Data Privacy
1. Brief Overview
This privacy policy provides information on how ZEJA GmbH processes personal data when you visit our website, contact us, or interact with our online offers.
We process in particular technical access data, contact and communication data as well as – with your consent – information about the use of our website. In doing so, Framer, Google Analytics, Google Ads, the Meta Pixel as well as embedded content from YouTube, Vimeo, and Google Maps may be used, among others.
Non-essential analysis, marketing, and third-party services are generally only activated after you have given your consent via our cookie banner.
We do not sell personal data.
2. Controller
The body responsible for processing your personal data is:
ZEJA GmbH
Amthofstrasse 16
8630 Rüti
Switzerland
Email: info@zeja.ch
Website: zeja.ch
Inquiries regarding data protection as well as requests to exercise your data protection rights can be sent to the email address mentioned above.
3. Applicable Data Protection Law
We process personal data in particular in accordance with the Swiss Federal Act on Data Protection, the associated Data Protection Ordinance and – as far as applicable – the General Data Protection Regulation of the European Union.
The GDPR is applicable in particular if our data processing affects individuals in the European Economic Area or falls within the territorial scope of the GDPR for other reasons.
Insofar as the GDPR is applicable, the processing is based in particular on the following legal grounds:
Your consent pursuant to Art. 6 para. 1 lit. a GDPR;
the performance of a contract or pre-contractual measures pursuant to Art. 6 para. 1 lit. b GDPR;
compliance with legal obligations pursuant to Art. 6 para. 1 lit. c GDPR;
our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR.
Our legitimate interests include, in particular, the secure and economic operation of our website, communication with interested parties and customers, the improvement of our services, range measurement, performance measurement of our advertising, as well as the prevention of abuse and cyber attacks.
According to Swiss data protection law, we process personal data in particular in accordance with the principles of lawfulness, proportionality, purpose limitation, transparency, and data security. Where necessary, we base processing on consent, a legal basis, a contract, or overriding private or public interests.
4. Definitions
Personal data means any information relating to an identified or identifiable natural person.
Processing means any operation with personal data, in particular obtaining, collecting, storing, using, modifying, disclosing, transmitting, archiving, deleting, or destroying.
Sensitive personal data includes in particular information about health, religious or political views, intimate sphere, genetic and biometric data, as well as certain information about criminal or administrative proceedings.
5. Which Personal Data We Process
Depending on how you use our website, we process in particular the following categories of personal data:
Technical Data
This includes in particular:
IP address;
date and time of access;
pages and files accessed;
amount of data transferred;
referrer URL;
browser type and browser version;
operating system;
device type;
screen resolution;
language settings;
approximate geographical region;
Internet Service Provider;
technical identifiers;
cookie and tracking IDs;
protocol and security data.
Usage Data
This includes in particular:
visited pages;
dwell time;
clicks and interactions;
scrolling behavior;
navigation paths;
entry and exit pages;
played videos;
form interactions;
campaign and conversion data;
information on which ad or website brought you to us.
Contact and Communication Data
When you contact us, we process in particular:
first and last name;
company;
email address;
phone number;
content of your inquiry;
uploaded or submitted documents;
time and course of communication;
other details you share voluntarily.
Contract and Business Data
If a business relationship results from an inquiry, we also process in particular:
company and contact details;
project information;
offers and contracts;
services and orders;
payment and billing information;
correspondence;
business documents;
information on contract processing.
Please do not submit any sensitive personal data to us via freely accessible forms or unencrypted emails unless this is explicitly required and agreed upon with us.
6. Purposes of Data Processing
We process personal data in particular for the following purposes:
providing and operating our website;
technically correct presentation of our content;
ensuring stability and security;
detecting and preventing abuse, fraud, and cyber attacks;
processing contact requests;
initiating and conducting business relationships;
creating offers;
providing our services;
customer care;
analyzing the use of our website;
improving user experience;
optimizing our content and offers;
measuring the reach of our website;
measuring the success of ad campaigns;
displaying relevant advertising;
creating target groups for advertising campaigns;
remarketing and retargeting;
complying with legal retention and documentation obligations;
enforcing or defending legal claims;
administrative and internal organizational purposes.
7. Hosting and Website Builder Framer
Our website is operated using the website builder and hosting infrastructure of Framer.
The provider is Framer B.V., based in the Netherlands.
When accessing our website, technical data is transmitted to Framer or to hosting, cloud, and infrastructure partners used by Framer. This may include, in particular, the IP address, browser information, device information, visited pages, access times, and technical log data.
Processing is necessary to deliver our website, ensure its stability and security, and detect technical errors and unauthorized access.
Insofar as Framer processes personal data on our behalf, Framer acts as a data processor. Framer may use other sub-processors.
Framer and its sub-processors may also process data outside of Switzerland or the European Economic Area. According to Framer, suitable guarantees are used for such transfers, for example, adequacy decisions, applicable data protection frameworks, or standard contractual clauses.
8. Server Log Files
When you access our website, technical information can be automatically stored in so-called server log files.
This information includes in particular:
IP address;
date and time;
accessed page or file;
referrer URL;
browser and browser version;
operating system;
hostname of the accessing device;
amount of data transferred;
HTTP status code;
technical error and security information.
The log data is used to enable the operation of the website, analyze technical errors, detect attacks, and ensure the security of our systems.
Log data is only kept as long as necessary for the mentioned purposes. A longer retention period may occur if a security-relevant event needs to be investigated, legal obligations exist, or the data is needed to enforce or defend claims.
9. Framer Analytics
Framer can provide an integrated, privacy-focused statistics function for our website.
According to Framer, Framer Analytics does not use cookies or persistent user identifiers. To determine daily visitor numbers, the IP address and user agent are processed with a daily changing cryptographic value. This value is reset daily.
Framer Analytics provides us in particular with the following aggregated information:
number of page views;
number of daily visitors;
frequently accessed pages;
origin or access sources;
general usage statistics.
We use this information to understand the use and reach of our website and to improve our offer.
10. Cookies and Similar Technologies
Our website uses cookies as well as similar technologies such as Local Storage, pixels, tags, scripts, and comparable identifiers.
Cookies are small files stored on your end device. They can contain information about your device, your settings, or the use of a website.
Necessary Technologies
Necessary cookies and technologies are required for the website to function, to be securely delivered, and for your privacy or cookie settings to be saved. These technologies can be used without prior consent, as far as their use is technically necessary and legally permissible.
Functional Technologies
Functional technologies enable additional functions, such as the presentation of external videos, maps, or other content.
Analysis Technologies
Analysis technologies help us understand how our website is used. This includes, in particular, page views, interactions, time spent, access sources, and technical information.
Marketing Technologies
Marketing technologies help us measure advertising campaigns, create target groups, recognize returning visitors, and display more relevant advertising on platforms such as Google, Facebook, or Instagram.
Consent Management
Non-essential analysis, marketing, and third-party technologies are generally only activated after you have given consent via our cookie banner.
You can:
accept all non-essential services;
reject all non-essential services;
select individual categories;
change or withdraw your choice later.
You can change your selection at any time via the “Cookie Settings” link in the footer of our website. The withdrawal of consent is effective for the future. The lawfulness of the processing carried out until the withdrawal remains unaffected. You can also delete or block cookies via your browser settings. In the event of a complete block, individual functions of our website may be restricted.
11. Google Tag Manager
Where we use the Google Tag Manager, we use it for the central management of analysis and marketing tags.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
The Google Tag Manager is used for the technical triggering and management of other services. It does not create independent user profiles. When called up, however, technical data, in particular the IP address and device information, may be transmitted to Google.
Analysis and marketing services integrated via Google Tag Manager are only activated in accordance with the choice you made in the cookie banner.
12. Google Analytics 4
We use Google Analytics 4, a web analytics service from Google.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited. Further processing may be carried out by Google LLC and other Google companies.
Google Analytics helps us understand how visitors use our website. In particular, the following information can be processed:
visited pages;
time and duration of the visit;
clicks and interactions;
scrolling behavior;
session information;
referrer URL;
campaign information;
browser and device information;
operating system;
screen resolution;
approximate geographical region;
technical identifiers;
cookie and client IDs;
information about conversions.
Google uses the IP address technically to derive, among other things, an approximate geographical region. According to Google, IP addresses of users from Switzerland, the European Economic Area, and the United Kingdom are discarded before logging and are not permanently stored.
Google Analytics is generally only activated after your consent. The legal basis, as far as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
We use the information obtained to analyze website usage, compile aggregated statistics, improve our content, and measure our marketing activities.
The retention period for user and event-related data in our Google Analytics property is set to a maximum of 14 months. Aggregated or anonymized reports may be kept longer.
Where possible, we disable or restrict the use of analytics data for personalized advertising. Depending on our configuration and your consent, Google Analytics and Google Ads may be linked.
You can withdraw your consent at any time via the cookie settings. In addition, Google provides a browser add-on to disable Google Analytics.
13. Google Ads and Conversion Tracking
We use Google Ads to promote our services in Google search, on websites, and within the Google advertising network.
In connection with Google Ads, we may in particular use the following functions:
conversion tracking;
campaign and success measurement;
remarketing or retargeting;
target group formation;
measurement of website visits and contact inquiries;
analysis of interactions with our ads.
If you reach our website via a Google ad or perform a defined action, Google may store a cookie or a comparable identifier.
In particular, the following data can be processed:
IP address;
cookie and device identifiers;
browser and device information;
visited pages;
time of visit;
interactions and clicks;
information about the clicked ad;
campaign parameters;
submitted contact requests;
measured conversions.
Google can link this information with other data, in particular if you are logged into a Google account and have activated corresponding personalization settings.
Google Ads and the associated marketing technologies are generally only activated after your consent.
The legal basis, as far as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
You can withdraw your consent at any time via our cookie settings. You can also manage personalized advertising via the advertising and privacy settings of your Google account.
14. Meta Pixel and Meta Ads
We use the Meta Pixel to measure and optimize our advertising campaigns on Facebook and Instagram.
The provider for users in Switzerland and the European Economic Area is generally Meta Platforms Ireland Limited. Further processing can occur in particular by Meta Platforms, Inc. in the USA.
The Meta Pixel enables us in particular:
to measure whether users visit our website after seeing an ad;
to recognize which pages or offers were accessed;
to measure contact requests and other conversions;
to create target groups for advertising campaigns;
to re-target former website visitors with advertising;
to build lookalike audiences;
to analyze the effectiveness of our ads;
to better tailor ads to potential interests.
In doing so, the following data in particular can be transmitted to Meta:
IP address;
browser and device information;
operating system;
accessed URL;
referrer URL;
time of visit;
cookie and pixel IDs;
Facebook or Meta identifiers;
campaign information;
click and interaction data;
triggered events;
information about contact requests or other conversions.
Meta can, if necessary, assign this information to a Facebook or Instagram account and use it for its own advertising, analysis, security, and personalization purposes. This can also happen if you are not logged into Facebook or Instagram or do not have a corresponding account.
The Meta Pixel is generally only activated after your consent.
The legal basis, as far as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
In connection with the collection and transmission of certain event data, we and Meta can be jointly responsible under data protection law, as far as this is provided for under the applicable law. Meta in particular takes over processing within its platforms as well as compliance with certain data subject rights with regard to the data stored by Meta.
You can withdraw your consent at any time via our cookie settings. You can also manage the use of your data for personalized advertising via the privacy and advertising settings of Facebook and Instagram.
15. YouTube Videos
Videos from the YouTube platform may be embedded on our website.
YouTube is a Google service. The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
When loading or playing an embedded YouTube video, the following data in particular can be transmitted to Google or YouTube:
IP address;
browser and device information;
visited page;
referrer URL;
time of access;
cookie and device identifiers;
information about the played video;
interactions with the video player.
If you are logged into a Google or YouTube account, Google can assign the visit and interaction to your account.
As far as technically possible, we use YouTube in privacy-enhanced mode. Nevertheless, data can be transmitted to Google at the latest when playing a video.
YouTube videos are generally only loaded after you have agreed to the category for external media or functional services. Before your consent, only a placeholder is displayed.
The legal basis, as far as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
16. Vimeo Videos
Videos from the Vimeo platform may be embedded on our website.
The provider is Vimeo.com, Inc., based in the USA.
When loading or playing a Vimeo video, the following data in particular can be processed:
IP address;
browser and device information;
visited page;
referrer URL;
time of access;
cookie and device identifiers;
information about the played video;
interactions with the video player.
If you are logged into a Vimeo account, Vimeo can associate the interaction with your account if necessary.
Vimeo videos are generally only loaded after you have agreed to the category for external media or functional services. Before your consent, a placeholder can be displayed.
The legal basis, as far as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
When using Vimeo, data may be transferred to the USA or other states. According to the provider, such transfers take place on the basis of the respectively applicable data protection mechanisms and contractual guarantees.
17. Google Maps
Maps and location information from Google Maps may be embedded on our website.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
When loading a Google Maps map, the following data in particular can be transmitted to Google:
IP address;
browser and device information;
operating system;
visited page;
time of access;
approximate location information;
cookie and device identifiers;
interactions with the map.
If you are logged into a Google account, Google can associate the visit or use of the map with your account.
Google Maps is generally only loaded after you have agreed to the category for external media or functional services. Before your consent, a placeholder or a simple link to the map view can be displayed instead.
The legal basis, as far as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
18. Contact Form
If you contact us via a contact form, we process the data you enter to answer your inquiry
This includes in particular:
name;
email address;
phone number;
company;
subject;
content of the message;
voluntarily submitted additional information;
time of inquiry;
technical information to prevent abuse.
The form data is transmitted to us via the form and hosting infrastructure provided by Framer or via a service connected to the website.
The processing is carried out to communicate with you, to answer your inquiry, and, if necessary, to prepare or carry out a business relationship.
To the extent that the GDPR is applicable, the processing takes place depending on the content of your request, in particular on the basis of:
Art. 6 para. 1 lit. b GDPR for pre-contractual or contractual inquiries;
Art. 6 para. 1 lit. f GDPR for general business inquiries;
Art. 6 para. 1 lit. a GDPR if you have expressly consented to a specific processing.
Inquiries that do not result in a business relationship are generally deleted as soon as they have been finally processed and there are no legal, security-related, or regulatory reasons for further retention. Usually, deletion occurs at the latest after twelve months.
If a business relationship arises, the data may be stored longer in accordance with legal retention obligations.
19. Contact by Email or Phone
If you contact us by email or phone, we process your contact details and the content of your message to handle your request.
During communication by email, data is transmitted via the participating email and hosting providers. These providers can process technical connection and communication data.
Unencrypted emails are not a fully secure means of communication. Therefore, do not send us any sensitive or confidential information by unencrypted email.
Processing is carried out in particular for communication, to answer your inquiry, and to initiate or conduct a business relationship.
20. Links to Social Networks
Our website may contain links to our profiles on social networks, in particular Facebook, Instagram, LinkedIn, TikTok, YouTube, or Vimeo.
With simple links, data is generally only transmitted to the respective platform when you click on the link.
After clicking, the privacy policy of the respective platform applies. The providers can collect from which website you reached their platform. If you are logged in there, the visit can be associated with your user account.
We have no complete influence over which data the platforms subsequently process and for what purposes of their own they use them.
21. Recipients and Processors
We may disclose personal data to external service providers and recipients, as far as this is necessary for the purposes described in this privacy policy.
This includes in particular:
hosting and website providers;
cloud and infrastructure providers;
IT and security service providers;
email and communication providers;
analysis and statistics services;
advertising and marketing platforms;
video, map, and media services;
agencies and technical partners;
accounting and administration service providers;
banks and payment service providers;
insurances;
lawyers, tax advisors, and other consultants;
authorities and courts, if there is a legal obligation;
potential buyers or business partners in the context of a corporate transaction.
Service providers who process personal data on our behalf are contractually obligated, where necessary, to process the data only in accordance with our instructions, to implement appropriate security measures, and to comply with the applicable data protection regulations.
We do not sell personal data and do not share personal data with uninvolved third parties without a legal basis.
22. Processing of Personal Data Abroad
Our service providers and their subcontractors can process personal data in Switzerland, the European Economic Area, the USA, and in other countries.
Some of these countries may not have data protection laws that ensure an adequate level of data protection from a Swiss or European perspective.
If personal data is transferred to a country without an recognized adequate level of data protection, we base the transfer – where necessary – in particular on:
an adequacy decision;
standard contractual clauses;
standard contractual clauses adapted for Switzerland;
an recognized data protection framework;
binding corporate rules;
an explicit consent;
the necessity for contract fulfillment;
the establishment, exercise, or defense of legal claims;
another legally permissible exception.
Despite contractual and organizational protective measures, when processing abroad, it cannot be completely ruled out that foreign authorities access data within the scope of their legal powers.
23. Retention Period
We retain personal data only as long as necessary for the respective purpose or as long as there are legal or contractual retention obligations.
When determining the retention period, we consider in particular:
the purpose of data processing;
the type and sensitivity of the data;
legal retention obligations;
ongoing contractual relationships;
statutes of limitation;
potential legal claims;
security and verification requirements;
technical storage and backup cycles.
Business documents, accounting records, and contract-relevant correspondence can generally be retained for ten years in accordance with legal requirements.
Data from contact inquiries that do not lead to a business relationship are generally deleted after completion of the inquiry or at the latest after twelve months, unless there are reasons for longer retention.
Cookie and consent information is stored according to its technical lifetime and legal verification obligations.
After expiration of the retention period, the data is deleted, anonymized, or blocked, as far as deletion is technically not immediately possible.
24. Data Security
We take appropriate technical and organizational security measures to protect personal data from loss, misuse, unauthorized access, alteration, disclosure, or destruction.
These measures may include in particular:
encrypted data transmission via TLS/HTTPS;
access restrictions;
role and authorization concepts;
strong passwords and multi-factor authentication;
regular updates of the systems used;
backups;
logging of security-relevant processes;
protection against malware and unauthorized access;
selection of suitable service providers;
internal data protection and security requirements.
Fully risk-free data transmission and storage cannot be guaranteed despite appropriate protective measures.
25. Data Breaches
Should a violation of data security occur, we immediately investigate the incident and take the necessary measures.
To the extent required by law, we inform the responsible data protection supervisory authority and, if necessary, the affected individuals.
26. Your Rights
Depending on the applicable data protection law and the respective prerequisites, you can in particular assert the following rights:
information about whether and which personal data we process about you;
issuance of a copy of your personal data;
rectification of incorrect or incomplete data;
deletion of your personal data;
restriction of data processing;
objection to certain data processings;
withdrawal of a granted consent;
issuance or transfer of certain personal data in a common electronic format;
information about the origin of the data;
information about recipients or categories of recipients;
review of an automated individual decision;
complaint to a competent data protection supervisory authority.
These rights do not apply without restriction. We can reject, restrict, or postpone a request if legal requirements are met, overriding interests conflict, retention obligations exist, or the request is obviously unfounded or disproportionate.
To process a request, we can demand suitable proof of identity. This is to prevent personal data from being disclosed to unauthorized persons.
To exercise your rights, contact us at: info@zeja.ch
27. Withdrawal of Consent
You can withdraw a granted consent at any time with effect for the future.
Consents for cookies, analysis, marketing, and third-party services can be changed or withdrawn via the “Cookie Settings” link in the footer of our website.
You can withdraw other consents by email to info@zeja.ch.
The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal.
28. Objection to Direct Marketing
To the extent that we process personal data for direct marketing, you can object to this processing at any time.
After your objection, we will no longer use your personal data for corresponding direct marketing. Minimal block information may be retained to ensure that your objection is taken into account in the future.
29. Automated Decisions and Profiling
Our analysis and advertising services can use data to form user groups, derive interests, or display advertising more targetedly. This can be considered profiling under data protection law.
On the basis of this information, we do not make exclusively automated decisions that have legal effects on you or significantly affect you in a similar way.
30. Data of Children and Teenagers
Our website is primarily aimed at companies, business clients, and adult prospects.
We do not knowingly collect personal data of children unless consent of the legal guardian or another legal basis is present.
Legal guardians can contact us if they suspect that personal data of a child was submitted to us without a sufficient basis.
31. Obligation to Provide Personal Data
In principle, there is no obligation to provide us with personal data.
Certain information is, however, required so that we can answer inquiries, create offers, conclude contracts, or provide services. Without this information, we may not be able to offer corresponding services or only to a limited extent.
32. External Websites
Our website may contain links to websites and offers of third parties.
The respective operators are responsible for the content and privacy practices of these external offers. We recommend that you read the privacy policies of the providers concerned.
33. Competent Data Protection Supervisory Authority
For data protection concerns in Switzerland, you can contact the Federal Data Protection and Information Commissioner:
Federal Data Protection and Information Commissioner – FDPIC
Switzerland
Insofar as the GDPR is applicable, you also have the right to lodge a complaint with a competent data protection supervisory authority in the European Economic Area, in particular at your habitual residence, place of work, or place of the alleged data protection violation.
We recommend that you first contact us directly so that we can review and address your concern.
34. Changes to This Privacy Policy
We may adapt this privacy policy at any time, in particular if we change our website, our services, the technologies used, or the legal requirements.
The version published on our website shall apply.
In the event of significant changes, we may point this out separately on our website.
Status: July 21, 2026
ZEJA GmbH
Amthofstrasse 16
8630 Rüti
Switzerland
info@zeja.ch
1. Brief Overview
This Privacy Policy provides information on how ZEJA GmbH processes personal data when you visit our website, contact us, or interact with our online offers.
In particular, we process technical access data, contact and communication data, and – with your consent – information about the use of our website. Framer, Google Analytics, Google Ads, the Meta Pixel, as well as embedded content from YouTube, Vimeo, and Google Maps may be used, among others.
Non-essential analytical, marketing, and third-party services are generally only activated after you have given your consent via our cookie banner.
We do not sell personal data.
2. Controller
The entity responsible for processing your personal data is:
ZEJA GmbH
Amthofstrasse 16
8630 Rüti
Switzerland
Email: info@zeja.ch
Website: zeja.ch
Inquiries regarding data protection and requests to exercise your data protection rights can be sent to the email address mentioned above.
3. Applicable Data Protection Law
We process personal data in particular in accordance with the Swiss Federal Act on Data Protection, the corresponding Data Protection Ordinance and – as far as applicable – the General Data Protection Regulation of the European Union.
The GDPR is applicable in particular if our data processing affects individuals in the European Economic Area or falls within the territorial scope of the GDPR for other reasons.
Insofar as the GDPR is applicable, processing is carried out in particular based on the following legal grounds:
Your consent pursuant to Art. 6 para. 1 lit. a GDPR;
the performance of a contract or pre-contractual measures pursuant to Art. 6 para. 1 lit. b GDPR;
compliance with legal obligations pursuant to Art. 6 para. 1 lit. c GDPR;
our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR.
Our legitimate interests include, in particular, the secure and cost-effective operation of our website, communication with prospects and customers, the improvement of our services, reach measurement, evaluating the success of our advertising, and preventing abuse and cyberattacks.
According to Swiss data protection law, we process personal data in particular in accordance with the principles of lawfulness, proportionality, purpose limitation, transparency, and data security. Where necessary, we base processing on consent, a legal basis, a contract, or overriding private or public interests.
4. Definitions
Personal data means all information relating to an identified or identifiable natural person.
Processing means any operation with personal data, irrespective of the means and procedures applied, in particular the collection, recording, storage, use, modification, disclosure, transmission, archiving, erasure, or destruction.
Sensitive personal data includes, in particular, data on health, religious or political views, the intimate sphere, genetic and biometric data, as well as certain information on criminal or administrative proceedings.
5. Which Personal Data We Process
Depending on how you use our website, we process the following categories of personal data in particular:
Technical Data
This includes in particular:
IP address;
date and time of access;
pages and files accessed;
amount of data transferred;
referrer URL;
browser type and browser version;
operating system;
device type;
screen resolution;
language settings;
approximate geographical region;
Internet Service Provider;
technical identifiers;
cookie and tracking IDs;
protocol and security data.
Usage Data
This includes in particular:
visited pages;
duration of stay;
clicks and interactions;
scroll behavior;
navigation paths;
entry and exit pages;
videos played;
form interactions;
campaign and conversion data;
information on which ad or website brought you to us.
Contact and Communication Data
When you contact us, we process in particular:
First and last name;
company;
email address;
phone number;
content of your inquiry;
uploaded or submitted documents;
time and history of communication;
other information you voluntarily provide.
Contractual and Business Data
If a business relationship results from an inquiry, we additionally process in particular:
company and contact details;
project information;
offers and contracts;
services and orders;
payment and billing information;
correspondence;
business documents;
information on contract execution.
Please do not submit any sensitive personal data through freely accessible forms or unencrypted emails unless this is explicitly required and agreed upon with us.
6. Purposes of Data Processing
We process personal data in particular for the following purposes:
provision and operation of our website;
technically correct display of our content;
ensuring stability and security;
detecting and preventing abuse, fraud, and cyberattacks;
processing contact inquiries;
initiation and implementation of business relationships;
preparation of offers;
provision of our services;
customer support;
analysis of the use of our website;
improvement of user-friendliness;
optimization of our content and offers;
measuring the reach of our website;
measuring the success of advertising campaigns;
delivery of relevant advertising;
targeting user groups for advertising campaigns;
remarketing and retargeting;
compliance with statutory retention and documentation obligations;
assertion or defense of legal claims;
administrative and internal organizational purposes.
7. Hosting and Framer Website Builder
Our website is operated using the website builder and hosting infrastructure of Framer.
The provider is Framer B.V., based in the Netherlands.
When you visit our website, technical data is transmitted to Framer or to hosting, cloud, and infrastructure partners used by Framer. This may include, in particular, the IP address, browser information, device information, accessed pages, access times, and technical log data.
Processing is necessary to deliver our website, ensure its stability and security, and detect technical errors and unauthorized access.
To the extent that Framer processes personal data on our behalf, Framer acts as a data processor. Framer may use other sub-processors.
Framer and its sub-processors may also process data outside of Switzerland or the European Economic Area. According to Framer, appropriate safeguards, such as adequacy decisions, applicable data protection frameworks, or standard contractual clauses, are used for such transfers.
8. Server Log Files
When you access our website, technical information may automatically be stored in so-called server log files.
This information includes in particular:
IP address;
date and time;
accessed page or file;
referrer URL;
browser and browser version;
operating system;
hostname of the accessing device;
amount of data transferred;
HTTP status code;
technical error and security information.
The log data is used to operate the website, analyze technical errors, detect attacks, and ensure the security of our systems.
Log data is only kept for as long as is necessary for the stated purposes. A longer retention period may occur if a security-relevant event needs to be investigated, legal obligations exist, or the data is needed to assert or defend claims.
9. Framer Analytics
Framer may provide an integrated, privacy-focused statistics feature for our website.
According to Framer, Framer Analytics does not use cookies or permanent user identifiers. To determine daily visitor numbers, the IP address and user agent are processed with a cryptographically hashed value that changes daily. This value is reset daily.
In particular, Framer Analytics provides us with the following aggregated information:
number of page views;
number of daily visitors;
frequently accessed pages;
referrers or sources of access;
general usage statistics.
We use this information to understand the usage and reach of our website and to improve our services.
10. Cookies and Similar Technologies
Our website uses cookies and similar technologies such as local storage, pixels, tags, scripts, and comparable identifiers.
Cookies are small files stored on your device. They can contain information about your device, your settings, or your use of a website.
Necessary Technologies
Necessary cookies and technologies are required for the website to function, to be delivered securely, and to save your privacy or cookie settings. These technologies can be used without prior consent as far as their use is technically required and legally permitted.
Functional Technologies
Functional technologies enable additional features, such as displaying external videos, maps, or other content.
Analytical Technologies
Analytical technologies help us understand how our website is used. This includes page views, interactions, duration of stay, sources of access, and technical information.
Marketing Technologies
Marketing technologies help us measure advertising campaigns, target user groups, recognize returning visitors, and display more relevant advertising on platforms such as Google, Facebook, or Instagram.
Consent Management
Non-essential analytical, marketing, and third-party technologies are generally only activated after you have given your consent via our cookie banner.
You can:
accept all non-essential services;
decline all non-essential services;
select individual categories;
change or withdraw your selection later.
You can change your selection at any time via the "Cookie Settings" link in the footer of our website. The withdrawal of consent is effective for the future. The lawfulness of the processing carried out up to the time of withdrawal remains unaffected. You can also delete or block cookies via your browser settings. If you block cookies completely, individual features of our website may be restricted.
11. Google Tag Manager
Insofar as we use Google Tag Manager, we use it for the central management of analysis and marketing tags.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
The Google Tag Manager is used to technically trigger and manage other services. It does not create independent usage profiles. However, during access, technical data, in particular the IP address and device information, may be transmitted to Google.
Analysis and marketing services integrated via Google Tag Manager are only activated in accordance with the selection you made in the cookie banner.
12. Google Analytics 4
We use Google Analytics 4, a web analysis service from Google.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited. Further processing may be carried out by Google LLC and other Google companies.
Google Analytics helps us understand how visitors use our website. In particular, the following information may be processed:
pages accessed;
time and duration of the visit;
clicks and interactions;
scroll behavior;
session information;
referrer URL;
campaign information;
browser and device information;
operating system;
screen resolution;
approximate geographical region;
technical identifiers;
cookie and client IDs;
information about conversions.
Google uses the IP address technically, among other things, to derive an approximate geographical region. According to Google, IP addresses of users from Switzerland, the European Economic Area, and the United Kingdom are discarded prior to logging and are not permanently stored.
Google Analytics is generally only activated after your consent. The legal basis, insofar as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
We use the information obtained to analyze website usage, compile aggregated statistics, improve our content, and measure our marketing activities.
The retention period for user- and event-related data in our Google Analytics property is set to a maximum of 14 months. Aggregated or anonymized reports can be kept longer.
As far as possible, we deactivate or restrict the use of analytics data for personalized advertising. Depending on our configuration and your consent, Google Analytics and Google Ads may be linked.
You can withdraw your consent at any time via the cookie settings. In addition, Google provides a browser add-on to deactivate Google Analytics.
13. Google Ads and Conversion Tracking
We use Google Ads to advertise our services in Google Search, on websites, and within the Google advertising network.
In connection with Google Ads, we may use the following features in particular:
conversion tracking;
campaign and success measurement;
remarketing or retargeting;
target group creation;
measuring website visits and contact inquiries;
analyzing interactions with our ads.
If you reach our website via a Google ad or perform a defined action, Google may store a cookie or a comparable identifier.
In particular, the following data may be processed:
IP address;
cookie and device identifiers;
browser and device information;
pages visited;
time of visit;
interactions and clicks;
information about the clicked ad;
campaign parameters;
submitted contact inquiries;
measured conversions.
Google can link this information with other data, particularly if you are logged into a Google account and have activated corresponding personalization settings.
Google Ads and the associated marketing technologies are generally only activated after your consent.
The legal basis, insofar as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
You can withdraw your consent at any time via our cookie settings. You can additionally manage personalized advertising via the advertising and privacy settings of your Google account.
14. Meta Pixel and Meta Ads
We use the Meta Pixel to measure and optimize our advertising campaigns on Facebook and Instagram.
The provider for users in Switzerland and the European Economic Area is generally Meta Platforms Ireland Limited. Further processing may be carried out in particular by Meta Platforms, Inc. in the USA.
The Meta Pixel enables us in particular:
to measure whether users visit our website after seeing an ad;
to detect which pages or offers were accessed;
to measure contact inquiries and other conversions;
to create target groups for advertising campaigns;
to retarget previous website visitors with advertising;
to build lookalike audiences;
to analyze the effectiveness of our ads;
to better tailor ads to potential interests.
In doing so, the following data in particular may be transmitted to Meta:
IP address;
browser and device information;
operating system;
accessed URL;
referrer URL;
time of visit;
cookie and pixel IDs;
Facebook or Meta identifiers;
campaign information;
click and interaction data;
triggered events;
information about contact inquiries or other conversions.
Meta may associate this information with a Facebook or Instagram account and use it for its own advertising, analysis, security, and personalization purposes. This can also happen if you are not logged into Facebook or Instagram or do not have a corresponding account.
The Meta Pixel is generally only activated after your consent.
The legal basis, insofar as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
In connection with the collection and transmission of certain event data, we and Meta may be jointly responsible under data protection law, to the extent provided for by applicable law. Meta assumes responsibility in particular for processing within its platforms as well as the fulfillment of certain data subject rights regarding the data stored by Meta.
You can withdraw your consent at any time via our cookie settings. You can additionally manage the use of your data for personalized advertising via the privacy and ad settings of Facebook and Instagram.
15. YouTube Videos
Videos from the YouTube platform may be embedded on our website.
YouTube is a service of Google. The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
When loading or playing an embedded YouTube video, the following data in particular may be transmitted to Google or YouTube:
IP address;
browser and device information;
page accessed;
referrer URL;
time of access;
cookie and device identifiers;
information about the video played;
interactions with the video player.
If you are logged into a Google or YouTube account, Google can associate the visit and interaction with your account.
As far as technically possible, we use YouTube in privacy-enhanced mode. Nevertheless, data may be transmitted to Google at the latest when playing a video.
YouTube videos are generally only loaded after you have consented to the category for external media or functional services. Before your consent, only a placeholder is displayed.
The legal basis, insofar as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
16. Vimeo Videos
Videos from the Vimeo platform may be embedded on our website.
The provider is Vimeo.com, Inc., based in the USA.
When loading or playing a Vimeo video, the following data in particular may be processed:
IP address;
browser and device information;
page accessed;
referrer URL;
time of access;
cookie and device identifiers;
information about the video played;
interactions with the video player.
If you are logged into a Vimeo account, Vimeo may associate the interaction with your account.
Vimeo videos are generally only loaded after you have consented to the category for external media or functional services. Before your consent, a placeholder may be displayed.
The legal basis, insofar as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
When using Vimeo, data may be transferred to the USA or to other countries. According to the provider, such transfers take place based on the respective applicable data protection mechanisms and contractual safeguards.
17. Google Maps
Maps and location information from Google Maps may be embedded on our website.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
When loading a Google Maps map, the following data in particular may be transmitted to Google:
IP address;
browser and device information;
operating system;
page accessed;
time of access;
approximate location information;
cookie and device identifiers;
interactions with the map.
If you are logged into a Google account, Google can associate the visit or use of the map with your account.
Google Maps is generally only loaded after you have consented to the category for external media or functional services. Before your consent, a placeholder or a simple link to the map view may be displayed instead.
The legal basis, insofar as the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
18. Contact Form
If you contact us via a contact form, we process the data you enter to respond to your inquiry
This includes in particular:
name;
email address;
phone number;
company;
subject;
content of the message;
voluntarily submitted additional information;
time of the request;
technical information to prevent abuse.
The form data is transmitted to us via the form and hosting infrastructure provided by Framer or via a service connected to the website.
Processing is carried out to communicate with you, to respond to your inquiry, and, if applicable, to prepare or execute a business relationship.
Insofar as the GDPR is applicable, processing is carried out depending on the content of your inquiry, in particular on the basis of:
Art. 6 para. 1 lit. b GDPR for pre-contractual or contractual requests;
Art. 6 para. 1 lit. f GDPR for general business inquiries;
Art. 6 para. 1 lit. a GDPR if you have explicitly consented to specific processing.
Inquiries that do not lead to a business relationship are generally deleted as soon as they have been finally processed and there are no statutory, security-related, or legal reasons for further storage. As a rule, deletion occurs at the latest after twelve months.
If a business relationship arises, the data may be stored longer in accordance with statutory retention obligations.
19. Contacting us by Email or Phone
If you contact us by email or phone, we process your contact details and the content of your message to process your request.
During communication by email, data is transmitted via the email and hosting providers involved. These providers may process technical connection and communication data.
Unencrypted emails are not a completely secure means of communication. Therefore, do not send us any highly sensitive or confidential information via unencrypted email.
Processing is carried out in particular for communication, to answer your request, and to initiate or execute a business relationship.
20. Links to Social Networks
Our website may contain links to our profiles on social networks, in particular Facebook, Instagram, LinkedIn, TikTok, YouTube, or Vimeo.
In the case of simple links, data is generally only transmitted to the respective platform when you click on the link.
After clicking, the privacy policy of the respective platform applies. The providers can record from which website you reached their platform. If you are logged in there, the visit can be associated with your user account.
We do not have complete influence over which data the platforms subsequently process and for what purposes of their own they use it.
21. Recipients and Processors
We may disclose personal data to external service providers and recipients as far as necessary for the purposes described in this Privacy Policy.
This includes in particular:
hosting and website providers;
cloud and infrastructure providers;
IT and security service providers;
email and communication providers;
analysis and statistics services;
advertising and marketing platforms;
video, map, and media services;
agencies and technical partners;
accounting and administration service providers;
banks and payment service providers;
insurances;
lawyers, tax advisors, and other consultants;
authorities and courts, provided there is a legal obligation;
potential purchasers or business partners in the course of a corporate transaction.
Service providers who process personal data on our behalf are contractually obligated, where necessary, to process the data only in accordance with our instructions, to implement appropriate security measures, and to comply with applicable data protection regulations.
We do not sell personal data and do not share personal data with uninvolved third parties without a legal basis.
22. Processing of Personal Data Abroad
Our service providers and their subcontractors may process personal data in Switzerland, the European Economic Area, the USA, and other countries.
Some of these countries may not have data protection laws that ensure an adequate level of data protection from a Swiss or European perspective.
If personal data is transferred to a country without an officially recognized adequate level of data protection, we base the transfer – where necessary – in particular on:
an adequacy decision;
standard contractual clauses;
standard contractual clauses adapted for Switzerland;
a recognized data protection framework;
binding corporate rules;
explicit consent;
necessity for the performance of a contract;
the establishment, exercise, or defense of legal claims;
another legally permitted exception.
Despite contractual and organizational safeguards, it cannot be completely ruled out during processing abroad that foreign authorities may access data within the scope of their statutory powers.
23. Retention Period
We store personal data only for as long as is necessary for the respective purpose or as long as statutory or contractual retention obligations exist.
When determining the retention period, we consider in particular:
the purpose of the data processing;
the nature and sensitivity of the data;
statutory retention obligations;
ongoing contractual relationships;
limitation periods;
possible legal claims;
security and evidence requirements;
technical storage and backup cycles.
Business documents, accounting records, and contract-relevant correspondence can generally be retained for ten years in accordance with statutory requirements.
Data from contact inquiries that do not lead to a business relationship are generally deleted after the inquiry is concluded or at the latest after twelve months, provided there are no reasons for longer retention.
Cookie and consent information is stored in accordance with its technical lifetime and legal proof requirements.
After the retention period has expired, the data is deleted, anonymized, or blocked, as far as deletion is technically not immediately possible.
24. Data Security
We take appropriate technical and organizational security measures to protect personal data against loss, misuse, unauthorized access, alteration, disclosure, or destruction.
These measures may include in particular:
encrypted data transmission using TLS/HTTPS;
access restrictions;
role and authorization concepts;
strong passwords and multi-factor authentication;
regular updates of systems used;
backups;
logging of security-relevant processes;
protection against malware and unauthorized access;
selection of suitable service providers;
internal data protection and security policies.
A completely risk-free data transmission and storage cannot be guaranteed despite appropriate protective measures.
25. Data Breaches
Should a data security breach occur, we will investigate the incident immediately and take the necessary measures.
To the extent required by law, we will inform the responsible data protection supervisory authority and, if applicable, the affected individuals.
26. Your Rights
Depending on the applicable data protection law and the respective requirements, you can assert the following rights in particular:
information about whether and which personal data we process about you;
provision of a copy of your personal data;
rectification of inaccurate or incomplete data;
erasure of your personal data;
restriction of data processing;
objection to specific data processings;
withdrawal of consent given;
provision or transfer of certain personal data in a common electronic format;
information about the origin of the data;
information about recipients or categories of recipients;
review of an automated individual decision;
complaint to a competent data protection supervisory authority.
These rights do not apply without restriction. We can refuse, restrict, or postpone a request if legal requirements are met, overriding interests conflict, retention obligations exist, or the request is obviously unfounded or disproportionate.
To process a request, we may require suitable proof of identity. This is to prevent personal data from being disclosed to unauthorized persons.
To exercise your rights, please contact us at: info@zeja.ch
27. Withdrawal of Consent
You can withdraw consent given at any time with effect for the future.
You can change or withdraw consent for cookies, analytical, marketing, and third-party services via the "Cookie Settings" link in the footer of our website.
You can withdraw other consents by sending an email to info@zeja.ch.
The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal.
28. Objection to Direct Marketing
Insofar as we process personal data for direct marketing, you can object to this processing at any time.
After your objection, we will no longer use your personal data for corresponding direct marketing. Minimal blocking information may be retained to ensure that your objection is respected in the future.
29. Automated Decisions and Profiling
Our analysis and advertising services may use data to form user groups, infer interests, or target advertising more specifically. Under data protection law, this may be considered profiling.
Based on this information, we do not make solely automated decisions that have legal effects on you or significantly affect you in a similar way.
30. Data of Children and Adolescents
Our website is primarily aimed at companies, business customers, and adult prospects.
We do not knowingly collect personal data from children unless consent is given by the parent or guardian or there is another legal basis.
Parents or guardians can contact us if they suspect that we have been sent personal data of a child without a sufficient legal basis.
31. Obligation to Provide Personal Data
In principle, there is no obligation to provide us with personal data.
However, certain information is required so that we can answer inquiries, prepare offers, conclude contracts, or provide services. Without this information, we may not be able to offer corresponding services or only to a limited extent.
32. External Websites
Our website may contain links to websites and services of third parties.
The respective operators are responsible for the content and privacy practices of these external services. We recommend that you read the privacy policies of the providers concerned.
33. Competent Data Protection Supervisory Authority
For data protection concerns in Switzerland, you can contact the Federal Data Protection and Information Commissioner:
Federal Data Protection and Information Commissioner – FDPIC
Switzerland
Insofar as the GDPR is applicable, you also have the right to lodge a complaint with a competent data protection supervisory authority in the European Economic Area, in particular in your habitual residence, your place of work, or the place of the alleged data protection violation.
We recommend that you contact us directly first so that we can examine and address your concern.
34. Changes to This Privacy Policy
We can adapt this Privacy Policy at any time, in particular if we change our website, our services, the technologies used, or the legal requirements.
The version published on our website shall apply.
In the event of significant changes, we may point this out separately on our website.
Last updated: July 21, 2026
ZEJA GmbH
Amthofstrasse 16
8630 Rüti
Switzerland
info@zeja.ch