Privacy Policy

This privacy policy explains how we process personal data when you visit our website, contact us, subscribe to our newsletter or do business with us. Personal data means any information relating to an identified or identifiable natural person.

 

1. Controller and contact

Antrimon Group AG
Gotthardstrasse 3, 5630 Muri AG, Switzerland
UID: CHE-110.095.988
Email for data protection matters: datenschutz@antrimon.com

Representative in the EU (Art. 27 GDPR)
ANTRIMON (Deutschland) GmbH
Heerstrasse 26, 78554 Aldingen, Germany
Email: datenschutz@antrimon.com

 

2. Scope and applicable law

This privacy policy is based on the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies in individual cases, we also comply with its requirements and state the relevant legal bases in addition.

Applications are governed by our separate privacy policy for applicants, available on our career portal at https://antrimon-group-ag.jobs.personio.de.

If you provide us with personal data of other persons (e.g. colleagues), please ensure that these persons are aware of this privacy policy and that the data is accurate.

 

3. Data we process

Depending on your contact with us, we process in particular the following categories of personal data:

  • Usage data: IP address, date and time of access, pages visited, browser, operating system, device type and referring website.
  • Contact data and enquiries: name, company, position, email address, telephone number and content of your message.
  • Business relationship data: details of contact persons at customers, suppliers and partners, correspondence, quotations, contracts, orders and invoicing data.
  • Marketing data: newsletter subscription, interests and information on the use of our newsletters.
  • Security vulnerability reports: contact details of the reporting person and content of the report.

We receive this data primarily from you directly. In some cases it comes from your employer or from publicly available sources such as the commercial register, company websites or professional networks.

 

4. Purposes of processing

We process personal data in particular for the following purposes:

  • Provision, security and further development of our website
  • Responding to enquiries and communicating with you
  • Initiating, concluding and performing contracts with customers, suppliers and partners
  • Maintaining business relationships and marketing, including newsletters and events
  • Measuring reach and evaluating our advertising, where you have consented
  • Complying with legal obligations, e.g. retention obligations and obligations under the Cyber Resilience Act (CRA)
  • Enforcing and defending legal claims

Where the GDPR applies, we rely on your consent (Art. 6(1)(a) GDPR), the performance of a contract or pre-contractual measures (lit. b), legal obligations (lit. c) or our legitimate interest in efficient business operations, the security of our systems and the maintenance of our customer relationships (lit. f).

We do not make automated individual decisions and do not carry out high-risk profiling.

 

5. Contacting us

If you contact us via the contact form, by email or by telephone, we process your details in order to respond to your enquiry. We retain the data for as long as necessary to handle the enquiry and any resulting business relationship and delete it thereafter, subject to statutory retention obligations.

 

6. Newsletter and CRM

We use the SuperOffice software of SuperOffice AS, Oslo (Norway), to manage our customer relationships and send our newsletter.

Newsletter subscription uses a double opt-in procedure: after subscribing, you receive an email in which you confirm your subscription. We analyse whether and when a newsletter is opened and which links are clicked in order to improve our content. You can unsubscribe at any time via the unsubscribe link in the newsletter or by email to newsletter@antrimon.com. Your data will then be removed from the mailing list.

 

7. Reporting security vulnerabilities (CRA)

End users, customers and security researchers can report vulnerabilities in our products by email to info@antrimon.com with the subject line "CRA-[product name]". We process the data provided in order to record, assess and remedy the reported vulnerability and to comply with our obligations under the Cyber Resilience Act. Data is only disclosed where necessary to remedy the vulnerability or where statutory reporting obligations to authorities apply.

 

8. Cookies and consent management

Our website uses cookies and similar technologies. We use technically necessary cookies without consent, as the website would not function otherwise. We only use cookies for statistics and marketing if you have consented via our cookie banner.

We use CookieHub of CookieHub ehf., Iceland, to manage your consent. You can change or withdraw your selection at any time via the cookie settings on our website.

 

9. Web analytics and advertising

We use the following services only with your consent via the cookie banner:

  • Google Tag Manager (Google Ireland Limited, Dublin, Ireland): tool for managing the integration of other services on our website. The Tag Manager itself does not analyse usage data.
  • Google Analytics (Google Ireland Limited, Dublin, Ireland): analysis of the use of our website. IP addresses are truncated. Information: https://policies.google.com/privacy
  • Microsoft Clarity (Microsoft Ireland Operations Limited, Dublin, Ireland): analysis of the use of our website by means of heatmaps and anonymised session recordings. Entries in form fields are not recorded. Information: https://privacy.microsoft.com
  • LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company, Dublin, Ireland): evaluation of the effectiveness of our advertising on LinkedIn and creation of anonymous statistics on website visitors. Information: https://www.linkedin.com/legal/privacy-policy
  • Google Ads conversion tracking (Google Ireland Limited, Dublin, Ireland): measuring the effectiveness of our ads.

These providers may also transfer data to the USA (see section 12).

 

10. Embedded content and links to social networks

On some pages we embed YouTube videos (Google Ireland Limited, Dublin, Ireland) in privacy-enhanced mode. A connection to YouTube is only established when you play the video. If you are logged in to your Google account at the time, YouTube may associate the visit with your account.

On the "Jobs & Career" page, we load current job openings directly from our applicant management system Personio (Personio SE & Co. KG, Munich, Germany). For technical reasons, Personio receives your IP address in the process. Applications are submitted via the Personio career portal, for which our privacy policy for applicants applies.

We link to our profiles on LinkedIn, Facebook, X and Xing using simple links. No data is transmitted to these networks when you visit our website. Only when you click a link are you taken to the respective provider's page, which is subject to its own privacy policy.

 

11. Recipients of personal data

We only disclose personal data where necessary for the purposes stated, in particular to:

  • IT service providers, e.g. for hosting our website (creanet, Switzerland), email and office applications (Microsoft 365) and ERP (SAP Business One)
  • Providers of the services mentioned in sections 6, 8, 9 and 10, including Personio
  • Companies of our group, in particular ANTRIMON (Deutschland) GmbH and companies of the SwissFactory Group, where necessary for cooperation
  • Banks, insurers, auditors, fiduciaries and advisers
  • Authorities and courts, where we are legally obliged to do so or where necessary to protect our rights
  • Buyers or prospective buyers in the event of a transfer of parts of the business

We contractually oblige service providers who process data on our behalf to comply with data protection requirements.

 

12. Disclosure abroad

Personal data may be disclosed to the following countries: Switzerland, member states of the EU and the EEA (in particular Germany, Ireland, Norway and Iceland) and the USA.

According to the Swiss Federal Council, the EU and EEA member states provide an adequate level of data protection. For recipients in the USA, we rely on the Swiss-U.S. Data Privacy Framework where the recipient is certified, or on the European Commission's standard contractual clauses with the adaptations required for Switzerland. You can request a copy of these safeguards at datenschutz@antrimon.com.

 

13. Retention period

We retain personal data for as long as required for the respective purpose, as long as statutory retention obligations apply or as long as we have a legitimate interest, e.g. to preserve evidence during limitation periods. We generally retain business records for 10 years (Art. 958f of the Swiss Code of Obligations). We generally delete server log data after 12 months at the latest. The data is then deleted or anonymised.

 

14. Data security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss and misuse. These include in particular encrypted transmission on our website (TLS), role-based access rights and training of our employees.

 

15. Your rights

Within the scope of applicable law, you have in particular the right to:

  • Access your personal data processed by us
  • Rectification of inaccurate data
  • Erasure or restriction of processing
  • Receive or transfer your data in a common electronic format
  • Object to processing, in particular for marketing purposes
  • Withdraw consent given, with effect for the future

Please send your request to datenschutz@antrimon.com. We may request proof of identity if your identity cannot otherwise be established. Statutory restrictions remain reserved, e.g. where we are obliged to retain data.

You may also contact the Federal Data Protection and Information Commissioner (FDPIC) (www.edoeb.admin.ch). Where the GDPR applies, you may lodge a complaint with a data protection supervisory authority in the EU, in particular in your country of residence.

 

16. Changes

We may amend this privacy policy at any time. The version published on our website applies.

Muri, September 2026