Legal notice

Privacy Policyexplanation

Data protection is important to us. This statement informs you about which personal data we process on creaskill.ch, for what purposes and to what extent.

Foreword

With the following privacy policy, we would like to inform you which types of your personal data (hereinafter also referred to simply as «data») we process, for what purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as «online offering»).

You can find the Swiss Data Protection Act (revFADP) here: newsd.admin.ch (PDF). The EU counterpart here: GDPR-law.de. As we operate as a business throughout Europe, we refer to the GDPR; the Swiss Data Protection Act applies mutatis mutandis.

Gender declaration: For reasons of better readability, the generic masculine is used. Female and other gender identities are explicitly included where required for the statement.

Source: The basic content originates from devowl.io and have been adapted and supplemented.

Controller

creaSKILL GmbH, represented by Heinz W. Süess
Natternweg 3, CH-4852 Rothrist
Telephone: +41 62 544 02 04
E-Mail: [email protected]

Record of processing activities

The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects.

Types of processed data

  • Master data
  • Payment details
  • Contact details
  • Content data
  • Contract details
  • Usage data
  • metadata, communication and process data

Categories of data subjects

  • Customers
  • Prospective buyers
  • communication partner
  • User
  • business and contractual partners
  • Participants

Purposes of processing

  • Provision of contractual services and customer service
  • Contact enquiries and communication
  • Appointment scheduling and management
  • Security measures
  • audience measurement
  • office and organisational procedures
  • Management and answering of enquiries
  • Feedback
  • Provision of our online services and user-friendliness
  • IT infrastructure

Security measures

We take appropriate technical and organisational measures, in accordance with statutory requirements and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, to ensure a level of security appropriate to the risk.

The measures include, in particular, ensuring the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to them, input, transfer, securing availability and their separation. Furthermore, we have established procedures to ensure the exercise of data subjects' rights, the erasure of data and responses to threats to the data. In addition, we already take the protection of personal data into account during the development or selection of hardware, software and procedures in accordance with the principle of data protection by design and by default.

TLS encryption (HTTPS): To protect your data transmitted via our online service, we use TLS encryption. You can recognise such encrypted connections by the prefix https:// in your browser's address bar.

Transfer of personal data

When we process personal data, it may happen that the data is transferred to other bodies, companies, legally independent organisational units or persons, or disclosed to them. Recipients of this data may include, for example, service providers tasked with IT duties or providers of services and content that are integrated into a website. In such cases, we comply with legal requirements and, in particular, conclude corresponding contracts or agreements with the recipients of your data that serve to protect your data.

Deletion of data

The data processed by us will be deleted in accordance with the statutory regulations as soon as the consents permitting their processing are revoked or other permissions cease to apply (e.g. if the purpose for processing this data has ceased to apply or they are not required for the purpose). If the data is not deleted because it is required for other and legally permissible purposes, its processing will be restricted to these purposes. This means that the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons or whose storage is necessary for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person.

Use of cookies

Cookies are small text files or other storage records that store information on terminal devices and read information from terminal devices—for example, to save the login status, accessed content or used functions of an online service. Furthermore, cookies can be used for various purposes, such as for the functionality, security and convenience of online services as well as the creation of analyses of visitor flows.

Consent information: We use cookies in accordance with legal regulations. Therefore, we obtain prior consent from users unless this is not required by law. In particular, consent is not necessary if the storing and reading of information are strictly necessary in order to provide users with a service they have expressly requested (i.e. our online service). The revocable consent is clearly communicated to users and contains information on the respective use of cookies.

Retention period: Temporary cookies (session cookies) are deleted at the latest after a user leaves an online service and closes their device. Permanent cookies remain stored even after the device is closed. Unless we provide users with explicit information on the type and storage duration of cookies (e.g. as part of obtaining consent), users should assume that cookies are permanent and that the storage period can be up to two years.

Cancellation and objection (opt-out): Users can revoke the consent they have given at any time and also object to processing in accordance with legal requirements – including via their browser settings, e.g. by deactivating the use of cookies (which may, however, limit the functionality of our online services). You will find a link in the footer of our website that you can use to change your cookie settings and revoke consent.

Processed data types: Usage data (e.g. websites visited, access times); meta, communication and procedural data (e.g. IP addresses, timestamps, consent status).
Affected persons: User.
Purposes: Provision of our online services and user-friendliness.
Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Consent (Article 6(1)(a) GDPR).

Video conferences, online meetings and webinars

We use third-party platforms and applications (hereinafter «conference platforms») for the purpose of holding video and audio conferences, webinars and other types of video and audio meetings. When selecting conference platforms and their services, we comply with statutory requirements.

As part of participating in a conference, the conference platforms process personal data of the participants. The scope depends on which data are requested in the context of a specific conference (e.g. provision of access credentials or real names) and which optional details are provided. The processed data include personal data (first and last name), contact information (email address, telephone number), access credentials, profile pictures, details regarding professional position/role, the IP address, details concerning the end devices, as well as inputs in chats and audio and video data. The contents of communications are encrypted to the extent technically provided by the conference providers.

Logging and recordings: If text inputs, participation results or video or audio recordings are logged, participants will be informed of this transparently in advance and – where necessary – asked for their consent.

Participants' data protection measures: Please refer to the privacy policies of the conference platforms for details regarding the processing of your data and select the optimal security and privacy settings for your needs. Please ensure data and personal privacy are maintained in the background of your recording for the duration of a video conference. Links to the conference rooms and access data must not be passed on to unauthorised third parties.

Processed data types: Inventory data; contact data; content data; usage data; meta, communication and procedural data.
Affected persons: communication partner; user; depicted individuals.
Purposes: Provision of contractual services and customer service; contact enquiries and communication; office and organisational procedures.
Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

Cloud services

We use software services accessible via the Internet and executed on the servers of their providers (so-called «cloud services», also «Software as a Service») for the storage and management of content (e.g. document storage and management, exchange of documents and information with specific recipients). Within this framework, personal data may be processed and stored on the providers' servers, provided that this data forms part of communication processes with us. This data may include, in particular, master data and contact data of users, data relating to transactions, contracts and other processes, and their contents. The providers of the cloud services also process usage data and metadata, which are used by them for security purposes and service optimisation.

Processed data types: Inventory data; contact data; content data; usage data; meta, communication and procedural data.
Affected persons: Customers; prospective customers; communication partners; users.
Purposes: Office and organisational procedures; information technology infrastructure.
Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

Contact and enquiries

When contacting us (e.g. via contact form, email or telephone) and as part of existing user and business relationships, the details of the enquiring persons are processed, insofar as this is necessary for responding to the contact enquiries and any requested measures. Please note that emails on the internet are generally not sent with end-to-end encryption; we therefore cannot accept any responsibility for the transmission path between the sender and receipt on our server.

Processed data types: Inventory data; contact data; content data; meta, communication and procedural data.
Affected persons: Communication partners; prospective clients.
Purposes: Contact enquiries and communication; management and answering of enquiries; provision of contractual services and customer service.
Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR); Legitimate interests (Art. 6(1)(f) GDPR).

Web analytics, monitoring and optimisation

Web analytics (also known as «audience measurement») serves to evaluate visitor flows to our online service and can include visitor behaviour, interests or demographic information as pseudonymous values. With the help of audience analysis, we can, for example, identify at what times our online service or its functions and content are used most frequently, and understand which areas require optimisation.

The IP addresses of users are also stored. However, we use an IP masking procedure (pseudonymisation by truncating the IP address) to protect users. Generally, as part of web analysis and optimisation, no clear user data (such as email addresses or names) is stored, but rather pseudonyms.

Processed data types: Usage data; meta, communication and procedural data.
Affected persons: User.
Purposes: Audience measurement; provision of our online service and user-friendliness.
Safety measures: IP masking (pseudonymisation of the IP address).
Legal bases: Legitimate interests (Article 6(1)(f) GDPR); Consent (Article 6(1)(a) GDPR).

Plugins and embedded features as well as content

We integrate functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter referred to as «third-party providers»). These can, for example, be graphics, videos or appointment booking widgets (hereinafter uniformly referred to as «content»).

The integration always presupposes that the third-party providers of this content process the users' IP address, as without the IP address they could not send the content to their browser. The IP address is therefore required for the display of this content or functions. We endeavour to use only such content whose respective providers use the IP address solely for the delivery of the content. Third-party providers may also use so-called pixel tags for statistical or marketing purposes.

Processed data types: Usage data; meta, communication and procedural data; inventory data; contact data; content data.
Affected persons: User.
Purposes: Provision of our online services and user-friendliness; provision of contractual services and customer service; security measures.
Legal bases: Legitimate interests (Article 6(1)(f) GDPR).

Tools and services used on this website

WordPress

WordPress is a content management system (CMS) used to create this website. It is based on PHP and requires a MySQL database.

GeneratePress / GenerateBlocks

GeneratePress is the theme and GenerateBlocks is the layout extension used to create the design of this website. These components do not set any tracking cookies.

Google Fonts

Google Fonts is a service that downloads fonts that are not installed on the user's device and embeds them into the website. No cookies in the technical sense are set on the user's device, but technical and personal data such as the IP address are transmitted from the client to the service provider's server in order to enable the use of the service.

Real Cookie Banner

Real Cookie Banner asks website visitors for consent to set cookies and process personal data (service provider: devowl.io GmbH, Tannet 12, 94539 Grafling, Germany). For this purpose, each website visitor is assigned a UUID (pseudonymous identification), which is valid until the cookie for storing the consent expires. The consent obtained is fully documented in accordance with the accountability obligation under the GDPR. Details on how it works: devowl.io/en/rcb/data-processing. The legal bases are Article 6(1)(c) and Article 6(1)(f) of the GDPR; our legitimate interest is the management of the cookies used and the consents given in relation thereto.

Wordfence

Wordfence protects this website against various types of attack. Cookies are used to check user permissions before accessing WordPress, to notify administrators when a user logs in from a new device or location, and to bypass certain country restrictions using specially prepared links.

Google reCAPTCHA

Google reCAPTCHA is a bot detection solution, for example when entering data into online forms, and is used to prevent spam. The cookies are used to identify the user within the data known to Google as a user. This collected data can be linked with data about users who are signed in to their Google accounts. As an alternative to using the form, you can send us an email directly at any time.

Data subject rights

As a data subject under the GDPR, you have various rights which derive in particular from Articles 15 to 21 of the GDPR:

  • Right to object: You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point (e) or (f) of Article 6(1) GDPR, including profiling based on those provisions. Where personal data concerning you are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing.
  • Right of withdrawal for consents: You have the right to withdraw given consents at any time.
  • Right of access: You have the right to request confirmation as to whether data in question is being processed, and to request information about this data as well as further information and a copy of the data in accordance with the statutory provisions.
  • Right to rectification: In accordance with the statutory provisions, you have the right to request the completion of data concerning you or the rectification of incorrect data concerning you.
  • Right to erasure and restriction of processing: You have the right, in accordance with statutory requirements, to demand that data concerning you be erased without undue delay, or alternatively to demand a restriction on the processing of the data.
  • Right to data portability: You have the right to receive personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format, or to request its transmission to another controller.
  • Complaint to supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you consider that the processing of personal data relating to you infringes legal requirements.

As of: July 2026 · Basis: Privacy Policy creaskill.ch (19 March 2026)

Further information in the legal notice