Privacy Policy
1. Controller
The controller responsible for processing personal data in connection with this website is:
Efendy Partners GmbHGewerbestrasse 12a9462 MontlingenSwitzerlandEmail: info@efendy-partners.com
For any questions regarding data protection or to exercise your rights, please contact us at the email address above.
2. Scope and Applicable Law
This privacy policy applies to the website www.efendy-partners.com. The governing law is the Swiss Federal Act on Data Protection (FADP) and its implementing ordinance. Where we process personal data of individuals in the European Economic Area and the General Data Protection Regulation (GDPR) applies, we additionally comply with its requirements. Where relevant, we therefore also state the applicable legal basis under Article 6 GDPR.
3. Principles
We process personal data in good faith, proportionately, and only for the purposes set out in this policy. We do not collect more data than necessary, do not retain it longer than required, and disclose it only where necessary for the respective purpose or where we are legally obliged to do so.
Personal data means any information relating to an identified or identifiable natural person.
4. Processing When Visiting the Website
4.1 Server Log Files
Our website is hosted by:
Hostinger International Limited61 Lordou Vironos Street6023 Larnaca, Cyprus
When you access our website, your browser transmits technically necessary data which our hosting provider stores in server log files. This includes in particular:
- IP address of the requesting device
- Date and time of access
- Name and URL of the file retrieved
- Volume of data transferred and notification of successful retrieval
- Browser type and version
- Operating system of the device
- Previously visited page (referrer URL)
This processing is technically necessary for the website to be delivered and serves system stability, security and the prevention of misuse. Under the GDPR, the legal basis is our legitimate interest in the secure and functional operation of the website (Article 6(1)(f) GDPR).
Log files are automatically deleted after a short period, unless security-related incidents require longer retention. A data processing agreement is in place with the provider.
4.2 Externally Embedded Content
Our website embeds content loaded from third-party servers. This includes video files delivered via the Amazon CloudFront content delivery network (Amazon Web Services) and individual images from the Unsplash service (Unsplash Inc., Canada). When such content is loaded, your IP address is transmitted to the respective provider, as it would otherwise be unable to send the content to your browser.
We use these services to deliver content quickly and reliably. Under the GDPR, the legal basis is our legitimate interest in the performant presentation of our website (Article 6(1)(f) GDPR).
Fonts are served exclusively from our own server. No connection to third-party servers takes place for this purpose.
4.3 Cookies and Similar Technologies
Cookies are small text files stored on your device. We distinguish between:
Strictly necessary cookies, which enable the operation of the website and its core functions, such as storing your language selection or your consent decision. Without them, the website does not function properly. Under the GDPR, the legal basis is our legitimate interest (Article 6(1)(f) GDPR).
Analytics and marketing cookies, which we use only if you have given prior consent. Under the GDPR, the legal basis is your consent (Article 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG).
4.4 Consent Management
When you first access our website, you will be presented with a notice allowing you to decide on the use of non-essential cookies and services. No analytics or marketing services are loaded before you give consent.
Your decision is stored so that the notice does not reappear on every page view. You may withdraw or adjust your consent at any time with effect for the future by reopening the cookie settings. The lawfulness of processing carried out before withdrawal remains unaffected.
5. Contact and Enquiries
You can send us an enquiry via the contact form on our website. We collect your name, email address, telephone number and the content of your message. The information is transmitted by email to our mailbox; it is not permanently stored in a form system.
The same applies to enquiries sent directly by email, as well as to appointment requests and enquiries regarding our audit offerings. These are also handled by email.
We process this data solely in order to respond to your enquiry and to handle the resulting communication. Under the GDPR, the legal basis is the performance of pre-contractual measures or the performance of a contract (Article 6(1)(b) GDPR), and otherwise our legitimate interest in responding to enquiries (Article 6(1)(f) GDPR).
Your data will be deleted once your enquiry has been conclusively dealt with, provided no statutory retention obligations apply. Business correspondence leading to a contractual relationship is retained for ten years in accordance with commercial and tax law requirements.
Providing your data is voluntary. However, without an email address or telephone number we cannot respond to you.
6. Analytics and Advertising
The services described below are loaded only after you have given consent via the consent notice. Under the GDPR, the legal basis in each case is your consent (Article 6(1)(a) GDPR).
6.1 Google Analytics
We use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The service helps us understand how our website is used, which content attracts interest and where we can improve.
The data collected includes the pages accessed, time spent, country of origin, approximate location based on a truncated IP address, the device used and the source through which you reached us. We have enabled IP anonymisation, so your IP address is truncated before further processing.
Google also processes this data in the United States. Further details can be found in Google's privacy policy at policies.google.com/privacy.
6.2 Google Ads and Google Tag Manager
We use Google Ads to promote our services, together with conversion tracking to determine whether an advertisement has led to an enquiry. A cookie is set when you reach our website via one of our advertisements. We receive only statistical evaluations from Google and cannot identify individual users.
We use Google Tag Manager to integrate and manage these services. Tag Manager itself does not collect personal data but enables the above services to be deployed following your consent.
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
6.3 Meta Pixel
We use the Meta Pixel provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland. It allows us to measure the effectiveness of our advertisements on Facebook and Instagram and to re-engage people who have shown interest in our services.
The pixel records which pages you have visited and whether you have performed certain actions, such as submitting an enquiry. If you hold an account with a Meta service, Meta may associate this information with your account.
We are joint controllers with Meta for the collection and transmission of the data to Meta. Further processing by Meta takes place under Meta's sole responsibility. The essential elements of this joint controllership are available at www.facebook.com/legal/controller_addendum. Meta also processes data in the United States.
6.4 LinkedIn Insight Tag
We use the Insight Tag provided by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, in order to evaluate the performance of our LinkedIn campaigns and to reach relevant audiences.
The data recorded includes the URL of the page accessed, the referrer URL, the IP address, device and browser characteristics, and the timestamp. IP addresses are truncated or hashed by LinkedIn. If you are a LinkedIn member, the data may be associated with your account. LinkedIn also processes data in the United States.
7. Our Social Media Presence
We maintain a publicly accessible profile on Instagram (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland). If you visit or interact with this profile, the privacy provisions of the respective network apply primarily. We have only limited influence over the data processing carried out by the operator.
Where we receive statistical evaluations relating to our profile, we are joint controllers with the operator for this purpose. These evaluations are aggregated; we cannot draw conclusions about individual persons from them.
On our website the network is merely linked. No network content is embedded unless you click the link.
8. Disclosure to Third Parties
We disclose personal data only where necessary to provide our services, where you have consented, or where we are legally obliged to do so. Recipients may include:
- Providers of hosting, email and IT infrastructure
- Providers of the analytics and advertising services named above
- Fiduciary, audit and legal advisers, to the extent required
- Authorities and courts, where a statutory obligation exists
With service providers processing data on our behalf, we conclude agreements ensuring processing in accordance with Swiss and European law. We do not sell personal data.
9. Transfers Abroad
Some of the service providers named above are established outside Switzerland or process data outside Switzerland, in particular in member states of the European Union and in the United States.
For countries without an adequate level of data protection, we base such transfers on appropriate safeguards, generally the Standard Contractual Clauses approved by the European Commission in the version recognised by the Swiss Federal Data Protection and Information Commissioner, supplemented where necessary by additional protective measures. Where a recipient in the United States is certified under the Swiss-U.S. Data Privacy Framework, we base the transfer on that certification.
You may request a copy of the relevant safeguards at the contact address given above.
10. Retention Periods
We retain personal data only for as long as necessary for the respective purposes or as required by statutory retention periods. Data is subsequently deleted or anonymised. Business records are subject to the commercial law retention period of ten years.
11. Data Security
We take appropriate technical and organisational measures to protect your data against unauthorised access, loss and misuse. These include encrypted transmission via TLS, restrictive allocation of access rights and regular updates to the systems we use. Complete protection against all risks is technically impossible when transmitting data over the internet.
12. Your Rights
Within the scope of applicable law, you have in particular the following rights:
- Access to information on whether and which personal data we process about you
- Rectification of inaccurate data
- Erasure of data whose processing is no longer necessary
- Restriction of processing
- Objection to processing based on a legitimate interest
- Data portability in a common electronic format
- Withdrawal of consent at any time with effect for the future
An informal message to info@efendy-partners.com is sufficient to exercise these rights. In order to protect your data, we may need to ask you to verify your identity.
You also have the right to lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern. Where processing falls under the GDPR, you may contact the supervisory authority of your country of residence.
13. Processing on Behalf of Our Clients
In the course of providing our services in marketing, digital growth and AI systems, we regularly process personal data made available to us by our clients or arising within their systems, such as contact details from advertising campaigns.
In these cases we act as a processor. The client company remains the controller of this data and determines the purposes and means of processing. We process the data solely on its instructions and on the basis of a data processing agreement.
Data subjects should address requests for information and the exercise of their rights directly to the company concerned. If such a request reaches us, we forward it to the responsible company.
This privacy policy does not apply to such processing; the privacy policy of the respective client company governs instead.
14. No Automated Decision-Making
We do not use automated decision-making that produces legal effects concerning you or similarly significantly affects you.
15. Changes to This Privacy Policy
We may amend this privacy policy if our services, the technologies we use or the legal framework change. The version published on this page at any given time applies.
Last updated: July 2026
Back to home