Hero Image

Privacy Policy and Handling of Your Data at Adfinis

Change Log: v2.0 - 28 Jul 2026 - Full replacement of the 2021 policy. All Privacy Shield references removed and replaced with EU-US and Swiss-US Data Privacy Framework language, with the 2021 SCCs as structural backup. Third-party services updated to reflect the current stack (Google Ads / Maps / reCAPTCHA / YouTube / Web Fonts, Matomo, LinkedIn Insight Tag + Conversions API, Reddit Pixel + Conversions API). Joint-controller position stated for the LinkedIn Insight Tag and the Reddit Pixel per CJEU C-40/17 (Fashion ID). Server-side tracking and SHA-256 hashing described honestly as pseudonymisation per EDPB January 2025 guidance. Right to lodge a complaint with the FDPIC / lead EU supervisory authority added. Retention periods stated per processing operation. DPO contact alias added. "Federal Republic of Germany / Data Protection Act, DSG" mis-reference in the 2021 general note corrected.

1. Controller and Data Protection Officer

Document Version: 2.0 The controller responsible for the processing of personal data through the adfinis.com website within the meaning of the Swiss revFADP and the EU GDPR is:

Adfinis AG Giessereiweg 5 CH-3007 Bern, Switzerland Phone: +41 61 500 31 31 Email: [email protected]

Adfinis AG is the parent of the Adfinis group; a current list of Adfinis subsidiaries is available on our Contact page. Where processing is carried out jointly with a subsidiary or on behalf of a group entity, Adfinis AG remains the accountable controller for the personal data processed through this website.

Group Data Protection Officer: Chandra Challagonda, Adfinis AG, Giessereiweg 5, CH-3007 Bern. Dedicated email: [email protected]. You may contact the DPO directly on any question about this policy, your rights, or the processing of your personal data.

2. Scope and general information

This policy applies to the processing of personal data that takes place when you visit adfinis.com, submit an enquiry through our contact form, subscribe to a newsletter, apply for a role, or otherwise interact with our public web platform.

We process personal data in accordance with the Swiss Federal Act on Data Protection ("FADP", as revised and in force 1 September 2023) and, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). Article 13 of the Swiss Federal Constitution and Article 8 of the European Convention on Human Rights recognise the right to privacy; this policy explains how we operationalise that right for our website.

Data transmission over the internet is not entirely secure. While we protect our systems as described in §14, we cannot guarantee the security of data transmitted to us over email or the public internet. Please do not send special-category personal data (health data, government identifiers, payment card data, credentials) to us through unsecured channels.

3. Personal data we process, purposes, and legal bases

We process personal data for the specific purposes and on the specific legal bases set out below. We do not process personal data for purposes incompatible with these.

  • Delivery of the website and security. Access logs (IP address, user-agent, requested URL, timestamp, response status, response size, request correlation ID). Purpose: to serve the site and detect abuse. Legal basis: Art. 6(1)(f) GDPR / Art. 31(1) revFADP (legitimate interest in the security and operation of the site). Retention: see §13.
  • Handling contact-form and business-development enquiries. Name, email, company, message content and any attachments. Purpose: to respond to your enquiry and to prevent misuse of the form. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in preventing form abuse) / Art. 31(1) revFADP. Retention: see §13.
  • Recruitment (careers form). Name, contact details, CV, cover-letter content and any supporting documents. Purpose: to assess your application. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) / Art. 31(1) revFADP. Retention: see §13.
  • Website analytics (Matomo). Aggregated visitor statistics using anonymised IPs, no third-party transfer. Legal basis: Art. 6(1)(f) GDPR / Art. 31(1) revFADP, supported by a legitimate interest assessment on file. See §10.
  • Advertising, retargeting and campaign measurement via third-party services. Cookies and server-side event data transmitted to Google, LinkedIn and Reddit as described in §§5–8. Legal basis: Art. 6(1)(a) GDPR (explicit consent) / Art. 31(1) revFADP. These services are loaded only after you have given consent in our consent management platform ("CMP"), and you can withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR).
  • Embedded content - maps, video, fonts, bot protection. As described in §§9–12. Where the embedded service sets cookies or transfers data outside Switzerland/EEA, we load it only after CMP consent. Bot-protection (reCAPTCHA) is loaded on the basis of Art. 6(1)(f) GDPR / Art. 31(1) revFADP (legitimate interest in form-abuse prevention); this classification is documented in an LIA and is kept under review in light of recent regulator guidance.

4. Cookies and consent management

We use cookies and similar technologies (including local storage, browser pixels and server-side event APIs) both for strictly necessary purposes (security, remembering your consent choices) and for optional purposes (analytics, marketing). Strictly necessary cookies are loaded automatically on the basis of legitimate interest and, where applicable, the ePrivacy exception for cookies strictly necessary to deliver the service you requested. All other cookies and tracking technologies are loaded only after you have given explicit, granular opt-in consent via our consent management platform. Browser-level opt-out alone is not sufficient for those categories. A full inventory of cookies and third-party trackers, with categories, purposes and durations, is set out in our Cookie & Tracking Policy, which forms part of this Privacy Policy and is available at adfinis.com/en/cookie-policy. To review or change your choices at any time, use the Manage cookie preferences link in the footer of the website. We keep a record of each consent event (opaque consent ID, timestamp in ISO 8601 UTC, banner version, categories accepted and rejected, country-level geolocation) for the duration of the consent plus three years, so that we can demonstrate compliance if challenged. City-level geolocation is not logged.

5. Services Provided by Third Parties

This website uses third-party services for advertising, analytics, embedded media, mapping, and bot protection. The services in active use are: Google Maps, Google reCAPTCHA, YouTube and Google Ads (all provided by Google Ireland Limited as EEA controller, with onward transfer to Google LLC in the USA), the LinkedIn Insight Tag and LinkedIn Conversions API (provided by LinkedIn Ireland Unlimited Company as EEA controller, with onward transfer to LinkedIn Corporation in the USA), and the Reddit Pixel and Reddit Conversions API (provided by Reddit Netherlands B.V. as regional contracting entity for European users, with onward transfer to Reddit, Inc. in the, Inc. Inc., USA). These services may set cookies in your browser and / or receive server-to-server event data from our infrastructure.

Transfers to the United States are primarily based on the European Commission's adequacy decision for the EU-US Data Privacy Framework and the corresponding Swiss-US Data Privacy Framework where the recipient is self-certified; active certifications are held by Google LLC, LinkedIn Corporation and Reddit, Inc. As a structural backup, these transfers are further secured by the European Commission's Standard Contractual Clauses (Decision 2021/914), using Module 1 (controller-to-controller) or Module 2 (controller-to-processor) as determined by the specific processing phase, together, Modules 2 or 3, with the Swiss addendum issued by the FDPIC. A Transfer Impact Assessment is maintained on file for each recipient. Non-essential services are loaded only after you have given your explicit, granular consent in our consent management platform; we keep a record of your consent (consent ID, time stamp, categories, and CMP version) for as long as required to demonstrate compliance.

6. LinkedIn Insight Tag and LinkedIn Conversions API

We use the LinkedIn Insight Tag and the LinkedIn Conversions API provided by LinkedIn Ireland Unlimited Company ("LinkedIn"). For the collection and initial transmission of personal data from your device or our servers, Adfinis AG and LinkedIn act as joint controllers within the meaning of Article 26 GDPR. The arrangement is set out in the Joint Controller Addendum that LinkedIn publishes for the use of its insights products; the essence of the arrangement is available on request and the lead supervisory authority is the Irish Data Protection Commission. LinkedIn acts as an independent controller for all subsequent processing inside its own systems.

The Insight Tag sets a LinkedIn cookie on your browser and transmits standard request data (IP address, user-agent, page URL, timestamp, event metadata). The Conversions API sends conversion events (such as a form submission) directly from our server to LinkedIn. Where conversion events include personal identifiers such as your email address, those identifiers are hashed using SHA-256 before being transmitted; we treat the hashed identifiers as pseudonymised personal data because LinkedIn can re-identify the visitor by matching them to its member graph. We use this data to measure the effectiveness of our LinkedIn advertising and, where you have consented to marketing categories, to build matched and retargeting audiences. The legal basis is your explicit consent under Article 6(1)(a) GDPR / Article 31(1) revFADP, which you can withdraw at any time in the CMP without affecting the lawfulness of processing carried out before withdrawal. Transfers to LinkedIn Corporation in the USA are based on LinkedIn's certification under the EU-US and Swiss-US Data Privacy Frameworks.

7. Reddit Pixel and Reddit Conversions API

We use the Reddit Pixel and the Reddit Conversions API provided by Reddit Netherlands B.V. as a regional contracting entity, with onward transfer to Reddit, Inc. in the USA (together"Reddit"). The Pixel may set cookies on your device to record on-site events; the Conversions API sends the same event data server-to-server from our infrastructure to Reddit. Where events include personal identifiers such as your email address, those identifiers are hashed with SHA-256 before transmission and we treat them as pseudonymised personal data, because Reddit can re-identify the visitor by matching them to its user base. We use this data solely to measure the effectiveness of our Reddit advertising and to build matched audiences. The legal basis is your explicit consent under Article 6(1)(a) GDPR / Article 31(1) revFADP, which you can withdraw at any time in the CMP without affecting the lawfulness of processing carried out before withdrawal.

For the Conversions API path, Adfinis and Reddit each act as independent controllers for the event data, with Adfinis as the controller initiating the transmission. For the Reddit Pixel path, the embedding of the Pixel on our website co-determines Reddit's collection of personal data from your browser; for that collection-and-transmission phase Adfinis and Reddit are joint controllers within the meaning of CJEU Case C-40/17 (Fashion ID), and Adfinis discharges the user-facing transparency and rights obligations through this Privacy Policy. Reddit acts as an independent controller for all subsequent processing in its own systems. Transfers to Reddit Inc in the USA are primarily based on Reddit's certification under the EU-US and Swiss-US Data Privacy Frameworks; as a structural backup, they are further secured by the the European Commission's Standard Contractual Clauses 2021/914 (1, controller-to-controller for both the Conversions API and Pixel paths) as incorporated by reference into Reddit's published Advertising Data Processing Agreement, together with the Swiss FDPIC addendum and a Transfer Impact Assessment held on file.

8. Server-Side Tracking and Hashing

Complementary server-side tracking. For Google Ads, the LinkedIn Conversions API and the Reddit Conversions API, we also use server-to-server event transmission alongside the browser-based tags described above. Server-side calls are made only after you have given consent to the relevant marketing category in our consent management platform, and the same consent withdrawal applies. Where events contain personal identifiers such as your email address, those identifiers are hashed using SHA-256 before they leave our server environment and we treat the hashed values as pseudonymised personal data within the meaning of Article 4(5) GDPR — they are no longer directly readable, but the receiving platform may re-identify the visitor by matching them to its own user base. We use the data only for conversion measurement and audience matching for our own advertising campaigns.

9. Google Maps, YouTube and Google reCAPTCHA

For embedded maps we use Google Maps; for embedded video we use YouTube; for protection against automated form abuse we use Google reCAPTCHA. All three are provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) as EEA controller, with onward transfer to Google LLC in the USA under the EU-US and Swiss-US Data Privacy Frameworks and, as a structural backup, the 2021 SCCs with the Swiss addendum.

Google Maps and YouTube may set cookies and collect standard request data (including IP address and user-agent). They are loaded only after you have given consent to the corresponding category in our CMP. Where technically supported, YouTube is loaded in privacy-enhanced mode until you interact with the player. Google reCAPTCHA operates as an anti-fraud measure and may collect device and behavioural signals to distinguish humans from automated agents. It is loaded on the basis of Art. 6(1)(f) GDPR / Art. 31(1) revFADP (legitimate interest in preventing form abuse). We keep this classification under review in light of recent supervisory-authority guidance; a documented LIA and, if the position changes, a consent-based deployment or a switch to an alternative bot-protection provider will follow.

10. Matomo Analytics

We use Matomo (an open-source analytics platform) to understand aggregated visitor behaviour and improve our content. Our Matomo instance is hosted in Switzerland, configured for IP anonymisation before storage, and operated in cookie-less mode. We honour the Do Not Track (DNT) header and, where the browser sends it, the Global Privacy Control (GPC) signal. Because no third-country transfer takes place and no persistent identifier is stored on your device, this processing is carried out on the basis of Art. 6(1)(f) GDPR / Art. 31(1) revFADP (legitimate interest in understanding aggregate usage), supported by an LIA on file.

11. Google Web Fonts

We serve web fonts from our own infrastructure (self-hosted) rather than from Google's CDN, so that no personal data is transmitted to Google merely because you loaded the site. This design follows the Landgericht München I decision of 20 January 2022 (Az. 3 O 17493/20).

12. Contact Form Data Protection Notice

If you send us an enquiry through the contact form on our website, we process the personal data you provide (typically your name, email address, company name and message content) to respond to your enquiry and to prevent misuse of the form. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in preventing form abuse) / Art. 31(1) revFADP). We delete your enquiry no later than 12 months after closure unless a contract is concluded with you, in which case the retention rules of that contract apply. Please do not send confidential information, passwords, or special categories of personal data through this form.

If you apply for a role through our careers form, the information you provide (including your CV and any supporting documents) is processed by Adfinis AG's People team to assess your application, on the basis of Art. 6(1)(b) GDPR / Art. 31(1) revFADP. Rejected applications are retained for six months from the closure of the vacancy for legal-defence purposes, after which they are deleted, unless we have obtained your separate consent to retain them for future opportunities.

13. How long we keep your data

The following retention periods apply to the personal data processed through this website. Where a longer retention obligation arises from applicable law (for example, statutory accounting or limitation periods), we apply the longer period and restrict processing to the corresponding purpose.

Overview

Contact-form enquiries

Retention: 12 months after closure

Reason: Follow-up and abuse-prevention; longer if a contract is concluded.

Careers-form applications

Retention: 6 months after vacancy closes

Reason: Legal-defence period; longer only with your separate consent.

Access / server logs (full IP)

Retention: 90 days

Reason: Security incident forensic window aligned with Art. 33 GDPR notification requirements.

Access / server logs (IP truncated)

Retention: 13 months

Reason: Aggregate trend analysis; direct identifiability reduced by truncation.

CMS audit logs

Retention: 12 months (up to 3 years for customer content)

Reason: Accountability under Art. 5(2) GDPR; longer for regulated-customer-facing content.

Consent records

Retention: Duration of consent + 3 years

Reason: Ability to demonstrate consent under Art. 7(1) GDPR; three-year tail aligned with the Swiss general limitation period.

Marketing tags and cookies (LinkedIn, Reddit, Google Ads)

Retention: Capped at 13 months

Reason: Per provider technical defaults, aligned with CNIL, EDPB, and BayLDA guidance on marketing-cookie lifetime.

Hashed identifier batches sent via CAPI

Retention: Max 90 days

Reason: Kept only as long as necessary for the corresponding conversion-attribution window (receiving platform governed by own policy).

Breach register entries

Retention: 10 years

Reason: FDPIC / lead SA may request the record long after the incident.

14. Security

We apply appropriate technical and organisational measures to protect your personal data against loss, alteration, disclosure or unauthorised access, as required by Art. 32 GDPR and Art. 8 revFADP. These include: TLS 1.2/1.3 encryption for all traffic to and from the website; role-based access control on our content management system and support tooling; secrets management for API credentials; append-only logging with tamper detection; regular vulnerability scanning; and least-privilege access to production systems for a small named group of engineers and administrators. We operate a documented incident-response process. In the event of a personal-data breach that meets the notification threshold, we notify the FDPIC (under Art. 24 revFADP) and, where the breach affects EU/EEA data subjects, the competent EU supervisory authority within the 72-hour window (Art. 33 GDPR). Where the breach is likely to result in a high risk to affected individuals, we also inform those individuals directly (Art. 34 GDPR).

15. Recipients of personal data and international transfers

Personal data processed through this website is disclosed to the following categories of recipients only:

  • Adfinis group entities in Switzerland, Germany, the Netherlands, Australia, New Zealand and Egypt, where necessary to respond to your enquiry or provide the service you requested. Intra-group transfers are governed by our internal group Data Processing Agreement and, where the destination is outside the EEA / Switzerland, by the 2021 SCCs with the Swiss FDPIC addendum.
  • Third-party service providers named in §§5–11 (Google Ireland / Google LLC, LinkedIn Ireland / LinkedIn Corporation, Reddit Netherlands B.V. / Reddit, Inc., Matomo), each on the legal basis and with the transfer safeguard described in the relevant section. Processors that assist us with our hosting, email, CRM, marketing automation and analytics, under Article 28 GDPR / Article 9 revFADP data processing agreements. A current list is available from the DPO on request. Public authorities where we are required to disclose personal data by applicable law or a valid legal order. We do not sell personal data, and we do not disclose personal data for the direct commercial purposes of third parties beyond what is described above.

16. Your rights and how to exercise them

You have the following rights in relation to the personal data we process about you (subject to the conditions and exceptions set out in the applicable law): Access (Art. 15 GDPR / Art. 25 revFADP) - request confirmation of processing and a copy of your data. Rectification (Art. 16 GDPR / Art. 32(1) revFADP) - correct inaccurate or incomplete data. Erasure (Art. 17 GDPR / Art. 32(2) revFADP) - request deletion under the conditions set out in the law. Restriction of processing (Art. 18 GDPR). Data portability (Art. 20 GDPR / Art. 28 revFADP) - receive your data in a common machine-readable format. Objection (Art. 21 GDPR) to processing based on legitimate interest, at any time and on grounds relating to your particular situation. Withdrawal of consent (Art. 7(3) GDPR) at any time, without affecting the lawfulness of processing carried out before withdrawal. For marketing and analytics categories this is done through the Manage cookie preferences link in the footer of the website. Not to be subject to automated decision-making with legal or similarly significant effects (Art. 22 GDPR). We do not carry out such automated decision-making through this website. To exercise any of these rights, please contact the Group DPO at [email protected]. We will respond within the statutory time limits (one month under Art. 12(3) GDPR, extendable by a further two months where necessary; without undue delay under revFADP). Right to lodge a complaint. You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland (edoeb.admin.ch) and, if you are in the EU/EEA, with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement (Art. 77 GDPR).

17. Automated decision-making and profiling

We do not carry out automated decision-making with legal or similarly significant effects on you through this website. The marketing-audience matching described in §§6–8 is used solely for our own campaign measurement and audience building; it does not, in itself, take a decision about you. If we introduce such automated decision-making in the future, we will update this policy and inform affected individuals in advance.

18. Changes to this policy

We keep this policy under review. Substantive changes (for example, a change of controller, of a legal basis, of a processing purpose, or the introduction of a new third-party service) will be announced by updating the version and effective date at the top of this document and, where there is a material impact on you, through a notice on the website. Insofar as this policy forms part of an agreement between us and you, we will notify you of the change by email or another appropriate channel.

19. Contact

Adfinis AG · Group Data Protection Officer · Chandra Challagonda Giessereiweg 5, CH-3007 Bern, Switzerland [email protected] +41 61 500 31 31