Privacy Policy

Privacy Notice – Customers/Clients

This notice applies to you and your personal data because you are a client of CBC Health AG, Bodenhof 4, 6014 Lucerne, Switzerland (CBC Health Clinic). This company acts as the controller for the processing of your personal data. This notice explains how the personal data acquired from you or from third parties is used during our contractual relationship.

We may update this notice from time to time and we will notify you here if this happens. This version of the notice was issued on 01/10/2019 and updated on 21/02/2022.

Categories of personal data

We process the following data:

Service Category of personal data Example of personal data
Conclusion of contracts for consultancy services Personal contact details Name, surname, permanent residence address, correspondence address, email address, contact telephone number, ID number, academic degree
Contract details Content of the contract concluded with our company, including all annexes, scope of the services provided
Services and products provided Products and services, subscription, order history, accommodation, transportation, arrival/departure, etc.
Payment details Bank account number and amount of chargeable services, products, payment date and payment time
Correspondence and communication details Emails, letter correspondence
Support for sales and customer service Personal contact details Name and surname, address, gender, telephone, email, employment position, payment details
Contract details Bank account number and amount of chargeable services, products, payment date and payment time, identification of the payer
Correspondence and communication details Email, letter correspondence
Complaints / Cancellations Name, surname, address, amount of the fee, name of the product or service complained about, date of receipt of the complaint, form of settlement
Webinars and remote online trainings Personal contact details Name, surname, or Nickname of the user used on Skype or Hangout, email address, form of realisation or access to the webinars/trainings you are interested in
Contract details Name of the webinar/training, bank account number and amount of chargeable services, products, payment date and payment time, identification of the payer, date and time the webinar/training was held
Correspondence and communication details Email, letter correspondence
Comparison of attributes of the person in question to the group with a similar profile through different scoring Personal contact details Email address, date and time of registration
Contract details Date and time of service activation
Activities Interest types
Archiving of documentation in accordance with special regulations According to the above columns According to the above columns for the duration of retention

Purposes and objectives of data processing

CBC Health Clinic will process your data for the following purposes:

Service Purpose of processing Description of the purpose of processing Legal basis
Customer administration for selected medical treatments Conclusion of contract with the client We keep personal records of all our customers and their selected services. Based on the analysis of our records, we make strategic decisions regarding the offers for our customers The legal basis for this purpose is the contract concluded between our company and you as the data subject
Handling of disputes and complaints We may process personal data for the handling of disputes, complaints or legal proceedings, or in the event of suspected violations that we wish to investigate further. The legal basis for this purpose is a legitimate interest of our company as the data controller. It is in our interest to have all documents secured and available for the resolution of a possible dispute.
Taxes and accounting For the purpose of fulfilling obligations arising from tax law or other regulations related to financial benefits, we are obliged to process certain personal data The legal basis for this purpose is the fulfilment of legal obligations based on accounting and tax regulations
Statistical purposes Summarised or aggregated personal data can serve as an evaluation object for the internal needs of the data controller The legal basis for the processing is the legitimate interest and the fulfilment of the legal obligation of the data controller.
Compliance with laws We may need to process your personal data to comply with the law (e.g. to comply with security requests from government bodies or a court order) The legal basis for this purpose is the fulfilment of legal obligations
Archiving In accordance with special regulations, we are obliged to retain some data from our relationships The legal basis for this purpose is the fulfilment of legal obligations
Webinars and remote online trainings Registration of participation in the training We keep personal records of all our customers and their selected services. Based on the analysis of our records, we make strategic decisions regarding the offers for our customers The legal basis for this purpose is the contract concluded between our company and you as the data subject
Taxes and accounting For the purpose of fulfilling obligations arising from tax law or other regulations related to financial benefits, we are obliged to process certain personal data The legal basis for this purpose is the fulfilment of legal obligations based on accounting and tax regulations
Direct marketing We deal with the development of our customers and with customised offers for them The legal basis for this purpose is a legitimate interest of our company as the data controller.
Statistical purposes Summarised or aggregated personal data can serve as an evaluation object for the internal needs of the data controller The legal basis for the processing is the legitimate interest and the fulfillment of the legal obligation of the data controller
Compliance with laws We may need to process your personal data to comply with the law (e.g. to comply with security requests from government bodies or a court order) The legal basis for this purpose is the fulfilment of legal obligations
Archiving In accordance with special regulations, we are obliged to retain some data from our relationships The legal basis for this purpose is the fulfilment of legal obligations
Invoicing, complaints, information link Processing of events, invoicing,
responses to questions, information on debtor payments (basis for invoicing)
For the purpose of fulfilling obligations arising from tax law or other regulations related to financial benefits, we are obliged to process certain personal data The legal basis for this purpose is the fulfilment of legal obligations based on accounting and tax regulations
Handling of disputes and complaints We may process personal data for the handling of disputes, complaints or legal proceedings, or in the event of suspected violations that we wish to investigate further. The legal basis for this purpose is a legitimate interest of our company as the data controller
Statistical purposes Summarised or aggregated personal data can serve as an evaluation object for the internal needs of the data controller The legal basis for the processing is the legitimate interest and the fulfillment of the legal obligation of the data controller
Compliance with laws We may need to process your personal data to comply with the law (e.g. to comply with security requests from government bodies or a court order) The legal basis for this purpose is the fulfilment of legal obligations
Archiving In accordance with special regulations, we are obliged to retain some data from our relationships The legal basis for this purpose is the fulfilment of legal obligations
Statistics and marketing Comparison of attributes of the person in question to the group with a similar profile through different scoring Registration of participation in the competition The legal basis for the processing is the consent of the data subject and the performance of the contract, where the data subject is one of the contracting parties
Handover of the prize – Legal compliance Notification of the result and transfer of the prize The legal basis for the processing is the legitimate interest and the fulfillment of the legal obligation of the data controller

Parties who may have access to your data

The data controller may share your data with third parties in the following circumstances:

Positioning of your personal data

Access to your personal data, insofar as it is in our care, will be granted to staff within the European Union and the European Economic Area.

Storage of personal data

Your personal data will be stored by us for a limited period of time and will be deleted when it is no longer required for processing purposes. In the majority of cases, this means that we only store your data for the duration of your contractual relationship with us. If possible, we will delete the data within this relationship as soon as it is no longer necessary.

In any case, we will delete your personal data at the latest within 30 calendar days after the termination of the contractual relationship (unless local legislation requires longer storage to a defined extent, e.g. special regulations such as accounting law, VAT law, etc.).

We may process your personal data for a longer period of time after the termination of the contractual relationship in the event of an ongoing legal dispute, as well as in the event of your consent for long-term personal data retention.

If you have given your consent for us to inform you about share offers from CBC Health Clinic and commercial information from contractual partners through appropriate communication channels, we will process your personal data for this purpose until you withdraw your consent. You will be informed about the possibility of withdrawing your consent in every message you receive. If we process your personal data on the legal basis of legitimate interest, you can object to this processing. We will carefully and individually evaluate your objections and inform you of our decision in this regard.

Purpose of processing Storage period
Customer administration From the 1st of January of the following year in which the contractual relationship is terminated, it will be 4 years
Handling of disputes and complaints Three months after the end of the dispute; in the case of tax benefits, the following 10 years
Taxes and accounting From the 1st of January of the following year in which the relationship ends, for 10 years
Direct marketing Within the period of validity of the contractual relationship or membership
Compliance with laws Within 4 years
Marketing consents Within the marketing consent period, or until consent is withdrawn
Statistical purposes Within 4 years
Communication/IT Monitoring/Logs Within 2 years

Your rights under data protection law

According to the EU General Data Protection Regulation (GDPR), you have certain rights:

Your rights Meaning
 

Right to access

You may request information about how we process your personal data, including information about:

  • why we process your personal data
  • which categories of personal data we process
  • with whom we share your personal data
  • how long we store your personal data or what the criteria are for determining this period
  • what rights you have
  • where we obtain your personal data from (if we have not obtained it from you)
  • if the processing includes automated decision-making (so-called profiling)
  • if your personal data has been transferred to a country outside the European Economic Area, how we ensure the protection of your personal data

All of the above information is contained in these principles for the protection of personal data.

You can also request a copy of your personal data that we process. However, repeated requests may be subject to a fee.

Right to correction or amendment It is important that we have accurate information about you and we ask you to let us know if any of your personal data does not match, for example if you have changed your name or if you have moved residence
Right to be forgotten or right to erasure If we process your personal data unlawfully, e.g. if we process your personal data for longer than necessary or without justification, you can request us to delete this data
Right to restriction of processing You have the right to restrict the processing of your personal data from the point at which you request a change to your personal data or object to its processing until such time as we are able to resolve the issue or confirm the accuracy of your personal data (or change it in accordance with your instructions). It means that (with the exception of the storage of personal data) we may only process your personal data with your consent if it is necessary in connection with legal claims, for the legal protection of someone else, or if there is a significant public interest in the processing.

You can also request a restriction of the processing of your personal data if the processing is unlawful but you do not want the personal data to be deleted.

Right to object to the processing If you believe that we do not have the right to process your personal data, you can object to our processing. In such cases, we can only continue processing if we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. However, we may process your personal data at any time if it is necessary for the establishment, exercise or defence of our legal claims.
Right to data portability You may request that your personal data, which you have provided to us for processing on the basis of your consent or for the purpose of fulfilling a contract, be provided in a structured, commonly used and machine-readable form. You also have the right to request the transfer of this data to other data controllers.
Right to withdraw consent In cases where we request your consent for the processing of personal data, you have the right to withdraw this consent for the further use of your personal data at any time

We will also inform the other parties with whom we have shared your personal data about your request(s).

Contact details

If you have any further questions regarding the processing of your personal data, you can contact us in this regard by sending an email to info@cbchealth.de, or by post to the address: CBC Health AG, Bodenhof 4, 6014 Lucerne, Switzerland

If you are not satisfied with our response, or if you believe that we are processing your data unfairly or unlawfully, you can lodge a complaint with the supervisory authority – in this case the Office for Personal Data Protection.