GDPR Compliance Statement
Effective date: 2025-02-10
1. Controller Identity
- Company Legal Name
- Cessoalpino
- Registered Address
- Hauptstraße 123, 8000 Zürich, Switzerland
- Registration Number
- CHE-123.456.789 (Handelsregister Zürich)
- Privacy Contact
- contact@cessoalpino.com
2. Legal Bases for Processing
We rely on the following GDPR legal bases:
- Consent — where you voluntarily provide information or opt in.
- Contract — when data is needed to fulfill agreements with you.
- Legal obligations — to comply with tax, accounting, or regulatory requirements.
- Legitimate interests — to ensure security, maintain services, and communicate essential information (balanced against your rights).
3. Data Retention
Personal data is kept only as long as necessary:
- Contact inquiries: 48 months
- Contracts/transactions: statutory retention 4 years
- Server logs: typically 112 weeks
4. Cross-Border Data Transfers
If personal data is transferred outside the EU/EEA, we use appropriate safeguards:
- Standard Contractual Clauses (SCCs)
- EU adequacy decisions
- Technical & organizational measures for security
5. Your Rights
Under GDPR, you have rights to:
- Access and receive a copy of your data
- Rectify inaccuracies
- Request erasure (with limitations)
- Restrict or object to processing
- Data portability
- Withdraw consent anytime (where applicable)