Privacy policy

This privacy policy explains how karlmeparte collects, uses, and protects personal data in accordance with the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR) where applicable, and relevant cantonal provisions.

Data controller and contact details

The data controller responsible for processing personal data is karlmeparte, located at 15 Avenue de la Gare, 1003 Lausanne, Switzerland. For any questions regarding this policy or to exercise your data protection rights, contact us at [email protected] or +41 21 648 3920.

We have not appointed a dedicated Data Protection Officer, as our processing activities do not meet the thresholds requiring one under applicable law. Privacy enquiries are handled directly by our management team.

Categories of personal data we collect

We collect contact information including name, email address, telephone number, and company name when you enquire about our services or enter into a contract with us. Project-related data may include job title, department, and workplace requirements shared during planning engagements.

When you visit our website, we automatically collect technical data such as IP address, browser type, device information, and pages visited. Cookie preferences are stored locally under the key klmp_workspace_prefs as described in our Cookie Policy.

Legal bases and purposes of processing

We process personal data to respond to enquiries, prepare proposals, deliver contracted services, and manage client relationships. The legal bases include contract performance, legitimate interests in operating our business, and consent where required for marketing communications or non-essential cookies.

Website analytics help us understand how visitors use our site and improve its content. We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.

Data sharing and international transfers

Personal data is shared with service providers who assist with hosting, email delivery, and project management tools, solely to the extent necessary for their functions. All processors are bound by data processing agreements requiring appropriate security measures.

Where data is transferred outside Switzerland or the EEA, we ensure adequate protection through Standard Contractual Clauses, adequacy decisions, or other mechanisms recognised under FADP and GDPR.

Retention periods and data security

Enquiry records are retained for three years unless a business relationship is established, in which case data is kept for the duration of the contract plus ten years for legal and accounting purposes. Website logs are retained for twelve months before anonymisation or deletion.

We implement technical and organisational measures including encrypted connections, access controls, and regular security reviews to protect personal data against unauthorised access, loss, or alteration.

Your rights under GDPR and FADP

You have the right to access, rectify, erase, restrict, and port your personal data, as well as the right to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if applicable, your local EU supervisory authority.