1. Principles of data processing

In this data protection declaration, we, vogt ag steuerberatung, describe how we collect and process personal data. It also regulates the transfer of data, the retention period and your rights. This data protection declaration is not an exhaustive description; if necessary, other declarations relating to data protection regulate specific issues. For this privacy policy, personal data means any information relating to an identified or identifiable person. Personal data (hereinafter also referred to as data) means any information relating to an identified or identifiable natural person. The term "data processing" is to be understood situationally and includes any handling of personal data, regardless of the means and procedures used, particularly the collection, storage, use, modification, disclosure, archiving or destruction of data.

We collect and process personal data for the fulfilment of our business tasks within the legally and contractually regulated framework. The collection, processing and use of personal data are subject to the applicable Swiss [1] and, where applicable, European legal provisions [2].

We transparently collect personal data and comply with the principles of proportionality and purpose limitation. The data is only processed to the extent and for as long as is necessary for our tasks and obligations.

We may have personal data processed by third parties. We may process personal data jointly with third parties or transfer it to third parties. Such third parties are, in particular, specialised providers whose services we use. We also ensure data protection for such third parties.

2. Responsible body and contact

The controller responsible for the data processing described here is vogt ag steuerberatung, unless otherwise stated in individual cases. Enquiries about data protection can be sent to us by letter or email, enclosing a copy of the ID or passport identifying the user:

vogt ag steuerberatung
Armin Vogt
Bleicherweg 45
CH-8002 Zuerich
info@avogt.ch

3. collection and processing of personal data

We process personal data in the following categories of processing in particular

  • Customer data of customers for whom we provide or have provided services.
  • Personal data that we have received indirectly from our customers during the provision of services
  • When you visit our website
  • When we communicate or a visit takes place.
  • In other contractual relationships, e.g. as a supplier, service provider or consultant.
  • For applications
  • If we are obliged to do so for legal or regulatory reasons
  • When we exercise our due diligence or other legitimate interests, e.g. to avoid conflicts of interest, to avoid money laundering or other risks, to ensure data accuracy, to check creditworthiness, to ensure security or to enforce our rights.

For more detailed information, please refer to the description of the respective categories of processing in section 4.

 4. Categories of personal data

The personal data we process depends on your relationship with us and the purpose for which we process it. In addition to your contact details, we also process other information about you or about people who have a relationship with you. Under certain circumstances, this information may also include particularly sensitive personal data. We collect the following categories of personal data, depending on the purpose for which we process it:

a) Contact information (e.g. surname, first name, address, telephone number, email, other contact information, marketing data)

b) Customer information and personal details (e.g. date of birth, nationality, marital status, profession, title, job title, passport / ID number, AHV number, family circumstances, information about children, etc.)

c) Risk assessment data (e.g. creditworthiness information, commercial register data, sanctions lists, specialised databases, data from the Internet)

d) Financial information (e.g. data on bank details, investments or shareholdings)

e) Mandate data, depending on the mandate (e.g. tax information, articles of association, minutes, projects, contracts, Employee data (e.g. headcount, specialist areas, number of employees or managers, job percentages, salary, social insurance), accounting data, beneficial owners, ownership structure, details of branches and group companies, etc.)

f) Particularly sensitive personal data: This personal data may also include particularly sensitive personal data, such as data relating to health, religious beliefs or social assistance measures, particularly if we provide payroll processing or accounting services.

g) Website data (e.g. IP address, device information (UDI), browser information, website usage (analysis and use of plugins, etc.)

h) Application data (e.g. CV, job references)

i) Marketing information 

j) Security and network data (e.g. visitor lists, access controls, network and mail scanners, telephone call lists)

If permitted, we also extract certain data from publicly accessible sources (e.g. debt collection registers, land registers, commercial registers, press, internet) or receive such data from our clients and their employees, from authorities, (arbitration) courts and other third parties. In addition to the data that you provide to us directly, the categories of personal data that we receive from third parties about you include, in particular, information from public registers, information that we learn in connection with administrative and judicial proceedings, information in connection with your professional functions and activities (so that we can, for example to conclude and process transactions with your employer with your help), information about you in correspondence and meetings with third parties, creditworthiness information, information about you provided to us by persons close to you (family, advisors, legal representatives, etc.) so that we can conclude or process contracts with you or with your involvement (e.g. references, your address for business transactions, etc.). References, your address for deliveries, powers of attorney) Information on compliance with legal requirements such as anti-money laundering and export restrictions, information from banks, insurance companies, sales and other contractual partners of ours on the utilisation or provision of services by you (e.g. payments made, purchases made), information from the media and the Internet about your person (insofar as this is appropriate in the specific case, e.g. in the context of an application, etc.). e.g. in the context of a job application etc.), your addresses and, if applicable, interests and other socio-demographic data (for marketing purposes), data in connection with the use of the website (e.g. IP address, MAC address of the smartphone or computer, information about your device and settings, cookies, date and time of the visit, pages and content accessed, functions used, referring website, location data).

5. Purposes of data processing and legal basis

5.1. Provision of services

We primarily process the personal data that we receive from our clients and other persons involved in the context of our client relationships with our clients and other contractual relationships with business partners.

The personal data of our clients is, in particular, information that we disclose under section 4 letters a to f.

We process this personal data for the purposes described based on the following legal bases:

  • Conclusion or performance of a contract with the data subject or in favour of the data subject, including contract initiation and any enforcement (e.g. consulting, fiduciary services)
  • Fulfilment of a legal obligation (e.g. if we are obliged to disclose information)
  • Protecting legitimate interests (e.g. for administrative purposes, to improve our quality, to ensure security, to manage risk, to enforce our rights, to defend ourselves against claims or to check for potential conflicts of interest)
  • Consent (e.g. to send you marketing information).

5.2. Indirect data processing from the provision of services

When we provide services to our customers, we may also process personal data that we have not collected directly from the data subjects or personal data from third parties. These third parties are usually employees, contact persons, family members or persons who have a relationship with the customers or data subjects for other reasons. We require this personal data to fulfil contracts with our customers. We receive this personal data from our customers or third parties commissioned by our customers. Third parties whose information we process for this purpose are informed by our customers that we are processing their data. Our customers can refer to this privacy policy for this purpose.

The personal data of persons who have a relationship with our customers is, in particular, the information that we provide under section 4 letters a to f.

We process this personal data for the purposes described based on the following legal bases:

  • Conclusion or performance of a contract with the data subject or in favour of the data subject (e.g. when we fulfil our contractual obligations)Fulfilment of a legal obligation (e.g. if we are obliged to disclose information)
  • Protecting legitimate interests, in particular, our interest in providing an optimal service to our customers

5.3.  Use of our website

The personal data we collect includes your IP address and other information that you freely provide to us, e.g. by e-mail link.

Server log files

Our server automatically stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request
  • IP address

This data is not merged with other data sources.

Cookies

Internet pages often use so-called cookies. Cookies are small text files that are stored on your computer and saved by your browser; they do not cause any damage to your computer and do not contain viruses, but serve to make our website more user-friendly, effective and secure.

Most of the cookies we use are so-called «session cookies» or «functional cookies», «session cookies» are automatically deleted at the end of your visit. 

«Functional cookies» are necessary for basic functions and are therefore stored automatically when you visit our websites. These cookies save your preferences when you use our websites. They are also used to distribute the utilisation of our servers to keep our website available, as well as for security purposes. No consent is required for the use of functional cookies, which enable the basic functions of the website.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted. 

Correspondence data

This concerns the following information in particular: 

  • Contact information (e.g. surname, first name, address, telephone number, email address)
  • Other information that you provide to us via the website
  • Automatically transmitted technical information to us or our service providers 
We process this personal data for the purposes described based on the following legal bases:

  • Protection of legitimate interests (e.g. for administrative purposes, to improve our quality, to analyse data or to publicise our services)

5.4. Direct communication and visits

When you contact us (e.g. by telephone, email or chat) or we contact you, we process the personal data required for this. We also process this personal data when you visit us. In this case, you may have to leave your contact details before your visit or at reception. We store this data for a certain period to protect our infrastructure and our information.

For the realisation of telephone conferences, online meetings, video conferences and/or webinars («online meetings») we mainly use the service

  • Microsoft Teams: a platform for audio and video conferencing, among other things, Zoom: video conferencing or
  • the video conferencing service provider you use

Specific data protection provisions are specified by the providers

We process the following information in particular:

  • Contact information (e.g. surname, first name, address, telephone number, email address)
  • Communication data (e.g. IP address, duration of communication, communication channel)
  • Recordings of conversations, e.g. during video conferences
  • Other information that the user uploads, provides or creates during the use of the video conferencing service as well as metadata used for the maintenance of the service provided Additional information about the processing of personal data by Zoom or Microsoft Teams can be found in their privacy policies.
  • Personal information (e.g. profession, function, title, employer company)
  • Time and reason for the visit

We process this personal data for the purposes described based on the following legal bases:

  • Fulfilment of a contractual obligation with the data subject or in favour of the data subject, including contract initiation and possible enforcement (provision of a service)
  • Protection of legitimate interests (e.g. security, traceability, processing and administration of customer relationships)

5.5. Applications

You can submit your application for a position with us by post or via the e-mail address provided on our website. The application documents and all personal data disclosed to us will be treated in strict confidence, will not be disclosed to third parties and will only be processed to process your application for employment with us. Without your consent to the contrary, your application dossier will either be returned to you or deleted/destroyed after the application process has been completed, unless it is subject to a statutory retention obligation. The legal basis for the processing of your data is your consent, the fulfilment of the contract with you and our legitimate interests.

We process the following information in particular:

  • Contact information (e.g. surname, first name, address, telephone number, email address)
  • Personal information (e.g. profession, function, title, employer company)
  • Application documents (e.g. letter of motivation, certificates, diplomas, CV)
  • Assessment information (e.g. assessment by personnel consultant, reference information, assessments)

We process this personal data for the purposes described based on the following legal bases:

  • Protection of legitimate interests (e.g. recruitment of new employees)
  • Consent  

5.6. Suppliers, service providers, and other contractual partners

When we enter into a contract with you to provide a service to us, we process personal data about you or your employees. We need this data to communicate with you and utilise your services. We may also process this personal data to check whether there may be a conflict of interest and to ensure that we do not take any unwanted risks, e.g. concerning money laundering or sanctions, by working with you.

We process the following information in particular:

  • Contact information (e.g. surname, first name, address, telephone number, email).Personal information (e.g. profession, function, title, employer company).
  • Financial information (e.g. data on bank details).

We process this personal data for the purposes described based on the following legal bases:

  • Conclusion or performance of a contract with the data subject or in favour of the data subject, including contract initiation and any enforcement
  • Protecting legitimate interests (e.g. avoiding conflicts of interest, protecting the company, enforcing legal claims).

6. Data disclosure and data transfer

We only pass on your data to third parties if this is necessary for the provision of our services, if these third parties provide a service for us, if we are legally or officially obliged to do so or if we have an overriding interest in passing on the personal data. We will also disclose personal data to third parties if you have given your consent or requested us to do so. Not all personal data is transmitted in encrypted form by default. Unless explicitly agreed otherwise with the customer, accounting data, payroll administration data, pay slips and statements and tax declarations can be transmitted unencrypted.

The following categories of recipients may receive personal data from us:

  • Branch offices, subsidiaries or sister companies.
  • Service providers (e.g. IT service providers, hosting providers, suppliers, consultants, lawyers, insurance companies).
  • Third parties within the scope of our legal or contractual obligations, authorities (e.g. audit supervisory authority, tax authorities, etc.), state institutions, and courts.

We conclude contracts with service providers who process personal data on our behalf, which obliges them to guarantee data protection. The majority of our service providers are located in Switzerland or the EU/EEA. Certain personal data may also be transferred to the USA (e.g. US tax authorities) or, in exceptional cases, to other countries worldwide. If it is necessary to transfer data to other countries that do not have an adequate level of data protection, this will be done based on the EU standard contractual clauses or other suitable instruments).

7. duration of storage of personal data

We process and store your personal data for as long as is necessary for the fulfilment of our contractual and legal obligations or otherwise for the purposes pursued with the processing, i.e. for example for the duration of the entire business relationship (from the initiation, processing to the termination of a contract) as well as beyond that following the statutory retention and documentation obligations. It is possible that personal data may be stored for the period in which claims can be asserted against our company (i.e. in particular during the statutory limitation period) and insofar as we are otherwise legally obliged to do so or legitimate business interests require this (e.g. for evidence and documentation purposes). As soon as your personal data is no longer required for the above-mentioned purposes, it will be deleted or anonymised as a matter of principle and as far as possible. Shorter retention periods of twelve months or less apply to operational data (e.g. system logs, logs).

8. Data security

We take appropriate technical and organisational security precautions to protect your personal data from unauthorised access and misuse, such as issuing instructions, training, IT and network security solutions, access controls and restrictions, encryption of data carriers and transmissions, pseudonymisation and controls.

9. Obligation to provide personal data

In the context of our business relationship, you must provide the personal data that is necessary for the establishment and performance of a business relationship and the fulfilment of the associated contractual obligations (as a rule, you do not have a legal obligation to provide us with data). Without this data, we cannot enter into or fulfil a contract with you (or the entity or person you represent). The website can also not be used if certain information to secure data traffic (such as IP address) is not disclosed.

10. Your rights

You have the following rights in connection with our processing of personal data:

  • Right to information about your data stored by us, the purpose of processing, the origin and recipients or categories of recipients to whom personal data is disclosed.
  • Right to rectification if your data is incorrect or incomplete.
  • Right to restrict the processing of your personal data
  • Right to request the deletion of the processed personal data
  • Right to data portability
  • Right to object to data processing or to withdraw consent to the processing of personal data at any time without giving reasons.
  • Right to complain with a competent supervisory authority, if provided for by law.

To assert these rights, please contact the address given in section 2.

Please note, however, that we reserve the right to assert the restrictions provided for by law, for example, if we are obliged to store or process certain data, have an overriding interest in doing so (insofar as we are entitled to invoke this) or need it for the assertion of claims. If you incur costs, we will inform you in advance.

11. Amendment to the data protection declaration

We expressly reserve the right to amend this privacy policy at any time.

Last updated: December 2023