Data Privacy
1. Brief Overview
This privacy policy explains how ZEJA GmbH processes personal data when you visit our website, contact us, or interact with our online services.
In particular, we process technical access data, contact and communication data, and—subject to your consent—information about the use of our website. In doing so, tools such as Framer, Google Analytics, Google Ads, the Meta Pixel, as well as embedded content from YouTube, Vimeo, and Google Maps may be deployed.
Non-essential analytical, marketing, and third-party services are generally only activated after you have given consent via our cookie banner.
We do not sell personal data.
2. Controller
The controller responsible for processing your personal data is:
ZEJA GmbH
Landstrasse 38
5436 Würenlos
Switzerland
Email: info@zeja.ch
Website: zeja.ch
Data protection inquiries as well as requests to exercise your data protection rights can be sent to the email address listed above.
3. Applicable Data Protection Law
We process personal data in accordance with the Swiss Federal Act on Data Protection, the corresponding Data Protection Ordinance, and—where applicable—the General Data Protection Regulation of the European Union.
The GDPR is applicable in particular if our data processing affects individuals in the European Economic Area or falls within the territorial scope of the GDPR for other reasons.
To the extent the GDPR is applicable, processing is carried out in particular based on the following legal grounds:
Your consent pursuant to Art. 6 para. 1 lit. a GDPR;
The performance of a contract or pre-contractual measures pursuant to Art. 6 para. 1 lit. b GDPR;
The fulfillment of legal obligations pursuant to Art. 6 para. 1 lit. c GDPR;
Our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR.
Our legitimate interests include, in particular, the secure and cost-efficient operation of our website, communication with prospects and customers, the improvement of our offerings, reach measurement, performance tracking of our advertising, and the prevention of fraud and cyberattacks.
Under Swiss data protection law, we process personal data in line with the principles of lawfulness, proportionality, purpose limitation, transparency, and data security. Where necessary, we base processing on consent, a statutory basis, a contract, or overriding private or public interests.
4. Definitions
Personal data means any information relating to an identified or identifiable natural person.
Processing means any operation with personal data, irrespective of the means and procedures applied, in particular the acquisition, collection, storage, use, modification, disclosure, transmission, archiving, deletion, or destruction.
Sensitive personal data includes information on health, religious or political views, the intimate sphere, genetic and biometric data, as well as certain details concerning criminal or administrative proceedings.
5. What Personal Data We Process
Depending on how you use our website, we process the following categories of personal data in particular:
Technical Data
This includes, in particular:
IP address;
Date and time of access;
Pages and files accessed;
Data volume transmitted;
Referrer URL;
Browser type and version;
Operating system;
Device type;
Screen resolution;
Language settings;
Approximate geographical region;
Internet Service Provider (ISP);
Technical identifiers;
Cookie and tracking IDs;
Log and security data.
Usage Data
This includes, in particular:
Pages visited;
Time spent on site;
Clicks and interactions;
Scrolling behavior;
Navigation paths;
Entry and exit pages;
Videos played;
Form interactions;
Campaign and conversion data;
Information about which ad or website brought you to us.
Contact and Communication Data
When you contact us, we process in particular:
First and last name;
Company;
Email address;
Phone number;
Content of your inquiry;
Uploaded or submitted documents;
Time and progression of the communication;
Other details you share voluntarily.
Contractual and Business Data
If a business relationship arises from an inquiry, we additionally process in particular:
Company and contact details;
Project information;
Quotes and contracts;
Services rendered and orders;
Payment and billing information;
Correspondence;
Business documents;
Information regarding contract execution.
Please do not send us any sensitive personal data via openly accessible forms or unencrypted emails unless expressly required and agreed upon with us.
6. Purposes of Data Processing
We process personal data for the following purposes in particular:
Providing and operating our website;
Ensuring the technically correct display of our content;
Ensuring system stability and security;
Detecting and defending against abuse, fraud, and cyberattacks;
Processing contact inquiries;
Initiating and managing business relationships;
Creating quotes;
Rendering our services;
Customer support;
Analyzing the use of our website;
Improving user-friendliness;
Optimizing our content and offers;
Measuring the reach of our website;
Measuring the success of advertising campaigns;
Displaying relevant advertisements;
Creating target groups for advertising campaigns;
Remarketing and retargeting;
Fulfilling statutory retention and documentation obligations;
Enforcing or defending against legal claims;
Administrative and internal organizational purposes.
7. Hosting and Website Builder Framer
Our website is run using the website builder and hosting infrastructure of Framer.
The provider is Framer B.V., based in the Netherlands.
When accessing our website, technical data is transmitted to Framer or to hosting, cloud, and infrastructure partners used by Framer. This may include, in particular, your IP address, browser information, device information, pages viewed, times of access, and technical log data.
The processing is necessary to deliver our website, ensure its stability and security, and detect technical errors and unauthorized access.
To the extent Framer processes personal data on our behalf, Framer acts as a processor. Framer may use additional sub-processors.
Framer and its sub-processors may also process data outside of Switzerland or the European Economic Area. According to Framer, suitable safeguards are used for such transfers, such as adequacy decisions, applicable data privacy frameworks, or standard contractual clauses.
8. Server Log Files
When you access our website, technical information can be automatically stored in so-called server log files.
This information includes in particular:
IP address;
Date and time;
Page or file accessed;
Referrer URL;
Browser and browser version;
Operating system;
Hostname of the accessing device;
Data volume transmitted;
HTTP status code;
Technical error and security information.
The log data is used to run the website, analyze technical errors, detect attacks, and ensure the security of our systems.
Log data is only kept for as long as necessary for the aforementioned purposes. Longer retention may occur if a security-relevant event needs to be investigated, legal obligations exist, or the data is required to enforce or defend against claims.
9. Framer Analytics
Framer can provide an integrated, privacy-focused statistics feature for our website.
According to Framer, Framer Analytics does not use cookies or persistent user identifiers. To determine daily visitor counts, the IP address and user agent are processed using a daily changing cryptographic hash. This value is reset every day.
Framer Analytics provides us with the following aggregated information in particular:
Number of page views;
Number of daily visitors;
Frequently accessed pages;
Origin or access sources;
General usage statistics.
We use this information to understand the usage and reach of our website and to improve our services.
10. Cookies and Similar Technologies
Our website uses cookies as well as similar technologies such as local storage, pixels, tags, scripts, and comparable identifiers.
Cookies are small text files that are stored on your end device. They can contain information about your device, your settings, or your use of a website.
Necessary Technologies
Necessary cookies and technologies are required for the website to function, serve pages securely, and store your data protection or cookie preferences.
These technologies can be used without prior consent to the extent their use is technically necessary and legally permissible.
Functional Technologies
Functional technologies enable additional features, such as displaying external videos, maps, or other third-party content.
Analytical Technologies
Analytical technologies help us understand how our website is used. This includes page views, interactions, time spent on pages, access sources, and technical information.
Marketing Technologies
Marketing technologies help us measure advertising campaigns, create target groups, recognize returning visitors, and show more relevant advertising on platforms like Google, Facebook, or Instagram.
Consent Management
Non-essential analytical, marketing, and third-party technologies are generally only activated after you have given consent via our cookie banner.
You can:
Accept all non-essential services;
Decline all non-essential services;
Select specific categories;
Change or withdraw your selection at a later time.
You can change your selection at any time via the "Cookie Settings" link in the footer of our website.
WITHDRAWAL OF CONSENT IS EFFECTIVE FOR THE FUTURE. The lawfulness of processing carried out up to the time of withdrawal remains unaffected.
Additionally, you can delete or block cookies through your browser settings. Complete blocking may restrict some functions of our website.
11. Google Tag Manager
To the extent we use Google Tag Manager, we do so for the centralized management of analytic and marketing tags.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
Google Tag Manager serves only to trigger and manage other services. It does not create standalone user profiles of its own. However, when accessed, technical data, particularly your IP address and device information, may be transmitted to Google.
Analytical and marketing services integrated via Google Tag Manager are only activated in accordance with the selection made by you in the cookie banner.
12. Google Analytics 4
We use Google Analytics 4, a web analytics service from Google.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited. Further processing may be conducted by Google LLC and other Google affiliates.
Google Analytics helps us understand how visitors use our website. In this process, the following information in particular may be processed:
Pages accessed;
Time and duration of visit;
Clicks and interactions;
Scrolling behavior;
Session information;
Referrer URL;
Campaign information;
Browser and device information;
Operating system;
Screen resolution;
Approximate geographical region;
Technical identifiers;
Cookie and client IDs;
Information about conversions.
Google utilizes the IP address technically to derive an approximate geographical region, among other things. According to Google, IP addresses of users from Switzerland, the European Economic Area, and the United Kingdom are discarded prior to logging and are not persistently stored.
Google Analytics is generally only activated with your consent. To the extent the GDPR is applicable, the legal basis is Art. 6 para. 1 lit. a GDPR.
We use the information obtained to analyze website usage, compile aggregated statistics, improve our content, and measure our marketing initiatives.
The retention period for user- and event-level data in our Google Analytics property is set to a maximum of 14 months. Aggregated or anonymized reports may be retained longer.
Wherever possible, we disable or restrict the use of analytics data for personalized advertising. Depending on our configuration and your consent, Google Analytics and Google Ads may be linked with each other.
You can withdraw your consent at any time via the cookie settings. Additionally, Google provides a browser add-on to opt out of Google Analytics.
13. Google Ads and Conversion Tracking
We use Google Ads to advertise our services in Google Search, on third-party websites, and within the Google advertising network.
In connection with Google Ads, we may use the following features in particular:
Conversion tracking;
Campaign and performance measurement;
Remarketing or retargeting;
Target audience creation;
Measurement of website visits and contact requests;
Analysis of interactions with our ads.
If you reach our website via a Google ad or perform a defined action, Google may store a cookie or a comparable identifier.
The following data may be processed in this process in particular:
IP address;
Cookie and device identifiers;
Browser and device information;
Pages visited;
Time of visit;
Interactions and clicks;
Information about the ad clicked;
Campaign parameters;
Submitted contact requests;
Measured conversions.
Google can link this information with other data, particularly if you are signed in to a Google account and have activated corresponding personalization settings.
Google Ads and associated marketing technologies are generally only activated with your consent.
To the extent the GDPR is applicable, the legal basis is Art. 6 para. 1 lit. a GDPR.
You can withdraw your consent at any time via our cookie settings. You can also manage personalized advertising via the ad settings in your Google account.
14. Meta Pixel and Meta Ads
We use the Meta Pixel to measure and optimize our advertising campaigns on Facebook and Instagram.
The provider for users in Switzerland and the European Economic Area is generally Meta Platforms Ireland Limited. Further processing may be carried out by Meta Platforms, Inc. in the US.
The Meta Pixel enables us in particular:
To measure whether users visit our website after seeing an ad;
To recognize which pages or offers were accessed;
To measure contact requests and other conversions;
To create target groups for advertising campaigns;
To retarget previous website visitors with ads;
To create lookalike audiences;
To analyze the efficacy of our advertising;
To tailer ads better to potential interests.
The following data may be transmitted to Meta in this process in particular:
IP address;
Browser and device information;
Operating system;
URL accessed;
Referrer URL;
Time of visit;
Cookie and pixel IDs;
Facebook or Meta identifiers;
Campaign information;
Click and interaction data;
Triggered events;
Information about contact requests or other conversions.
Meta may match this information to a Facebook or Instagram account and use it for its own advertising, analytical, security, and personalization purposes. This can also occur if you are not signed in to Facebook or Instagram or do not have an account with them.
The Meta Pixel is generally only activated with your consent.
To the extent the GDPR is applicable, the legal basis is Art. 6 para. 1 lit. a GDPR.
In connection with the collection and transmission of certain event data, we and Meta may act as joint controllers to the extent provided by applicable law. Meta assumes responsibility in particular for processing within its platforms and for fulfilling certain data subject rights regarding the data stored by Meta.
You can withdraw your consent at any time via our cookie settings. You can also manage the use of your data for personalized ads via the privacy and ad settings on Facebook and Instagram.
15. YouTube Videos
Videos from the YouTube platform may be embedded on our website.
YouTube is a service provided by Google. The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
When loading or playing an embedded YouTube video, the following data may be transmitted to Google or YouTube in particular:
IP address;
Browser and device information;
Page accessed;
Referrer URL;
Time of access;
Cookie and device identifiers;
Information about the video played;
Interactions with the video player.
If you are signed in to a Google or YouTube account, Google can associate your visit and interaction with your account.
As far as technically possible, we use YouTube in privacy-enhanced mode. Nevertheless, data may be transmitted to Google, at the latest when playing a video.
YouTube videos are generally only loaded after you have agreed to the category for external media or functional services. Before your consent, only a placeholder is displayed.
To the extent the GDPR is applicable, the legal basis is Art. 6 para. 1 lit. a GDPR.
16. Vimeo Videos
Videos from the Vimeo platform may be embedded on our website.
The provider is Vimeo.com, Inc., based in the US.
When loading or playing a Vimeo video, the following data may be processed in particular:
IP address;
Browser and device information;
Page accessed;
Referrer URL;
Time of access;
Cookie and device identifiers;
Information about the video played;
Interactions with the video player.
If you are signed in to a Vimeo account, Vimeo may associate the interaction with your account.
Vimeo videos are generally only loaded after you have agreed to the category for external media or functional services. Before your consent, a placeholder may be displayed.
To the extent the GDPR is applicable, the legal basis is Art. 6 para. 1 lit. a GDPR.
When using Vimeo, data may be transferred to the US or to other countries. According to the provider, such transfers are based on the applicable data protection mechanisms and contractual safeguards in each case.
17. Google Maps
Maps and location information from Google Maps may be embedded on our website.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
When loading a Google Maps map, the following data may be transferred to Google in particular:
IP address;
Browser and device information;
Operating system;
Page accessed;
Time of access;
Approximate location information;
Cookie and device identifiers;
Interactions with the map.
If you are signed in to a Google account, Google can associate the visit or use of the map with your account.
Google Maps is generally only loaded after you have agreed to the category for external media or functional services. Before your consent, a placeholder or a simple link to the map view may be displayed instead.
To the extent the GDPR is applicable, the legal basis is Art. 6 para. 1 lit. a GDPR.
18. Contact Form
If you contact us via a contact form, we process the data you enter to respond to your inquiry.
This includes in particular:
Name;
Email address;
Phone number;
Company;
Subject;
Message content;
Voluntarily submitted supplemental information;
Time of inquiry;
Technical information to prevent abuse.
The form data is transmitted to us via the form and hosting infrastructure provided by Framer, or via a service connected to the website.
The processing is done to communicate with you, to answer your inquiry, and, if applicable, to prepare or execute a business relationship.
To the extent the GDPR is applicable, the processing is carried out depending on the content of your inquiry, in particular on the basis of:
Art. 6 para. 1 lit. b GDPR for pre-contractual or contractual inquiries;
Art. 6 para. 1 lit. f GDPR for general business inquiries;
Art. 6 para. 1 lit. a GDPR if you have expressly consented to specific processing.
Inquiries that do not result in a business relationship are generally deleted after they have been processed conclusively, unless statutory, security-related, or legal reasons dictate further retention. Deletion generally takes place within twelve months at the latest.
If a business relationship arises, the data can be stored longer in accordance with statutory retention requirements.
19. Communication via Email or Phone
If you contact us by email or telephone, we process your contact details and the content of your message to handle your request.
When communicating by email, data is transmitted via the email and hosting providers involved. These providers can process technical connection and communication data.
Unencrypted emails are not a completely secure means of communication. Therefore, please do not send us any highly sensitive or confidential information by unencrypted email.
Processing is carried out in particular for communication, key answering of your inquiry, and to initiate or conduct a business relationship.
20. Links to Social Networks
Our website may contain links to our profiles on social networks, particularly Facebook, Instagram, LinkedIn, TikTok, YouTube, or Vimeo.
With simple links, data is generally only transferred to the respective platform when you click the link.
Once clicked, the privacy policies of the respective platform apply. The providers can track which website you came from to reach their platform. If you are signed in there, the visit can be associated with your user account.
We have no complete control over which data the platforms subsequently process and for what internal purposes they use it.
21. Recipients and Processors
We may disclose personal data to external service providers and recipients to the extent necessary for the purposes described in this privacy policy.
This includes in particular:
Hosting and website providers;
Cloud and infrastructure providers;
IT and security service providers;
Email and communication providers;
Analysis and statistics services;
Advertising and marketing platforms;
Video, map, and media services;
Agencies and technical partners;
Accounting and administration service providers;
Banks and payment service providers;
Insurances;
Attorneys, tax advisors, and other consultants;
Authorities and courts, if there is a legal obligation to do so;
Potential acquirers or business partners in the context of a corporate transaction.
Service providers that process personal data on our behalf are contractually obligated, where required, to process the data only in accordance with our instructions, to implement appropriate security measures, and to comply with applicable data protection regulations.
We do not sell personal data and do not share personal data with uninvolved third parties without a legal basis.
22. Processing of Personal Data Abroad
Our service providers and their subcontractors may process personal data in Switzerland, the European Economic Area, the US, and other countries.
Some of these countries may not have data protection laws that ensure an adequate level of data protection from a Swiss or European perspective.
If personal data is transferred to a country without an recognized adequate level of data protection, we base the transfer—where required—in particular on:
An adequacy decision;
Standard contractual clauses;
Standard contractual clauses adapted for Switzerland;
An approved data privacy framework;
Binding Corporate Rules (BCRs);
Express consent;
The necessity for performance of a contract;
The establishment, exercise, or defense of legal claims;
Another legally permissible exception.
Despite contractual and organizational safeguards, it cannot be fully ruled out that foreign authorities may access data within the scope of their statutory powers when processed abroad.
23. Retention Period
We retain personal data only for as long as necessary for the respective purpose or as required by statutory or contractual retention obligations.
When determining the retention period, we consider in particular:
The purpose of the data processing;
The type and sensitivity of the data;
Statutory retention requirements;
Ongoing contractual relationships;
Statutes of limitation;
Potential legal claims;
Security and evidence requirements;
Technical storage and backup cycles.
Business documents, accounting records, and contract-related correspondence can generally be retained for ten years in accordance with statutory requirements.
Data from contact inquiries that do not lead to a business relationship is generally deleted after completion of the inquiry or after twelve months at the latest, unless reasons for longer retention exist.
Cookie and consent information is stored in accordance with its technical lifespan and statutory proof obligations.
After the retention period has expired, the data is deleted, anonymized, or blocked, to the extent that deletion is technically not possible immediately.
24. Data Security
We take appropriate technical and organizational security measures to protect personal data from loss, misuse, unauthorized access, alteration, disclosure, or destruction.
These measures can include in particular:
Encrypted data transmission via TLS/HTTPS;
Access restrictions;
Role and permission concepts;
Strong passwords and multi-factor authentication;
Regular updates of the deployed systems;
Backups;
Logging of security-relevant processes;
Protection against malware and unauthorized access;
Selection of appropriate service providers;
Internal data protection and security guidelines.
A completely risk-free data transmission and storage cannot be guaranteed despite appropriate protective measures.
25. Data Breaches
In the event of a breach of data security, we will evaluate the incident immediately and take the necessary measures.
Where legally required, we will inform the competent data protection supervisory authority and, if applicable, the affected individuals.
26. Your Rights
Depending on the applicable data protection law and the respective conditions, you can assert the following rights in particular:
Information as to whether and which personal data we process about you;
Delivery of a copy of your personal data;
Correction of inaccurate or incomplete data;
Deletion of your personal data;
Restriction of data processing;
Objection to certain data treatments;
Withdrawal of granted consent;
Delivery or transfer of certain personal data in a standard electronic format;
Information about the origin of the data;
Information about recipients or categories of recipients;
Review of an automated individual decision;
Complaint to a competent data protection supervisory authority.
These rights do not apply without limitation. We can refuse, restrict, or postpone a request if legal conditions are met, overriding interests conflict, retention obligations exist, or the request is manifestly unfounded or disproportionate.
To process a request, we may require suitable proof of identity. This is to prevent personal data from being disclosed to unauthorized persons.
To exercise your rights, contact us at:
27. Withdrawal of Consent
You can withdraw a granted consent at any time with effect for the future.
You can change or withdraw consent for cookies, analytical, marketing, and third-party services via the "Cookie Settings" link in the footer of our website.
You can withdraw other consents by email to info@zeja.ch.
The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal.
28. Objection to Direct Marketing
To the extent we process personal data for direct marketing, you can object to this processing at any time.
Following your objection, we will no longer use your personal data for such direct marketing. Minimal blocklist information may be retained to ensure that your objection is honored in the future.
29. Automated Decisions and Profiling
Our analysis and advertising services may use data to form user groups, infer interests, or target advertisements more effectively. Under data protection law, this may be considered profiling.
We generally do not make solely automated decisions based on this information that produce legal effects concerning you or similarly significantly affect you.
30. Data of Children and Minors
Our website is primarily aimed at companies, business clients, and adult prospects.
We do not knowingly collect personal data from children unless consent of the parent or legal guardian has been obtained or another legal basis exists.
Parents or legal guardians can contact us if they suspect that personal data of a child has been transmitted to us without a sufficient basis.
31. Obligation to Provide Personal Data
In principle, there is no obligation to provide us with personal data.
However, certain details are required for us to respond to inquiries, create quotes, conclude contracts, or render services. Without this information, we may not be able to offer corresponding services, or only to a limited extent.
32. Third-Party Websites
Our website may contain links to websites and offerings of third parties.
The respective operators are responsible for the content and privacy practices of these external offerings. We encourage you to read the privacy policies of the respective providers.
33. Competent Data Protection Supervisory Authority
For data protection matters in Switzerland, you can contact the Federal Data Protection and Information Commissioner (FDPIC):
Federal Data Protection and Information Commissioner – FDPIC
Switzerland
To the extent the GDPR is applicable, you also have the right to lodge a complaint with a competent data protection supervisory authority in the European Economic Area, in particular at your habitual residence, your place of work, or the place of the alleged infringement.
We recommend that you first contact us directly so that we can review and resolve your concern.
34. Changes to This Privacy Policy
We can adapt this privacy policy at any time, in particular if we change our website, our services, the technologies deployed, or regulatory requirements.
The version published on our website at any given time shall apply.
In the event of material changes, we may notify you separately on our website.
As of: July 21, 2026
ZEJA GmbH
Landstrasse 38
5436 Würenlos
Switzerland
info@zeja.ch
1. Quick Overview
This Privacy Policy informs you about how ZEJA GmbH processes personal data when you visit our website, contact us, or interact with our online offerings.
In particular, we process technical access data, contact and communication data, and – subject to your consent – information about the use of our website. This may involve the use of Framer, Google Analytics, Google Ads, the Meta Pixel, as well as embedded content from YouTube, Vimeo, and Google Maps, among others.
Non-essential analysis, marketing, and third-party services are generally only activated after you have given your consent via our cookie banner.
We do not sell personal data.
2. Controller
The entity responsible for processing your personal data is:
ZEJA GmbH
Landstrasse 38
5436 Würenlos
Switzerland
Email: info@zeja.ch
Website: zeja.ch
Inquiries regarding data protection and requests to exercise your data protection rights can be directed to the email address mentioned above.
3. Applicable Data Protection Law
We process personal data in particular in accordance with the Swiss Federal Act on Data Protection, the associated Data Protection Ordinance, and – where applicable – the General Data Protection Regulation of the European Union.
The GDPR is applicable in particular if our data processing affects individuals in the European Economic Area or falls within the territorial scope of the GDPR for other reasons.
Insofar as the GDPR is applicable, processing is carried out in particular based on the following legal grounds:
Your consent pursuant to Art. 6 para. 1 lit. a GDPR;
performance of a contract or pre-contractual measures pursuant to Art. 6 para. 1 lit. b GDPR;
compliance with a legal obligation pursuant to Art. 6 para. 1 lit. c GDPR;
our legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR.
Our legitimate interests include, in particular, the secure and cost-effective operation of our website, communication with prospects and customers, optimization of our offers, reach measurement, tracking the effectiveness of our advertising, as well as the prevention of misuse and cyberattacks.
According to Swiss data protection law, we process personal data in accordance with the principles of lawfulness, proportionality, purpose limitation, transparency, and data security. Where required, we base the processing on consent, a statutory basis, a contract, or overriding private or public interests.
4. Definitions
Personal data means any information relating to an identified or identifiable natural person.
Processing means any operation with personal data, in particular acquiring, recording, storing, using, modifying, disclosing, transmitting, archiving, deleting, or destroying.
Sensitive personal data includes, in particular, details about health, religious or political views, the intimate sphere, genetic and biometric data, as well as certain details about criminal or administrative proceedings.
5. Which Personal Data We Process
Depending on the use of our website, we process in particular the following categories of personal data:
Technical Data
These include in particular:
IP address;
date and time of access;
accessed pages and files;
amount of data transferred;
referrer URL;
browser type and browser version;
operating system;
device type;
screen resolution;
language settings;
approximate geographical region;
Internet Service Provider;
technical identifiers;
cookie and tracking IDs;
protocol and security data.
Usage Data
These include in particular:
visited pages;
duration of stay;
clicks and interactions;
scrolling behavior;
navigation paths;
entry and exit pages;
played videos;
form interactions;
campaign and conversion data;
information about which ad or website directed you to us.
Contact and Communication Data
When you contact us, we process in particular:
first and last name;
company;
email address;
phone number;
content of your inquiry;
uploaded or transmitted documents;
timing and history of communication;
further information you voluntarily share.
Contractual and Business Data
If a business relationship results from an inquiry, we additionally process in particular:
company and contact details;
project information;
offers and contracts;
services and orders;
payment and billing information;
correspondence;
business documents;
information on contract execution.
Please do not send us sensitive personal data through freely accessible forms or unencrypted emails unless expressly required and agreed upon with us.
6. Purposes of Data Processing
We process personal data in particular for the following purposes:
provision and operation of our website;
technically correct presentation of our content;
ensuring stability and security;
detection and prevention of abuse, fraud, and cyberattacks;
processing contact inquiries;
initiating and executing business relationships;
creating offers;
performing our services;
customer support;
analyzing the use of our website;
improving user-friendliness;
optimizing our content and offerings;
measuring the reach of our website;
measuring the success of advertising campaigns;
displaying relevant advertising;
building target audiences for advertising campaigns;
remarketing and retargeting;
complying with legal retention and documentation obligations;
enforcement or defense of legal claims;
administrative and internal organizational purposes.
7. Hosting and Framer Website Builder
Our website is operated using the website builder and hosting infrastructure of Framer.
The provider is Framer B.V., based in the Netherlands.
When accessing our website, technical data is transmitted to Framer or to hosting, cloud, and infrastructure partners used by Framer. This may include, in particular, the IP address, browser information, device information, accessed pages, access times, and technical log data.
The processing is necessary to deliver our website, ensure its stability and security, and detect technical errors and unauthorized access.
Insofar as Framer processes personal data on our behalf, Framer acts as a processor. Framer may use other sub-processors.
Framer and its sub-processors may also process data outside Switzerland or the European Economic Area. According to Framer, appropriate safeguards, such as adequacy decisions, applicable data privacy frameworks, or standard contractual clauses, are applied to such transfers.
8. Server Log Files
When accessing our website, technical information may be automatically stored in so-called server log files.
This information includes in particular:
IP address;
date and time;
accessed page or file;
referrer URL;
browser and browser version;
operating system;
host name of the accessing device;
amount of data transferred;
HTTP status code;
technical error and security information.
The log data is used to enable the operation of the website, analyze technical errors, detect attacks, and ensure the security of our systems.
Log data is kept only as long as necessary for the stated purposes. A longer retention period may occur if a security-related event needs to be investigated, legal obligations exist, or the data is required to assert or defend claims.
9. Framer Analytics
Framer can provide an integrated, privacy-focused statistics feature for our website.
According to Framer, Framer Analytics does not use cookies or persistent user identifiers. To determine daily visitor numbers, the IP address and user agent are processed with a cryptographic value that changes daily. This value is reset every day.
In particular, Framer Analytics provides us with the following aggregated information:
number of page views;
number of daily visitors;
frequently accessed pages;
origin or access sources;
general usage statistics.
We use this information to understand the usage and reach of our website and to improve our offering.
10. Cookies and Similar Technologies
Our website uses cookies as well as similar technologies such as local storage, pixels, tags, scripts, and comparable identifiers.
Cookies are small files stored on your device. They may contain information about your device, your settings, or your use of a website.
Necessary Technologies
Necessary cookies and technologies are required for the website to function, to be securely delivered, and to save your privacy or cookie settings.
These technologies can be deployed without prior consent, provided their use is technically required and legally permissible.
Functional Technologies
Functional technologies enable additional features, such as displaying external videos, maps, or other content.
Analytics Technologies
Analytics technologies help us understand how our website is used. This includes page views, interactions, time spent of the page, access sources, and technical information.
Marketing Technologies
Marketing technologies help us measure advertising campaigns, target audiences, recognize returning visitors, and show more relevant advertising on platforms like Google, Facebook, or Instagram.
Consent Management
Non-essential analytics, marketing, and third-party technologies are generally only activated after you have given consent via our cookie banner.
You can:
accept all non-essential services;
decline all non-essential services;
select individual categories;
change or withdraw your selection later.
You can change your selection at any time via the link "Cookie Settings" in the footer of our website.
Withdrawing consent is effective for the future. The lawfulness of the processing carried out up to the withdrawal remains unaffected.
Additionally, you can delete or block cookies through your browser settings. In the event of complete blocking, certain features of our website may be restricted.
11. Google Tag Manager
Insofar as we use Google Tag Manager, we do so for the central management of analytics and marketing tags.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
Google Tag Manager serves the technical triggering and management of other services. It generally does not create independent user profiles of its own. However, when accessed, technical data, particularly your IP address and device information, may be transmitted to Google.
Analytics and marketing services integrated via Google Tag Manager are only activated in accordance with the selection you made in the cookie banner.
12. Google Analytics 4
We use Google Analytics 4, a web analytics service from Google.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited. Further processing may be carried out by Google LLC and other Google companies.
Google Analytics helps us understand how visitors use our website. In particular, the following information may be processed:
visited pages;
time and duration of the visit;
clicks and interactions;
scrolling behavior;
session information;
referrer URL;
campaign information;
browser and device information;
operating system;
screen resolution;
approximate geographical region;
technical identifiers;
cookie and client IDs;
information about conversions.
Google uses the IP address technically to derive, among other things, an approximate geographical region. According to Google, IP addresses of users from Switzerland, the European Economic Area, and the United Kingdom are discarded prior to logging and are not stored permanently.
Google Analytics is generally only activated after your consent. The legal basis, where the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
We use the information obtained to analyze website usage, compile aggregated statistics, improve our content, and measure our marketing efforts.
The retention period for user and event-related data in our Google Analytics property is set to a maximum of 14 months. Aggregated or anonymized reports may be kept longer.
To the extent possible, we disable or restrict the use of analytics data for personalized advertising. Depending on our configuration and your consent, Google Analytics and Google Ads may be linked with each other.
You can withdraw your consent at any time via the cookie settings. Additionally, Google provides a browser add-on to disable Google Analytics.
13. Google Ads and Conversion Tracking
We use Google Ads to promote our services in Google search, on websites, and within the Google advertising network.
In connection with Google Ads, we may use in particular the following features:
conversion tracking;
campaign and success measurement;
remarketing and retargeting;
audience building;
measurement of website visits and contact requests;
analysis of interactions with our ads.
When you reach our website via a Google ad or perform a defined action, Google may store a cookie or comparable identifier.
In particular, the following data may be processed:
IP address;
cookie and device identifiers;
browser and device information;
visited pages;
time of visit;
interactions and clicks;
information about the clicked ad;
campaign parameters;
submitted contact requests;
measured conversions.
Google may link this information with other data, particularly if you are logged into a Google account and have activated corresponding personalization settings.
Google Ads and the associated marketing technologies are generally only activated after your consent.
The legal basis, where the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
You can withdraw your consent at any time via our cookie settings. You can also manage personalized advertising via the advertising and privacy settings in your Google account.
14. Meta Pixel and Meta Ads
We use the Meta Pixel to measure and optimize our advertising campaigns on Facebook and Instagram.
The provider for users in Switzerland and the European Economic Area is generally Meta Platforms Ireland Limited. Further processing may be carried out in particular by Meta Platforms, Inc. in the US.
The Meta Pixel enables us in particular to:
measure whether users visit our website after seeing an ad;
identify which pages or offers were accessed;
measure contact requests and other conversions;
create target audiences for advertising campaigns;
re-engage previous website visitors with advertising;
build lookalike audiences;
analyze the effectiveness of our ads;
better tailor ads to potential interests.
In particular, the following data may be transmitted to Meta:
IP address;
browser and device information;
operating system;
accessed URL;
referrer URL;
time of visit;
cookie and pixel IDs;
Facebook or Meta identifiers;
campaign information;
click and interaction data;
triggered events;
information about contact requests or other conversions.
Meta may associate this information with a Facebook or Instagram account and use it for its own advertising, analytics, security, and personalization purposes. This can also occur if you are not logged in to Facebook or Instagram or do not have an account with them.
The Meta Pixel is generally only activated after your consent.
The legal basis, where the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
In connection with the collection and transmission of certain event data, we and Meta may be joint controllers under data protection law, to the extent provided by applicable law. Meta handles in particular the processing within its platforms as well as compliance with certain data subject rights regarding the data stored by Meta.
You can withdraw your consent at any time via our cookie settings. You can also manage the use of your data for personalized ads via the privacy and advertising settings on Facebook and Instagram.
15. YouTube Videos
Videos from the YouTube platform may be embedded on our website.
YouTube is a service provided by Google. The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
When loading or playing an embedded YouTube video, the following data in particular may be transmitted to Google or YouTube:
IP address;
browser and device information;
accessed page;
referrer URL;
time of access;
cookie and device identifiers;
information about the played video;
interactions with the video player.
If you are logged in to a Google or YouTube account, Google can associate the visit and interaction with your account.
Where technically possible, we use YouTube in privacy-enhanced mode. Nevertheless, data may be transmitted to Google when playing a video at the latest.
YouTube videos are generally only loaded after you have consented to the category for external media or functional services. Before your consent, placeholder is displayed instead.
The legal basis, where the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
16. Vimeo Videos
Videos from the Vimeo platform may be embedded on our website.
The provider is Vimeo.com, Inc., based in the US.
When loading or playing a Vimeo video, the following data in particular may be processed:
IP address;
browser and device information;
accessed page;
referrer URL;
time of access;
cookie and device identifiers;
information about the played video;
interactions with the video player.
If you are logged in to a Vimeo account, Vimeo may combine the interaction with your account.
Vimeo videos are generally only loaded after you have consented to the category for external media or functional services. Before your consent, a placeholder may be displayed instead.
The legal basis, where the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
When using Vimeo, data may be transferred to the US or to other countries. According to the provider, such transfers are based on the applicable data protection mechanisms and contractual guarantees in each case.
17. Google Maps
Maps and location information from Google Maps may be embedded on our website.
The provider for users in Switzerland and the European Economic Area is generally Google Ireland Limited.
When loading a Google Maps map, the following data in particular may be transmitted to Google:
IP address;
browser and device information;
operating system;
accessed page;
time of access;
approximate location information;
cookie and device identifiers;
interactions with the map.
If you are logged in to a Google account, Google can associate the visit or use of the map with your account.
Google Maps is generally only loaded after you have consented to the category for external media or functional services. Before your consent, placeholder or a simple link to the map view may be displayed instead.
The legal basis, where the GDPR is applicable, is Art. 6 para. 1 lit. a GDPR.
18. Contact Form
If you contact us via a contact form, we process the data you enter to respond to your inquiry.
This includes in particular:
name;
email address;
phone number;
company;
subject;
content of the message;
voluntarily submitted additional information;
time of the inquiry;
technical information to prevent abuse.
The form data is transmitted to us via the form and hosting infrastructure provided by Framer or via a service connected to the website.
The processing is done to communicate with you, to answer your inquiry, and, if applicable, to prepare or execute a business relationship.
Insofar as the GDPR is applicable, data processing is carried out, depending on the content of your inquiry, in particular on the basis of:
Art. 6 para. 1 lit. b GDPR for pre-contractual or contractual requests;
Art. 6 para. 1 lit. f GDPR for general business inquiries;
Art. 6 para. 1 lit. a GDPR if you have expressly consented to a specific processing.
Inquiries that do not lead to a business relationship are generally deleted once they have been conclusively processed and there are no legal, security-related, or regulatory reasons for further retention. Regularly, deletion takes place within twelve months at the latest.
If a business relationship arises, the data may be stored longer in accordance with statutory retention obligations.
19. Communication by Email or Phone
If you contact us via email or telephone, we process your contact details and the content of your message to handle your request.
During email communication, data is transmitted via the email and hosting providers involved. These providers may process technical connection and communication data.
Unencrypted emails are not a fully secure means of communication. Therefore, do not send us any sensitive or confidential information by unencrypted email.
Processing takes place in particular for communication, answering your inquiry, as well as initiating or executing a business relationship.
20. Links to Social Networks
Our website may contain links to our profiles on social networks, particularly Facebook, Instagram, LinkedIn, TikTok, YouTube, or Vimeo.
In the case of simple links, data is generally only transferred to the respective platform when you click the link.
After clicking, the privacy policies of the respective platform apply. The providers may record from which website you directed to their platform. If you are logged in there, the visit can be associated with your user account.
We have no complete influence on what data the platforms subsequently process and for what internal purposes they use it.
21. Recipients and Processors
We may disclose personal data to external service providers and recipients, insofar as this is necessary for the purposes described in this Privacy Policy.
These include in particular:
hosting and website providers;
cloud and infrastructure providers;
IT and security service providers;
email and communication providers;
analytics and statistics services;
advertising and marketing platforms;
video, map, and media services;
agencies and technical partners;
accounting and administration service providers;
banks and payment service providers;
insurances;
lawyers, tax advisors, and other consultants;
authorities and courts, provided there is a legal obligation to do so;
potential buyers or business partners in the context of a corporate transaction.
Service providers processing personal data on our behalf are contractually obligated, where required, to process the data only in accordance with our instructions, implement appropriate security measures, and comply with the applicable data protection regulations.
We do not sell personal data and do not share personal data with uninvolved third parties without a legal basis.
22. Processing of Personal Data Abroad
Our service providers and their subcontractors may process personal data in Switzerland, the European Economic Area, the US, and other countries.
Some of these countries may not have data protection laws that guarantee an adequate level of data protection from a Swiss or European perspective.
If personal data is transferred to a country without an recognized adequate level of data protection, we base the transfer – where necessary – in particular on:
an adequacy decision;
standard contractual clauses;
standard contractual clauses adapted for Switzerland;
a recognized data privacy framework;
binding corporate rules;
explicit consent;
necessity for the performance of a contract;
establishment, exercise, or defense of legal claims;
another legally permitted exception.
Despite contractual and organizational protection measures, it cannot be completely ruled out during processing abroad that foreign authorities may access data under their statutory powers.
23. Retention Period
We keep personal data only for as long as necessary for the respective purpose or as long as visual or contractual retention obligations exist.
When determining the retention period, we consider in particular:
the purpose of the data processing;
the type and sensitivity of the data;
statutory retention obligations;
ongoing contractual relationships;
statutes of limitations;
potential legal claims;
security and evidence requirements;
technical storage and backup cycles.
Business documents, accounting records, and contract-relevant correspondence can generally be retained for ten years in accordance with legal requirements.
Data from contact inquiries that do not lead to a business relationship are generally deleted after the completion of the inquiry or after twelve months at the latest, unless there are reasons for a longer retention.
Cookie and consent information is stored in accordance with their technical runtime and legal proof obligations.
Upon expiry of the retention period, the data is deleted, anonymized, or blocked, unless deletion is not technically immediately possible.
24. Data Security
We take appropriate technical and organizational security measures to protect personal data from loss, misuse, unauthorized access, alteration, disclosure, or destruction.
These measures may include in particular:
encrypted data transmission via TLS/HTTPS;
access restrictions;
role and authorization concepts;
strong passwords and multi-factor authentication;
regular updating of the systems used;
backups;
logging of security-relevant processes;
protection against malware and unauthorized access;
selection of suitable service providers;
internal data protection and security policies.
A completely risk-free data transmission and storage cannot be guaranteed despite appropriate protection measures.
25. Data Breaches
In the event of a breach of data security, we investigate the incident immediately and take the necessary measures.
Where legally required, we inform the competent data protection supervisory authority and, if applicable, the affected individuals.
26. Your Rights
Depending on the applicable data protection law and the respective conditions, you can assert the following rights in particular:
information on whether and which personal data we process about you;
provision of a copy of your personal data;
rectification of inaccurate or incomplete data;
deletion of your personal data;
restriction of data processing;
objection to certain data processing operations;
withdrawal of consent given;
provision or transfer of certain personal data in a standard electronic format;
information about the origin of the data;
information on recipients or categories of recipients;
review of an automated individual decision;
complaint to a competent data protection supervisory authority.
These rights are not absolute. We may deny, restrict, or defer a request if statutory conditions are met, overriding interests conflict, retention obligations exist, or the request is manifestly unfounded or disproportionate.
To process a request, we may require suitable proof of identity. This is to prevent personal data from being disclosed to unauthorized persons.
To exercise your rights, please contact us at:
27. Withdrawal of Consent
You can withdraw consent given at any time with effect for the future.
Consent for cookies, analysis, marketing, and third-party services can be changed or withdrawn via the "Cookie Settings" link in the footer of our website.
Other consents can be withdrawn by email to info@zeja.ch.
The withdrawal does not affect the lawfulness of the processing carried out prior to the withdrawal.
28. Objection to Direct Marketing
Insofar as we process personal data for direct marketing purposes, you can object to this processing at any time.
After your objection, we will no longer use your personal data for corresponding direct marketing. Minimal blocking information can be kept to ensure that your objection is observed in the future.
29. Automated Decisions and Profiling
Our analysis and advertising services may use data to form user groups, infer interests, or target ads more specifically. Under data protection law, this may be considered profiling.
We generally do not make solely automated decisions based on this information that produce legal effects concerning you or similarly significantly affect you.
30. Data of Children and Minors
Our website is primarily aimed at companies, business clients, and adult prospects.
We do not knowingly collect personal data from children without the consent of the holder of parental responsibility or another legal basis.
Holders of parental responsibility can contact us if they suspect that personal data of a child was transmitted to us without sufficient basis.
31. Obligation to Provide Personal Data
Generally, there is no obligation to provide us with personal data.
However, certain details are necessary for us to respond to inquiries, create offers, conclude contracts, or perform services. Without these details, we may not be able to offer corresponding services or only to a limited extent.
32. External Websites
Our website may contain links to third-party websites and offers.
The respective operators are responsible for the content and privacy practices of these external offerings. We recommend that you read the privacy policies of the providers concerned.
33. Competent Data Protection Supervisory Authority
For data protection matters in Switzerland, you can contact the Federal Data Protection and Information Commissioner:
Federal Data Protection and Information Commissioner – FDPIC
Switzerland
Insofar as the GDPR is applicable, you also have the right to lodge a complaint with a competent data protection supervisory authority in the European Economic Area, in particular at your habitual residence, place of work, or place of the alleged infringement.
We recommend that you contact us directly first so we can review and address your concerns.
34. Changes to This Privacy Policy
We can adapt this Privacy Policy at any time, in particular if we change our website, our services, the technologies used, or legal requirements.
The version published on our website at any given time shall apply.
In the event of material changes, we may notify you separately on our website.
As of: July 21, 2026
ZEJA GmbH
Landstrasse 38
5436 Würenlos
Switzerland
info@zeja.ch