Home / Privacy Policy
Privacy Policy
With this privacy policy, we inform you about which personal data we process in connection with our activities, including our quellenhofrapperswil.ch website. In particular, we inform you about the purposes for which, how and where we process which personal data. We also inform you about the rights of persons whose data we process.
For individual or additional activities, further privacy policies as well as other legal documents such as general terms and conditions (GTC), terms of use or terms of participation may apply.
1. Contact addresses
Responsibility for the processing of personal data:
Hannes Mandl
Restaurant Quellenhof
Halsgasse 34 / Engelplatz
8640 Rapperswil
info@quellenhofrapperswil.ch
We will point out if, in individual cases, there are other parties responsible for the processing of personal data.
Data protection advisor
We have the following data protection advisor as a point of contact for data subjects and authorities for enquiries relating to data protection:
Hannes Mandl
Restaurant Quellenhof
Halsgasse 34 / Engelplatz
8640 Rapperswil
info@quellenhofrapperswil.ch
2. Terms and legal bases
2.1 Terms
Personal data is all information relating to an identified or identifiable natural person. A data subject is a person about whom we process personal data.
Processing covers any handling of personal data, regardless of the means and procedures used, for example the querying, comparing, adapting, archiving, storing, reading, disclosing, obtaining, recording, collecting, deleting, revealing, arranging, organising, retaining, changing, disseminating, linking, destroying and using of personal data.
2.2 Legal bases
We process personal data in accordance with Swiss data protection law, in particular the Federal Act on Data Protection (Data Protection Act, DPA) and the Ordinance on Data Protection (Data Protection Ordinance, DPO).
3. Nature, scope and purpose
We process the personal data that is necessary in order to be able to carry out our activities in a permanent, user-friendly, secure and reliable manner. Such personal data may in particular fall into the categories of inventory and contact data, browser and device data, content data, meta or marginal data and usage data, location data, sales data as well as contract and payment data.
We process personal data for the period that is necessary for the respective purpose or purposes or that is required by law. Personal data whose processing is no longer necessary is anonymised or deleted.
We may have personal data processed by third parties. We may process personal data together with third parties or transmit it to third parties. Such third parties are in particular specialised providers whose services we use. We also ensure data protection with such third parties.
In principle, we only process personal data with the consent of the data subjects. Insofar as the processing is permitted for other legal reasons, we may refrain from obtaining consent. For example, we may process personal data without consent in order to perform a contract, to fulfil legal obligations or to safeguard overriding interests.
Within this framework, we process in particular information that a data subject voluntarily transmits to us when making contact – for example by postal mail, e-mail, instant messaging, contact form, social media or telephone – or when registering for a user account. We may store such information, for example, in an address book, in a customer relationship management system (CRM system) or with comparable tools. If we receive data transmitted about other persons, the transmitting persons are obliged to ensure data protection towards these persons and to ensure the accuracy of this personal data.
We also process personal data that we receive from third parties, obtain from publicly accessible sources or collect in the course of carrying out our activities, insofar as such processing is permitted for legal reasons.
4. Applications
We process personal data about applicants insofar as it is necessary for assessing suitability for an employment relationship or for the subsequent performance of an employment contract. The necessary personal data results in particular from the information requested, for example within the scope of a job advertisement. We also process the personal data that applicants voluntarily provide or publish, in particular as part of cover letters, CVs and other application documents as well as online profiles.
5. Personal data abroad
In principle, we process personal data in Switzerland. However, we may also disclose or export personal data to other countries, in particular in order to process it there or have it processed there.
We may disclose personal data to all countries and territories on earth as well as elsewhere in the universe, provided that the local law ensures adequate data protection according to a decision of the Swiss Federal Council.
We may disclose personal data to countries whose law does not ensure adequate data protection if suitable data protection is ensured for other reasons. Suitable data protection can be ensured, for example, by appropriate contractual agreements, on the basis of standard data protection clauses or with other suitable guarantees. Exceptionally, we may export personal data to countries without adequate or suitable data protection if the special data protection requirements for this are met, for example the explicit consent of the data subjects or a direct connection with the conclusion or performance of a contract. We are happy to provide data subjects with information about any guarantees on request or provide a copy of guarantees.
6. Rights of data subjects
6.1 Data protection claims
We grant data subjects all claims in accordance with the applicable data protection law. In particular, data subjects have the following rights:
- Information: Data subjects can request information as to whether we process personal data about them and, if so, what personal data is involved. Data subjects also receive the information that is necessary to assert their data protection claims and to ensure transparency. This includes the processed personal data as such, but also, among other things, information on the processing purpose, the duration of storage, any disclosure or export of data to other countries and the origin of the personal data.
- Rectification and restriction: Data subjects can have incorrect personal data rectified, incomplete data completed and the processing of their data restricted.
- Deletion and objection: Data subjects can have personal data deleted (“right to be forgotten”) and object to the processing of their data with effect for the future.
- Data release and data transfer: Data subjects can request the release of personal data or the transfer of their data to another controller.
We may postpone, restrict or refuse the exercise of the rights of data subjects within the legally permissible scope. We may point out to data subjects any conditions that must be met in order to exercise their data protection claims. For example, we may refuse information in whole or in part with reference to trade secrets or the protection of other persons. For example, we may also refuse the deletion of personal data in whole or in part with reference to statutory retention obligations.
We may exceptionally provide for costs for the exercise of rights. We inform data subjects in advance of any costs.
We are obliged to identify data subjects who request information or assert other rights with reasonable measures. Data subjects are obliged to cooperate.
6.2 Right to complain
Data subjects have the right to enforce their data protection claims through legal channels or to lodge a complaint with a competent data protection supervisory authority.
The data protection supervisory authority for private controllers and federal bodies in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).
7. Data security
We take appropriate technical and organisational measures to ensure data security appropriate to the respective risk. However, we cannot guarantee absolute data security.
Access to our website takes place using transport encryption (SSL / TLS, in particular with the Hypertext Transfer Protocol Secure, abbreviated HTTPS). Most browsers indicate transport encryption with a padlock in the address bar.
Our digital communication is subject – like basically all digital communication – to mass surveillance without cause or suspicion as well as other surveillance by security authorities in Switzerland, the rest of Europe, the United States of America (USA) and other countries. We cannot exert any direct influence on the corresponding processing of personal data by intelligence services, police authorities and other security authorities.
8. Use of the website
8.1 Cookies
We may use cookies. Cookies – both our own cookies (first-party cookies) and cookies from third parties whose services we use (third-party cookies) – are data that is stored in the browser. Such stored data need not be limited to traditional cookies in text form.
Cookies can be stored in the browser temporarily as “session cookies” or for a certain period as so-called permanent cookies. “Session cookies” are automatically deleted when the browser is closed. Permanent cookies have a certain storage duration. Cookies enable, in particular, a browser to be recognised on the next visit to our website and thereby, for example, to measure the reach of our website. However, permanent cookies can also be used for online marketing, for example.
Cookies can be completely or partially deactivated and deleted at any time in the browser settings. Without cookies, our website may no longer be available in full. We actively request – at least insofar as necessary – the explicit consent to the use of cookies.
8.2 Server log files
For each access to our website, we may record the following information, provided that it is transmitted by your browser to our server infrastructure or can be determined by our web server: date and time including time zone, Internet Protocol (IP) address, access status (HTTP status code), operating system including user interface and version, browser including language and version, the individual sub-page of our website that was accessed including the amount of data transferred, the website last accessed in the same browser window (referrer).
We store such information, which may also constitute personal data, in server log files. The information is necessary in order to be able to provide our website permanently, in a user-friendly manner and reliably, and to ensure data security and thus, in particular, the protection of personal data – also by third parties or with the help of third parties.
8.3 Counting pixels
We may use counting pixels on our website. Counting pixels are also referred to as web beacons. Counting pixels – also from third parties whose services we use – are small, usually invisible images that are automatically retrieved when our website is visited. The same information as in server log files can be recorded with counting pixels.
9. Social media
We are present on social media platforms and other online platforms in order to be able to communicate with interested persons and to inform them about our activities. In connection with such platforms, personal data may also be processed outside Switzerland.
The respective general terms and conditions (GTC) and terms of use as well as privacy policies and other provisions of the individual operators of such platforms also apply. These provisions inform in particular about the rights of data subjects directly towards the respective platform, which includes, for example, the right to information.
10. Services of third parties
We use services of specialised third parties in order to be able to carry out our activities permanently, in a user-friendly, secure and reliable manner. With such services, we can, among other things, embed functions and content in our website. With such embedding, the services used record, for technically compelling reasons, at least temporarily the Internet Protocol (IP) addresses of the users.
For necessary security-relevant, statistical and technical purposes, third parties whose services we use may process data in connection with our activities in aggregated, anonymised or pseudonymised form. This is, for example, performance or usage data in order to be able to offer the respective service.
10.1 Digital infrastructure
We use services of specialised third parties in order to be able to use the required digital infrastructure in connection with our activities. This includes, for example, hosting and storage services from selected providers.
10.2 Contact options
We use services of selected providers in order to be able to communicate better with third parties such as, for example, potential and existing customers.
10.3 Appointment scheduling
We use services of specialised third parties in order to be able to arrange appointments online, for example for meetings. In addition to this privacy policy, any directly visible conditions of the services used, such as terms of use or privacy policies, also apply.
11. Video surveillance
We use video surveillance to prevent criminal offences and to secure evidence in the event of criminal offences, as well as to exercise our domiciliary rights.
We store recordings from our video surveillance for as long as they are necessary for securing evidence. As a rule, the recordings are deleted or overwritten after 48 hours.
We may secure recordings on the basis of legal obligations, to enforce our own legal claims and in the event of suspicion of criminal offences, and transmit them to competent bodies such as, in particular, judicial or law enforcement authorities.
12. Final provisions
We have created this privacy policy with the data protection generator from Datenschutzpartner.
We may adapt and supplement this privacy policy at any time. We will inform about such adaptations and supplements in a suitable form, in particular by publishing the respective current privacy policy on our website.