Privacy Policy

(as of February 1, 2024)

This privacy policy informs users about the nature, scope and purposes of the recording and use of personal data by the responsible provider YOU Photo GmbH, Blegistrasse 7, 6340 Baar, Switzerland, E-Mail: you@youstudio.ch, Telephone: +41 79 790 80 00.


1. WHAT IS THE SUBJECT OF THIS PRIVACY POLICY?

YOU Photo GmbH, Blegistrasse 7, 6340 Baar, Switzerland (hereinafter referred to as “Studio”, and also “we”, “us”) collects and processes personal data that could relate to you or other people (hereinafter referred to as “third parties”). In this document, the term “data” is used synonymously with “personal data” or “personal information”.

In this privacy policy, we describe what we do with your data when you use our website www.youstudio.ch, or use our services or products, in the performance of contractual obligations, communicate with us or otherwise engage with us, or if you are a shareholder of or investor in our company. We may also notify you separately regarding the processing of your data (e.g. in forms, contractual conditions or additional privacy policies).

If you disclose data concerning other people (e.g. family members, work colleagues) to us, we assume that you are authorised to do so and that the data is correct. You confirm this by transferring data about third parties. Please ensure that these third parties have been informed of this privacy policy.

This privacy policy is designed to comply with the Swiss Federal Act on Data Protection (FADP), the New Federal Act on Data Protection (nFADP) and the requirements of the European Union’s General Data Protection Regulation (GDPR). Whether and to what extent these laws are applicable depends on the specific case.

The Notice currently in place dates of February 1, 2024.


2. WHO IS RESPONSIBLE FOR PROCESSING YOUR DATA?

For the data processing described in this privacy policy, Studio is the data controller under data protection law unless otherwise communicated in specific cases.

Our address:

YOU Photo GmbH,

Blegistrasse 7,

6340 Baar,

Switzerland,

E-Mail: you@youstudio.ch,

Telephone: +41 79 790 80 00.


3. WHAT DATA DO WE PROCESS?

We collect personal data that you provide to us, such as by filling out a contact form, registering for an account, using interactive features, subscribing to a service, participating in a marketing promotion, booking service, requesting information and/or material or complete surveys. Such personal data may consist of:

-contact information (such as name, postal address, email address, and mobile or other telephone number);

- purchase and transaction information;

- data that arises in the context of competitions or when redeeming vouchers/gift certificates;

- payment information (such as your payment card number, expiration date, authorization number or security code, delivery address, and billing address);

- customer service information (such as customer service inquiries, comments, and repair history);

- customer history;

- information regarding your personal or professional interests, date of birth, marital status, demographics, and experiences with our products and contact preferences;

- photographs, comments and other content you provide;

- contact information you provide about friends or other people you would like us to contact; and

- information we may obtain from our third-party service providers;

- data about your behaviour and preferences (such as reactions to electronic messages, navigation on the website, interactions with our social media profiles, participation in competitions or events, etc.), potentially supplemented by information from third parties (also from publicly accessible sources).

We collect metadata, for example details of your visits to the Website, such as traffic data, location data, IP address, browser information, session data, preferences, settings, weblogs and other communication data, which we monitor during your interaction with the Website.


4. WHERE DOES THE DATA COME FROM?

  • From you: Much of the data specified in section 3 is provided to us by you (e.g. during communication with us, in connection with our services, through the use of our website and other services, etc.). You are not obliged to disclose your data except in specific cases (e.g. legal obligations such as legally required identification
  • From third parties, including open sources, Internet analytics services, media or the Internet incl. social media. If you work for an employer or client or someone else who has a business relationship or other dealings with us, they may also share data about you with us.

5. ON WHICH BASIS DO WE PROCESS YOUR PERSONAL DATA?

We process your personal data for the purposes indicated or obvious at the time of collection and to which you have agreed, for example by checking a box, or for which we are required by applicable laws, for example to comply with data retention requirements regarding data relevant for financial reporting; or which is necessary for the performance of a contract, for example if you order services; or for which we rely on other legitimate interests.

We process your data based on:

  • Your explicit consent: When we request your consent for the processing of your data, this is the legal basis on which we process your data. We will inform you of the purpose of the processing. You can revoke your consent in writing (via post or, if not otherwise specified or agreed, via e-mail) at any time, with future effect. As soon as we receive and process the revocation of your consent, we will no longer process your data for the purposes to which you originally consented (unless the further processing is permitted on another legal basis);
  • Legitimate interest: We may process your data based on our own legitimate interest or the legitimate interest of a third party. This applies in particular to achievement of the purposes and objectives and the execution of related measures. Among other things, we have a legitimate (and overriding) interest in the marketing of ourservices as well as a better understanding of the markets relevant to us and our activities (in particular in the efficient and secure performance of our processes and the further development of our activities), in the efficient and effective management of our company, and in safeguarding the security of our systems, buildings and our interests vis-à-vis third parties.
  • Our egitimate interests may include gathering market intelligence, promoting products and services, communicating with and tailoring offers to you; delivering and improving our products or services; management of customer, client, vendor and other relationships, sharing intelligence with internal stakeholders, implementing safety procedures, and planning and allocate resources and budget; monitoring, detecting and protecting the organisation, its systems, network, infrastructure, computers, information, intellectual property and other rights from unwanted security intrusion, unauthorised access, disclosure and acquisition of information, data and system breaches, hacking, industrial espionage and cyberattacks; protecting and developing industry standards; sharing intelligence about individuals or concerns that may have a negative or detrimental impact; and following industry best practices; or complying with industry standards, regulators’ requirements and other requirements related to fraud prevention and anti-money laundering.
  • Legal obligations: we may process your data to comply with applicable legal, regulatory or professional conduct provisions to which we are subject.
  • Contract: we process data for the conclusion and performance of contracts concluded for or with you or your employer, client or other persons for whom you are working, this is also the legal basis for our processing of your data.
  • Other legal bases: In specific cases, we may also process data on other legal bases which include:

6. FOR WHAT PURPOSES DO WE PROCESS YOUR DATA?

We process your personal data for the following purposes:

  • Communication: In order to communicate with you (e.g. to answer inquiries, or in the context of consultations or contract performance), we must process your data . In particular, we use communication data and master data for this purpose, as well as registration data in connection with the services you use.
  • Preparation, administration and processing of bookings: In connection with the initiation, conclusion and processing of booking with our guests (e.g. in the context of booking management) and other customers, subcontractors or other contractual partners (e.g. software suppliers), we process related personal data. This also includes the enforcement of legal claims arising from contracts (debt collection, legal proceedings, etc.), accounting, termination of contracts and public communications.
  • ​​Marketing purposes and relationship maintenance: We process data for marketing and relationship maintenance purposes, for example to send our guests and other customers, other contractual partners and other interested parties personalised advertising (e.g. as printed matter, via e-mail, via other electronic channels or via telephone) regarding products, services and other news from us and from third parties (e.g. from product partners), in connection with free services (e.g. invitations, vouchers, etc.) or in the context of individual marketing campaigns (e.g. events, competitions, etc.). You may refuse such contacts or revoke your consent to be contacted for advertising purposes by notifying us at any time. With your consent, we can tailor our online advertising on the Internet more specifically to you. This also includes interaction with existing customers and their contacts, which can be personalised based on behavioural and preference data. In the context of relationship management, we may also operate a customer relationship management (CRM) system in which we store the data of guests, other customers and other business partners. In particular, we process communication, registration, behavioural and preference data for marketing and relationship maintenance purposes.
  • Market research, improvement of our services and operations, and product development: In order to continuously improve our products and services (incl. our website) and to be able to react promptly to changing requirements, we analyse information such as how you navigate our website, which products are used by which groups of people in which way, and how new products and services can be designed. This gives us insights into the market acceptance of existing products and services and the market potential of new ones. For this purpose, we process in particular master data, behavioural and preference data, as well as communication data, information from customer questionnaires, surveys and studies, and other information, for example in the media, on social media, from the Internet and from other public sources. To the extent reasonably practicable, we use pseudonymised or anonymised information for these purposes.
  • Registration and security purposes as well as technical and physical access controls: In order to use certain services (e.g. WLAN), you must register (via our external login service providers “SWISSCOM”); your data will be processed for this purpose. We continuously monitor and improve the security of our IT. We therefore process data for the purposes of monitoring, checking, analysing and testing our networks and IT infrastructure, for system and error checks, for documentation purposes, and for the production of backups. For security purposes (preventive and to investigate incidents), we also keep access logs and guest lists and use surveillance systems (e.g. security cameras). Appropriate signs at the respective locations indicate the presence of surveillance systems. For this purpose, we process in particular registration and technical data, but also other data mentioned above.
  • Risk management and business management: We may process personal data in the context of risk management (e.g. to protect against criminal activities). We process in particular master data, booking data, registration data and technical data, as well as behavioural and communication data.
  • Job applications: If you apply for a job with us, we collect and process the information we need to check the application, carry out the application process and, in the case of a successful application, prepare and conclude the contract. For this purpose, we in particular process master data and application data.

7. PROFILING

Profiling is a procedure in which personal data is automatically processed in order to analyse personal aspects or make predictions (e.g. to analyse the personal interests, preferences and inclinations of a person or to predict probable behaviour). For example, we conduct profiling in connection with booking on our website (e.g. in order to determine which other services could be of interest to you based on your booking). In particular, we use behavioural and preference data, technical data and communication data (e.g. your reaction to advertising and other messages). Profiling helps us continuously improve our products and services and better adapt them to your specific requirements, plan our business activities, determine the likelihood that a transaction is fraudulent and assist you more effectively through our customer service.


8. WITH WHOM DO WE SHARE YOUR DATA?

In connection with our contracts, the website, our services and products, our legal obligations, the enforcement of our legitimate interests and the other purposes, we share your personal data with third parties, and in particular the following categories of recipients:

  • Service providers: We work with service providers in Switzerland and abroad (third parties) that process data about you (i) on our behalf, (ii) jointly with us or (iii) process data that they have received from us on their own authority (e.g. IT providers, advertising service providers, security companies, banks, insurance companies,).
  • Authorities: We may share personal data with government agencies, courts and other authorities (such as the cantonal aliens department) in Switzerland or abroad if we are legally obliged or entitled to do so or this appears necessary to enforce our interests. The recipients are responsible for their processing of the data.
  • Other people: When we work with media and share material with them (e.g. photos), you may also be affected. We may also share data concerning you in the context of communications with our competitors, industry organisations, associations and other bodies.

All of these categories may in turn also involve third parties, thus making your data accessible to them as well. We can restrict processing by certain third parties (e.g. IT providers), but not by other third parties (e.g. authorities, etc.).


9. IS YOUR PERSONAL DATA TRANSFERRED TO OTHER COUNTRIES?

We may internationally transfer your personal data, including to countries that are not considered providing an adequate level of data protection by the relevant regulatory bodies, for example to countries not considered by the European Commission or the Swiss Federal Data Protection and Information Commissioner to be providing such level. In such a case, we ensure the adequate protection of your personal data by having the recipients adhere to binding contractual obligations in accordance with applicable standards approved by the relevant regulatory bodies or by relying on other safeguards, such as self-certifications, approved by the relevant regulatory bodies.


10. PARTNERS’ WEBSITES AND NETWORKS.

This Website may contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that they have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.


11. FOR HOW LONG DO WE PROCESS YOUR DATA?

We process your personal data:

  • until you withdraw your consent for future processing, for example until you unsubscribe from our newsletter or delete your account with us;
  • until we are sure that you are satisfied after you have approached us, e.g. to ask a question, to request information, to make a reservation;
  • in connection with a booking you make or in connection with a customer service transaction for the time until the appointment is completed plus at least three month to which we may add a grace period for your benefit, unless we can rely on another justification, have informed you otherwise or you have given your consent for a longer retention period;
  • for as long as you remain our business partner plus ten years, unless we can rely on another justification, have informed you otherwise or you have given your consent for a longer retention period;
  • for as long as laws require us, e.g. legal retention obligations based on bookkeeping or tax laws and regulations.

Pending or expected legal proceedings may result in processing extending beyond this time period.


12. HOW DO WE PROTECT YOUR DATA?

We undertake appropriate security measures to maintain the confidentiality, integrity and availability of your personal data in order to protect it against unauthorised or illegal processing and to minimise the risk of loss, unintentional change, unwanted disclosure or unauthorised access. However, such security risks can generally not be entirely eliminated and a certain degree of residual risk is unavoidable.


13. WHAT ARE YOUR RIGHTS?

You have the right:

  • to request from us access to and rectification or deletion of your personal data;
  • to request the erasure of data;
  • to request us to restrict the processing of your personal data, in particular to object to the processing of your personal data for direct marketing purposes;
  • to request from us to provide you or any person or entity you appointed with a digital file of your personal data (data portability);
  • the right to revoke consent, insofar as our processing is based on your consent;
  • the right to obtain, on request, other information required to exercise these rights.

You may withdraw your consent that allows us to process your personal data for the indicated purposes at any time.

To exercise the above rights, you may contact us as indicated below.

You also have the right to lodge a complaint with the competent authority.

Under certain circumstances, the applicable data protection law grants you the right to object to the processing of your data, in particular processing for direct marketing purposes, profiling for direct advertising purposes and other legitimate interests in processing.

You also have these rights with respect to other entities that work with us on their own authority – please contact them directly if you wish to exercise rights in connection with their processing.


14. WHAT DATA DO WE PROCESS ON OUR PAGES ON SOCIAL NETWORKS?

We may operate pages aon social networks and other platforms operated by third parties and process the data collected about you there as described above and below. We receive this information from you and the platforms when you interact with us through our online pages (e.g. when you communicate with us, comment on our content or visit our pages). At the same time, the platform providers may analyse your use of our online pages (e.g. the way you interact with us, how you use our online pages, what you view, comment on or like) and process this data together with other data they have about you (e.g. information about your age and gender and other demographic information). In this way, they create profiles about you and generate statistics about the use of our online pages. They use the data and profiles to display our ads or other ads and other personalised content on the platform as well as to manage behaviour on the platform, but also for market and user research and to provide us and other parties with information about you and the use of our online pages. Insofar as we are jointly responsible for certain types of processing with the provider, we will conclude a corresponding contract with the provider. You can obtain information about the substantive content of this contract from the provider. They also process this data for their own purposes, in particular for marketing and market research purposes (e.g. to personalise advertising) and to manage their platforms (e.g. to decide what content they show you); for these purposes, they act as a separate data controller.

We are authorised, but not obliged, to check content before or after its publication on our online sites, to delete content without notice and to report it to the provider of the respective platform if appropriate. In the event of violations of codes of decency and conduct, we may also inform the provider of the platform on which the user account is located for the purpose of blocking or deleting it.

Further information on processing by the platform operators can be found in the privacy policies of the respective platforms. There you can also find out which countries your data is processed in, what rights of information and erasure you have and how you can exercise them or receive further information.


15. THIS PRIVACY POLICY AMENDMENT

This privacy policy is not part of a contract with you. We can modify this privacy policy at any time. The version published on this website is the current version.


16. HOW CAN YOU CONTACT US

For any questions or to exercise your rights, you may contact us as follows:

YOU Photo GmbH

Blegistrasse 7,

6340 Baar

Switzerland

E-Mail: you@youstudio.ch,


To exclude the possibility of misuse, we must establish your identity (e.g. with a copy of an identity document, if this is not possible by less intrusive means).