Introduction
Given the importance we place on protecting your data and your privacy, we have drawn up this data protection notice to explain what we do when you visit our website aegryn.com.
This data protection notice covers only the data processing related to our website. Specific data protection notices may apply to other services and offerings we provide.
In Switzerland, the protection of your data is based in particular on the Swiss Federal Act on Data Protection of 25 September 2020 (FADP) and the Federal Ordinance on Data Protection (DPO) of 31 August. Our data protection notice and our practices are aligned with the legal provisions in that legislation.
We have grouped the key definitions to facilitate understanding of this notice:
- Data subject: the natural person whose personal data is processed.
- Personal data: any information relating to an identified or identifiable natural person.
- Sensitive personal data: data relating to religious, philosophical, political or trade union opinions or activities; data relating to health, the private sphere or racial or ethnic origin; genetic data; biometric data; data relating to criminal and administrative proceedings and sanctions; data relating to social welfare measures.
- Processing: any handling of personal data, regardless of the means and procedures used.
- Controller: a private person or federal body who, alone or jointly with others, determines the purposes and means of processing personal data.
- Processor: the private person or federal body that processes personal data on behalf of the controller.
- FDPIC: the Federal Data Protection and Information Commissioner, responsible for overseeing the proper application of federal data protection provisions.
Who are we and how can you contact us?
Aegryn is the name of our company. If you have questions about the data processing related to our website, you can contact us by mail: Aegryn (BOHA-Group sàrl), c/o Cofidex SA, Rue du Centre 142, 1025 St-Sulpice. You can also contact us by email at legal@boha-group.com or via our contact form.
What is our role regarding data protection?
When you browse our website, we may process some of your personal data. In accordance with the FADP, we are the controller.
As controller, we are responsible for determining the purposes for which we process your personal data, how it is processed and the security measures. When working with service providers, we ensure they share our data protection commitment.
Data protection is everyone's concern. We encourage you to read this notice and, if you are one of our clients, to consult the contractual documents between us.
When and how do we collect your data?
From your first interaction with our website, we collect data (for example to determine whether you consent to the use of cookies). You also provide us with your data when you contact us via our contact form.
What categories of data do we process?
Contact data
We process your contact data, such as your first name, last name, address, phone number or email address.
Internet and connection data
For technical reasons and to improve our website, we process your IP address, information about your internet service provider and the operating system of your device, information about the referring URL, browser used, date and time of access, and content viewed during your visit.
What about sensitive data and minors?
We do not collect or process any sensitive personal data. While access to our website is open to all, our services are exclusively intended for adults. We do not target minors and do not deliberately collect any personal data about them.
Why do we process your data?
We process your data in order to:
- Communicate with you, in particular to respond to your requests and exercise your rights.
- Inform you about our services and offerings.
- Manage your account and subscription (registration, billing, referral programme).
- Process NDA access requests for asset dossiers and retain signature records.
- Conduct CIFS certification missions (collection and evaluation of seller dossiers).
- Generate traffic statistics useful for improving our website.
- Comply with laws, directives and recommendations from authorities.
It is important to note that we do not make any automated individual decisions.
What are your rights?
In general, the FADP grants you the following rights:
- You have the right to access your data.
- You have the right to request that your data be provided in a commonly used electronic format.
- You have the right to have inaccurate data corrected.
- You have the right to object to the processing of your data.
- You have the right to request the deletion or destruction of your data.
- You have the right to request that an automated individual decision be reviewed by a natural person.
To exercise any of these rights, please contact us. If you believe we are processing your data in violation of data protection provisions, you can also report us to the FDPIC.
How do we protect your data?
We take appropriate security measures, such as encryption, to protect your personal data. If you believe your personal data has been compromised, please inform us immediately at legal@boha-group.com.
Where is your data stored and for how long?
Data is stored at our premises as well as in processing centres operated by our service providers. We process your data for as long as the purpose of processing requires, we have a legitimate interest in retaining it, or the data is subject to a legal retention obligation (up to 10 years for certain data).
With whom do we share your data?
Managing our website involves working with external specialised service providers (creation, maintenance, hosting). We ensure that such communications are strictly limited to what is necessary. When data is transferred outside Switzerland or the EEA, we use the revised standard contractual clauses of the European Commission or other appropriate safeguards.
Our service providers
| Provider | Purpose | Processing location |
|---|---|---|
| Supabase | Database, authentication and dossier storage (accounts, KYC, NDA, CIFS certification). | EEA/USA |
| Stripe | Payment processing and Expert subscription management. | EEA/USA |
| Vercel | Website hosting and deployment. | EEA/USA |
| Cloudflare | Website security, availability and GDPR-compliant analytics. | EEA/USA |
| Resend | Transactional sending of contact emails and notifications. | EEA/USA |
What cookies do we use?
Our website uses cookies. You can access the list of cookie types via our cookie banner. You can block cookies by enabling a setting in your browser or via our cookie banner.
Social media
We maintain our presence on social media (LinkedIn, Facebook, Instagram, TikTok, YouTube). When you communicate with us on these platforms, we collect data used primarily to communicate with you. For more information, please consult the data protection notices of the relevant operators.
Contact and communication services
Aegryn is not a telecommunications service provider. Communication features within applications (calls, chat) operate exclusively via Internet protocols (VoIP and data messaging). This contact number and application communication functions are not intended for emergency services.
Final provisions
We reserve the right to amend the terms of this notice at our sole discretion. Any amended version will be published on our website.