This privacy policy explains how we handle your personal data, i.e. what we do with your data and how and why we do so. It applies to all users of the Takt platform (also referred to below as “digital offerings”).
Processing personal data is complex, especially where companies such as ours cooperate in the digital sphere on a division-of-labour basis. Our aim in this privacy policy is to explain as simply as possible what we do with your data, how we do it and why. If you nevertheless have further questions about our data processing, you are welcome to contact us (section 14).
We have aligned this privacy policy not only with the Swiss Data Protection Act (DPA), but also with the European General Data Protection Regulation (GDPR), which sets global standards for robust data protection. Whether and to what extent the GDPR applies, however, depends on the individual case.
Every processing operation has a “controller”, i.e. a company that is primarily responsible for compliance with data protection law. This is the company that determines whether processing takes place, the purposes it serves and how it is carried out.
The following company (“we” or “us”) is responsible under data protection law for the processing described in this privacy policy:
Please note that any third-party offerings accessible through our digital offerings are not subject to this privacy policy. We accept no responsibility or liability for third-party websites’ compliance with data protection requirements and recommend consulting their privacy policies.
Personal data means all information relating to, or capable of being associated with, an identified or identifiable person. The following describes the main categories of personal data we process. Section 4 explains where that data comes from and section 5 explains the purposes for which we process it.
Depending on the individual case, we may also need or wish to process additional personal data. Where legally required, we will inform you accordingly, for example in consent declarations or supplementary privacy policies.
Master data is basic information such as name, contact details or date of birth. We collect master data particularly when you register for a digital offering, enter into a contract with us or subscribe to a newsletter. Some information is marked or technically configured as mandatory; you may often provide further personal data voluntarily.
Master data may include, for example:
Contract data is personal data arising in connection with the conclusion or performance of a contract. This includes, for example, information about entering into a contract, contractual services, claims and receivables, or customer satisfaction.
Contract data may include information about:
When we are in contact with you, for example when you contact customer service, we process the communication content exchanged and information about the type, time and place of communication. In certain situations, we may ask for proof of identity, for example when you exercise your data-subject rights (section 13).
Communication data may include:
Telephone calls with us may be recorded for education and training purposes; we will inform you at the beginning of the call. If you do not wish a call to be recorded, you may end it at any time and contact us by another means, for example email.
When you use our digital offerings or receive newsletters, we collect data about that use and, generally, your interaction with digital offerings.
If you have a user account, behavioural and transaction data may be attributed to your profile even when you are not logged in while using a digital offering.
We want to tailor the content and presentation of our digital offerings and advertising displayed through them as closely as possible to our customers. We therefore also process information about your interests and preferences. We may analyse behavioural and transaction data, whether personal or non-personal, together with other data, in order to draw conclusions about characteristics, preferences and likely behaviour. Further information on profiling is provided in section 9.
When you use our digital offerings, we collect certain technical data, such as your IP address or device ID. This includes logs recording use of our systems. We may assign your device (tablet, PC or smartphone) a unique identifier, for example by means of cookies and similar technologies, so that we can recognise it later.
We often receive personal data directly from you, for example when you submit data to us or communicate with us. We generally receive master, contract and communication data from you.
Providing
personal data is generally voluntary. However, we must collect and process
personal data required to perform a contractual relationship and related
obligations, or required by law, such as mandatory master and contract data.
If you
provide data about other persons, we assume you are authorised to do so and
that the data is correct. Please also ensure that those persons have
been informed about this privacy policy.
We may collect personal data about you ourselves or
automatically, particularly behavioural and transaction data and technical
data. We may also derive personal data from existing data, for example by
analysing behavioural and transaction data; derived data is often preference
data.
We may also receive personal data from other TX Group
companies, third parties with whom we work, persons communicating with us,
public authorities, credit agencies, banks, insurers, service providers and
public sources.
We process personal data for one or more purposes, in particular the purposes set out below.
We process personal data to communicate with you, answer enquiries, provide customer care, authenticate users, assure quality and provide training. We may personalise the content and timing of messages using behavioural, transaction and preference data.
We process personal data in connection with initiating, administering and performing contractual relationships, including your use of digital offerings and any agreed personalisation of services. This includes deciding whether and on what terms to enter into contracts, providing services and functions, billing, accounting, customer-satisfaction measurement, retention, IT-resource management, enforcement of claims and termination of contracts.
When you register and create a user account, you must provide certain personal data, such as email address, password and, depending on the offering, name, address, telephone number, date of birth, gender, newsletter preferences and language preferences. We use this data to operate and administer our digital offerings, check data for plausibility, establish, perform and amend contractual relationships through your account, and issue invoices for paid services.
We process personal data for relationship-management and marketing purposes, including to send or display written and electronic communications and advertising concerning our own offerings, offerings of other TX Group companies or advertising partners. Communications and advertising may be personalised. You may refuse marketing contacts at any time; newsletters and other electronic communications normally include an unsubscribe link.
We process personal data to improve and develop our offerings, conduct user surveys and studies, assess acceptance and usability, test new offerings, improve internal processes, train employees, compile statistics and monitor markets. Where possible, we use pseudonymised or anonymised data.
We process personal data to ensure security and IT security, prevent fraud and misuse, investigate suspected misconduct, protect systems and assets, and preserve evidence.
We process personal data to comply with legal obligations, receive and handle complaints and reports, cooperate with authorities and investigations, meet disclosure, information, reporting and retention obligations, and enforce or defend legal claims before courts and authorities in Switzerland and abroad.
We process personal data for efficient internal group administration, including central storage and management of data used by multiple TX Group companies, IT management, archiving, training, corporate transactions, forwarding enquiries to responsible entities, and review and improvement of internal processes.
Depending on the purpose, we rely in particular on Articles 6 and 9 GDPR: consent; performance of a contract or pre-contractual measures; compliance with a legal obligation; and safeguarding legitimate interests.
Our legitimate interests include continuously improving and financing our offerings, customer care and communications, intra-group administration and support, prevention and investigation of fraud and offences, protection of persons, data, secrets and assets, IT security, organisation and development of business operations and systems, corporate management and development, corporate transactions, enforcement or defence of legal claims, and compliance with Swiss and foreign law and internal rules.
Consent may be withdrawn at any time with future effect. This does not affect the lawfulness of processing carried out before withdrawal.
We may disclose personal data to other TX Group companies, for example for intra-group administration and support. We may also disclose data to service providers within and outside the TX Group that process data on our behalf as processors, including providers of advertising and marketing, administration, payment, credit-information, debt-collection, IT and consulting services. We select service providers carefully and use appropriate contractual safeguards. In individual cases, we may disclose personal data to third parties for their own purposes, for example where you have consented or where we are legally obliged or entitled to do so. This may include transfers of receivables, corporate transactions, disclosures to courts and authorities, and disclosures required to comply with court orders or assert or defend legal claims. Such recipients are generally independent controllers.
Recipients may be located abroad, including outside the European Economic Area (EEA). Not all such countries protect personal data to the same extent as Switzerland or the EEA. Where we transfer data to such a country, we ensure appropriate protection, for example by entering into data-transfer agreements incorporating standard contractual clauses recognised by the European Commission and the Swiss Federal Data Protection and Information Commissioner. In exceptional cases, transfers may also be permitted on the basis of consent, in connection with foreign legal proceedings or where necessary to perform a contract.
“Profiling” means automated processing of personal data to analyse personal aspects or make predictions, for example analysis of interests, preferences, affinities and habits or prediction of likely behaviour. Profiling may in particular generate preference data. We may use profiling based on master and contract data, behavioural and transaction data, technical data, data relating to competitions or prize draws, and communication data. It helps us improve offerings, tailor content and advertising, support customer service and determine available payment options based on a credit check. We may combine data from different sources to improve our analyses and predictions. You may object to profiling in certain cases as described in section 13.
An automated individual decision is a decision made entirely by automated processing, without human involvement, that has legal consequences for a data subject or otherwise significantly affects them. We do not generally make such decisions; if we use them in individual cases, we will inform you separately. You then have the right to request a review of the decision if you disagree with it.
We take appropriate technical and organisational security measures to protect your personal data against unauthorised or unlawful processing, loss, accidental alteration, unwanted disclosure and unauthorised access. Our measures are continually adapted to technological developments. Although no company can exclude security breaches with absolute certainty, residual risks are unavoidable. Access is granted to employees only where necessary for their work. They are bound by our instructions and confidentiality obligations. Security measures include password-protected areas, encryption and pseudonymisation, logging, access restrictions, backups, internal instructions, confidentiality agreements and controls. We also require processors to take appropriate measures.
We process and retain personal data for at least as long as necessary for the relevant or compatible purposes; for contracts, generally at least for the duration of the contractual relationship. We also retain data while we have a legitimate interest in retention, for example to enforce or defend claims, for archiving or to ensure IT security, and as long as statutory retention obligations apply. Certain data is subject to a ten-year retention period; other data may have shorter periods, for example log data. We delete or anonymise personal data after these periods expire.
You have the right to object to processing, particularly where we process your personal data based on legitimate interests and the other applicable conditions are met. You may object at any time to processing for direct marketing, including related profiling.
Where applicable conditions are met and no legal exceptions apply, you also have rights of access, rectification, erasure, restriction of processing and receipt of personal data you have provided in a common format. You may withdraw consent with future effect.
Right to information: you have the right to be informed about our processing and your rights.
Right of access: you may request information about personal data we hold about you.
Right to rectification: you may have inaccurate or incomplete data corrected or completed.
Right to erasure: you may request deletion where the data is no longer required, consent has been withdrawn, you have effectively objected, or processing is unlawful, subject to applicable exceptions and retention obligations.
Right to restriction: under certain circumstances, you may request restricted processing.
Right to data portability: you may receive data you provided in a structured, commonly used, machine-readable format where the legal requirements are met.
Right to withdraw consent: consent may be withdrawn at any time with future effect.
To exercise your rights or ask questions, contact us as set out in section 14. You may also unsubscribe from newsletters and other promotional emails by clicking the link at the end of the email. You may lodge a complaint with a competent supervisory authority if you have concerns about lawfulness. In Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC).
If you have questions about this privacy policy or our processing of your personal data, or wish to exercise rights under section 13, please contact us at info@takt.ch. For matters originating in the EU, you may contact our representative (Article 27 GDPR): ePrivacy GmbH, Burchardstrasse 14, D-20095 Hamburg, Germany, https://www.eprivacy.eu.
This privacy policy may be amended over time, in particular if we further develop our website, implement new technologies or new legal requirements become applicable. In the event of material changes, we will actively inform registered persons at the email address provided during registration or by an appropriate notice where this is possible without disproportionate effort. The version of this privacy policy current at the start of the relevant processing applies in each case. The original version of this privacy statement is in German. The translated versions are provided solely for the purpose of better understanding. In the event of any discrepancies, the German text shall prevail.
Version: 1 May 2026