Skip to content

Data protection declaration

Last updated: 30 September 2026

This declaration describes how BS & Partners processes the personal data collected through the bs-partners.ch website and through the contact forms linked to Google Ads campaigns.

Processing is governed by the Federal Act on Data Protection of 25 September 2020 (FADP, SR 235.1) and by the related Data Protection Ordinance (SR 235.11). For people located in the European Union, Regulation (EU) 2016/679 (GDPR) also applies.

1. Controller (art. 19 para. 2 let. a FADP)

BS & Partners – Stefano Benigni
Morbio Inferiore, Switzerland
Email: direzione@bs-partners.ch

2. Data processed

  • Contact details provided through the website form or the Google Ads contact form: name, email, telephone number, company name and the content of the enquiry.
  • Data exchanged by email or telephone in the course of the contact.
  • Technical browsing data (IP address, browser type, pages visited, date and time of access), recorded by the server for security and operational reasons.
  • Aggregated visit statistics, collected with Umami, a tool that does not use cookies and does not build user profiles.

3. Purpose of processing (art. 19 para. 2 let. b FADP)

  • Responding to enquiries and requests for quotations.
  • Managing the client relationship, including accounting and tax obligations.
  • Ensuring the security and operation of the website.

The data is not used for automated individual decision-making, nor sold to third parties.

For people in the European Union the legal bases are: pre-contractual measures and performance of the contract (art. 6 para. 1 let. b GDPR), legal obligations (art. 6 para. 1 let. c GDPR), legitimate interest in the security of the website (art. 6 para. 1 let. f GDPR).

4. Recipients (art. 19 para. 2 let. c FADP)

The data may be processed, on behalf of BS & Partners, by the following providers:

  • Infomaniak Network SA (Switzerland), for hosting the website and the email service;
  • Umami Software, Inc. (United States), for anonymous visit statistics; the servers may be located in the European Union or in the United States.
  • Google Ireland Limited (Ireland) and Google LLC (United States), for the contact forms linked to Google Ads campaigns.

The data is not disclosed to any other party, save for legal obligations.

5. Disclosure abroad (art. 19 para. 4 and art. 16 FADP)

  • Ireland (European Union): a State with an adequate level of protection under Annex 1 to the Data Protection Ordinance.
  • United States: Google LLC is certified under the Swiss-U.S. Data Privacy Framework; since 15 September 2024 certified companies have been recognised by the Federal Council as providing adequate protection (Annex 1 to the Data Protection Ordinance). For people in the European Union the transfer is based on the EU-U.S. Data Privacy Framework.
  • Umami Software, Inc.: visit data, processed anonymously, may be stored in the European Union, a State with an adequate level of protection under Annex 1 to the Data Protection Ordinance, or in the United States.

6. Retention period

  • Contact enquiries not followed by an engagement: 12 months from receipt.
  • Client data: for the duration of the relationship and thereafter for 10 years, as required for accounting records (art. 958f of the Swiss Code of Obligations).
  • Technical server data: for the limited period set by the hosting provider's configuration.

7. Rights of the data subject

You may exercise at any time, by writing to direzione@bs-partners.ch:

  • the right of access to your data (art. 25 FADP), with a reply that is as a rule free of charge within 30 days;
  • the right to the handover or transfer of your data (art. 28 FADP);
  • the right to request the correction or deletion of your data and to object to the processing (art. 32 FADP).

You may also contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch.

If you are in the European Union you also have the rights set out in art. 15–21 GDPR and may lodge a complaint with the supervisory authority of your country (in Italy: Garante per la protezione dei dati personali, www.garanteprivacy.it).

8. Cookies and similar technologies (art. 45c TCA)

The website does not use profiling or marketing cookies. Visit statistics are collected with Umami, which does not use cookies. You can still block or delete cookies from your browser settings.

9. Security

We take technical and organisational measures appropriate to the risk to protect data against unauthorised access, loss or alteration (art. 8 FADP).

10. Changes

This declaration may be updated. The version in force is the one published on this page.