Nubeck Holding AG is committed to compliance with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP). This statement describes how we uphold the rights and principles set out in those frameworks.
1. Principles We Follow
We process personal data lawfully, fairly, and transparently; collect it for specified, explicit, and legitimate purposes; limit it to what is necessary; keep it accurate; retain it no longer than required; and ensure appropriate security.
2. Lawful Basis for Processing
We rely on one or more lawful bases under Article 6 GDPR: your consent, the performance of a contract, compliance with a legal obligation, or our legitimate interests, balanced against your rights and freedoms.
3. Data Subject Rights
Under the GDPR you have the right of access, rectification, erasure ('right to be forgotten'), restriction of processing, data portability, objection to processing, and the right not to be subject to solely automated decision-making.
We respond to verified requests without undue delay and within one month, as required by law. To exercise your rights, contact office@nubeckholding.com.
4. Consent Management
Where we rely on consent, it is freely given, specific, informed, and unambiguous. You can withdraw consent at any time without affecting the lawfulness of prior processing.
5. International Data Transfers
For transfers outside the EEA/Switzerland, we use appropriate safeguards such as European Commission Standard Contractual Clauses and adequacy decisions where applicable.
6. Data Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and affected individuals where required.
7. Data Protection by Design and Default
We integrate data protection into our processes and systems from the outset and apply data minimization and security measures by default.
8. Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority in your country of residence, place of work, or place of the alleged infringement.
