1. Controller

The controller responsible for processing your personal data within the meaning of the Swiss Federal Act on Data Protection (nFADP, in force since 1 September 2023) is:

MS Governance & Risk Advisory GmbH
Stadtturmstrasse 19
5400 Baden
Switzerland
Phone: +41 79 800 59 27
E-mail: info@ms-gra.com

For clients and prospective clients in the European Union, the EU General Data Protection Regulation (GDPR) additionally applies. Where the GDPR is applicable, our data protection officer corresponds to the controller indicated above.

2. Principles of Data Processing

We process your personal data in accordance with the following principles:

  • Lawfulness: We process data only on a lawful basis (performance of a contract, legitimate interest, legal obligation or consent).
  • Purpose limitation: Data is used only for the stated purpose.
  • Data minimisation: We collect only the data necessary for the respective purpose.
  • Accuracy: We endeavour to keep data up to date and accurate.
  • Storage limitation: Data is retained only for as long as required by the purpose or by law.
  • Confidentiality: We protect your data through appropriate technical and organisational measures.

3. What Data We Process

3.1 Website Usage

When you visit our website, technical information is automatically recorded by the server (server log files):

  • IP address (anonymised after a short period)
  • Date and time of access
  • URL / page accessed
  • Browser type and version, operating system
  • Referrer URL (previously visited page)

This data is used exclusively for technical fault analysis and security. It is not combined with other data.

3.2 Contact Form

When you use our contact form, we collect the following data:

  • Name (required)
  • E-mail address (required)
  • Phone number (optional)
  • Company / institution (optional)
  • Subject and message text

3.3 Event Registrations

When registering for events, we collect your name, e-mail address, phone number (optional), company (optional) and your role / function.

3.4 Business Correspondence

In the course of consulting mandates, we process the personal data of our contact persons that is necessary for service delivery (name, contact details, professional role).

4. Purposes and Legal Bases

We process your data for the following purposes:

  • Responding to enquiries (Art. 6(1)(b) GDPR / legitimate interest)
  • Provision of advisory services (performance of contract)
  • Event management (consent / performance of contract)
  • Distribution of newsletters / publications (consent)
  • Compliance with statutory obligations (accounting, retention obligations)
  • Security of our information systems (legitimate interest)

Under Swiss law, we rely on Art. 31 nFADP (legitimate interest), Art. 13 nFADP (consent) and the respective contractual bases.

5. Disclosure to Third Parties

We do not generally disclose your personal data to third parties. Exceptions:

  • Data processors: IT service providers and web hosting companies that we use to operate our website act exclusively on our instructions and are contractually bound to confidentiality.
  • SMTP e-mail delivery: For the dispatch of contact and registration confirmations, we use a configured SMTP server. The data necessary for sending is transmitted in this process.
  • Legal obligation: Where we are legally required to disclose data (e.g. pursuant to an official order).
  • Legal enforcement: For the assertion or defence of legal claims.

Transmission to countries without an adequate level of data protection takes place only with your express consent or to the extent permitted by law.

6. Retention Periods

  • Contact enquiries: Until fully processed, then deleted within 12 months, provided no business relationship has arisen.
  • Business correspondence / contract documents: 10 years pursuant to Art. 958f CO (Swiss Code of Obligations).
  • Server logs: Maximum 30 days.
  • Event registrations: Up to 6 months after the event.
  • Newsletter subscriptions: Until withdrawal of consent.

7. Data Security

We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss or misuse:

  • Encrypted data transmission (HTTPS / TLS)
  • Encrypted e-mail transmission (SMTP with TLS)
  • Access controls and password protection
  • Regular security updates
  • No storage of form data in databases unless necessary

Please note that complete security of data transmission over the internet cannot be technically guaranteed.

8. Cookies and Tracking

This website does not use tracking cookies, analytics tools (e.g. Google Analytics) or third-party social media plug-ins.

We use only technically necessary session cookies for the functioning of the website (e.g. CSRF protection for forms). These cookies are automatically deleted at the end of the browser session.

The following data is stored in browser LocalStorage:

  • Selected language (ms_lang) – for language preference
  • Cookie notice confirmation (ms_cookie)

This data does not leave your browser and is not transmitted to us.

9. Your Rights

You have the following rights with regard to your personal data:

  • Right of access (Art. 25 nFADP / Art. 15 GDPR): You may request information about the data we hold about you.
  • Right to rectification (Art. 32 nFADP / Art. 16 GDPR): You may request the correction of inaccurate data.
  • Right to erasure (Art. 32 nFADP / Art. 17 GDPR): Under certain conditions, you may request the deletion of your data.
  • Right to restriction of processing (Art. 18 GDPR): You may request that processing be restricted.
  • Right to data portability (Art. 20 GDPR): You may receive your data in a machine-readable format.
  • Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests.
  • Withdrawal of consent: You may withdraw any consent given at any time with effect for the future.
  • Right to lodge a complaint: You have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC) or the supervisory authority of your EU member state.

To exercise your rights, please contact us in writing (see contact details in section 11).

10. Changes to this Privacy Policy

We reserve the right to amend this Privacy Policy at any time. The current version is available on this website. The «Version» date at the beginning of this document is authoritative.

In the event of material changes, we will notify you via the contact channels indicated on our website, provided you have shared your contact details with us.

11. Contact for Privacy Matters

For questions about data protection or to exercise your rights, please contact:

MS Governance & Risk Advisory GmbH
Attn: Data Protection
Stadtturmstrasse 19, 5400 Baden, Switzerland
E-mail: info@ms-gra.com
Phone: +41 79 800 59 27

We process data protection requests within 30 days.

Back to Homepage

Other Legal Documents


Questions? We are happy to help:

info@ms-gra.com