Data protection

General privacy policy of Availabill AG

September 1, 2023

Availabill AG (“Availabill” or “we”) attaches great importance to the responsible and legally compliant handling of personal data. Personal data is processed exclusively on the basis of the applicable law. In this privacy policy, we inform our customers1) and visitors to our websites (“customers” or “you”) about the handling and processing of personal data.

The privacy policy addresses Availabill’s entire customer base, regardless of the grammatical formulations used here, and includes the following areas:

  1. Privacy policy for purchase on account and purchase in installments.
  2. Terms and conditions for visiting our websites
  3. Cookie policy
  4. Privacy policy for my.availabill

In addition to these conditions, customers must also observe the following legal information in connection with this privacy policy:

Availabill reserves the right to amend this privacy policy at any time. The version published at www.availabill.ch is the currently valid version.

1. privacy policy for “purchase on account” and “purchase in installments”

Availabill processes personal data of customers who are in direct or indirect contact with it. We use the term “data” synonymously with the term “personal data”. Data refers to information that relates directly to customers or can be directly assigned to a customer by us. Under para. 1.2. informs Availabill about the categories of data that are processed in accordance with the information in this privacy policy. Processing means any handling of data, e.g. obtaining, storing, using, disclosing or deleting.

This privacy policy describes how we process data when customers use our services or products, are in contact with us as part of a contract or communicate with us in general. This privacy policy therefore applies to the processing of data that we have already collected or will collect in the future.

We provide information about certain data processing separately, e.g. in further data protection notices, in general terms and conditions, in conditions of participation for specific products or services, in product and service descriptions, on our websites and in declarations of consent, contracts and forms.

If data relating to other persons is communicated to us, the sender confirms that they are authorized to do so and that the data is correct. The sender must ensure that these third parties are informed about the processing of the data by us before communicating it to us.

1.1 Who is responsible for processing the data?

Availabill AG is responsible for data processing in accordance with this Privacy Policy and is primarily responsible under data protection law, unless otherwise communicated in individual cases. You can contact us in writing (Availabill AG Datenschutz, Hagenholzstrasse 85a, 8050 Zurich), by e-mail (datenschutz@availabill.ch) or by telephone on +41 (0)58 433 22 00 to exercise your rights and to contact us about data protection issues.

1.2 What data is processed, for what purpose and from what sources?

We process different data from different sources depending on the situation and purpose. We primarily collect and receive this data directly from our customers when they use our products and services or as part of general customer communication. We may also obtain data from other sources, e.g. from public registers or other publicly accessible sources, from authorities and other third parties. Availabill processes various categories of data. The most important categories of data are described below:

  • Master data: Master data refers to data relating to identity and personal characteristics and circumstances, e.g. name, address or date of birth. This data can also refer to third parties (authorized representatives) and also includes signature authorizations, powers of attorney and declarations of consent.
  • Contract data: When a contract is concluded with us, we process master data as well as other data, such as information about the purchase and use of products and services. Such data includes information on the processing and enforcement of contracts as well as feedback from our customers on services.
  • Behavioral and preference data: Behavioral data is data about certain actions and interactions of our customers with Availabill. Behavioral data provides us with information about certain actions, e.g. logins, the use of the payment methods “purchase on account” and “purchase in installments”, payments, the purchase and use of products and services, contacting our customer service or participating in competitions, contests and events.
    Preference data provides us with information about your needs, which products and services you might be interested in or when and how you react to messages from Availabill. We obtain this information from the analysis of existing data in order to get to know our customers better and to tailor and improve offers to them more precisely.
    Behavioral and preference data can either be evaluated on a personal basis in order to provide customized offers or display advertising, or for the purpose of market research or product development, also on a non-personal basis.
  • Communication data: Communication data refers to data in connection with communication with you in correspondence, by telephone and via electronic channels (e.g. contact form on our websites, e-mail and SMS). When establishing your identity (e.g. when requesting information), we also collect data to identify you (e.g. via a copy of an identification document).
  • Technical data: Technical data is data that we collect when you use electronic services. This data also includes the IP address of an end device and the logs in which we record the use of our systems. To ensure the functioning of these services, we can assign an individual code to end devices (e.g. in the form of a cookie). Technical data does not allow any conclusions to be drawn about the identity of a person. Together with the data from user accounts, registrations, access controls or the processing of contracts, for example, we may be able to link other data to specific persons.
    In addition to the IP address and information about the end device, the technical data also includes the date and time, the geographical region and the type of browser or device used by customers to access our electronic services. This information helps us to display content in a browser or on an end device. Based on the IP address, we receive information about a telecommunications provider, but are generally unable to deduce the identity unless customers are logged into a user account. Technical data also includes log files that are generated in our systems.
  • Registration data: Registration data is data about customers that is transmitted during registration or activation in order to be able to use certain services (e.g. newsletters and competitions).
  • Other data: We collect other data relating to customers in various contexts. For example, data is collected in connection with official or legal proceedings (e.g. files, evidence, etc.). We may also collect data for reasons of fraud prevention.
1.3 What is the data used for and how is it processed?

We process data for the following purposes:

  • Establishment, processing and termination of business relationships: We process data for the initiation, registration, processing and termination of business relationships. The type of data processed differs depending on the type and scope of the customer relationship and may primarily include master data, financial and risk data, order and transaction data as well as registration and communication data. Order and transaction data is also processed as part of transaction automation.
  • Provision of the payment methods “purchase on account” and “purchase in installments”: By selecting the payment method “purchase on account” or “purchase in installments”, the customer transmits data to us. We process the contact details (name and address, e-mail, etc.), date of birth and creditworthiness data to check the customer’s creditworthiness.
  • Processing the application for purchase on account and purchase in installments: When applying for the payment method purchase on account and purchase in installments, the applicant transmits data to us. In particular, we process contact data such as name, address, gender, date of birth, creditworthiness data and data for the purpose of combating money laundering for the purpose of checking creditworthiness or credit capacity.
    The applicant’s data may also be processed and linked with other data that we receive from other sources or can collect ourselves. In particular, we receive and obtain this data from authorities, databases and credit agencies (CRIF, Swiss Post, Multisource), registers such as local.ch, commercial registers, the media and generally from the Internet.
  • Use of purchase on account and purchase in installments: When using the “purchase on account” and “purchase in installments” payment methods, we process data that is communicated to us during the term of the contractual relationship or that we collect ourselves (e.g. name changes, changes in beneficial ownership, proof of income, data of other persons in the event of an insurance claim). From the transaction data, we may draw far-reaching conclusions about the customer’s behavior, in particular for fraud prevention (e.g. place of residence and work, financial circumstances and other information).
  • Merchants’ credit notes and reversals: As part of a chargeback, we regularly receive detailed information about the transaction from the Merchants concerned.
  • Compliance with laws, official recommendations and internal regulations: We also process data to comply with laws, directives and recommendations from authorities as well as internal regulations (compliance). The processed data includes, in particular, master data, financial and risk data, communication data, order and transaction data as well as behavioral data (fraud prevention). This includes the legally regulated fight against money laundering and terrorist financing. We are obliged to carry out certain clarifications or, under certain circumstances, to make a report. In addition, data processing requires the fulfillment of disclosure, information or reporting obligations, the fulfillment of retention obligations and the prevention, detection and clarification of criminal offenses and other violations. This includes receiving and processing complaints and other reports, monitoring communications, internal investigations or disclosing documents to an authority if we are obliged to do so or have a legitimate interest in disclosure. Customer data may also be processed during external investigations (e.g. by a regulatory or law enforcement authority or a commissioned private body) and during internal investigations. This purpose also includes the evaluation of order and transaction data as well as payment transactions in order to identify unusual transactions.
  • Risk management, prevention of fraud and other unauthorized activities: We also process data – in particular master data, order and transaction data, financial and risk data and behavioral data – for risk management purposes, to prevent fraud and other unlawful acts and as part of prudent business management, including business organization and business development.
    In the area of business development, we may sell or acquire businesses, parts of businesses or companies and enter into partnerships, which may also lead to the exchange and processing of data. Data may also be processed as part of the review and improvement of internal processes. To prevent fraud and other unauthorized activities, we may conduct internal investigations to identify irregularities.
  • Brokerage of products and services: We process master data as well as order and transaction data in connection with the brokerage of third-party products and services, e.g. insurance. When we broker products and services, these are offered via our infrastructure, but are executed and processed in whole or in part by third parties.
  • Marketing, profiling and customer care: We process data for marketing purposes and for customer care in order to provide customers with personalized information and offers on products and services from us and third parties (e.g. partners). This may take the form of a letter, a newsletter or an e-mail. We may also process data in order to tailor marketing content to better meet customer interests. For marketing purposes and customer care, we primarily use master, financial and risk data, order and transaction data as well as behavioral and preference data and other information on the contractual relationship.
    In particular, you authorize us to create and evaluate customer, consumption and preference profiles in order to develop or evaluate products and services in which you may be interested and to offer such products and services (also from third parties) or to inform you about them and to send them to your postal address, e-mail address or telephone number (e.g. SMS). You have the option of revoking profiling for marketing purposes for the future by sending us a corresponding written notification (including by email) (profiling block). This does not apply to non-commercial messages and automatically generated system and invoice texts.
    We also process data in connection with competitions, prize draws and events. Customer care includes personalized contact with existing customers. As part of customer care, we maintain a customer relationship management system (CRM) in which the data required to maintain the relationship with our customers is stored. This includes data on contact persons, the relationship history (e.g. products and services purchased or supplied and interactions), interests and marketing measures.
    You have the option to object to the sending of information (advertising block) or to generally revoke your consent to data processing for marketing purposes by sending a corresponding written message (also by e-mail) to availabill (general revocation). This does not apply to non-advertising communications and automatically generated system and invoice texts.
  • Improvement of services and operations as well as product development: Data is also processed to improve services and operations as well as for product development. For these purposes, we use master data, behavioral and preference data as well as information from surveys.
    We continuously develop our own products and services, adapt them to the needs of our customers and determine the level of satisfaction. We analyze which products are used by which groups of people and in what way, and how new products and services could be designed and used. This gives us an indication of the market acceptance of existing products and services and the market potential of new products and services.
  • Security purposes and access control: Availabill may also process master data, technical data, behavioral data and other data for security purposes and access control. We continuously review and improve the security of our IT and infrastructure. However, data security breaches cannot be ruled out with complete certainty. Availabill counters this risk with appropriate technical and organizational measures in accordance with the state of the art. Access controls include controlling access to electronic systems on the one hand and physical access control on the other.
  • Communication: We process data in order to communicate with you, provide you with information or send you messages and process your requests. We use master data and communication data for this purpose. We generally store this data in order to be able to document the communication that has taken place, but also for quality assurance and for subsequent inquiries. If customers contact us by e-mail, we are expressly authorized to reply via the same channel to the sender’s address or to the address provided. E-mails are transmitted unencrypted via the open Internet and it cannot be ruled out that they can be accessed, viewed and manipulated by third parties. This means that e-mail communication is not suitable for transmitting confidential information.
  • Other purposes: Availabill may process data for other purposes, e.g. as part of internal processes and for administrative purposes. Administrative purposes include the management of master data, accounting and data retention as well as the auditing and management of the IT infrastructure. We also use this data to protect and exercise our own rights, e.g. to enforce claims in court, in or out of court and before authorities in Switzerland and abroad, to preserve evidence, to carry out legal investigations and to participate in court or official proceedings.
    Other purposes include evaluating and improving internal processes and preparing and processing purchases and sales of companies and assets as well as training and education purposes. The protection of other legitimate interests, which cannot be listed exhaustively, are also included.
1.4 What applies to automated decision-making?

With regard to the items under no. 1.3. We may process and evaluate data in an automated and computerized manner for the purposes mentioned above in order to determine preference data, identify abuse and security risks, carry out statistical evaluations or plan company operations. We can also create risk profiles for the same purposes. In doing so, we combine behavioural and preference data, master data, order and transaction data, information on the contractual relationship and personalized technical data so that risks and characteristics can be better identified.

This also allows us to learn more about our customers and the products and services that could be of interest or are already in use. For reasons of efficiency and uniformity of decision-making processes, Availabill can make decisions automatically. If these decisions have a legal effect on customers or affect them in any other way, we inform them immediately and take the legally required measures.

We will inform you in each individual case if an automated decision leads to negative legal consequences or significant impairments. In this case, you have the rights described under point. 1.8. rights if you do not agree with the result of the decision.

1.5 To whom do we disclose data?

We are bound to confidentiality by the Data Protection Act and other regulatory provisions. Products and services are often developed, provided and processed based on a division of labor. Data is therefore processed by different departments. The departments involved may process your data, but may only do so within the framework of legal and/or contractual requirements. We transfer data to the following categories of recipients.

  • Availabill-internal persons: Within Availabill, individuals and their corporate entities have access to data to the extent necessary for the purposes set out in this Privacy Policy.
  • Service providers: We work with service providers in Switzerland and abroad. To enable us to provide their products and services efficiently, securely and cost-effectively, we procure services from third parties in various areas. These services include IT services, the dispatch of information, marketing, sales, communication, market research or printing services, debt collection, anti-fraud measures and services from consulting firms and law firms. We only disclose to service providers the data required and necessary for the provision of services.
  • Employees of contractual partners: If persons work for a contractual partner who have a contractual relationship with Availabill, we may collect data about this person. We may pass on the data collected to persons and other bodies involved in the processing of the contractual relationship.
  • Third parties: Third parties are persons or companies that process data about you for their own purposes. Third parties are not service providers commissioned by Availabill. In connection with purchase on account and purchase in installments, we do not pass on any data to third parties for their own purposes; this applies in particular to transaction data or customer and consumer data. An exception to this principle is the forwarding of data that has been expressly requested by customers or to which they have expressly consented.
  • Authorities and other official bodies: We may disclose data to offices, courts and other authorities or official bodies if we are legally obliged or entitled to disclose such data or if we represent our own rights and legitimate interests.
  • Other persons: We also pass on data to the Information Office for Consumer Credit (IKO/ZEK) within the scope of legal obligations.
  • Electronic data transmission: Data may be transmitted to third parties in Germany and abroad during electronic data transmission, even without any action on our part. In particular when using mobile devices, manufacturers of devices or software (such as Apple or Google) may receive data. These third parties may process and also pass on this data in accordance with their own terms of use or data protection notices. As a result, these third parties may be able to infer a relationship between customers, availabill and merchants.
1.6 How long does availabill store the data and when is it deleted?

We store data for as long as required by the applicable legal provisions or the purpose of the processing. The duration of storage therefore depends on the legal and internal regulations. Availabill also takes into account retention obligations and processing purposes and the need to protect its own interests (e.g. to enforce or defend against claims and to ensure IT security). If these purposes have been achieved or no longer apply and there is no longer an obligation to retain the data, availabill deletes or anonymizes this data as part of the usual processes. Depending on the legal basis, this may be after more than ten years.

Documentation and evidence purposes include availabill’s interest in documenting processes, interactions and other facts in the event of legal claims and discrepancies for the purposes of IT and infrastructure security and to provide evidence of good corporate governance and compliance. Retention may be technically necessary because certain data cannot be separated from others and this data must continue to be stored together with them (e.g. in the case of backup or document management systems).

1.7 How does availabill protect the data?

Availabill takes appropriate security measures of a personal, technical and organizational nature in order to maintain the security of data, to protect it against unauthorized or unlawful processing and to counteract the risk of loss and unintentional alteration, unwanted disclosure or unauthorized access.

These security measures include the encryption and pseudonymization of data, logging, access restrictions, the storage of backup copies, instructions to employees, confidentiality agreements and controls. In addition, availabill also obliges third parties to take appropriate, state-of-the-art security measures. However, security risks cannot be completely ruled out. Residual risks are unavoidable.

1.8. What rights do customers have in relation to their data?

Customers have the right to request certain information about data and its processing by us (right of access). Customers also have various rights that help to control the processing of data by us. They can request that we correct or complete incorrect or incomplete data (rectification). You can also request that we delete certain data. If we provide information about an automated decision, customers have the right to express their point of view and to request that the decision be reviewed by a natural person.

If rights are exercised, customers must contact availabill with a signed letter and a legible copy of their ID. A revocation can be made by other means, provided that we make these available. It should be noted that these rights are subject to legal requirements and restrictions and therefore cannot be exercised in full in every case. We will inform you if exceptions apply. These rights can also be exercised vis-à-vis other bodies that cooperate with availabill on their own responsibility. Insofar as the requirements of the applicable law are met, customers and other data subjects therefore have the following rights:

  • Access to information about your own data;
  • Correction of incorrect or incomplete data;
  • Deletion of own data;
  • Restriction of data processing of own data;
  • Submitting a complaint against the way in which data is processed.
1.9. Do customers have a right of withdrawal?

Customers have the right to withdraw their consent at any time with effect for the future. In certain cases, customers can also object to data processing (e.g. in the case of data processing in connection with advertising). However, processing activities carried out in the past on the basis of consent are not rendered unlawful by the customer’s withdrawal of consent.

In cases where data processing is absolutely necessary for the provision of the service or for the fulfillment of the contract for the payment methods “purchase on account” and “purchase in installments” (e.g. data processing for risk purposes), revocation is not possible. In such cases, it is only possible to waive this data processing by terminating the contractual relationship.

2. provisions for visiting our websites

The information published on our websites does not constitute a recommendation to enter into transactions, other legal transactions or offers. Products and services presented by third parties may not be available for purchase by residents of certain countries. If problems arise in a contractual relationship between you and a third party, you must hold the third party liable as the injured party. We are not liable for any damages arising from contractual relationships with third parties.

Although we take every care to ensure that the information published on our websites is correct at the time of publication, no representation or warranty, express or implied, is given as to the accuracy, reliability, timeliness or completeness of the information.

We assume no responsibility and give no assurance that the functions will be available without interruption or that the respective server is free of viruses or other harmful components.

availabill assumes no liability for direct or indirect, direct or indirect damages and losses of any kind that may result from the following reasons, even in the event of negligence:

  • from access to services;
  • from the inability to access or use services;
  • from linking or accessing links to other websites of third parties;
  • due to manipulation of the Internet user’s IT systems by unauthorized persons;
  • from contact via the Internet or e-mail with availabill.

availabill websites are not intended for visitors who are subject to a jurisdiction that prohibits or otherwise restricts access to or dissemination, publication, provision or use of the information contained therein. Persons who are subject to such restrictions are not permitted access and access must be refrained from.

By accessing availabill websites, you agree to these terms and conditions.

We use the term “cookies” to refer to cookies and similar technologies that are used in the context of electronic communication. With the following information, we inform you about the most important aspects of the processing of your data in the context of the use of our websites and social media channels. As a rule, you can also use our websites and social media channels without providing us with personal data such as your name or email address. In this case, we can clearly assign the data collected in connection with the corresponding use to specific visitors, but not to persons known by name. In this sense, online data is generally not personal. However, if you provide us with your name, an e-mail address or other personal data in this context, we will process this data. In addition to this processing, we can also establish a connection between you and otherwise non-personal data.

This cookie policy applies to all websites for which we are responsible. Our websites may contain links to third-party websites. These websites are not subject to this Cookie Policy. We are neither responsible for their content nor for their handling of personal data. We recommend that you read the data protection declarations of the respective website providers.

3.1 What are cookies and similar technologies?
  • Cookies are small files that are transmitted to your end device and stored there when you visit a website. In particular, a cookie contains information about the origin of the website and the lifespan of the cookie (i.e. how long it remains stored on your end device). Some cookies are deleted again at the end of the browser session (session cookies). Other cookies remain on your end device (persistent cookies).
  • If you visit these websites again, we can record your renewed visit, even if we do not know your identity. Cookies can also be used to collect information about your usage behavior.
3.2 Which cookies do we use?

We use cookies for the operation of our websites insofar as they are technically necessary, as well as for statistical purposes and to improve user-friendliness.

  • Technically necessary cookies are required for the technical operation of the websites, enable security-relevant functionalities and serve the purpose of user-friendliness. Technically necessary cookies cannot be switched off in our systems. However, you can set your browser so that these cookies are blocked or reported to you; however, this may result in parts of our websites not functioning properly.
  • Analysis and statistics cookies are used to improve our websites and the placement of offers. For this purpose, we use cookies to collect data on the use and behavior of visitors to our websites. This enables us to record traffic and usage, determine the impact of our websites and optimize content accordingly. They help us to find out which pages are the most and least popular and to track how visitors move around the websites. You can reject analysis and statistics cookies in the settings.

The use of cookies is based on our legitimate interest in providing user-friendly and attractive websites and ensuring the fulfillment of contracts.

3.3 How can you control the use of cookies?
  • If you do not want to allow or deactivate cookies, the functionality of our websites may be restricted. If you do not want cookies, you can set up your web browser so that it informs you about the setting of cookies and you only allow this in individual cases. You can also set your web browser so that cookies are automatically deactivated.
  • Please note that most web browsers offer options to protect your privacy. Although most web browsers automatically accept cookies, they offer the option of blocking or deleting them. The instructions for managing cookies on your browser can usually be found under the help function of the browser or in the operating instructions of your mobile device.
3.4 How and where is your data stored?
  • We would like to point out that the IP address of the end device is stored by the website operator when you visit our website. For technical reasons, further log data is recorded, e.g. information about the Internet service provider, information about the operating system of the end device and the browser used, information about the referring URL (origin), date and time of access and content accessed. Under certain circumstances, personal data such as the name and address of the visitor may also be recorded, e.g. if you register on a website. In this case, we may also process log data on a personal basis.
  • We process personal data that is necessary for the fulfillment of the contract or in the context of business initiation or for which you have given us your separate consent. Consent can be revoked at any time with effect for the future. Personal data that is communicated to us via our websites is only stored until the purpose has been fulfilled or until statutory retention periods prescribe this.
  • However, we may use service providers to process data in connection with our websites and social media channels who carry out evaluations for us on the basis of this data. In this case, your data may also be transferred abroad, including to countries outside the EU or the European Economic Area. These third countries may not have laws that protect your data to the same extent as in Switzerland, the EU or the EEA. In this case, we ensure data protection through data transfer agreements. In certain cases, we may also transfer data without such contracts in accordance with data protection regulations, e.g. if you have consented to the corresponding disclosure or if the disclosure is necessary for the execution of the contract, for the establishment, exercise or enforcement of legal claims or for overriding public interests.

Regardless of the measures taken to protect your data, data protection and confidentiality may be restricted when data is processed via universally accessible media. When using the Internet as a transmission medium with a computer, smartphone or other end device, the possibility of third parties gaining access to your data cannot be ruled out due to its design. Any liability for direct and indirect damages arising as a result of such data transmission in connection with the use of our websites is rejected in full.

3.5 For what purposes do we use online data?

We use cookies and the data collected by cookies as well as the data contained in the aforementioned log files (log data; hereinafter collectively referred to as “online data”) in particular for the purposes stated below.

  • Operation of the online offering: Log data is automatically collected when you use the online offering, which is why it is necessary for the operation of the online offering. We also require other online data, in particular data collected via cookies, so that certain functions of the online service can be offered or so that we can ask you for your consent to the use of cookies and other technologies.
  • Provision of certain content and functions: If you use content and functions of our website and disclose data to us in the process, e.g. if you register for a newsletter, we will process the online data you submit in accordance with the respective purpose of the function or content.
  • Security and stability: We use online data to improve the security and stability of our online offering. As a rule, we do not require any directly personal data for this purpose. If we can assign cookies to you personally, we can use them for security and stability purposes where necessary, but also on a personal basis.
  • Statistics: We use personal and non-personal online data for statistical purposes, i.e. for evaluations with the aim of obtaining certain information, e.g. information about fluctuations in the use of the online offer. This information is aggregated, i.e. no longer personal.
  • Improvement of offers: We use online data to continuously improve our online offerings. However, we only use online data for this purpose in aggregated form.
  • Communication: We use online data to communicate with you via electronic channels. For this purpose, we process the content of the communication, but also log data about the type and time of the communication.
  • Compliance with legal and regulatory requirements: We may process online data in order to comply with laws, directives and recommendations from authorities and internal regulations. This includes the prevention, detection and investigation of criminal offenses and other violations, internal and external investigations and the disclosure of online data to an authority.
  • Defense and enforcement of claims: We may use online data for civil and criminal prosecution or defense in such proceedings.
3.6 How do we obtain evaluations and statistics?

We use service providers to analyze the behavior of visitors. They may receive log data and other online data from us and may themselves use cookies and similar technologies to collect online data about our online offering. However, we do not provide them with any directly personal data such as your name or e-mail address.

Three of the most important service providers are “Google, Complianz and Clarity”. You will find more information on these below:

Google Analytics: We use the “Google Analytics” analysis service operated by a Google company in Ireland (Google). Cookies are used to record data about the behavior on our online offer (duration and frequency of page views, content accessed, geographical origin of access, etc.), and on this basis Google creates evaluations of the use of our online offer for us. Google uses Google LLC in the USA as a processor, whereby IP addresses (this is the easiest way to identify individual persons) are shortened before being forwarded to Google LLC. We have deactivated the settings “Data transfer” and “Signals”. Nevertheless, we cannot rule out the possibility that Google may use the online data collected for its own purposes to draw conclusions about the identity of visitors, create personal profiles and link this data to Google accounts. Information on Google’s data protection policy is available at www.google.com/privacy.html. You can find information on Google Analytics data protection at https://support.google.com/analytics/answer/6004245?hl=de, and if you have a Google account, you can find information on processing by Google at https://policies.google.com/technologies/partner-sites?hl=de. You can deactivate Google Analytics by installing a browser extension under the following link: https://tools.google.com/dlpage/gaoptout?hl=de.

Complianz.io: With complianz.io we manage and store the consent status on the websites. Complianz is a cookie consent tool that allows us to check whether you have accepted the cookie preference box in our cookie banner. These cookies are categorized as functional cookies and cannot be deactivated via the cookie settings. However, information collected and stored through the use of these cookies is not stored for longer than one year and is not processed outside Switzerland or the European Union. We do not transmit any data to Complianz.io that can be linked to you.

Clarity: Another example of a service for the statistical analysis of our users’ needs is Clarity, a service provided by Microsoft Corporation. Clarity works with cookies and other technologies to collect data about the behavior of the users of our online offer and their end devices, in particular the IP address of the end device (which is only recorded anonymously), screen size, device type, information about the browser used and the location (country only) and language setting of the browser. Clarity stores this information in a pseudonymized user profile and uses it for evaluations with which we can better understand the needs of the users of the online offer and improve the online offer and better align it to our users. You can find further information at https://clarity.microsoft.com/

etracker: As a further analysis service on our website, we use etracker from etracker GmbH in Hamburg, Germany. We use etracker to analyze the behavior of visitors to our website in order to optimize our offering and make it more user-friendly. etracker processes the following data: Pseudonymized IP address, technical information (e.g. browser type, operating system, end device), usage data (e.g. pages visited, length of stay, interactions), referrer URL and subsequent pages. The data is anonymized and not used to identify individual persons. etracker has been independently audited and awarded the ePrivacyseal data protection seal of approval. Further information can be found at www.etracker.com.

3.7 How do we integrate social media on our websites?
  • Instagram linkOur website uses a link to the social media platform Instagram, which is operated by Instagram LLC, 1601 Willow Road, Menlo Park, CA 94025, USA. The link is marked with an Instagram logo in the form of an “Instagram camera”. If you click on the Instagram button, you will be redirected to your user account in a separate browser window if you are logged into your Instagram user account. This establishes a direct link between your browser and the Instagram server. This information (including your IP address) is transmitted directly from your browser to an Instagram server in the USA and stored there. If you are logged in to Instagram, Instagram can directly associate your visit to our website with your Instagram account. If you do not want Instagram to associate the data collected via our website directly with your Instagram account, you must log out of Instagram before visiting our website. Further information on this can be found in Instagram’s privacy policy ( https://help.instagram.com/155833707900388).
  • LinkedIn Link: Our website uses a link to the LinkedIn network. The provider is LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA. If you click on the “LinkedIn button”, you will be redirected to your user account in a separate browser window, provided you are logged into your LinkedIn user account. This establishes a direct connection between your browser and the LinkedIn server. LinkedIn receives the information that you have visited our website with your IP address. In addition, LinkedIn is then able to associate your visit to our website with you and your user account. We would like to point out that we have no knowledge of the content of the transmitted (personal) data or its use by LinkedIn. Further information on this can be found in LinkedIn’s privacy policy at: https://www.linkedin.com/legal/privacy-policy.
  • Embedded YouTube videos: We embed YouTube videos on some of our websites. The operator is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA. When you visit a page with the YouTube plugin, a connection to YouTube servers is established. YouTube is informed which pages you visit. If you are logged into your YouTube account, YouTube can assign your surfing behavior to you personally. You can prevent this by logging out of your YouTube account beforehand. When a YouTube video is started, the provider uses cookies that collect information about user behavior. If you have deactivated the storage of cookies for the Google Ad program, you will not have to expect any such cookies when watching YouTube videos. However, YouTube also stores non-personal usage information in other cookies. If you wish to prevent this, you must block the storage of cookies in your browser. Further information on data protection at “Youtube” can be found in the provider’s privacy policy at https://www.google.de/intl/de/policies/privacy
3.8 Making contact

When contacting us (e.g. by contact form, email, telephone or via social media), the user’s details are processed to handle the contact request and its processing. The user’s details may be stored in a customer relationship management system (“CRM system”) or comparable inquiry organization. We delete the inquiries if they are no longer required. We review the necessity every six months; the statutory archiving obligations also apply.

3.8.1 How do we handle newsletters?

The following information explains the content of our newsletter as well as the registration, dispatch and statistical evaluation procedure and your rights of objection. By subscribing to our newsletter, you agree to receive it and to the procedures described.

We only send newsletters, emails and other electronic notifications containing advertising information with the consent of the recipient or with legal permission. If the contents of the newsletter are specifically described when registering for the newsletter, they are decisive for the user’s consent. Our newsletters also contain information about digital education, teaching materials for teachers and interesting events for teachers and other people from the education sector.

The registration for our newsletter takes place in a so-called double opt-in procedure. This means that after registering, you will receive an e-mail asking you to confirm your registration. This confirmation is necessary so that no-one can register with other people’s e-mail addresses.

Subscriptions to the newsletter are logged in order to be able to prove the registration process in accordance with legal requirements. This includes storing the time of registration and confirmation as well as the IP address. Changes to your data stored with MailChimp are also logged.

The newsletter is sent using “MailChimp”, a newsletter dispatch platform of the US provider Rocket Science Group, LLC, 675 Ponce De Leon Ave NE #5000, Atlanta, GA 30308, USA.

The email addresses of our newsletter recipients, as well as their other data described in this notice, are stored on MailChimp’s servers in the USA. MailChimp uses this information to send and analyze the newsletter on our behalf. Furthermore, MailChimp may, according to its own information, use this data to optimize or improve its own services, e.g. for the technical optimization of the dispatch and presentation of the newsletter or for economic purposes in order to determine from which countries the recipients come. However, MailChimp does not use the data of our newsletter recipients to write to them itself or to pass it on to third parties.

We trust in the reliability and IT and data security of MailChimp. MailChimp is certified under the US-EU data protection agreement “Privacy Shield” and thus undertakes to comply with EU data protection regulations. Furthermore, we have concluded a “Data Processing Agreement” with MailChimp. This is a contract in which MailChimp undertakes to protect the data of our users, to process it on our behalf in accordance with its data protection regulations and, in particular, not to pass it on to third parties. You can view MailChimp’s privacy policy here.

To subscribe to the newsletter, simply enter your e-mail address. Optionally, we ask you to enter your first and last name. This is only for the personalization of the newsletter.

The newsletters contain a so-called “web-beacon”, i.e. a pixel-sized file that is retrieved from the MailChimp server when the newsletter is opened. As part of this retrieval, technical information, such as information about the browser and your system, as well as your IP address and time of retrieval, is initially collected. This information is used for the technical improvement of the services based on the technical data or the target groups and their reading behavior based on their retrieval locations (which can be determined with the help of the IP address) or the access times.

The statistical surveys also include determining whether the newsletters are opened, when they are opened and which links are clicked. For technical reasons, this information can be assigned to individual newsletter recipients. However, it is neither our intention nor that of MailChimp to observe individual users. The evaluations serve us much more to recognize the reading habits of our users and to adapt our content to them or to send different content according to the interests of our users.

There are cases in which we direct newsletter recipients to the MailChimp website. For example, our newsletters contain a link that newsletter recipients can use to retrieve the newsletter online (e.g. in the event of display problems in the email program). Newsletter recipients can also correct their data, such as their email address, at a later date. MailChimp’s privacy policy is also only available on their website.

In this context, we would like to point out that cookies are used on MailChimp’s websites and that personal data is therefore processed by MailChimp, its partners and service providers (e.g. Google Analytics). We have no influence on this data collection. Further information can be found in MailChimp’s privacy policy.

You can unsubscribe from our newsletter at any time, i.e. revoke your consent. Your consent to receive the newsletter via MailChimp and the statistical analyses will expire at the same time. Unfortunately, it is not possible to cancel the sending of the newsletter via MailChimp or the statistical analysis separately. You will find a link to unsubscribe from the newsletter at the end of each newsletter.

4. privacy policy for my.availabill

The privacy policy for my.availabill informs users and visitors to the my.availabill.ch website (“user” or “you”) about the processing of data in connection with the use of my.availabill.

4.1 What data is processed?

We process the following categories of data in particular

4.1.1 Data disclosed by the users

When registering and logging in to my.availabill.ch, as well as in the context of managing the user account, users may be asked to provide their title, name, date of birth, e-mail address, cell phone number, card number and activation code, among other things, at my.availabill.ch.

4.1.2 Information provided in my.availabill

Information about users, their invoices for purchases from merchants associated with Availabill and about cards registered on my.availabill.ch, which are stored in the user account.

4.2. What is the data used for and how is it processed?
4.2.1 Provision of digital services on my.availabill
  • Enabling registration, login to and use of my.availabill Digital Services;
  • Authentication of users when performing actions. Mobile devices used are clearly assigned to users when they register on my.availabill. Availabill can thus ensure that the confirmation actions are carried out on the website or with the registered mobile devices;
  • Communication with users and transmission of information in connection with fraud alerts and fraud monitoring, on behalf of the merchant and the card issuer, and as the operator of my.availabill (e.g. the provision of invoices) via my.availabill and the mobile device;
  • Receiving messages from users, e.g. via the contact form;
  • Display of transactions and invoices
  • Transmission of confirmation requests, e.g. via push message or SMS code; establishment of a secure connection between my.availabill and the user’s mobile devices.
4.2.2 Marketing
  • Transmission of information via my.availabill on existing or new products and services (also from third parties) to users;
  • Users may withdraw their consent to the processing of data for marketing purposes at any time by notifying Availabill.
4.2.3 Market research and improvement of services
  • Availabill also processes user data for market research purposes and to improve its services. Availabill uses master data, behavioral data and preference data in particular for this purpose;
  • Availabill analyzes which services are used by which user groups and in what way in order to determine the market acceptance of existing products and services and the market potential of new ones.
4.2.4 Security purposes and access controls
  • Availabill also uses user data – in particular master data, technical data, behavioral data and other data – for security purposes and for access control;
  • This also includes controlling access to my.availabill (e.g. login data and user accounts).
4.2.5 Communication
  • Communication with users and third parties in order to provide information or send messages. Availabill uses master data and communication data for this purpose and generally stores this data in order to document communication with users;
  • If the Users contact Availabill by e-mail – whether by using a published e-mail address or a contact form – the Users expressly authorize Availabill to reply via the same channel to the sender’s address or to the address provided.
4.2.6 Further processing purposes
  • Proof of actions and defense of claims against Availabill;
  • Compliance with legal and regulatory requirements;
  • Training and educational purposes;
  • Administrative purposes, such as the management of master data, accounting and data storage as well as the management of the IT infrastructure.
4.3. To whom do we disclose data?
4.3.1 Availabill-internal persons

Within Availabill, persons and company units have access to user data to the extent necessary for the purposes set out in this privacy policy and for the use of my.availabill.

4.3.2 Service providers

Availabill works with service providers and subcontracted auxiliary persons (so-called order processors) in Switzerland and abroad (e.g. consulting, software and maintenance work, customer service, IT services, sending information, marketing, sales and market research services) to provide the services and data processing indicated in this privacy policy. Where necessary, data is forwarded to service providers and order processors. Availabill ensures that data protection is safeguarded during the processing of data by service providers and processors by selecting the processors and through suitable contractual agreements.

4.3.3 Third parties

Third parties are persons or companies that process user data for their own purposes. Third parties are not service providers commissioned by Availabill. In connection with my.availabill, Availabill does not pass on any data to third parties for their own purposes; this applies in particular to transaction data or customer, consumer and preference profiles. An exception to this principle is the forwarding of my.availabill data that has been expressly requested by users or to which they have expressly consented.

4.3.4 Authorities and other official bodies

Availabill may disclose data to public authorities, courts and other authorities or official bodies if Availabill is legally obliged or entitled to do so or in order to protect its own rights and legitimate interests.

4.3.5 Electronic data transmission

User data may be transferred to third parties in Switzerland and abroad during electronic data transmission, even without availabill’s involvement. In particular, when using the my.availabill website and/or mobile devices, manufacturers of devices or software (such as Apple or Google) may receive data. Third parties may process and also pass on this data in accordance with their own terms of use or data protection notices. As a result, these third parties may be able to infer a relationship between users, Availabill, Merchants from the Availabill partner network and the card issuer.

4.4 What data is disclosed to other recipients?

The transmission of information between Availabill and the web and/or mobile devices of the users is encrypted – with the exception of sending SMS. However, communication with users takes place via public communication networks. This data can in principle be viewed by third parties, can be lost during transmission or can be intercepted by unauthorized third parties. It therefore cannot be ruled out that third parties may gain access to communication with users when using my.availabill despite all security measures.

When using the internet, data may also be transmitted via third countries even if the users are located in Switzerland. These third countries may not offer the same level of data protection as Switzerland.

4.5 How long does Availabill store data on availabill.ch and when does Availabill delete it?

Availabill only stores data for as long as is necessary for the purpose for which it was collected. Availabill also stores data if a legitimate interest in the storage is justified, e.g. if Availabill needs data to enforce or defend against claims, to ensure IT security or if limitation periods are affected. Finally, Availabill stores data in order to comply with regulatory and legal obligations.

If users no longer use my.availabill and deactivate their access, Availabill deletes all data stored on my.availabill.ch (e.g. access data) that does not have to be retained due to statutory retention obligations or contractual obligations.

Data for which there is no legal basis for processing or storage can be further processed anonymously. Data that must be stored for a longer period of time due to statutory retention obligations is excluded from deletion or anonymization.

4.6 How does Availabill protect the data in my.availabill?

Availabill’s IT infrastructure complies with international security standards through the use of modern security software. Availabill also takes additional security precautions for access to user accounts via the Internet as well as technical and organizational measures to protect data from loss, unauthorized access or misuse.

Regardless of the measures taken, when using the Internet as a transmission medium via computer, smartphone or other end device, it cannot be ruled out that third parties may gain access to user data.

Availabill accepts no liability whatsoever for direct or indirect damage arising in connection with the use of my.availabill. This also applies to damage caused by viruses and targeted hacker attacks.

4.7 What rights do users have in connection with their data?

If the requirements of the applicable law are met, users have the following rights:

  • Access to information about your own data, how Availabill processes it and copies of it;
  • Correction of incorrect or incomplete data;
  • Deletion of own data;
  • Restriction of the processing of personal data;
  • Submitting a complaint against the way in which data is processed to a competent data protection authority;
  • Revocation of a given consent to data processing, whereby the data can continue to be processed by Availabill to the extent permitted by law in the event of revocation.

If Availabill informs users of an automated decision, they have the right to lodge a complaint and have the decision reviewed by a natural person. To exercise these rights, users must make their claims in writing and enclose a copy of their ID. A revocation can be made by other means, provided Availabill makes these available (e.g. in my.availabill). These rights may be subject to legal requirements and restrictions, which is why they cannot always be exercised in full. For example, there are statutory retention obligations.

Furthermore, users pursuant to para. 1.4. that data may also be held by other data controllers. In order to safeguard the rights of data subjects under data protection law, users must contact them directly.

4.8 How is business communicated?

By using my.availabill, users expressly agree that Availabill may contact them for business, administrative communication via the registered and verified e-mail address (so-called primary e-mail address).

Version September 1, 2023

Availabill AG, Hagenholzstrasse 85a, 8050 Zurich, phone +41 58 433 22 00

How can we help?

Here you will find all available contact options to get answers to all your questions and requests.

Contact us