Your Data

Pri­vacy Policy for lupus-suisse.ch

In this pri­vacy policy, we, Lupus suisse (here­in­after we), explain how we col­lect and pro­cess per­son­al data on the web­site lupus-suisse.ch. Per­son­al data refers to any inform­a­tion relat­ing to an iden­ti­fied or iden­ti­fi­able person. 

This pri­vacy policy is designed to meet the require­ments of the Swiss Data Pro­tec­tion Act (“DSG”). How­ever, wheth­er and to what extent these laws apply depends on the indi­vidu­al case. 

Respons­ib­il­ity We are respons­ible for the data pro­cessing described here, unless oth­er­wise stated in indi­vidu­al cases. If you have any data pro­tec­tion con­cerns, you can con­tact us at the fol­low­ing address: 

Respons­ible party:
Mar­tin Bien­lein, Pres­id­ent

Address:
Josef­strasse 92
8005 Zurich
Tel.: +41 44 487 60 67
Email: info@lupus-suisse.ch

Col­lec­tion and Processing

Col­lec­tion and Pro­cessing of Per­son­al Data

We primar­ily pro­cess per­son­al data that we col­lect in the course of our activ­it­ies from mem­bers, donors, spon­sors, related organ­iz­a­tions, busi­ness part­ners, self-help groups and indi­vidu­als inter­ested in self-help, or that we col­lect from users when oper­at­ing our web­site. This may include in particular: 

  • Per­son­al information
  • Con­tact inform­a­tion and location
  • Regis­tra­tion details
  • User inform­a­tion and usage data
  • Pay­ment data
  • Recruit­ment details
  • Cus­tom­er inquiries

We gen­er­ally pro­cess per­son­al data only in accord­ance with the data pro­tec­tion laws applic­able to us or if con­sent has been giv­en by the per­son con­cerned or if there is anoth­er leg­al basis. Pro­cessing is car­ried out to the extent neces­sary to ful­fill the respect­ive pur­pose. The pro­cessing of data includes in par­tic­u­lar the col­lec­tion, stor­age, use, modi­fic­a­tion, trans­mis­sion, archiv­ing and destruc­tion of col­lec­ted per­son­al data. 

In addi­tion to the data you provide to us dir­ectly, the cat­egor­ies of per­son­al data include in par­tic­u­lar your booked treat­ments and oth­er data in con­nec­tion with the use of the web­site (e.g., IP address, MAC address of the smart­phone or com­puter, inform­a­tion about your device and set­tings, cook­ies, date and time of vis­it, pages and con­tent accessed, func­tions used, refer­ring web­site, loc­a­tion information).

Pur­poses of Data Processing

We use the per­son­al data we col­lect primar­ily to provide inform­a­tion about self-help in Switzer­land and to receive dona­tions, to facil­it­ate self-help groups, and to pur­chase products and ser­vices from our sup­pli­ers and sub­con­tract­ors, as well as to com­ply with our leg­al oblig­a­tions at home and abroad.

In addi­tion, we pro­cess per­son­al data from you, to the extent per­mit­ted and deemed appro­pri­ate, for the fol­low­ing pur­poses in which we (and some­times third parties) have a legit­im­ate interest cor­res­pond­ing to the purpose:

  • Pro­vi­sion of our web­site and oth­er platforms
  • Offer­ing and fur­ther devel­op­ment of our ser­vices and websites
  • Review and optim­iz­a­tion of pro­ced­ures for needs ana­lys­is for the pur­pose of dir­ect cus­tom­er con­tact and col­lec­tion of per­son­al data from pub­licly access­ible sources for the pur­pose of cus­tom­er acquisition;
  • Advert­ising and marketing
  • Needs and opin­ion research, media monitoring;
  • Asser­tion of leg­al claims and defense in con­nec­tion with leg­al dis­putes and offi­cial proceedings
  • Pre­ven­tion and invest­ig­a­tion of crim­in­al offenses and oth­er mis­con­duct (e.g., con­duct­ing intern­al invest­ig­a­tions, data ana­lys­is for fraud prevention);
  • Ensur­ing our oper­a­tions, in par­tic­u­lar our IT, our web­sites, apps and oth­er platforms;

If you have giv­en us con­sent to pro­cess your per­son­al data for spe­cif­ic pur­poses (for example, when you register to receive news­let­ters or as a mem­ber), we pro­cess your per­son­al data with­in the scope of and based on this con­sent, unless we have anoth­er leg­al basis and we require one under the data pro­tec­tion legis­la­tion applic­able to us. Con­sent giv­en may be revoked at any time for the future, but this has no effect on data pro­cessing that has already taken place. 

Data Pro­cessing by Third Parties

a) Dona­tions

To receive dona­tions, we col­lect your data via a web applic­a­tion from Rais­eNow AG, Hardturmstrasse 101, 8005 Zurich. For this pur­pose, the per­son­al data you enter is pro­cessed by Rais­eNow AG, in par­tic­u­lar by pro­cessing your pay­ment data. Their pri­vacy policy can be found at the fol­low­ing link: https://www.raisenow.com/de-ch/datenschutz. The dona­tion is received in trust by the asso­ci­ation Fair­Give, Hardturmstrasse 101, 8005 Zurich, and for­war­ded dir­ectly to lupus suisse. Fur­ther inform­a­tion about the asso­ci­ation Fair­Give is avail­able at https://fairgive.org/.

b) Cook­ies /​ Track­ing and Oth­er Tech­no­lo­gies in Con­nec­tion with the Use of Our Website

We typ­ic­ally use “cook­ies” and sim­il­ar tech­no­lo­gies on our web­sites that can identi­fy your browser or device. A cook­ie is a small file that is sent to your com­puter or auto­mat­ic­ally stored by the web browser used on your com­puter or mobile device when you vis­it our website. 

When you vis­it this web­site again, we can recog­nize you, even if we do not know who you are. In addi­tion to cook­ies that are only used dur­ing a ses­sion and deleted after your web­site vis­it (“ses­sion cook­ies”), cook­ies can also be used to store user set­tings and oth­er inform­a­tion for a cer­tain peri­od of time (e.g., two years) (“per­man­ent cookies”). 

How­ever, you can set your browser to reject cook­ies, store them only for one ses­sion, or delete them pre­ma­turely. Most browsers are pre­set to accept cookies.

We use per­man­ent cook­ies so that you can save user set­tings (e.g., lan­guage, auto-login), so that we can bet­ter under­stand how you use our ser­vices and con­tent, and so that we can show you cus­tom­ized offers and advert­ising (which can also hap­pen on web­sites of oth­er com­pan­ies; how­ever, they do not learn from us who you are, if we even know that ourselves, because they only see that the same user who was on a cer­tain page with us is on their web­site). Some cook­ies are set by us, some also by con­trac­tu­al part­ners with whom we work. If you block cook­ies, cer­tain func­tion­al­it­ies may no longer work. 

We par­tially incor­por­ate vis­ible and invis­ible image ele­ments in our news­let­ters, to the extent per­mit­ted, through the retriev­al of which from our serv­ers we can determ­ine wheth­er and when you opened the email, so that we can also meas­ure and bet­ter under­stand how you use our ser­vices and tail­or them to you. You can block this in your email pro­gram; most are pre­set to do so. 

By using our web­site and con­sent­ing to receive news­let­ters and oth­er mar­ket­ing emails, you agree to the use of these tech­no­lo­gies. If you do not want this, you must con­fig­ure your browser or email pro­gram accordingly.

We use Google Ana­lyt­ics or com­par­able ser­vices on our web­sites, for example. This is a ser­vice provided by third parties who may be loc­ated in any coun­try in the world. 

Spe­cific­ally, we use the fol­low­ing cook­ie and track­ing tools:

Google Ana­lyt­ics and Google Search Engine: This allows us to meas­ure and eval­u­ate the use of the web­site (non-per­son­ally). Per­man­ent cook­ies from Google LLC or Alpha­bet Inc. are also used for this pur­pose, which are set by the ser­vice pro­vider Google. By set­ting these cook­ies, we can spe­cific­ally provide our web­site users with advert­ising through Google on Google plat­forms such as You­Tube or the Google Search Engine if they exhib­it cer­tain user beha­vi­or. Google Ire­land relies on Google LLC, based in the USA, as a pro­cessor. These are sub­si­di­ar­ies of Alpha­bet Inc., also based in the USA. We have con­figured the ser­vice so that the IP addresses of vis­it­ors are shortened by Google in Europe before being for­war­ded to the USA and there­fore can­not be traced back. We have dis­abled the “Data Shar­ing” and “Sig­nals” set­tings. Although we can assume that the inform­a­tion we share with Google is not per­son­al data for Google, it is pos­sible that Google can draw con­clu­sions about the iden­tity of vis­it­ors from this data for its own pur­poses, cre­ate per­son­al pro­files, and link this data with the Google accounts of these indi­vidu­als. If you have registered with the ser­vice pro­vider your­self, the ser­vice pro­vider also knows you. The pro­cessing of your per­son­al data by the ser­vice pro­vider is then car­ried out under the respons­ib­il­ity of the ser­vice pro­vider in accord­ance with its pri­vacy policy. The ser­vice pro­vider only tells us how our respect­ive web­site is used (no inform­a­tion about you personally).

We also use so-called plug-ins from social net­works such as Face­book, Twit­ter, Sound­cloud, You­Tube or Ins­tagram on our web­sites. This is vis­ible to you (typ­ic­ally via cor­res­pond­ing sym­bols). We have con­figured these ele­ments so that they are dis­abled by default. If you activ­ate them (by click­ing on them), the oper­at­ors of the respect­ive social net­works can register. You can then use our web­site wherever you are loc­ated. The oper­at­ors of these social net­works can use this inform­a­tion for their pur­poses. The pro­cessing of your per­son­al data is then car­ried out under the respons­ib­il­ity of these oper­at­ors in accord­ance with their pri­vacy policies. We do not receive any inform­a­tion about you from them. 

Data Dis­clos­ure and Data Trans­fer Abroad

In the con­text of our admin­is­trat­ive activ­it­ies and/​or to ful­fill the pro­cessing pur­pose, we also dis­close inform­a­tion to third parties to the extent per­mit­ted and deemed appro­pri­ate. This par­tic­u­larly con­cerns the fol­low­ing entities: 

  • Host­point AG (serv­er loc­a­tion Switzer­land; email host­ing), Neue Jonas­trasse 60, 8640
  • Rheum­a­liga Sch­weiz, Josef­strasse 92, 8050 Zurich, www.rheumaliga-schweiz.ch (admin­is­trat­ive work)
  • Web tools such as Google, etc. (see above under Cook­ies /​ Track­ing)

If a recip­i­ent is loc­ated in a coun­try without adequate leg­al data pro­tec­tion, we con­trac­tu­ally oblige the recip­i­ent to com­ply with applic­able data pro­tec­tion, unless they are already sub­ject to a leg­ally recog­nized frame­work for ensur­ing data pro­tec­tion and we can­not rely on an excep­tion pro­vi­sion. An excep­tion may apply in par­tic­u­lar to leg­al pro­ceed­ings abroad, but also in cases of over­rid­ing pub­lic interests or if con­tract per­form­ance requires such dis­clos­ure, if you have con­sen­ted, or if it con­cerns data you have made pub­licly access­ible and whose pro­cessing you have not objec­ted to. 

Many coun­tries out­side Switzer­land or the EU and EEA cur­rently do not have laws that guar­an­tee an adequate level of data pro­tec­tion from the per­spect­ive of the DSG. The con­trac­tu­al arrange­ments men­tioned can par­tially com­pensate for this weak­er or absent leg­al pro­tec­tion. How­ever, con­trac­tu­al arrange­ments can­not elim­in­ate all risks (par­tic­u­larly from gov­ern­ment access abroad). You should be aware of these resid­ual risks, even if the risk in indi­vidu­al cases may be low. 

Data Secur­ity We take appro­pri­ate tech­nic­al and organ­iz­a­tion­al secur­ity meas­ures to pro­tect your per­son­al data from unau­thor­ized access and mis­use. How­ever, we can only secure areas that we con­trol. We also require our pro­cessors to take appro­pri­ate secur­ity meas­ures. How­ever, secur­ity risks can­not be com­pletely elim­in­ated in gen­er­al; resid­ual risks are unavoidable. 

Pro­fil­ing

We par­tially pro­cess your per­son­al data auto­mat­ic­ally with the aim of eval­u­at­ing cer­tain per­son­al aspects (pro­fil­ing). We use eval­u­ation tools that enable us to com­mu­nic­ate accord­ing to needs. This is done via the third-party pro­vider Google as part of web ana­lys­is, without us being able to see which spe­cif­ic indi­vidu­als are involved (see above Cook­ies /​ Track­ing).

Oth­er­wise, we gen­er­ally do not use fully auto­mated decision-mak­ing. Should we use such pro­ced­ures in indi­vidu­al cases, we will inform you sep­ar­ately about this, provided this is required by law, and inform you about the related rights. 

Rights of the Data Sub­ject You have the right, with­in the frame­work of the data pro­tec­tion law applic­able to you and to the extent provided therein, to access, rec­ti­fic­a­tion, dele­tion, the right to restric­tion of data pro­cessing and oth­er­wise to object to our data pro­cessing, in par­tic­u­lar for fur­ther legit­im­ate interests in pro­cessing, as well as to the release of cer­tain per­son­al data for the pur­pose of trans­fer to anoth­er entity (so-called data port­ab­il­ity). Please note, how­ever, that we reserve the right to assert the leg­ally provided restric­tions on our part, for example if we are obliged to retain or pro­cess cer­tain data, have an over­rid­ing interest in doing so (to the extent we may rely on this), or need it to assert claims. If costs are incurred for you, we will inform you in advance. 

The exer­cise of such rights gen­er­ally requires that you clearly prove your iden­tity (e.g., by means of a copy of an iden­tity doc­u­ment, where your iden­tity is oth­er­wise not clear or can­not be veri­fied). To assert your rights, you can con­tact us at the address giv­en in Sec­tion 1. 

Each data sub­ject also has the right to enforce their claims in court or to file a com­plaint with the com­pet­ent data pro­tec­tion author­ity. The com­pet­ent data pro­tec­tion author­ity in Switzer­land is the Fed­er­al Data Pro­tec­tion and Inform­a­tion Com­mis­sion­er (http://www.edoeb.admin.ch).

Changes We may adjust this pri­vacy policy at any time without pri­or notice. The cur­rent ver­sion pub­lished on our web­site applies. If the pri­vacy policy is part of an agree­ment with you, we will inform you of the change by email or in anoth­er appro­pri­ate man­ner in the event of an update. 

Pri­vacy Policy as of: March 12, 2026