Privacy Policy
- Data Controller
| Company | immopac ag |
| Address | Birmensdorferstrasse 125, 8003 Zurich |
| Contact | [email protected] |
- Scope and Applicable Law
This Privacy Policy applies to the processing of personal data in connection with visits to our website immopac.ch and the use of our contact and marketing channels.
Immopac ag is based in Switzerland. The processing of personal data is primarily governed by the Federal Act on Data Protection (FADP) and the associated Data Protection Ordinance (DPO).
Where we process personal data of individuals in the EU/EEA or where our website is specifically targeted at the EU, the General Data Protection Regulation (GDPR) also applies.
- What personal data we process
3.1 Automatically collected access data (server logs)
Each time our website is accessed, the following data is collected for technical reasons and stored in server logs:
- IP address (anonymised after 7 days)
- Date and time of access and the visitor’s local time zone
- Visitor’s geolocation (country, region, city)
- Title of the page displayed
- URL of the page displayed
- Page generation time (the time taken for web pages to be generated by the web server and subsequently downloaded by the user)
- URL accessed, HTTP status code
- Files clicked on and downloads made
- Links clicked to third-party websites
- Browser type, language and version, operating system and screen resolution
- Referrer URL
Legal basis: Article 31(1) FADP (legitimate interest in operation and security) / Article 6(1)(f) GDPR. Retention period: A maximum of 12 months, followed by automatic deletion.
Apart from the above data, which is collected for technical reasons and stored in server logs, no other data of any kind is collected, stored or processed when you visit our website. In particular, no cookies of any kind are used on our site that result in, or could result in, the collection, storage, processing or deletion of data.
3.2 Getting in touch
If you contact us via our contact form or by email, we will process the following: your name, email address, telephone number and the content of your enquiry.
Legal basis: Article 31(1) of the Federal Data Protection Act (FADP) (pre-contractual measures / legitimate interest) / Article 6(1)(b) and (f) of the General Data Protection Regulation (GDPR). Retention period: Up to 2 years after the enquiry has been finalised, depending on the nature of the enquiry and provided that no contractual relationship arises and no statutory requirements stipulate a longer retention period.
- Recipients and data processors
We only disclose personal data where this is necessary for the performance of our services, permitted by law or carried out with your consent. A full list of our sub-processors (sub-processor list) is available separately and will be provided on request.
Categories of recipients:
- Public authorities, where required by law
- Group companies in the context of centralised services or to respond specifically to your enquiry
- Retention period
We only retain personal data for as long as is necessary for the relevant purpose or as required by statutory retention obligations (e.g. 10 years for business records under the Swiss Code of Obligations). Once the purpose no longer applies and there is no retention obligation, the data is deleted or irreversibly anonymised.
- Your rights as a data subject
You have the following rights under the provisions of the FADP and – where applicable – the GDPR:
| Individual Rights | Description |
| Right of access (Art. 25 FADP / Art. 15 GDPR) | You may request information about the personal data held about you. |
| Right to rectification (Art. 32 FADP / Art. 16 GDPR) | You can have any incorrect data corrected. |
| Right to erasure (Art. 32 FADP / Art. 17 GDPR) | You may request that your data be deleted, provided there are no retention obligations that prevent this. |
| Right to restriction of processing (Art. 32 FADP / Art. 18 GDPR) | Under certain circumstances, you may request that the processing of your data be restricted. |
| Data portability (Art. 20 GDPR) | You may receive your data in a commonly used, machine-readable format. |
| Objection (Art. 21 GDPR) | You may object to processing based on legitimate interests. |
| Withdrawal of consent | You may withdraw any consent you have given at any time with effect for the future. |
| Right to lodge a complaint | You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) or a competent EU supervisory authority. |
To exercise your rights, please contact: [email protected]
- Cookies and consent management
Our website does not use or employ cookies of any kind that result in, or could result in, the collection, storage, processing or deletion of data. Consequently, there is no need to give or withhold consent of any kind.
- Data security
The hosting partner and immopac ag employ technical and organisational security measures in accordance with recognised industry standards to protect stored personal data against accidental, unlawful or unauthorised manipulation, deletion, alteration, access, disclosure or use, and against partial or complete loss. The servers of the hosting provider and immopac ag are located in Switzerland. The connection to the servers is established using SSL encryption. The hosting provider and immopac ag carry out regular backups of customer data. To prevent data loss even in extreme circumstances (e.g. destruction of a data centre by an earthquake), the encrypted backups are stored in parallel across several data centres in Switzerland. Security measures are continuously adapted and improved in line with technological developments. Furthermore, the hosting provider and immopac ag cannot guarantee the security of data transmission over the internet; in particular, there is a risk of third-party access when data is transmitted via email. However, access to the website and transmission via the contact form are protected by HTTPS.
- Duration of storage
We process and store your personal data for as long as is necessary to fulfil our contractual and legal obligations or for the purposes otherwise pursued by the processing; this includes, for example, the duration of the entire business relationship (from the initiation and execution of a contract through to its termination) and beyond, in accordance with statutory retention and documentation requirements. It is possible that personal data may be retained for the period during which claims may be brought against our company and to the extent that we are otherwise legally obliged to do so or where legitimate business interests so require (e.g. for evidential and documentation purposes). As soon as your personal data is no longer required for the purposes mentioned above, it will, as a general rule and where possible, be deleted or irrevocably anonymised. For operational data (e.g. system logs), shorter retention periods of twelve months or less generally apply.
- Reporting data breaches
In the event of a data breach that is likely to result in a high risk to data subjects, we will inform them without delay in accordance with Article 24 of the FADP and – where the GDPR applies – we will report the breach to the relevant supervisory authority within 72 hours (Section 33 of the GDPR).
- Changes to this Privacy Policy
This Privacy Policy may be amended at any time. The version currently published on our website shall apply. In the event of significant changes, we will inform you by email, provided we have your email address.

