Privacy Policy Statement
Oniva Ltd.
8600 Dübendorf
Switzerland
Privacy Policy Statement of Oniva Ltd.
1. What this is about
We take the protection of personal data seriously. This Privacy Policy describes which personal data Oniva AG («Oniva», «we») processes as the controller, for what purposes and on what legal basis, and what rights you have in this regard.
It applies to:
- visiting and using our websites at www.oniva.events and the associated subdomains;
- initiating and managing business relationships, including quotations, contracts and invoicing;
- enquiries submitted to our Support and Help Centre;
- our newsletter, events and marketing activities;
- applications for advertised positions or unsolicited applications.
It does not apply to personal data that our customers process on the Oniva platform. See section 2 for more information.
We comply with the Swiss Federal Act on Data Protection (FADP) and, where applicable, Regulation (EU) 2016/679 (GDPR).
2. Our two roles
Data protection law distinguishes between companies that process personal data for their own purposes (controllers) and those that process personal data on behalf of another company (processors). Depending on the circumstances, Oniva acts in both roles. Where the GDPR applies, the term «processor» is used.
As a controller, we process the data listed in section 1. This Privacy Policy applies to such processing.
As a processor, we process all personal data that our customers collect, manage and process via the Oniva platform, in particular data relating to participants in their events. The respective customer is solely responsible for this data. The customer determines the purposes and means of the processing, and we act only on its instructions. The details are governed by our Data Processing Agreement, available at www.oniva.events/adv. You will also find there the current list of our sub-processors, the technical and organisational measures, and the provisions governing deletion and return of data.
Are you a participant in an event? If so, your data was entered into Oniva by the organiser or by you, not by us. For access, rectification or deletion requests, please contact the organiser directly. We will support the organiser in fulfilling your request, but may not process your data independently without its instructions. The organiser is generally identified in the invitation, on the event website or in the confirmation.
For personal data relating to employees and other personnel of our contractual partners that arise in the course of managing the contractual relationship, we and our contractual partners act as joint controllers. The details are set out in section 12.1 of our General Terms and Conditions.
3. Contact
The controller within the meaning of data protection law for the processing described in section 1 is:
Oniva Ltd.
Zürichstrasse 98
8600 Dübendorf
Switzerland
Registered office: Dübendorf
Registering authority: Zurich
Registration number: CHE-262.252.215
Represented by the Managing Directors:
Marc Blindenbacher
Anna Fredholm
Simon Gadient
Marc Bischof
Contact point for data protection enquiries: security@oniva.events
4. What data we process
When using our websites
When you access our websites, technical data is processed, in particular the IP address of your device, the date and time of access, the pages accessed, the page visited previously, the browser and operating system used, and approximate location information based on the IP address. This data is technically necessary and is used to ensure secure operation and, in aggregated form, for analysis. Our websites are provided via Webflow Inc. Forms on our websites, for example for contacting us and requesting a demo, are embedded from our CRM system. The information you enter is transmitted directly to this system and is not stored by Webflow. When the page is accessed and the form is loaded, however, connection data such as your IP address is transmitted to Webflow or to the provider of the CRM system.
When contacting us, requesting a demo or receiving a quotation
Name, company, position, email address, telephone number, language, as well as the content of your enquiry and our correspondence.
For existing customer relationships
Contact details of contact persons, contract and order data, invoicing and payment data, information on services and licences purchased, correspondence, support history, and information relating to training and satisfaction surveys.
For support enquiries
Name and contact details, a description of the request, and technical information relating to the incident. Where necessary for processing the request, our employees may access the customer's instance in accordance with the provisions of the Data Processing Agreement.
For newsletters, events and marketing
Email address, name, company, areas of interest, language, and information on the opening and use of our mailings.
For applications
The documents and information you submit, as well as our notes from the application process.
We generally collect this data directly from you. In addition, we process information from publicly accessible sources such as company websites, commercial registers or professional networks, as well as information provided to us by customers or partners as part of a recommendation.
5. Purposes and legal bases
Under Swiss law, we process personal data in accordance with the applicable data processing principles, in particular in the context of performing contracts, on the basis of overriding private interests or on the basis of consent.
Where we rely on consent, you may withdraw your consent at any time with effect for the future. This does not affect the lawfulness of processing carried out up to the point of withdrawal.
6. Cookies and tracking
Our websites use cookies and similar technologies. Essential cookies are necessary for the operation of the website and are set without consent. We only use cookies for personalisation, analytics and marketing if you have given your consent in the consent banner.
You can change your settings at any time via the privacy settings centre on our websites. Details of the cookies we use, how long they are stored and which providers are involved can be found in our Cookie Policy at www.oniva.events/cookies.
We use Google Analytics to analyse website usage. Your IP address is shortened so that individual devices cannot be identified.
7. Recipients
Within Oniva, only those employees who require access to your data for the performance of their duties have access to it.
In addition, we disclose personal data to the following categories of recipients where this is necessary for the purposes stated:
- Providers of hosting and cloud infrastructure; Microsoft (Schweiz) GmbH
- Providers of communication, email and collaboration services; HubSpot Inc., Webflow Inc., Microsoft (Schweiz) GmbH
- Providers of CRM, marketing and support systems; HubSpot Inc.
- Providers of security and analytics services; Cloudflare Inc.
- Fiduciary, audit, legal and consulting service providers; Bexio, Onaccounting
- Authorities and courts, where we are legally obliged to do so.
These service providers are contractually obliged to process personal data only for the purpose of providing their services and in accordance with our instructions.
For the sub-processors we use in operating the Oniva platform, we maintain a continuously updated list in the Data Processing Agreement at www.oniva.events/en/dpa. This list is the authoritative source; we do not maintain a second list elsewhere.
In the event of a sale or restructuring of our company, personal data may be disclosed to the parties involved, subject to confidentiality.
8. Disclosure abroad
Data relating to the Oniva platform is hosted exclusively in Switzerland.
Our CRM and marketing system is operated by HubSpot, Inc. and hosted in a data centre in Frankfurt, Germany. Data from enquiries, demo requests and our newsletter therefore remains within the European Economic Area, for which an adequate level of data protection is recognised.
Our marketing websites are operated via Webflow Inc., whose infrastructure is located in the United States. When you visit our websites, connection data such as your IP address is therefore processed in the United States. Form content is not stored by Webflow but is transmitted directly to our CRM system. Webflow is certified under the Swiss-U.S. and EU-U.S. Data Privacy Frameworks; in addition, the standard contractual clauses set out in Webflow's Data Processing Addendum apply.
If data is transferred to a country without an adequate level of data protection, we ensure an appropriate level of protection, in particular by entering into the European Commission's standard contractual clauses pursuant to Commission Implementing Decision (EU) 2021/914 in the version recognised by the Federal Data Protection and Information Commissioner, where necessary supplemented by additional technical and organisational measures.
Upon request to security@oniva.events, we will provide you with information on the specific safeguards.
9. Retention and deletion
We retain personal data for as long as necessary for the stated purposes and subsequently delete or anonymise it. In particular, the following applies:
- Contract and business data: for the duration of the business relationship and thereafter for the statutory retention period of ten years pursuant to Art. 958f of the Swiss Code of Obligations;
- Enquiries without conclusion of a contract: generally 36 months from the last contact;
- Newsletter data: until consent is withdrawn or you unsubscribe;
- Support records: generally 36 months after completion of the matter;
- Application documents: six months after completion of the recruitment process; where consent has been given for inclusion in our talent pool, up to 24 months;
- Data on the Oniva platform: in accordance with the Data Processing Agreement and section 15.4 of our Terms of Use.
Data may be retained for longer where this is necessary for the assertion or defence of legal claims.
10. Data security
We implement appropriate technical and organisational measures in accordance with the state of the art to protect personal data against unauthorised access, loss, misuse and alteration. These measures include, among other things, encrypted transmission, access and authorisation controls, logging, regular backups and recurring security assessments by external specialists.
Further information on our security measures can be found at www.oniva.events/en/security-compliance.
If we become aware of a security incident that is likely to result in a high risk to the data subjects concerned, we will inform the competent supervisory authority and, where required, the data subjects concerned. In relation to our customers, the deadlines set out in section 8.5 of our Terms of Use also apply.
11. Artificial intelligence
We use services based on artificial intelligence for certain functions of the platform and in internal workflows.
We do not use our customers' content or personal data to train or further develop artificial intelligence models. Where we use third-party services, we contractually ensure that the data transmitted is not used for training purposes. The services used are listed in the sub-processor list in the Data Processing Agreement. The corresponding assurance is set out in section 14.5 of our Terms of Use.
We do not make automated individual decisions with legal effect or similarly significant effects within the meaning of Art. 22 GDPR or Art. 21 FADP.
12. Your rights
Under applicable law, you have the following rights:
- to obtain information as to whether and which personal data we process about you;
- to have inaccurate data rectified;
- to have your data deleted, unless a legal retention obligation or an overriding interest prevents this;
- to request restriction of processing;
- to object to processing based on a legitimate interest, as well as to direct marketing at any time;
- to data portability for data that you have provided to us and that we process automatically on the basis of consent or a contract;
- to withdraw consent with effect for the future.
Please contact us at security@oniva.events. To safeguard your rights, we must verify your identity; we will only request the information necessary in the individual case.
We will respond to requests within 30 days. If a request is complex, we will inform you within this period that the deadline is being extended.
You also have the right to lodge a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC); in the EU, it is the data protection authority at your place of residence or work.
If your request concerns data processed by a customer on the Oniva platform, we will forward it to the relevant customer or refer you to them where we are able to identify the relevant customer.
13. Changes to this Privacy Policy
We may amend this Privacy Policy at any time, in particular in response to changes to our services or to the applicable law. The version published on our website with the date stated above is authoritative. We will inform data subjects of material changes in an appropriate manner.
14. Further legal documents
- General Terms and Conditions, available at www.oniva.events/en/terms-conditions
- Terms of Use, available at www.oniva.events/en/terms-of-use
- Data Processing Agreement, available at www.oniva.events/en/dpa
- Cookie Policy, available at www.oniva.events/en/cookies
- Security and Compliance, available at www.oniva.events/en/security-compliance
Last updated: August 2026