Framework only. This page lists the disclosures a privacy policy for this shop needs to make. The actual wording must be completed and reviewed by qualified counsel against the Swiss Federal Act on Data Protection and, where applicable, the GDPR, before the shop goes live.
1. Controller
[NAME AND CONTACT DETAILS OF THE CONTROLLER TO CONFIRM]
Data protection contact: [DATA PROTECTION CONTACT TO CONFIRM]
Representative in the EU or Switzerland, if required: [REPRESENTATIVE TO CONFIRM]
2. What we process and why
[CATEGORIES OF DATA AND PURPOSES TO CONFIRM: account and order data, payment data, delivery data, support correspondence, newsletter subscription, website usage.]
3. Legal basis
[LEGAL BASIS PER PURPOSE TO CONFIRM]
4. Recipients and processors
[LIST OF PROCESSORS TO CONFIRM: shop platform, payment providers, delivery partners, email and analytics providers.]
5. Transfers abroad
[COUNTRIES AND SAFEGUARDS TO CONFIRM]
6. Retention periods
[RETENTION PERIODS PER CATEGORY TO CONFIRM]
7. Your rights
[RIGHTS OF ACCESS, RECTIFICATION, ERASURE, RESTRICTION, PORTABILITY, OBJECTION AND COMPLAINT, WITH THE ADDRESS FOR EXERCISING THEM, TO CONFIRM]
8. Cookies and tracking
Described separately in the cookie policy, where you can also change your consent.
9. Security
[TECHNICAL AND ORGANISATIONAL MEASURES TO CONFIRM]
10. Changes
[CHANGE NOTICE AND VERSION DATE TO CONFIRM]