Skip to content

Legal

Privacy

1. Introduction and scope

With this privacy policy we provide you with comprehensive information about the nature, scope and purposes of the collection and use of your personal data by CORUS Russo & Partner Engineering + Consulting KmG.

This privacy policy applies to our website https://corus.ag and to all associated online services, offerings and communication channels.

We take the protection of your personal data very seriously and treat your personal data confidentially and in accordance with Swiss data protection law, in particular the revised Swiss Federal Act on Data Protection (revDSG).

As a rule, you can use our website without providing personal data. Where personal data is collected on our pages, this is always done on a voluntary basis. This data is not passed on to third parties without your express consent.

Special, supplementary or additional privacy policies as well as other legal documents such as general terms and conditions (GTC), terms of use or terms of participation may apply to individual or additional offerings.

2. Controller

The controller responsible for the processing of data within the meaning of data protection legislation is:

CORUS Russo & Partner Engineering + Consulting KmG
Hohlgasse 25
6233 Büron
Switzerland

If you have any questions about data protection, you can contact us at any time.

3. Definitions of terms

To make this privacy policy easy to understand, we use the following definitions of terms:

Personal data
All information relating to an identified or identifiable natural person. This includes, for example, name, address, email address, telephone number or IP address.
Processing
Any handling of personal data, irrespective of the means and procedures applied, in particular the obtaining, storing, keeping, using, altering, disclosing, archiving, deleting or destroying of data.
Data subject
The natural person whose personal data is processed.
Controller
The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Processor
A natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Consent
Any freely given, specific, informed and unambiguous indication of will in the form of a statement or any other clear affirmative action.
Cookies
Small text files that are stored on your device and may contain certain information. A distinction is made between session cookies (which are deleted after the browser session ends) and persistent cookies (which are stored for a defined period of time).

4. Legal bases

We process personal data in accordance with Swiss data protection law, in particular the revised Swiss Federal Act on Data Protection (revDSG) of 25 September 2020 and the Ordinance on Data Protection (DPO).

Under Swiss law, the processing of personal data is generally permitted provided that:

  • there is no legal prohibition
  • the data subject has consented
  • there is an overriding private or public interest
  • the processing is necessary for the performance of a contract

Stricter requirements apply to the processing of particularly sensitive personal data or to high-risk profiling.

5. Nature of the data collected

We collect and process various categories of personal data. Which data is collected specifically depends on the respective services and functions you use.

Overview of data categories

CategoryExamplesDescription
Master dataSurname, first name, form of address, titleBasic personal information for identification
Contact dataEmail address, telephone number, postal addressInformation for making contact and communicating
Technical dataIP address, browser type and version, operating system, device type, screen resolutionInformation automatically captured when using our website
Usage dataPages visited, time spent, click paths, access timesInformation about your usage behavior on our website
Content dataText entries in forms, message content, filesInformation actively transmitted by you

Data sources

The data is collected in various ways:

  • Directly from you: through entries in forms, emails, registration
  • Automatically: through technical logging when visiting the website
  • From third parties: e.g. through payment service providers or advertising partners (where applicable)

6. Purposes of data processing

We process your personal data for the following purposes:

PurposeDescriptionLegal basis
Provision and operation of our websiteTo make our website and its functions available to youLegitimate interest
Ensuring IT securityProtecting our systems against misuse, attacks and technical disruptionsLegitimate interest
Handling of contact inquiriesTo respond to your inquiries and to communicate with youPre-contractual measures / legitimate interest
Fulfillment of legal obligationsTo comply with statutory retention and documentation obligationsLegal obligation

7. General data processing

Contact forms

If you contact us via a contact form, the data you provide (name, email address, telephone number, message) is processed and stored in order to handle your inquiry.

  • Data processed: name, email address, optionally telephone number, message content
  • Legal basis: performance of a contract or pre-contractual measures (Art. 31 para. 2 let. a revDSG) or legitimate interest (Art. 31 para. 1 revDSG)
  • Retention period: The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected and no statutory retention obligations prevent this.

Server log files

Each time our website is accessed, technical data is automatically recorded in server log files. This is necessary for technical and security-related reasons.

  • Data processed: IP address, date and time of access, page/file accessed, volume of data transferred, browser type and version, operating system used, referrer URL, host name of the accessing computer
  • Legal basis: legitimate interest (Art. 31 para. 1 revDSG) - ensuring system security and error analysis
  • Retention period: The log files are automatically deleted after 30 days, unless longer retention is required for evidentiary purposes.

8. Data processing in detail (third-party services)

We use the services of third-party providers to operate, analyze and improve our website. Below we provide you with detailed information about the services used.

Vercel - hosting and infrastructure

Provider
Vercel Inc.
Location
USA
Purpose
Frontend hosting and serverless functions
Data categories
IP address, server logs, deployment data
Legal basis
Performance of a contract

9. International data transfer

Data transfer to third countries

As part of our data processing, personal data is also transferred to recipients outside Switzerland. This concerns in particular the following countries: USA.

For these countries there is no adequacy decision by the European Commission or the Federal Data Protection and Information Commissioner (FDPIC) confirming a level of data protection comparable to that of Switzerland.

Safeguards for the data transfer

In order to ensure an adequate level of data protection, we rely on the following safeguards:

  • Standard contractual clauses (SCC): We have concluded with the relevant recipients the standard contractual clauses approved by the European Commission, which contractually guarantee an adequate level of data protection.
  • Adequacy assessment: Before each data transfer, we assess whether the recipient country offers an adequate level of data protection or whether additional protective measures are required.
  • Additional protective measures: Where necessary, we implement technical and organizational measures such as encryption, pseudonymization or contractual arrangements to ensure the protection of your data.

Note on transfers to the USA

Some of our service providers are based in the USA. The USA currently does not have a level of data protection that corresponds to that in Switzerland. However, we have agreed standard contractual clauses with these providers and/or they have committed to complying with adequate data protection standards.

Please note that, under certain circumstances, US authorities could gain access to transferred data. By using the relevant services (after being informed and, where applicable, giving consent), you accept this residual risk.

Your rights

You have the right to request a copy of the agreed standard contractual clauses or information about the protective measures implemented.

10. Retention periods

We store your personal data only for as long as is necessary to fulfill the purposes for which it was collected or as provided for by statutory retention obligations.

General principles

The retention period is determined by:

  • the purpose of the data processing
  • statutory retention obligations
  • legitimate interests (e.g. defense against legal claims)
  • the nature of the data and the risk to the data subjects

Specific retention periods

Data categoryRetention periodBasis
Contact inquiries12 monthsFulfillment of purpose / legitimate interest
Server log files30 daysIT security
Accounting vouchers / invoices10 yearsArt. 958f OR (Swiss law)
Contracts and business correspondence10 years after the end of the contractArt. 958f OR / limitation periods

Statutory retention obligations (Switzerland)

Under Swiss law, the following retention obligations apply in particular:

  • Art. 958f OR: Accounting records and accounting vouchers as well as the annual report and the audit report must be kept for ten years.
  • Tax law provisions may stipulate additional retention obligations.

After the respective periods expire, the data is routinely deleted, unless it is still required for other purposes.

11. Data security

We take appropriate technical and organizational security measures (TOM) to protect your personal data against unauthorized access, loss, misuse or destruction. The specific measures used are based on the current state of the art and are reviewed and adapted regularly.

Depending on the risk and protection requirements, our security measures may include in particular:

  • Encrypted data transmission (e.g. TLS/SSL)
  • Access restrictions and authorization concepts
  • Protection of the IT infrastructure through suitable security systems
  • Regular data backups
  • Maintenance and updating of our systems
  • Confidentiality obligations for employees
  • Careful selection and contractual commitment of service providers
  • Processes for detecting and handling security incidents

Security in international data transfers

Where personal data is transferred to recipients in countries without an adequate level of data protection, we ensure through suitable safeguards that your data is adequately protected. These may include in particular standard contractual clauses, contractual arrangements or technical protective measures such as encryption.

Limitation

Despite all precautionary measures, no data transmission over the internet can be guaranteed to be completely secure.

In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will inform you without delay and notify the competent authorities.

12. Rights of data subjects

As a data subject you have various rights with regard to your personal data. These rights derive from the Swiss data protection act (revDSG).

Right of access
You have the right to obtain confirmation from us as to whether we process personal data concerning you. If this is the case, you have the right to access this data as well as further information such as the purposes of processing, the categories of data, recipients and the envisaged retention period.
Right to rectification
You have the right to request the rectification of inaccurate personal data or the completion of incomplete personal data.
Right to erasure (right to be forgotten)
You have the right to request the erasure of your personal data under certain conditions. This applies in particular where the data is no longer necessary for the purposes for which it was collected or where you withdraw your consent.
Right to restriction of processing
You have the right to request the restriction of the processing of your data under certain conditions, e.g. where you contest the accuracy of the data or where the processing is unlawful.
Right to data portability
You have the right to receive the personal data concerning you which you have provided to us in a structured, commonly used and machine-readable format and to transmit this data to another controller.
Right to withdraw consent
Where processing is based on consent, you have the right to withdraw it at any time with effect for the future.
Right to lodge a complaint
You have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).

Federal Data Protection and Information Commissioner (FDPIC)

Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
3003 Bern
Tel.: +41 58 462 43 95
www.edoeb.admin.ch

Exercising your rights

To exercise your rights, you can contact us at any time:

In order to process your request, we require proof of identity to ensure that the request originates from the authorized person. As a rule, we process your request within one month.

13. Updates and contact

Updating this privacy policy

We may adapt and update this privacy policy from time to time in order to take account of changes to our data processing practices, new legal requirements or other developments.

Changes will be published on our website. In the case of significant changes affecting your rights or the nature of the data processing, we will - where possible and appropriate - inform you separately.

We recommend that you review this privacy policy regularly in order to stay informed about the current state of our data protection practices.

Contact for questions

If you have any questions about this privacy policy or about the processing of your personal data, you can contact us at any time:

CORUS Russo & Partner Engineering + Consulting KmG

Last updated: June 2026