Skip to main content

Promethiem

Privacy Policy

Promethiem AG, a limited company with registered address at Erlenweg 6, 6312 Steinhausen (“Promethiem”, “We”, “Our”), are committed to ensuring that your privacy is protected. We act as the controller of the data processing described in this Privacy Policy and responsible for your personal data. We are committed to ensuring that your privacy is protected. This Privacy Policy describes how we collect, store, share and make use of the personal information you give the company when you use this website. When used in this Privacy Policy: ‘Personal information’ is defined as any information relating to an identified or identifiable individual. It does not include data where the identity has been removed (anonymous data). If you are asked to provide personal information when using this website, it will only be used in the ways described in this Privacy Policy. This website Privacy Policy was last updated on August 11th 2026. This policy may be updated from time to time. The latest version is published on this page.

Personal information we collect about you

We may gather and use certain information in order to enable certain functions on this website. We may also collect activity information to better understand how visitors use this website and to present timely, relevant information to them.

We may collect the following personal information about you:

• Website usage data (e.g. browsing history, activity logs, logfiles);
• Online identifiers (e.g. IP address, cookie identifiers, device identifiers, terminal ID);
• Communication data (e.g. information relevant to client enquiries, e-mail exchanges);
• Contact details (e.g. names, email address and phone number);
• Marketing and Communications Data: includes your preferences in receiving marketing from us and our third parties and your communication preferences.

Collecting this information helps us understand what you are looking for from the company and enabling us to deliver improved services.
There is no obligation to provide your personal data. However, please note that our website may not work properly if you do not provide the required data strictly necessary for performing the contract between you and us.

How is your data collected

We use different methods to collect data from and about you including through:

• Your interactions with us. You may give us your personal data by filling in online forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:

• Request marketing to be sent to you;
• Give us feedback or contact us.


• Automated technologies or interactions. As you interact with our website, we will automatically collect some technical data about your equipment, browsing actions and patterns. We collect this personal data by using cookies and other simmilar technologies.



Specifically, we may use data:

• For our own internal records;
• To contact you in response to a specific enquiry;
• To customise the website for you;
• To contact you via email, telephone or mail for market research reasons.

How and why we use your personal information

Under data protection law, we can only use your personal information if we have a proper reason for doing so, e.g.:

• To comply with our legal and regulatory obligations (to notify you about changes to our services and our Privacy Policy, to comply with applicable regulations and legislation and for the legal enforcement of claims and rights);
• To perform our contractual obligations (to provide you with our services and improve them, to provide and manage you access to the website and its functionalities, as well as to personalise them to your preferences, as well as to authenticate you and provide secure access to your account, to provide you with customer support and respond to your inquiries submitted through our website or other electronic means);
• For our legitimate interests or those of a third party (to detect, prevent, and address security threats related to the website, to place essential cookies and other tools on your browser that are technically necessary for our services, to collect and analyse your feedback to improve our website and user experience, to enforce the terms and conditions of the Website and protect against fraudulent activities); or
• Where you have given consent (to contact you, to provide users with news, special offers, newsletters, and general information about goods and services which we offer, to display personalised advertisements based on your preferences, location and browsing behaviour, to analyse, improve, personalise and monitor the usage of our website and communications, to place non-essential cookies and other tools on your browser).

Who we share your personal information with

We engage third-party companies ("Service Providers") to facilitate the operation of our services, assist in analysing the usage of our services, or perform necessary services, such as the provision of IT infrastructure. These third parties have access to your personal data only to the extent necessary to perform these tasks.

Type(s) of Service Providers who might access your personal data:

• Companies within the Promethiem group of companies;
• Third parties we use to help deliver our products and/or services to you;
• Professional advisers that we use, such as accountants and lawyers;
• Social media platforms;
• Hosting and cloud service providers and other third-parties providing IT software services;
• Other third parties we use to help us run our business (e.g. marketing agencies or website hostsclient insights tools).

Transferring your personal information out of the EEA

To deliver services to you, it is sometimes necessary for us to share your personal information outside the European Economic Area (EEA), e.g.:

• With your and our Service Providers located outside the EEA;
• If you are based outside the EEA; and
• Where there is an international dimension to the services we are providing to you.

These transfers are subject to special rules under European and Swiss data protection law.

We may use service providers partly located in so-called third countries (outside the European Union or the European Economic Area or Switzerland) or process personal data there, i.e. countries whose level of data protection does not correspond to that of the EU or Switzerland.

We safeguard your personal data per our contractual obligations and applicable data protection legislation when transferring data abroad.

Such safeguards may include:

• The transfer to countries where there is an adequacy decision by the European Commission in place;
• Applying standard data protection model clauses, binding corporate rules or other standard contractual obligations that provide appropriate data protection.
• If a third country transfer takes place and there are no adequacy decision or appropriate safeguards, it is possible and there is a risk that authorities in the third country (e.g. intelligence services) can gain access to the transferred data and that the enforceability of your data subject's rights cannot be guaranteed.
• If you would like further information please contact our Data Protection Officer (see ‘How to contact us’ below).

Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

Data Retention

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, or other requirements.

In some circumstances you can ask us to delete your data: see below for further information.

Your Rights

You have the following rights in relation to your personal information:

Access - The right to request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it;
Rectification - The right to require us to correct any mistakes in your personal information;
Erasure - The right to require us to delete or remove personal data where there is no good reason for us continuing to process it, in certain situations;
Restriction of processing - The right to require us to restrict processing of your personal information, in certain circumstances (e.g. if you contest the accuracy of the data);
Data Portability - The right to receive the personal information you provided to us, in a structured, commonly used and machine-readable format and/or transmit that data to a third party – in certain situations;
Objection - The right to object:

• at any time to your personal information being processed for direct marketing (including profiling);
• in certain other situations to our continued processing of your personal information (e.g. processing carried out for the purpose of our legitimate interests).
• We will abide by your request unless we have a compelling legal basis for the processing which overrides your interests or if we need to continue to process the personal data for the exercise or defence of a legal claim.

Withdraw Consent - The right to withdraw consent where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out prior to you withdrawing your consent.
Right to lodge a complaint with a supervisory authority - You have the right of appeal to a data protection supervisory authority if you believe that the processing of your personal data violates data protection law. The competent data protection authority in Switzerland is the Federal Data Protection and Information Commissioner (Click here). In the EU and EEA, you can exercise this right, for example, before a supervisory authority in the Member State of your residence, your place of work or the place of the alleged infringement. You can find a list of the relevant authorities here.

If you would like to exercise any of these rights, please:

• Email: legal@promethiem.com; and
• Provide us with enough information to identify you (e.g. your full name, address);
• Provide us with proof of your identity and address (e.g. a copy of your driving licence or passport and a recent utility or credit card bill); and

Let us know which right you want to exercise and the information to which your request relates.