policy
When you use our services, you entrust us with your data. We are aware that this is a great responsibility and we do everything to protect your data and ensure that you retain control over it.
This privacy policy explains what data we collect, what purposes we pursue with it, and how we handle your data. All personal data is processed on a lawful basis in accordance with the provisions of the Swiss Data Protection Act (DSG) and the European General Data Protection Regulation (GDPR).
We develop a variety of services that help thousands of people every day to manage their work more easily and better. Our services include: Business platforms like Exxas, Online Customer Portal (OCP) websites and newsletters like exxas.net or the Exxas Update service, and services like consulting and support. This privacy policy applies to all services, websites, and newsletters of Exxas AG (hereinafter "Exxas").
Personal Data Collected by Exxas
Exxas collects data about you through our interactions with you and through our products, services, websites, and newsletters (hereinafter "Services"). You provide some of this data directly, for example, when you create a customer account, conclude a contract for your company, request an offer, store a document in Exxas, purchase a service, register a new user, or when you contact us for support. We receive this by collecting data about your interactions, use, and experiences with our services, as well as through communication.
In processing the data, we rely on a variety of legal regulations and authorizations ("a legal basis"), including your consent, a balancing of legitimate interests, the necessity for the implementation and execution of contracts, and compliance with legal obligations. This is done for various purposes, which are described below.
We also receive data from third-party providers. We protect third-party data according to the guidelines described in these provisions and all other restrictions of the sources from which the data originates. These third-party sources may change over time and include: data brokers from whom we acquire demographic data to supplement the collected data. Services that forward user-generated content from their services to third parties, such as local business reviews or public social media posts. Communication services, including email providers and social networks, if you provide us with permission to access your data on these third-party services or networks. Service providers who help us determine the location of your device. Partners for whom we provide co-branding services and joint marketing activities. Generally available data sources such as public government databases. With the technology you use and the data you share, you have choices available. For example, you can visit our websites and learn about our services without telling us who you are. However, when you visit our websites, we collect technical data. This data includes the IP address and operating system of your device, the date and time of use, the website from which you visit us, and the type of browser you use to access our website. Insofar as we process personal data in this context, we do so based on our interest in providing the website, offering you the best possible user experience, and ensuring the security and stability of our systems. If you are asked to provide personal data, you can always decline. Many of our services use personal data that you provide. If you choose not to provide data that is required for the provision of a service, you may not be able to use the service. We must also collect personal data legally when we sign or enter into a contract with you. If you do not wish to provide data, we cannot enter into a contract with you. Should this relate to an existing service you are using, we must stop or discontinue its use. We will notify you if this is the case. The data we collect may include:
Name and Contact Information
Your first and last name, email address, postal address, phone number, and other similar contact details.
Login Credentials
Passwords, password hints, and similar security information used for authentication and account access.
Payment Data
Data important for processing your payment, such as your payment instrument number (e.g., credit card number) and the security code associated with the payment instrument.
License and Subscription Data
Information about your subscriptions, licenses, and other entitlements.
Interactions
Data about the use of Exxas services. In interactions with Exxas, for example, when using support or services, we link these activities with your personal data.
Content
The content of your files and communications that you enter, upload, receive, create, and control. For example, if you have enabled full-text search across file content or store an email in Exxas, we must analyze this content to present you with search results. Other content we collect when providing services includes: communications, including audio, video, text (typed, drawn, dictated, or otherwise) in messages, email, calls, meeting requests, or chats; photos, images, songs, movies, software, and other media documents that you store, retrieve, or otherwise process with our cloud; videos or recordings; recordings of events and activities in Exxas buildings and other locations. At Exxas events, your image and voice may be captured.
Feedback and Ratings
Information and content from messages you send us, such as feedback, survey data, and product reviews you write. When you use the registration, order, or contact forms on our website or inquire about our offers and services by phone, we collect your contact data and other contract-relevant personal data. We collect and process this personal data for the purposes of service provision and information about our services. After your personal data is no longer needed for its intended purpose, we delete or anonymize it.
How We Use Personal Data
Exxas uses the data we collect to provide comprehensive, interactive user and customer experiences. Specifically, we use data for the following: To provide our services, update them, secure them, and address problems such as providing support. This also includes sharing data, if necessary, to provide the service or execute the transactions you have requested; to improve and develop our services; to send you advertising, including promotions, targeted advertising, and offering relevant offers. We also use the data for our business, including analysis and performance, compliance with our legal obligations, for our workforce, and for development. We therefore combine the data collected from different contexts (e.g., from the use of two Exxas services). When we collect personal data about you, this is done with your consent or as needed to offer the services you use, for our business operations, to fulfill our contractual and legal obligations, to ensure the security of our systems and our customers, or to fulfill other legitimate interests of Exxas. To answer your inquiries, we regularly require your first name, last name, email address, phone number, and your user account (Exxas account). We process this personal data based on our interest in answering your inquiries as best as possible, providing and developing our services according to the contract, or optimizing your user experience. Based on our interest in informing about new developments, services, and offers from Exxas, we also provide you with corresponding commercial information (e.g., via newsletters) if you are interested. However, you always have the option to opt out of receiving such information.
How We Share Personal Data
We share your personal data with your consent or as needed to complete a transaction or provide a service you have requested or authorized. If you provide payment data to make a purchase, we will share the payment data with banks and other companies that process payment transactions or offer other financial services, as well as for fraud prevention and credit risk reduction. In addition, we share personal data with companies controlled by Exxas (Exxas Group companies). This includes parent, subsidiary, and affiliated companies of Exxas. We also share personal data with suppliers or agents who act on our behalf for the purposes described here. For example, companies we have hired to support customer service or to help protect the security of our systems and services may need access to personal data to enable these functions. In such cases, these companies must comply with our privacy and security policies and may not use the personal data received from us for other purposes. Furthermore, Exxas may disclose personal data as part of its business operations, such as a merger or the sale of assets. We conduct credit checks in cooperation with partners. We may have outstanding payments collected by a collection agency or a law firm. In doing so, we and our partners process personal data to check whether a contract can be concluded with you or based on our interest in avoiding payment defaults. On our websites, we use fonts from Google LLC "Google" (Google Fonts). To integrate the Google Fonts into the website, your browser establishes a connection to Google's server. Your device's IP address is transmitted to Google in the process. Google logs records of font file requests and protects this data from unauthorized access. Google analyzes aggregated data to optimize Google Fonts and to identify which websites use Google Fonts.
Personal Data We Store and Provide on Your Behalf
We collect and process personal data on your behalf that you yourself store when you use our services. This processing consists of the storage, provision, transmission, and deletion of data according to our contractual agreements with you. For example, we store and process personal data on your behalf when you create a new contact in Exxas or we create a user for a new employee in your Exxas on your behalf. Personal data that we store and provide on your behalf is governed by the order data processing terms.
Cookies and Similar Technologies
Cookies are small text files placed on your device that collect data that can later be read by a web server in the domain that placed the cookie. The data often consists of a series of numbers and letters that uniquely identify your computer. However, it may also contain other information. Some cookies are placed by third-party providers working on our behalf. We use cookies and similar technologies for storing your preferences and settings, which fulfills your login, providing personalized advertising, combating fraud, and analyzing how our services work, as well as other legitimate purposes.
Storing Your Preferences and Setting
We use cookies to store your preferences and settings on your device and to improve your experience. Storing your settings in cookies, e.g., your preferred language, prevents you from repeatedly having to set your settings.
Login and Authentication
We use cookies to authenticate you. Once you log in to a website with your personal account, a unique ID number and the time of your login are stored in an encrypted cookie on your device. This cookie allows you to navigate various pages within the website without having to log in again on each page. You can also save your login information so that you don't have to log in every time you return to the website.
Security
We use cookies to store information that protects our products and detects fraud and abuse.
Storing Your Information Provided on a Website
We use cookies to store information that you have shared. When you provide information to Exxas, for example, by adding products to your shopping cart when shopping on the Exxas websites, we store data about the products and information you have added in a cookie.
Social Media
Some of our websites contain social media cookies, including cookies that allow users logged into the social media service to share content via that service.
Feedback
Exxas uses cookies to allow you to provide feedback on a website.
Analysis
We use third-party cookies and other detection capabilities that collect usage and performance data. For example, we use cookies to determine the number of individual visitors to a website or service or to collect other statistics regarding the operation of our services. We use Google Analytics and other analytics services for this purpose. The information generated by the cookie about your use of the website is transmitted to a Google server in the USA and stored there. However, your IP address will be shortened and thus anonymized by Google within member states of the European Union or in other contracting states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the website operator, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website and internet usage to the website operator. Google may also transfer this information to third parties if required by law or insofar as third parties process this data on behalf of Google. The IP address transmitted by your browser within the scope of Google Analytics will not be merged with other Google data. You can prevent the storage of cookies by setting your browser software accordingly; however, we would like to point out that in this case, you may not be able to use all functions of the Exxas websites to their full extent. You can also prevent Google from collecting the data generated by the cookie and related to your use of the websites (including your IP address) and from processing this data by Google by downloading and installing the browser plug-in available under the following link ([https://tools.google.com/dlpage/gaoptout?hl=de](https://tools.google.com/dlpage/gaoptout?hl=de)).
Performance
Exxas uses cookies to understand and improve the function of our services. For example, we use cookies to collect data related to network load balancing. This ensures that our websites remain secure.
Advertising
We use Google Tag Manager on our websites to create tags for our website and applications. These tags enable us to target marketing measures concerning our services specifically to potential customers (re-targeting). We use advertising technologies from Google (AdWords), Microsoft (Bing Ads), Facebook, and other providers. According to our settings in Google Tag Manager, Google, Microsoft, and Facebook use so-called conversion cookies. This is necessary to verify the effectiveness of the respective advertising measures. We have a legitimate interest in this. In addition, we use Google Tag Manager to set re-targeting tags. These tags enable us to specifically address users with information about our services when they visit other websites (e.g., Bing or Facebook). You can set your web browser to disable the storage of cookies. However, please note that some functions of the website or our services may be limited or unavailable if you disable the storage of cookies.
Services Provided by Your Organization
If you use an email address provided by an organization affiliated with you, such as your employer or school, the organization can: control and manage your personal account; and access and process your data, including the content of your communications and files associated with your account. If you lose access to your work or school account (e.g., due to a change of employment), you will no longer have access to this service and all associated content of this service, including those you acquired on your behalf when you used your business or school account to log in to these services.
Exxas Account
With an Exxas account, you can log in to Exxas services. If applicable, you may receive an Exxas account through your affiliated organization (e.g., your employer). In this case, your employer has created a personal account, had one created, or it was automatically created when your user was recorded. Personal data linked to your Exxas account includes login credentials, names and contact data, payment data, device and usage data, your contacts, information about your activities, and your interests and favorites. Logging in to your Exxas account enables personalization, provides consistent experiences for services, and allows you to gain and use access to cloud data storage, pay using payment methods stored in your Exxas account, and use other advanced features and settings.
Where We Store and Process Personal Data
Personal data collected by Exxas is stored and processed in Switzerland. Data collected via cookies for website analysis and data for Exxas newsletters may be stored and processed in any country. Exxas maintains several geo-redundant data centers in Switzerland.
Our Approach to Storing Personal Data
Exxas stores personal data for as long as necessary to provide and complete services and transactions you have requested or for other legitimate purposes, such as compliance with our legal obligations, dispute resolution, and for enforcing our contracts. Since these measures vary for other data types in the context of our interactions with you or the use of other products, the actual retention period may vary considerably.
Your Rights Regarding Your Personal Data
You have the right to receive information about the personal data we process about you. You have a right to rectification of your personal data and to restriction of processing. In addition, you have a right to erasure of your personal data and a right to object to the processing of personal data. Insofar as the DSG or the GDPR apply and we carry out the processing to fulfill a contract or based on your consent, you also have a right to receive a copy of the personal data for transmission to a third party. Please note that exceptions or limitations apply to these rights. In particular, we may need to continue processing and storing your personal data to fulfill a contract with you, to protect our own legitimate interests such as asserting, exercising, or defending legal claims, or to comply with legal obligations. To the extent legally permissible, particularly to protect the rights and freedoms of other data subjects and to protect our legitimate interests (e.g., confidentiality and security interests as well as consideration of our operational resources and capabilities), we may therefore reject your data protection requests, e.g., requests for information and deletion, or only partially comply with them. However, you have the right to lodge a complaint with a competent supervisory authority. If you wish to exercise your data subject rights as a user of a service of one of our customers (e.g., as an employee of one of our customers), please do so directly with the respective organization (e.g., employer). This is because we are only a data processor in this regard. The customer responsible for the processing must observe the data subject rights.
Changes to This Privacy Policy
We update this privacy policy as needed for more transparency or in response to: feedback from customers, authorities, industries, or other stakeholders; changes to our products; or changes to our data processing activities or policies. The currently valid privacy policy can be found on our website. If changes have been made to the provisions, you can recognize this by the changed date under "Last updated" at the beginning of the privacy policy.
How to Contact Us
If you have any questions or complaints about data protection or a question for Exxas' data protection officer, please contact datenschutz@exxas.net or the following address. We will answer questions or other concerns within 30 days. You can also file a complaint with a data protection authority or another official authority.
Exxas AG
Datenschutzbeauftragter
Rietbachstrasse 10
8952 Schlieren-Zürich
Switzerland