Privacy Policy

AYOS Coffee GmbH (Neuhofstrasse 5A, 6340 Baar, Switzerland, registered in the commercial register of the Canton of Zug under number CHE, also known under the business name "i-commerce") operates the website revitalice.ch. We are responsible for the collection, processing, and use of your personal data and for ensuring that data processing complies with applicable data protection law.
Your trust is important to us, which is why we take data protection seriously and ensure appropriate security. Naturally, we comply with the legal provisions of the Federal Act on Data Protection (FADP), the Ordinance to the Federal Act on Data Protection (OFADP), the Telecommunications Act (TCA), and other applicable data protection regulations under Swiss or EU law, in particular the General Data Protection Regulation (GDPR).
To ensure you are aware of what personal data we collect from you and for what purposes we use it, please take note of the information below.


A. Data processing


1. When you visit our website
When you visit our website, our servers temporarily store each access in a log file. The following technical data is collected automatically, as is standard practice with any connection to a web server, and stored by us until its automatic deletion after a maximum of 6 months:

• the IP address of the requesting computer,
• the name of the owner of the IP address range (usually your Internet access provider),
• the date and time of access,
• the website from which the access was made (referrer URL), possibly including the search term used,
• the name and URL of the retrieved file,
• the status code (e.g. error message),
• your computer's operating system,
• the browser you are using (type, version and language),
• the transmission protocol used (e.g. HTTP/1.1) and
• Possibly your username from a registration/authentication.

The collection and processing of this data is carried out for the purpose of enabling the use of our website (establishing a connection), ensuring the ongoing security and stability of our systems, optimizing our online services, and for internal statistical purposes. This constitutes our legitimate interest in data processing within the meaning of Article 6(1)(f) GDPR.

Furthermore, the IP address, along with other data, is analyzed for the purpose of investigating and defending against attacks on the network infrastructure or other unauthorized or abusive use of the website, and may be used, if necessary, in criminal proceedings to identify and pursue civil and criminal action against the users in question. This constitutes our legitimate interest in data processing within the meaning of Article 6(1)(f) GDPR.

2. When using our contact form
You have the option of using a contact form to get in touch with us. For this, you must provide the following information:
• E-mail address
• Notice

We use this and other data you voluntarily provide only to answer your contact request in the best possible and most personalized way. The processing of this data is therefore necessary for the performance of pre-contractual measures within the meaning of Article 6(1)(b) GDPR, or is in our legitimate interest pursuant to Article 6(1)(f) GDPR.

3. When you subscribe to our newsletter
You have the option to subscribe to our newsletter on our website. Registration via email address is required for this. Registration uses a double opt-in process, meaning that after registering, you will receive an email asking you to confirm your subscription. We process your email address solely to personalize the information and offers we send you and to better tailor them to your interests.

By registering, you give us your consent to process the data you provide for the regular delivery of the newsletter to the address you specify, as well as for the statistical analysis of user behavior and the optimization of the newsletter. This consent constitutes our legal basis for processing your email address in accordance with Article 6(1)(a) of the GDPR.

The newsletters are sent via »Klaviyo«, 225 Franklin St, Boston, MA 02110, USA.
The email addresses of our newsletter recipients, as well as other data described in this notice, are stored on Klaviyo's servers in the USA. Klaviyo uses this information to send and analyze the newsletters on our behalf. Furthermore, according to its own information, Klaviyo may use this data to optimize or improve its own services, for example, for the technical optimization of newsletter delivery and display, or for business purposes, such as determining the countries of origin of the recipients. However, Klaviyo does not use the data of our newsletter recipients to contact them directly or to share it with third parties.

We trust in Klaviyo's reliability and its IT and data security. Klaviyo is certified under the EU-US Privacy Shield Framework and is therefore committed to complying with EU data protection regulations. Furthermore, we have entered into a Data Processing Agreement with Klaviyo. This agreement obligates Klaviyo to protect our users' data, to process it on our behalf in accordance with its privacy policy, and, in particular, not to disclose it to third parties. You can find Klaviyo's privacy policy here (in English).

At the end of each newsletter, you will find a link that allows you to unsubscribe at any time. After unsubscribing, your personal data will be deleted. This will simultaneously revoke your consent to its distribution via Klaviyo and the statistical analyses. Unfortunately, it is not possible to separately revoke consent for distribution via Klaviyo or for the statistical analysis.

4. When opening a customer account
To place orders on our website, you can order as a guest or create a customer account. When registering for a customer account, we require the following data:

• Salutation
• First and Last Name
• E-mail address
• Postal address (only upon ordering)
• E-mail address
• Password

This data is collected for the purpose of providing you with password-protected direct access to your basic data stored with us. You can view your past and current orders, or manage and change your personal data.
The legal basis for processing the data for this purpose lies in your consent, partly in the performance of (pre-)contractual obligations and our legitimate interest pursuant to Art. 6 para. 1 lit. a, b and f GDPR.

5. Upon receiving your application
You can apply to us spontaneously or in response to a specific job posting. We generally require the following information and documents:

• First and Last Name
• Postal address
• Telephone or mobile number
• E-mail address
• Birth date
• Nationality / Residence permit
• Cover letter
• CV

We use this and other data you voluntarily provide to process your application. Application documents from unsuccessful candidates for a specific open position will be deleted no later than three months after the position has been filled. Your application documents will only be deleted after 24 months if you have given us your consent to store them for a longer period. For applications that have resulted in a successful placement, the documents will be transferred to our employee records.
The legal basis for processing your data for this purpose is therefore our legitimate interest, the fulfillment of (pre-)contractual obligations and partly your consent pursuant to Art. 6 para. 1 lit. a, b and f GDPR.

6. When conducting a prize draw
We offer prize draws on our website on various occasions. We generally require the following information from you:

• First and Last Name
• Country
• E-mail address

This data, and any other information you voluntarily provide, will only be used for administering the prize draw. Once the prize draw is complete and the winner has been determined and notified, the collected data will be deleted.
The legal basis for processing your data is your consent and our legitimate interest pursuant to Art. 6 para. 1 lit. a and f GDPR.

7. Cookies
Cookies help in many ways to make your visit to our website easier, more enjoyable, and more meaningful. Cookies are information files that your web browser automatically saves to your computer's hard drive when you visit our website.
We use cookies, for example, to temporarily save your selected services and entries when filling out a form on the website, so that you don't have to re-enter the information when visiting another page. Cookies may also be used to identify you as a registered user after you register on the website, without requiring you to log in again when visiting another page.

Most internet browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer or so that a notification always appears when you receive a new cookie. The following pages explain how to configure cookie settings in the most common browsers:

• Microsoft's Windows Internet Explorer
• Microsoft's Windows Internet Explorer Mobile
• Mozilla Firefox
• Google Chrome for Desktop
• Google Chrome for Mobile
• Apple Safari for Desktop
• Apple Safari for Mobile

Disabling cookies may prevent you from using all the features of our website.


B. Use of your data for advertising purposes


For the purpose of tailoring our website to user needs and continuously optimizing it, we use various tracking and retargeting technologies:

1. Google Analytics, Google Remarketing, Google Tag Manager
We use the web analytics service Google Analytics from Google Inc., Amphitheatre Parkway, Mountain View, CA 94043, USA, on our website. We use Google Analytics to continuously optimize our website and tailor it to user needs. Google Analytics uses cookies (see section 7), which are stored on your computer and enable analysis of website usage. The information generated by the cookie about your use of this website, in particular

• the navigation path a visitor follows on the page
• the time spent on the website or subpage
• the next website accessed after visiting the website
• the country, region or city from which access is made
• the end device (type, version, color depth, resolution, width and height of the browser window)
• returning or new visitors
• the type and version of the internet browser used
• the operating system used
• the website from which access is made (so-called referrer URL)
• the IP address of the accessing computer (anonymized)
• the time of the server request
• the actions on the website (clicks, downloads, purchases)

The information generated by the cookie about your use of the website will be transmitted to and stored on Google servers in the USA. Google will use this information to evaluate your use of the website, to compile reports on website activity for us, and to provide other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will not associate your IP address with any other data held by Google. IP addresses are anonymized so that they cannot be linked to you as an individual. Google is listed as a participant in the Privacy Shield framework. The Privacy Shield agreement between the EU and the USA guarantees minimum standards for data protection.

We continue to use Google Remarketing (so-called DoubleClick by Google) for online advertising and to analyze the use of our website. The combined use of first-party and third-party cookies allows us to analyze in reports how ad impressions relate to website visits. Third-party providers, including Google, have the ability to display ads on websites and target and optimize them based on previous website visits according to demographic characteristics and interests (for example, age, gender, or interests). The data may be obtained from Google or from third-party visitor data sources.

We also use Google Tag Manager to manage services related to interest-based advertising. The tool itself is a cookieless domain and does not collect any personal data. Rather, it triggers other tags, which may in turn collect data. If you have deactivated tracking at the domain or cookie level, this deactivation will remain in effect for all tracking tags implemented with Google Tag Manager.

By using our website, you agree to the processing of your data in the manner and for the purpose described above.
You have the option to prevent your data from being analyzed by Google Analytics. If you wish to do so, please follow this link to download and install a browser plugin. Further information about Google's privacy policy can be found here.
The legal basis for processing the data for this purpose lies in our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.

2. Facebook Connect
We use Facebook Connect, a service provided by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA, or, if you are located in the EU, by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. Facebook Connect allows users to log in to other websites, apps, and services using their Facebook identity. In doing so, these other services gain access to certain preferences and connections stored in Facebook, which they can use to tailor their own offerings. Facebook can use data about users' activity on these other services to recognize visitors to our website on its own services and to present them with personalized offers based on their interests and preferences.
Further information about the retargeting tool used can be found in Facebook's privacy policy at this link.
The legal basis for processing the data for this purpose lies in our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.

3. Facebook Custom Audience
We use Facebook Custom Audiences, a service provided by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA, or, if you are located in the EU, by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. When using Custom Audiences, a non-reversible and non-personally identifiable checksum (hash value) is generated from your usage data, which can be transmitted to Facebook for analysis and marketing purposes.
Further information on how Facebook Pixel works and on the general display of Facebook ads can be found in Facebook's privacy policy at this link.
The legal basis for processing the data for this purpose lies in our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.

4. Creating user profiles
To provide you with personalized services and information, we use and analyze the data we collect about you. Analyzing your user behavior may lead to the creation of a so-called usage profile.
The legal basis for processing the data for this purpose lies in our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.

5. Clear Attribution
We use the services of Klar (Klar Insights GmbH, Marktstr. 18, 80802 Munich, Germany) on our website. Klar collects, processes, and stores data on this website and its subpages for audience measurement and statistical analysis on our behalf. This data collection is based on the following legal grounds:
If the user has given their consent in accordance with Article 6 Paragraph 1 Sentence 1 a GDPR and Section 25 Paragraph 1 Sentence 1 TTDSG, the data to be processed will be collected on a user-specific basis.
Different cookies are used for the aforementioned different types of data collection in order to ensure the respective type of data collection.
Cookie - Opt-out
To object to the use of Klar altogether, please use this Clicking this link will set a cookie named "do_not_track" from the domain "revitalice.ch". Please do not delete this cookie, as otherwise we cannot guarantee that you will not be tracked by Klar.
Information on data protection and data usage by Klar can be found on the following website: https://www.getklar.com/data-protection
C. Social media functionalities
Our website uses social plugins. These include "like" buttons or similar social media functionalities, as well as dynamic links to our social media profiles on the respective social media networks. You can recognize the plugins by the logo of the respective network.
If you are logged into a social network and visit our website, the social network can directly associate your visit with your social media account. If you interact with the plugins, the corresponding information is also transmitted directly to a server of the provider and stored there. This information may also be published on the social network and potentially displayed to other users of the social network (e.g., if the "Like" button is clicked).

The social network provider may use this information for advertising, market research, and to tailor its services to user needs. This may involve creating usage, interest, and relationship profiles, for example, to analyze website usage in relation to advertising, to inform other users about your activities on our website, and to provide other services related to the use of the social network.
For information on the purpose and scope of data collection and the further processing and use of data by the providers of the social networks, as well as the user's rights and settings options for protecting their privacy, please refer to the privacy policy of the respective provider.

If you do not want the social network provider to be able to associate your data with your account, you must log out of the social network before activating the plugins or before visiting our website.
This website uses plugins from the following providers:

• Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA, or, if you are located in the EU, Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland
• Instagram Inc., 1601 Willow Road, Meno Park, CA 94025, USA
• Pinterest Inc., 635 High Street, Palo Alto, CA, 94301, USA,
• Google+, Google Inc., Amphitheater Parkway, Mountain View, CA 94043, USA
• Linkedin Ltd., Dublin 2, Ireland,
• YouTube, a service operated by Google Inc.

You can object to this data processing at any time by using the opt-out options mentioned in this section.
The legal basis for this data processing lies in our legitimate interest pursuant to Art. 6 para. 1 lit. f GDPR.


D. Storage and exchange of data with third parties


1. Central storage and linking of data
We store the data specified in the preceding paragraphs in a central electronic data processing system. Your data is systematically collected and linked for the purpose of processing your orders and fulfilling our contractual obligations. For this, we use software from Magento, 54 N Central Ave Ste 200, Campbell, CA 95008, USA. We base the processing of this data within the software on our legitimate interest, as defined in Article 6(1)(f) of the GDPR, in customer-friendly and efficient customer data management.


2. Storage period
We only store personal data for as long as necessary to use the aforementioned tracking services and for other processing activities within the scope of our legitimate interests. Contractual data is retained for a longer period, as required by statutory retention obligations.
Data retention obligations arise from accounting and tax law. According to these regulations, business correspondence, concluded contracts, and accounting documents must be retained for up to 10 years. If we no longer require this data to provide services to you, the data will be restricted. This means that the data may then only be used for accounting and tax purposes.


3. Disclosure of data to third parties
We only share your personal data if you have given your explicit consent, if there is a legal obligation to do so, or if it is necessary to enforce our rights, in particular to enforce claims arising from the contractual relationship. Furthermore, we share your data with third parties to the extent necessary for the use of the website and the processing of the contract (including outside the website), specifically the processing of your order. Various third-party service providers are explicitly mentioned in this privacy policy (e.g., in sections 3 and 8-10).

Finally, when you pay by credit card on our website, we forward your credit card information to your credit card issuer and the credit card acquirer. If you choose to pay by credit card, you will be asked to enter all the necessary information. The legal basis for this data transfer is the performance of a contract pursuant to Art. 6 para. 1 lit. b GDPR. Regarding the processing of your credit card information by these third parties, please also read the terms and conditions and privacy policy of your credit card issuer.
Klarna's payment options: In order to offer you Klarna's payment options, to assess your eligibility, and to tailor these options to your needs, we may share your personal data, such as contact and order information, with Klarna during the checkout process. Your personal data will be processed in accordance with applicable data protection laws and as described in Klarna's privacy policy (available in German, French, Italian, and English versions).

4. Transfer of personal data abroad
We are entitled to transfer your personal data to third-party companies (contracted service providers) abroad for the purposes of the data processing described in this privacy policy. These companies are bound by the same data protection obligations as we are. If the level of data protection in a country does not correspond to the Swiss or European level, we contractually ensure that the protection of your personal data is equivalent to that in Switzerland or the EU at all times.


E. Further information

1. Right to information, rectification, erasure and restriction of processing; right to data portability
You have the right to request information about the personal data we hold about you. You also have the right to correct inaccurate data and the right to have your personal data deleted, provided that this does not conflict with any legal obligation to retain the data or a legal basis that permits us to process it.

You also have the right to request the data you have provided to us back (right to data portability). Upon request, we will also transfer the data to a third party of your choice. You have the right to receive the data in a commonly used file format.
You can contact us for the aforementioned purposes via this email address. We may, at our discretion, request proof of identity to process your requests.


2. Data security
We employ appropriate technical and organizational security measures to protect your personal data stored with us against manipulation, partial or complete loss, and unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.

You should always keep your login details confidential and close the browser window when you have finished communicating with us, especially if you share the computer with others.
We also take internal data protection very seriously. Our employees and the service providers we commission are bound by confidentiality agreements and are obligated to comply with data protection regulations.


3. Note on data transfers to the USA
For the sake of completeness, we would like to inform users residing or domiciled in Switzerland that US authorities have surveillance measures in place that generally allow the storage of all personal data of any person whose data has been transferred from Switzerland to the USA. This occurs without differentiation, limitation, or exception based on the pursued objective and without any objective criterion that would allow US authorities to restrict access to and subsequent use of the data to very specific, strictly limited purposes that could justify the interference associated with both accessing and using this data.

Furthermore, we would like to point out that in the USA, individuals from Switzerland have no legal remedies to access their personal data and have it corrected or deleted, nor is there effective judicial protection against the general access rights of US authorities. We explicitly inform the data subjects of this legal and factual situation so that they can make a correspondingly informed decision regarding their consent to the use of their data.

Users residing in an EU member state are advised that, from the European Union's perspective, the USA does not provide an adequate level of data protection – due, among other things, to the issues mentioned in this section. Where this privacy policy indicates that recipients of data (such as Google) are located in the USA, we will ensure that your data is adequately protected by our partners, either through contractual agreements with these companies or by ensuring their certification under the EU-US or Swiss-US Privacy Shield.


4. Right to lodge a complaint with a data protection supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority at any time.

As of October 2023

AYOS Coffee GmbH