General Privacy Notice

1. Introduction

At Pexapark (we, our or Pexapark), we recognize the importance of your privacy and of transparency.  

This general privacy notice applies to all our activities, including the digital solutions and platforms accessible at https://pexapark.com/, https://app.pexapark.com, https://platform.pexapark.com, https://quote.pexapark.com, https://quantonline.pexapark.com, https://portfolio.pexapark.com, and https://greenpowertrader.pexapark.com (the Solution), and the services we provide in this context (together with the provision of the Solution, our Services).

We may have additional privacy notices (the Additional Privacy Notices), as specified in section 13 of this General Privacy Notice (Service-Specific Information), which apply in addition or instead of this General Privacy Notice in specific situations or for specific Services, in which case the terms of such Additional Privacy Notices will prevail over those of this General Privacy Notice. 

This Privacy Notice is incorporated into and forms an integral part of our terms of use for the Solution (ToU). All capitalized terms not defined in this document have the meaning given to them in the ToU. 

2. Short Version

The following is a summary of (but not a replacement for) this General Privacy Notice. We recommend all users read Notice fully.   

  • Our role. We, Pexapark, are responsible for the processing, as controller, of your personal data (but only for our own activities and not those of third-party providers) (see section 3);  
  • Data we collect. We collect the information which is provided to us by you or third parties. We also automatically collect some information when you interact with the Services (see section 4); 
  • How we use it. We process your personal data in compliance with Swiss law and other data protection laws applicable to us. This means that we will only process your information where we have a legal basis to do so (see section 5), and only for certain reasons (mainly for providing our Services, operating our Solution, and for the other legitimate purposes indicated in this General Privacy Notice) (see section 6); 
  • Control and Access. Your personal data is stored in Switzerland and/or the European Union. We do not share it with third parties or transfer it abroad unless this is both necessary for the operation of our Services and permitted by applicable laws. This may for instance be the case when we use service providers or must interact with third parties to conduct our professional activities (see sections  7 and 8); 
  • Retention. We do not store your personal data for longer than necessary for us to fulfill the purposes set out in this General Privacy Notice (see section 9); 
  • Security. We apply security measures and strive to protect your personal data. However, no IT infrastructure is completely secure, and we cannot guarantee that ours is (see section 10); 
  • Your rights. You may contact us (dpo@pexapark.com) to exercise your rights pertaining to your personal data (see section 12 and 15).

3. Who is responsible for the processing of your personal data

Pexapark AG, Wiesenstrasse 5, 8952 Schlieren, Switzerland, is responsible for the processing, as controller, of your personal data. You will find our contact details in section 15 below.  

However, some of the processing activities set out in this General Privacy Notice are undertaken by our group entities, which will then act as data controller. The exact split differs between group entities and over time. We can confirm which processing activities are undertaken by which entity, on request. 

This General Privacy Notice only applies to data processing undertaken by or on behalf of us. Whilst we may provide links to third party websites, contents, or services, we are not responsible for their policies in relation to personal data. In such circumstances, the collection and use of your personal data are governed by the privacy policy of those third-party providers, which you should carefully review to learn more about their personal data processing practices.  

4. How we collect your personal data

We collect the personal data you provide to us.

We collect the personal data that you provide to us when using our Services, for example when you use our Solution, place an order, or communicate with us, when you create and/or manage your account, through web forms you fill or when you subscribe to our newsletter. 

It is only mandatory that you complete the data fields identified as such. If one or more mandatory data fields are not completed, we will not be able to provide access to our Services. You are not required to complete the optional data fields to access our Services. These fields may be completed at any time through your account settings. 

Some information about you may also be provided to us directly by our users

Even if you are not a user of our Services, we may collect certain information about you if this is provided to us by one of our users. Such information may comprise anything that is included in the datasets that are uploaded by our users in connection with their use of our Services. 

Certain personal data are also collected in an automated manner. 

We also automatically collect personal data, including by means of tools, web forms, cookies and other active elements, as further described in this General Privacy Notice.  

Some personal data are also collected from a third-party data processer and/or controller

When you access our Services online, such as webinars and virtual events, or when you access or download content available through the Services (guides, market reports, etc.), we collect personal data that you provide to us to access such Services. When you do so, we may also enrich your personal data by using a third party platform, who processes personal data on behalf of Pexapark as the event owner/data controller, and on your behalf as the attendee/user who signs up to our events or wants to download our content. When we sponsor an external event through a contractual relationship, we may obtain information about you as an event delegate through a third party event organiser as part of a sponsorship contract.

 

You may define certain authorizations relating to the automatic collection of your personal data when you configure your device or your internet browser according to available functionalities.

You may also define certain settings for the automated collection of your personal data through the cookies setting plugin available on the Solution. For more detailed information, please see our Cookie Policy. 

5. How we use your data

We process your personal data in accordance with applicable laws and only if we have a valid legal ground to do so. 

We process your personal data in compliance with applicable law, in particular Swiss data protection laws and, to the extent they apply to us, other data protection legislations, such as the EU General Data Protection Regulation (GDPR) or its equivalent in the United Kingdom, manually or automatically using computer tools. 

This means that we will only process your information for certain reasons (see Section 7) where we have a legal basis to do so.

  • Additional Information on the "legal basis"

    Here is what each of these legal bases is: 

    • Contractual Necessity: the processing is necessary to fulfil our contractual obligations to you or to take pre-contractual steps at your request. This is particularly the case when processing your personal data is strictly required to provide you with the Services such as to deliver, grant access to or activate features of our platforms for you to view pricing and asset data and relevant information, to proceed with your purchase order, and to receive technical support. When the GDPR applies, Contractual Necessity is based on Article 6(1)(b) GDPR. 
    • Legitimate Interest: The processing is necessary for the fulfilment of our legitimate and commercial interests, and only to the extent that your interests or fundamental rights and freedoms do not require us to refrain from processing. Such processing includes the way we authenticate customer identification data, display pricing and asset information and animation, process order and payment, and understand our customer needs and benefits in using our products and services. When the GDPR applies, Legitimate Interest is based on Article 6(1)(f) GDPR. 
    • Consent: we have obtained your prior consent in a clear and unambiguous manner when your personal data are obtained through the use of our services and products. Consent given can be withdrawn at any time, but this does not affect data processed prior to withdrawal.  When the GDPR applies, Consent is based on Article 6(1)(a) GDPR. 
    • Legal Obligation: the processing is necessary to comply with our legal or regulatory obligations. When the GDPR applies, Legal Obligation is based on Article 6(1)(c) GDPR. 
  • Additional Information on profiling and automated decisions

    We may process your personal data to create a profile about you and provide you with more relevant information and services (profiling), for instance to show you more relevant information based on prior interactions with our Services. 

    We, however, do not make decisions exclusively on the basis of an automated processing which have legal effects on the data subjects or affect them significantly (automated individual decision). You may have the right to object to such activities, in accordance with applicable data protection laws (see section 12 below for additional information on your rights). 

6. Why we use your data

We process your personal data for the reasons indicated in this Section or in any Additional Privacy Notice: 

To provide our Services and operate the Solution. 

We mainly process your personal data to provide the Solution and the Services, including for creating and maintaining your user account, interacting with you, processing your orders and payments, and providing you with the requested information and Services. 

Legal basis: Contractual Necessity, Legitimate Interests

  • Additional Information
    • Contacting you and responding to your queries. You have the option of contacting us via the Solution or by email. In this context, we process the data which you provide to us (including your contact information and the subject-matter of the request). This data is used for the purpose of providing you with the requested information and services.  

    The retention period depends on the reason for your request and its context. Requests relating to orders will be retained for the period specified for orders. Other requests are, as a rule, retained for the time necessary to meaningfully process the request, but as a general rule not for more than a few weeks or months depending on the nature of the request,  unless there is legal ground for retaining them longer (such as evidentiary or tax purposes). 

    • For instance, if you have an account, your account information is retained for as long as your account is active. If you suppress your user account, we will delete your personal data within 30 days after such event, unless data must be retained for a valid reason. 
    • Processing orders and payments. To place an order, you must provide the information requested from you (e.g. contact information, billing address, payment method and related information). 

    We also automatically collect data related to your use of the Solution in accordance with our Cookie Policy. 

    We use third-party services for payments and the dispatch of orders. For example, depending on the payment method selected, you will be redirected to the website of an online payment provider which is responsible for processing the payment. We transmit to these third parties only the data necessary for the operations they perform.  

    We are required by law to store certain information such as invoices, contracts and other information relevant to accounting for a certain period of time (generally for 10 years). Data relating to uncompleted orders is stored for the time required to meaningfully determine that the order will not be completed, but as a general rule not for more than a few months, and then deleted. 

    What If You Are Not a User or Customer of Our Services?

    If you are not a user, we will process your personal data if it is provided to us by one of our users, for instance due to your position in an organization to which a user is affiliated (Organization). In this case, we process your personal data for the purpose of providing the Solution and the Services to your Organization, based on a contract between us and your Organization. This General Privacy Notice does not govern how your Organization processes your personal data or how we process your data for the account of your Organization (e.g. to carry out the analysis requested by your Organization). Please refer to your Organization’s policies and contact your Organization directly for any inquiry relating to the use of your personal data by it.

For our legitimate business interests related to the provision of the Services, including to ensure the security of the Services, improve our Services, as well as for monitoring or statistical purposes.

We may also process your personal data for our legitimate business operations related to providing our Services, which include (i) ensuring that our Services are provided in an efficient and secure way (e.g. through internal analysis of the Services’ stability and security, updates and troubleshooting); (ii) protecting the security of our IT systems, architecture and networks; (iii) benefiting from cost-effective services (e.g. we may opt to use certain services offered by suppliers rather than undertaking the activity ourselves); (iv) improving and developing the Services (including monitoring the use of our Services, and for statistical purposes); and (v) achieving our corporate goals). 

Legal basis: Legitimate Interests, Consent  

  • Additional Information

    Additional information on the processing of your personal data for our legitimate business operations: 

    • Ensuring that our Solution is provided in an efficient and secure way. In addition to the personal data which you provide when logging-in to your account or interacting with the Solution (e.g. when you fill in forms or upload content to the Solution), we automatically collect technical information about your interactions with the Solution, such as IP address, the content that was accessed, date and time of access, information about your web browser, your preferences, or other information related to your interaction with the Solution, including your navigation details on the Solution.  

    We process this data to establish a connection with your device over the internet, to identify you when you use the Solution, control the use of the Solution and for security purposes. 

    • Protecting the security of our IT systems, architecture, and networks. We use data to protect the security of our IT systems, architecture, and networks, for instance to detect and disrupt the operation of malicious software by systematically scanning contents in an automated manner. 
    • Personalizing and improving our Services. We may process your personal data, in particular data relating to your use of our Services and your habits and preferences (e.g. the content you accessed, date and time of access and your preferences), for internal analysis and statistical purposes, in order to better understand the needs of our users, to optimize their experience by personalizing our Services, and in general to improve the ergonomics and functionality of our Services. You may object to such processing activities at any time (see section 12 below for additional information on your rights). 

    You will find additional information in our Cookie Policy in relation to the use of cookies for this purpose, including on the duration for which data collected this way are stored. Data collected by other means is deleted or anonymized at the latest 7 days after its collection. 

    • Data anonymization. We may combine your personal data with other information (aggregate) or erase any information that allows us to identify you (anonymize), so that it is no longer considered personal data under applicable data protection law, in which case this General Privacy Notice will no longer apply and we may use such data for purposes not contemplated by this General Privacy Notice (e.g. for benchmarking or analytics purposes, or to develop and market new services). You may object to the anonymization or aggregation of your personal data for this purpose at any time (see section 12 below for additional information on your rights). 

To send you our newsletter and other advertising information.

If you subscribe to our newsletter or agree to receive our marketing emails, we will collect your contact details and use them to provide you with our email communications. You may choose to unsubscribe or opt into the newsletter service at any time through our Email Preferences page. When you unsubscribe, you will not receive marketing emails from Pexapark until you resubscribe. You may contact us at any time and ask for your contact details to be deleted from our mailing list. 

Legal basis: Consent 

We also process the time of registration and your opt-in confirmation to demonstrate compliance. We also analyse your use of our newsletter, e.g. whether you have opened it or clicked on certain links, and process this data to optimize and improve our newsletter. 

Legal basis: Legal Obligation; Legitimate Interests 

We use the third-party services of Salesforce to provide our newsletter service, which will have access to your login data to this end. Salesforce’s privacy policy applies in connection with this. You will find it here: https://www.salesforce.com/company/privacy/. 

Based on the information you already provide, we use the third-party service for conducting a survey [Typeform, Qualtrics], for appointment scheduling [Calendly] and for enriching the data for accuracy [Cognism]. Their privacy policies apply to the processing of your personal data in connection with these services. You will find them here: https://www.typeform.com/help/a/security-privacy-standards-at-typeform-9350912237844/, https://www.qualtrics.com/privacy-statement/, https://calendly.com/privacy and https://www.cognism.com/en/privacy-policy 

Independently from your subscription to our newsletter, we may contact you by email to inform you about our activities if you have previously subscribed for the use of our Services, if you have not objected to the corresponding use of your email address. You can object to the use of your email address for this purpose at any time by contacting us (see contact details in section 14).  

We use the third-party services of Mailgun to provide you with important notifications from our applications in case you have subscribed to them (such as Multi-factor authentication codes). Mailguns privacy policy applies in connection with this. You will find it here: https://www.mailgun.com/legal/privacy-policy/  

Legal basis: Legitimate Interest  

To provide you with job opportunities within Pexapark.

We may process your personal data to allow you to consult and apply for job opportunities within Pexapark. We will process the personal data you provide. In addition, if you provide us with links to your profile on social media platforms (such as LinkedIn) or with contact information for references, we will assume that we may gather information from these sources. 

Any information you submit must be true, complete and not misleading. Should the information provided be inaccurate, incomplete, or misleading, subject to applicable law, this may lead to a rejection of your application during the application process or disciplinary action including immediate dismissal if you have been employed.   

We will process your personal data exclusively for assessing your application. Your personal data is retained no longer than the duration of the recruitment process unless otherwise permitted by applicable laws and regulations. 

Legal basis: Contractual Necessity (to take pre-contractual steps at your request) 

To provide you with targeted information or advertisements based on the content you published and your interactions with the Solution.

Provided we have collected your valid consent. we use as part of our operation of the Solution the services of third parties, which may place cookies on your device in order to provide you with personalized advertisements based on your interaction with the Solution. The privacy policies of those providers are applicable in relation to their activities. You may withdraw your consent at any time (see section 12 below for additional information on your rights). 

You will find additional information in section 11 in relation to the use of cookies for this purpose, including on the duration for which data collected this way are stored, and the link to the privacy policies of those external service providers. 

Legal basis: Consent 

To comply with our other legal obligations or for other legitimate interests.

We may further process your personal data if we have a legal obligation to do so or for other legitimate interests. This will for instance be the case if we need to disclose certain information to public authorities or retain such information for tax or accounting purposes, or for the establishment, exercise, or defense of legal claims.  

The personal data that we process for this purpose are those that we collected for one of the purposes indicated elsewhere in this section 6. We retain the personal data for the duration of the legal obligation imposed on us. 

Legal basis: Legal Obligations, Legitimate Interests 

7. The circumstances in which we share your personal data with third parties

We will only share your personal data with third parties if this is necessary for the operation of our Services, if there is a legal obligation or permission to do so, or if there is another valid reason to do so. 

  • Additional Information
    • Our service providers. We may share your personal data with third parties in connection with the operation of the Services and with subcontractors such as IT service providers, cloud service providers, database providers, automated marketing solutions providers and consultants. Detailed information on these providers can be found in the previous section.   
    • Events we organize. If you signup to events we organize, the providers we use to organize them will have access to the information required to provide their services.  
    • Social plug-ins. We may also enable you to use third-party services directly from the Solution, in particular through the social plug-ins of Google, Facebook, LinkedIn, Twitter, and Microsoft, in which case you acknowledge that the third-party operators of such services may access some of your personal data related to the Solution, in accordance with their own privacy practices. 
    • Legal Obligation. We may also disclose your personal data where we have a legitimate interest in doing so, for example (i) to respond to a request from a judicial authority or in accordance with a legal obligation; (ii) to bring or defend against a claim or lawsuit; or (iii) in the context of restructuring, in particular if we transfer our assets to another company.

8. International Transfers

We store your personal data on servers located in Switzerland and/or the European Union.  

In principle, we do not transfer your personal data to other countries or make it available there. However, in certain circumstances, in particular in connection with the operations of our subcontractors, your personal data may be made available to recipients located abroad (e.g.  USA, countries of the European Union, United Kingdom, Ukraine, Serbia, from which locations some data may be available). In such cases, we will ensure that suitable safeguards are in place, in accordance with applicable data protection laws, for instance by relying on standard contractual clauses adopted by the European Commission.  

If you transmit information and data to us, you are expressly deemed to consent to such data transfers. You may request additional information in this regard and obtain a copy of the relevant safeguards upon request by sending a request to the contact address indicated in section 15 below. 

9. How long we store your personal data

Your personal data will not be stored longer than necessary. We will erase or anonymize your personal data as soon as it is no longer necessary for us to fulfil the purposes set out in section 6 of this General Privacy Notice. This period varies, depending on the type of data concerned and the applicable legal requirements. More information on each type of processing can be found in section 6 above.  

Your account information is retained for as long as your account is active. If you suppress your user account, your account information will be deleted or anonymized within 30 days after such event, unless data must be retained for a valid reason (such as evidentiary or tax purposes). 

In view of the legal obligations incumbent upon us, certain information relating in particular to the contractual relationship must be retained for at least 10 years.

10. Security

We are committed to the security of your personal data, and have in place physical, administrative and technical measures designed to keep secure your personal data and to prevent unauthorized access to it. We use two-factor authentication whenever possible. We restrict access to your personal data to those persons who need to know it for the purpose described in this General Privacy Notice. In addition, we use standard security protocols and mechanisms to exchange the transmission of sensitive data. When you enter sensitive information on our Solution, we encrypt it using Transport Layer Security (TLS) technology. 

Although we take appropriate steps to protect your personal data, no IT infrastructure is completely secure. Therefore, we cannot guarantee that data you provide to us is safe and protected from all unauthorized third-party access and theft. We waive any liability in this respect. 

The internet is a global environment. As a result, by sending information to us electronically, such data may be transferred internationally over the internet depending upon your location. Internet is not a secure environment, and this General Privacy Notice applies to our use of your personal data once it is under our control only. Given the inherent nature of the internet, all internet transmissions are done at your own risk. 

If we have reasonable reasons to believe that your personal data have been acquired by an unauthorized person, and applicable law requires notification, we will promptly notify you of the breach by email (if we have it) and/or by any other channel of communication (including by posting a notice on the Solution). 

11. How we use cookies or other analytical tools

We and our third-party service providers use cookies and other similar technologies (Cookies) in connection with our Solution for us to provide our Services and ensure that it performs properly, to analyse our performance, to personalize your experience, and for our marketing activities, some of which are capable of automatically processing data on your electronic device and/or of transferring personal data about you to us or third parties. 

You can learn more about how we use Cookies and similar technologies and how you can exercise control over them in our Cookie Policy. 

12. Your rights regarding the processing of your personal data

You have the right to access your personal data we process and may request that they be removed, updated, or rectified. 

Unless otherwise provided by law, you have the right to know whether we are processing your personal data. You may contact us to know the content of such personal data, to verify its accuracy, and to the extent permitted by law, to request that it be supplemented, updated, rectified, or erased. You also have the right to ask us to cease any specific processing of personal data that may have been obtained or processed in breach of applicable law, and you have the right to object to any processing of personal data for legitimate reasons. However, if you are not a user of our Services, you should direct your privacy inquiries relating to the use of your personal data by your Organization, including any requests to exercise your data protection rights, directly to your Organization. 

By accessing your user account (if you have one), you can review, update, correct or delete the personal data available within your user account. Should there not be an option to edit the information in the interface, you can request us to review, update, correct or delete the personal data, and we will comply with this request within 30 days. 

If you request us to delete your personal data from our systems, we will do so unless we need to retain your data for legal or other legitimate reasons. Please note that any information that we have copied may remain in back-up storage for some period of time after your deletion request. 

Where we rely on your consent to process your personal data, we will seek your freely given and specific consent by providing you with informed and unambiguous indications relating to your personal data. You may revoke at any time such consent (without such withdrawal affecting the lawfulness of processing made prior to).  

The above does not restrict any other rights you might have pursuant to applicable data protection legislation under certain circumstances 

  • Additional Information

    In particular, if the GDPR applies to the processing of your personal data you have the following rights under the GDPR if the respective requirements are met: 

    • Right of access (Art. 15 GDPR) – you have the right to access and ask us for copies of your personal data.  
    • Right to rectification (Art. 16 GDPR) – you have the right to ask us to rectify personal data you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.  
    • Right to erasure (Art. 17 GDPR) – you have the right to ask us to erase your personal data in certain circumstances.  
    • Right to restriction of processing (Art. 18 GDPR) – you have the right to ask us to restrict the processing of your personal data in certain circumstances.  
    • Right to data portability (Art. 20 GDPR) – you have the right to ask that we transfer in a structured, commonly used and machine-readable format the personal data you gave us to another organization, or to you, in certain circumstances. 
    • Right to object to processing (Art. 21 GDPR) – you have the right to object to the processing of your personal data which is based on our legitimate interests, in certain circumstances. In such case, we will no longer process the personal data unless we demonstrate compelling legitimate grounds for the processing, which override your interests, rights, and freedoms or where the processing is necessary for the establishment, exercise or defense of legal claims. 
    • As a rule, you are not required to pay any charge for exercising your rights and we will respond to your request within one month.  

You will find further details of your rights in sections  5 and 6 and  of this General Privacy Notice in connection with each processing activity we perform. If you want to exercise any of your rights, or want additional information about them, please contact us using the contact details listed below (see section 14). 

You have the right to lodge a complaint with the competent authority.

If you are not satisfied with the way in which we process your personal data, you may lodge a complaint with the competent data protection supervisory authority, in the Member State of your habitual residence, place of work or place of the alleged infringement, in addition to the rights described above.  

Although this is not required, we recommend that you contact us first, as we might be able to respond to your request directly. 

13. Service-Specific Information

This section of the General Privacy Notice contains the information which is specific to certain  specific services provided by Pexapark. It applies in addition to the other sections of this General Privacy Notice.

14. Children Privacy

Pexapark’s services are not intended for children. Pexapark does not knowingly collect personal data from children under the age of 13. If you learn that a child has provided us with personal data in violation of this General Privacy Policy, please alert us via email (see contact details under section 15). 

15. Contact Us

If you believe your personal data has been used in a way that is not consistent with this General Privacy Notice, or if you have any questions or queries regarding the collection or processing of your personal data, please contact us at dpo@pexapark.com. 

You can also contact our representative in the European Union via email at info@datenschutzpartner.eu or by mail at: 

VGS Datenschutzpartner UG 

Am Kaiserkai 69, 20457 Hamburg, Germany  

16. Updates to this General Privacy Notice

This General Privacy Notice may be subject to amendments. Any changes or additions to the processing of personal data as described in this General Privacy Notice affecting you will be communicated to you through an appropriate channel, depending on how we normally communicate with you (including by email and/or via the Solution, e.g. banners, pop-ups or other notification mechanisms). If you do not agree to the changes made, you must stop accessing and/or using the impacted Services. 

Last Updated Version

29.12.2023