Privacy Policy — Chili-Chocolate
Effective as of:

At Chili-Chocolate (hereinafter “Chili-Chocolate”, “we”, “us”), we place great importance on the protection of data and the safeguarding of the privacy of our users, visitors and customers (hereinafter: “users”). We treat personal data confidentially and in accordance with the legal data protection regulations as well as this privacy policy.

This privacy policy provides you as a user with a transparent overview of the extent to which and how we – as well as third parties mentioned in this statement – collect, process, store and protect your personal data. This is done in consideration of the principles of the Swiss Federal Act on Data Protection (hereinafter “FADP”).

In the context of our business relationship, you must provide personal data that is necessary for the execution and fulfillment of your order as well as for contractual obligations. Without this data, we cannot conclude or process a contract with you. The use of our website is also only possible if technical information such as your IP address is transmitted to ensure data traffic.

  1. Responsibility

    Responsible within the meaning of the FADP for the provision of the website is:

    Chili-Chocolate by Socheat Baeumler
    Socheat Baeumler
    Gattikonerstrasse 130
    CH – 8136 Gattikon

    hello@chili-chocolate.ch
    +41 79 213 64 77

    For orders or applications, the company named in the process is responsible for data protection.

  2. Purposes of Data Processing
    1. Orders and Provision of Services

      Personal data is any information relating to an identified or identifiable natural person (e.g., name, address, phone number, email address).

      We process data only to the extent necessary for the operation of a functional website, for the provision of our services (in particular online orders, marketing activities), and for the fulfillment of contracts.

      Data transmitted during an order or registration is used exclusively for the purposes stated in this privacy policy. If our pages are visited for information purposes only, we generally do not process personal data – except for cookies, tracking pixels, and the tools described in the following chapters.

    2. Contact Form and Email

      Data transmitted via the contact form or email is stored for the purpose of processing the inquiry and any follow-up questions and is not passed on to third parties. In addition, we may create anonymized statistics to optimize our services.

    3. Newsletter

      You can sign up for our newsletter on our website. In doing so, we obtain your consent. This can be revoked informally at any time (information on this is included in every newsletter). The data provided is used exclusively for sending the newsletter.

    4. Applications

      In the case of applications, we process the transmitted data to review and carry out the application process. If no employment results, the data is stored only as long as necessary or until you object to its retention.

    5. Log Files

      When our website is accessed, our system automatically collects general information (e.g., IP address, date/time, browser type, operating system). This data is stored in server log files and used exclusively for statistical evaluation and to improve our services. It is not merged with other data sources.

  3. Disclosure of Data to Third Parties

    We share data with third parties insofar as this is necessary for contract fulfillment, payment processing, or technical provision. This includes in particular IT service providers, payment providers, or delivery partners.

    All third parties process the data exclusively on our behalf and are contractually obliged to comply with data protection. Data processing for their own purposes does not take place.

    For online orders, we forward your data to the respective delivery driver so that the delivery can be carried out.

  4. Data Transfer Abroad

    A transfer of data abroad (in particular to the EU or the USA) may occur in the context of contract fulfillment or for the use of services.

    If the recipient is located in a country without adequate legal data protection, we contractually oblige them to comply with an appropriate level of protection. A transfer may exceptionally also take place if this is required for contract fulfillment, overriding public interests exist, you have consented, or you have made the data generally accessible.

    We point out that, in particular in the USA, authorities may access transmitted data without us or you being informed.

  5. Technical and Organizational Measures

    We protect personal data through appropriate technical and organizational measures against loss, unauthorized access, or manipulation. Nevertheless, electronic data transmission generally carries certain risks.

  6. Cookies and Tracking Pixels

    We use cookies and tracking pixels to analyze the use of our website, store settings, and improve our services.

    • Session cookies: are automatically deleted after the end of the visit.
    • Persistent cookies: remain on the device until they are manually deleted or expire after a maximum of one year.

    Users can disable or delete cookies in their browser. This may limit the functionality of the website.

  7. Third-Party Tools
    1. Google Analytics

      We use Google Analytics (Google Ireland Limited / Google LLC). The collected data (e.g., IP address, browser data, user behavior) is usually transferred to servers in the USA. We have enabled IP anonymization.

      Legal basis: Legitimate interest in optimizing and improving the user-friendliness of our services.
      More info: https://policies.google.com/privacy?hl=en.

    2. CAPTCHA (Cloudflare Turnstile)

      We use Cloudflare Turnstile to prevent automated access. Technical information (e.g., IP address, browser data, interactions) is transmitted to Cloudflare and used exclusively to distinguish between humans and bots.

      Legal basis: Legitimate interest in the security of our website.
      More info: https://www.cloudflare.com/en-gb/privacypolicy/.

    3. Social Networks

      Our website may contain plugins or links to social networks (e.g., Facebook, LinkedIn, TikTok, YouTube). Data is only transmitted when you actively click a plugin or play embedded content.

    4. Google Maps

      Google Maps enables the display of maps and our location. In doing so, user data (e.g., IP address, location data) may be transmitted to Google.

    5. Google Fonts

      Google Fonts are used on our websites to ensure a consistent display of fonts. When accessed, data (e.g., IP address, browser data) is transmitted to Google servers.

    6. Legal basis in each case: Legitimate interest in a user-friendly design of the website.

  8. User Rights

    You have the right to request information about the data stored about you at any time. You can also request the correction, deletion, or restriction of the processing of your data, insofar as legally permissible.

    Consent given (e.g., newsletter) can be revoked at any time with effect for the future.

    Please address corresponding requests with clear identification of your person to the contact details mentioned in section 1.

  9. Storage Period

    We store personal data only as long as necessary for the purposes mentioned or as long as we have a legitimate interest (e.g., for evidentiary purposes). After that, they are deleted or anonymized.

    A longer storage period may occur if legal obligations (e.g., commercial and tax law) require this.

  10. Amendments

    We reserve the right to amend this privacy policy at any time. The version published on our website is authoritative.