Privacy Policy & Cookie Policy
of https://www.visium.com/
Table of contents
1. Data controller and Website operator
1.1. The website available at https://www.visium.com/ (the “Website”) is operated by Visium SA, a company incorporated under the laws of Switzerland, with its registered office in Prilly, Canton of Vaud, Switzerland (“Visium”, “we”, “us” or “our”).
1.2. Visium acts as the controller of Personal Data within the meaning of Regulation (EU) 2016/679 (the “GDPR”) and the Swiss Federal Act on Data Protection of 25 September 2020 (the “FADP”) in respect of Personal Data Processed through the Website.
1.3. References in this Policy to “Applicable Data Protection Law” include, as applicable, the GDPR and the FADP.
1.4. Where both the GDPR and the FADP apply, Visium will comply with each regime. References to a legal basis under the GDPR describe the basis on which Visium relies where the GDPR applies. Under the FADP, Processing is carried out in accordance with the applicable processing principles and, where necessary, the justifications available under Swiss law.
2. Purpose and scope of this Policy
2.1. This Privacy and Cookie Policy (the “Policy”) sets out:
2.1.1. the categories of information and Personal Data that we collect through the Website;
2.1.2. the purposes for which, and the legal bases on which, such Personal Data is Processed;
2.1.3. the periods for which Personal Data is retained;
2.1.4. the persons to whom Personal Data may be disclosed or transferred, including recipients outside the European Economic Area (the “EEA”) and Switzerland;
2.1.5. the measures applied to safeguard Personal Data; and
2.1.6. the rights that Users may exercise in relation to their Personal Data.
2.2. Our objective is to limit the collection and Processing of Personal Data to what is strictly necessary to provide, maintain and improve the Services, while ensuring a high standard of privacy protection. This objective includes compliance with the principles of lawfulness, good faith, transparency, purpose limitation, proportionality, data minimisation, accuracy, storage limitation, data security, privacy by design and privacy by default.
3. Meaning of Personal Data and other defined terms
3.1. “Personal Data”:
3.1.1. under the GDPR, means any information relating to an identified or identifiable natural person. A natural person is identifiable if that person can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, an online identifier, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity; and
3.1.2. under the FADP, means any information relating to an identified or identifiable natural person.
3.2. For the purposes of this Policy:
3.2.1. “User” means any natural or legal person who accesses or uses the Website;
3.2.2. “Newsletter” means the periodic information about Visium that a User has agreed to receive by email;
3.2.3. “Terms” means Visium’s Website Terms, as amended from time to time; and
3.2.4. “Content” and “Services” have the meanings given to those terms in the Terms.
4. Meaning of Processing
4.1. “Processing” of Personal Data:
4.1.1. under the GDPR, means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, including, without limitation:
4.1.1.1. collection, recording and organisation;
4.1.1.2. structuring and storage;
4.1.1.3. adaptation or alteration;
4.1.1.4. retrieval and consultation;
4.1.1.5. use and disclosure by transmission, dissemination or otherwise making available;
4.1.1.6. alignment or combination; and
4.1.1.7. restriction, erasure or destruction; and
4.1.2. under the FADP, means any handling of Personal Data, irrespective of the means and procedures applied.
4.2. Any handling of Personal Data in connection with the Website falls within this broad concept of Processing.
5. Special categories of Personal Data and sensitive Personal Data
5.1. Visium does not intentionally collect or otherwise seek to Process:
5.1.1. special categories of Personal Data within the meaning of Article 9 of the GDPR, including data revealing or concerning:
5.1.1.1. racial or ethnic origin;
5.1.1.2. political opinions;
5.1.1.3. religious or philosophical beliefs;
5.1.1.4. trade union membership;
5.1.1.5. physical or mental health;
5.1.1.6. genetic or biometric data Processed for the purpose of uniquely identifying a natural person; or
5.1.1.7. a natural person’s sex life or sexual orientation;
5.1.2. Personal Data relating to criminal convictions and offences, or related security measures, within the meaning of Article 10 of the GDPR; or
5.1.3. sensitive Personal Data within the meaning of Article 5(c) of the FADP, including Personal Data relating to:
5.1.3.1. a User’s intimate sphere;
5.1.3.2. administrative or criminal proceedings or sanctions; or
5.1.3.3. social assistance measures.
5.2. We design our systems and practices with a view to avoiding the collection of such data in connection with the Website.
5.3. Users should not submit any special category of Personal Data and/or sensitive Personal Data through the contact form. If such data is nevertheless provided, Visium will Process it only to the extent permitted by Applicable Data Protection Law and, where consent is required, on the basis of the User’s valid and express consent.
6. Categories and sources of data collected
6.1. We distinguish between:
6.1.1. metadata and other information, which may or may not, in isolation, constitute Personal Data (for example, technical and usage data); and
6.1.2. Personal Data in the strict sense, which is typically provided directly by Users who subscribe to the Newsletter or contact us through the Website.
6.2. Metadata is collected in respect of all Users and may include information obtained through small data files placed on a User’s computer or mobile device when the User visits a website (“Cookies”). We use Cookies to enable the Website to function, to improve its efficiency and to obtain reporting information.
6.3. Personal Data in the strict sense is collected from Users who:
6.3.1. subscribe to the Newsletter; or
6.3.2. contact us through the Website contact form.
6.4. The specific nature of the information collected depends on how the User interacts with the Website and on the choices the User makes in relation to Cookies.
7. Metadata collected through analytics and security technologies
7.1. Google Analytics is an analytics service provided by Google that we use to understand how Users engage with the Website. It collects information about Website usage that generally relates to devices, browsers, sessions and interactions. The Website also uses security and performance technologies that place or access Cookies.
7.2. Subject to the applicable configuration and, where required, the User’s consent, we may collect the following data or categories of data:
7.2.1. _cf_bm
7.2.1.1. This is a strictly necessary Cookie used to:
7.2.1.1.1. distinguish between humans and bots;
7.2.1.1.2. support valid reporting on use of the Website; and
7.2.1.1.3. recognise new and returning Users in a browser over time.
7.2.1.2. Where the GDPR applies, the relevant Processing is carried out, as applicable, because it is necessary for the performance of a contract under Article 6(1)(b) of the GDPR and/or on the basis of Visium’s legitimate interests under Article 6(1)(f) of the GDPR. Where the FADP applies, the relevant Processing is carried out in accordance with the principles set out in Article 6(1) to (5) of the FADP.
7.2.2. _ga
7.2.2.1. This is a performance Cookie used to:
7.2.2.1.1. associate the Website with Google Universal Analytics; and
7.2.2.1.2. distinguish unique Users.
7.2.2.2. The relevant Processing is based on the User’s consent under Article 6(1)(a) of the GDPR and, where applicable, Article 6(6) of the FADP.
7.2.3. _ga_9QMBFRNBNV
7.2.3.1. This is a performance Cookie used to persist session state through Google Analytics.
7.2.3.2. The relevant Processing is based on the User’s consent under Article 6(1)(a) of the GDPR and, where applicable, Article 6(6) of the FADP.
7.2.4. _cfuvid
7.2.4.1. This is a performance Cookie used to:
7.2.4.1.1. track Users across sessions;
7.2.4.1.2. maintain session consistency; and
7.2.4.1.3. provide personalised services.
7.2.4.2. The relevant Processing is based on the User’s consent under Article 6(1)(a) of the GDPR and, where applicable, Article 6(6) of the FADP.
8. Metadata that constitutes Personal Data
8.1. Where any metadata, whether by itself or in combination with other data, constitutes Personal Data relating to an identifiable natural person, the relevant User may exercise all applicable rights specified in Section 17.
9. Personal Data collected directly from Users
9.1. If a User subscribes to the Newsletter, we collect the following Personal Data:
9.1.1. the User’s email address; and
9.1.2. the User’s name, where provided and where it constitutes Personal Data.
9.1.3. The relevant Processing is based on the User’s consent under Article 6(1)(a) of the GDPR and, where applicable, Article 6(6) of the FADP.
9.2. If a User contacts us through the Website contact form, we collect the following Personal Data:
9.3. the User’s email address; and
9.3.1. the User’s name, where provided and where it constitutes Personal Data.
9.3.2. The relevant Processing is based on the User’s consent under Article 6(1)(a) of the GDPR and, where applicable, Article 6(6) of the FADP.
10. Data retention periods
10.1. We do not retain Personal Data indefinitely. We retain Personal Data only for as long as is necessary having regard to the relevant legal basis and the purposes for which it was collected, or as otherwise required by law. The applicable retention periods are as follows:
10.1.1. Personal Data Processed on the basis of consent is retained until the relevant consent is withdrawn;
10.1.2. Personal Data Processed for the performance of a contract, including the Terms, is retained for the duration of that contract and for an additional period of six (6) years thereafter, to enable us to establish, exercise or defend legal claims and comply with statutory record-keeping requirements; and
10.1.3. Personal Data Processed on the basis of our legitimate interests is retained for as long as those legitimate interests continue to apply or until the User successfully objects to the Processing, whichever occurs first.
10.2. Where no specific contractual or statutory requirement applies, the standard maximum retention period for Personal Data will not normally exceed ten (10) years.
11. Disclosure of Personal Data to processors acting on our behalf
11.1. We may disclose Personal Data to carefully selected third parties that Process Personal Data on our behalf under a written data processing agreement. In such cases:
11.1.1. Visium remains the controller and verifies that the relevant processor is capable of ensuring appropriate data security;
11.1.2. the third party acts as a processor strictly in accordance with our written instructions; and
11.1.3. each relevant agreement contains provisions designed to ensure a level of confidentiality, integrity and security for Personal Data comparable to our own internal standards.
12. Categories of recipients of Personal Data
12.1. Recipients of Personal Data Processed on behalf of Visium may include, in particular:
12.1.1. providers of data protection, cybersecurity and IT security services;
12.1.2. providers of analytics services, including Google Analytics;
12.1.3. hosting and cloud infrastructure providers;
12.1.4. providers of software, maintenance and hardware support services;
12.1.5. marketing and/or sales representatives acting for Visium;
12.1.6. subcontractors engaged by Visium for service delivery or support;
12.1.7. survey and reporting service providers; and
12.1.8. accountants and strategic, business, legal and tax advisers.
12.2. Where required, Visium will provide information regarding the relevant recipients or categories of recipients and, in the case of disclosures abroad, the relevant destination country and applicable safeguard.
13. Transfers of Personal Data outside the EEA and Switzerland
13.1. Certain service providers and processors to whom we transfer Personal Data may be located outside the EEA and/or Switzerland, including, in particular, in the United States of America.
14. Safeguards for data international transfers
14.1. Visium seeks to minimise the scope, volume and sensitivity of Personal Data transferred to third countries.
14.2. Where Personal Data is transferred outside the EEA and/or Switzerland, as applicable, we rely on appropriate safeguards, including:
14.2.1. standard contractual clauses adopted by the European Commission and/or recognised or approved by the Swiss Federal Data Protection and Information Commissioner;
14.2.2. supplementary technical and organisational measures, where appropriate, designed to ensure a level of protection essentially equivalent to that afforded within the EEA and/or Switzerland; and
14.2.3. a determination that the destination provides an adequate level of protection, including, where the FADP applies, recognition by the Swiss Federal Council, or reliance on other appropriate safeguards.
15. Automated decision-making and profiling
15.1. Personal Data relating to Users may be Processed by automated means, which may include profiling for analytics, service optimisation and, where applicable, marketing purposes.
15.2. Where required by law, we will obtain the User’s explicit consent before carrying out specific automated decision-making or profiling that produces legal effects concerning the User or similarly significantly affects the User.
15.3. Visium may also engage or cooperate with third parties in connection with such automated Processing, subject to appropriate safeguards.
15.4. Where a decision is based exclusively on automated Processing and produces legal effects concerning a User or significantly affects the User, Visium will inform the User and will, upon request and where no statutory exception applies, allow the User to express his or her point of view and request review by a natural person.
15.5. Before commencing any Processing that is likely to result in a high risk to a User’s personality or fundamental rights, Visium will carry out a data protection impact assessment.
16. Data security measures
16.1. Visium applies physical, technical and organisational measures that it considers appropriate and reasonable and that are designed to protect Personal Data against:
16.1.1. accidental or unlawful destruction or loss;
16.1.2. unauthorised alteration; and
16.1.3. unauthorised disclosure or access.
16.2. These measures include, for example, access controls, encryption or pseudonymisation where appropriate, secure hosting arrangements, staff training, and internal policies and procedures designed to ensure compliance with Applicable Data Protection Law.
16.3. We regularly review and update our safeguards in light of technological developments, regulatory expectations and our own risk assessments.
16.4. Personal Data breaches will be notified or reported as required by the GDPR and/or the FADP.
17. Data subject rights
17.1. Once we have collected Personal Data relating to a User, that User may, as a data subject under the GDPR and/or the FADP (as applicable), exercise the following rights, subject in each case to the conditions, limitations and exceptions set out in Applicable Data Protection Law:
17.1.1. Right of access – to obtain confirmation as to whether we Process the User’s Personal Data and, where that is the case, to receive a copy of that Personal Data and further information about the Processing;
17.1.2. Right to rectification – to obtain the correction of inaccurate Personal Data and the completion of incomplete Personal Data;
17.1.3. Right to erasure (the “right to be forgotten”) – to request deletion of Personal Data in the circumstances contemplated by the GDPR, for example where the Personal Data is no longer necessary, or consent to the Processing has been withdrawn and there is no other legal ground for the Processing;
17.1.4. Right to data portability – to receive Personal Data that the User has provided to us in a structured, commonly used and machine-readable format and to transmit that Personal Data to another controller, where the Processing is based on consent or contract and is carried out by automated means;
17.1.5. Right to object – to object, on grounds relating to the User’s particular situation, to the Processing of Personal Data based on our legitimate interests, including profiling, and to object at any time to Processing for direct marketing purposes;
17.1.6. Right to withdraw consent to the Processing of metadata that has become Personal Data – where metadata or similar information constitutes Personal Data and is Processed on the basis of consent, the User may withdraw that consent at any time;
17.1.7. Right to withdraw consent to the Processing of Personal Data – where Personal Data is Processed on the basis of the User’s consent, the User may withdraw that consent at any time;
17.1.8. Right to restrict the scope of collected and Processed metadata that constitutes Personal Data – the User may request restriction of Processing in specified circumstances or exercise available opt-out mechanisms, in particular in relation to Cookies, analytics and tracking technologies; and
17.1.9. Right to lodge a complaint – if the User considers that the Processing of his or her Personal Data infringes Applicable Data Protection Law, the User may lodge a complaint with a competent supervisory authority.
17.1.10. Withdrawal of consent under Sections 17.1.6, 17.1.7 or 17.1.8 does not affect the lawfulness of Processing carried out before that consent was withdrawn.
18. How to exercise data subject rights
18.1. Rights specified in Sections 17.1.1 to 17.1.7
18.1.1. A User may exercise these rights by contacting Visium using the contact details set out in Section 19. We may need to verify the User’s identity before acting on the request.
18.2. Right specified in Section 17.1.8
18.2.1. Users may manage their preferences regarding the collection of metadata and related Personal Data by selecting the relevant Cookie options in the Website’s Cookie preference tool, including by ticking the applicable Cookie boxes as illustrated below.
18.3. Right specified in Section 17.1.9
18.3.1. A User may lodge a complaint with a competent national data protection authority. A list of European data protection authorities is available on the website of the European Data Protection Board at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.
18.3.2. In Switzerland, Users may contact the Federal Data Protection and Information Commissioner (FDPIC). Information and contact options are available at https://www.edoeb.admin.ch/.
19. Contact details of the controller
19.1. Visium’s contact details are as follows:
Visium SA
Unlimitrust Campus
Route des Flumeaux
1008 Prilly
Switzerland
email: legal@visium.com
20. Amendments to this Policy
20.1. We may amend or update this Policy from time to time. Amendments will typically reflect:
20.1.1. technological developments affecting the Website or our data Processing practices;
20.1.2. changes in applicable laws or regulatory guidance; or
20.1.3. recommendations or guidelines issued by national or international data protection authorities.
20.2. We are committed to complying with Applicable Data Protection Law and relevant regulatory expectations. Accordingly, we reserve the right to modify this Policy where we consider it necessary or appropriate to do so.
20.3. Any updated version will be published on the Website and, where legally required, we will inform Users by appropriate means.