The responsible handling of your data is important to us.
Introduction
We respect your privacy and data protection is important to us. This Privacy Policy informs clients of Helvecura Cooperative and users of this website, in accordance with Swiss and EU data protection law, about the type, scope and purpose of the collection and use of personal data. We always provide you with transparent information about why we need your data and whether, or for how long, we store it.
We have taken technical and organisational measures to ensure that data protection regulations are complied with both by us as well as by our external service providers. Personal data must be processed lawfully, in good faith and in a manner that is comprehensible to the data subject.
We act in accordance with the principles of the FADP, in other words, in the light of transparency, purpose limitation, fairness, data minimisation, limited storage periods, data accuracy, data security, privacy by design and privacy by default.
When performing a public task outside of acts under private law, the provisions for federal bodies apply. For example, a data protection consultant is appointed and a processing record is always maintained. In this case, a legal basis is required for data processing (Art. 33 et seq. FADP).
Important: This Privacy Policy is subject to change. Please stay informed and keep up-to-date on this website.
1. Purpose of this Privacy Policy
Data protection is a matter of trust. Your trust is very important to us. This Privacy Policy informs you about the collection, processing and use of your personal data.
Primarily, this Privacy Policy provides the following information:
- which personal data we collect and process;
- the purposes for which we use your personal data;
- who has access to your personal data;
- the benefits of our data processing for you;
- duration of processing and storage of your personal data;
- your rights with regard to your personal data;
- and our contact addresses.
This Privacy Policy is valid under both the Swiss Data Protection Act (FADP) as well as the European General Data Protection Regulation (GDPR).
2. Terms
2.1. Personal data
Personal data is all information that can be associated with a specific person, can be attributed to a specific person or identifies a specific person (such as names, addresses, IP numbers, email addresses). A natural person is deemed identifiable if they can be identified directly or indirectly, in particular through assignment to an identifier such as a name, to an identification number, to location data, to an online identifier or to one or more special features that express the physical, physiological, genetic, mental, economic, cultural or social identity of this natural person.
2.2. Processing
Processing is any handling of personal data, irrespective of the means and procedures used, in particular the procurement, storage, retention, use, modification, disclosure, archiving, deletion or destruction of data.
2.3. Controller
The controller is the person who specifies the purpose and means of processing, i.e. who decides whether personal data is to be processed at all and which essential conditions apply for this purpose.
2.4. Order processor
The order processor is the person who arranges for third-party data processing. Although the order processor decides itself whether it operates its business and whether it processes data of the controller, it is ultimately the controller who decides whether this processing is carried out. The controller has the right to issue instructions to the order processor.
3. Data processing controller
Under data protection law, the controller for a specific data processing is the company, primarily the contractual partner, who determines the purpose and scope.
The controller responsible for data processing in accordance with this Privacy Policy is:
Helvecura Cooperative
c/o ATAG Wirtschaftsorganisationen AG
P.O. Box 1023
3000 Bern 14
+41 31 380 79 61
info@helvecura.ch
Certain processing operations may be carried out under the responsibility of other companies. If this is the case, it is indicated below in the respective description of the processing.
4. Data protection consultant
The following person is appointed as data protection consultant:
Raphael Ciapparelli
Bracher und Partner Recht AG
Eisenbahnstrasse 11
P.O. Box 1661
4901 Langenthal
5. Recipients of this Privacy Policy
This Privacy Policy applies for all persons whose data we process and regardless of how you contact us, e.g. online, by telephone or by post.
It applies for the processing of personal data already collected as well as for the processing of personal data to be collected in the future.
You can find further information in the relevant contract. This may contain additional information on the purpose of data processing.
6. Collection of personal data
6.1. Data provided
You often disclose personal data to us yourself, for example by communicating with us, transmitting data and making it available to us.
You do this, for example, in the following situations:
- you conclude a contract with us;
- you request a customer account/login;
- you contact our office;
- you register for other offers (such as events, Annual General Meeting).
You provide personal data primarily on a voluntary basis. However, in order to process and fulfil orders and contracts, we need to collect and process certain personal data. Statutory retention obligations also exist. Otherwise, we will be unable to enter into, fulfil or continue the contract concerned. Processing personal data is generally permitted for the purposes of order/contract fulfilment.
If you provide us with data about other persons (such as work colleagues), we can assume that you are authorised to do so and that this data is correct. You must also ensure that these other persons have been informed of this Privacy Policy.
6.2. Data collected
Personal data can also be collected automatically, for example, online. This often includes behavioural and transaction data as well as technical data (e.g. time of access to the website, etc.).
Personal data may be collected independently in the following cases, for example:
- you request a login for the customer portal of our administration application;
- you interact with our administration application via the customer portal (downloading and uploading documents, etc.);
- you visit our website;
- you disclose your customer account in a communication with us;
- you interact in another way using one of our communication measures (e.g. email).
- We can derive further personal data from existing personal data to evaluate behavioural and transaction data, for example. This type of derived personal data is often preference data.
Aus bereits vorhandenen Personendaten können wir bspw. Auswertung von Verhaltens- und Transaktionsdaten weitere Personendaten ableiten. Bei solchen abgeleiteten Personendaten handelt es sich oft um Präferenzdaten.
6.3. Data received
We may receive personal data from other contractual partners if you consent to their transfer to us. We may also obtain personal data about you from public sources.
7. Purposes of processing
Helvecura is a self-help organisation for the holders of compulsory stocks of therapeutic products in the interests of economic national supply. As a cooperative, it performs tasks assigned to it by the Swiss Confederation in connection with compulsory stockpiling and safeguards the interests of its members in the area of compulsory stockpiling.
In addition, we collect personal data for the following purposes:
- opening a customer account (login for the administrative application customer portal) for the purpose of reporting the medicinal products placed on the market;
- invoices of fees and statements of compensation;
- communicating with third parties and processing their enquiries (e.g. generic enquiries, notification of new articles);
- reviewing and optimising needs analysis procedures with a view to addressing customers directly and collecting personal data from publicly available sources;
- asserting legal claims and defence in relation to legal disputes and administrative proceedings;
- optimising the website (adapting the website to your needs);
- defence against and recording of hacking attacks
When you visit the website, we also temporarily store your data in a log file known as a server log file. The log files are stored to guarantee the functionality of the website and to ensure the security of our information technology systems. The data is deleted as soon as it is no longer required for the purpose for which it was collected.
We use the personal data we collect primarily for the purpose of contract fulfilment or order fulfilment, in other words, to support our customers or clients with their projects. This also includes fulfilling contracts with our partners.
If your personal data is processed in the context of public sector contracts, the law and Ordinance dictate which data we process and in what form.
On behalf of these customers or clients, we process the data for the purpose of fulfilling our tasks in connection with the compulsory stockpiling of therapeutic products, optimising website visits, processing enquiries, optimising access to the customer portal and creating increased security through automatic logout.
7.1. Communication
We would like to stay in touch with you and respond to your individual concerns. We therefore process personal data for the purpose of communicating with you.
The purpose of communication mainly includes:
- responding to enquiries;
- contacting you if you have any questions;
- communication in connection with order/contract fulfilment;
- notifications of progress or status;
- quality assurance and training in relation to the fulfilment of the requirements for compulsory stockpiling.
7.2. Contract processing
We also want to ensure that the order/contract is fulfilled to your utmost satisfaction. We therefore process personal data to fulfil the order/contract and all related areas directly or indirectly, such as support, maintenance, repairs and information about innovations and adjustments. The purpose of order/contract processing generally encompasses everything that is necessary or expedient to conclude, execute and fulfil an order/contract. Order/contract processing may also include an agreed personalisation of services.
7.3. Information and marketing
We also process personal data for the purpose of maintaining relationships, for example, by sending written or electronic messages. These communications can be personalised.
And may include the following:
- electronic messages;
- information by post;
- other printed matter;
- invitations to events.
7.4. Safety and prevention
We want to ensure your safety and ours as well as prevent misuse.
To ensure your safety and ours as well as to prevent misuse, we process personal data for security purposes, to guarantee IT security, to prevent theft, fraud and misuse as well as for evidentiary purposes.
We will therefore collect, evaluate and store your personal data for security purposes.
7.5. Legal obligations
We will comply with any existing legal obligations, for example, to retain or disclose information. Otherwise, we will not disclose your personal data.
7.6. Upholding rights
In order to enforce our claims, we process your personal data, for example within the context of preserving evidence or clarifying any prospects for litigation. Upon request, we will disclose your personal data to authorities.
8. Legal basis for data processing
The processing of personal data is based on various legal bases depending on the purpose of the processing. Data processing is primarily permitted in Switzerland unless prohibited by law (FADP or GDPR).
Data processing is permissible for fulfilling an order/contract independently or even against the will of the data subject.
Furthermore, legitimate interests allow us to process data. Legitimate interests can be of an ideal or economic nature. One recognised purpose is, for example, direct advertising. This includes contacting people with advertising information, for example, by phone, email or letter.
Any data processing based on your consent or required to comply with Swiss or foreign legal regulations is also permitted.
9. Disclosure of your personal data
9.1. Within Helvecura Cooperative
We may share your personal data within our organisation. The transfer may serve internal administration purposes or support the company concerned.
9.2. To third parties
We may also pass on your personal data to companies outside our company if we use their services. These service providers mainly process your personal data on our behalf as order processors. By means of a data processing agreement (DPA), we oblige our order processors to process your personal data exclusively in accordance with our instructions and to take suitable data security measures.
Disclosing your personal data to other third parties for their own purposes requires your consent, unless there is a legal basis that obliges us to disclose it by law, such as:
- exchange with the supervisory authority;
- the transfer of claims to other companies;
- the review or execution of corporate transactions such as company acquisitions, sales and mergers;
- the disclosure of personal data to courts and authorities in Switzerland and abroad;
- the processing of personal data to comply with a court order or official order;
- to assert legal claims.
10. Disclosure abroad
10.1. Switzerland and EU
We process and store personal data in Switzerland and the European Union. The GDPR guarantees a level of data protection equivalent to that of Switzerland.
In certain cases, we may also disclose personal data to service providers and other recipients who are located outside this territory or who process personal data outside of this territory, generally in any country in the world.
Personal data may only be transferred abroad without problems (or can be accessed from abroad) if the country in question has a level of protection that is appropriate from a Swiss perspective.
The countries concerned outside the EU often do not have laws that protect your personal data to the same extent as in Switzerland or the EU. If we transfer your personal data to one of these countries, we will ensure that your personal data is protected in an appropriate manner.
One means of ensuring appropriate data protection is contractual in nature, which ensures the necessary data protection of your personal data abroad. Standard contractual clauses (approved by the FDPIC Federal Data Protection and Information Commissioner) are often used. Contractual arrangements often do not fully compensate for weaker legal protection or even a lack of legal protection, so your consent would be required.
10.2. Transfer to third countries (e.g. USA)
Our website may incorporate services from companies based in the USA or with connections to the USA. You must consent to this data processing. In this case, unrestricted access by the US authorities to your personal data cannot be excluded. No legal action may be taken.
In the following cases, we cannot adequately ensure protection of your personal data, even by means of standard data protection clauses.
This list of services and service providers is not exhaustive:
Akismet
www.akismet.com
Datenschutzerklärung: https://automattic.com/privacy-notice/
Cloudflare
www.cloudflare.com
Datenschutzerklärung: https://www.cloudflare.com/security-policy
The accuracy of the above address and group information is not guaranteed and may change in a dynamic economic environment.
However, it cannot be ruled out for all the aforementioned companies that they must grant the US authorities access to your personal data (US CLOUD Act), even if it is not stored in the US.
For this reason, this type of data processing only takes place with your explicit consent.
The information concerning the USA is provided subject to the proviso that Switzerland and the USA still do not have an EU-US data protection framework or an equivalent adequacy decision in terms of a Swiss-US data privacy framework.
10.3. Data is transferred to the following countries
Depending on the order or its self-declaration, data may be transferred to the following countries:
- Belgium
- Germany
- France
- United Kingdom
- Ireland
- Liechtenstein
- Luxembourg
- Netherlands
- Austria
- Portugal
- Spain
Basically, this concerns the following data:
- Login for the Helvecura administration application
- Guarantee Fund contribution invoices
- Compulsory storage compensation
- General correspondence
This only concerns countries with an appropriate level of data protection.
11. Particularly sensitive personal data
Certain types of personal data are considered to be particularly sensitive under data protection law. This includes primarily, but not exclusively, health data, biometric characteristics or DNA profiles.
We only process particularly sensitive personal data if it is absolutely necessary for providing a service, if you have disclosed this data voluntarily or consented to its processing. This type of data is primarily not passed on abroad.
12. Profiling
We do not perform profiling, but we will inform you as follows:
Profiling refers to the automated processing of personal data for the purpose of analysing your personal aspects, such as personal interests, preferences, affinities and habits.
We do not perform profiling without your consent.
13. Automated individual decisions
Automated individual decisions are fully automated, thus without any human influence. However, these decisions have legal consequences for the data subject or significantly affect them in a different manner.
We do not use automated individual decisions. However, if we were to use automated individual decisions in individual cases, we would inform you. You will then have the option of having the decision reviewed by a person.
14. Data protection and security
We take appropriate and state-of-the-art security measures of a technical and organisational nature to uphold the security of your personal data, to protect it against unauthorised or unlawful processing and to counteract the risk of loss, inadvertent alteration, unintended disclosure or unauthorised access.
We also oblige our order processors to take appropriate technical and organisational security measures.
Unfortunately, we cannot rule out breaches of data with absolute certainty. We will inform you and the FDPIC of any data loss or data leaks in the cases provided for by law.
15. Processing time
In accordance with the principles of data minimisation and transparency, we process and store your personal data only for as long as it is necessary to achieve the agreed purpose (such as fulfilling the contract), in other words, only for as long as we have a legitimate interest in storage, for example, until payment has been made in full.
In the case of statutory retention obligations, the data is stored for a corresponding length of time.
If we wish to store your data for longer, we will ask for your consent.
16. Cookies and similar technologies
16.1. Purpose
We provide information on how and for what purpose we collect, process, use and store personal data and other data when our website and the customer portal of our administration application are used, in particular with regard to cookies and similar technologies. The term “website” below also refers to the administration application.
16.2. Log data
For technical reasons, every time our website is used, certain data is automatically stored temporarily in log files known as server log files. This includes the following technical data, whereby the list is not exhaustive:
- browser type and version;
- operating system used;
- the user’s Internet service provider;
- host name of the accessing computer;
- the user’s IP address;
- date and time of access;
- amount of data sent in bytes;
- name (according to the user role defined in the management application);
- telephone number;
- email.
With the exception of the customer portal login screen of the administration application, this data cannot be assigned to a specific person and it is not merged with other data sources. This data is processed for the purpose of using our website and establishing a connection as well as to ensure functionality, system security and stability, to optimise our website and for statistical purposes. The data will only be stored for as long as necessary to achieve the purpose for which it was collected. Accordingly, the data will be deleted at the end of each session. The storage of log files is absolutely necessary to operate the website. You will therefore not be able to object to this.
The IP address is also evaluated together with log data and other data in the event of attacks on the IT infrastructure for clarification and defence purposes and, if necessary, used in the context of criminal and civil proceedings, for example, to identify the persons concerned.
16.3. Cookies and similar technologies
Our websites use cookies. Cookies are small text files that are stored on your computer or mobile device via an Internet browser when you visit the websites. If you visit one of the websites again, the website will recognise you without knowing who you are. The purpose of this recognition is to make it easier for you to use the website. By using cookies, we can provide you with more user-friendly services that would not be possible without the cookie setting.
You can configure your browser’s settings so as to block certain cookies or similar technologies or to delete existing cookies and other data previously saved in your browser. You can also expand your browser with software (known as “plug-ins”) that blocks tracking by certain third parties. You can access information on this using the help pages of your browser, which can often be found under Data Privacy.
However, if you block cookies and similar technologies, our website may no longer be able to function fully.
16.4. Akismet
Our website uses Akismet software from Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, United States of America. Akismet is a service that protects the website from spam messages as comments under blog posts, content pages and other types of content. To check whether a comment qualifies as spam, Akismet collects the input data of the website user as well as technical information such as IP address, country of residence, browser, screen resolution and related information. This data is transmitted to the USA, where the servers of the service are located, for automatic verification. The data will be processed, then further processed, shared and deleted in accordance with the privacy policy of Automattic Inc.
16.5. Cloudflare
We use DNS services and a Content Delivery Network (CDN) from Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA for our website. Cloudflare is certified under the Privacy Shield Agreement and thereby offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnZKAA0&status=Active). CDNs are services with which content, in particular larger media files such as graphics and videos, can be delivered more quickly using regionally distributed servers. User data processing takes place solely for the aforementioned purposes and to maintain the security and functionality of the CDN. DNS (Domain Name System) services help the browser to find the appropriate IP address of the server hosting and delivering this page for an entered domain such as www.example.com. Use is based on our legitimate interests, i.e. interest in the secure and efficient provision, analysis and optimisation of our online offer.
16.6. Matomo
Matomo, formerly Piwik, is an open-source web application for web analytics. It is the successor of the now discontinued phpMyVisites project and an alternative to Google Analytics. Matomo can be hosted in the cloud or locally with the provider. On this website, Matomo is used to collect statistical evaluations about the performance of individual pages with the aim of optimising user experience. The following data is processed: the browser type and version you use, your operating system, your country of origin, the date and time of the server request, the number of visits, the length of time you spend on the website and any external links you use. The user’s IP address is anonymised before it is stored. Matomo uses cookies stored on the user’s computer, which enable an analysis of the use of our website by users. This can involve creating pseudonymous user profiles from the processed data. The information generated by the cookie regarding your use of this website is only stored on our server and is not passed on to third parties.
16.7. Mapbox
On our website we embed, amongst other things, or exclusively, maps from the “Mapbox” service of the provider Mapbox, Logan Exchange 2nd Floor 1509 16th Street Northwest Washington, DC 20036, USA. The processed data may include mainly IP addresses and the users’ location data. The data may be processed in the USA and/or Europe. Mapbox Privacy Policy: https://www.mapbox.com/privacy/. For more information, please contact privacy@mapbox.com.
17. Data processing after consent
Data may only be processed by certain service providers, such as Google, LinkedIn, Facebook, YouTube, etc., with explicit consent, if possible by means of “double opt-in”. You can revoke your consent at any time.
You must consent to data processing by companies based in the USA or with relationships in the USA. In this case, unrestricted access by the US authorities to your personal data cannot be excluded. No legal action may be taken. In the following cases, we cannot adequately ensure protection of your personal data, even by means of standard data protection clauses. In this respect, it cannot be ruled out that the US authorities may have access to your personal data (US CLOUD Act). This is subject to the proviso that Switzerland and the USA continue to have an equivalent adequacy decision in terms of a Swiss-US data privacy framework.
18. Your rights to revocation, information, rectification, erasure, etc.
18.1. Right to information
You have the right to request a confirmation from us as to whether personal data concerning you is processed by us. In this case, you have the right to information about this personal data and to further information. Please submit the request for information together with proof of your identity.
18.2. Right to rectification
You have the right to demand from us the rectification of your inaccurate personal data without undue delay. Taking into account the purposes of processing, this also includes the right to demand the completion of incomplete personal data – including by means of a supplementary declaration.
18.3. Right to erasure
You have the right to demand the erasure or anonymisation of all your personal data without delay, unless we are legally obliged to retain it.
18.4. Right to data portability and surrender
You also have the right to receive the data you have provided to us in a common file format.
18.5. Revocation of consent
You can revoke your consent at any time with future effect. Please note that exercising these rights may conflict with contractual agreements and this may, for example, have cost implications.
18.6. Objection
You can object to data processing, particularly if we process your personal data based on a legitimate interest and the other applicable requirements are met.
18.7. Legal recourse
You can also assert your rights in court or file a report with the competent supervisory authority. The Fed-eral Data Protection and Information Commissioner (FDPIC) is responsible for this in Switzerland. You can find more information at: https://www.edoeb.admin.ch.
19. Contact Information
If you have any questions or concerns about data protection on our website, if you would like information about your data or if you would like to have your data deleted, please get in touch with our contact person for data protection law using the details below (online or by post), as well as if you have any questions about this Privacy Policy or the processing of your personal data.
Helvecura Cooperative
c/o ATAG Wirtschaftsorganisationen AG
P.O. Box 1023
3000 Bern 14
20. Amendments to this Privacy Policy
We reserve the right to amend this Privacy Policy at any time. We therefore recommend that you review this Policy on a regular basis.
Last updated: 8 May 2026