Privacy Policy
How we collect, process, and protect personal data.
Effective Date: 24 April 2025
This Privacy Policy explains how Norevian Helvetic GmbH ("Norevian Helvetic", "we", "us", or "our") collects, processes, and protects personal data in connection with the use of our website https://norevianhelvetic.ch/ (the "Website"). We are committed to full compliance with the Swiss Federal Act on Data Protection (nDSG, in force since 1 September 2023), the EU General Data Protection Regulation (GDPR) where applicable, and all other relevant applicable data protection laws.
1. Identity of the Data Controller
The entity responsible for data processing in relation to this Website is:
Company: Norevian Helvetic GmbH
Address: Dorfstrasse 11, 6442 Gersau, Switzerland
General Contact: office@norevianhelvetic.ch
Privacy / Data Protection: privacy@norevianhelvetic.ch
Phone: +41 77 487 97 92
Managing Director: Mihai Bejenaru
For all data protection enquiries, please contact us at: privacy@norevianhelvetic.ch
2. Scope and Purpose of This Policy
This Policy applies exclusively to the Website operated by Norevian Helvetic GmbH. Our Website is a presentation and information website. We do not offer e-commerce, user accounts, or subscription services. The data processing described herein is therefore limited in scope and proportionate to the nature of the Website.
3. Data We Collect and Why
3.1 Server Log Files (Automatically Collected)
When you visit our Website, our hosting provider automatically collects technical log data, including:
- IP address (anonymised where technically possible)
- Date and time of the request
- URL requested and referring URL
- Browser type and version
- Operating system
- HTTP status code and volume of data transferred
Legal basis (nDSG/GDPR): Legitimate interest (Art. 6(1)(f) GDPR / Art. 31 nDSG) in ensuring website security, stability, and proper technical operation. Log data is retained for a maximum of 30 days and then deleted, unless a longer retention period is required for security incident investigation.
3.2 Contact by Email or Phone
If you contact us voluntarily by email or telephone, we process the personal data you provide (e.g. name, email address, message content) solely for the purpose of responding to your enquiry.
Legal basis: Performance of pre-contractual measures or legitimate interest (Art. 6(1)(b) and (f) GDPR / Art. 31 nDSG). Data is retained for as long as necessary to handle your request and for a maximum of 3 years thereafter, unless legal retention obligations require a longer period.
3.3 Cookies
Our Website uses cookies. Cookies are small text files stored on your device by your browser. We use the following categories:
Strictly necessary cookies: These cookies are essential for the Website to function correctly (e.g. session management, security). They cannot be disabled without breaking Website functionality. No consent is required for these cookies under Swiss or EU law.
Analytics / performance cookies (Lovable platform): Our Website is built using Lovable (lovable.dev). Lovable may set analytics cookies to monitor Website performance and usage patterns. These cookies may be set by third-party providers. Where these cookies process personal data, they are subject to the consent mechanism described in Section 4 below. Please refer to Lovable's privacy documentation for further detail on the cookies they set.
We do not use advertising, tracking, or profiling cookies for marketing purposes. We do not engage in cross-site tracking.
4. Cookie Consent and Management
When you first visit our Website, you are presented with a cookie consent banner. Strictly necessary cookies are activated automatically. Analytics cookies are only activated if you click 'Accept'. You may withdraw your consent at any time by adjusting your browser settings to delete or block cookies, or by clearing your browser's cookie storage.
Please note that disabling cookies may affect the display or functionality of parts of the Website.
5. Third-Party Processors and Data Transfers
5.1 Hosting and Website Platform
Our Website is hosted and built using Lovable (lovable.dev). Lovable acts as a data processor on our behalf. By using the Website, technical data (including server logs and cookies as described above) may be processed on Lovable's infrastructure. Lovable may be located or use infrastructure outside Switzerland and the European Economic Area (EEA), including in the United States.
Where data is transferred to the United States or other third countries without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) as approved by the European Commission, or equivalent mechanisms recognised under Swiss data protection law.
5.2 No Sale of Data
We do not sell, rent, or otherwise commercially exploit your personal data to any third party.
5.3 Disclosure to Authorities
We may disclose personal data to competent authorities if required by applicable law, court order, or to protect our legitimate legal interests. We will notify you of any such disclosure where permitted by law.
6. International Data Transfers
As noted above, our Website platform (Lovable) may process data outside Switzerland and the EEA. Any such transfer is carried out in accordance with Chapter V GDPR and the applicable provisions of the nDSG, using Standard Contractual Clauses or other recognised transfer mechanisms. You may request information about the safeguards in place by contacting us at privacy@norevianhelvetic.ch.
7. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by applicable law:
- Server log files: maximum 30 days
- Email/phone correspondence: maximum 3 years from last contact
- Consent records (cookie consent logs): 3 years
- Legal and accounting records: 10 years (as required by Swiss law)
After the applicable retention period, data is securely deleted or anonymised.
8. Your Rights as a Data Subject
Under the nDSG and GDPR (where applicable), you have the following rights:
- Right of access (Art. 25 nDSG / Art. 15 GDPR): You may request confirmation of whether we process personal data about you and obtain a copy.
- Right to rectification (Art. 32 nDSG / Art. 16 GDPR): You may request correction of inaccurate or incomplete data.
- Right to erasure (Art. 32 nDSG / Art. 17 GDPR): You may request deletion of your personal data, subject to legal retention obligations.
- Right to restriction of processing (Art. 18 GDPR): You may request that we restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20 GDPR): Where processing is based on consent or contract and carried out by automated means, you may request a machine-readable copy of your data.
- Right to object (Art. 21 GDPR / Art. 32 nDSG): You may object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at privacy@norevianhelvetic.ch. We will respond within 30 days. We may need to verify your identity before processing your request. There is no charge for exercising your rights.
If you believe we have violated your data protection rights, you have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch, or with the supervisory authority of your EU Member State if you reside in the EU.
9. Data Security
We implement appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encrypted transmission via HTTPS/TLS
- Access controls limiting data access to authorised personnel
- Regular review of our security practices
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and, where required, notify affected individuals without undue delay.
10. Automated Decision-Making and Profiling
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects individuals, as referred to in Art. 22 GDPR or Art. 21 nDSG.
11. Children's Data
Our Website is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@norevianhelvetic.ch and we will delete it promptly.
12. Links to Third-Party Websites
Our Website may contain links to external websites. This Privacy Policy applies only to our Website. We have no control over, and accept no responsibility for, the privacy practices of third-party websites. We encourage you to review the privacy policies of any third-party websites you visit.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or Website functionality. The current version is always available on our Website. Where changes are material, we will provide prominent notice. The date at the top of this document indicates when the Policy was last updated.
14. Contact
For any questions, requests, or concerns regarding this Privacy Policy or our data processing practices, please contact:
Norevian Helvetic GmbH
Address: Dorfstrasse 11, 6442 Gersau, Switzerland
Privacy / Data Protection: privacy@norevianhelvetic.ch
Phone: +41 77 487 97 92
Norevian Helvetic GmbH — 24 April 2025
Dorfstrasse 11, 6442 Gersau, Switzerland | CHE-150.903.293