Home
|

Privacy policy

Privacy policy of the BODY FACE HEALTH website

The rights of users in Switzerland are governed by the Federal Act on Data Protection (FADP) and its implementing provisions and essentially include the following points:

  • the right to access to personal data
  • the right to object to the processing of personal data (including the right to request its restriction, deletion or destruction and the prohibition of the disclosure of certain personal data to third parties)
  • the right to receive his or her personal data and to have it transferred to another controller (data portability)
  • the right to rectification of inaccurate personal data.

DATA PROTECTION

Your data is a matter of trust for BODY FACE HEALTH, Klosbachstrasse 54, 8032 Zurich, Switzerland.

In most cases, the processing of personal data is subject to the provisions of the Swiss Data Protection Act (DSG) and the associated Ordinance (DSV). In some cases, the provisions of the EU General Data Protection Regulation (GDPR) may also be directly applicable.

The purpose of data protection legislation is to protect the privacy of individuals.

In this privacy policy, you will learn what data we collect, how we use it, and what rights you have regarding your data.

DATA COLLECTION

When you use this website, various personal data is collected. Personal data is information that can be used to identify you personally.

CATEGORIES OF DATA

Master Data

e.g. title, first name, last name, gender, date of birth, address, e-mail address, telephone number, customer and booking numbers (e.g. online appointment booking), date and time of registrations, declarations of consent.

Contract data

Contract data is personal data that arises in connection with the conclusion or performance of a contract, contract, e.g. the nature and duration of a treatment contract entered between you and us.

Contract data is processed for the following purposes

  • billing for our services
  • Preparation of reimbursement documents for the health insurer
  • General accounting purposes
  • Customer care and customer satisfaction surveys
  • Enforcement of legal claims arising from the contract (debt collection, debt enforcement, legal proceedings, etc.)
  • Management and control of our IT and other resources
  • Retention of data in accordance with retention obligations

Health data

As part of the provision of therapeutic and aesthetic services, we regularly process data about your health. This includes any information that allows conclusions to be drawn about a person’s state of health. Sensitive personal data includes, for example, medical histories (anamnesis) and customer files. Or you may have applied for a reimbursement voucher for services covered by your health insurance.

Communication data

This includes all data transmitted during communications between you and us and with third parties (e.g. the content of emails, telephone calls, letters and metadata such as the date and time of a call or email delivery, website ratings).

Technical data

Technical data may be used to collect behavioral data, i.e. information about your use of the Site, such as your IP address, information about your device’s operating system, region and time of use. Technical data does not allow any conclusions to be drawn about your identity.

Behavioural and transactional data

When you use our services, we often collect data about that use and about your behaviour in general.  This includes, for example, data collected when you book appointments online, navigate the website or interact with our social media profiles. This data is supplemented by data from third parties, including publicly available sources.

Preference data

We want to tailor our offers and services to our customers. We therefore also process data about your interests and preferences. To do this, we may combine behavioural and transactional data with other data and evaluate this data on a personal and non-personal basis (but we do not do this with customer dossiers). In this way, we can draw conclusions about your characteristics, preferences and expected behaviour, such as your preferences and affinities for certain services.

WHAT DATA WE COLLECT and WHAT WE USE IT FOR

  • Firstly, your information is collected when you provide it to us. For example, the information you provide when booking an appointment online (title, surname, first name, date of birth, contact telephone numbers, email address, postal address).
  • Other data is collected automatically or with your consent by our IT systems when you visit our website. These are mainly technical data (Internet browser, operating system, time of page view, etc.).
  • Some of the data is collected to ensure that the website functions correctly. Other data may be used to analyse your user behaviour.

DATA SECURITY

We employ technical and organizational security measures to protect your data from unauthorized access, loss, or destruction. Our security measures are regularly reviewed and adjusted according to the state of the art.

STORAGE PERIOD

Unless a specific retention period is specified in this Privacy Policy, we will retain your personal data until the purpose for which it was collected is no longer valid, or until you request its deletion or revoke your consent to its processing.

OBJECTION

Many data processing operations are only possible with your explicit consent. Once you have given your consent, you may revoke it at any time. The lawfulness of the data processing carried out up to the time of withdrawal is not affected by the withdrawal.

WITH WHOM DO WE SHARE YOUR PERSONAL DATA?

We may disclose your personal data to third parties (e.g. courts and authorities in Switzerland and abroad) if we are required to do so by law. In addition, we reserve the right to process your personal data to comply with a court order, to establish or defend legal claims, or if we deem it necessary for other legal reasons. In this context, we may also disclose personal data to other parties involved in the proceedings.

HOSTING

Our website is hosted by Hostpoint.

The provider is Hostpoint AG, Neue Jonastrasse 60, 8640 Rapperswil-Jona, Switzerland

Details can be found in Hostpoint’s privacy policy: https://www.hostpoint.ch/hostpoint/kontakt-agb.html#datenschutz

Hostpoint is used based on the provisions of the Swiss Data Protection Act (DSG) and the associated Ordinance (DSV). We have a legitimate interest in ensuring that our website is displayed as reliably as possible.

Personal data collected on this website is stored on the servers of the hosting provider. This may include IP addresses, meta and communication data, contract data, contact data, names, access to the website and other data generated by the website.

Our hosting provider will only process your data to the extent necessary to fulfil its service obligations and to comply with our instructions in relation to that data.

Server Log Files

The provider of these pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are

  • Browser type/version
  • Operating system
  • Referrer URL
  • Host name of the accessing computer
  • Time of server request
  • IP address

This data is not merged with other data sources.

The website operator has a legitimate interest in the technically correct presentation and optimisation of its website – the storage of server log files is necessary for this purpose.

COOKIES

Cookies are small text files that are stored on your device or computer. They make your visit to our website more attractive and enable you to use certain functions. The text files are sent by the web server to the web browser, stored there and sent back by the server to the web browser when a page is requested again. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your device or computer until you delete them, or your web browser automatically deletes them. Cookies do not contain any personally identifiable information.

Cookies functions

  • Many cookies are technically necessary, as certain website functions would not work without them (e.g. displaying videos). Other cookies are used to evaluate user behaviour or to display advertisements.
  • Necessary cookies are required to carry out electronic communication, to provide certain functions you wish to use or to optimise the website (e.g. to measure the web audience). The website operator has a legitimate interest in the storage of necessary cookies for the technically faultless and optimised provision of its services. Consent may be withdrawn at any time.

More information about cookies and how to disable cookies can be found here: http://www.allaboutcookies.org

THIRD-PARTY SERVICES

Our website has directly integrated third-party services such as YouTube and Google Maps. These providers also use cookies. When you use our website, user data is automatically sent to these companies and may also be shared with third parties. We have no knowledge of the extent to which, where and for how long these companies store this data, whether they comply with existing deletion obligations, what analyses and links they make with the data and to whom they disclose the data.

Google YouTube

When you visit a page with an embedded YouTube video, a connection is made to the YouTube servers and YouTube plugins are occasionally used. YouTube is notified of which page was visited from which IP address.

Google Maps

The Google Maps service is occasionally used to display an interactive map. By using Google Maps, information about your use (e.g. IP address) may be stored and transmitted to a Google server in the USA.

The data controller is determined by your usual place of residence, unless otherwise stated in the privacy notice for a particular service:

  • Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). For users of Google services whose habitual residence is in the European Economic Area or Switzerland
  • Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). For users of Google services who are habitually resident in the United Kingdom.

Regardless of your location, Google LLC is the data controller for the processing of information indexed and displayed by services such as Google Search and Google Maps.

The representative of Google Ireland Limited for the purposes of Art. 14 of the Swiss Federal Data Protection Act, which serves as a contact for data subjects and the Swiss Federal Data Protection and Information Commissioner, is Vischer AG.

Google reCaptcha

Under the name reCaptcha, Google LLC operates services that can detect and prevent automated actions on websites.

Google Web Fonts

If Google Maps is enabled, Google may use Google Web Fonts to display fonts in a consistent manner. When you access Google Maps, the required web fonts are loaded into your browser’s cache to display text and fonts correctly. In other cases, the device’s default font is used. Google Fonts are embedded locally on the website. There is no exchange with the Google servers: https://developers.google.com/fonts/faq

However, Google’s services will only be used if you have given your consent in the cookie banner.

For more information about Google’s handling of user data, please see Google’s privacy policy: https://policies.google.com/privacy?hl=en

Google Analytics

This website uses functions of the web analysis service Google Analytics (Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).

Google Analytics uses cookies. The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers in the United States.

We have enabled IP anonymisation on this website. This means that Google will truncate your IP address within the member states of the European Union or in other signatory states to the Agreement on the European Economic Area before transmitting it to the USA. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA where it will be truncated. Google will use this information on behalf of the website operator to analyse your use of the website, to compile reports on website activity and to provide the website operator with further services relating to website activity and internet usage. Google will not associate the IP address transmitted by your browser with any other data held by Google.

You can find more information about the use of your personal data by Google here: https://www.google.com/intl/en/policies/privacy/

You can disable Google Analytics by following this link: https://tools.google.com/dlpage/gaoptout

Browser Plugin

You may refuse the use of cookies by selecting the appropriate settings on your browser. However, please note that if you do so, you may not be able to use the full functionality of this website. You may refuse the use of cookies by selecting the appropriate settings on your browser, however, please note that you may not be able to use the full functionality of this website if cookies are disabled. You may also refuse the use of cookies by selecting the appropriate settings on your browser, such as the use of cookies by default.

OBJECTION TO DATA COLLECTION

You may opt out of the data collection by Google Analytics.

You can find more information about the processing of user data by Google Analytics in Google’s privacy policy: https://support.google.com/analytics/answer/6004245?hl=de

CHANGES TO THIS PRIVACY POLICY

We reserve the right to change this privacy policy to adapt it to changed legal conditions or new services. The current version can be found on our website.