Privacy Policy

This privacy policy (the Privacy Policy) applies to the processing of personal data by DSS Sustainable Solutions Switzerland SA (CHE-371.503.138), Rue Pierre Fatio 15, c/o Gyrus Capital SA, 1204 Genève (DSS Sustainable Solutions, we, us or our) in connection with the SafetyTech Platform, accessible without limitation at www.safetytech.ai (the Platform).

By accessing and using the Platform, you expressly agree that we collect and process your personal data in accordance with this Privacy Policy.

We reserve the right to amend the Privacy Policy at any time at our sole discretion in order to adapt it to any new commercial or technological practice or change in the law. Should this occur, we will inform you by any appropriate means (including via email and/or the Platform). If you do not accept the amendments thus made by us, your sole remedy is to no longer access and/or use the Platform.

1. Introduction

We recognize the importance of your privacy and of transparency in our processing of your personal data. 

 
1.1 This Privacy Policy explains (i) which personal data are collected when you access and use the Platform, (ii) the manner and the purposes for which we process the personal data, and (iii) the measures which we take in order to protect such personal data.

We only process your personal data if we have a valid legal ground to do so.


1.2  We will only process your personal data if we have valid legal ground to do so, i.e. in any of the following situations:

-  we have obtained your prior unambiguous consent; 

-  the processing is necessary to perform our contractual obligations towards you or to take pre-contractual steps at your request;

-  the processing is necessary to comply with our legal or regulatory obligations; or

-  the processing is necessary for our legitimate interests except where they are overridden by your interests or fundamental rights and freedoms. Relevant ‘legitimate interests’ include: (i) to benefit from cost-effective services (e.g. we may opt to use certain platforms offered by suppliers); (ii) to protect the security of our IT systems, architecture and networks; and (iii) to meet our corporate and social responsibility objectives.

2. How and Where We Collect Your Personal Data

We collect the personal data which you provide.


2.1 We collect, directly or indirectly via our partners, the personal data you provide in your correspondence with us and/or our partners, or in your use of the Platform, for example, when creating and/or managing your account, though webforms you fill in or when you contact us via our chatbot.

2.2 Such information may include your name, address, email, telephone numbers, job title, business name, business address, industry, interests and any other information which we and/or our partners may request from you.

Certain personal data are also collected in an automated manner.


2.3 We may also automatically collect personal data when you access and use the Platform, including by means of tools, web forms, cookies and other active elements contained in our emails and/or those of our partners, such as the IP address or other user identifications on your devices, geolocation of your device, your browser settings preferences (e.g. languages).

You can define certain authorizations and settings related to the automated collection of your personal data.We collect the personal data which you provide.


2.4 You may define certain authorizations related to data collection, in particular in connection with the geolocation and your device’s right to access data contained in your device, according to the available functionalities.

2.5 You may also define certain settings for the automated collection of your personal data on your web browser or through the cookies setting plugin available on the Platform. For more detailed information, please consult the chapter on cookies below.

3. Processing Methods

We may process your personal data by automated means but take appropriate security measures in this respect.

 
3.1 We process your personal data in compliance with Swiss data protection law and the EU General Data Protection Regulation and namely take the appropriate technical and organizational security measures to prevent the unauthorized access, disclosure, modification, alteration or destruction of your personal data. Data processing is carried out with computers or computer tools, and in compliance with the purposes indicated in this Privacy Policy.

3.2 We may use your personal data to create a profile about you and provide you with more relevant information and services (profiling). You may have the right to object to such activities, in accordance with applicable data protection laws. We do not use any individual decision-making based solely on automated processing.

4. Purposes of Data Processing

We process your personal data to operate the Platform and to provide the related services.


4.1 Your personal data are collected so that we may operate the Platform and provide the services connected therewith, including for creating and maintaining a user profile, interacting with you, providing you with requested information and services, identifying your business interests and/or managing customer relationship, or in the manner expressly indicated when the personal data concerned are collected.

We may process your personal data for marketing and advertising purposes.


4.2 We may use your personal data, in particular, the contact details as well as other indications and data collected in accordance with this Privacy Policy, for marketing and advertising purposes, e.g. to send you information and offers relating to our products and services and/or of our partners, such as prospectuses, newsletters, and other advertising messages. You may withdraw your consent at any time.

We may process your personal data for statistical and planning purposes.


4.3 Notably without limitation, we process your personal data to improve the Platform or its products and services, and for internal analyses and statistics. You may withdraw your consent at any time.

5. How long do we store your Personal Data?

We will not retain your personal data for a longer period than necessary for the purposes as outlined in this Privacy Policy. If you suppress your user account, we will delete your personal data within 30 days after such event, unless data must be retained for a valid reason.

6. Communication to Third Parties

We may disclose your personal data to third parties in case this is necessary for the proper operation of the Platform and the provision of the related services, or for promotional services.


6.1 We may communicate your personal data to third parties as part of operating the Platform, and to subcontractors such as IT systems providers, cloud service providers, database providers, automated marketing solutions providers and consultants, including Amazon Web Services and/or Microsoft Azure (hosting services), Krish TechnoLabs (website maintenance and technical support services), SalesForce (database services), Contentim, Oracle Eloqua, Microsoft Dynamics (marketing and customer relationship), Haptik (chatbot provider), Magento and/or Braintree (financial services / payments providers) and TrustArc (cookies management).

6.2 We may also enable you to use third-party services directly from the Platform, namely through social plug-ins of Google Maps, Kaltura video streaming and Google Analytics, in which case you recognize that the third-party operators of these services may access some of your personal data in connection with the Platform.

6.3 In the above contexts, the Platform may contain links to other websites. Please note that this Privacy Policy does not apply to the practices of any company or individual that we do not control, nor to any other website that may be linked from the Platform. You should carefully review the privacy policies of any other website that you visit from the Platform to learn more about their information and privacy practices. In such contexts, the collection and use of your personal data shall be governed by such other party or websites’ privacy policy. We shall not be held responsible for their privacy practices.

We may also disclose your personal data to third parties when we have a legitimate interest to do so.


6.4 We may also disclose your personal data when we have a legitimate interest to do so, for instance to (i) any third party to whom we assigns or transfers any of our rights or obligations; (ii) to competent courts or supervisory or regulatory bodies, when we must compellingly disclose your personal data, pursuant to any applicable law, regulation or order.

7. International Transfers

Your personal data may be disclosed outside of your country of residence, including to countries that do not guarantee the same level of data protection and privacy as Switzerland and the European Union.

 
7.1 The personal data that we collect from you may be stored and processed in your region, or transferred to, stored at or otherwise processed outside your country of residence, including, in respect of residents of a country within the European Economic Area (the “EEA”) or Switzerland, in a country outside the EEA or Switzerland, including without limitation the U.S. and/or India, or any other country which do not necessarily offer an adequate level of data protection as recognized by the European Commission or Switzerland. Your personal data may also be processed by staff operating inside or outside your country of residence, including staff located outside of the EEA or Switzerland, who work for us or our service providers.

7.2 Where we transfer your Personal Data outside the EEA or Switzerland, we will ensure that suitable safeguards are in place to help ensure that our third party service providers provide an adequate level of protection to your Personal Data, for instance by relying on the EU-U.S. Privacy Shield Framework, the Swiss-U.S. Privacy Shield Framework, or on standard contractual clauses adopted by the European Commission.

7.3 You may request additional information in this respect and obtain a copy of the relevant safeguards upon request through sending a request to the contact indicated section 11 below.

8. Security

We maintain physical, technical and procedural safeguards to keep secure your personal data.


8.1 We are committed to the security of your personal data, and have in place physical, administrative and technical measures designed to keep secure your personal data and to prevent unauthorized access to it. We restrict access to your personal data to those persons who need to know it for the purpose described in this Privacy Policy. In addition, we use standard security protocols and mechanisms to exchange the transmission of sensitive data. When you enter sensitive information on our site, we encrypt it using secure socket layer (SSL) technology.

8.2 Although we take appropriate steps to protect your personal data, no website is completely secure. Therefore, we cannot guarantee that data you provide to us is safe and protected from all unauthorized third-party access and theft. We waive any liability in this respect.

8.3 The internet is a global environment. As a result, by sending information to us electronically, such data may be transferred internationally over the internet depending upon your location. Internet is not a secure environment and this Privacy Policy applies to your use and disclosure of your personal data once it is under our control only. Given the inherent nature of the internet, all internet transmissions are done at your own risk.

8.4 If we have reasonable reasons to believe that your personal data have been acquired by an unauthorized person, and applicable law requires notification, we will promptly notify you of the breach by email (if we have it) and/or by any other channel of communication (including by posting a notice on the Platform).

9. Cookies and Similar Technologies

We use cookies and other similar technologies in connection with the Platform.


9.1 A cookie is a small data file that we transfer to and is stored on your electronic device. For example, we use cookies or other analytics tools to measure the traffic to and usage of the Platform and their distinctive features, and other miscellaneous uses.

9.2 We use various types of cookies or other similar technologies some of which are likely to automatically process data directly on your devices and/or to transfer data personal concerning you to us.

You may manage the cookies and similar technologies via the settings of your browser and/or your devices, as well as through the interface available on the Platform.


9.3 If you do not want cookies to be stored on your device, you can configure your browser or your device to refuse and/or restrict the cookies. You may also change your cookies preferences through the interface available on the Platform. Certain cookies are however essential to the functioning of the Platform itself and its use may be altered or prevented by refusing these cookies.

9.4 For more information, please visit http://www.allaboutcookies.org/fr/. Please check the user help sections of your internet browser or electronic devices for specific instructions on the management of cookies.

Why and how we use cookies and other similar technologies?


9.5 These technologies are generally aimed at monitoring and analyzing your interactions with the Platform and/or to enable us to improve the Platform and their functionalities, namely through a personalization of the Platform and the related services, according to your interactions. We also use cookies and similar technologies to measure and monitor the traffic and use of the Platform, as well as its performance.

9.6 Some cookies are retained in your electronic device for only as long as you access and use the Platform, while others persist for a longer specified or unspecified period.

We use the following cookies:


Essential cookies

9.7 Some cookies we place on your electronic device ensure that the Platform delivers you without limitation information securely and optimally. The Service/website cannot function properly without these Cookies.

Cookie

Stored / processed data

Expiry

Description

CURRENCY

 Magento

Persistent

Representation of the user preferred currency

EXTERNAL_NO_CACHE

Magento

Persistent

A flag, which indicates whether caching is disabled or not.

FRONTEND

Magento

Persistent

Representation of the user session ID on the server.

STORE

Magento

Persistent

Representation of the store view or language selected by the user

USER_ALLOWED_SAVE_COOKIE

Magento

Persistent

Indicates whether a user allowed the use of cookies.


Functionality cookies

9.8 Some cookies enable the Platform to remember choices persons make, for example, user name, and language or text size. These cookies are known as "functionality cookies" and help to improve a person's experience of the Platform by providing a more personalized service.

Cookie

Stored / processed data

Expiry

Description

CART

Magento

Persistent

A representation of the user shopping cart.

CATEGORY_INFO

Magento

Persistent

Stores the category info on the page, that allows to display pages more quickly.

COMPARE

Magento

session

The items that user have in the Compare Products list.

CUSTOMER

Magento

Persistent

An encrypted version of your user id with the store.

CUSTOMER_AUTH

Magento

session

An indicator if the user is currently logged into the store.

CUSTOMER_SEGMENT_IDS

Magento

Persistent

Stores the user Segment ID / catogory

GUEST-VIEW

Magento

session

Allows customers to edit their orders.

NEWMESSAGE

Magento

Persistent

Indicates whether a new message has been received.

NO_CACHE

Magento

Persistent

Indicates whether it is allowed to use cache.

PERSISTENT_SHOPPING_CART

Magento

session

A link to information about the user cart and viewing history if users have requested from the site.

 
Advertising cookies

9.9 These cookies are used to better understand customer interests and to display more relevant advertisements.

Cookie

Stored / processed data

Expiry

Description

_ga

Google Analytics

Persistent

Used to distinguish users.

_gid

Google Analytics

Persistent

Used to distinguish users.

_gat

Google Analytics

Persistent

Used to throttle request rate. If Google Analytics is deployed via Google Tag Manager, this cookie will be named _dc_gtm_ .

__utma

Google Analytics

Persistent

Used to distinguish users and sessions. The cookie is created when the javascript library executes and no existing __utma cookies exists. The cookie is updated every time data is sent to Google Analytics.

__utmc

Google Analytics

Session

Not used in ga.js. Set for interoperability with urchin.js. Historically, this cookie operated in conjunction with the __utmb cookie to determine whether the user was in a new session/visit.

__utmz

Google Analytics

Session

Stores the traffic source or campaign that explains how the user reached your site. The cookie is created when the javascript library executes and is updated every time data is sent to Google Analytics.

CUSTOMER_INFO

Magento

Persistant

 

An encrypted version of the user group they belong to.

LAST_CATEGORY

Magento

Session

The last category the user visited.

LAST_PRODUCT

Magento

Session

The most recent product the user have viewed.

POLL

Magento

Session

The ID of any polls the user have recently voted in.

POLLN

Magento

Session

Information on what polls the user have voted on.

RECENTLYCOMPARED

Magento

Session

The items that the user have recently compared.

STF

Magento

Session

Information on products the user have emailed to friends.

VIEWED_PRODUCT_IDS

Magento

Session

The products that the user have recently viewed.

WISHLIST

Magento

Session

An encrypted list of products added to the user Wishlist.

WISHLIST_CNT

Magento

session

The number of items in the user Wishlist.

eloqua.com

 

Oracle

session

Oracle Eloqua cookies help identify the user as a website visitor according to their specific browser and computer combination in the event that they return to this domain.

linkedin.com

LinkedIn

Session

Collects Anonymous data (Ad Views, Browser Information, Cookie Data , Hardware/Software Type, Internet Service Provider, Interaction Data , Page Views , Serving Domains)


10. Your Rights

You have the right to access your personal data processed by us and may request without limitation that they be removed, updated, or rectified.


10.1 Except as otherwise required by law, you are entitled at all times to know if we are processing personal data concerning you. You may contact us to know the content of such personal data, verify their accuracy and request that they be supplemented, removed, updated, or rectified. You also have the right to ask us to cease processing any personal data that may have been obtained in breach of applicable law, and to object to the processing of your personal data for any other legitimate reason.

10.2 By accessing your user account (if any), you can review, update, correct or delete the personal data available within your user account. If you would like us to delete your personal data from our system, please send a request pursuant to the contact details below and your request will be accommodated unless we have a legal obligation to retain the record. Please note that any information that we have copied may remain in back-up storage for some period of time after your deletion request.

10.3 Where we rely on your consent to process your personal data, we will seek your freely given and specific consent by providing you with informed and unambiguous indications relating to your personal data. You may revoke at any time such consent.

10.4 You have also the right to request your personal data’s portability, i.e. that the personal data you have provided to you be returned to you or transferred to the person of your choice, in a structured, commonly used and machine-readable format without hinderance from us and subject to our confidentiality obligations.

You have the right to lodge a complaint.


10.5 If you are not satisfied with how we process your personal data, you may file a complaint with the competent supervisory authority, in addition to your rights outlined above.

11. Contact

We have appointed a Chief Privacy Officer. If you believe your personal data has been used in a way that is not consistent with this policy, or if you have any questions or a request in relation to the processing of your personal data by us, please contact us at Dell Joshi or privacy@consultdss.com.


Last updated on: 08 June, 2020