Privacy Policy
The responsible body within the meaning of the data protection laws, in particular the EU data protection basic regulation (DSGVO), is
MACA-LOCA Schweiz
Bruno Hubli
Buchenstrasse 11
CH-4533 Riedholz
Telefon: +41 41 500 42 25
E-mail: contact@maca-loca-cafe.shop
Website: https://maca-loca.shop
General Note
Based on Article 13 of the Swiss Federal Constitution and the data protection provisions of the Swiss Confederation (Data Protection Act, DSG), every person is entitled to protection of his or her privacy and protection against misuse of his or her personal data. The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and according to the legal data protection regulations as well as this privacy policy.
In cooperation with our hosting providers, we make every effort to protect the databases as well as possible against unauthorized access, loss, misuse or forgery.
We would like to point out that data transmission over the Internet (e.g. communication by e-mail) may have security gaps. A complete protection of data against access by third parties is not possible.
By using this website, you agree to the collection, processing and use of data in accordance with the following description. This website can be visited without registration. Data such as pages called up or the name of the file called up, date and time are stored on the server for statistical purposes without these data being directly related to your person. Personal data, in particular name, address or e-mail address are collected on a voluntary basis as far as possible. The data will not be passed on to third parties without your consent.
Processing of personal data
Personal data is all information that relates to an identified or identifiable person. A data subject is a person about whom personal data is processed. Processing includes any handling of personal data, irrespective of the means and procedures used, in particular the storage, disclosure, procurement, deletion, storage, modification, destruction and use of personal data.
We process personal data in accordance with Swiss data protection law. In addition, we process personal data – insofar and to the extent that the EU DSGVO is applicable – in accordance with the following legal bases in connection with Art. 6 Para. 1 DSGVO:
- lit. a) Processing of personal data with the consent of the person concerned.
- lit. b) Processing of personal data for the fulfilment of a contract with the data subject and for the implementation of appropriate pre-contractual measures.
- lit. c) Processing of personal data for the fulfilment of a legal obligation to which we are subject under any applicable law of the EU or under any applicable law of a country in which the DSGVO is applicable in whole or in part.
- lit. d) processing of personal data to protect vital interests of the data subject or of another natural person.
- lit. f) processing of personal data to safeguard the legitimate interests of us or of third parties, except where such interests are overridden by the fundamental freedoms and rights and interests of the data subject. Legitimate interests are in particular our commercial interest in being able to provide our website, information security, the enforcement of our own legal claims and compliance with Swiss law.
We process personal data for as long as is necessary for the respective purpose or purposes. In the case of longer-term storage obligations due to legal and other obligations to which we are subject, we restrict processing accordingly.
Data protection declaration for cookies
This website uses cookies. These are small text files that make it possible to store specific information relating to the user on the user’s terminal device while he or she is using the website. Cookies make it possible, in particular, to determine the frequency of use and the number of users of the pages, to analyse the behaviour of page use, but also to make our offer more customer-friendly. Cookies remain stored at the end of a browser session and can be retrieved when the user revisits the site. If you do not wish this, you should set your internet browser to refuse to accept cookies.
A general objection to the use of cookies used for online marketing purposes can be declared for many of the services, especially in the case of tracking, via the US site http://www.aboutads.info/choices/ or the EU site http://www.youronlinechoices.com/. Furthermore, the storage of cookies can be achieved by deactivating them in the browser settings. Please note that in this case not all functions of this online offer can be used.
Data protection declaration for SSL/TLS encryption
This website uses SSL/TLS encryption for reasons of security and to protect the transmission of confidential content, such as the requests you send to us as the site operator. You can recognise an encrypted connection by the fact that the address line of your browser changes from “http://” to “https://” and by the lock symbol in your browser line.
If the SSL or TLS encryption is activated, the data that you transmit to us cannot be read by third parties.
Data protection declaration for Server log files
The provider of this website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
These data cannot be assigned to specific persons. A consolidation of this data with other data sources is not carried out. We reserve the right to check this data subsequently if we become aware of concrete indications of illegal use.
Rights of affected persons
Right to confirmation
Every data subject has the right to obtain confirmation from the website operator as to whether personal data relating to him are being processed. If you wish to exercise this right of confirmation, you can contact the data protection officer at any time.
Right to information
Every person affected by the processing of personal data has the right to receive free information from the operator of this website at any time about the personal data stored about him and a copy of this information. In addition, the following information may be provided if necessary:
- The processing purposes
- The categories of personal data processed
- The recipients to whom the personal data have been or will be disclosed
- If possible, the planned duration for which the personal data will be stored or, if this is not possible, the criteria for determining this duration
- The existence of a right of rectification or erasure of personal data relating to them or of a right of objection to their processing by the controller
- The existence of a right of appeal to a supervisory authority
- If the personal data are not collected from the data subject: All available information on the origin of the data
- The data subject shall also have the right to obtain information as to whether personal data have been transferred to a third country or to an international organisation. If this is the case, the data subject shall also have the right to obtain information on the appropriate safeguards in relation to the transfer.
If you wish to exercise this right of information, you can contact our data protection officer at any time.
Right of rectification
Any person concerned by the processing of personal data shall have the right to obtain the rectification without delay of inaccurate personal data concerning him. The data subject shall also have the right to obtain the completion of incomplete personal data, including by means of a supplementary declaration, having regard to the purposes of the processing.
If you wish to exercise this right of correction, you can contact our data protection officer at any time.
Right of cancellation (right to be forgotten)
Any person concerned by the processing of personal data has the right to obtain from the controller of this website the immediate deletion of personal data concerning him/her, if one of the following reasons applies and insofar as the processing is not necessary:
- The personal data have been collected or otherwise processed for purposes for which they are no longer necessary
- The data subject withdraws the consent on which the processing was based and there is no other legal basis for the processing
- The data subject objects to the processing for reasons arising from his or her particular situation and there are no overriding legitimate reasons for processing, or, in the case of direct marketing and related profiling, the data subject objects to the processing
- The personal data were processed unlawfully
- The deletion of personal data is necessary to comply with a legal obligation under Union law or the law of the Member States to which the controller is subject
- The personal data were collected in relation to information society services provided directly to a child
If one of the above-mentioned reasons applies and you wish to have personal data stored by the operator of this website deleted, you can contact our data protection officer at any time. The data protection officer of this website will ensure that the request for deletion is complied with immediately.
Right to limitation of processing
Any person concerned by the processing of personal data has the right to obtain from the controller of this website the restriction of the processing if one of the following conditions is met:
- The accuracy of the personal data is contested by the data subject, for a period of time sufficient to enable the controller to verify the accuracy of the personal data
- The processing is unlawful, the data subject refuses to have the personal data deleted and instead requests that the use of the personal data be restricted
- The controller no longer needs the personal data for the purposes of the processing, but the data subject needs them in order to exercise or defend his rights
- The data subject has lodged an objection to the processing for reasons arising from his or her particular situation and it is not yet clear whether the legitimate reasons given by the controller outweigh those given by the data subject
If one of the above-mentioned conditions is met, you can request the restriction of personal data stored by the operator of this website, you can contact our data protection officer at any time. The data protection officer of this website will arrange for the restriction of the processing.
Right to data transferability
Any person concerned by the processing of personal data has the right to obtain the personal data concerning him/her in a structured, standard and machine-readable format. He/she also has the right to have these data communicated to another controller, if the legal requirements are met.
The data subject also has the right to obtain that the personal data be transferred directly from one controller to another controller, insofar as this is technically feasible and provided that it does not adversely affect the rights and freedoms of other persons.
To assert the right to data transfer, you can contact the data protection officer appointed by the operator of this website at any time.
Right of objection
Any person concerned by the processing of personal data has the right to object at any time, on grounds relating to his particular situation, to the processing of personal data concerning him.
In the event of such an objection, the operator of this website will no longer process the personal data, unless we can prove compelling reasons for processing that are worthy of protection, which outweigh the interests, rights and freedoms of the person concerned, or if the processing serves to assert, exercise or defend legal claims.
To exercise your right to object, you can contact the data protection officer of this website directly.
Right to revoke a consent under data protection law
Any person affected by the processing of personal data has the right to withdraw his or her consent to the processing of personal data at any time.
If you wish to exercise your right to revoke a consent, you can contact our data protection officer at any time.
Data protection declaration for objection to advertising e-mails
We hereby object to the use of contact data published within the scope of the imprint obligation to send advertising and information material not expressly requested. The operators of this website expressly reserve the right to take legal action in the event that unsolicited advertising information is sent, for example by spam e-mails.
External payment providers
This website uses external payment service providers through whose platforms the users and we can make payment transactions. For example via
- PostFinance (https://www.postfinance.ch/de/detail/rechtliches-barrierefreiheit.html)
- Visa (https://www.visa.de/nutzungsbedingungen/visa-privacy-center.html)
- Mastercard (https://www.mastercard.ch/de-ch/datenschutz.html)
- American Express (https://www.americanexpress.com/de/content/privacy-policy-statement.html)
- Paypal (https://www.paypal.com/de/webapps/mpp/ua/privacy-full)
- Bexio AG (https://www.bexio.com/de-CH/datenschutz)
- Payrexx AG (https://www.payrexx.ch/site/assets/files/2592/datenschutzerklaerung.pdf)
- Apple Pay (https://support.apple.com/de-ch/ht203027)
- Stripe (https://stripe.com/ch/privacy)
- Klarna (https://www.klarna.com/de/datenschutz/)
- Skrill (https://www.skrill.com/de/fusszeile/datenschutzrichtlinie/)
- Giropay (https://www.giropay.de/rechtliches/datenschutz-agb/) etc.
Within the framework of the performance of contracts, we appoint payment service providers on the basis of the Swiss Data Protection Ordinance and, where necessary, Art. 6 para. 1 lit. b. EU-DSGVO. Furthermore, we use external payment service providers on the basis of our legitimate interests in accordance with the Swiss Data Protection Ordinance and, where necessary, Art. 6 para. 1 lit. f. EU-DSGVO in order to offer our users effective and secure payment options.
The data processed by the payment service providers include inventory data, such as name and address, bank data, such as account or credit card numbers, passwords, TANs and checksums, as well as contract, sum and recipient related data. These details are required to carry out the transactions. However, the data entered is only processed by the payment service providers and stored by them. We as the operator do not receive any information about (bank) account or credit card, but only information to confirm (accept) or reject the payment. Under certain circumstances, the payment service providers may transfer the data to credit agencies. The purpose of this transmission is to check identity and creditworthiness. In this regard we refer to the general terms and conditions and data protection information of the payment service providers.
The terms and conditions and data protection information of the respective payment service providers, which can be accessed within the respective website or transaction applications, apply to the payment transactions. We also refer to them for further information and the assertion of rights of revocation, information and other rights of affected persons.
Order processing in the online shop with customer account
We process the data of our customers in accordance with the data protection regulations of the Federal Republic of Germany (Data Protection Act, DSG) and the EU-DSGVO, within the framework of the order processes in our online shop, in order to enable them to select and order the selected products and services, as well as to enable payment and delivery or execution.
The processed data includes master data (inventory data), communication data, contract data, payment data and the persons affected by the processing include our customers, interested parties and other business partners. The processing is carried out for the purpose of providing contractual services within the operation of an online shop, billing, delivery and customer services. For this purpose, we use session cookies, e.g. for storing the contents of the shopping cart, and permanent cookies, e.g. for storing the login status.
The processing is based on art. 6 para. 1 lit. b (execution of order processes) and c (legally required archiving) DSGVO. The information marked as required is required for the justification and fulfilment of the contract. We disclose the data to third parties only within the framework of delivery, payment or within the framework of the legal permits and obligations. The data will only be processed in third countries if this is necessary for the fulfilment of the contract (e.g. on customer request for delivery or payment).
Users have the option of creating a user account, in which they can view their orders in particular. Within the scope of registration, the required mandatory data will be communicated to the users. The user accounts are not public and cannot be indexed by search engines, e.g. Google. If users have terminated their user account, their data will be deleted with regard to the user account, subject to their safekeeping is necessary for reasons of commercial or tax law in accordance with Art. 6 Para. 1 lit. c DSGVO. Data in the customer account will remain until their deletion with subsequent archiving in case of a legal obligation. It is the responsibility of the users to save their data in case of termination before the end of the contract.
Within the scope of registration and renewed logins and use of our online services, we store the IP address and the time of the respective user action. The storage is based on our legitimate interests, as well as the user’s need for protection against misuse and other unauthorized use. As a matter of principle, this data is not passed on to third parties unless it is necessary to pursue our claims or there is a legal obligation to do so in accordance with Art. 6 Para. 1 lit. c DSGVO.
Deletion is carried out after the expiry of legal warranty and comparable obligations, the necessity of keeping the data is checked at irregular intervals. In the case of legal archiving obligations, deletion takes place after the expiry of these obligations.
Copyrights
The copyrights and all other rights to content, images, photos or other files on the website belong exclusively to the operator of this website or the specifically named rights holders. For the reproduction of all files, the written consent of the copyright holder must be obtained in advance.
Anyone who commits a copyright infringement without the consent of the respective copyright holder may be liable to prosecution and, if necessary, damages.
General exclusion of liability
All information on our website has been carefully checked. We make every effort to ensure that the information we offer is up-to-date, correct and complete. Nevertheless, the occurrence of errors cannot be completely ruled out, which means that we cannot guarantee the completeness, correctness and topicality of information, including journalistic and editorial information. Liability claims arising from material or non-material damage caused by the use of the information provided are excluded, unless there is evidence of wilful intent or gross negligence.
The publisher may change or delete texts at his own discretion and without prior notice and is not obliged to update the contents of this website. The use or access to this website is at the visitor’s own risk. The publisher, his clients or partners are not responsible for damages, such as direct, indirect, accidental, in advance concretely to be determined or consequential damages, which are allegedly caused by visiting this website and therefore do not assume any liability for them.
The publisher also accepts no responsibility or liability for the content and availability of third-party websites that can be accessed via external links on this website. The operators of the linked sites are solely responsible for the content of these sites. The publisher thus expressly distances itself from all third-party content that may be relevant under criminal or liability law or that is contrary to public decency.
Changes
We may change this privacy policy at any time without notice. The current version published on our website applies. If the data protection declaration is part of an agreement with you, we will inform you of the change by e-mail or other suitable means in the event of an update.
Questions to the data protection officer
If you have any questions regarding data protection, please send us an e-mail or contact the person responsible for data protection in our organization listed at the beginning of this privacy policy.
Riedholz, 29.02.2020
Source: SwissAnwalt