Privacy policy

Data protection

We are pleased that you have visited our website and are interested in in-factory GmbH, in-factory Deutschland GmbH, and our products and services.

The protection of your personal data and its confidential handling are important to us. We process personal data exclusively in accordance with the applicable data protection laws.

For in-factory GmbH, headquartered in Switzerland, the Swiss Federal Data Protection Act (DSG) and the associated Data Protection Ordinance (DSV) apply in particular. To the extent that the European Union’s General Data Protection Regulation (GDPR) applies, its provisions are also taken into account.

In particular, in-factory Deutschland GmbH is subject to the GDPR, the Federal Data Protection Act (BDSG), and—where applicable—the Telecommunications and Digital Services Data Protection Act (TDDDG).

In this Privacy Policy, we provide you with information about what personal data is processed in connection with our website and our services, for what purposes this is done, which service providers are used, and what rights you have.

1. Responsible Entities and Responsibilities

1.1 Entity Responsible for the Website, Content, and Hosting

The entity responsible for the operation and technical provision of this website is:

in-factory GmbH
Huebstrasse 35a
8317 Tagelswangen
Switzerland

Phone: +41 (0)52 235 19-88
Fax: +41 (0)52 235 19-98
Email: [email protected]

in-factory GmbH is specifically responsible for:

  • Operation and hosting of this website,
  • Hosting and technical infrastructure,
  • Server and access logs,
  • Website IT security,
  • technical and editorial content,
  • Administration and Maintenance,
  • Management and use of website plugins,
  • Integration of external services,
  • Consent and Cookie Management,
  • Translation functions,
  • Tracking and analytics features, as well as
  • Technical implementation of contact forms.

Whenever this Privacy Policy refers to processing “on our website,” “when visiting our website,” or through the technical services used on the website, in-factory GmbH is generally responsible for such processing, unless otherwise specified in the relevant section.

1.2 in-factory Deutschland GmbH

This website also showcases the products and services of the German subsidiary:

in-factory Deutschland GmbH
Georg-Deuschle-Str. 84
D-73730 Esslingen
Germany

Phone: +49 711 31 688 02
Email: [email protected]

in-factory Deutschland GmbH is not the operator of the website and is not responsible for its hosting, technical infrastructure, or editorial content.

However, it is the independent data controller under data protection law to the extent that personal data is processed for its own business purposes.

This applies in particular to:

  • Direct inquiries to in-factory Deutschland GmbH,
  • Quotes and orders from in-factory Deutschland GmbH,
  • Customer and Prospect Relationships,
  • Contract Negotiation and Contract Execution,
  • Communication with business partners and customers, as well as
  • Other business relationships with in-factory Deutschland GmbH.

If personal data is initially collected via this website by in-factory GmbH through technical means, and if a request clearly concerns in-factory Deutschland GmbH, the data necessary for processing may be transferred to in-factory Deutschland GmbH.

The subsequent processing for its own business purposes is carried out by in-factory Deutschland GmbH, which is solely responsible for compliance with data protection laws.

2. Scope of Data Protection

The subject of data protection is personal data.

This includes all information relating to an identified or identifiable natural person.

In particular, these may include:

  • First and last name,
  • Address,
  • Email address,
  • Phone number,
  • Company and job title,
  • The content of messages and inquiries,
  • IP address,
  • Browser and device information,
  • Usage and access data,
  • Cookie identifiers,
  • Consent information, as well as
  • Other information that you voluntarily provide to us.

Personal data may be collected both directly from you and automatically when you use our website.

3. General Purposes of Data Processing

Personal data is processed, in particular, for the following purposes:

  • Hosting and operation of the website,
  • Ensuring IT security and system stability,
  • Error Analysis and Fraud Prevention,
  • Processing of contact and information requests,
  • Contract Negotiation and Contract Execution,
  • Provision of forms and interactive features,
  • Display of the website in various languages,
  • Analysis and optimization of our website,
  • Management of customer and prospect relationships,
  • Marketing and communication, to the extent permitted by law,
  • Manage your cookie and privacy settings,
  • Compliance with legal obligations, as well as
  • Protection and enforcement of legal claims.

To the extent that the GDPR applies, processing is based in particular on:

  • Based on your consent pursuant to Article 6(1)(a) of the GDPR,
  • to take steps prior to entering into a contract or to fulfill a contract pursuant to Article 6(1)(b) of the GDPR,
  • to comply with legal obligations pursuant to Article 6(1)(c) of the GDPR, or
  • based on our legitimate interests pursuant to Article 6(1)(f) of the GDPR.

Our legitimate interests include, in particular, the secure, reliable, and cost-effective operation of our website, efficient communication with customers and prospective customers, and the optimization of our offerings.

4. Visits to Our Website and Server Log Files

When you visit our website, the web server transmits and processes information that is technically necessary.

These may include, in particular:

  • IP address,
  • Date and time of access,
  • page or file accessed,
  • Referrer URL,
  • Browser type and browser version,
  • operating system used,
  • Device type,
  • Language settings,
  • Hostname,
  • amount of data transferred,
  • HTTP status code and
  • Additional technical connection information.

Data is processed in particular for the following purposes:

  • technical implementation of the website,
  • Ensuring operational capability,
  • Ensuring system and network security,
  • Detection and defense against attacks,
  • Error analysis and
  • Prevention of misuse.

To the extent that the GDPR applies, processing is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure and uninterrupted operation of our website.

The data will be deleted or anonymized when it is no longer needed for these purposes and there are no legal retention requirements or security reasons that would prevent its deletion.

5. Encrypted Data Transmission

Our website uses an encrypted HTTPS connection.

This ensures that data transmitted between your browser and our website is protected against unauthorized access using state-of-the-art technology.

6. Cookies and Similar Technologies

Our website uses cookies and similar technologies.

Cookies are small files or pieces of information that can be stored on or retrieved from your device.

In particular, we distinguish between:

  • technically necessary cookies,
  • functional cookies,
  • Statistics and analytics cookies, as well as
  • Marketing cookies.

Technically necessary cookies are used to the extent that they are required for the operation of the website or to provide a feature you have expressly requested.

Cookies and similar technologies that are not technically necessary will—to the extent required by law—only be used after you have given your consent through our consent management system.

To the extent that the GDPR applies, the subsequent processing of personal data in connection with technologies requiring consent is generally based on Article 6(1)(a) of the GDPR.

When accessing or storing information on end devices, we also take into account the requirements of § 25 TDDDG, to the extent that they apply to users in Germany.

You may revoke or change your consent at any time, effective for the future, using the privacy settings available on our website.

The cookies currently used on our website, their providers, purposes, and storage periods can be found in the cookie policy provided via Cookiebot.

7. Cookiebot Consent Management Platform

We use the Cookiebot Consent Management Platform (CMP) on our website to manage your cookie and privacy settings.

The provider is:

Usercentrics A/S
Havnegade 39
1058 Copenhagen
Denmark

Cookiebot is primarily used to:

  • to obtain your consent,
  • to implement the selected settings,
  • To save consents or refusals,
  • Recognize your settings during future visits and
  • to be able to provide the legally required proof of consent.

In particular, the following may be processed:

  • Consent status,
  • Date and time of the decision,
  • Information about the browser being used,
  • Website or URL,
  • truncated or anonymized IP information, as well as
  • A randomly generated and encrypted identifier, or consent ID.

The consent decision is also stored in your browser via a first-party cookie.

Cookiebot generally stores consent records for up to twelve months.

To the extent that the GDPR applies, processing is carried out, in particular, to fulfill our legal obligations regarding evidence and documentation pursuant to Article 6(1)(c) of the GDPR, as well as based on our legitimate interest in legally compliant consent management pursuant to Article 6(1)(f) of the GDPR.

You can change or withdraw your consent at any time via the privacy settings on our website.

8. HubSpot

We use features from the following providers on our website:

HubSpot, Inc.
Two Canal Park
, Cambridge, MA 02141
USA

HubSpot is used in particular to provide forms, process contact requests, manage customers and prospects, and—provided you have given your consent—analyze the use of our website.

Depending on the feature used, the following data, in particular, may be processed:

  • IP address,
  • Browser and device information,
  • pages visited,
  • Time of page views,
  • Source or referrer,
  • Interactions with our website,
  • Cookie or visitor identifiers,
  • Name,
  • Email address,
  • Phone number,
  • Companies,
  • The content of a request, as well as
  • Additional information provided voluntarily.

8.1 HubSpot Forms

If you use a form hosted by HubSpot, the information you enter will be processed and stored in our HubSpot system.

Your data is processed to handle your inquiry, to communicate with you, and, if applicable, to carry out pre-contractual measures.

To the extent that the GDPR applies, processing is based in particular on Article 6(1)(b) of the GDPR or, in the case of general business inquiries, on Article 6(1)(f) of the GDPR.

8.2 HubSpot Tracking

If you have given your consent, we use HubSpot's tracking features.

This allows HubSpot to collect information about visits to our website, page views, interactions, and repeat visitors.

Cookies and online identifiers, in particular, may be used for this purpose.

Depending on the configuration, cookies such as the following may be used:

  • hubspotutk,
  • __hstc,
  • __hssc and
  • __hssrc

be used.

Under certain conditions, these identifiers can be used to associate website visits with a contact identified later through a form submission.

HubSpot tracking is used only if you have given your consent through our consent management system.

To the extent that the GDPR applies, the legal basis is Article 6(1)(a) of the GDPR.

You can revoke your consent at any time through our privacy settings.

8.3 HubSpot CRM

Data that you provide to us when you contact us may be stored in our HubSpot CRM.

In particular, this serves the following purpose:

  • To process inquiries in a structured manner,
  • Manage relationships with customers and prospects,
  • To be able to understand communication processes and
  • To carry out sales and service processes.

If your inquiry concerns in-factory Deutschland GmbH, the contact information required to process it may be processed within HubSpot by in-factory Deutschland GmbH for its own business purposes.

in-factory Deutschland GmbH is solely responsible for this subsequent business processing.

8.4 Data Hosting and Transfers to Third Countries

HubSpot operates its product infrastructure through Amazon Web Services in the European Union—including Germany—as well as in other regions such as the United States.

The specific hosting location depends on the configuration of the HubSpot account being used.

Since HubSpot is a U.S. company and may involve affiliates or subcontractors located outside Switzerland or the European Economic Area, it cannot be ruled out that data may also be processed across borders.

HubSpot specifically provides for the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework, and standard contractual clauses or comparable permissible transfer mechanisms for this purpose.

9. Popup Maker

We use the WordPress plugin Popup Maker to display notices, information, forms, or other content in pop-up windows.

Popup Maker is used within our WordPress installation.

The plugin may use cookies to store information such as:

  • whether a pop-up has already been displayed,
  • whether a pop-up was opened,
  • whether a pop-up has been closed or
  • whether a form was submitted within a pop-up.

Cookie names typically follow this pattern:

pum-[ID]

The retention period can be configured within the plugin. The default setting in Popup Maker is currently one month.

According to the provider, the standard Popup Maker cookies themselves generally do not contain any personal information or login data; rather, they are used primarily to control when pop-ups are displayed again.

If a cookie is technically necessary for a function you have requested, its use may be based on technical necessity.

To the extent that Popup Maker is used for analytics, marketing, or similar purposes, the relevant technologies will be used only after you have given your consent.

If a pop-up contains a form or a feature from another service provider, such as HubSpot or Elfsight, the privacy policy of that service also applies.

10. Weglot

We use the Weglot translation service to make our website available in multiple languages.

The provider is:

Weglot SAS
7 Cité Paradis
75010 Paris
France

Weglot analyzes the content of our website in order to translate it into the selected language.

In particular, the following may be processed:

  • Website content,
  • Original texts and translations,
  • URLs,
  • Languages used,
  • IP address and
  • Technical browser and device information.

According to Weglot, it works with the following services in particular for automatic translation:

  • DeepL,
  • Google Translate and
  • Microsoft Bing Translator.

Weglot selects an appropriate translation provider based on the specific language pair.

Weglot states that it operates its own servers within the European Union. However, subcontractors located outside the European Union may also be involved in the provision of the service.

To the extent that it is technically possible and necessary, content that is not intended for automatic translation will be excluded from the translation.

To the extent that the GDPR applies, the processing required to provide the multilingual website is based, in particular, on Article 6(1)(f) of the GDPR. Our legitimate interest is to make our information and services available to an international audience.

Unless Weglot or integrated services use cookies or similar technologies that are technically necessary, their use is subject to your consent.

11. Elfsight

On our website, we use widgets from:

Elfsight, SL
C. de la Constitució 17
AD700 Escaldes-Engordany
Andorra

Elfsight offers a variety of website elements and widgets.

The personal data that is processed depends on the specific widget being used.

According to Elfsight, the following information, in particular, may be processed when an Elfsight widget is loaded:

  • IP address,
  • Operating system and

Elfsight states that it generally stores this technical information for seven days. It is used, in particular, for error analysis, system security, and the detection of unauthorized access.

For widgets that include input fields, the personal data entered by the user may also be processed.

This may include, for example, forms, contact features, registration processes, or similar interactive features.

Elfsight states that it stores personal data from its widgets on secure systems on the Google Cloud Platform.

Unless an Elfsight widget uses cookies, tracking technologies, or external content that are technically necessary, the corresponding feature will not be loaded until you have given your consent.

To the extent that the GDPR applies, processing in these cases is based on Article 6(1)(a) of the GDPR.

If an Elfsight widget embeds content from other third-party providers, this may result in additional data being transmitted to those providers. Where necessary, this content will also be loaded only after you have given your consent.

12. File Manager

We use a file manager for the technical management of files in our WordPress installation.

The file manager is primarily used for internal administration and management of files on the server infrastructure used for the website.

Provided that the file manager is used exclusively within the secure administration area, simply visiting our public website generally does not result in any additional processing of personal data by the file manager.

However, the file manager can manage files that contain personal data.

To the extent that this is the case, processing is carried out exclusively within the scope of the respective original purpose of processing and in accordance with the relevant access and authorization policies.

If file activities are logged, the following, in particular, may be processed:

  • User ID,
  • Time of an action,
  • Filename,
  • technical log data,
  • IP address and
  • Information about uploads, downloads, modifications, or deletions.

This processing is used, in particular, for administrative purposes, IT security, and the traceability of administrative processes.

To the extent that the GDPR applies, processing is based in particular on Article 6(1)(f) of the GDPR.

13. Making Contact

If you contact us by email, phone, or through a contact form, we will process the personal data you provide in order to handle your inquiry.

These may include, in particular:

  • Name,
  • Companies,
  • Email address,
  • Phone number,
  • Subject,
  • The content of your message, as well as
  • Additional information provided voluntarily.

in-factory GmbH is responsible for the technical implementation of the contact form on this website.

If your inquiry concerns in-factory Deutschland GmbH, the necessary personal data may be shared with that company.

in-factory Deutschland GmbH is solely responsible under data protection law for the subsequent processing of the inquiry.

To the extent that your inquiry relates to the initiation or performance of a contract, the processing—to the extent that the GDPR applies—is based on Article 6(1)(b) of the GDPR.

For other business inquiries, the processing may be based on our legitimate interest in properly handling and responding to your inquiry in accordance with Article 6(1)(f) of the GDPR.

14. Communication and Direct Marketing

If you have provided us with your contact information in connection with a business relationship or inquiry, we may also use it for further business communications to the extent permitted by law.

Newsletters, electronic advertisements, or similar marketing communications will only be sent if there is a legal basis for doing so.

To the extent that the processing is based on your consent, you may revoke it at any time with future effect.

If a message contains an unsubscribe link, you can also use it to stop receiving such communications.

15. Data Transfer Within the in-factory Group

Personal data may be transferred between in-factory GmbH and in-factory Deutschland GmbH to the extent that this is necessary for:

  • Processing a request,
  • Customer Service,
  • Contract initiation,
  • Contract performance,
  • Carrying out a project or
  • for other legally permissible reasons

is required.

This is particularly the case when an inquiry received through the website relates to the other company's offerings or business activities.

Each company processes the personal data it receives exclusively for the permitted purposes and in compliance with the data protection regulations applicable to it.

Since in-factory GmbH is headquartered in Switzerland and in-factory Deutschland GmbH is headquartered in Germany, this constitutes a cross-border data transfer between Switzerland and the European Union.

The European Union recognizes that Switzerland has an adequate level of data protection. Under Swiss data protection law as well, the member states of the European Union are generally considered to be countries with an adequate level of data protection.

Therefore, no additional safeguards are generally required for data transfers between Germany or the European Union and Switzerland, as would be necessary for transfers to countries without an adequate level of data protection.

16. Other Recipients of Personal Data

We will only disclose personal data if:

  • this is necessary for the provision of our services,
  • a service provider processes data on our behalf,
  • there is a legal obligation to,
  • another legal basis permits the disclosure, or
  • You have given your consent to this.

Recipients may include, in particular:

  • Hosting and IT service providers,
  • Website and maintenance service providers,
  • CRM service provider,
  • Marketing service providers,
  • Translation service providers,
  • Consent management providers,
  • Providers of embedded widgets,
  • Communications service provider,
  • Tax advisors, legal advisors, and other professional advisors, as well as
  • Government agencies, courts, or other public authorities, provided there is a corresponding obligation to do so.

To the extent that external service providers process personal data on our behalf, they are contractually obligated to do so in accordance with the applicable data protection regulations.

17. Data Transfers to Third Countries

In connection with certain services, personal data may be transferred to countries outside Switzerland, the European Union, or the European Economic Area, or made accessible from those countries.

Such a transfer will take place only in compliance with the applicable legal requirements.

If a country has a legally recognized adequacy decision or a recognized adequate level of data protection, a transfer may take place on that basis.

If there is no adequate level of data protection, we will use appropriate safeguards, as necessary.

These may include, in particular:

  • Standard Contractual Clauses,
  • recognized data protection frameworks,
  • binding internal data protection policies, or
  • other guarantees provided for by law.

For appropriately certified companies in the United States, the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework, in particular, can serve as a basis for data transfers.

18. Retention Period

As a general rule, we store personal data only for as long as is necessary for the respective purpose of processing.

Data may be retained beyond this period if:

  • there are statutory retention requirements,
  • Data is necessary to assert, exercise, or defend legal claims,
  • consent permits further storage, or
  • legitimate security interests require that the data be retained for a temporary period.

Once the relevant purpose no longer applies and any existing retention obligations have expired, personal data will be deleted or anonymized.

Specific retention periods for individual services can also be found in the relevant sections of this Privacy Policy or our Cookie Policy.

19. Data Security

We take appropriate technical and organizational measures to protect personal data from:

  • Loss,
  • Manipulation,
  • unauthorized access,
  • unauthorized disclosure,
  • unintentional changes and
  • other unlawful processing

to protect.

Depending on the system used, these include, in particular:

  • encrypted data transmission,
  • Access restrictions,
  • Role and permission models,
  • secure authentication methods,
  • regular software updates,
  • Data backups, as well as
  • Measures for detecting and defending against attacks.

Security measures are reviewed and updated in line with technological developments.

20. Automated Decisions and Profiling

In the course of general use of our website, there is generally no exclusively automated decision-making that has legal effects on you or significantly affects you in a comparable manner.

To the extent that analytics or CRM systems are used, information about your interests and interactions with our website may be aggregated.

This is done exclusively within the scope of the purposes and legal bases described in each case.

21. Use of AI-powered tools in image editing

Applications and tools that provide functions based on artificial intelligence can be used to assist in the creation and maintenance of our website.

This applies in particular to the technical and creative post-processing of individual images, for example, to improve:

  • Image quality,
  • Sharpness,
  • Lighting,
  • Contrast,
  • Image detail or
  • comparable design characteristics.

The AI-powered edits we use are intended to optimize the technical and/or creative aspects of existing image content and do not significantly alter their meaning.

We do not use AI-powered image editing on this website for the purpose of misrepresenting real people, objects, places, or events in a deceptively realistic manner, or to create a false impression in the viewer regarding the authenticity or actual content.

In particular, the image optimizations described do not generate so-called “deepfakes” as defined in Article 3(60) of Regulation (EU) 2024/1689 on Artificial Intelligence (“AI Act”).

For support functions related to routine or standard processing—in which input data or its meaning is not substantially altered—the transparency provisions of the AI Act provide for appropriate distinctions.

A separate, visible “deepfake” label is therefore generally not required for images that we have only slightly optimized in terms of technical aspects or design.

Should AI-generated or AI-manipulated content be used in the future that is subject to a transparency or labeling requirement under Article 50 of the AI Act or other applicable laws, we will provide the necessary disclosures accordingly.

To the extent that personal data is processed in connection with the use of AI tools, this is done exclusively in compliance with the applicable data protection regulations.

22. Rights of Data Subjects

Depending on the applicable data protection laws, you have the following rights in particular:

Information

You may request information regarding whether we process personal data about you and, if so, what data we process.

Correction

You may request the correction of inaccurate personal data and the completion of incomplete personal data.

Deletion

Subject to the legal requirements, you may request the deletion of your personal data.

Restriction of Processing

To the extent that the GDPR applies, you may, under the conditions set forth by law, request that the processing of your personal data be restricted.

Data Portability

Provided that the legal requirements are met, you may request to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, or to have it transferred to another data controller.

Withdrawal of Consent

If processing is based on your consent, you may withdraw it at any time, effective for the future.

The lawfulness of the processing carried out on the basis of consent until such consent is revoked remains unaffected.

Objection

To the extent that the GDPR applies and processing is based on Article 6(1)(f) of the GDPR, you may object to the processing for reasons arising from your particular situation.

You may object at any time to the processing of your personal data for direct marketing purposes.

Changing Your Cookie Settings

You can change or revoke your cookie and consent settings at any time via the privacy settings on our website.

23. Our Own Services

Handling of Applicant Data
We offer you the opportunity to apply for a position with us (e.g., by email, mail, or via our online application form). Below, we provide information regarding the scope, purpose, and use of your personal data collected as part of the application process. We assure you that the collection, processing, and use of your data are carried out in accordance with applicable data protection laws and all other legal provisions, and that your data will be treated with the strictest confidentiality.

Scope and Purpose of Data Collection
When you submit an application to us, we process your associated personal data (e.g., contact and communication information, application documents, notes taken during job interviews, etc.) to the extent necessary to decide whether to establish an employment relationship. The legal basis for this is Section 26 of the New Federal Data Protection Act (BDSG-neu) under German law (initiation of an employment relationship), Article 6(1)(b) of the GDPR (general contract initiation), and—if you have provided consent—Article 6(1)(a) of the GDPR. You may withdraw your consent at any time. Within our company, your personal data will be disclosed exclusively to those individuals involved in processing your application.

If the application is successful, the data submitted by you will be stored in our data processing systems on the basis of § 26 BDSG-new and Art. 6 para. 1 lit. b GDPR for the purpose of implementing the employment relationship.

Data Retention Period
If we are unable to offer you a job, you decline a job offer, or you withdraw your application, we reserve the right to retain the data you have provided based on our legitimate interests (Art. 6(1)(f) GDPR) for up to 6 months from the conclusion of the application process (rejection or withdrawal of the application). Thereafter, the data will be deleted and the physical application documents will be destroyed. This retention serves, in particular, as evidence in the event of a legal dispute. If it becomes apparent that the data will be required after the 6-month period has expired (e.g., due to an impending or pending legal dispute), the data will not be deleted until the purpose for its continued retention no longer applies.

Data may also be stored for longer if you have given your consent (Art. 6 para. 1 lit. a GDPR) or if statutory retention obligations prevent deletion.

Inclusion in the Candidate Pool
If we do not offer you a position, we may include you in our candidate pool. If you are included, all documents and information from your application will be transferred to the candidate pool so that we can contact you if suitable openings arise.

Inclusion in the applicant pool is based exclusively on your express consent (Art. 6 para. 1 lit. a GDPR). Giving consent is voluntary and is not related to the current application process. The data subject can withdraw their consent at any time. In this case, the data will be irrevocably deleted from the applicant pool, provided there are no legal grounds for retention.

The data from the applicant pool will be irrevocably deleted no later than two years after consent has been granted.

24. Exercising Your Rights

For data protection inquiries related to the website, hosting, website plugins, or technical data processing, please contact:

in-factory GmbH
Huebstrasse 35a
8317 Tagelswangen
Switzerland

Email: [email protected]

For data protection inquiries related to the German company's own business relationships, please contact:

in-factory Deutschland GmbH
Georg-Deuschle-Str. 84
D-73730 Esslingen
Germany

Email: [email protected]

To prevent the unauthorized disclosure of personal data, we may require you to provide appropriate proof of your identity.

25. Right to File a Complaint and Regulatory Authorities

If you believe that personal data is not being processed lawfully, you may contact a competent data protection supervisory authority.

The following person is specifically responsible for in-factory GmbH in Switzerland:

Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
3003 Bern
Switzerland

To the extent that the GDPR applies, you also have the right to file a complaint with a competent data protection supervisory authority in the European Union or the European Economic Area.

Regarding data processing by in-factory Deutschland GmbH, you may contact, in particular, the data protection supervisory authority in Baden-Württemberg that has jurisdiction over the company.

26. Links to Third-Party Websites and Services

Our website may contain links to websites or services provided by other providers.

By accessing such an external website, you are leaving our area of responsibility.

As a general rule, the respective operator of the external website is responsible for the subsequent processing of personal data.

Please check with the respective provider for its privacy policy.

27. Changes to This Privacy Policy

Due to technical advancements, changes to our website, changes in the service providers we use, or new legal requirements, it may be necessary to update this Privacy Policy.

The current version published on our website applies in each case.

As of August 1, 2026