Legal

Privacy Policy Statement

Oniva Ltd.

Zürichstrasse 98
8600 Dübendorf
Switzerland
Table of contents

Privacy Policy Statement of Oniva Ltd.

1. What this is about

We take the protection of personal data seriously. This Privacy Policy describes which personal data Oniva AG («Oniva», «we») processes as the controller, for what purposes and on what legal basis, and what rights you have in this regard.

It applies to:

It does not apply to personal data that our customers process on the Oniva platform. See section 2 for more information.

We comply with the Swiss Federal Act on Data Protection (FADP) and, where applicable, Regulation (EU) 2016/679 (GDPR).

2. Our two roles

Data protection law distinguishes between companies that process personal data for their own purposes (controllers) and those that process personal data on behalf of another company (processors). Depending on the circumstances, Oniva acts in both roles. Where the GDPR applies, the term «processor» is used.

As a controller, we process the data listed in section 1. This Privacy Policy applies to such processing.

As a processor, we process all personal data that our customers collect, manage and process via the Oniva platform, in particular data relating to participants in their events. The respective customer is solely responsible for this data. The customer determines the purposes and means of the processing, and we act only on its instructions. The details are governed by our Data Processing Agreement, available at www.oniva.events/adv. You will also find there the current list of our sub-processors, the technical and organisational measures, and the provisions governing deletion and return of data.

Are you a participant in an event? If so, your data was entered into Oniva by the organiser or by you, not by us. For access, rectification or deletion requests, please contact the organiser directly. We will support the organiser in fulfilling your request, but may not process your data independently without its instructions. The organiser is generally identified in the invitation, on the event website or in the confirmation.

For personal data relating to employees and other personnel of our contractual partners that arise in the course of managing the contractual relationship, we and our contractual partners act as joint controllers. The details are set out in section 12.1 of our General Terms and Conditions.

3. Contact

The controller within the meaning of data protection law for the processing described in section 1 is:

Oniva Ltd.
Zürichstrasse 98
8600 Dübendorf
Switzerland

Registered office: Dübendorf
Registering authority: Zurich
Registration number: CHE-262.252.215

Represented by the Managing Directors:
Marc Blindenbacher
Anna Fredholm
Simon Gadient
Marc Bischof

Contact point for data protection enquiries: security@oniva.events

4. What data we process

When using our websites
When you access our websites, technical data is processed, in particular the IP address of your device, the date and time of access, the pages accessed, the page visited previously, the browser and operating system used, and approximate location information based on the IP address. This data is technically necessary and is used to ensure secure operation and, in aggregated form, for analysis. Our websites are provided via Webflow Inc. Forms on our websites, for example for contacting us and requesting a demo, are embedded from our CRM system. The information you enter is transmitted directly to this system and is not stored by Webflow. When the page is accessed and the form is loaded, however, connection data such as your IP address is transmitted to Webflow or to the provider of the CRM system.

When contacting us, requesting a demo or receiving a quotation
Name, company, position, email address, telephone number, language, as well as the content of your enquiry and our correspondence.

For existing customer relationships
Contact details of contact persons, contract and order data, invoicing and payment data, information on services and licences purchased, correspondence, support history, and information relating to training and satisfaction surveys.

For support enquiries
Name and contact details, a description of the request, and technical information relating to the incident. Where necessary for processing the request, our employees may access the customer's instance in accordance with the provisions of the Data Processing Agreement.

For newsletters, events and marketing
Email address, name, company, areas of interest, language, and information on the opening and use of our mailings.

For applications
The documents and information you submit, as well as our notes from the application process.

We generally collect this data directly from you. In addition, we process information from publicly accessible sources such as company websites, commercial registers or professional networks, as well as information provided to us by customers or partners as part of a recommendation.

5. Purposes and legal bases

Purpose Legal basis under the GDPR
Provision, security and stability of our websites Legitimate interest, Art. 6(1)(f)
Responding to enquiries and preparing quotations Pre-contractual measures, Art. 6(1)(b)
Conclusion and performance of contracts, invoicing Performance of a contract, Art. 6(1)(b)
Support, training and further development of our services Performance of a contract and legitimate interest, Art. 6(1)(b) and (f)
Newsletter and marketing to prospective customers Consent, Art. 6(1)(a)
Informing existing customers about our own similar services Legitimate interest, Art. 6(1)(f)
Analysis of website usage using non-essential cookies Consent, Art. 6(1)(a)
Recruitment process Pre-contractual measures, Art. 6(1)(b)
Compliance with legal obligations, such as accounting and retention requirements Legal obligation, Art. 6(1)(c)
Assertion and defence of legal claims Legitimate interest, Art. 6(1)(f)
Provision, security and stability of our websites
Legal basis Legitimate interest, Art. 6(1)(f)
Responding to enquiries and preparing quotations
Legal basis Pre-contractual measures, Art. 6(1)(b)
Conclusion and performance of contracts, invoicing
Legal basis Performance of a contract, Art. 6(1)(b)
Support, training and further development of our services
Legal basis Performance of a contract and legitimate interest, Art. 6(1)(b) and (f)
Newsletter and marketing to prospective customers
Legal basis Consent, Art. 6(1)(a)
Informing existing customers about our own similar services
Legal basis Legitimate interest, Art. 6( 1)(f)
Analysis of website usage using non-essential cookies
Legal basis Consent, Art. 6( 1)(a)
Recruitment process
Legal basis Pre-contractual measures, Art. 6(1)(b)
Compliance with legal obligations, such as accounting and retention requirements
Legal basis Legal obligation, Art. 6(1)(c)
Assertion and defence of legal claims
Legal basis Legitimate interest, Art. 6(1)(f)

Under Swiss law, we process personal data in accordance with the applicable data processing principles, in particular in the context of performing contracts, on the basis of overriding private interests or on the basis of consent.

Where we rely on consent, you may withdraw your consent at any time with effect for the future. This does not affect the lawfulness of processing carried out up to the point of withdrawal.

6. Cookies and tracking

Our websites use cookies and similar technologies. Essential cookies are necessary for the operation of the website and are set without consent. We only use cookies for personalisation, analytics and marketing if you have given your consent in the consent banner.

You can change your settings at any time via the privacy settings centre on our websites. Details of the cookies we use, how long they are stored and which providers are involved can be found in our Cookie Policy at www.oniva.events/cookies.

We use Google Analytics to analyse website usage. Your IP address is shortened so that individual devices cannot be identified.

7. Recipients

Within Oniva, only those employees who require access to your data for the performance of their duties have access to it.

In addition, we disclose personal data to the following categories of recipients where this is necessary for the purposes stated:

These service providers are contractually obliged to process personal data only for the purpose of providing their services and in accordance with our instructions.

For the sub-processors we use in operating the Oniva platform, we maintain a continuously updated list in the Data Processing Agreement at www.oniva.events/en/dpa. This list is the authoritative source; we do not maintain a second list elsewhere.

In the event of a sale or restructuring of our company, personal data may be disclosed to the parties involved, subject to confidentiality.

8. Disclosure abroad

Data relating to the Oniva platform is hosted exclusively in Switzerland.

Our CRM and marketing system is operated by HubSpot, Inc. and hosted in a data centre in Frankfurt, Germany. Data from enquiries, demo requests and our newsletter therefore remains within the European Economic Area, for which an adequate level of data protection is recognised.

Our marketing websites are operated via Webflow Inc., whose infrastructure is located in the United States. When you visit our websites, connection data such as your IP address is therefore processed in the United States. Form content is not stored by Webflow but is transmitted directly to our CRM system. Webflow is certified under the Swiss-U.S. and EU-U.S. Data Privacy Frameworks; in addition, the standard contractual clauses set out in Webflow's Data Processing Addendum apply.

If data is transferred to a country without an adequate level of data protection, we ensure an appropriate level of protection, in particular by entering into the European Commission's standard contractual clauses pursuant to Commission Implementing Decision (EU) 2021/914 in the version recognised by the Federal Data Protection and Information Commissioner, where necessary supplemented by additional technical and organisational measures.

Upon request to security@oniva.events, we will provide you with information on the specific safeguards.

9. Retention and deletion

We retain personal data for as long as necessary for the stated purposes and subsequently delete or anonymise it. In particular, the following applies:

Data may be retained for longer where this is necessary for the assertion or defence of legal claims.

10. Data security

We implement appropriate technical and organisational measures in accordance with the state of the art to protect personal data against unauthorised access, loss, misuse and alteration. These measures include, among other things, encrypted transmission, access and authorisation controls, logging, regular backups and recurring security assessments by external specialists.

Further information on our security measures can be found at www.oniva.events/en/security-compliance.

If we become aware of a security incident that is likely to result in a high risk to the data subjects concerned, we will inform the competent supervisory authority and, where required, the data subjects concerned. In relation to our customers, the deadlines set out in section 8.5 of our Terms of Use also apply.

11. Artificial intelligence

We use services based on artificial intelligence for certain functions of the platform and in internal workflows.

We do not use our customers' content or personal data to train or further develop artificial intelligence models. Where we use third-party services, we contractually ensure that the data transmitted is not used for training purposes. The services used are listed in the sub-processor list in the Data Processing Agreement. The corresponding assurance is set out in section 14.5 of our Terms of Use.

We do not make automated individual decisions with legal effect or similarly significant effects within the meaning of Art. 22 GDPR or Art. 21 FADP.

12. Your rights

Under applicable law, you have the following rights:

Please contact us at security@oniva.events. To safeguard your rights, we must verify your identity; we will only request the information necessary in the individual case.

We will respond to requests within 30 days. If a request is complex, we will inform you within this period that the deadline is being extended.

You also have the right to lodge a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC); in the EU, it is the data protection authority at your place of residence or work.

If your request concerns data processed by a customer on the Oniva platform, we will forward it to the relevant customer or refer you to them where we are able to identify the relevant customer.

13. Changes to this Privacy Policy

We may amend this Privacy Policy at any time, in particular in response to changes to our services or to the applicable law. The version published on our website with the date stated above is authoritative. We will inform data subjects of material changes in an appropriate manner.

14. Further legal documents

Last updated: August 2026