Last modified on December 09, 2019.
This Privacy Notice (the “Privacy Notice”) describes the principles based on which Hightide Kayak School GmbH (hereinafter “Hightide”, “us” or “we”) processes personal data collected through this Website (the “Website”). It informs you in particular about what personal data we collect, for which purposes it is processed, with whom it may be shared, for how long we retain it and which rights and options relating to the use of your personal data you may have. “Personal data” means any and all information relating to an identified or identifiable natural person, for example name, address, e-mail address, an online identifier or the phone number.
This Privacy Notice applies as far as the processing activities are not subject to other privacy policies or are provided for by applicable law. Please read this Privacy Notice carefully. By using the services of our Website or by registering on our Website you consent to the collection and processing of your personal information as set forth in this Privacy Notice.
The Controller of personal data collected through the Website is:
Hightide Kayak School
Lütschinenstrasse 24 | CH-3806 Bönigen | Switzerland
+41 (0)79 906 0551
Hightide determines the purposes and means of the processing of your personal data and is therefore responsible for the processing and use of your personal data as described in this Privacy Notice. If you have any questions or concerns regarding this Privacy Notice or how we process your personal data, kindly contact us at any time by sending an email to email@example.com.
Any personal data collected through the Website is processed in accordance with the provisions of applicable data protection and privacy laws. We collect and process personal data carefully and for the purposes described in this Privacy Notice. In accordance with applicable law, we may also use your personal data in other ways as described in this Privacy Notice. In such event, we will provide specific privacy policies or notices at the time of collection and obtain your consent where necessary. We always seek, to the extent reasonably possible, to collect information on an anonymized or pseudonymized basis so we cannot recognize your identity.
We may collect the following personal data via our Website:
Information automatically collected
Hightide collects and stores information that your browser automatically transmits to us in “server log files” when visiting our Website. These may include the following data:
- Browser type and browser version
- Operating system used
- Referrer URL
- Host name of the accessing computer
- Time of the server request
- IP address
These data will not be combined with data from other sources. It is stored by us until it is automatically deleted.
Information provided by you
We collect information which you actively and voluntarily provide us with through the Website via registration, by creating a login, by creating a booking, by sending a message to our contact email address firstname.lastname@example.org or by phone call. This may include the following personal data:
name, first name, address, email address, phone number, gender, language spoken, discount code, wetsuit/drysuit size, additional information about yourself.
If you do a booking for other persons that are joining you, you may provide the following personal data: name, first name, address, email address, phone number, gender, language spoken, discount code, wetsuit/drysuit, additional information about the other person.
If you provide us with personal data of other persons, please provide their personal data only if you are allowed to do so in line with applicable data protection laws and only if the other person would agree to you providing its personal data to us for the purposes the data are collected and the processing of its personal data according to our Privacy Notice.
Information generated in connection with a service-booking and during a trip
If you do a booking to use our services and during a booked trip, we may collect the following personal data:
name, first name, address, email address, phone number, payment information, photos or videos of you, subject to your consent or upon your request (for example for your posts on your social media networks). In some cases consent is provided by agreeing to the General Terms and Conditions.
The providing of such personal data will always be voluntary based on your consent or, based on a contract, for the performance of our services requested by you. Without providing such information you may, however, not be able to use the services or purposes for which the information is requested.
Purposes of processing Information automatically collected
The data automatically collected as described above is processed for the purposes of proper functioning of our Website, e.g. for establishing a connection, ensuring stability and uninterrupted system security, to improve our services, and for statistical purposes in the event of attacks on the network infrastructure on which the Website is made available.
Information provided by you
We will use the information provided by you for the lawful purposes which were evident from the circumstance or indicated at the time of collection which may include the following purposes:
- communicating with you (e.g. about our services) and provide you with the best possible and personalized information you may require from us
- for answering any questions or requests you may have about our services in the best possible manner, asking you questions and giving additional information tailored to your interests in connection with our services prior to entering into a possible contract relation
- For complying with legal or other regulatory requirements and internal rules; and
- For establishing, exercise and/or defend actual or potential legal claims, investigations or similar proceedings.
Information generated in connection with a service-booking and during a trip
We will use the information provided by you for the provision of our services as requested by you and to enhance your customer experience and our business performance.
Legal basis for processing
The legal basis for processing your personal data for the purposes described above may be based on the following legal grounds:
- your consent, only if it may be withdrawn at any time;
- for the performance of a contract with you or for the intention to enter into a contract with you;
- to comply with a legal obligation (e.g. for tax reasons or for purposes of legal investigations or proceedings); or
- for the purposes of our legitimate interests, for example for maintaining and improving our internal business administration, organization, operations, risk management, protection of systems and premises, prevention of fraud and other offences, for advertising and marketing activities, to guarantee an effective, efficient, secure and harmonized service, to comply with legal or other regulatory requirements and internal rules, and for establishing, exercise and/or defend actual or potential legal claims, investigations or similar proceedings.
Should the processing be based on your consent or our legitimate interests, you may withdraw consent or object to that processing at any time by contacting us directly at email@example.com. Please note, however, that the withdrawal of your consent will not affect the lawfulness of processing based on consent before its withdrawal.
We take necessary measures to ensure only our authorized personnel on a need to know basis will have access to your personal data to fulfill the purposes for which your personal data was collected.
We may share your personal data with the following categories of recipients in accordance with the purposes of processing as described herein:
- Our trusted third-party service providers, including processors (e.g. providers of IT services);
- Website designers and developers;
- the public, including social media sites of Hightide;
- professional advisors and auditors;
- governmental administrations, courts and other competent authorities;
- other parties in potential or actual legal proceedings.
We choose our partners and data processors carefully and only upon sufficient guarantees they have appropriate technical and organizational measures in place. Our third-party partners are subject to confidentiality requirements and may use your personal data solely to the extent necessary to fulfill the purpose for which your personal data was collected, except as otherwise required by law.
The personal data collected through our Website is stored in Switzerland. Moreover, we may transfer, store and process your personal data in data locations around the world, for example where our third-party providers or business partners are located. Therefore, we may transfer your personal data outside the European Economic Area (EEA) if it is required for the data processing described in this Privacy Notice in accordance with applicable law.
If data is disclosed to countries that do not guarantee an adequate level of protection, Hightide will ensure adequate protection of data disclosed by putting appropriate safeguards in place, such as contractual guarantees (e.g., on the basis of EU standard clauses), binding corporate rules, on the basis of the EU-U.S. and the Swiss-U.S. Privacy Shield Framework for transfers to third parties based in the U.S., or transferring data pursuant to your explicit consent, conclusion or performance of a contract, or in connection with the determination, exercise or enforcement of legal claims. You may obtain more information about our appropriate safeguards by contacting us via email to firstname.lastname@example.org.
We retain your personal data for as long as necessary to fulfill the purposes for which your personal data was collected. For this reason, we will delete or anonymize personal data (or equivalent) once they are no longer necessary to achieve the purposes, subject however (i) to any applicable legal or regulatory requirements to store personal data for a longer period (e.g. for tax or accounting reasons), or (ii) if we have an overriding interest (e.g. an interest for reasons of proof to establish, exercise and/or defend actual or potential legal claims, investigations or similar proceedings, including legal holds, which we may enforce to preserve relevant information, or if we have an interest in non-personalized analysis).
On that basis, we normally process personal data subject to the following rules and obligations:
For contract related personal data (including business records and communication), we retain personal data as long as the contractual relation is ongoing and for ten years after the termination of the contractual relationship unless (i) a shorter or longer statutory storage obligation is applicable on a case-by-case basis, (ii) the retention is required for reasons of proof or another valid reason based on applicable law, or (iii) the deletion of the data is required earlier (because e.g. the data is no longer required or we are required to delete the respective data);
For operational data containing data (e.g. protocols, logs), we retain personal data for a period of 3 – 12 months.
When you access or use the Website, we may place so called cookies – small text files – or similar tools on your computer. We use these cookies to recognize you as a user of the Website, to customize content, to improve the Website’s performance and to enhance your user experience.
Categories of Cookies we use
Depending on their function and intended purpose, cookies we may use can be divided into the following categories: functional cookies, performance cookies, and advertising cookies.
Functional cookies: These cookies serve a variety of purposes to the presentation, functionality and performance of a website and in particular to enhance visitors’ experience and enjoyment of the website. They enable a website to save details that have already been provided (e.g. user name, your location or language choices) and offer the visitors improved, more personal functions. Functional cookies are used, for example, to remember things like your log-in information. These cookies cannot track your movement on other websites.
Performance cookies: These cookies are used to collect information about how a website is used – for example how visitors came to our website, which pages a visitor opens most frequently, how they navigated around our website during their visit and whether they receive error messages from a page. We also may use these cookies to provide us with certain statistical and analytics information, such as how many visitors came to our website. These cookies are used to monitor the level of activities of the Website and to improve the performance of the Website.
Advertising cookies: Enable the website owner or a third party service provider to place ads on the website of the website owner or on websites of third parties with products that the user may like, so that the advertisement the user sees can be more relevant to the user’s preferences or interests (sometimes referred to as “targeting cookies”). They may also be used to evaluate effectiveness of advertising and promotion.
These cookies may be placed by us or a third party on our behalf. To learn more about cookies and how they are used, please visit: https://www.allaboutcookies.org/.
On your computer, we store the cookies of Google Analytics. Google Analytics is a web analytics service that is operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
The cookies of Google Analytics allow an analysis of the use of the website by you and other website users that Google provides to us. The information generated by the cookie about your use of our Website is usually transmitted to a Google server in the USA and stored there. This information may include the number of times a user visits the website, dates of the first and last visit, duration of the visits, the page from where the user accessed the website, the search engine the user used to access the website or the link they clicked on, the place in the world from where the user accesses, etc. Google will use this information on our behalf to evaluate your use of the website, to compile reports on your website activity, and to provide other services regarding website activity and internet usage for us.
We have activated the IP anonymization feature on our Website. Your IP address will be shortened by Google within the European Union or other parties to the Agreement on the European Economic Area prior to transmission to the United States. Only in exceptional cases is the full IP address sent to a Google server in the US and shortened there.
In addition, Google may monitor the use of the Website by the user and combine this data with data from other websites monitored by Google which the user has visited and Google may use these findings for its own benefits (e.g. to control advertisement), under their responsibility and based on their own privacy policies that can be found here (https://policies.google.com/).You can learn more about Google Analytics and how they process Personal Data here (https://policies.google.com/technologies/partner-sites).
Management of Cookies
If you do not want to accept these cookies you can change your browser settings to delete or prevent certain cookies from being stored on your computer or device without your consent. Each browser is different in the type, how it manages the cookie-settings. This is normally described in the «Help» menu of each browser. You will find this information for the most popular browsers under the following links:
Mozilla Firefox: http://support.mozilla.com/en-US/kb/Cookies
Please note, however, that by disabling the cookies function in your browser settings, you may no longer be able to use all the functions of the Website.
Social Media Plugins
We also use social media buttons and plugins on this site that allow you to connect with your social network in various ways. For these to work the following social media sites including; Facebook (with Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA, as the operator of the service); Twitter (with Twitter Inc., 1355 Market St, Suite 900, San Francisco, CA 94103, USA, as the operator of the service); Youtube (with YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA, as the operator of the service); Instagram (a service offered from Facebook); and Meetup (a service offered by Meetup Inc, 632 Broadway FI 10, New York City, NY 10012, as the operator of the service), will set cookies through our site which may be used to enhance your profile on their site or contribute to the data they hold for various purposes outlined in their respective privacy policies.
The subsequent processing of the personal data will be conducted in the responsibility of the social media provider according to data protection and privacy laws and according to its data protection policies published on its website (such as www.facebook.com, www.twitter.com., www.instagram or https://medium.com). Please carefully read the privacy policies of your social networks for detailed information about their collection and transfer of personal data, your rights, and how you can achieve satisfactory privacy settings.
The legal basis for the processing of personal data by using cookies or social network plug-ins are our legitimate interests in operating, protecting, analyzing, optimizing, and improving our Website.
We will use your email address for sending you information about our services and other commercial communications that may be of interest for you as long as you will be subscribed to the email mailing list. You can unsubscribe from such emails at any time, by clicking the highlighted link “unsubscribe from this list” at the end of each email or by contacting us directly via email at email@example.com.
We have implemented various technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised use, disclosure or access, in particular where processing involves the transmission of data over a network, and against all other unlawful forms of processing and misuse.
Hightide may use third party data processors to collect and process your personal data. Any data processors commissioned by us will only process your personal data in accordance with our instructions and are legally obliged to adhere to strict security procedures when handling personal data.
Unfortunately, transmission of information via the internet is not wholly secure. Although we do our utmost to protect your personal data, we cannot guarantee the security of your data transmitted to our Website; any transmission is done so at your own risk. For this reason, you are always free to transfer your personal data to us via alternative means, e.g. by telephone. Once we have received your information, we employ strict procedures and rigid security measures to try to prevent unauthorised access.
Our Website is not intended for children and we do not knowingly collect personal data from children under the age of 16, except with the explicit parental consent. If we are notified or otherwise learn that personal data of a child under the age of 16 has been improperly collected, we will take all reasonable steps to delete that personal data.
You may request information from Hightide as to whether data concerning you is being processed. In addition, you have the right to request the correction, destruction or restriction of personal data regarding yourself as well as to object to the processing of personal data. Should the processing of personal data be based on our consent, you may withdraw consent at any time. However, please note that a withdrawal does not affect the legitimacy of the processing activities that took place before you withdrew your consent. In countries of the EEA you may, in certain cases, have the right to obtain data generated during the use of online services in a structured, common and machine-readable format which allows for further use and transfer.
Requests in this respect shall be submitted to Hightide via the following email address: firstname.lastname@example.org. Hightide reserves the right to restrict the rights of the affected user in accordance with applicable law and e.g. not to disclose comprehensive information or not to delete data.
If we refuse your request or if you are not satisfied with our processing, you are also entitled to lodge a complaint with the competent supervisory authority and seek a judicial remedy. For users located in Switzerland, the competent authority is the Federal Data Protection and Information Commissioner in Switzerland (http://www.edoeb.admin.ch). For the users located in the EU Countries, a list of the supervisory authorities can be found here.
This Privacy Notice may be changed from time to time and without prior notice or announcement. All changes to this Privacy Notice are effective when they are posted on the Website unless indicated otherwise. When we change the policy in a material manner, we will let you know via email and/or a prominent notice on our Website or in another appropriate manner prior to the change becoming effective and update the ‘effective date’ at the top of this page.