Privacy Policy – wisperapp.com

I.    Scope of this Privacy Policy

This Privacy Policy applies to the website “wisperapp.com”. This privacy policy (data protection policy) only applies to this particular website. It does not apply for other websites which are merely referenced via hyperlink. We cannot assume responsibility for the confidential handling of your personal data on these third-party websites, since we do not have any influence in the data protection compliance by these companies. Please inform yourself on the handling of personal data by these companies directly on their websites. 

With regard to the general data processing on the application “Wisper” regarding Swiss Federal Act on Data Protection (FADP), General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), we refer you to the “Wisper Privacy Policy”, available at https://wisperapp.com/terms.

This privacy policy does not apply to personal data we process as a processor on behalf of third parties. This is especially the case with hosting personal data for third parties who run an organization on Wisper and their invitations to end users to join that organization. If you are an end user of one of those organizations, such as an employee or student, you should read that organization’s privacy policy and direct any privacy inquiries to the third party who runs that organization on Wisper.



II. Our privacy policy (data protection policy) under FADP and the GDPR

1.    General information and principles of data processing

We are pleased that you are visiting our website. 
The protection of your privacy and the protection of your personal data is an important concern to us.
In accordance with Article 5 (a) FADP and 4 (1) GDPR, personal data means any information relating to an identified or identifiable natural person. This includes, for example, information such as first and last name, address, telephone number, email address, but also an IP address.
Data that cannot be linked to your person, for example through anonymisation, is not personal data. Under Article 6 (1) FADP personal data must be processed lawfully and the processing of sensitive personal data according to Article 6 (6) and (7) FADP requires a consent. Under the GDPR, processing of personal data (e.g. collection, storage, readout, retrieval, use, transmission, deletion or destruction) according to Article 4 (2) GDPR always requires a legal basis or a consent. Processed personal data must be deleted as soon as the purpose of their processing has been achieved, and there are no longer any legally prescribed retention obligations.
Here you will find information on the handling of your personal data upon visiting our website. In order to provide the functions and services of our website, it is necessary for us to collect your personal data.
In the following, we explain the type and scope, purpose, legal basis and storage period of the respective data processing.


2.    Controller

Responsible for the processing of personal data on this website (see imprint) is:

Wisper GmbH
c/o Mercandor AG
Unter Altstadt 28
6300 Zug
Switzerland

Phone:     +41 (0) 41 710 2628
Email: info@wisperapp.com



3.    Representative of Controller according to Article 27 GDPR

FamCap Partners GmbH
Menzelstraße 5
81679 Munich
Germany

Phone: +49 (0)89 2305 9692
Email:    info@famcap.de



4.    Provision and use of the website / server log files

a)    Type and extent of data processing

When you access our website (i.e. when you merely view it without registering and without otherwise providing us with information), we process the following personal data, which your browser automatically transmits to our server:

·    Date and time of the request
·    Time zone difference to Greenwich Mean Time (GMT)
·    Content of the request (visited page)
·    Access status/HTTP status code
·    Amount of transferred data 
·    Web address from which the page or file was accessed or the requested function was initiated (referrer URL)
·    IP-address 
·    Browser
·    Language and version of the browser software
·    Operating system

b)    Purpose of data processing

This data described above is technically necessary to enable you to use our website. In addition, the data is technically necessary to ensure the stability of the website and IT security, in particular to protect our IT systems from misuse and to defend against attacks.

c)    Legal basis

As required under the GDPR, the legal basis for the collection and processing of the data is Article 6(1)(f) GDPR.

d)    Storage period

The aforementioned data will be recorded for the duration of the communication process. 
To guarantee IT security, the IP-address will be saved for an additional short period of time of no more than seven calendar days. 

e)    Right of objection

Under the GDPR, if your personal data is processed in accordance with Article 6(1)(f) GDPR you have a right of objection in accordance with Article 21 GDPR. However, in the case of the specific data processing operation, we have compelling legitimate grounds for processing the data that is necessary for the protection of these data, because without the processing of these data we cannot provide and operate our website.


5.    Use of cookies

We use cookies. Cookies are small files that are placed on your computer and stored by your browser. Some functions of our website cannot be offered without the use of technically necessary cookies, whereas other cookies allow us to perform various analyses. For example, some cookies can recognize the browser you are using when returning to our website and transmit various information to us. We use cookies in order to facilitate and improve the use of our website. For instance, through cookies we can create a more user-friendly and effective web offer for you, for example by retracing your use of our website and determining your preferred settings (e.g. country and language settings). If third parties process information via cookies, this information will be directly collected via your browser. Cookies do not cause any damage to your terminal device. They can neither run programs nor contain viruses. Various types of cookies are used on our website, their type and function are explained in the following.

If German law applies and cookies or cookie-like technologies are used in the context of data processing on this website, the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of user is based on your consent pursuant to Section 25 (1) of the German Telecommunications Digital Services Data Protection Act (“TDDDG”) in conjunction with the requirements of consent under data protection law pursuant to Art. 4 (11), 7 GDPR.

a)    Temporary cookies/ session cookies

Our website uses so-called temporary cookies or session cookies, which are automatically deleted when you close your browser. Through this type of cookies, it is possible to record your session ID. This allows various requests from your browser to be assigned to a common session and makes it possible to recognize your terminal device during subsequent visits to the website. These session cookies expire at the end of the session.

b)    Persistent cookies

Our website uses so-called persistent cookies. Persistent cookies are cookies that are stored in your browser over a longer period of time and can transmit information. The respective storage period varies depending on the cookie. Permanent cookies may be deleted independently via your browser settings.

c)     Cookie Consent with the consent management platform cookiebot by Usercentrics

Our website uses consent management platform cookiebot by Usercentrics to obtain your consent in the storage of cookies in your browser and document these in compliance with data protection. Provider of cookiebot by Usercentrics is Usercentrics GmbH, Sendlingerstraße 7, 80331 Munich, Germany.
Upon entering the website, cookiebot by Usercentrics stores a cookie in your browser, in which your obtained consent or the revocation of consent are documented. However, this data will not be transmitted to the provider cookiebot by Usercentrics. This is a required cookie, which does not need a consent. Under the GDPR, the legal basis for the data processing is Article 6(1)(a) GDPR. We use cookiebot by Usercentrics to ensure compliance with our legal obligations.     

The cookies are stored until you ask us to delete this data, you delete the cookie yourself or the storage is no longer necessary for the purpose of data processing. You can change your cookie settings at any time using the button to the lower left.     

d)    Categories of cookies

We use the following categories of cookies:

Necessary cookies:

Necessary cookies ensure functions that are essential to use our website as intended. These absolutely necessary cookies are used, for example, to ensure that registered users remain logged in when accessing various subpages. These are so-called first party cookies are only used by us. 
Under the GDPR, the legal basis for the data processing is Article 6(1)(f) GDPR – and if German law applies Section 25(2) TDDDG, as we have a legitimate interest in maintaining the functionality of our website. You have a right of objection pursuant to Article 21 GDPR. In the case of technically necessary cookies, however, we have compelling reasons worthy of protection for processing the data, because without processing this data we cannot properly provide our website or the respective functionality of the website.
As soon as the cookies are no longer required for the purposes described, they are deleted.

Preference cookies:

Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.

Under the GDPR, the legal basis for the processing of this personal data are our legitimate interests in accordance with Article 6(1)(f) GDPR and – if necessary – your consent in accordance with Article 6(1)(a) GDPR. As soon as the cookies are no longer required for the purposes described, the storage period ends or you withdraw your consent, these cookies are deleted.

Statistics cookies:

Statistics Cookies collect information about how a website is used in order to improve its attractiveness, content and functionality. For example, the following data is collected:

·    number of visits to a website or sub-pages
·    time spent on the website
·    sequence of visited pages
·    search terms 
·    country, region, city from which access is made
·    analysis which areas of our website are of particular interest to you

An overview of the cookies used can be found at the button to the lower left.

Under the GDPR, the legal basis for the processing of this personal data is your consent pursuant to Article 6(1)(a) GDPR – if German law applies in conjunction with Section 25(1) TDDDG. As soon as the cookies are no longer required for the purposes described, the storage period ends or you withdraw your consent, these cookies are deleted.

Marketing cookies: 

Marketing cookies are used to display interest-based advertisements to website visitors. Besides they are also used to limit the frequency of display and measure the effectiveness of advertisement campaigns. The information obtained with third parties such as advertisers. Cookies to improve targeting and advertising are often linked to third party site functionalities. 

Under the GDRP, the legal basis for the processing of this personal data is your consent pursuant to Article 6(1)(a) GDPR – if German law applies in conjunction with Section 25(1) TDDDG and Article 4(11), 7 GDPR for the following processing of personal data. As soon as the cookies are no longer required for the purposes described, the storage period ends or you withdraw your consent, these cookies are deleted.


6.    Services with statistics cookies (Statistics)


Google Analytics

a)    Type and scope of data processing 
On our website we use the tracking tool Google Analytics of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Tel: +353 1 543 1000, Fax: +353 1 686 5660 („Google“).
We have contracted a so-called data processing agreement with Google.

We have concluded a so-called order processing agreement insofar as Google acts as a processor for us. The data sharing settings to Google has been deactivated, so that consequently there is no joint controllership with Google. Google Analytics uses cookies, which are text files placed on your computer, to help the website analyze how users use the site. 

The information generated by cookies about your use of this website is usually transferred to a Google server in the USA and stored there. On behalf of the operator of this website, Google will use this information for the purpose of systematically evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage to the website operator. 

If individual pages of our website are called up, the following data is stored:

•    three bytes of the IP-address of the calling system of the user (anonymized IP-address) 
•    accessed website
•    website from which the user accessed the page of our website (referrer) 
•    sub-pages that are called from the caller page
•    time spent on the website 
•    frequency of a call of the website
•    scroll behavior and clicks
•    achievement of "website objectives" (e.g. newsletter registrations)
•    approximate location
•    information about the used browser, internet provider and device information

We use Google Analytics with enabled IP anonymization. Through this, the IP addresses are shortened by the last octet (e.g. 192.168.79.***; so-called IP masking). It is no longer possible to assign the abbreviated IP address to the calling computer or terminal device. 

FADP:
Google Ireland Limited transmits data to Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. We would like to point out that the Court of Justice of the European Union (CJEU) has doubts about the adequacy of the level of data protection in the USA. In particular, there is a risk that personal data may be processed by government authorities for control and monitoring purposes, possibly also without any legal remedy.

GDPR:
Google Ireland Limited transmits data to Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. The USA is a so-called third country, because it is located outside the EU. However, the USA has an adequacy decision from the European Commission (EU-U.S. Data Privacy Framework (DPF)). The decision concludes that the United States ensures an adequate level of protection – comparable to that of the European Union – for personal data transferred from the EU to US companies under the new framework. Google LLC has certified itself according to the DPF: 

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active 

b)    Purpose of data processing
The service of Google Analytics is used to analyse the usage behaviour of our online presence. 

c)    Legal basis 
Under the GDPR, the legal basis for the use of Google Analytics is your consent pursuant to Article 6(1)(a) GDPR. 

Your consent is also consent to data processing in the USA pursuant to Article 17 (1) (a) FADP.

d)    Storage period
The stored data will be deleted as soon as the cookie expires, or you withdraw your consent.
Google Analytics stores cookies in your web browser for a period of 14 months since your last visit. These cookies contain a randomly generated user ID that allows you to be recognized during future visits to the website.

The recorded data is stored together with the randomly generated user ID, which enables the evaluation of pseudonymous user profiles. This user-related data is automatically deleted after 14 months. Other data remains stored in aggregated form for an unlimited period.

e)    Right of withdrawal
The stored data will be deleted as soon as you withdraw your consent by deselecting the selected cookie category "Statistics" under "cookie settings".

f)    Further information
Further information on Google Analytics data protection: 
https://support.google.com/analytics/answer/6004245?hl=en
Further information on Google’s privacy policy can be found here: https://policies.google.com/privacy



7.    Services with marketing cookies


Google Tag Manager
We use Google Tag Manager. Google Tag Manager is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Tel: +353 1 543 1000, Fax: +353 1 686 5660, ("Google") that allows marketers to manage website tags through a single interface.

FADP:
Google Ireland Limited transmits data to Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. We would like to point out that the Court of Justice of the European Union (CJEU) has doubts about the adequacy of the level of data protection in the USA. 
In particular, there is a risk that personal data may be processed by government authorities for control and monitoring purposes, possibly also without any legal remedy.

GDPR:
Google Ireland Limited transmits data to Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. The USA is a so-called third country, because it is located outside the EU. However, the USA has an adequacy decision from the European Commission (EU-U.S. Data Privacy Framework (DPF)). The decision concludes that the United States ensures an adequate level of protection – comparable to that of the European Union – for personal data transferred from the EU to US companies under the new framework. Google LLC has certified itself according to the DPF: 

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active 

Google Tag Manager only implements tags. Tags are small elements of code on your website which, among other things, serve to measure traffic and visitor behaviour, to identify the impacts of online advertisement and social channels, use remarketing and targeting and to test and optimize your website. This means: No additional cookies are used. Google Tag Manager triggers other tags, which may collect data. Google Tag Manager does not access this data. If deactivation has been made at the domain or cookie level - in particular, if you have opted for the Google Analytics opt-out solution described above or have made the corresponding settings in your browser - it will remain in effect for all tracking tags provided that these are implemented with the Google Tag Manager.
For more information see Google's privacy policy: https://policies.google.com/terms
Privacy Policy for Advertising: www.google.de/intl/de/policies/technologies/ads.

Google Ads Remarketing
a)    Type and scope of data processing
We use Google Ads Remarketing. Google Ads Remarketing is a web analysis service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irleand, Tel: +353 1 543 1000, Fax: +353 1 686 5660 („Google").

This enables us to analyze user activities on our website, e.g. which offers a user was interested in, in order to be able to show the user targeted advertising on other pages after visiting our website. For this purpose, Google stores cookies on users' end devices, which serve to uniquely identify a web browser on a particular device.

FADP:
Google Ireland Limited transmits data to Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. We would like to point out that the Court of Justice of the European Union (CJEU) has doubts about the adequacy of the level of data protection in the USA. In particular, there is a risk that personal data may be processed by government authorities for control and monitoring purposes, possibly also without any legal remedy.

GDPR:
Google Ireland Limited transmits data to Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. The USA is a so-called third country, because it is located outside the EU. However, the USA has an adequacy decision from the European Commission (EU-U.S. Data Privacy Framework (DPF)). The decision concludes that the United States ensures an adequate level of protection – comparable to that of the European Union – for personal data transferred from the EU to US companies under the new framework. Google LLC has certified itself according to the DPF: 

https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt000000001L5AAI&status=Active 

b)    Purpose of data processing
The Google Ads Remarketing service is used to analyze the usage behavior of our website.

c)    Legal basis 
Under the GDPR, the legal basis for the use of Google Ads Remarketing is your consent pursuant to Article 6(1)(a) GDPR. 

Your consent is also consent to data processing in the USA pursuant to Article 17 (1) (a) FADP.

d)    Storage period    
The stored data will be deleted as soon as the cookie expires, or you withdraw your consent.

e)    Right of withdrawal
The stored data will be deleted as soon as you withdraw your consent by deselecting the selected cookie category "Marketing " under "change cookie settings".

f)    Further information
For more information about Google Remarketing and its privacy policy, please visit: https://policies.google.com/technologies/ads?hl=en
For more information see Google's privacy policy: https://policies.google.com/privacy?hl=en

LinkedIn Insight Tag    
a)    Type and extent of data processing 
We use the conversion tool "LinkedIn Insight Tag" of LinkedIn Ireland Unlimited Company, which is integrated on this website. 

With the help of a cookie, the following data is processed:

•    URL
•    referrer URL
•    IP address
•    device and browser properties (user agent)
•    page activity (e.g. page views)
•    timestampURL

The embedded LinkedIn Insight tag establishes a connection to the LinkedIn server if you visit this website and are logged into your LinkedIn account at the same time. The data collected by the LinkedIn Insight tag is encrypted.

The information generated by the tag about your use of this website may be transmitted to LinkedIn servers outside Switzerland and the EU and stored there.

We would like to point out that the Court of Justice of the European Union (CJEU) has doubts about the adequacy of the level of data protection in the USA. In particular, there is a risk that personal data may be processed by government authorities for control and monitoring purposes, possibly also without any legal remedy.

b)    Purpose of data processing
LinkedIn does not share any personally identifiable information with us, but only provides reports and notifications (in which you are not identified) about website audience and ad performance. LinkedIn also provides retargeting for website visitors, so we can use this data to display targeted ads outside of our website without identifying you as a member.

c)    Legal basis
Under the GDPR, The legal basis for the use of LinkedIn Insight Tag is your consent pursuant to Article 6(1)(a) GDPR.     

Your consent is also consent to data processing in the USA pursuant to Article 17 (1) (a) FADP or Article 49(1)(a) GDPR.

d)    Storage period
Members' direct identifiers are removed within seven days to pseudonymize the data. This remaining pseudonymized data is then deleted within 180 days.

e)    Right of withdrawal
The stored data will be deleted as soon as you withdraw your consent by deselecting the selected cookie category "Marketing" under "Change cookie settings".

LinkedIn members can opt out of the use of their personal data for promotional purposes in their account settings under the section "interactions with companies".

Alternatively, you can give a revocation under this link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out 


8.    Contact options by e-mail     

a)    Type and scope of data processing 
You can contact us by e-mail. Our data collection is limited to the e-mail address of the e-mail account used by you to contact us as well as to the personal data provided by you in the course of contacting us. If you send us an e-mail without encryption, the e-mail is not protected against unauthorized access or modification by third parties during transmission.

b)    Purpose of data processing
The purpose of data processing is to be able to answer your request appropriately. 

c)    Legal basis 
Under the GDPR, the legal basis for this is Article 6(1)(f) GDPR. There is a legitimate interest in the processing of the above-mentioned personal data in order to be able to process your request appropriately, e.g. to answer your inquiry or to fulfil your request for information.

d)    Storage period    
The duration of the storage of the above-mentioned data depends on the background of your contact. Your personal data will be deleted on a regular basis if the intended purpose of the communication ceases to apply and storage is no longer necessary. This may result, for example, from processing your request.


9.    Register your Interest

a) Type and scope of data processing
On our website we offer you to register your interest to be informed by us about the availability of the Wisper App.

To receive a personalised notification if and when the Wisper App is available, we need to process the following personal data: 
•    First name
•    Last name 
•    Business Email address

All other data that you may provide when registering your interest are voluntary and not required.

To activate the registration of your interest in a notification about the availability of the Wisper App, we use the so-called “double opt-in procedure”, in which we will send you an email to the email address you provided with a request to confirm your consent. This ensures that the access was requested by you and not by a third party.

b) Purpose of data processing
The purpose of the data processing is processing of data regarding the registration of your interest and sending you a personalised notification if and when the Wisper App is available.

c) Legal basis
Under the GDPR, the legal basis for this processing is Article 6(1)(b) GDPR, the processing of the data serves the fulfilment of a contract or the implementation of pre-contractual measures. If the data is not required for the performance of the contract and you enter the data voluntarily, the legal basis is your consent voluntarily submitted by you and revocable at any time in the future in accordance with Article 6(1)(a) GDPR and – if German law applies – Section 7(2)(3) UWG (German law against unfair competition). In addition, we process your personal data to document your consent (Article 6(1)(c) GDPR).

d) Storage period
If you do not confirm the registration of your interest in a notification about the availability of the Wisper App by using the link in the email we send to you, your personal data will be deleted promptly. 

If you have successfully registered for the notification, the stored data will be deleted as soon as it is no longer necessary for the purpose of its processing.

e) Right of withdrawal
Under the GDPR, if the legal basis is your consent, you can withdraw your consent at any time with effect for the future towards us, e.g. by sending an email to our contact information.

10.    Newsletter 


a)    Type and scope of data processing 
Our website may offer the possibility to subscribe to a free regular e-mail newsletter. In order to send you the newsletter regularly, we need your e-mail address. Beyond this, your data will not be passed on to third parties. For the newsletter distribution, we use the so-called double opt-in procedure. This means that we will only send you an e-mail newsletter if you have explicitly confirmed your consent to the dispatch of the newsletter. We will then send you a confirmation e-mail asking you to click on a link to confirm that you wish to receive newsletters from us in the future. This is to ensure that only you yourself, as the owner of the e-mail address provided, can subscribe to the newsletter. Your confirmation must take place promptly after receipt of the confirmation e-mail, otherwise your newsletter registration will be automatically deleted from our database. When you subscribe to the newsletter, we collect and store the data you enter in the input mask (e.g. last name, first name, e-mail address). 

When you register for the newsletter, we may save your IP address entered by your Internet Service Provider (ISP) as well as the date and time of registration, in order to be able to trace possible misuse of your e-mail address at a later time. In the confirmation mail sent for control purposes (double opt in the e-mail) we may also save the date and time of the click on the confirmation link and the IP address entered by the Internet Service Provider (ISP). 

Furthermore, the success of the newsletter is measured. If you open our e-mail newsletters, click on the links contained in them, send a web page form after clicking on a link, you retrieve images in e-mail newsletters, we may track this and save this information. In addition, we may determine the type of end device used and, by assigning your IP address, from which location the retrieval took place.

b)    Purpose of data processing
The data collected by us when registering for the newsletter will be used exclusively for the following purposes. By subscribing, you agree that we may send you information about our products and services limited to the topics artificial intelligence, processing of classical signals by quantum information methods, quantum random number generator, quantum cryptography, software and hardware development, quantum computing, by e-mail to your business email you have provided us.

c)    Legal basis 
Under the GDPR, the processing of your e-mail address for the newsletter dispatch is based on the declaration of consent voluntarily submitted by you in the following and revocable at any time in the future in accordance with Article 6(1)(a) GDPR and – if German law applies – Section 7(2)(3) UWG (German law against unfair competition). In addition, we process your personal data to document your consent (Article 6(1)(c) GDPR).

d)    Storage period
Your e-mail address will be stored as long as you have subscribed to the newsletter. After you have unsubscribed from the newsletter, your e-mail address will be deleted, unless you have explicitly consented to further use of your data.

11.    Categories of recipients of the personal data


Under the GDPR, we only pass on your personal data to third parties if:

a)     you have given your explicit consent to do so in accordance with Article 6(1)(a) GDPR.
b)     this is legally permissible and, in accordance with Article 6(1)(b) GDPR, is necessary for the fulfilment of a contractual relationship with you or the implementation of pre-contractual measures.
c)     there is a legal obligation under Article 6(1)(c) GDPR for the transfer.
We are legally obliged to transfer data to state authorities, e.g. tax authorities and law enforcement agencies.
d)     the disclosure in accordance with Article 6(1)(f) GDPR is necessary to safeguard legitimate corporate interests and to assert, exercise or defend legal claims, and there is no reason to assume that you have an overriding interest worthy of protection in the non-disclosure of your data.

We use external service providers (so-called processors) to process personal data in accordance with Article 9 FADP or Article 28(3) GDPR. These processors have been carefully selected by us and are obliged by a data processing agreement to handle personal data in accordance with data protection regulations. 

We use such external service providers in the following areas: 

•    IT service providers
•    Marketing
•    Support

FADP:
When transferring personal data abroad, we ensure that personal data is treated with the same care. We only transfer personal data abroad if the legislation of the State concerned or the international body guarantees an adequate level of protection. In the absence of a decision by the Federal Council we disclose personal data abroad only if an adequate level of data protection is guaranteed by a treaty under international law, data protection clauses in an agreement between the controller or the processor and its contractual partner, notice of which has been given to the FDPIC beforehand; specific guarantees drawn up by the competent federal body, notice of which has been given to the FDPIC beforehand, standard data protection clauses that the FDPIC has approved, issued or recognised beforehand; or binding corporate rules that have been approved in advance by the FDPIC or by the authority responsible for data protection in a State that guarantees an adequate level of protection.

GDPR:
When transferring personal data to so-called third countries, i.e. outside the EU or EEA, we ensure that your personal data is treated with the same care as within the EU or EEA. We only transfer personal data to third countries where the EU Commission has confirmed an adequate level of data protection or where we have ensured the careful handling of personal data by contractual agreements or other suitable guarantees.


 

12.    Data security and security measures


We are committed to protecting your privacy and treating your personal data confidentially. For this purpose, we take extensive technical and organisational security precautions, which are regularly checked and adapted to technological progress.

These include the use of recognised encryption procedures (SSL or TLS). Unencrypted data, e.g. when sent by unencrypted email, may be read by third parties. We have no influence on this. It is the responsibility of the respective user to protect the data provided by him/her against misuse by means of encryption or in any other way.


13.    Your rights (as a data subject)

Here you will find your rights regarding your personal data. Details of this are set out in Chapter 4 and 5 of the FADP or Articles 7, 15-22 and 77 of the GDPR, as applicable. You can contact the controller (Section 2) or representative (Section 3) in this regard.

a) Under the FADP you have the following rights:

aa) Right to information according to Article 25 FADP

You have the right to request confirmation as to whether we process personal data relating to you. If this is the case, you have the right to be informed about your personal data and to receive further information, e.g. identity and the contact details of the controller; the processed personal data, the purpose of processing; the retention period for the personal data, the available information about the source of the personal data, recipients or the categories of recipients to which personal data is disclosed. We may refuse to provide information, or restrict or delay the provision of information according to Article 26, 27 FADP

bb) Right to data portability according to Article 28 FADP

You have the right to request the controller to deliver the personal data that they have disclosed to it in a conventional electronic format.

The controller may refuse, restrict or delay the delivery or transfer of personal data for the reasons set out in Article 26 paragraphs 1 and 2 according to Article 29. The controller must give reasons why it has decided to refuse, restrict or delay the delivery or transfer.

cc) Right to correction according to Article 32 (1) FADP

You have the right to request that incorrect personal data be corrected unless: a statutory provision prohibits the correction or the personal data are processed for archiving purposes that are in the public interest.

b) Under the GDPR you have the following rights:

aa) Right to withdraw your data protection consent in accordance with Article 7(3) GDPR

You can withdraw your consent to the processing of your personal data at any time with effect for the future. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

bb) Right of access according to Article 15 GDPR 

You have the right to request confirmation as to whether we process personal data concerning you. If this is the case, you have the right to be informed about your personal data and to receive further information, e.g. the purposes of processing, the categories of personal data processed, the recipients and the planned duration of storage or the criteria for determining the duration.

cc) Right to rectification and completion under Article 16 GDPR

You have the right to demand the correction of incorrect data without delay. Taking into account the purposes of the processing, you have the right to request the completion of incomplete data.

dd) Right to erasure („right to be forgotten“) in accordance with Article 17 GDPR

You have the right of erasure, as far as the processing is not necessary.
This is the case, for example, if your data is no longer necessary for the original purposes, if you have withdrawn your declaration of consent under data protection law or if the data was processed unlawfully.

ee) Right to restriction of processing in accordance with Article 18 GDPR

You have the right to limit the processing, for example if you believe that personal data is incorrect.

ff) Right to data portability according to Article 20 GDPR

You have the right to receive personal data concerning you in a structured, common and machine-readable format.

gg) Right to object according to Article 21 GDPR

You have the right to object at any time for reasons arising from your particular situation to the processing of certain personal data concerning you.
In the case of direct marketing, you, as the data subject, have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing, including profiling, insofar as it relates to such direct marketing.

hh) Automated individual decision-making, including profiling in accordance with Article 22 GDPR

You have the right not to be subject to a decision based solely on automated processing, including profiling, except in the exceptional circumstances referred to in Article 22 GDPR.
You will not be subject to a decision based solely on automated processing of your data, including profiling (Article 13 (2) (f) GDPR, Articles 22 (1) to (4) GDPR, Article 4 (4) GDPR, Articles 22 (1) to (4) GDPR), which would have legal effect on you or would have a similarly significant adverse effect on you.

ii) Right to lodge a complaint with a data protection supervisory authority according to Article 77 GDPR

You can also lodge a complaint with a data protection supervisory authority at any time, for example if you believe that data processing is not in compliance with data protection regulations.


14.    Changes to this privacy policy

Our privacy policy serves the fulfilment of legal information duties. We update our data protection declaration as far as this becomes necessary.

III. Our privacy policy (data protection policy) under the CCPA


Pursuant to California law, we are providing additional information to California residents. Please read this information together with our Privacy Policy under Section II.

Under California law, certain organizations need to disclose whether the following categories of “personal information” are collected or disclosed for an organization’s “business purpose” as those terms are defined under California law. 

Below please find the categories of personal information about California residents that we collect or disclose to third parties or service providers. 

Note that while a category may be included below that does not necessarily mean that we have or collect information in that category about you. The personal information we collect depends on the nature of our interaction with you and the Services you may use. 

We do not sell personal information. 

Category of personal information collected Categories of third parties to whom we disclose personal information for a business purpose
Identifiers such as a real name, alias, postal address, unique personal identifier, online identifier, internet protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers
  • Our affiliates or subsidiaries
  • Our service providers
  • Product and service fulfillment companies
  • Subscribing, accrediting or professional organizations
  • Government authorities and regulators
Characteristics of protected classifications under California or federal law
  • Our affiliates or subsidiaries
  • Our service providers
  • Government authorities and regulators
Commercial information, including products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
  • Our affiliates or subsidiaries
  • Our service providers
  • Product and service fulfillment companies
  • Subscribing, accrediting or professional organizations
Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumer’s interaction with an Internet website, application, or advertisement
  • Our affiliates or subsidiaries
  • Our service providers
  • Product and service fulfillment companies
  • Subscribing, accrediting or professional organizations
Electronic information
  • Our affiliates or subsidiaries
  • Our service providers
  • Product and service fulfillment companies
  • Subscribing, accrediting or professional organizations
  • Government authorities and regulators
Professional or employment-related information
  • Our affiliates or subsidiaries
  • Our service providers
  • Product and service fulfillment companies
  • Subscribing, accrediting or professional organizations

We and our third-party service providers collect personal information from the following sources: 

•    Direct interactions, such as, when you register for our Services or make a purchase
•    Data from third parties, such as, information on third-party websites or other information you may have made publicly available or information provided by third party sources, including but not limited to government entities and data resellers
•    Automated tracking technologies, such as, information automatically collected about your interaction with our Services and websites using various technologies such as cookies, web logs and beacons and internet tags
•    Depending on how you interact with us and our Services, we may use and disclose personal information for the following business purposes:
•    Auditing
•    Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity,
•    Detecting and repairing errors,
•    Performing services on behalf of other businesses,
•    Processing or fulfilling orders and transactions,
•    Providing advertising or marketing,
•    Conducting internal research for product and service development, and
•    Improving, upgrading, and enhancing our services.
•    In addition to sharing personal information for the business purposes identified within the California Consumer Privacy Act, we also share personal information as needed, or required, with the following additional third parties:
•    organizations involved in business transfers, e.g. to a purchaser or successor entity in the event of a sale or any other corporate transaction involving some or all of our business;
•    other parties, e.g. as needed for external audit, compliance, risk management, corporate development and/or corporate governance related matters,
•    business partners as directed by an individual, or as needed to process an individual’s request; and
•    governmental authorities and regulators, as required under applicable law.

Exercising Rights to Request Access and Request Deletion 

Subject to certain exceptions, California residents have the right to request access, deletion and portability of their personal information. This includes 

•    the right to know about the personal information a business collects about them and how it is used and shared;
•    the right to delete personal information collected from them;
•    the right to opt-out of the sale of their personal information; and
•    the right to non-discrimination for exercising their CCPA rights.

For further rights, we refer to our privacy policy under Section II.

If you would like to submit a request or have additional questions about the personal information that we have about you, please contact us at privacy@wisperapp.com

When you submit your request, we will take steps to attempt to verify your identity. We will seek to match the information in your request to the personal information we maintain about you. As part of our verification process, we may ask you to submit additional information, use identity verification services to assist us, or if you have set up an account on our website, we may ask you to sign in to your account as part of our identity verification process. Please understand that, depending on the type of request you submit, to protect the privacy and security of your personal information, we will only complete your request when we are satisfied that we have verified your identity to a reasonable degree of certainty. 

We do not discriminate against individuals who exercise their rights under applicable law. 

If we receive a request from an authorized agent, we have the right to verify with the data subject that the data subject indeed wants to take the action requested by the agent and will do so by contacting the data subject directly.