At Winston Graf your trust is important to us
Our website address is: https://winston-graf.ch
Winston Graf AG SWITZERLAND
I. Name and address of the data controller
The controller within the meaning of the EU General Data Protection Regulation (GDPR) and other applicable national data protection laws is:
Winston Graf AG
II. General information on data processing
III. Provision of the website and creation of log files
Description and scope of the data processing
Every time you visit our website, the system of our website hosting provider automatically collects data and information from the computer system you are using. The following data are collected:
a. The IP address of the user
b. The operating system of the user’s computer
c. The type of browser used
d. The date and time of accessThe data are also stored in the log files of our website hosting providers system. These data are not stored together with other personal data of the user.
Purpose of data processing
The temporary storage of the IP address by the system is necessary in order to enable the website to be delivered to the user’s computer. For this reason, the IP address of the user must remain stored for the duration of the session.
The data are stored in log files in order to ensure the functionality of the website. In addition, the data help us to optimize the website and to ensure the security of our information technology systems. Data collected in this way will not be evaluated for marketing purposes.
Duration of storage
The data will be erased as soon as they are no longer required in order to achieve the purpose for which they were collected. Where data are collected for the provision of the website, this occurs when the respective session ends.
If data are stored in log files, this occurs after twenty-four hours at the latest. Continued storage to evaluate visitor statistics is possible. For this purpose, your data will be stored at Hostpoint Ltd. on servers in Switzerland.
Possibility of objection and removal
The collection of data for the provision of the website and the storage of data in log files is absolutely essential for operation of the website. The user consequently has no right to object.
V. Contact forms and email contact
Description and extent of the data processing
Our website may provide for contact forms that can be used to make contact electronically. If a user makes use of this option, the data entered in the input screen will be transmitted to us and stored. These data are:
Name, address, email, telephone number, message content
The following data will also be saved at the time the message is sent:
a. The IP address of the user
b. The date and time of registrationAlternatively, you can make contact using the email addresses provided. In this case the user’s personal data provided with the email will be stored.
Data provided in this context will not be forwarded to third parties but will only be used for the purposes of processing the conversation.
Purpose of the data processing
We process the personal data provided in the input screen solely in order to handle the contact request. In the case of contact by email, this also establishes the necessary legitimate interest for us in processing the data. The other personal data processed during the send process are used to prevent any misuse of the contact form and ensure the security of our information technology systems.
Duration of storage
The data will be erased as soon as they are no longer required in order to achieve the purpose for which they were collected. For the personal data from the input screen of the contact form and the personal data that were sent by email, this is the case when the respective conversation with the user has ended. The conversation has ended if the circumstances suggest that the relevant matters have been finally clarified.
Possibility of objection and removal
The user has the possibility at any time of withdrawing its consent to the processing of its personal data. If the user contacts WGAG by email, he may at any time object to the storage of its personal data. In such a case the conversation cannot be continued.
The notice of objection must be sent to the above contact details by email or in writing. In this case all personal data stored in the course of contacting us will be erased.
VI. Web-tracking services
VIII. Rights of the data subject
If your personal data are processed, you are a data subject within the meaning of the GDPR and you have the following rights granted by the GDPR vis-à-vis the controller:
Right of access
You can demand confirmation from the controller whether we are processing personal data concerning you. If such processing is taking place, you can demand the following information from the controller:
a. the purposes for which the personal data are processed;
b. the categories of personal data being processed;
c. the recipients or categories of recipients to whom the personal data concerning you have been or are still being disclosed;
d. the planned duration of the storage of the personal data concerning you or, if specific information on this is not possible, criteria for determining the storage period;
e. the existence of a right to the rectification or erasure of personal data concerning you, a right to the restriction of processing by the controller or a right to object to such processing;
f. the existence of a right to lodge a complaint with a supervisory authority;
g. any available information on the origin of the data if the personal data are not collected from the data subject;
h. the existence of automated decision-making including profiling in accordance with Art. 22(1) and (4) GDPR and – at least in these cases – meaningful information about the logic involved and as well as the significance and the envisaged consequences of such processing for the data subject.You have the right to demand information as to whether the personal data concerning you is transferred to a third country or to an international organisation. In this context, you may demand to be informed of the appropriate guarantees pursuant to Art. 46 GDPR in connection with the transfer.
Right to rectification
You have the right to obtain rectification and/or completion from the controller without undue delay if your personal data processed are incorrect or incomplete.
Right to restriction of processing
You may request that the processing of personal data concerning you be restricted where one of the following applies:
a. you contest the accuracy of the personal data concerning you for a period enabling the controller to verify the accuracy of the personal data;
b. the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead;
c. the controller no longer needs the personal data for the purposes of processing, but you require them for the establishment, exercise or defence of legal claims, or
d. you have lodged an objection to processing pursuant to Art. 21(1) GDPR and it has not yet been determined whether the legitimate grounds of the controller override your grounds.If the processing of your personal data has been restricted, such data may only be processed – apart from being stored – with your consent or for the purpose of the establishment, exercise or defence of rights or the protection of the rights of another natural or legal person or on grounds of important public interest.
If the processing has been restricted according to the above conditions, you will be informed by the controller before the restriction is lifted.
Right to erasure
a. Duty to erase
You may request the controller to erase your personal data without undue delay. The controller is obliged to erase this data without undue delay if one of the following reasons applies:i. the personal data concerning you are no longer necessary for the purposes for which they were collected or otherwise processed;
ii. you withdraw your consent, on which the processing was based and there is no other legal basis for the processing;
iii. you lodge an objection against the processing and there are no compelling legitimate grounds for the processing;
iv. the personal data concerning you have been processed unlawfully;
v. the deletion of personal data concerning you is necessary in order to fulfil a legal obligation un-der any law to which the controller is subject to; or
vi. the personal data concerning you were collected in relation to information society services offered pursuant to Art. 8(1) GDPR.b. Information to third parties
If the controller has made the personal data concerning you public and is obliged to erase it, the controller, taking account of available technology and reasonable cost of implementation, will take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.c. Exceptions
The right to erasure does not exist insofar as the processing is necessary:
i. for exercising the right of freedom of expression and information;
ii. for compliance with a legal obligation which requires processing by law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
iii. for reasons of public interest in the area of public health in accordance with Art. 9(2)(h) and (i) as well as Art. 9(3) GDPR;
iv. for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Art. 89(1) GDPR in so far as the right referred to in paragraph (a) is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
v. for the establishment, exercise or defence of legal claims.
Right to be informed
If you have exercised your right to have the controller rectify or erase data or restrict its processing, the controller is obliged to inform all recipients to whom your personal data have been disclosed of this rectification or erasure of the data or restriction on processing, unless this proves impossible or involves a disproportionate effort. You have the right to be informed of such recipients.
Right to data portability
You have the right to receive the personal data concerning you, which you have provided to a controller, in a structured, commonly used and machine-readable format. You also have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:a. the processing is based on consent pursuant to Art. 6(1)(a) or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR; and
b. the processing is carried out by automated means.In exercising this right, you also have the right to have the personal data transmitted directly from one controller to another, where technically feasible. This must not adversely affect the rights and freedoms of others.
Right to object
You have the right to object, on grounds relating to your particular situation, at any time to processing of your person-al data which is based on Art. 6(1)(e) or (f) GDPR; this also applies for profiling based on those provisions.
The controller will no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims.
If the personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to processing of your personal data for such marketing; this also applies for profiling to the extent that it is related to such direct marketing.
If you object to processing for direct marketing purposes, the personal data will no longer be processed for such purposes.
In the context of the use of information society services, you may exercise your right to object by automated means using technical specifications.
Right to withdraw consent on data processing
You have the right to withdraw your consent on data processing at any time. The withdrawal of consent will not affect the lawfulness of the processing carried out on the basis of the consent until withdrawal.
Automated individual decision-making, including profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects on you or which affects you in a similarly significant way. This does not apply if the decision:
a. is necessary for entering into, or performance of, a contract between you and a data controller;
b. is authorised by law to which the controller is subject and which also lays down suitable measures to safe-guard your rights and freedoms and legitimate interests; or
c. is based on your explicit consent.However, these decisions must not be based on special sensitive categories of personal data unless legal exceptions apply and suitable measures to safeguard your rights and freedoms and legitimate interests are in place.
In the cases referred to in (1) and (3), the data controller will implement suitable measures to safeguard your rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.
IX. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the EU-Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR. In such a case, the supervisory authority with which the complaint has been lodged will inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Art. 78 GDPR.
Choose a language English Deutsch Español Русский