1. Controller and contact
The controller responsible for the processing of personal data in connection with this website is:
NeoKultur GmbH
St. Galler-Ring 202
4054 Basel
Switzerland
UID: CHE-112.866.834
NeoKultur GmbH operates this website under the Safescout24 brand.
Postal address: Postfach 238, 4051 Basel
Telephone: +41 (0) 76 625 62 82
E-mail: info@safescout24.ch
For any data protection matter, in particular requests for access, rectification or erasure, please contact us at the e-mail address above or in writing at the postal address. We have appointed neither a data protection adviser under Article 10 revFADP nor a representative in the European Union under Article 27 GDPR.
2. Scope and legal bases
This privacy policy applies to the website safescout24.ch and all its subpages in German and English.
The governing law is the Swiss Federal Act on Data Protection of 25 September 2020 (revFADP). Where individuals located in the European Union or the European Economic Area are concerned, Regulation (EU) 2016/679 (GDPR) applies in addition. Where we cite a legal basis under the GDPR below, we do so for that case; under Swiss law we base the processing on Articles 6 and 31 revFADP.
3. Definitions
Personal data means any information relating to an identified or identifiable natural person. Processing means any handling of personal data, regardless of the means and procedures applied, in particular the collection, storage, use, disclosure and deletion of such data.
Data subject means you as a visitor to this website. Processors are third parties who process personal data on our behalf and on our instructions.
4. Principles of processing
We process personal data in good faith, lawfully and proportionately. We collect data only for a specific purpose that is apparent to you, and we process it only in a manner compatible with that purpose. We do not collect more data than we need for the respective purpose, and we delete or anonymise it as soon as the purpose ceases to apply and no statutory retention obligation stands in the way.
5. Processing when you visit the website
Each time this website is accessed, your browser transmits data to our web server for technical reasons. This data is recorded in what are known as server log files:
- the IP address of the requesting device
- the date and time of access
- the name and address of the file or page requested
- the website from which the access was made (referrer)
- the browser used and its version
- the operating system used
- the volume of data transferred and a message indicating successful retrieval
We process this data in order to ensure the operation of the website, to detect and remedy faults, to deliver content correctly and to safeguard the security of our systems. This data is not combined with other data sources and is not analysed in order to identify individual persons; analysis in the event of an attack on our infrastructure is reserved.
The legal basis is our legitimate interest in the secure and uninterrupted operation of the website, Article 31 paragraph 1 revFADP and Article 6 paragraph 1 letter f GDPR.
The website is operated by an external hosting provider that supplies the server infrastructure and acts as our processor in this respect. Log files are generally retained for a few weeks and then deleted automatically.
6. Cookies and similar technologies
Cookies are small text files placed on your device when you visit a website. We treat comparable technologies such as the browser’s local storage in the same way.
On this website we use a consent management tool. On your first visit a banner appears through which you can give or refuse your consent for the non-essential categories. A distinction is made between the categories Functional, Preferences, Statistics and Marketing. The Functional category covers only technically necessary storage and cannot be deselected; it includes the cookie in which your cookie decision itself is recorded and a cookie storing your chosen language version of the website.
Your consent is voluntary and you may withdraw it at any time with effect for the future. You can withdraw it via the link to the cookie settings, which is available in the banner and in the cookie policy. You can also delete cookies at any time in your browser settings or restrict their placement generally; individual functions of this website may then no longer be fully usable.
Details of the cookies set, their function and their storage period can be found in our cookie policy.
The legal basis for technically necessary storage is our legitimate interest in operating the website, Article 31 paragraph 1 revFADP and Article 6 paragraph 1 letter f GDPR. The legal basis for all other cookies and for the consent-based services listed in section 9 is your consent, Article 6 paragraph 6 revFADP and Article 6 paragraph 1 letter a GDPR.
7. Contacting us and forms
7.1 Enquiry form
On the enquiry form page you can submit your request for a safe deposit box in several steps. In doing so we collect:
- the desired safe deposit box size
- whether you are enquiring from Switzerland or from abroad
- your interest in a key tag
- your name
- your telephone number
- your e-mail address
- your message to us
In addition, technical origin data is transmitted that records which campaign or referral brought you to the form.
We process this information solely in order to answer your enquiry and to prepare and perform any resulting contractual relationship. The information is sent to us by e-mail, stored in the database of this website so that no enquiry is lost, and transmitted to a system we use for processing enquiries. A copy is sent to our marketing agency, which supports us in handling enquiries (see section 10). After submitting the form you are redirected to a confirmation page.
The legal basis is the initiation and performance of a contract, Article 31 paragraph 2 letter a revFADP and Article 6 paragraph 1 letter b GDPR.
7.2 Contact by e-mail, telephone and WhatsApp
If you contact us by e-mail or telephone, we process the information provided in order to answer your enquiry. A window is also available on the website through which you can start a conversation via the WhatsApp messaging service; in doing so you provide your name, your WhatsApp number, your e-mail address and the service you are interested in.
If you continue the conversation on WhatsApp, the terms and the data processing of the provider WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland apply in addition. We have no influence over the processing of connection and usage data by that provider. If you wish to avoid this, please use our e-mail address or the enquiry form instead. Information on data processing by WhatsApp is available at whatsapp.com/legal/privacy-policy-eea.
The legal basis is the initiation and performance of a contract, respectively our legitimate interest in answering enquiries, Article 31 revFADP and Article 6 paragraph 1 letters b and f GDPR.
7.3 Sending our e-mails
We use a dispatch service for the reliable delivery of the e-mails generated by this website. It processes the recipient address and the content of the message on our behalf.
8. Job applications
We advertise vacancies on our job advertisements page. Application documents are sent to us by e-mail. We process the information they contain solely in order to assess your application and carry out the selection procedure. Access is limited to the persons involved in that procedure.
The legal basis is the initiation of an employment relationship, Article 31 revFADP and Article 6 paragraph 1 letter b GDPR.
If no employment results, we delete the documents six months after the procedure has been concluded. If you would like us to keep your documents for future vacancies, please let us know; we will then retain them on the basis of your consent, which you may withdraw at any time.
9. Third-party services used
The services listed below are loaded only after you have given the corresponding consent via the banner, insofar as consent is stated as the legal basis for them.
9.1 Google Tag Manager
We use Google Tag Manager provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Tag Manager is not itself an analytics tool and does not set cookies; it serves solely to embed and manage other tools on the website. Your IP address is transmitted to Google when it loads.
The legal basis is your consent, Article 6 paragraph 6 revFADP and Article 6 paragraph 1 letter a GDPR.
9.2 Google Analytics 4
We use Google Analytics 4 provided by Google Ireland Limited in order to analyse the use of our website and improve our offering. The data collected includes the pages visited, the time spent, the approximate geographic origin, the type of device and browser used, and the website from which you reached us. Your IP address is truncated by Google and is not combined with other Google data.
The legal basis is your consent, Article 6 paragraph 6 revFADP and Article 6 paragraph 1 letter a GDPR. Information on data processing by Google is available at policies.google.com/privacy.
9.3 Google Site Kit and Google Search Console
The Google Site Kit extension is installed on the website, connecting our website with Google services. It consolidates the analyses of the Google services named above within the website’s administration area. This does not involve any collection of personal data beyond that described in section 9.2.
9.4 Meta Pixel
We use the Meta Pixel provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. The pixel records which pages you visit on our site and which actions you take there. This allows us to measure the success of our advertising on Facebook and Instagram and to show you advertising there that matches your interests. If you have a Facebook or Instagram account, Meta may associate the data collected with your account.
The legal basis is your consent, Article 6 paragraph 6 revFADP and Article 6 paragraph 1 letter a GDPR. Information on data processing by Meta is available at facebook.com/privacy/policy.
9.5 Google Maps
On the contact page we embed a map from the Google Maps service provided by Google Ireland Limited so that you can find our location. The map is loaded only after you have consented to the Marketing category; until then you see a placeholder with a notice in its place. Your IP address is transmitted to Google when the map loads.
The legal basis is your consent, Article 6 paragraph 6 revFADP and Article 6 paragraph 1 letter a GDPR.
9.6 Google Fonts
To display fonts consistently, this website embeds typefaces from the Google Fonts service provided by Google Ireland Limited. The fonts are not retrieved from our own server but from a Google server; your IP address is transmitted to Google in the process.
The legal basis is your consent, Article 6 paragraph 6 revFADP and Article 6 paragraph 1 letter a GDPR.
9.7 Consent management
To obtain and document your consent we use an extension that runs on our own server. It records which consent you gave and when. This record is required by law so that we can demonstrate the consent given.
The legal basis is compliance with a legal obligation and our legitimate interest in demonstrating consent, Article 31 revFADP and Article 6 paragraph 1 letters c and f GDPR.
9.8 Technical extensions without disclosure of data
To speed up the website, optimise images and provide the German and English language versions, we use extensions that operate exclusively on our own server. They do not pass any data to third parties. A technically necessary cookie is set for the language switch, recording your choice of language.
9.9 Social networks
In the footer and on the contact page we link to our profiles on Instagram and Facebook using icons. These are simple links, not embedded content. Data is transmitted to the respective provider only once you click the link and open the network’s page. The respective provider is responsible for the data processing on those pages.
10. Disclosure to third parties and processors
We pass on personal data only where this is necessary in order to provide our services, where you have consented, or where we are legally obliged to do so. We do not sell personal data.
The processors we use include in particular:
- the provider that operates our website and supplies the server infrastructure
- the service through which the e-mails from this website are sent
- Spaeth-Wiesner GmbH, Augst BL, Switzerland, which supports us with marketing, website maintenance and the handling of incoming enquiries and receives a copy of form enquiries for that purpose
Agreements are in place with all processors obliging them to process personal data only on our instructions and only as we ourselves are permitted to, and to ensure appropriate data security.
Beyond this, we may disclose personal data to authorities, courts or legal representatives where we are legally obliged to do so or where it is necessary to protect our rights.
11. Disclosure abroad
The services named in section 9 are offered by companies domiciled in Ireland. Their parent companies are domiciled in the United States of America, and it cannot be ruled out that data is transmitted there.
Switzerland and the European Union recognise an adequate level of data protection for companies certified under the Swiss-U.S. Data Privacy Framework and the EU-U.S. Data Privacy Framework respectively. Google and Meta are certified under that framework. Insofar as transfers are not covered by it, we base them on the Standard Contractual Clauses of the European Commission, which are recognised by the Swiss Federal Data Protection and Information Commissioner.
The legal bases are Articles 16 and 17 revFADP and Articles 44 to 49 GDPR. We inform you about disclosure abroad on the basis of Article 19 paragraph 4 revFADP.
12. Retention and deletion
We retain personal data for as long as the respective purpose requires or the law demands:
- server log files: generally a few weeks
- form enquiries and correspondence: until your request has been dealt with conclusively; if the enquiry leads to a contract, the periods below apply
- business records and documents relating to contracts: ten years, pursuant to Article 958f of the Swiss Code of Obligations
- application documents: six months after conclusion of the procedure
- record of cookie consent: for the period necessary to comply with the obligation to demonstrate consent
After that we delete or anonymise the data.
13. Data security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss and misuse. These include in particular the encrypted transmission of all content on this website via TLS, recognisable by the padlock symbol and the address beginning with https, as well as restricted access rights to the administration of the website and regular updates of the software used.
Complete protection against every conceivable form of access cannot be achieved when transmitting data over the internet according to the current state of the art. We review our measures on an ongoing basis and adapt them to technical developments.
The legal bases are Article 8 revFADP and Article 32 GDPR.
14. Your rights
Within the scope of the applicable law, you have the following rights.
Under the revFADP:
- the right of access to the data processed about you (Article 25)
- the right to rectification of incorrect data (Article 32 paragraph 1)
- the right to erasure and to prohibit a particular processing operation (Article 32 paragraph 2)
- the right to the handing over and transfer of your data (Article 28)
- the right to withdraw a consent given at any time (Article 6 paragraph 6)
Under the GDPR, insofar as it applies to you:
- the right of access (Article 15)
- the right to rectification (Article 16)
- the right to erasure (Article 17)
- the right to restriction of processing (Article 18)
- the right to data portability (Article 20)
- the right to object to processing based on a legitimate interest (Article 21)
- the right to withdraw a consent given at any time (Article 7 paragraph 3)
The withdrawal of consent takes effect for the future; the lawfulness of the processing carried out up to that point remains unaffected.
Please address your request to the contact details given in section 1. Access is generally free of charge and is usually granted within thirty days (Article 25 paragraphs 6 and 7 revFADP). To ensure that we do not disclose data to an unauthorised person, we may require proof of your identity.
15. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority.
In Switzerland this is the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch.
Individuals in the European Union or the European Economic Area may additionally contact the supervisory authority at their place of residence, their place of work or the place of the alleged infringement (Article 77 GDPR).
16. Automated individual decision-making
We do not take decisions based solely on automated processing that produce legal effects concerning you or significantly affect you. No high-risk profiling within the meaning of Article 5 letter g revFADP takes place.
17. Changes to this privacy policy
We may amend this privacy policy at any time, in particular if our services, the services we use or the legal situation change. The version published on this website at the relevant time applies. We recommend that you read it again from time to time.
Last updated: September 2026