Privacy Policy

This Privacy Notice describes how your personal data is processed when you visit and use this website.

This Privacy Policy has been machine-translated. In case of doubt, the original German version shall prevail.

With this Privacy Policy we inform about the processing of personal data in connection with our activities and operations, including our website at the domain name act-4-children.org. We inform in particular about what personal data we process, for what purpose, in what manner, and where. We also inform about the rights of individuals whose data we process.

This Privacy Policy has been written in German. In the event of publication in another language, the German-language Privacy Policy shall prevail.

For individual or additional activities and operations, we may publish further privacy policies or other information on data protection.

We are subject to Swiss law and, where applicable, foreign law, in particular that of the European Union (EU) with the European General Data Protection Regulation (GDPR).

The European Commission recognized by decision of 26 July 2000 that Swiss data protection law ensures an adequate level of data protection. The European Commission confirmed this adequacy decision by report of 15 January 2024.

 

1. Contact Details

The data controller in the sense of data protection law is:

ACT for Children Foundation
Mühlebachstrasse 2
8024 Zurich
Switzerland

info@act-4-children.org

In individual cases, third parties may be responsible for the processing of personal data, or joint responsibility with third parties may exist. We are happy to provide affected individuals with information about the respective responsibilities upon request.

 

2. Definitions and Legal Basis

2.1 Definitions

Data Subject: A natural person about whom we process personal data.

Personal Data: All information relating to an identified or identifiable natural person.

Sensitive Personal Data: Data on trade union, political, religious or philosophical views and activities; data on health, the intimate sphere, or membership of an ethnic group or race; genetic data; biometric data that uniquely identify a natural person; data on criminal or administrative sanctions or proceedings; and data on social welfare measures.

Processing: Any handling of personal data, regardless of the means and procedures applied, such as querying, matching, adapting, archiving, storing, reading, disclosing, obtaining, recording, collecting, deleting, making accessible, organizing, saving, modifying, distributing, linking, destroying, and using personal data.

European Economic Area (EEA): Member States of the European Union (EU) as well as the Principality of Liechtenstein, Iceland, and Norway.

2.2 Legal Basis

We process personal data in accordance with Swiss law, in particular the Federal Act on Data Protection (FADP) and the Ordinance on Data Protection (ODP).

Where and to the extent that the European General Data Protection Regulation (GDPR) is applicable, we process personal data based on at least one of the following legal bases:

  • Art. 6(1)(b) GDPR for the processing necessary for the performance of a contract with the data subject and for pre-contractual measures.
  • Art. 6(1)(f) GDPR for the processing necessary to pursue legitimate interests – including those of third parties – unless the fundamental freedoms, rights, and interests of the data subject override such interests. Such interests include in particular the sustainable, user-friendly, secure, and reliable conduct of our activities, ensuring information security, protection against misuse, enforcement of our own legal claims, and compliance with Swiss law.
  • Art. 6(1)(c) GDPR for the processing necessary to comply with a legal obligation under applicable law of EEA member states.
  • Art. 6(1)(e) GDPR for the processing necessary for the performance of a task carried out in the public interest.
  • Art. 6(1)(a) GDPR for the processing of personal data with the consent of the data subject.
  • Art. 6(1)(d) GDPR for the processing necessary to protect the vital interests of the data subject or another natural person.
  • Art. 9(2) et seq. GDPR for the processing of special categories of personal data, in particular with the consent of the data subjects.

The GDPR refers to the processing of personal data as “processing of personal data” and the processing of sensitive personal data as “processing of special categories of personal data” (Art. 9 GDPR).

 

3. Nature, Scope, and Purpose of Processing Personal Data

We process only those personal data that are necessary to conduct our activities and operations in a sustainable, user-friendly, secure, and reliable manner. The personal data processed may fall in particular into the following categories: browser and device data, content data, communication data, metadata, usage data, master data including inventory and contact data, location data, transaction data, contract data, and payment data. The personal data may also constitute sensitive personal data.

We also process personal data that we receive from third parties, obtain from publicly accessible sources, or collect in the course of our activities and operations, to the extent that such processing is permitted.

We process personal data, where required, with the consent of the data subjects. We may process personal data in many cases without consent, for example to fulfil legal obligations or to protect overriding interests. We may also ask data subjects for their consent where their consent is not strictly required.

We process personal data for the duration required for the respective purpose. We anonymize or delete personal data in particular in accordance with applicable statutory retention and limitation periods.

 

4. Automation and Artificial Intelligence (AI)

We may process personal data in an automated manner or use artificial intelligence for the processing of personal data.

We may use profiling to automatically evaluate certain personal aspects relating to data subjects. Profiling is used, for example, to analyze or predict interests, behaviors, or personal preferences.

In individual cases, we will inform data subjects about decisions based solely on automated processing of personal data that have legal consequences for them or significantly affect them (automated individual decisions).

 

5. Disclosure of Personal Data

We may disclose personal data to third parties, have it processed by third parties, or process it jointly with third parties. Such third parties may include, for example, specialized service providers whose services we use. These third parties may in turn disclose personal data to further third parties.

In the course of our activities and operations, we may disclose personal data in particular to banks and other financial service providers, authorities, educational and research institutions, consultants and lawyers, accounting and fiduciary service providers, debt collection agencies, interest groups, IT service providers, cooperation partners, credit and business information agencies, logistics and shipping companies, marketing and advertising agencies, media, parent, sister and subsidiary companies, organizations and associations, social institutions, telecommunications companies, insurance providers, and payment service providers.

 

6. Communication

We process personal data in order to communicate with individuals as well as with authorities, organizations, and companies. In doing so, we process in particular data that a data subject transmits to us when making contact, for example by mail or email. We may store such data in an address book or similar tools.

Third parties who transmit data about other individuals to us are legally obligated to ensure data protection for those affected individuals on their own responsibility. They must in particular ensure that they are authorized to transmit such data and that the data transmitted is accurate.

 

7. Data Security

We implement appropriate technical and organizational measures to ensure a level of data security appropriate to the respective risk. Our measures ensure in particular the confidentiality, availability, traceability, and integrity of the personal data processed, without being able to guarantee absolute data security.

Access to our website and other digital presence is secured via transport encryption (SSL / TLS, in particular via the Hypertext Transfer Protocol Secure, abbreviated HTTPS). Most browsers warn before visiting a website without transport encryption.

Our digital communication is subject – as is fundamentally all digital communication – to mass surveillance without cause or suspicion by security authorities in Switzerland, the rest of Europe, the United States of America (USA), and other countries. We cannot directly influence the corresponding processing of personal data by intelligence services, police agencies, and other security authorities. We also cannot exclude the possibility that a data subject is specifically monitored.

 

8. Personal Data Abroad

We process personal data primarily in Switzerland and the European Economic Area (EEA). However, we may also export or transfer personal data to other countries, in particular in order to process or have it processed there.

We may export personal data to all countries on earth and elsewhere in the universe, provided that the applicable law there ensures adequate data protection in accordance with a decision of the Swiss Federal Council and – where the GDPR is applicable – also in accordance with a decision of the European Commission.

We may transfer personal data to countries whose law does not ensure adequate data protection, provided that data protection is ensured for other reasons, in particular on the basis of standard contractual clauses or other appropriate safeguards. Exceptionally, we may export personal data to countries without adequate or appropriate data protection if the special data protection conditions are met, for example the explicit consent of the data subjects or a direct connection with the conclusion or execution of a contract. We are happy to provide data subjects with information about any applicable guarantees or to supply a copy thereof upon request.

 

9. Rights of Data Subjects

9.1 Data Protection Rights

We grant data subjects all rights to which they are entitled under applicable law. Data subjects have in particular the following rights:

  • Access: Data subjects may request information as to whether we are processing personal data about them, and if so, what data. Data subjects also receive the information necessary to assert their data protection rights and to ensure transparency. This includes the personal data itself, as well as information on the purpose of processing, the duration of storage, any disclosure or export of data to other countries, and the origin of the personal data.
  • Rectification and Restriction: Data subjects may have inaccurate personal data corrected, incomplete data completed, and the processing of their data restricted.
  • Right to Express Own Viewpoint and Human Review: Data subjects may, in the case of decisions based solely on automated processing that have legal consequences for them or significantly affect them (automated individual decisions), express their own point of view and request review by a human.
  • Deletion and Objection: Data subjects may request the deletion of their personal data (“right to be forgotten”) and object to the processing of their data with effect for the future.
  • Data Portability and Transfer: Data subjects may request the release of personal data or the transfer of their data to another controller.

We may defer, restrict, or refuse the exercise of data subjects’ rights within the legally permissible scope. We may refer data subjects to conditions that may need to be met to exercise their data protection rights. For example, we may refuse access in whole or in part with reference to confidentiality obligations, overriding interests, or the protection of other individuals. We may, for example, also refuse the deletion of personal data in whole or in part, in particular with reference to statutory retention obligations.

In exceptional cases, we may charge fees for the exercise of rights. We will inform data subjects in advance of any applicable fees.

We are required to identify data subjects who request information or assert other rights by appropriate means. Data subjects are obliged to cooperate.

9.2 Legal Redress

Data subjects have the right to enforce their data protection rights through legal channels or to file a complaint with a data protection supervisory authority.

The data protection supervisory authority for private controllers and federal bodies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).

European data protection supervisory authorities are organized as members of the European Data Protection Board (EDPB). In some EEA member states, data protection supervisory authorities are federally structured, particularly in Germany.

 

10. Use of the Website

10.1 Cookies

We may use cookies. Cookies – both our own (first-party cookies) and those from third parties whose services we use (third-party cookies) – are data stored in the browser. Such stored data is not necessarily limited to traditional text-form cookies.

Cookies may be stored in the browser temporarily as “session cookies” or for a specified period as “persistent cookies”. Session cookies are automatically deleted when the browser is closed. Persistent cookies have a defined storage duration. Cookies enable in particular the recognition of a browser on the next visit to our website, thereby allowing, for example, the measurement of our website’s reach. Persistent cookies may also be used for online marketing, for example.

Cookies can be disabled, restricted, or deleted in whole or in part at any time via browser settings. Browser settings often also allow automated deletion and other management of cookies. Without cookies, our website may no longer be fully available. We actively request – at minimum where and to the extent required by applicable law – explicit consent to the use of cookies.

10.2 Server Log Files

For each access to our website and other digital presence, we may log at least the following information, provided that it is routinely determined or transmitted to our digital infrastructure during such access: date and time including time zone, IP address, access status (HTTP status code), operating system including user interface and version, browser including language and version, individual sub-page of our website accessed including the amount of data transferred, last webpage visited in the same browser window (referrer).

We store such information, which may also constitute personal data, in log files. This information is necessary to be able to provide our digital presence in a sustainable, user-friendly, and reliable manner. It is also necessary to ensure data security – including through or with the assistance of third parties.

10.3 Tracking Pixels

We may integrate tracking pixels (also referred to as web beacons) in our digital presence. Tracking pixels – including those from third parties whose services we use – are typically small, invisible images or scripts formulated in JavaScript that are automatically retrieved when accessing our digital presence. Tracking pixels can capture at least the same information as server log file recording.

 

11. Third-Party Services

We use services from specialized third parties to be able to conduct our activities and operations in a sustainable, user-friendly, secure, and reliable manner. Through such services, we may among other things embed functions and content into our website. When embedding such content, the services used capture at least temporarily, for technical reasons, the IP addresses of users.

For necessary security-related, statistical, and technical purposes, third parties whose services we use may process data in connection with our activities and operations in aggregated, anonymized, or pseudonymized form – for example, performance or usage data to provide the respective service.

11.1 Digital Infrastructure

We use services from specialized third parties to access the digital infrastructure required in connection with our activities and operations. This includes, for example, hosting and storage services from selected providers.

We use in particular:

11.2 Digital Content

We use services from specialized third parties to embed digital content in our website. Digital content includes in particular images and video material, music, and podcasts.

We use in particular:

12. Website Extensions

We use extensions for our website to enable additional functions. We may use selected services from suitable providers or deploy such extensions on our own digital infrastructure.

We use in particular:

  • WP Armour: Bot protection (distinguishing between desired human activity and undesired bot activity); Developer: Dinesh Karki (USA); Privacy information: Used on own digital infrastructure and without cookies.

 

13. Final Notes on This Privacy Policy

We may update this Privacy Policy at any time. We will inform about updates by publishing the current version of the Privacy Policy on our website.