Questions about data protection?
Privacy Policy
Introduction and Responsibility
With this privacy policy, we inform you about which personal data we collect, how we use it, and what rights you are entitled to. This privacy policy serves to provide information both under the Swiss FADP (DSG) and under the EU General Data Protection Regulation (GDPR). For reasons of broader comprehensibility, GDPR terminology is used (e.g., 'personal data' instead of 'person-related data').
Controller
Woop MAAN Technology
Dorfstrasse 9
9656 Alt St. Johann
Switzerland
Phone: +41 76 520 65 98
Email: kontakt@woop.swiss
Website: www.woop.swiss
EU Representative pursuant to Art. 27 GDPR
Pursuant to Art. 27 GDPR, we designate the following EU data protection representative:
Mr Ralph D. Woop
Schillerstrasse 39
73635 Rudersberg
Germany
Email: eu-representative@woop.swiss
General Information and Security Measures
SSL or TLS Encryption
For security reasons and to protect the transmission of confidential content, such as inquiries you send to us as the site operator via our contact form, this website uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from 'http://' to 'https://' and by the small lock symbol in your browser line. TLS encryption protects data in transit from being read by unauthorized parties. However, we would like to point out that data transmission over the Internet (e.g., when communicating via email) can generally have security vulnerabilities. Complete protection of data against access by third parties is not possible.
General Retention Period and Erasure
Unless a more specific retention period is specified within this privacy policy for individual data processing operations, your personal data will generally remain with us only until the purpose for the data processing no longer applies. If you assert a legitimate request for erasure or revoke consent granted for data processing, your data will be deleted immediately. An exception to this principle exists only if we have other legally permissible reasons or statutory obligations to store your personal data. This applies in particular to data that must be archived due to commercial or tax retention periods. In these cases, the statutory retention period replaces the actual purpose limitation. The erasure of data only takes place after these mandatory retention reasons no longer apply.
Your Rights as a Data Subject (Data Subject Rights)
As a data subject, you have the following rights under the GDPR as well as under the analogous provisions of the Swiss FADP:
- Right of Access (Art. 15 GDPR): You have the right to request information at any time and free of charge as to whether and which of your personal data we process. This includes, among other things, information on the purposes of processing, the origin of the data, the recipients, and the planned retention period.
- Right to Rectification (Art. 16 GDPR): You can request the immediate correction of incorrect data or the completion of your personal data stored with us.
- Right to Erasure / 'Right to be Forgotten' (Art. 17 GDPR): You have the right to request the deletion of your personal data as soon as the purpose of the data processing no longer applies, you revoke your consent, or the processing is unlawful. An exception applies in the case of statutory retention obligations.
- Right to Restriction of Processing (Art. 18 GDPR): Under certain conditions, you can request that the processing of your data be restricted.
- Right to Data Portability (Art. 20 GDPR): You have the right to receive data that we process automatically on the basis of your consent or for the performance of a contract in a structured, commonly used, and machine-readable format.
- Right to Withdraw Consent (Art. 7 Abs. 3 GDPR): You can withdraw consent to data processing once given to us at any time with effect for the future. The lawfulness of the data processing carried out up to the withdrawal remains unaffected.
- Right to Object (Art. 21 GDPR): If the data processing is based on our legitimate interest, you have the right to object for reasons arising from your particular situation. In the case of direct marketing, you have a general right to object.
- Right to Lodge a Complaint (Art. 77 GDPR): You have the right to complain to a data protection supervisory authority. In Switzerland, you can contact the Federal Data Protection and Information Commissioner (FDPIC / EDÖB).
Server Log Files
With every purely informative visit to our website (i.e., if you do not register via a form or otherwise transmit information to us), our system automatically collects general data and information from the computer system of the calling computer.
Every time our website is accessed, the systems of our server infrastructure (load balancer, caching layer, and web server) automatically record technical log data. The following information is recorded in so-called server log files: the IP address of the requesting device, the date and exact time of access (timestamp), the specific target address or path called up (HTTP request), the HTTP status code, the amount of data transferred, as well as the referrer URL and the user agent (browser type and operating system). The purpose of this processing is to ensure IT security, stability, and the proper load distribution of our systems. The temporary storage of the IP address is technically mandatory in order to detect, defend against, and, in the event of an emergency, prosecute cyber attacks (e.g., DDoS attacks, automated malware access). An evaluation of this data for marketing purposes or profiling does not take place.
Processing is carried out on the basis of our legitimate or overriding interest pursuant to Art. 6 (1) (f) GDPR and Art. 31 (1) and (2) (a) FADP. Our legitimate interest lies in ensuring the permanent operational security, integrity, and availability of our web infrastructure as well as fulfilling our legal obligation to ensure data security (Art. 32 GDPR).
The recipient of the data is netcup GmbH, Daimlerstrasse 25, 76185 Karlsruhe, Germany. Data-protection-compliant processing is guaranteed by a concluded contract on order processing (AVV) pursuant to Art. 28 GDPR or the specifications of the Swiss FADP; the service provider processes the data strictly in accordance with our instructions. The data is stored exclusively in certified data centers within Germany (European Union). Since our company is based in Switzerland, administrative access to these servers is carried out by us from Switzerland. This cross-border data flow is legally secured by the official adequacy decision of the EU Commission for Switzerland. A further transfer to unauthorized third parties or to insecure third countries (such as the USA) does not take place via the hosting.
The complete log data (including IP addresses) is stored on our server structures for a period of up to 30 days for IT security reasons and for technical error analysis, after which it is deleted fully automatically. Longer storage only takes place if a specific security incident (e.g., a cyber attack) requires further investigation and securing of evidence.
The provision of this data is not voluntary and cannot be prevented or configured in advance by the user. The collection is a mandatory, purely automatic part of Internet protocol communication. As soon as your browser initiates a connection to our server infrastructure, this data is processed system-side before the first website content is delivered. Using the website without this automated logging is technically impossible. Therefore, there is no right to object or option for an 'opt-out' for these purely operational infrastructure logs.
External Web Hosting and Infrastructure
For the provision, stable operation, and secure delivery of our website, we use the infrastructure of an external web hosting provider. All personal data collected when visiting or using our website (such as IP addresses as part of automatic network communication or data actively entered by you in forms) is processed and stored on the systems of this service provider.
The use of the external hoster is based on our legitimate or overriding interest pursuant to Art. 6 (1) (f) GDPR (or Art. 31 (1) FADP). Our legitimate interest lies in the technically error-free, stable, high-performance, and secure provision of our online offer.
The recipient of the data is netcup GmbH, Daimlerstrasse 25, 76185 Karlsruhe, Germany. Data-protection-compliant processing is guaranteed by a concluded contract on order processing (AVV) pursuant to Art. 28 GDPR or the specifications of the Swiss FADP; the service provider processes the data strictly in accordance with our instructions. The data is stored exclusively in certified data centers within Germany (European Union). Since our company is based in Switzerland, administrative access to these servers is carried out by us from Switzerland. This cross-border data flow is legally secured by the official adequacy decision of the EU Commission for Switzerland. A further transfer to unauthorized third parties or to insecure third countries (such as the USA) does not take place via the hosting.
The data remains on the hoster's servers until the purpose for the data processing no longer applies (e.g., after an inquiry from the contact form has been processed). Automatically collected system data (server log files) is - as described in the separate section on log files - stored for up to 30 days and then fully automatically deleted or anonymized, unless a specific security incident makes longer storage necessary for evidence purposes.
The processing of your data on the server structures of our partner is neither legally nor contractually required. However, it is a mandatory, automatic part of Internet protocol communication. As soon as your browser initiates a connection to our domain, the server processes this data before the actual website content is delivered. Displaying and using the website without this infrastructural processing is technically impossible, which is why no prior opt-out can be set up.
Consent Management and Use of Cookies
General Information on Cookies and Local Storage Technologies
Our website uses cookies and comparable local storage technologies (such as your browser's LocalStorage). Cookies are small text files or data fragments that your browser automatically stores on your end device (computer, tablet, smartphone) when you visit our website.
We distinguish between two categories of functions:
- Technically necessary (essential) functions: These are strictly required so that our website, its basic functions (e.g., remembering your privacy choice), and the security of the site work error-free.
- Non-necessary services (Analysis & Marketing): These services (e.g., Google Analytics 4) help us evaluate user behavior and optimize our offer. They are exclusively activated after your prior and explicit consent.
Consent Management (Consent Banner)
In order to query and manage your decisions regarding services requiring consent in a data-protection-compliant manner, we use an integrated consent management system on our website. This system is operated directly on our server infrastructure and at no time transmits data to external third-party providers of consent management platforms.
Your current Consent ID
This unique ID is stored locally in your browser and pseudonymized on our server to prove your privacy choice.
No choice made yetWhen you access our website and make your choice in the consent banner, our system processes this decision. In order to comply with the legal obligation to provide proof, we must log that you consented or objected at a specific time. This is done via a privacy-friendly, pseudonymized proof procedure using a Consent ID. Locally in the browser: When submitting your declaration, our system generates a random, unique character string (the 'Consent ID') and stores it locally on your end device so that the page remembers your choice when you switch subpages. On the server: In parallel, this Consent ID is stored in a protected log file on our server. Linked to this ID, we log the exact timestamp, the status of your selection (allowed/rejected services), the user agent used (browser type/operating system), and your IP address exclusively in anonymized (shortened) form (e.g., 193.12.xx.xx). The Consent ID is not directly linked to your name or any other directly identifying information.
Compliance with a legal obligation (Art. 6 (1) (c) GDPR): The server-side logging of your decision serves the legally required proof of consent granted. Legitimate or overriding interest (Art. 6 (1) (f) GDPR or Art. 31 (1) FADP): Setting the technically necessary storage value on your end device is done in order to show you a functioning and GDPR-compliant website.
The log data of the consent management is sent encrypted to our servers in Germany (EU) and stored there. Since our company is based in Switzerland, access to these servers is carried out by us from Switzerland. A data transfer to Switzerland therefore takes place, for which, however, an adequacy decision of the EU Commission is in place, which guarantees an equivalent level of data protection. An inadmissible data transfer to unauthorized third parties or to insecure third countries (such as the USA) does not take place for this service.
The selection element (cookie) on your end device remains stored until you delete it manually or the maximum storage duration of 1 year is reached. The associated log data for proof (server logs) is kept independently for a fixed period of 1 year on our server in order to comply with our statutory obligation to provide proof and is then automatically deleted.
The collection of the Consent ID and the saving of your selection is technically required in order to ensure the GDPR compliance of the page. However, granting consent for optional tools (such as Google Analytics) is completely voluntary.
Contact Form and Communication
If you send us a message via our contact form, we process the data you enter there, in particular your name, email address, telephone number, company name, the selected topic, your preferred contact language, the project category, the planned timing, and your message. The purpose of the processing is the proper processing of your request, contacting you, and clarifying any follow-up questions.
If your request serves the preparation of a contract or the performance of an existing contract, the legal basis is Art. 6 (1) (b) GDPR (or Art. 31 (2) (a) FADP). In all other cases, processing is based on our legitimate or overriding interest in an efficient and rapid response to customer inquiries pursuant to Art. 6 (1) (f) GDPR (or Art. 31 (1) FADP).
For the technical delivery of your contact request, we use an external email delivery service. The data you enter in the form is transmitted encrypted to our server infrastructure and, from there, automatically sent as an email to one of our internal collection addresses. The delivery service processes the message content only transiently for the purpose of delivery; the configured processing region is Germany (EU), so that processing takes place within the EU. The recipient of the data in this respect is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. The email is then received in our contact mailbox, which we operate via an external provider of email services; the recipient of the data here is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The retrieval and processing of your message is carried out by us at our registered office in Switzerland; this cross-border data flow is secured by the official adequacy decision of the EU Commission for Switzerland. Both providers are companies with a US parent company, which means access from an unsafe third country cannot be entirely ruled out. The legal and technical protective measures we have taken for this purpose (data processing agreements, the EU-U.S./Swiss-U.S. Data Privacy Framework, and Standard Contractual Clauses) can be found in the section “International Data Transfers (Third-Country Transfers)” of this privacy policy.
Your contact request is received as an email in our contact mailbox and remains there until the purpose for storing the data no longer applies (e.g., after your request has been fully processed) or you request us to delete it. The email delivery service does not store the message content permanently; processing there is limited to the period technically required for delivery. Mandatory statutory provisions - in particular commercial or tax retention periods for business contracts or resulting correspondence - remain unaffected.
The provision of your data is completely voluntary. Without providing your name and a valid email address, however, we cannot technically accept or reply to your request.
Google Tag Manager (GTM)
We use the Google Tag Manager on our website. This is a technical management system that itself does not set cookies and does not create independent user profiles. It serves exclusively as a tool to centrally control other analysis and statistical tools (such as Google Analytics 4). In order for the service to be loaded, your browser must establish a technical connection to Google, whereby your IP address is transmitted to Google.
The Google Tag Manager is only loaded on our website after you have given us your explicit and voluntary consent via our consent banner. The legal basis is therefore your consent pursuant to Art. 6 (1) (a) GDPR (or Art. 31 (1) FADP).
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. As a subsidiary of Google LLC (USA), it cannot be excluded that data will be transferred to the servers of the parent company in the USA and stored there. Detailed information on this third-country transfer and the technical and contractual security guarantees taken by us can be found centrally in the section “International Data Transfers (Third-Country Transfers)” of this privacy policy.
The Google Tag Manager itself does not store personal data permanently. The processing of your IP address is transient for the pure technical connection setup and retrieval of the service.
The provision of your consent is voluntary. If you refuse consent, the Google Tag Manager will not be loaded; this will not result in any disadvantages for you when using the website.
Google Analytics 4 (GA4)
Insofar as you have given your consent, we use Google Analytics 4 for statistical evaluation and range measurement of our website. In the process, data about your user behavior is recorded via cookies or device identifiers (e.g., pages called up, duration of visit, click paths, your approximate location, and technical details about your browser and end device). We have activated IP anonymization by default, so that your IP address is shortened by Google within Switzerland or the EU/EEA before a data transfer takes place.
Processing is carried out exclusively on the basis of your explicit consent via our consent banner pursuant to Art. 6 (1) (a) GDPR (or Art. 31 (1) FADP).
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. As a subsidiary of Google LLC (USA), it cannot be excluded that data will be transferred to the servers of the parent company in the USA and stored there. Detailed information on this third-country transfer and the technical and contractual security guarantees taken by us can be found centrally in the section “International Data Transfers (Third-Country Transfers)” of this privacy policy.
The data transmitted by us to Google at user level and event level (e.g., clicks) is set to be deleted automatically and permanently on Google's servers after 14 months.
Provision is voluntary. You can withdraw your consent at any time with effect for the future via the 'Cookie Settings' in the footer of our website.
Google Ads conversion tracking
Where you have given your consent, we use Google Ads to measure whether a visit that originated from one of our ads subsequently leads to a contact request. When you click an ad, Google appends a click identifier (GCLID) to the destination address; this is stored on your device in first-party cookies whose names begin with _gcl_ (_gcl_aw, _gcl_au), as well as in _gac_*. If you then successfully submit our contact form, our website reports to Google that a conversion took place at this point. Only this fact is transmitted, together with the click identifier – not the details you entered into the form, and not your name, email address or phone number.
The Google Ads tag is only loaded after you have given us your explicit and voluntary consent to the “Marketing” category via our consent banner. Until then, the advertising signals of Google Consent Mode remain set to “denied” and no cookie is set. The legal basis is therefore your consent pursuant to Art. 6 (1) (a) GDPR (or Art. 31 (1) FADP).
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. As a subsidiary of Google LLC (USA), it cannot be excluded that data will be transferred to the servers of the parent company in the USA and stored there. Detailed information on this third-country transfer and the technical and contractual security guarantees taken by us can be found centrally in the section “International Data Transfers (Third-Country Transfers)” of this privacy policy.
These cookies are stored on your device for 90 days and are then deleted automatically. You can remove them at any time via your browser settings or withdraw your consent in our cookie settings.
Giving your consent is voluntary. If you refuse consent, the Google Ads tag will not be loaded; this will not result in any disadvantages for you when using the website or when we process your request.
Appointment Booking and Reservations via Google Calendar
In order to offer you an uncomplicated online appointment booking, we embed the reservation function of Google Calendar. In order to protect your privacy, this service is deactivated by default. Only when you actively request the calendar via the corresponding button (two-click solution), the technical resources (scripts, stylesheets) of Google are loaded. In the process, Google processes your IP address. If you use the function for appointment booking, we process the data you enter (first and last name, email address, as well as your preferred appointment and the reason for the meeting) for the purpose of automated booking and coordination of the appointment.
Consent (Art. 6 (1) (a) GDPR / Art. 31 (1) FADP): Loading the external resources and the associated transmission of your IP address to Google takes place exclusively on the basis of your active consent (click on the activation button). Performance of a contract and pre-contractual measures (Art. 6 (1) (b) GDPR / Art. 31 (2) (a) FADP): The subsequent processing of your appointment data entered in the form serves the implementation of pre-contractual measures (scheduling) or the performance of an existing contract.
The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. As a subsidiary of Google LLC (USA), it cannot be excluded that data will be transferred to the servers of the parent company in the USA and stored there. Detailed information on this third-country transfer and the technical and contractual security guarantees taken by us can be found centrally in the section “International Data Transfers (Third-Country Transfers)” of this privacy policy.
Your entered appointment data remains in our internal calendar until the purpose of the data storage no longer applies (e.g., after the appointment has been successfully held) or you request us to delete it. Statutory retention obligations remain unaffected. The loading of Google resources takes place for the duration of your current browser session.
The use of the online calendar is voluntary. If you do not wish to activate the external service, you can of course also arrange appointments conventionally by email or phone.
International Data Transfers (Third-Country Transfers)
As part of the provision of our website and our services, we work with external partners and service providers who have their registered office or their servers in a third country outside the European Union (EU), the European Economic Area (EEA), or Switzerland – in particular in the USA. This currently concerns the Google services we use (Google Analytics, Google Tag Manager, Google Ads, Google Calendar, and our contact mailbox) as well as the email delivery services from Amazon Web Services, which we use to send contact requests.
When we transmit personal data to these service providers, we ensure that an adequate level of data protection is maintained. For this purpose, we have taken the following legal and technical protective measures:
- Data Processing Agreements (DPAs / AVV): We have concluded legally compliant data processing agreements with our partners in the USA pursuant to Art. 28 GDPR or the Swiss FADP. In these agreements, the providers commit to processing your data only in accordance with our strict instructions.
- Data Privacy Framework (DPF): The USA has been recognized by the EU Commission and the Swiss Federal Council as a country with an adequate level of data protection, provided that the respective US company has certified itself. Our partners (Google and Amazon Web Services) are certified under the 'EU-U.S. Data Privacy Framework' and the 'Swiss-U.S. Data Privacy Framework'. For certified companies, the respective Data Privacy Framework provides a basis for such data transfers.
- Standard Contractual Clauses (SCCs): In addition and as an extra safeguard, the data transfer is based on the Standard Contractual Clauses provided by the EU Commission and recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC / EDÖB).
Validity and Amendments to this Privacy Policy
This privacy policy is currently valid and has the status of August 2026. Due to the further development of our website or due to changed statutory requirements, it may become necessary to adapt this policy. We reserve the right to change this privacy policy at any time and without notice. The current version published on our website always applies to your visit. Insofar as future changes affect consent-based data use, we will – as far as legally required – obtain new consent from you.