Privacy policy

Preamble

With the following privacy policy, we would like to inform you about what types of your personal data (hereinafter also referred to as “data”) we process, for what purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of the provision of our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as “online offer”).

The terms used are not gender-specific.

Status: March 16, 2025

Table of contents

Person responsible

OSLO STUDIOS AG
Oslo-Strasse 2
CH-4142 Münchenstein (near Basel)

Persons authorized to represent the company: Philipp Steiner

E-mail address: info@oslostudios.ch

Imprint: https://oslostudios.ch/policy/impressum/

Contact data protection officer

philipp.steiner@oslostudios.ch

Overview of processing

The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.

Types of data processed

Categories of affected persons

Purposes of the processing

Relevant legal bases

Relevant legal bases under the Swiss Data Protection Act: If you are located in Switzerland, we process your data on the basis of the Swiss Federal Act on Data Protection (“Swiss FADP” for short). Unlike the GDPR, for example, the Swiss FADP does not generally require that a legal basis for the processing of personal data be specified and that the processing of personal data be carried out in good faith, lawfully and proportionately (Art. 6 para. 1 and 2 of the Swiss FADP). In addition, personal data will only be obtained by us for a specific purpose that is recognizable to the data subject and will only be processed in a manner that is compatible with this purpose (Art. 6 para. 3 of the Swiss FADP).

Security measures

We take appropriate technical and organizational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.

The measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as the access, input, disclosure, safeguarding of availability and its separation. Furthermore, we have established procedures that ensure the exercise of data subject rights, the deletion of data and responses to data threats. Furthermore, we already take the protection of personal data into account during the development or selection of hardware, software and processes in accordance with the principle of data protection, through technology design and through data protection-friendly default settings.

Transmission of personal data

As part of our processing of personal data, it may be transmitted to other bodies, companies, legally independent organizational units or persons or disclosed to them. The recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we observe the legal requirements and, in particular, conclude corresponding contracts or agreements with the recipients of your data that serve to protect your data.

International data transfers

Disclosure of personal data abroad: In accordance with the Swiss FADP, we only disclose personal data abroad if adequate protection of the data subjects is guaranteed (Art. 16 Swiss FADP). If the Federal Council has not determined adequate protection (list: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we take alternative security measures.

For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by a Swiss adequacy decision dated 07.06.2024. In addition, we have concluded standard data protection clauses with the respective providers, which have been approved by the Federal Data Protection and Information Commissioner (FDPIC) and set out contractual obligations to protect your data.

This dual protection ensures comprehensive protection of your data: The DPF forms the primary layer of protection, while the standard data protection clauses serve as additional security. Should there be any changes to the DPF, the standard data protection clauses act as a reliable fall-back option. In this way, we ensure that your data always remains adequately protected, even in the event of any political or legal changes.

For the individual service providers, we will inform you whether they are certified in accordance with the DPF and whether standard data protection clauses are in place. The list of certified companies and further information on the DPF can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/.

For data transfers to other third countries, appropriate security measures apply, including international contracts, specific guarantees, standard data protection clauses approved by the FDPIC or internal company data protection regulations recognized in advance by the FDPIC or a competent data protection authority of another country.

General information on data storage and deletion

We delete personal data that we process in accordance with the statutory provisions as soon as the underlying consents are revoked or there is no further legal basis for the processing. This applies to cases in which the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule exist if legal obligations or special interests require longer storage or archiving of the data.

In particular, data that must be stored for commercial or tax law reasons or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons must be archived accordingly.

Our data protection information contains additional information on the retention and deletion of data that applies specifically to certain processing operations.

If there is more than one indication of the retention period or deletion period for a date, the longest period is always decisive.

If a period does not expressly begin on a specific date and is at least one year, it shall automatically start at the end of the calendar year in which the event triggering the period occurred. In the case of ongoing contractual relationships in the context of which data is stored, the event triggering the deadline is the date on which the termination or other termination of the legal relationship takes effect.

We only process data that is no longer stored for the originally intended purpose, but due to legal requirements or other reasons, for the reasons that justify its storage.

Further information on processing operations, procedures and services:

Business services

We process data of our contractual and business partners, e.g. customers and interested parties (collectively referred to as “contractual partners”), in the context of contractual and comparable legal relationships and related measures and with regard to communication with the contractual partners (or pre-contractual), for example to respond to inquiries.

We use this data to fulfill our contractual obligations. These include, in particular, the obligations to provide the agreed services, any updating obligations and remedies in the event of warranty and other service disruptions. In addition, we use the data to safeguard our rights and for the purpose of the administrative tasks associated with these obligations and the company organization. We also process the data on the basis of our legitimate interests both in the proper and efficient management of our business and in security measures to protect our contractual partners and our business operations from misuse, threats to their data, secrets, information and rights (e.g. to involve telecommunications, transport and other auxiliary services as well as subcontractors, banks, tax and legal advisors, payment service providers or tax authorities). Within the framework of applicable law, we only pass on the data of contractual partners to third parties to the extent that this is necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners will be informed about other forms of processing, such as for marketing purposes, as part of this privacy policy.

We inform the contractual partners which data is required for the aforementioned purposes before or during data collection, e.g. in online forms, by means of special marking (e.g. colors) or symbols (e.g. asterisks or similar), or in person.

We delete the data after the expiry of statutory warranty and comparable obligations, i.e. generally after four years, unless the data is stored in a customer account, e.g. as long as it must be retained for legal archiving reasons (e.g. for tax purposes, generally ten years). We delete data disclosed to us by the contractual partner as part of an order in accordance with the specifications and generally after the end of the order.

Business processes and procedures

Personal data of service recipients and clients – including customers, clients or, in special cases, clients, patients or business partners as well as other third parties – are processed within the scope of contractual and comparable legal relationships and pre-contractual measures such as the initiation of business relationships. This data processing supports and facilitates business processes in areas such as customer management, sales, payment transactions, accounting and project management.

The data collected is used to fulfill contractual obligations and efficiently design operational processes. This includes the processing of business transactions, the management of customer relationships, the optimization of sales strategies and the guarantee of internal accounting and financial processes. In addition, the data supports the protection of the rights of the controller and promotes administrative tasks and the organization of the company.

Personal data may be passed on to third parties if this is necessary to fulfill the stated purposes or legal obligations. Payment data (e.g. bank details, invoices, payment history)Contact data (e.g. postal and e-mail addresses or content data (e.g. textual or pictorial messages and contributions as well as the information relating to them, such as information on authorship. Contract data (e.g. subject matter of the contract, term, customer category).

  • Affected persons: Service recipients and clients; interested parties; communication partners. Business and contractual partners.
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; office and organizational procedures. Business processes and business management procedures.
  • Storage and deletion: Deletion in accordance with the information in the section “General information on data storage and deletion”.
  • Legal bases: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
  • Provision of the online offer and web hosting

    We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or end device.

    Further information on processing operations, procedures and services: