Skip to main content

Privacy Policy

How Grünig-SignTronic AG protects and processes personal data for its screen-making solutions.

1. Introduction

Grünig-SignTronic AG (“Grünig-SignTronic”, “we”, “us”) develops and supplies screen-making systems and related services to industrial customers worldwide. This Privacy Policy explains how we process personal data when you visit our website, interact with us digitally or offline, or collaborate with us as a customer, supplier, or partner. We comply with the Swiss Federal Act on Data Protection (revFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

The policy applies to the domain https://www.grunig-signtronic.com and any associated microsites or online services managed by us.

2. Controller and contact

The controller responsible for data processing is:

Grünig-SignTronic AG
Ringgenmatt 14
CH-3150 Schwarzenburg
Switzerland

Grünig-SignTronic AG
Rossrütistrasse 4
CH-9464 Rüthi SG
Switzerland

For general and privacy-related enquiries, please use our contact page.

We have not designated a representative in the EU or the United Kingdom. Our offerings are directed exclusively at businesses (B2B); where the GDPR applies in an individual case, you can reach us directly for all data protection matters using the contact details above.

We process personal data to the extent necessary for:

  • fulfilling contracts and precontractual measures (Art. 6(1)(b) GDPR; Art. 31(2)(a) revFADP),
  • complying with legal obligations (Art. 6(1)(c) GDPR; Art. 31(1) revFADP),
  • safeguarding legitimate interests, such as ensuring secure operation of our infrastructure, improving our offerings, and maintaining business relationships (Art. 6(1)(f) GDPR; Art. 31(1) revFADP),
  • obtaining consent for specific purposes such as optional cookies or marketing communications (Art. 6(1)(a) GDPR; Art. 31(1) revFADP).

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR; Art. 21 revFADP).

If you provide us with personal data of third parties, you must ensure that the data is accurate and that the individuals are informed of this policy.

4. Categories of data and purposes

4.1 Visiting our websites

When you access our websites, our hosting provider automatically stores technical information (server log files), including IP address, date and time of access, URL accessed, referrer URL, browser type and version, and operating system. We process this data to ensure network security, detect faults, and compile anonymised usage statistics. Log files are retained only for as long as necessary for these purposes, at most for twelve months, unless a longer period is required to analyse security incidents.

4.2 Contact and service communication

When you contact us by phone, email, contact form, or at trade fairs, we process your contact details, company affiliation, and the contents of your message in order to respond to your request, provide quotations, or support services. We retain this data as long as it is necessary to handle your enquiry and in accordance with statutory retention duties.

4.3 Contract and supplier management

For customer orders, projects, and supplier relationships we process master data (e.g., name, position, business contact details), contract-related information, delivery and payment data, as well as correspondence. Processing is required to perform our contracts, manage warranties, maintain quality records, and comply with accounting and export regulations. Documentation is stored at least for the duration of the business relationship and in line with the retention obligations under Swiss law (typically ten years).

4.4 Careers and job applications

If you apply for a position or a trial apprenticeship, we process the data you provide (e.g., CV, certificates, references, interview notes, and form entries submitted via protected application forms). Applicants’ data is stored exclusively for recruitment purposes and is deleted or anonymised after six months unless you consent to a longer retention or statutory obligations require longer storage. If employment commences, the application data becomes part of the personnel file.

4.5 Events, trainings, and webinars

When you register for trainings, demonstrations, or webinars, we collect participants’ details and preferences to organise the event and send related information. Attendance records may be retained for follow-up support, documentation of safety instructions, or proof of participation.

We use technically necessary storage mechanisms to operate our website. Depending on the function, these may be cookies or local browser storage.

This includes, in particular:

  • a temporary session cookie for security checks on protected quote and application forms (max. 30 minutes),
  • local browser storage for privacy settings, theme selection, and dismissed non-essential notices.

Optional external content (for example hosted videos or Microsoft Forms) is loaded only after your consent. We store this choice locally in your browser so that we do not need to ask again on each page. You can revise this setting at any time via the privacy settings control on the website.

We evaluate aggregated, anonymised usage trends using server-side logs and Umami Analytics, a privacy-friendly, cookie-less web analytics solution (for more information about the software, refer to Umami). We operate Umami as a self-hosted instance on infrastructure under our control; no analytics data is transmitted to the software vendor or any other third party. Umami does not set any cookies, does not permanently store any personal data, and does not track you across other websites; IP addresses are processed only transiently to associate a session (truncated or as a daily-rotating hash) and are not stored. Umami also honors your browser’s Do Not Track (DNT) signal by default; if you explicitly consent to analytics (see below), your consent takes precedence over the DNT heuristic. Cloudflare, our hosting and security provider, may set strictly necessary cookies for security, performance optimization, and load balancing.

For session replays and heatmaps (page-overlay analysis) we additionally use the Umami recorder to understand how visitors interact with our pages, such as clicks, scroll depth, and cursor movement. Because this feature reads information from your device, we load it only after your explicit consent (Art. 6(1)(a) GDPR; Art. 31 revFADP); without your consent the recorder is not loaded. Recording is cookieless and inputs into form fields are masked by default. We store your consent locally in your browser; you can withdraw it at any time via the privacy settings on the website with effect for the future.

To provide selected online functionality and links to our external presences, we use services from the following providers. Depending on the service, providers receive at least your IP address and technically required metadata.

The legal basis depends on the function involved:

  • your consent for externally hosted videos and Microsoft Forms loaded on our pages (Art. 6(1)(a) GDPR),
  • our legitimate interests for security protections and external links to corporate profiles or route planners (Art. 6(1)(f) GDPR).

Hosted videos and forms are loaded only after you activate them on the respective page or enable external content via our privacy settings. External platforms such as social networks, GitHub, or Google Maps are only contacted when you click the corresponding link.

Because these providers are responsible for their own data processing, please consult their policies for additional information.

7. Social media and external platform presences

We maintain company presences on LinkedIn, YouTube, Vimeo, Facebook, Instagram, and GitHub. When you visit these pages or repositories, the respective platform processes your data under its own terms of use and privacy notices. We may receive aggregated statistics (insights) and may respond to your interactions there (e.g., comments, messages, or issue reports). If you no longer wish us to process data that you made public on our presences, please delete the relevant content or contact us.

8. Recipients and international transfers

We only disclose personal data to third parties if necessary for the purposes outlined above, if you have consented, or if we are obliged by law. Typical recipients include:

  • hosting, CRM, ERP, and ticketing service providers (Switzerland, EU/EEA, USA),
  • logistics and installation partners,
  • banks, insurance companies, auditors, and legal advisors,
  • authorities and courts where legally required.

We host this website on Cloudflare’s global infrastructure (Cloudflare, Inc., USA) via Cloudflare Workers. Cloudflare operates data centres worldwide, including within the EU/EEA and Switzerland, with intelligent routing to serve content from the nearest location. Cloudflare is certified under the Swiss–U.S. Data Privacy Framework and additionally implements Standard Contractual Clauses and further safeguards for international transfers. Cloudflare may process technical data such as IP addresses, request metadata, and security-relevant information to provide CDN services, DDoS protection, and performance optimization. For details, see Cloudflare’s privacy policy: https://www.cloudflare.com/privacypolicy/.

For transfers to the USA we primarily rely on the Swiss–U.S. Data Privacy Framework (DPF): the Swiss Federal Council recognised the USA as providing an adequate level of data protection for DPF-certified companies with effect from 15 September 2024. The US providers we use (Cloudflare, Microsoft, Google, Vimeo) are certified under the Swiss–U.S. DPF. Where data is transferred to other countries without an adequate level of protection or to non-certified recipients, we rely on recognised safeguards such as Standard Contractual Clauses, binding corporate rules, or your explicit consent.

9. Data retention

We process personal data only for as long as necessary to fulfil the respective purpose or statutory retention requirements. Business correspondence and contractual documents are generally retained for ten years under Swiss commercial and tax law. Technical logs are stored for up to twelve months unless security investigations require longer retention. After expiry of the relevant periods, data is deleted or anonymised.

10. Security

We implement state-of-the-art organisational and technical measures to protect personal data against unauthorised access, loss, or misuse. Measures include TLS-encrypted data transmission, access management, role-based authorisations, multi-factor authentication for critical systems, regular backups, and employee awareness programmes. Nevertheless, no internet-based transmission is entirely secure; please use suitably protected channels for highly confidential information.

11. Your rights

Subject to applicable law, you have the following rights:

  • access to your personal data and request a copy;
  • rectification of inaccurate or incomplete data;
  • erasure (“right to be forgotten”) where legal grounds apply;
  • restriction of processing;
  • data portability for data you provided to us in a structured format;
  • objection to processing based on legitimate interests, including direct marketing;
  • withdrawal of consent at any time with effect for the future.

Please submit your request through our contact page. We may require proof of identity to process your request.

12. Right to lodge a complaint

If you believe that our processing infringes data-protection law, you may contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where the GDPR applies, the supervisory authority at your habitual residence or place of work.

Swiss FDPIC
Feldeggweg 1
CH-3003 Bern
https://www.edoeb.admin.ch

13. Updates to this policy

We may amend this Privacy Policy to reflect changes in our processing activities or legal requirements. The version published on our websites applies; the date of the last update is shown at the top of this page.