Disclaimer
This English version of the Privacy Policy is provided for your convenience. In the event of any discrepancy between this translation and the German original, the
German version shall prevail and be legally binding.
01
Data Controller
The data controller as defined by the Swiss Federal Act on Data Protection (FADP / nDSG) and the EU General Data Protection Regulation (GDPR) is:
For individuals residing in the EU or EEA, the GDPR applies additionally. For inquiries regarding your GDPR rights, please contact one of the email addresses listed above.
02
Principles of Data Processing
candea processes personal data only to the extent necessary to provide our consulting services. We follow these principles:
- Lawfulness – We process data only based on legal grounds or your consent.
- Purpose limitation – Data is collected only for specified, clearly defined purposes and not processed beyond them.
- Proportionality – We collect only the data actually required for the respective purpose.
- Accuracy – We take appropriate measures to correct or delete inaccurate data.
- Data security – We protect personal data through appropriate technical and organizational measures.
- Transparency – You are informed about the data processing that concerns you.
03
What Data We Process
Depending on the nature of your contact with candea, we process different categories of personal data:
| Category | Examples | Context |
| Contact data | Name, email, phone, company name, role | Initial contact, engagements |
| Communication data | Email content, meeting notes | Inquiries, consulting |
| Contract data | Engagement details, fee agreements, project documents | Engagement execution |
| Financial data | Billing address, payment details (for invoicing only) | Accounting |
| Usage data | IP address, browser type, page views, timestamps | Website operations |
| HR-related data | Organizational charts, anonymized employee data (within HR engagements) | HR engagements (confidential) |
We generally do not process special categories of personal data unless expressly agreed for a specific engagement and legally permissible.
04
Purposes and Legal Bases
| Purpose | Legal Basis (FADP / GDPR) |
| Responding to inquiries and initial conversations | Legitimate interests / pre-contractual measures (Art. 6(1)(b) GDPR) |
| Conclusion and execution of consulting engagements | Contract performance (Art. 6(1)(b) GDPR) |
| Invoicing and accounting | Legal obligation / contract performance (Art. 6(1)(b) and (c) GDPR) |
| Website operation and optimization | Legitimate interests (Art. 6(1)(f) GDPR) |
| Legal retention and documentation obligations | Legal obligation (Art. 6(1)(c) GDPR) |
| Relationship management and networking | Legitimate interests (Art. 6(1)(f) GDPR) |
05
Website Operation and Technical Data
When visiting www.candea.ch, the web server automatically records technical data ("server log files"): IP address, date and time of access, pages viewed, browser type and version, and operating system. This data is used exclusively for technical website operation and deleted within 30 days at the latest.
Hosting note
The website is hosted with a Swiss or European hosting provider. We currently use no analytics tools (e.g., Google Analytics), no advertising technologies, and no social media tracking pixels.
06
Email Contact
When you contact us by email, we process your data to respond to your inquiry and to prepare for a possible collaboration. This data is not shared with third parties and is deleted once the purpose has lapsed and no legal retention obligation remains.
Note
Email is not a fully encrypted communication channel. For particularly confidential information, we recommend contacting us by phone first.
07
Consulting Engagements and Contract Data
In the context of consulting engagements, we process contact details of designated contacts, HR data of employees (where contractually agreed), financial data, and engagement-related communication. For data processing on behalf of clients, we enter into a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR. The confidentiality of all information obtained during an engagement is protected by NDA agreements.
08
Disclosure of Personal Data
candea does not generally share your personal data with third parties. Disclosure only occurs to processors (e.g., hosting providers), under a legal obligation to disclose, with your explicit consent, or where required for a commissioned engagement. We do not share data for advertising purposes, nor do we sell personal data.
09
International Data Transfers
Personal data is generally processed in Switzerland or within the EU/EEA. For international engagements, we ensure an adequate level of data protection through appropriate measures.
Note
Switzerland is recognized by the EU Commission as providing an adequate level of data protection (Art. 45 GDPR). Data transfers between Switzerland and the EU/EEA are therefore permitted without additional safeguards.
10
Retention and Deletion
| Data Category | Retention Period |
| General inquiries (without engagement) | 12 months after end of communication |
| Contract data / engagement documents | 10 years after engagement closure (Swiss Code of Obligations, Art. 958f) |
| Invoice records / accounting | 10 years (Swiss tax and commercial law) |
| Server log files (website) | Maximum 30 days |
| Engagement-related HR data of third parties | Deleted / returned after engagement closure |
11
Data Security
candea implements appropriate technical and organizational measures to protect your personal data:
- Encrypted data transmission via HTTPS (TLS/SSL)
- Password protection and access control for engagement-related documents
- Confidentiality obligations for all individuals with data access
- Regular review of security measures
- Careful selection and review of processors
12
Your Rights
Under the Swiss FADP and — where applicable — the GDPR, you have the following rights:
Right
Description
Legal Basis
Access
Information about processed data
Art. 25 FADP; Art. 15 GDPR
Rectification
Correction of inaccurate data
Art. 32 FADP; Art. 16 GDPR
Erasure
Deletion of data (unless retention is required)
Art. 32 FADP; Art. 17 GDPR
Restriction
Restriction of processing
Art. 18 GDPR
Data portability
Data in a machine-readable format
Art. 20 GDPR
Objection
Objection to legitimate interests
Art. 21 GDPR
To exercise your rights, please contact us in writing. We will process your request within 30 days, free of charge.
13
Cookies and Tracking
The website www.candea.ch uses only technically necessary cookies. Analytics cookies, marketing cookies, and social media plugins are not used. Should we introduce such cookies in the future, we will inform you and — where required — obtain your consent.
14
Changes to this Policy
candea reserves the right to update this Privacy Policy at any time. The current version is always available at www.candea.ch. The version in force at the time of data processing always applies.
Last updatedMay 2026 · candea GmbH, Zurich
15
Contact and Right to Lodge a Complaint
For questions about data protection or to exercise your rights, please contact:
You have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC):
FDPIC – Swiss Supervisory Authority
Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Feldeggweg 1, 3003 Bern, Switzerland
www.edoeb.admin.ch
Individuals residing in the EU or EEA additionally have the right to contact the competent national data protection authority (Art. 77 GDPR).