Data Protection Statement 

Cheel SA, Avenue de la Gare 66, 1920 Martigny, Switzerland (hereinafter the “Provider”), is the author of this Privacy Policy. This Privacy Policy applies to all users of the Provider’s services insofar as personal data is processed in connection with the provision of these services. This includes, in particular, Clients who have entered into a contract with the Provider for its services, their employees and visitors to the website. The Provider may also declare this Privacy Policy applicable to other contractual partners on a contractual basis. For the sake of simplicity, all persons concerned by data processing are hereinafter referred to as “Clients”.

The Provider endeavours to process its Clients’ personal information carefully and conscientiously. The Provider is responsible for the collection, processing, transmission, storage and protection of its Clients’ personal information and ensures compliance with the Federal Act on Data Protection (“FADP”) with regard to the protected data of Swiss Clients; it also complies with the European Union’s General Data Protection Regulation (“GDPR”) insofar as the protected data of Clients in the European area is concerned.

The Client’s consent to this Privacy Policy may be withdrawn at any time with immediate effect (see section 11, final paragraph).

Contact Details 
The data controller is:

Cheel SA
Avenue de la Gare 66
1920 Martigny
Switzerland
+41 27 564 0417

The Data Protection Officer (DPO) can be contacted by email at: dpo@cheel.ch


Applicable Law
The processing of data belonging to Swiss Clients is governed exclusively by Swiss law, in particular the Federal Act on Data Protection (FADP 2023). The General Data Protection Regulation of the European Union (GDPR) does not apply. The GDPR remains applicable (i) where expressly provided for in certain areas of this Privacy Policy and (ii) where its application is mandatory for the data of Swiss Clients due to particular circumstances.

In addition to Swiss law, Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation), applies to the processing of data belonging to Clients established in the EU. See also section 13 (Additional provisions for Clients established in the European area)..

Collection of Personal Data
When Clients browse the Provider’s website without accessing the secure area requiring identification, the web server automatically records their browsing data. This includes, among other things, the IP address of the device used, which is anonymised by Google before being stored so that it can no longer be associated with a specific Client. Google uses the _anonymizeIp() method for this purpose. This collection also includes information about the browser type, Internet service provider and operating system used.

When using the paid version of the cheel software, all data entered by the Client in the secure area requiring identification as part of the registration process and use of the software is recorded. This applies in particular when the Client registers, places orders, completes online forms, participates in surveys or competitions, communicates with the Provider online or offline, or contacts the Provider via social networks, blogs or other interactive media.

As a general rule, personal data such as name, address and email address is collected, together with the information required to use the relevant service.

By entering their information, the Client expressly consents to their personal information being processed, used and transmitted within the framework and scope of the purposes described in this Privacy Policy.

Sharing of Data with Third Parties / Trustees 
The Client may share their data with third parties, in particular their personal fiduciary, either directly or as part of the fiduciary partnership programme developed by the Provider. By granting access rights, the Client agrees that the Provider may make certain data available to a third party (such as the fiduciary) or allow access to such data. The Client retains full control over third-party access rights at all times and may restrict or refuse such access at any time.

In addition, the Provider authorises certain third parties, particularly fiduciaries, to open a cheel account for their clients and act as Clients themselves. In this case, the third party (fiduciary or other) manages access rights as a Client and may grant, restrict or refuse access to third parties.

Data Hosting 
Data recorded and processed in Cheel ERP is hosted exclusively in Switzerland. Cheel SA uses specialised Swiss service providers to provide its cloud infrastructure, in particular Exoscale (Akenes SA) and Infomaniak Network SA. The infrastructure used by Cheel SA through these providers is located in Switzerland. Data backups are also stored exclusively in data centres located in Switzerland. The providers used by Cheel SA are contractually required to comply with the applicable data protection and data security requirements.

Data Security 
The Provider implements technical and organisational security measures in accordance with recognised industry standards to protect the personal data it collects against accidental, unlawful or unauthorised manipulation. Access to Clients’ data by Cheel SA employees is strictly limited to authorised personnel and only to the extent necessary to provide technical support or maintain the service. Where applicable, the requirements of the FADP and GDPR are fully complied with at all times.

Communications between applications and the Provider’s servers are protected using secure encryption protocols. Security measures are regularly reassessed and adapted in response to technological developments, risks and threats. To prevent data loss, including in extreme circumstances such as the destruction of a data centre following an earthquake, encrypted backups are stored in parallel in several other data centres in Switzerland.

The Provider’s security measures are continuously updated and strengthened in line with technological developments. The Provider accepts no liability for data loss or the consultation and use of data by third parties. Despite the measures implemented, no transmission of data over the Internet can be considered completely risk-free. In particular, the transmission of data by email may involve risks depending on the systems used by the sender and recipient. If the Client wishes, they may opt for two-factor authentication at any time.

Purpose of Processing Data / Recipients of Data 
The Provider processes the collected data for the purposes of providing technical support, managing security when using the applications and improving performance. If personal information is processed or stored in a country that does not guarantee an appropriate level of data protection equivalent to the level of protection provided in Switzerland, the Provider requires the service provider, by contractual obligation, to fully comply with the relevant provisions of the FADP (or the GDPR where the data concerned belongs to Clients established in the European area).

The Provider may engage third-party service providers (processors) to provide certain services necessary for the operation of the platform, particularly in the areas of hosting and cloud infrastructure, backup and IT security. The Provider’s processors are contractually required to comply with data protection regulations. These companies are based in Switzerland.

Cookies
Cookies make visiting the Provider’s website easier, more convenient and more relevant. Cookies are files containing information that the web browser automatically stores on the computer’s hard drive when the Client visits the website and uses the Provider’s product.

The Client may modify their browser’s security settings to block or disable cookies. However, this may mean that certain Provider services can no longer be used in their entirety.

Tracking and Analytics Tools / Social Media 
The Google Analytics analytics tool is a service provided by Google LLC. Consequently, the data collected may in principle be transmitted to a Google server in the United States (or another country determined by Google).

The Provider’s website uses Google Analytics, a web analytics service provided by Google Inc., headquartered at 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (“Google”). Google Analytics uses “cookies”: text files installed on the Client’s computer to analyse how the Client uses the website. The information generated by the cookies concerning the use of the website, including the IP address, which is anonymised by Google before it can be attributed to the Client, is transmitted to and stored on a Google server in the United States (or another country determined by Google).

Google uses this information to analyse website usage, prepare reports on website activity for the Provider and provide other services relating to website and Internet use. Google may also transfer this information to third parties where required to do so by law or where such third parties process the data on Google’s behalf. Under no circumstances will Google associate the Client’s IP address with other Google data.

If the Client does not wish their online activity to be available to Google Analytics, they may install the Google Analytics opt-out browser add-on.

This add-on prevents the JavaScript code from Google Analytics (ga.js, analytics.js and dc.js) embedded in websites from sharing information about their visit with Google Analytics.

However, installing this add-on does not prevent website operators from using other tools to perform analytics. Data may therefore still be sent to websites or other web analytics services.

Finally, the Provider collects certain information transmitted automatically by the Client’s Internet browser in server log files. These include, among other things, the user agent (browser type and version, operating system), HTTP header information (referrer URL, IP address of the device used), the time of the server request and connection status. These server log files are only combined with other data sources for error analysis.

Technologies for Advertising Purposes 
The Provider’s website uses Google Analytics Remarketing features in conjunction with the cross-device features of Google AdWords and Google DoubleClick. These services are provided by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (“Google”).

This function makes it possible to associate advertising target groups created with Google Analytics Remarketing with the cross-device features of Google AdWords and Google DoubleClick. As a result, targeted and personalised advertisements tailored to the Client’s needs on one device, such as a mobile phone, based on their usage and browsing behaviour may also be displayed on another device, such as a tablet or PC.

If the Client has given consent to Google, Google associates the Client’s web browsing history and app history with their Google account for this purpose. The same personalised advertisements can therefore be displayed on all devices on which the Client signs in with their Google account.

As part of this function, Google Analytics collects identifiers of users logged in to Google, which are temporarily linked to the Provider’s Google Analytics data for the purpose of defining and creating target groups for cross-device advertising.

The Client can permanently disable cross-device remarketing by disabling ad personalisation in their Google account.

Further information is provided in Google’s data protection statement.

The Provider’s website also uses the Google AdWords advertising tool operated by Google Inc.

As part of Google AdWords, the Provider uses what is known as conversion tracking. When the Client clicks on an advertisement placed by Google, a conversion tracking cookie is set. Cookies are small text files stored by the Internet browser on the Client’s computer. These cookies expire after 30 days and are not used to personally identify users.

If the Client visits the Provider’s website while the cookie has not yet expired, Google and the Provider can see that the Client clicked on the advertisement and was redirected to this page.

Google informs the Provider of the total number of users who clicked on its advertisement and were redirected to its website with a conversion tracking tag. However, the Provider does not receive any information that would allow it to personally identify the Client.

To prevent cookies from being stored, the Client may modify their browser settings. However, the Provider points out that the Client may then be unable to use all of the website’s functions in their entirety. The Client may also prevent conversion tracking by disabling the corresponding cookie in their browser’s user settings.

Further information is provided in Google’s privacy policy.

The Provider’s website also uses the Facebook Pixel analytics tool, operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, United States.
 
Other Tools
The Provider’s website uses the Google Maps mapping service operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States. If the Client uses Google Maps functions, their IP address is recorded by Google and generally transmitted to a Google server in the United States. The Provider has no control over this data transfer.

Further information is provided in Google’s privacy policy: https://www.google.de/intl/de/policies/privacy/

Newsletter and Email Marketing 
When the Client subscribes to one of the newsletters offered on the Provider’s website, the Provider requests their email address and other information allowing it to verify that they are the holder of the email address provided and that they agree to receive the newsletter (double confirmation or “double opt-in” procedure).

The newsletter enables the Client to regularly receive a range of offers and recommendations that may be of interest to them. For this purpose, the Provider collects and processes personal data relating to how the Client uses the website, the cheel software and the newsletter, such as whether they open it and which links they click. The Provider uses this data for statistical purposes in order to better tailor the newsletter to the Client’s interests.

The processing of personal data entered in the newsletter registration form is based on the Client’s consent, which may be withdrawn at any time. Withdrawal is carried out via the unsubscribe link contained in the newsletter. The personal data collected is necessary for preparing and sending the newsletter.

The personal data collected by the Provider as part of the newsletter subscription remains stored until the Client unsubscribes.

Retention Period 
The Provider processes and stores the Client’s personal data for as long as the Client uses the service. It should be noted that the contractual relationship is an ongoing relationship established for periods of several years.

In case the contractual relationship is terminated, the Client’s data is retained for the period necessary to fulfil legal or contractual obligations and is then deleted or anonymised within a reasonable period. Data that is no longer required is regularly deleted, except where its processing may subsequently be necessary, for example due to statutory retention obligations or for strictly necessary internal purposes.

Right to Acces, Right to Rectification, Right to Erasure, Right to Object, Consent
With regard to personal data, Clients have the following rights in accordance with the FADP and GDPR. As a general principle, the Provider also grants Swiss Clients the rights provided for under the GDPR. However, the Provider reserves the right to assess individual situations differently.

  • Right of access (Art. 8 FADP, Art. 15 GDPR);
  • Right to rectification (Art. 5 para. 2 FADP, Art. 16 GDPR);
  • Right to erasure (Art. 17 GDPR);
  • Right to restriction of processing (Art. 18 GDPR);
  • Right to data portability (Art. 20 GDPR);
  • Right to object (Art. 21 GDPR).

The above rights are subject to any restrictions under the GDPR and the respective applicable national laws, whether or not relating to data protection.

As part of the provision of the services offered by the Provider, the Client is asked to consent to the collection, processing, transmission and use of their personal data by ticking the relevant box.

The Client may withdraw their consent at any time without affecting the lawfulness of processing based on consent carried out prior to its withdrawal. A request to withdraw consent may be submitted in writing to the Provider at the address indicated above or by email to dpo@cheel.ch.

Links to Other Websites 
The Provider’s website contains hyperlinks to third-party websites that are not operated or controlled by the Provider. The Provider accepts no responsibility for their content or data protection practices.

Additional Provisions for Clients Established in the EU
The following provisions apply only to Clients established in the European area. They do not apply to Swiss Clients.

Legal Base for Processing 
Processing of data for the purposes specified in section 5 is carried out pursuant to Article 6(1)(b) GDPR for the performance of the contract. The services mentioned above form the subject matter of the contract.

As stated above, data is also processed on the basis of the Provider’s legitimate interests (Article 6(1)(f) GDPR). These include improving products and services, including the distribution of direct marketing, monitoring and optimising the performance of our offering, and detecting, preventing and investigating potential illegal activities.

In addition, data is processed pursuant to Article 6(1)(c) GDPR in order to fulfil the Provider’s legal obligations, particularly statutory retention and documentation obligations. Personal master data is particularly concerned.

If the Client believes that one or more of the purposes specified in section 5 are not covered by the legal bases mentioned above, they may request that the Provider cease processing their personal data for the purposes concerned (“opt-out”). Such withdrawal of consent does not prevent the Client from continuing to use the cheel software unless such use necessarily involves processing the data in question. The Client may notify the Provider of the withdrawal of consent in writing at the Provider’s address indicated at the beginning of this Privacy Policy or by email at dpo@cheel.ch.

Right of Appeal
If the Client believes that the processing of their personal data violates the provisions of the GDPR, they may lodge a complaint with a supervisory authority in accordance with Article 77 GDPR.

The Provider is, of course, willing to consider the Client’s questions and requests before formal proceedings are initiated. The Client may contact the Provider in writing or by email at dpo@cheel.ch.

Cheel SA
Avenue de la Gare 66
1920 Martigny
Switzerland