Data protection

Protecting and respecting information

Caritas Switzerland takes the protection of personal data seriously. Data is treated with strict confidentiality and is neither transferred nor sold to third parties.

General

This data protection declaration has been drawn up in accordance with the applicable data protection laws of Switzerland, in particular with the Swiss Data Protection Act (nDSG), but also with the European General Data Protection Regulation (GDPR). The competent data protection authority in Switzerland is the Federal Data Protection and Information Commissioner (FDPIC).

The current version of the data protection declaration is indicated at the top of this page. The data protection declaration can be adapted at any time. The current version published on our website applies.

The information you provide will be recorded in our database and used for information purposes. We process your data partly by automated means for fundraising and to inform and advise you specifically about products (profiling).

Caritas Switzerland employees as well as external service providers who handle your data are obliged to strictly comply with data protection regulations.

We process different data categories. The most important categories are the following:

Technical data: If you use our website or other electronic offers such as our free WLAN, we collect the IP address of your terminal device and other technical data. This ensures the functionality and security of these offers. This data also includes protocols that record the use of our systems. In order to ensure the functionality of these offers, we can assign an individual code to you, or rather to your terminal device, for example in the form of a cookie. The technical data in itself does not allow any conclusions to be drawn about your identity. However, in the context of user accounts, registrations, access controls or processing of contracts, they can be linked with other data categories and may thus be linked to your person.

Technical data includes, amongst other things, the IP address and details about your terminal’s operating system, the date, region and time of use as well as the type of browser you use to access our electronic offers. This can help us to provide the correct formatting of the website or show you a website adapted to your language region. Although we know, on the basis of the IP address, via which provider you access our offers and also from which region, we cannot as a rule deduce from this who you are. This changes if, for example, you open an account. Because then, the personal data can be linked with the technical data and we can see, for example, which browser you use in order to use an account via our website. Examples of technical data are also protocols - so-called «logs» - that accumulate in our systems. An example of this is the user login on our website.

Registration data: Specific offers in connection with competitions and services, for example login areas of our website, newsletter dispatch or free WLAN access can only be used with an account or a registration, which can be done directly with us or via our external login service provider. You must provide us with specific data, and we collect data about the use of the offer or the service. If you redeem a voucher with us, we may ask you for specific data when you redeem it. If we issue you a voucher for one of our contractual partners, we may forward certain of your registration data to the respective contractual partner or receive such data. Access controls to specific sites may require registration data; depending on the control system, also biometric data.

Registration data includes, among other things, the details you provide if you set up an account on our website, such as username, password, name, email address. But the registration data also includes data that we may require from you before you can use certain services. You also have to register if you want to subscribe to our Newsletter. As part of access controls, we may have to register you with your data for identification (see category of «other data»).

Communication data: If you are in contact with us via the contact form, by email, telephone or Chat, by letter or via any other means of communication, we record the data exchanged between you and us, including your contact data and the marginal data of the communication. If we record or listen to telephone conversations or video conferences, for example for training or quality assurance purposes, we inform you about this. Such recordings may only be produced and used in accordance with our internal rules. You will be informed about whether and when such records are produced, for example through a notice during the respective video conference. If you do not want any record, please let us know or terminate your participation. If you simply don’t want your image to appear, please turn off your camera. If we want to or have to know your identity, for example if you have asked for information, want access to the media or something similar, we collect data to identify you, for example a copy of your passport or ID card.

Master data: We use the term master data to refer to the basic data that we require, in addition to the contractual data, (see below) for handling our contractual and other business relationships, or for marketing and advertising purposes, such as name, contact details and information about your role and function, your bank details, your date of birth, the customer history, powers of attorney, signature authorisations and declarations of consent. We process your master data if you are a customer, a donor or other business contact or if you act on their behalf, for example as contact person of the business partner, or because we want to be in contact with you for our own purposes or the purposes of a contractual partner, for example in the context of marketing and advertising with invitations to events, vouchers, newsletters etc. We receive master data directly from you, for example through a purchase or as part of a registration, from organisations you work for, or from third parties such as our contractual partners, associations and address traders and from publicly accessible sources such as public registers or the Internet (websites, social media etc.). Within the framework of master data, we can also process health data and details about third parties.

Master data includes, for example, data such as name, address, email address, telephone number and other contact details, gender, date of birth, nationality, details about related persons, websites, profile in Social Media, photos and videos, copies of I.D. cards; also details about your relationship with us - customer, donor, supplier, visitor, service recipient, details on your status with us, allocations, classifications and distribution lists, information about our interactions with you - possibly a history of it with corresponding entries, reports from the media or official documents such as trade register extracts, permits that concern you. For payment purposes we require, for example, your bank details, account number and credit card details. Consent or blocking notices are also part of the master data, as well as details about third parties such as contact persons, recipients of services, advertising recipients or sales representatives.

In the case of contact persons and representatives of our customers, donors, suppliers and partners, we process as master data, for instance, name and address, information about the role, function in the company, qualifications and where appropriate details about managers, employees and subordinates, and details about interactions with these persons.

Master data is not collected comprehensively for all contacts. What data we collect in individual cases depends particularly on the purpose of the processing.

Caritas Switzerland has its own in-house printing press which can have access to the master data for printed matter. As regards printed matter that is not produced in our own printing press, we forward personal data only to third parties if this is necessary for the contract execution.

Contract data: This is data that arises in connection with the conclusion of a contract or the processing of a contract, for example information about contracts and the services to be provided or that have been provided, as well as data from the pre-contractual phase, the information required or used in the processing, and information about responses such as complaints, or information about satisfaction. Details about health and information about third parties are also part of this, for example about hereditary illnesses in the family. We normally collect this data from you, from contractual partners, from third parties involved in the execution of the contract and from publicly accessible sources.

Contract data includes information about the conclusion of the contract, about your contracts such as the type and date of the conclusion of the contract, information from the application process such as an application for our products or services and information about the particular contract (e.g. its duration), the processing and management of the contracts (such as information in connection with invoicing, customer service, support in technical matters and the enforcement of contractual claims). Contractual data also includes information about deficiencies, complaints and adaptation of a contract, as well as information about customer satisfaction, which we can collect, for example, by means of surveys.

Behavioural and preference data: Depending on the relationship we have with you, we try to get to know you and to tailor our products, services and offers better to you. To this end, we collect data about your behaviour and your preferences. We do this by evaluating information about your behaviour in our field and we can supplement this information with third-party information - including from publicly accessible sources. Based on this, we can for instance calculate the probability that you will use certain services or behave in a certain way. We already know some of the data processed for this purpose if, for instance, you make use of our services, or we get this data by recording your behaviour, for example how you navigate our website. We anonymise or delete this data if it is no longer relevant for the purposes pursued.

Behavioural data is information about specific actions, for example your reaction to electronic messages - whether and when you opened an email, about your location, your interaction with our social media profiles or your participation in sweepstakes, competitions or similar events. We can collect your location data, for example, through unique codes sent by your mobile phone or if you use our website. We will inform you of the collection of anonymous movement profiles at the relevant locations by means of appropriate signs; we will only create a personalised movement profile with your consent.

Preference data gives us information about your needs, which products or services could interest you, or when and how you are likely to respond to messages from us. We obtain this information from the analysis of existing data such as behavioural data. We thus get to know you better and can deliver more personalised advice and offers to you. We can also generally improve our offers as a result. In order to be able to improve the quality of our analyses, we can link this data with other data. We can also get this data from third parties such as address traders, public offices and publicly accessible sources such as the Internet. This can be data such as information about your household size, income bracket and purchasing power, shopping behaviour and contact details of relatives, or anonymous information from statistical offices.

Behavioural and preference data can be analysed on a personal basis, for example to show you personalised advertising, but also on a non-personal basis, for example for market research or product development. Behavioural and preference data can also be combined with other data. For example, movement data can be used in the context of a health protection scheme for contact tracing.

Other data: Other data may be generated in connection with official or judicial procedures such as files and evidence which may also relate to your person. We may also collect data for reasons of health protection, for example within the framework of protection schemes. We may receive or produce photographs, videos and sound recordings in which you may be recognisable – this may be at events or via CCTV cameras. We can also collect data on who enters specific buildings when, or who has corresponding rights of access. This is possible, for example, in case of access controls, or based on registration data or visitor lists. We can also record who participates when in events or actions such as competitions, or who uses our infrastructure and systems and when. Finally, we collect and process data about our stakeholders such as shareholders and other investors. In addition to master data, this includes among other things information for the corresponding registers, concerning the exercise of their rights and the holding of events such as general meetings. The retention period of this data depends on the purpose and is limited to what is necessary.

Much of the data mentioned in this data protection regulation is provided by yourself, for example in forms, in the context of communication with us, in connection with contracts or while using the website. You are not obliged to do so. There are some exceptions, for example within the framework of binding protection concepts involving legal obligation. If you conclude contracts with us or use services you must also, as part of your contractual obligations, provide us with data in connection with the relevant contract, in particular master, contractual and registration data. When using our website, the processing of technical data is unavoidable. If you want to get access to certain systems or buildings, you must provide us with registration data. However, with regard to behavioural and preference data, you can always object or not give your consent.

We will only make certain services available to you if you provide us with registration data because we, or our contractual partners, wish to know who uses our services or has accepted an invitation to an event. This is either technically necessary, or we want to communicate with you. If you or a person whom you represent - for example your employer, wishes to conclude or execute a contract with us, we must collect relevant master, contractual and communication data from you. We also process technical data if you want to use our website or other electronic offers for this purpose. If you do not provide us with the data required for the conclusion or processing of the contract you must expect that we will reject the conclusion of a contract, that you are committing an infringement of the contract, or that we will not execute the contract. Equally, we can only reply to an inquiry from you if we have the relevant communication data and - if you are communicating with us online - also technical data. It is not possible to use our website if we do not receive technical data.
Unless it is not permitted, we also collect data from publicly accessible sources, including debt collection register, land registers, commercial registers, media or the Internet and social media, or we obtain data from other companies within our group, from public authorities and other third parties such as credit reference agencies, address brokers, associations, contractual partners, Internet analysis services and others.

We process and store your personal data in accordance with the statutory storage and documentation obligations, for the duration of the business relationship. If necessary, the data is also retained beyond this period in order to assert possible claims against our company or on the basis of legal obligations and legitimate business interests, for example for the purposes of evidence and documentation. As soon as the data is no longer needed for these purposes, it is deactivated and no longer used.

In addition, we store operational data such as system protocols and logs. The data retention period is generally 10 years from the last contract activity but at least from the end of the contract. In certain cases, this period may be longer for reasons of evidence, legal or contractual requirements or technical requirements.

You have the right to information, correction, deletion, restriction of data processing and the right to object to our data processing and to the release of certain personal data for the purpose of transmission to another place (data portability).

Upon written request, we inform you about the data we have stored about you. Please send us your first name, surname and your email address as well as a copy of an official form of identification (identity card or passport).

All data that you provide is transferred to us via a secure connection, Secure Sockets Layer (SSL), in encrypted form.

Any liability over and above the above conditions is excluded. In particular, Caritas Switzerland accepts no liability whatsoever for damages arising from errors of transmission, disruptions or technical defects.

Despite careful control of the content, we accept no liability for the content of external links. The operators of linked pages are solely responsible for their content.

By participating in our events and offers, you are giving your tacit consent to the recording and use of photo, video and voice material. If you do not wish this, please contact the persons responsible for the particular event directly.

Third-party providers

Caritas Switzerland uses various offers of Google Llc. from Mountain View, USA. For analytic purposes we use Google Analytics 4. In addition, Google Signal activated in Google Analytics 4 helps to identify the user across devices. The «Ads Personalization», which can be set and viewed in the personal Google account, is used as the basis for tracking. Data will only be shown after 50 events. Conclusions about individual persons are not possible.

The Remarketing function is used to present interest-based advertisements to visitors to the website as part of the Google advertising network.

For our newsletter distribution, we use the software of the company ActiveCampaign Inc. from Chicago, USA. ActiveCampaign is certified under the Privacy Shield Agreement and thus offers a guarantee of compliance with European data protection standards.

The newsletter registration is done with your email address in a double opt-in procedure. Registrations and changes to the newsletter subscription are logged and can be traced. If you provide further information about yourself during the registration we will compare this with our own database.

The newsletters contain a so-called «web-beacon», i.e. a pixel-sized file that is retrieved from the server of the shipping service provider when the newsletter is opened. As part of this retrieval, technical information used to improve the offer is collected. For technical reasons, this information can be assigned to the individual newsletter recipients.

Mail Privacy Protection (MPP) is one of the data settings available to all Apple Mail users who use iOS 15, iPadOS 15, macOS Monterey and watchOS8. Users who run the mail app on their device can agree to this privacy setting. After logging in, the mail app masks the IP address on the device and prevents third parties from opening emails and other IP data.

You can make a donation or process a payment online easily and securely. The transaction is transmitted via Secure Sockets Layer (SSL) to RaiseNow via Paypal, Stripe or Worldline.

The company RaiseNow, based in Zurich, Switzerland, has developed an e-payment platform specially for non-profit organisations and aid organisations. RaiseNow meets all the guidelines of the Swiss financial authorities and IT Security Standards and is PCI-DSS-certified (Payment Card Industry Data Security-Standard).

We use the service of ConvertFlow Inc. from Miami, USA, to collect and store data for marketing, market research and optimisation purposes.

To collect the data, ConvertFlow sets a cookie in your browser and reads technical information about your device. IP addresses are only recorded and stored anonymously. This information is merged and stored by ConvertFlow in a pseudonymised user profile. The information is not used by ConvertFlow or Caritas Switzerland to identify individual users or combined with other data about individual users.

Xandr and AdForm are used as DSP (Demand-Side-Platform) to display advertising on third party websites via these platforms.

shop.caritas.ch is embedded in a Joomla environment. The products and your customer data are hosted in Ecwid. Advance payments are processed via the payment service provider Wallee. Card payments are processed by the acquirer Concardis.

If you click on an element of a third-party provider (e.g. «like», in Facebook), a connection to the servers of this third-party provider can be established automatically. In doing so, data about your visit to the website can be transmitted to the third-party provider and, under certain circumstances, assigned to your user account there. Caritas Switzerland uses the remarketing offers of the respective social media providers.

  • Meta (Facebook, Instagram)
  • LinkedIn
  • Google (YouTube)
  • Twitter
  • Spotify
  • Soundcloud
  • Issuu

The website backend is based on the Open Source CMS Drupal. Information you provide us with in a form on the website is stored in Drupal. The website frontend is shown via Netlify and Gatsby and stores or processes pre-rendered statistical data of the HTML pages.

When you visit our website you leave cookies. The purpose of the cookies is to analyse the use of this website as well as to make continuous improvements. We use CookiePro by OneTrust as our cookie consent tool.

Some service providers in our advertising environment set their own permanent cookies and can use these for their own purposes. The processing of your personal data by the service provider is the responsibility of the service provider according to its data protection regulations.

Mountain action

In order to book a placement, volunteers must provide their personal details and open a user account. In order to be able to open a user account, the volunteers’ email address is verified. Volunteers can directly adapt and update their personal data in the user account.

Use of the data: By making a booking, the volunteers agree that their details are sent to the mountain farmer family where the assignment will take place. After their action, they are sent a questionnaire by email for the purpose of quality control. The personal details provided are used by Caritas Mountain Action for correspondence with the volunteers in order to clarify any questions that may arise about their action.

The volunteers’ data is subject to Caritas Switzerland’s Data protection declaration.

In accordance with the provisions of the GDPR (art. 6 para. 1 lit. a) and Art. 13) your details, including the contact details provided by you, will be stored by us when you register for voluntary work for the purpose of processing your inquiry and where necessary to clarify further questions.

The processing of the data takes place on the basis of your consent. This means that you have given your consent to the processing of your data. We store your data to enable us to organise your volunteer placement in the most effective way. With your agreement, your data will also be passed on to cantonal authorities.

We will retain the data you have entered in the contact form until you ask us to delete it, revoke your consent to it being stored, or the purpose of the data storage no longer exists. Please note, however, that we are obliged to comply with statutory retention periods.

By signing the request for volunteer placements with Caritas Mountain Action, the mountain farmer families agree to the guidelines for mountain farmer families (German). They consent to their details being published on the website www.bergeinsatz.ch and on Caritas’ social media for the purpose of finding volunteers, and that the description with their personal details is passed on to the volunteer helpers who register for an action on their farm.

The personal data provided will be used by Caritas Mountain Action for correspondence with the mountain farmer families in order to clarify any questions around the volunteer actions.

The mountain farmer families’ data is subject to Caritas Switzerland’s data protection declaration.

Kontakt

Data Protection Office

Caritas SwitzerlandAdligenswilerstrasse 15
P.O. Box
CH-6002 Lucerne

datenschutz@caritas.ch