top of page
Aspireon
Privacy Policy
General Information
This Privacy Policy informs you about the processing of personal data by Aspireon AG (hereinafter "we" or
"Aspireon"). This Privacy Policy applies to all activities and operations of Aspireon, including the use of our websites and online services. It describes how we collect, process and use personal data, what rights data subjects have and how these can be exercised. In certain cases, additional privacy policies or other legal documents such as Terms and Conditions, Terms of Use or Participation Terms may apply to individual activities or services of Aspireon.
We are subject to Swiss data protection law as well as any applicable foreign data protection law, in particular
that of the European Union (EU) with the General Data Protection Regulation (GDPR). The European
Commission recognises that Swiss data protection law ensures an adequate level of data protection.
1. Contact Details
Responsible for the processing of personal data within Aspireon, unless otherwise stated:
Aspireon AG
c/o Fehr Legal GmbH
Lättichstrasse 6
CH-6340 Baar
Switzerland
Email: matthias.leybold@aspireon.com
2. Terms and Legal Basis
2.1 Terms
Personal data is any information relating to an identified or identifiable natural person. A data subject is a person about whom we process personal data. Processing includes any handling of personal data, regardless of the means and procedures used, for example querying, matching, adapting, archiving, storing, reading, disclosing, obtaining, recording, collecting, deleting, disclosing, ordering, organising, saving, modifying, distributing, linking, destroying and using personal data. The European Economic Area (EEA) comprises the member states of the European Union (EU) as well as the Principality of Liechtenstein, Iceland and Norway. The General Data Protection Regulation (GDPR) refers to the processing of personal data as the processing of personal data.
2.2 Legal Basis
We process personal data in accordance with Swiss data protection law, in particular the Federal Act on Data
Protection (Data Protection Act, DSG) and the Ordinance on Data Protection (Data Protection Ordinance,
DSV).
We process personal data – insofar as and to the extent that the General Data Protection Regulation (GDPR) is
applicable – in accordance with at least one of the following legal bases:
Art. 6 para. 1 lit. b GDPR for the necessary processing of personal data for the performance of a contract with
the data subject as well as for the implementation of pre-contractual measures.
Art. 6 para. 1 lit. f GDPR for the necessary processing of personal data in order to safeguard the legitimate
interests of us or third parties, provided that the fundamental freedoms and rights as well as interests of the data subject do not override. Legitimate interests include in particular our interest in being able to carry out our activities and operations permanently, in a user-friendly, secure and reliable manner and to communicate about them, ensuring information security, protection against misuse, enforcement of our own legal claims and compliance with Swiss law.
Art. 6 para. 1 lit. c GDPR for the necessary processing of personal data to fulfil a legal obligation to which we
are subject according to any applicable law of member states in the European Economic Area (EEA).
Art. 6 para. 1 lit. e GDPR for the necessary processing of personal data for the performance of a task carried out
in the public interest.
Art. 6 para. 1 lit. a GDPR for the processing of personal data with the consent of the data subject.
Art. 6 para. 1 lit. d GDPR for the necessary processing of personal data in order to protect vital interests of the
data subject or another natural person.
3. Type, Scope and Purpose
We process personal data that is necessary in order to carry out our activities and operations permanently, in a
user-friendly, secure and reliable manner. Such personal data may in particular fall into the categories of
inventory and contact data, browser and device data, content data, meta or marginal data and usage data,
location data, sales data as well as contract and payment data. We process personal data for the duration required for the respective purpose or purposes or as required by law. Personal data whose processing is no longer required will be anonymised or deleted.
We may have personal data processed by third parties. We may process personal data jointly with third parties
or transmit it to third parties. Such third parties are in particular specialised providers whose services we use.
We also ensure data protection with such third parties. We only process personal data with the consent of the data subject, unless the processing is permissible for other legal reasons. Processing without consent may be permissible, for example, for the performance of a contract with the data subject and for corresponding pre-contractual measures, to safeguard our overriding legitimate interests, because the processing is evident from the circumstances or after prior information. In this context, we process in particular information that a data subject voluntarily transmits to us when making contact – for example by post, email, instant messaging, contact form, social media or telephone – or when registering for a user account. We may store such information, for example, in an address book, in a customer relationship management system (CRM system) or with comparable tools. If we receive data about other persons, the transmitting persons are obliged to ensure data protection vis-à-vis these persons and to ensure the accuracy of this personal data. We also process personal data that we receive from third parties, obtain from publicly accessible sources or collect in the course of our activities and operations, insofar as and to the extent that such processing is permissible for legal reasons.
5. Personal Data Abroad
We generally process personal data in Switzerland and in the European Economic Area (EEA). However, it may
occur that we also transmit personal data to other countries or process it there or have it processed.
Personal data is only transmitted to countries outside Switzerland and the EEA if the relevant country, in the
opinion of the Swiss Federal Council and – insofar as the GDPR is applicable – the European Commission,
ensures adequate data protection.
In countries where adequate data protection is not guaranteed, personal data is only transmitted if other
protective measures such as standard data protection clauses or similar appropriate guarantees exist. In
exceptional cases, personal data may also be transmitted to countries without adequate or appropriate data
protection, provided that special data protection conditions are met, such as explicit consent of the data subjects or if the transmission is necessary for the performance or execution of a contract.
Data subjects can make enquiries with us to obtain further information about the security measures or to view a copy of the guarantees.
6. Rights of Data Subjects
6.1 Data Protection Claims
We grant data subjects all claims in accordance with applicable data protection law. Data subjects have in
particular the following rights:
Information: Data subjects can request information as to whether we process personal data about them and, if so, what personal data it is. Data subjects also receive the information necessary to assert their data protection claims and ensure transparency. This includes the processed personal data as such, but also, amongst other things, information on the purpose of processing, the duration of storage, any disclosure or export of data to other countries and the origin of the personal data.
Rectification and Restriction: Data subjects can have incorrect personal data rectified, incomplete data
completed and the processing of their data restricted.
Deletion and Objection: Data subjects can have personal data deleted ("right to be forgotten") and object to the processing of their data with effect for the future.
Data Portability: Data subjects can have personal data handed over or transferred to another controller.
6.2 Complaints
Data subjects have the right to assert their data protection claims by way of legal action or to file a complaint
with a competent data protection authority. The data protection authority for private controllers in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC): https://www.edoeb.admin.ch.
8. Website
8.1 Cookies
We use cookies. Cookies – including those from third parties whose services we use – are data stored in the
browser. Such stored data does not have to be limited to traditional cookies in text form.
Cookies can be stored in the browser temporarily as "session cookies" or for a certain period of time as so-
called permanent cookies. "Session cookies" are automatically deleted when the browser is closed. Permanent
cookies in particular have a specific storage period. Cookies enable in particular the recognition of a browser
when our website is accessed again and thereby, for example, to measure the reach of our website. Permanent
cookies can also be used, for example, for online marketing.
Cookies can be completely or partially deactivated and deleted at any time in the browser settings. Without
cookies, our website may no longer be fully available. We actively request – at least insofar as and to the extent
required – your express consent to the use of cookies.
For cookies that are used for success and reach measurement or for advertising, an objection ("opt-out") is
generally possible for numerous services via AdChoices (Digital Advertising Alliance of Canada), the European
Interactive Digital Advertising Alliance (EDAA), Network Advertising Initiative (NAI) or YourAdChoices
(Digital Advertising Alliance) as well as YourOnlineChoices (EDAA) is possible.
8.2 Server Log Files
We may record the following information for each access to our website, provided this is transmitted by your
browser to our server infrastructure or can be determined by our web server: date and time including time zone, Internet Protocol (IP) address, access status (HTTP status code), operating system including user interface and version, browser including language and version, individual sub-page of our website accessed including data volume transferred, last web page accessed in the same browser window (Referer or Referrer).
We store such information, which may also constitute personal data, in server log files. The information is
necessary in order to be able to provide our website permanently, in a user-friendly and reliable manner and to
ensure data security and thus in particular the protection of personal data – also by third parties or with the help of third parties.
8.3 Counting Pixels
We may use counting pixels on our website. Counting pixels are also referred to as web beacons. Counting
pixels – including those from third parties whose services we use – are small, usually invisible images that are
automatically retrieved when visiting our website. The same information as in server log files can be recorded
with counting pixels.
9. Notifications and Communications
We send notifications and communications by email and via other communication channels such as instant
messaging or SMS.
9.1 Success and Reach Measurement
Notifications and communications may contain web links or counting pixels that record whether an individual
communication has been opened and which web links have been clicked. Such web links and counting pixels
can also record the use of notifications and communications on a personal basis. We require this statistical
recording of use for success and reach measurement in order to be able to send notifications and
communications effectively and in a user-friendly manner as well as permanently, securely and reliably based
on the needs and reading habits of recipients.
9.2 Consent and Objection
You must generally expressly consent to the use of your email address and your other contact addresses, unless the use is permissible for other legal reasons. For any consent, we use the "double opt-in" procedure wherever possible, i.e. you receive an email with a web link that you must click to confirm, so that no misuse by
unauthorised third parties can take place. We may log such consents including Internet Protocol (IP) address as well as date and time for evidentiary and security reasons.
You can generally object to receiving notifications and communications such as newsletters at any time. With
such an objection, you can simultaneously object to the statistical recording of use for success and reach
measurement. Required notifications and communications in connection with our activities and operations
remain reserved.
10. Social Media
We are present on social media platforms and other online platforms in order to be able to communicate with
interested persons and inform them about our activities and operations. In connection with such platforms,
personal data may also be processed outside Switzerland and the European Economic Area (EEA).
The Terms and Conditions and Terms of Use as well as Privacy Policies and other provisions of the individual
operators of such platforms also apply. These provisions inform in particular about the rights of data subjects
directly vis-à-vis the respective platform, which includes, for example, the right to information.
11. Third-Party Services
In order to improve the performance, user-friendliness, security and reliability of our activities, we use
specialised services from third-party providers. These services may include functions and content integrated
into our website. When embedding these services, the providers record the IP addresses of users for technical
reasons, but only to the extent and for the duration necessary to provide the service.
Third parties may process data for necessary security purposes, statistical analyses and technical optimisation in aggregated, anonymised or pseudonymised form. This includes performance and usage data required for the provision of their services.
We use in particular services from:
Google: For users in the EEA and Switzerland by Google Ireland Limited. Further information on Google's data
protection practices can be found in their Privacy Policy and Privacy & Security Principles. You can adjust your
settings for personalised advertising with Google in the Ad Settings.
Microsoft: For users in the EEA, Great Britain and Switzerland by Microsoft Ireland Operations Limited.
Microsoft's data protection practices are presented in the Trust Centre and in their Privacy Statement. Users can manage their privacy settings in the Microsoft Privacy Dashboard.
11.1 Digital Infrastructure
We obtain the necessary digital infrastructure for our activities and services from specialised third-party
providers. We take precautions to ensure that these providers apply reliable security measures and comply with data protection standards.
We use in particular the following services:
Microsoft 365 for Business: Email, productivity tools and cloud storage; Provider: Microsoft Ireland
Operations Limited (Ireland) for users in the EEA and Switzerland; Privacy information: Privacy Statement,
Trust Centre.
Wix:
Website hosting, campaign and lead management, booking management; Provider: Wix.com Ltd. (Israel)
with servers worldwide; Wix is certified under the EU-US Data Privacy Framework; Privacy information:
Privacy Policy.
Bexio:
Customer and contract management, invoicing, accounting; Provider: Bexio AG (Switzerland); Privacy
information: Privacy Policy.
Zapier:
Integration and data transfer between Wix and Bexio; Provider: Zapier Inc. (USA); Zapier is certified
under the EU-US Data Privacy Framework; Privacy information: Privacy Policy.
11.3 Appointment Scheduling
We use Wix Bookings to enable online appointment scheduling. Further information on Wix can be found in
Section 11.1.
11.6 Advertising
We use the opportunity to have targeted advertising for our activities displayed by third parties. This includes
remarketing (people who have visited our website) and targeting (people with specific interests or professional
profiles). We can also determine whether our advertising is successful (conversion tracking).
We use in particular: Google Ads: Search engine advertising; Provider: Google Ireland Limited (Ireland);
Privacy information: Privacy Policy, "Advertising" (Google), "Why am I seeing a particular advert?".
LinkedIn Ads: Social media advertising; Provider: LinkedIn Ireland Unlimited Company (Ireland); Privacy
information: Privacy Policy, Opt-out of personalised advertising.
12. Success and Reach Measurement
We use Wix Analytics for success and reach measurement of our website. This analysis is carried out
anonymously and serves to improve our online offering.
We reserve the right to use additional analysis tools and will update this Privacy Policy accordingly.
13. Final Provisions
This Privacy Policy was created taking into account the applicable data protection laws and standards. Final
responsibility for the content lies with Aspireon AG.
We reserve the right to change this Privacy Policy at any time to adapt it to new legal requirements or changes
in our data protection practices. Changes become effective as soon as they are published on our website. We
recommend that you check this page regularly for updates. We will inform you about significant changes
wherever practically possible, for example by email or via a clearly visible notice on our website.
UPDATED: FEB 2026
bottom of page