Privacy Policy
Effective date: 10.2024
A. Introduction
At Yarowa we take the protection of your personal data very seriously. This privacy policy informs you about what personal data we collect when you visit our website and services, how we use it, and what rights you have regarding your data.
Please note that by accessing or using our website, we will apply these principles. If you do not agree with this Privacy Policy, please do not access or use our website. Also, we may update this Privacy Policy from time to time. The revised policy will be posted on this page with an updated "Effective Date." We encourage you to review this Privacy Policy periodically to stay informed of any changes.
B. Responsible office and contact
The following Yarowa companies (also referred to as "Yarowa" or "we"/"us" in this Privacy Policy) are responsible for data processing.
Business activities in Switzerland
Yarowa AG, Metallstrasse 9, 6300 Zug
Smart Step AG, Metallstrasse 9, 6300 Zug
Business activities in Germany
Yarowa GmbH, Sonnenstrasse 32, 80331 München
Business activities in United Kingdom
Yarowa Ltd., Fox Court, 14 Gray's Inn Road, London, WC1X 8HN
Business activities in Italy
Yarowa Srl, Via Genova Thaon di Revel, 20159 Milano
E-Mail privacy@yarowa.com
Contact details of the Data Protection Officer:
Swiss Infosec AG, Meienriesliweg 15, 6210 Sursee
C. How we process personal data
All personal data collected through the website or otherwise by us will be processed in accordance with the provisions of applicable data protection laws. We collect and process personal data carefully and for the purposes described in this privacy policy. In accordance with applicable law, we may also use your personal data in ways other than those described in this privacy policy. In such cases, we will provide specific privacy statements or notices at the time of collection and, if necessary, obtain your consent.
D. Scope and purpose of the collection, processing and use of personal data
1. Use of our website
Each visit to our website or our subdomains is stored on our server. For this purpose, we use the commonly known internet technology called 'cookies'. The following data is collected without your intervention and stored by us until it is automatically deleted:
- the IP address of the requesting computer,
- the name of your internet service provider (usually your internet access provider),
- the date and time of access,
- the name and URL of the retrieved file,
- the website from which our URL was accessed and, if applicable, the search term used,
- the country from which the access to our website occurs,
- the operating system of your computer and the browser you use (provider, version, and language), and
- the transmission protocol used (e.g., HTTP/1.1).
We process these personal data for the described purposes based on the following legal bases:
- Safeguarding of legitimate interests based on Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR (e.g. for administrative purposes, to improve our quality, analyse data or publicise our services).
- Consent based on Art. 31 para. 1 FADP, Art. 6 para. 1 lit. a GDPR and UK GDPR
2. When we communicate with you, or you visit us
If you contact us (e.g. via telephone, e-mail or chat) or if we contact you, we process the personal data required for this purpose. We also process these personal data when you visit one of our offices. In this case, you may be required to leave your contact information prior to your visit or at the reception desk. We retain these data for a restricted time to protect our infrastructure and information.
We process the following information in particular:
- Contact information (e.g. last name, first name, address, telephone number and e-mail address)
- Marginal data for communication (e.g. IP address, duration of communication, and communication channel).
- Recordings of conversations, e.g. during video conferences
- Personal information (e.g. occupation, function, title and employer)
- Time and reason for the visit.
We process these personal data for the described purposes based on the following legal bases:
- Fulfilment of a contractual obligation with or for the benefit of the data subject, including contract initiation and possible enforcement based on Art. 31 para. 2 lit. b FADP, Art. 6 para. 1 lit. b GDPR and UK GDPR (provision of a service)
- Safeguarding of legitimate interests based on Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR (e.g. security, traceability, and processing and administration of customer relationships).
- Consent based on Art. 31 para. 1 FADP, Art. 6 para. 1 lit. a GDPR and UK GDPR (e.g. to the recording of conversations).
3. When you use our service
From our customers we collect the personal data that we need to provide our contractually agreed service, to protect our interests, or on the basis of a legal or other binding regulation. When we fulfil a contract with you, we collect other personal data depending on the service involved and whether you are a natural person or a legal entity.
The personal data of our customers consist of the following pieces of information in particular:
- Contact information (e.g. last name, first name, address, telephone number, e-mail address and other contact information)
- Personal information (e.g. date of birth, nationality, marital status, occupation, title, job title, passport/ID number, AHV number, family circumstances, etc.)
- Risk management data (e.g. credit rating information, commercial register data, sanctions lists, specialised databases, data from BDO's network or the Internet)
- Financial information (e.g. data on bank details, investments and shareholdings)
- Mandate data, depending on the mandate, e.g. tax information, business data (statutes, minutes and projects), employee data (e.g. salary and social security), accounting data, etc.
- Sensitive personal data: these personal data may also include sensitive personal data such as data relating to health, religious beliefs and social assistance measures, in particular if we provide payroll processing or accounting services.
- Marketing information (e.g. use of website or subscription to a newsletter).
We process these personal data for the described purposes based on the following legal bases:
- Conclusion or execution of a contract with the data subject or for the benefit of the data subject, including contract initiation and possible enforcement based on Art. 31 para. 2 lit. b FADP, Art. 6 para. 1 lit. b GDPR and UK GDPR (e.g. consulting, and fiduciary),
- Fulfilment of a legal obligation based on Art. 6 para. 1 lit. c GDPR and UK GDPR (e.g. when we perform our duties as auditors or are required to disclose information).
- Safeguarding of legitimate interests based on Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR (e.g. for administrative purposes, to improve our quality, ensure safety, manage risk, enforce our rights, defend against claims, and review potential conflicts of interest).
- Consent based on Art. 31 para. 1 FADP, Art. 6 para. 1 lit. a GDPR and UK GDPR (e.g. to allow the use of cookies)
4. If we do not receive information directly from our customers
When we provide services to our customers, we may also process personal data that we have not collected directly from the data subjects or other persons' personal data. These other persons are usually employees, contacts, family members or persons who have a relationship with the customers or data subjects for other reasons. We need these personal data to fulfil the contracts with our customers. We receive these personal data from our customers or from third parties contracted by our customers. Persons whose information we process for this purpose are informed by our customers that we are processing their data. Our customers can refer to this privacy policy for this purpose.
The personal data of the persons who have a relationship with our customers consist of the following information in particular:
- Contact information (e.g. last name, first name, address, telephone number, e-mail address, other contact information, and marketing data)
- Personal information (e.g. date of birth, nationality, marital status, occupation, title, job title, passport/ID number, AHV number, family circumstances, etc.)
- Financial information (e.g. data on bank details, investments and shareholdings)
- Mandate data, depending on the mandate, e.g. tax information, business data (statutes, minutes and projects), employee data (e.g. salary and social security), accounting data
- Sensitive personal data: these personal data may also include sensitive personal data such as data relating to health, religious beliefs and social assistance measures, in particular if we provide payroll processing or accounting services.
We process these personal data for the described purposes based on the following legal bases:
- Conclusion or execution of a contract with the data subject or for the benefit of the data subject based on Art. 31 para. 2 lit. b FADP, Art. 6 para. 1 lit. b GDPR and UK GDPR (e.g. when we perform our contractual obligations)
- Fulfilment of a legal obligation based on Art. 6 para. 1 lit. c GDPR and UK GDPR (e.g. when we perform our duties as auditors or are required to disclose information).
5. When you attend a Yarowa event
When you attend an event organised by us, we collect personal data to organise and conduct the event and, if necessary, to send you additional information afterwards. You may be photographed or filmed by us at these events, and we may publish this footage internally or externally.
This consists of the following information in particular:
- Contact information (e.g. last name, first name, address, telephone number and e-mail address)
- Personal information (e.g. occupation, function, title, employer company and dietary information)
- Pictures or videos
We process these personal data for the described purposes based on the following legal bases:
- Fulfilment of a contractual obligation with or for the benefit of the data subject, including contract initiation and possible enforcement Art. 31 para. 2 lit. b FADP, Art. 6 para. 1 lit. b GDPR and UK GDPR (making participation in the event possible)
- Safeguarding of legitimate interests based on Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR (e.g. holding events, disseminating information about our event, providing services, and efficient organisation).
- Consent based on Art. 31 para. 1 FADP, Art. 6 para. 1 lit. a GDPR and UK GDPR (e.g. to send you marketing information or to create visual materials).
6. When you apply to Yarowa
We collect and generate personal data that you actively and voluntarily provide to us with your consent and/or in anticipation of a possible employment contract with us by sending your application documents via our contact email address, by phone, or in another way. This may include the following personal data:
- Personal data that you provide to us as part of the application process, such as salutation, name, first name, address, email address, phone number, date of birth, social security number, marital status, photo, language, CV, qualifications, work references, educational qualifications, training, further education, experience, your skills and abilities, criminal record extract (only if explicitly requested), additional information about you;
- Personal data that we have collected during our interview and assessment process;
- Publicly accessible professional personal data about you that is published on business and employment-related social networks (e.g., LinkedIn or XING).
We process this data for the purpose of recruiting employees. The processing of personal data is based on Art. 31 para 2 lit. a FADP, Art. 6 para. 1 lit. b GDPR and UK GDPR. If no employment is established, we will delete your data no later than 6 months after the process. You can object to this data processing at any time and withdraw your application. Please send your objection to: hr-internal@yarowa.com.
7. When we use Microsoft Teams
We use "Teams" to conduct online meetings. Teams is a software provided by Microsoft Ireland Operations Limited, South County Business Park, Leopardstown, Dublin 18, Ireland ("Microsoft").
The legal basis for processing data to conduct meetings via Teams is our legitimate interest in effectively and easily conducting online meetings, discussions, and presentations (Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR). Additionally, we process this data on a contractual basis, insofar as the meetings take place within the framework of existing contractual relationships with you. We are not responsible for further data processing on the Teams product website, where the desktop software can be downloaded and the web app can be used.
During a meeting, participant data (e.g., display name, first name, last name, phone number), metadata (e.g., meeting topic and description, IP address, time of the participant's last activity on Teams), chat or channel messages, microphone and video recording data, and phone usage may be processed. You can disable the transmission via microphone and camera at any time through the respective settings. We record meetings or log text data only with your consent and prior notification. Microsoft stores and uses the metadata to analyse and evaluate the use of Teams.
Microsoft may become aware of the aforementioned data as part of its contract with us. For more information, please refer to Microsoft's privacy policy at privacy.microsoft.com.
8. When you provide a contractual service in another capacity (e.g. suppliers, service providers, and other contractual partners)
When we enter into a contract with you to provide a service to us, we process personal data from you or your employees. We need these data to communicate with you and to make use of your services. We may also process these personal data to check whether there could be a conflict of interest in connection with our work as auditors and to ensure that we do not take any undesirable risks, e.g. with regard to money laundering or sanctions, through our cooperation.
We process the following information in particular:
- Contact information (e.g. last name, first name, address, telephone number and e-mail address)
- Personal information (e.g. occupation, function, title and employer company)
- Financial information (e.g. data on bank details).
We process these personal data for the described purposes based on the following legal bases:
- Conclusion or execution of a contract with the data subject or for the benefit of the data subject, including contract initiation and possible enforcement based on Art. 31 para. 2 lit. b FADP, Art. 6 para. 1 lit. b GDPR and UK GDPR
- Safeguarding of legitimate interests based on Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR (e.g. avoiding conflicts of interest, protecting the company and enforcing legal claims).
9. HubSpot CRM Marketing Supplement
We use HubSpot's CRM system to manage our customer and contact data. The provider is HubSpot Germany GmbH, based in Germany, which cooperates with other HubSpot-affiliated companies ("Affiliates") in the provision of the services, in particular with HubSpot, Inc. based in the USA ("HubSpot").
In the context of CRM use, HubSpot processes contact and identification data in particular (e.g. name, e-mail address, telephone number) as well as communication and interaction data (e.g. correspondence, conversation notes, inquiries). The processing is carried out to manage and maintain our business relationships and is based on our legitimate interests in efficient and structured customer and contact management.
To protect your personal data, we have a Data Processing Agreement which contains provisions on data security, the use of sub-processors and international data transfers.
The processed data will be stored and processed in a hosting region within the European Union designated by HubSpot for our account. Regardless of the hosting region we choose, HubSpot may transfer personal data to other countries in which HubSpot's affiliates or sub-processors operate. This includes, in particular, transfers to HubSpot, Inc. in the United States.
Such transfers are made in accordance with the applicable data protection requirements, in particular based on the standard contractual clauses approved by the European Commission. In addition, HubSpot, Inc. is listed under the EU-U.S. and Swiss-U.S. Data Privacy Framework.
For more information on data protection and data security at HubSpot, please refer to HubSpot's legal documents and HubSpot's Trust Centre.
Email marketing and newsletters are sent with HubSpot's email marketing features. Contact data (e.g. name, e-mail address) as well as interaction data (e.g. open and click rates) are processed. Marketing emails and newsletters are sent only to recipients who have given their consent. Consent can be withdrawn at any time, in particular by using the unsubscribe link included in each marketing email.
Marketing Automation in HubSpot is used for marketing and communication flows. Contact data as well as behavioural and interaction data are processed in order to trigger automated processes (e.g. sending an e-mail after a form submission). If the dispatch is based on consent, this is considered the legal basis; otherwise, we rely on our legitimate interests in efficient customer communication.
We operate landing pages through HubSpot and provide forms that interested parties can use to contact them or register for offers. The data collected in this context (e.g. name, email address, company details) is stored directly in HubSpot and used to process the respective request and for further contact management. The data processing takes place in the context of the initiation or performance of a contract or, where no contract exists, based on our legitimate interests in the efficient management of contact requests.
Website tracking and analytics may include HubSpot tracking codes. Technical data and behavioural data of website visitors are collected (e.g. pages visited, length of stay, origin of the visit, IP address). This data is used to analyse user behaviour and optimise marketing measures. Tracking is carried out exclusively on the basis of your prior consent via our cookie consent management. No tracking takes place without consent. HubSpot may also use the data collected via the tracking code (in particular IP addresses and other online identifiers) for its own purposes, namely for the maintenance and further development of its commercial dataset. To this extent, HubSpot acts as an independent controller. More details can be found in HubSpot's legal documents and Trust Centre.
HubSpot is integrated with third-party advertising platforms, specifically Google Ads and LinkedIn Ads. CRM data (e.g. e-mail addresses in anonymised form) can be transmitted to these platforms in order to create target groups, control campaigns and measure advertising success. These transfers are made exclusively on the basis of your prior consent. The respective data protection notices of these providers are decisive for data processing by Google and LinkedIn.
E. Use of cookies and similar technologies
We use so-called cookies on our website. Cookies are small text files that are placed and stored on your end device (laptop, tablet, smartphone, etc.) with the help of the browser. They are used to make our website more user-friendly and effective overall and to make your visit to our website as pleasant as possible. If the user visits the website again later, the website can read the data of the previously stored cookie and thus determine, for example, whether the user has visited the website before and which areas of the website the user was particularly interested in. Cookies do not cause any damage to your end device. They cannot execute programmes or contain viruses.
The use of necessary cookies serves to ensure that our website can be displayed correctly from a technical standpoint. The data processed by these cookies is required for the aforementioned purposes to safeguard our legitimate interests as well as those of third parties according to Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR. Our legitimate interest lies in providing a functional and user-friendly website.
In addition, we use cookies to optimize the user-friendliness of our offering and for statistical recording. We use so-called session cookies to recognize that you have already visited individual pages of our website. These cookies are automatically deleted after you leave our site. Furthermore, we use temporary cookies that are stored on your device for a specific predetermined period. If you visit our site again, it will automatically recognize that you have already been with us and what inputs and settings you have made so that you do not have to enter them again.
The legal basis for data processing through cookies for statistical purposes and evaluation of our offering is your consent according to Art. 31 para. 1 FADP, Art. 6 para. 1 lit. a GDPR and UK GDPR. This consent is voluntary and can be revoked by you at any time. If you do not give consent, no cookies will be set for marketing or analysis purposes.
You can also configure your browser so that no cookies are stored on your computer or a notice always appears before a new cookie is created. However, the complete deactivation of cookies may result in you not being able to use all the functions of our website. For more information on the use of cookies, please see our Cookie Policy.
1. Web hosting (Vercel)
Our website is hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA ("Vercel"). When you visit our website, Vercel processes technical connection data (e.g. IP address, date and time of access, browser type and operating system) in server log files to deliver the website reliably and securely. Vercel processes this data on our behalf on the basis of a Data Processing Agreement including the standard contractual clauses approved by the European Commission; Vercel is additionally certified under the EU-U.S. and Swiss-U.S. Data Privacy Framework. The legal basis for this processing is our legitimate interest in providing a secure and performant website according to Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR. Further information can be found in Vercel's privacy policy at vercel.com/legal/privacy-policy.
2. Audience measurement (Umami)
To evaluate how our website is used, we use Umami, an analytics application that we operate on our own instance at umami.yarowa.com. The data collected never leaves our infrastructure and is not passed on to an analytics provider. Umami sets no cookies, stores no information on your device and does not build profiles across websites. It collects the pages viewed, the referring page, browser, operating system, device type and country of origin; the IP address is not stored. Individual visitors cannot be identified. The legal basis is our legitimate interest in a data-minimising evaluation of how our website is used pursuant to Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR.
3. Session recording (Umami)
In addition, we may record individual visits as session replays. This captures mouse movement, clicks, scrolling, page changes and interactions with forms during a single session and stores them as a replay; entries in form fields are masked by default. The recordings serve solely to identify usability problems and errors on our website and are deleted after 30 days. This processing also takes place on our own instance. Unlike plain audience measurement it concerns individual behaviour, and it therefore only takes place with your consent. The legal basis is your consent pursuant to Art. 31 para. 1 FADP, Art. 6 para. 1 lit. a GDPR and UK GDPR, which you can withdraw at any time with effect for the future via the cookie settings in the footer of the site.
4. Sending form enquiries (Brevo)
To send the enquiries submitted through our contact form and our bug report form, we use the Brevo service operated by Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France. The details you enter in the form are transmitted as an email to the relevant contact at our company. Brevo processes this data exclusively on our behalf under a data processing agreement, and the processing takes place within the European Union. We do not additionally store the enquiries in a database on the website. The legal basis is our legitimate interest in responding to your enquiry and, for contract-related enquiries, the performance of pre-contractual measures pursuant to Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR.
5. Cookies and local storage set by us
We ourselves set a single cookie named yarowa_locale. It stores only the language version you selected, so that you do not have to set it again on your next visit, and it expires after one year. In addition, we store your choice in the consent dialogue under the name yarowa-consent in your browser's local storage, so that we do not have to ask you again on every visit. Both entries remain on your device and are not transmitted to us. The legal basis is our legitimate interest in a functioning website pursuant to Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR.
6. Fonts
The typeface used on our website is served from our own servers. No connection is made to Google Fonts or any other external font provider, and no data is transmitted to third parties.
7. Documents for download
Some documents, in particular the PDF files in our handbook and under contract components, are currently still delivered through the content delivery network of Webflow, Inc., 398 11th Street, San Francisco, CA 94103, USA. When you open such a document, your IP address is transmitted to Webflow. This transmission does not take place when you simply visit our website. The legal basis is our legitimate interest in making these documents available pursuant to Art. 31 para. 1 FADP, Art. 6 para. 1 lit. f GDPR and UK GDPR.
F. Links to other websites
Our Service may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the privacy notice of every site you visit. We have no control over and assume no responsibility for the content, privacy notice or practices of any third party sites or services.
G. Children's Privacy
Our Service does not address anyone under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental, judicial or guardian's consent, we take steps to remove that information from our servers.
H. Artificial intelligence (AI)
Artificial intelligence technologies may also be used when we perform our services. We may use these technologies to fulfil our obligations and improve our services, especially for the analysis of data or for programming. Artificial intelligence can also help with communication and content creation. It also helps us to handle our work in a simpler and better way by preparing, summarising or translating documents. We can make decisions more easily with the support of artificial intelligence technologies. Artificial intelligence technologies may also be used to ensure security.
We always use these technologies as an aid. Services are provided by Yarowa employees, and it is Yarowa employees who make decisions. We will also provide as much information as possible about when and how we use artificial intelligence technologies in rendering our services to you. We review, supervise and regularly assess artificial intelligence technologies.
In order to fulfil their purpose, artificial intelligence technologies must process information. This information may include data from our own databases. We will not process any of your personal data using artificial intelligence technologies in cases where this is not necessary. Under certain circumstances, however, your data may be used to train artificial intelligence. However, we will prevent this information from being passed on outside Yarowa.
I. Data sharing
Your personal data will not be shared with third parties unless you have expressly consented, it is necessary to fulfil our services or we are legally obliged to do so. We may share personal data we collect and receive on a need-to-know basis with the following parties:
- Other affiliates of our Group or its agents,
- Third-party providers that perform services for us (we work with service providers at home and abroad who process data about you on our behalf or in joint responsibility with us or receive data about you from us within their own sphere of responsibility. For example, we procure IT services such as hosting, support and maintenance, and testing from service providers. Our service providers are each subject to contractual and/or statutory confidentiality and data protection obligations),
- Competent public authorities or other third parties (if required by law or reasonably necessary to protect the rights, property and safety of ourselves or others).
We may also transfer your personal data in the event that we sell or transfer all or a portion of our business or assets on a need-to-know basis. Should such a sale or transfer occur, we will use reasonable efforts to direct the transferee to use personal data you have provided to us in a manner that is consistent with applicable law and this privacy notice.
J. Cross border transfers
We may transfer personal data we collected to third parties in countries outside of Switzerland and the European Economic Area (EEA). For example, your data may be processed worldwide if personal data is transmitted to other companies within our Group or to our service providers.
Many third countries may not offer an adequate level of data protection. When we transfer your personal data outside of Switzerland or the EEA, we will protect your personal data as described in this privacy notice and in accordance with applicable laws, such as by entering into Standard Contractual Clauses issued or recognized by the European Commission and the Swiss Data Protection and Information Commissioner (FDPIC).
K. Data retention
We process personal data for as long as is necessary for the fulfilment of our contractual obligations or otherwise for the purposes pursued with the processing, for example for the duration of the entire business relationship and beyond in accordance with the statutory retention and documentation obligations. It is possible that personal data may be stored for the period in which claims can be asserted against us and insofar as we are otherwise legally obliged to do so or legitimate interests require this (e.g. for evidence and documentation purposes). As soon as your personal data is no longer required for the above-mentioned purposes, it will generally be deleted or anonymized.
L. Data security
We handle our online platform data securely and take appropriate technical and organizational security measures to protect the confidentiality, integrity and availability of your personal data, to protect it against unauthorized or unlawful processing and to protect it against the risk of loss, accidental alteration, unauthorized disclosure or access. We utilize recognized security standards such as ISO 27001. However, security risks cannot generally be ruled out completely; certain residual risks are unavoidable.
When your data is transmitted via our online platform, we protect it during transmission using suitable encryption mechanisms. However, we can only secure areas that are under our control. If you contact us by e-mail, you do so at your own risk and agree that we may respond to you at the sender's address via the same channel. If you send us e-mails via the Internet in unencrypted form, third parties may be able to access, view and manipulate them, and data can be lost or intercepted and/or manipulated by third parties. Your end device is outside the security area that lies within our control. You are therefore required to learn about the necessary safety precautions and to take appropriate measures in this regard.
M. Your rights
You have various rights in connection with our data processing subject to applicable law:
- the right to request information from us as to whether we are processing your data, and which data we are processing based on Art. 25 FADP, Art. 15 GDPR, Art. 15 UK GDPR
- the right of data rectification (if your data is inaccurate) based on Art. 32 FADP, Art. 16 GDPR, Art. 16 UK GDPR
- the right of erasure (if the retention of your data is no longer necessary in relation to the envisaged purpose of the processing) based on Art. 32 FADP, Art. 17 GDPR, Art. 17 UK GDPR
- the right to object to our processing for specific purposes and to request the restriction or deletion of data unless we are obliged or entitled to continue processing it based on Art. 32 FADP, Art. 18 GDPR, Art. 18 UK GDPR
- the right to revoke consent, provided our processing is based on your consent (the right to withdraw your consent is not retroactive; any processing operations which took place before you revoked your consent will not become illegal on withdrawal) based on Art. 7 para. 3 GDPR, Art. 7 para. 3 UK GDPR
- the right to data portability based on Art. 49 para. 4 FADP, Art. 28 FADP, Art. 20 GDPR, Art. 20 UK GDPR, and
- the right to lodge a complaint with the competent supervisory authority based on Art. 77 GDPR, Art. 77 UK GDPR.
To exercise these rights, please contact us using our contact details set out below. We may request you to provide a copy of your ID card or otherwise evidence of your identity. To the extent legally permissible, in particular to protect the rights and freedoms of other data subjects and to safeguard sensitive interests, we may also reject your request in whole or in part.
We will respond to your request within the applicable statutory term. Please contact us at privacy@yarowa.com or via the address mentioned above.
N. Data protection supervisory authority
If you are of the opinion that Yarowa is not complying with the data protection regulations applicable to you, we recommend that you first contact the responsible Yarowa data protection coordinator (see contact details above or privacy@yarowa.com). However, you can also lodge a complaint directly with the competent data protection supervisory authority.