Privacy Policy
This Privacy Policy explains how we process personal data in connection with our activities and services, including our website at www.fantoche.ch. In particular, it explains what personal data we process, for what purposes, how and where we process it.
It also informs you about the rights of individuals whose personal data we process. We may publish additional privacy policies or other data protection information for specific or additional activities and services.
We are subject to Swiss law and, where applicable, foreign laws, in particular the data protection laws of the European Union (EU), including the General Data Protection Regulation (GDPR). By decision of 26 July 2000, the European Commission recognised that Swiss data protection law provides an adequate level of data protection. In its report of 15 January 2024, the European Commission confirmed this adequacy decision.
1. Contact Details
The controller responsible for data processing within the meaning of applicable data protection laws is:
Fantoche - International Animation Film Festival
Bruggerstrasse 37
5400 Baden
Schweiz
In individual cases, third parties may be responsible for the processing of personal data, or responsibility may be shared with third parties. Upon request, we are happy to provide data subjects with information about the respective responsibilities.
2. Definitions and Legal Bases
2.1 Definitions
Data Subject: A natural person whose personal data we process.
Personal Data: Any information relating to an identified or identifiable natural person.
Sensitive Personal Data: Data relating to trade union membership, political, religious or philosophical views and activities, health, intimate life, racial or ethnic origin, genetic data, biometric data uniquely identifying a natural person, criminal or administrative sanctions or proceedings, and social assistance measures.
Processing: Any operation performed on personal data, regardless of the means or procedures used, including collecting, recording, obtaining, organising, structuring, storing, adapting, modifying, retrieving, consulting, using, disclosing, transmitting, disseminating, linking, archiving, retaining, deleting, destroying or otherwise processing personal data.
European Economic Area (EEA): The Member States of the European Union (EU), as well as Liechtenstein, Iceland and Norway.
2.2 Legal Bases
We process personal data in accordance with Swiss law, in particular the Swiss Federal Act on Data Protection (FADP) and the Ordinance to the Federal Act on Data Protection (OFADP).
Where and to the extent that the General Data Protection Regulation (GDPR) applies, we process personal data on the basis of at least one of the following legal grounds:
-
Art. 6(1)(b) GDPR – Processing is necessary for the performance of a contract with the data subject or to take steps at the request of the data subject prior to entering into a contract.
-
Art. 6(1)(f) GDPR – Processing is necessary for the purposes of our legitimate interests, or those of a third party, provided these interests are not overridden by the interests or fundamental rights and freedoms of the data subject. Such legitimate interests include, in particular, the sustainable, user-friendly, secure and reliable operation of our activities and services, ensuring information security, preventing misuse, enforcing our legal claims and complying with Swiss law.
-
Art. 6(1)(c) GDPR – Processing is necessary for compliance with a legal obligation to which we are subject under applicable law in Member States of the European Economic Area (EEA).
-
Art. 6(1)(e) GDPR – Processing is necessary for the performance of a task carried out in the public interest.
-
Art. 6(1)(a) GDPR – Processing is based on the consent of the data subject.
-
Art. 6(1)(d) GDPR – Processing is necessary in order to protect the vital interests of the data subject or another natural person.
-
Art. 9(2) et seq. GDPR – Processing of special categories of personal data, in particular with the explicit consent of the data subject.
Under the GDPR, the processing of personal data is referred to as the processing of personal data, and the processing of sensitive personal data is referred to as the processing of special categories of personal data (Art. 9 GDPR).
3. Nature, Scope and Purpose of Processing Personal Data
We process the personal data that is necessary to carry out our activities and services in a sustainable, user-friendly, secure and reliable manner. The personal data processed may include, in particular, browser and device data, content data, communication data, metadata, usage data, master data (including customer and contact data), location data, transaction data, contract data and payment data. Personal data may also include sensitive personal data.
We also process personal data that we receive from third parties, obtain from publicly accessible sources, or collect in the course of our activities and services, provided that such processing is permitted by law.
Where necessary, we process personal data with the consent of the data subjects. In many cases, however, we may process personal data without consent, for example to comply with legal obligations or to safeguard overriding legitimate interests. We may also request consent even where it is not legally required.
We retain personal data only for as long as necessary for the respective purpose. In particular, we anonymise or delete personal data in accordance with applicable statutory retention and limitation periods.
4. Disclosure of Personal Data
We may disclose personal data to third parties, have personal data processed by third parties, or process personal data jointly with third parties. Such third parties may include specialised service providers whose services we use. These third parties may, in turn, disclose personal data to other third parties.
In the course of our activities and services, we may disclose personal data in particular to banks and other financial service providers, public authorities, educational and research institutions, consultants and legal advisers, accounting and fiduciary service providers, debt collection agencies, advocacy organisations, IT service providers, cooperation partners, credit reference agencies, logistics and shipping companies, marketing and advertising agencies, media organisations, parent, sister and subsidiary companies, organisations and associations, social institutions, telecommunications providers, insurance companies and payment service providers.
5. Communication
We process personal data in order to communicate with individuals, public authorities, organisations and companies. In particular, we process the information that a data subject provides to us when contacting us, for example by post or email. We may store such information in an address book or similar systems.
Third parties who provide us with personal data relating to other individuals are legally obliged to ensure compliance with applicable data protection requirements. In particular, they must ensure that they are entitled to disclose such data and that the information provided is accurate.
6. Job Applications
We process applicants' personal data to the extent necessary to assess their suitability for employment or for the subsequent performance of an employment contract. The required personal data is determined in particular by the information requested, for example in a job advertisement. We may publish job advertisements through suitable third parties, such as electronic and print media, job portals and recruitment platforms.
We also process any personal data that applicants voluntarily provide or publish, in particular as part of cover letters, CVs, other application documents and online profiles.
Where and to the extent that the GDPR applies, we process applicants' personal data in particular on the basis of Article 9(2)(b) GDPR.
7. Data Security
We implement appropriate technical and organisational measures to ensure a level of data security appropriate to the respective risk. In particular, these measures are designed to ensure the confidentiality, availability, traceability and integrity of the personal data we process. However, we cannot guarantee absolute data security.
Access to our website and other digital services is protected by transport encryption (SSL/TLS), in particular through Hypertext Transfer Protocol Secure (HTTPS). Most web browsers warn users when visiting websites that do not use encrypted connections.
Like all digital communications, our digital communications may be subject to mass surveillance by security authorities in Switzerland, elsewhere in Europe, the United States of America (USA) and other countries, without specific cause or suspicion. We have no direct influence over the processing of personal data by intelligence services, law enforcement agencies or other security authorities. Nor can we exclude the possibility that a data subject may be subject to targeted surveillance.
8. Personal Data Abroad
As a general rule, we process personal data in Switzerland and within the European Economic Area (EEA). However, we may also transfer personal data to other countries, in particular for processing or to have it processed there.
We may transfer personal data to any country in the world—and beyond—provided that the legal framework of the destination country ensures an adequate level of data protection, as recognised by the Swiss Federal Council and, where applicable, by the European Commission under the GDPR.
We may transfer personal data to countries that do not provide an adequate level of data protection where appropriate safeguards are in place, in particular on the basis of Standard Contractual Clauses or other suitable guarantees. In exceptional cases, we may transfer personal data to countries without an adequate level of protection if the specific legal requirements under data protection law are met, for example where the data subject has explicitly consented or where the transfer is directly related to the conclusion or performance of a contract. Upon request, we will provide information about any applicable safeguards or a copy of such safeguards.
9. Rights of Data Subjects
9.1 Data Protection Rights
We grant data subjects all rights provided under applicable law. In particular, data subjects have the following rights:
- Right of access: Data subjects may request information as to whether we process personal data concerning them and, if so, which personal data is being processed. They are also entitled to receive the information necessary to exercise their data protection rights and to ensure transparency. This includes, among other things, information about the purposes of processing, the retention period, any disclosure or transfer of personal data to other countries, and the origin of the personal data.
- Right to rectification and restriction of processing: Data subjects may request the correction of inaccurate personal data, the completion of incomplete data, and the restriction of the processing of their personal data.
- Right to express their point of view and request human review: Where decisions are based solely on automated processing and produce legal effects concerning the data subject or similarly significantly affect them (automated individual decision-making), data subjects have the right to express their point of view and request human intervention.
- Right to erasure and objection: Data subjects may request the deletion of their personal data ("right to be forgotten") and object to the future processing of their personal data.
- Right to data portability: Data subjects may request that their personal data be provided to them or transferred to another controller.
We may postpone, restrict or refuse the exercise of these rights where permitted by law. We may inform data subjects of any legal requirements that must be fulfilled before such rights can be exercised. For example, we may refuse access, in whole or in part, on the grounds of confidentiality obligations, overriding legitimate interests or the protection of other persons. Likewise, we may refuse the deletion of personal data where statutory retention obligations apply.
In exceptional cases, we may charge a fee for exercising these rights. Data subjects will be informed in advance of any applicable costs.
We are required to verify the identity of individuals requesting access to personal data or exercising other rights by appropriate means. Data subjects are required to cooperate in this process.
9.2 Legal Remedies
Data subjects have the right to enforce their data protection rights through legal proceedings or to lodge a complaint with a competent data protection supervisory authority.
In Switzerland, the competent supervisory authority for private controllers and federal authorities is the Federal Data Protection and Information Commissioner (FDPIC).
The data protection supervisory authorities within the European Economic Area (EEA) are organised as members of the European Data Protection Board (EDPB). In some EEA Member States, particularly Germany, these supervisory authorities are organised on a federal basis.
10. Use of the Website
10.1 Cookies
We may use cookies. Cookies—both our own cookies (first-party cookies) and cookies from third parties whose services we use (third-party cookies)—are data stored in your browser. Such stored data is not necessarily limited to traditional text-based cookies.
Cookies may be stored temporarily in your browser as session cookies or for a defined period as persistent cookies. Session cookies are automatically deleted when you close your browser. Persistent cookies remain stored for a specified period of time. Cookies enable us, in particular, to recognise your browser when you visit our website again and, for example, to measure the reach of our website. Persistent cookies may also be used for online marketing purposes.
Cookies can be disabled, restricted or deleted at any time, in whole or in part, through your browser settings. Browser settings often also allow for the automatic deletion and other management of cookies. Please note that certain functions of our website may not be available without cookies. Where required by applicable law, we actively obtain your express consent to the use of cookies.
For cookies used for analytics or advertising purposes, many services offer a general opt-out via AdChoices (Digital Advertising Alliance of Canada), the Network Advertising Initiative (NAI), YourAdChoices (Digital Advertising Alliance), or Your Online Choices (European Interactive Digital Advertising Alliance, EDAA).
10.2 Log Files
For each access to our website and other digital services, we may log at least the following information, provided that it is automatically transmitted to or collected by our digital infrastructure: date and time (including time zone), IP address, access status (HTTP status code), operating system (including user interface and version), browser (including language and version), the specific page visited (including the volume of data transferred), and the last website visited within the same browser window (referrer URL).
We record such information, which may also constitute personal data, in log files. These records are necessary to ensure the long-term, user-friendly and reliable operation of our digital services. They are also required to ensure data security, including by or with the assistance of third parties.
10.3 Web Beacons
We may integrate web beacons into our digital services. Web beacons, also known as tracking pixels, are generally small invisible images or JavaScript-based scripts that are automatically retrieved when our digital services are accessed. Web beacons—including those provided by third parties whose services we use—may collect at least the same information as is recorded in log files.
11. Notifications and Communications
11.1 Performance and Reach Measurement
Notifications and communications may contain web links or web beacons that record whether an individual message has been opened and which links have been clicked. Such web links and web beacons may also enable the collection of personal usage data. We require this statistical analysis to measure the effectiveness and reach of our communications so that we can send notifications and communications efficiently, in a user-friendly, secure and reliable manner, taking into account the needs and reading habits of recipients.
11.2 Consent and Objection
As a general rule, you must consent to the use of your email address and other contact details unless their use is permitted on another legal basis. Where appropriate, we may use a double opt-in procedure to obtain confirmed consent. In such cases, you will receive a message with instructions for confirming your consent. For evidentiary and security purposes, we may log the consent obtained, including the IP address and timestamp.
You may object to receiving notifications and communications, such as newsletters, at any time. By doing so, you may also object to the statistical measurement of their effectiveness and reach. This does not affect notifications and communications that are necessary in connection with our activities and services.
11.3 Notification and Communication Service Providers
We send notifications and communications using specialised service providers.
In particular, we use:
- CleverReach – Email marketing platform; provided by CleverReach GmbH & Co. KG (Germany). For further information, please refer to CleverReach's Privacy Policy and information on Data Security.
12. Social Media
We maintain a presence on social media platforms and other online platforms in order to communicate with interested individuals and to provide information about our activities and services. In connection with such platforms, personal data may also be processed outside Switzerland and the European Economic Area (EEA).
The terms and conditions, terms of use, privacy policies and other provisions of the respective platform operators also apply. These provisions provide information, in particular, about the rights of data subjects in relation to the respective platform, including the right of access.
With regard to our Facebook presence, including the so-called Page Insights, we are jointly responsible with Meta Platforms Ireland Limited (Ireland), where and to the extent that the General Data Protection Regulation (GDPR) applies. Meta Platforms Ireland Limited is part of the Meta group of companies, including entities in the United States. Page Insights provide us with information about how visitors interact with our Facebook page. We use Page Insights to operate our Facebook presence effectively and in a user-friendly manner.
Further information about the nature, scope and purpose of data processing, the rights of data subjects, and the contact details of Facebook and Facebook's Data Protection Officer can be found in Facebook's Privacy Policy. We have entered into Facebook's Controller Addendum, which provides, among other things, that Facebook is responsible for ensuring the rights of data subjects. Information relating to Page Insights can be found on Facebook's Page Insights Information page, including information on Page Insights Data.
13. Third-Party Services
We use specialised third-party services to ensure that we can carry out our activities and services in a sustainable, user-friendly, secure and reliable manner. Among other things, these services enable us to integrate functions and content into our website. Where such services are embedded, they process users' IP addresses, at least temporarily, for technical reasons.
For essential security, statistical and technical purposes, third parties whose services we use may process data related to our activities and services in an aggregated, anonymised or pseudonymised form. This may include, for example, performance or usage data required to provide the respective service.
In particular, we use:
- Google services: Provided by Google LLC (USA) and Google Ireland Limited (Ireland) (for users in the European Economic Area (EEA) and Switzerland). General information on data protection is available in Google's Privacy Policy and related information on privacy, security measures, the processing of personal data, cookies and personalised advertising settings.
- Microsoft services: Provided by Microsoft Ireland Operations Limited (Ireland) for users in the European Economic Area (EEA), Switzerland and the United Kingdom, and by Microsoft Corporation (USA) for users in the rest of the world. Further information can be found in Microsoft's Privacy Policy and Privacy & Security information.
13.1 Digital Infrastructure
We use specialised third-party services to provide the digital infrastructure required for our activities and services. This includes, for example, hosting and storage services from selected providers.
In particular, we use:
- Cyon – Hosting services provided by cyon AG (Switzerland). Further information is available in Cyon's Privacy Policy.
13.2 Online Collaboration
We use third-party services to facilitate online collaboration. In addition to this Privacy Policy, the terms of use, privacy policies and other conditions of the respective services may also apply where relevant.
In particular, we use:
- Microsoft Teams – A platform for online collaboration, including audio and video conferencing, provided by Microsoft. Further information is available in Microsoft's documentation on Security and Compliance in Microsoft Teams, particularly the sections relating to data protection.
13.3 Social Media Features and Content
We use third-party services and plugins to embed functions and content from social media platforms and to enable the sharing of content via social media and other channels.
In particular, we use:
- Facebook Social Plugins – To embed Facebook features and content, such as the Like and Share buttons. Provided by Meta Platforms Ireland Limited (Ireland) and other Meta group companies, including entities in the USA. Further information is available in Facebook's Privacy Policy.
- Instagram Platform – To embed Instagram content. Provided by Meta Platforms Ireland Limited (Ireland) and other Meta group companies, including entities in the USA. Further information is available in Instagram's and Facebook's Privacy Policies.
- LinkedIn Consumer Solutions Platform – To embed LinkedIn features and content, including the Share Plugin. Provided by Microsoft. Further information is available in LinkedIn's Privacy Policy, Cookie Policy, Privacy settings, and options to opt out of email, SMS and interest-based advertising.
13.4 Maps
We use third-party services to embed maps into our website.
In particular, we use:
- Google Maps, including the Google Maps Platform – Mapping services provided by Google. Further information is available in Google's documentation on How Google Uses Location Information.
13.5 Digital Content
We use specialised third-party services to integrate digital content into our website. Such content includes images, videos, music and podcasts.
In particular, we use:
- Vimeo – Video hosting platform provided by Vimeo Inc. (USA). Further information is available in Vimeo's Privacy Policy and information on Private Video Hosting.
- YouTube – Video hosting platform provided by Google. Further information is available in YouTube's Privacy & Safety Centre and Your Data in YouTube.
13.6 Documents
We use third-party services to embed documents into our website. These may include PDF files, presentations, spreadsheets and text documents. Such services may enable users not only to view documents but also to edit or comment on them.
In particular, we use:
- Canva – Digital document services provided by Canva Pty Ltd (Australia). Further information is available in Canva's Privacy Policy, Trust Centre, Security information and Cookie Policy.
- Google Docs – Documents, presentations and spreadsheets provided by Google. Further information is available in Google's documentation on privacy in Google Docs, Sheets and Slides.
- Issuu – Digital documents and electronic publications provided by Issuu Inc. (USA). Further information is available in Issuu's Privacy Policy.
- Microsoft 365 – Documents, presentations and spreadsheets provided by Microsoft. Further information is available in Microsoft's information on Privacy and Security in Microsoft 365.
13.7 Payments
We use specialised payment service providers to ensure that payments are processed securely and reliably. The legal terms of the respective payment providers, such as their terms and conditions and privacy policies, also apply to payment processing.
In particular, we use:
- PostFinance – Payment processing services provided by PostFinance AG (Switzerland). Further information is available in PostFinance's Legal Information, Accessibility and Privacy Policy.
- TWINT – Payment processing services in Switzerland provided by TWINT AG (Switzerland). Further information is available in TWINT's Privacy Policy and Security information.
- Worldline – Payment processing services, including mobile payment solutions, provided by Worldline SA (France), Worldline Schweiz AG (Switzerland) and other Worldline group companies worldwide, including the USA. Further information is available in Worldline's Privacy Policy, Responsible Data Programme and Cookie Policy.
13.8 Advertising
We use third-party advertising services, such as social media platforms and search engines, to display targeted advertisements for our activities and services.
Our aim is to reach individuals who are already interested, or may be interested, in our activities and services (remarketing and targeting). For this purpose, we may share relevant information, which may include personal data, with third parties that enable such advertising. We may also measure the effectiveness of our advertising, in particular whether it results in visits to our website (conversion tracking).
Third parties on whose platforms we advertise and where you maintain a user account may be able to associate your use of our website with your profile on their platform.
In particular, we use:
- Meta Ads – Social media advertising on Facebook and Instagram, provided by Meta Platforms Ireland Limited (Ireland) and other Meta group companies, including entities in the USA. This may include targeting and retargeting using the Meta Pixel, Custom Audiences and Lookalike Audiences. Further information is available in Meta's Privacy Policy and Advertising Preferences (login required).
14. Performance and Reach Measurement
We try to measure the success and reach of our activities and services. As part of this process, we can also measure the impact of third-party references or examine how different parts or versions of our digital presence are used (“A/B testing” method). Based on the results of these performance and reach measurements, we can identify and correct errors, strengthen popular content, or make improvements.
For performance and reach measurement, the IP addresses of individual users are generally collected in most cases. In this context, IP addresses are usually shortened (“IP masking”) in order to comply with the principle of data minimisation through appropriate pseudonymisation.
Cookies may be used and user profiles may be created as part of performance and reach measurement. Any user profiles created may include, for example, information about the individual pages visited or content viewed on our digital presence, details about the size of the screen or browser window, and the approximate location of the user. In principle, any user profiles created are generated exclusively in pseudonymised form and are not used to identify individual users. Certain third-party services where users are logged in may potentially associate the use of our online services with the user account or user profile held by the respective service.
We use the following services in particular:
- Google Marketing Platform: Performance and reach measurement, in particular using Google Analytics; provider: Google. Google Marketing Platform-specific information: Measurement may also take place across different browsers and devices (cross-device tracking). Further information can be found in Google Analytics’ privacy policy and in the “Browser Add-on to Disable Google Analytics”.
15. Final Notes on this Privacy Policy
We created this Privacy Policy using the privacy policy generator provided by Datenschutzpartner.
We may update this Privacy Policy at any time. We will inform users of any updates in an appropriate manner, in particular by publishing the current version of the Privacy Policy on our website.