Privacy policy
Version of 3 September 2026
This website uses no tracking cookies and embeds no third-party analytics services.
In this privacy policy we, om3 Marketing GmbH (hereafter «om3», «we» or «us»), explain how we collect and process personal data. Personal data means all information relating to an identified or identifiable person. If you provide us with personal data of other people (for example family members or data of work colleagues), please make sure that those people are aware of this privacy policy, and disclose their personal data to us only where you are permitted to do so and where that personal data is accurate. This privacy policy is drawn up to meet the requirements of the EU General Data Protection Regulation («GDPR») and the Swiss Data Protection Act («revDSG»). Whether and to what extent these laws apply, however, depends on the individual case. The terms used are not gender-specific.
01Controller
The controller for the processing described here is om3 Marketing GmbH, Baslerstrasse 30, 8048 Zürich, Switzerland, unless stated otherwise in an individual case. If you have any data protection concerns, you may address them to the following contact: postal address: Baslerstrasse 30, 8048 Zürich, Switzerland; email: info@om3.ch
02Collection and processing of personal data
We primarily process personal data that you provide to us yourself — through the contact form, when booking an appointment, by email or telephone, and in the course of working together.
In addition, visiting this website generates technical data that every web server logs: a shortened IP address, the date and time of access, the page requested, and browser and operating system details. These logs serve the operation and security of the website.
When you call, personal data is additionally transmitted to us by the telephone network — your telephone number.
We do not obtain personal data from public registers, credit reference agencies or address brokers. We do not buy in address data.
03Purposes of processing and legal bases
We process personal data for the following purposes:
Initiating and performing engagements — answering enquiries, arranging appointments, delivering our services in IT project management, interim management, systems integration and e-commerce, and the associated contract administration and invoicing.
Operation and security of the website — delivering the pages, preventing misuse, analysing faults.
Audience measurement — understanding which content is used, in anonymised form (see section 04).
Compliance with legal obligations — in particular retention obligations under commercial and tax law.
The legal bases are the initiation and performance of a contractual relationship (Art. 6(1)(b) GDPR), compliance with legal obligations (lit. c) and our legitimate interest in a secure, functioning and comprehensible web presence (lit. f). In one place we rely on your consent (lit. a): the single follow-up enquiry after the SEO Health Check, see section 08. You may withdraw it at any time with effect for the future. For users in Switzerland, the revised Swiss Data Protection Act (revDSG) applies.
We do not send a newsletter and do not carry out advertising outreach on the basis of this website.
04Audience measurement with Umami
We want to know which content on this website is used. For this we use Umami — open-source analytics software that we run on our own server. There is no connection to any third-party analytics service.
Umami works without cookies and without recognition markers on your device. No profile is built about you and no identifier is stored that would make you identifiable across several visits.
The following are recorded: the page requested, the referring source, the approximate region of origin at country level, device type, operating system, browser and screen size. Your IP address is used solely to form a non-reversible hash value and is not stored.
In addition we count three events: opening the appointment booking, submitting the contact form and clicking our telephone number. No personal data arises here either.
The analysis data remains on our server and is not transferred to third parties. Retention period: 24 months. After that it is deleted automatically.
The legal basis is our legitimate interest in designing this website to suit its users (Art. 6(1)(f) GDPR).
Objection: You can switch the counting off permanently for your browser. Open the developer console and run once: localStorage.setItem('umami.disabled', 1)
04aIdentifying visiting companies with Leadinfo
We want to know which companies visit this website. For this we use Leadinfo, a service of Leadinfo B.V., Netherlands, which acts for us as a processor.
Leadinfo matches the IP address of your internet connection against publicly available company data. From this it identifies which company visited the website, together with the pages requested and the time. No link is established between an IP address and an email address, and no individual persons are identified.
On this website Leadinfo works without cookies and without recognition markers on your device. Screen recording, form tracking and Persona Insights are switched off.
The legal basis is our legitimate interest in learning which companies are interested in our services (Art. 6(1)(f) GDPR).
You may object to this identification. Through Leadinfo's central opt-out page your company will no longer be identified: leadinfo.com/en/legal/opt-out.
The data is processed on servers in Ireland.
05Typefaces
The typefaces used on this website — Schibsted Grotesk, IBM Plex Sans and IBM Plex Mono — are served from our own server. There is no connection to Google Fonts or any other font service. Your IP address is not transferred to any third party in the process.
06Appointment booking
For arranging an initial consultation we run our own booking application on our server (Cal.diy, open source). It is not a third-party service: the booking data is collected by us, stored by us and processed by us.
Two-click solution. The booking view is not loaded automatically. You first see a placeholder area with a notice. Only when you click it is the booking application loaded.
Which data you enter. For a booking we need your name, your email address and an indication of what it is about. You may optionally leave a telephone number. We use this data to prepare and hold the conversation.
Confirmation and reminder emails are sent via the mail server of Hetzner Online GmbH (Germany); see section 10.
Calendar entry. The booked appointment is entered in our business calendar. This is currently kept with Google Ireland Limited. In doing so your name, your email address and the subject of the appointment are transferred to Google. Further detail on transfers abroad is in section 11.
The legal basis is the initiation of a contractual relationship (Art. 6(1)(b) GDPR).
Cancellation and deletion. You may cancel a booked appointment at any time using the link in your confirmation email. If you additionally wish your booking data to be deleted, an informal message to us is enough.
07Contact form and spam protection
Through the contact form you transmit to us the details entered there — name, email address and your message. We use these solely to answer your enquiry and for any collaboration that may arise from it.
To protect against automated submissions we use ALTCHA. We run it on our own server — it is not a third-party service, and no data is transferred to third parties. Your browser solves a small computational task in the process; it takes a moment and requires no input from you. Your behaviour is not analysed, no cookies are set and nothing is stored on your device.
Transmission by email. Your enquiry is delivered to us as an email and passes through the mail server of Hetzner Online GmbH (Germany), where we also keep our mailbox. See section 10.
Processing and filing. Your enquiry is processed on our server in Germany and filed in our customer management system, which we likewise run ourselves there. In doing so we store your name, company, email address, telephone number and the content of your message. In addition we record in a log when an enquiry arrived, which email address it was tied to and which entry in the customer management system it corresponds to. The content of your message does not appear in this log.
Abuse prevention. We use your IP address to limit the number of enquiries per sender. It is held only briefly in memory and discarded after 25 hours at the latest. It is not stored permanently.
Your enquiry is processed by an automation system we run on the same server. It records each call together with the technical details of the connection, including your IP address in plain text. This record serves only to trace errors and is deleted automatically after fourteen days.
Retention. We keep enquiries submitted through the contact form for as long as handling them and any follow-up question requires, for no longer than 24 months. If a collaboration arises from it, the statutory retention periods apply. Processing logs on our server that record the technical course of a transmission are deleted automatically after 14 days. Contact details in our customer management system are kept for as long as a business interest exists; you may object to this at any time, without formality.
The legal basis is the initiation of a contractual relationship (Art. 6(1)(b) GDPR) together with our legitimate interest in preventing abusive submissions (lit. f).
08SEO Health Check
At om3.ch/en/seo-check we offer a free automated check of websites. If you use it, we process the following data.
What you enter. The address of the website to be checked, your name or company name, your email address and, if you wish, a telephone number. We need these details in order to produce the report and send it to you.
What is checked automatically. Our system calls up the website you have given and evaluates publicly accessible technical characteristics — loading time, page structure, encryption, links and visibility in search engines. In doing so, personal data of third parties may also be captured, in so far as it appears publicly on the website checked, for example in a legal notice. Such details enter only into the report and are not further evaluated or stored by us.
Abuse prevention. In order to prevent the service being overloaded by automated requests, we form a non-reversible hash value (SHA-256) from your IP address and store it for a limited period. Your IP address itself is not stored.
Your enquiry is processed by an automation system we run on the same server. It records each call together with the technical details of the connection, including your IP address in plain text. This record serves only to trace errors and is deleted automatically after fourteen days.
Delivery. We send the report as a PDF to the email address you have given. It is dispatched via our mail server at Hetzner Online GmbH (see section 10).
Storage in the customer system. We file your details in our customer management system. We run this ourselves on our server; there is no transfer to third parties.
A single follow-up enquiry. About a week after the report has been delivered we ask once by email whether it was helpful. You receive this message only if you expressly consented when submitting. You may withdraw your consent at any time, without formality — a short message to us is enough, and you will receive no further message. A withdrawal takes effect for the future and does not affect the lawfulness of processing carried out up to that point.
No newsletter. Beyond the single follow-up enquiry mentioned, you receive no advertising from us. Your details are not used for other purposes and are not passed on to third parties.
Legal bases. Producing and delivering the report rests on taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR). The single follow-up enquiry rests on your consent (lit. a). Abuse prevention rests on our legitimate interest in undisturbed operation (lit. f).
Retention period. We keep your details for 24 months. If a collaboration arises from it, the statutory retention periods apply. The hash value of your IP address is deleted after 30 days.
Services used. For the technical check we draw on Google's PageSpeed Insights interface. In doing so the website address you have given is transferred to Google — not your personal details. Further detail is in section 11.
09Hosting
This website runs on a server that we rent from Hetzner Online GmbH (Germany) and administer ourselves. The server location is in Germany and therefore within the European Economic Area. We also run our booking system and our customer management system on rented servers from the same provider in Germany.
A data processing agreement is in place with Hetzner. The provider has no sight of the content and processes data solely on our instructions.
When the website is called up, server logs arise containing a shortened IP address, the date and time, the page requested and browser and system details. They serve secure operation and are deleted after 14 days at the latest.
The legal basis is our legitimate interest in the secure operation of this website (Art. 6(1)(f) GDPR).
10Disclosure to third parties
We do not pass on your personal data for advertising purposes and we do not sell data.
Disclosure takes place only in so far as it is necessary for the operation of this website or the delivery of our services, to the following recipients:
| Recipient | Purpose | Registered office |
|---|---|---|
| Hetzner Online GmbH | Hosting, server operation, booking system, customer system and email delivery | Germany |
| Google Ireland Limited | Calendar entry for booked appointments; technical website check in the SEO Health Check | Ireland, parent company USA |
| DomCop OÜ (Open PageRank) | Retrieval of a public metric on a domain's inbound links in the SEO Health Check | USA |
| Leadinfo B.V. | Identifying visiting companies from the IP address | Netherlands, processing in Ireland |
| Deepgram | Speech recognition for booking by phone | United States |
| Mistral AI | Response generation for booking by phone | France |
| Speech output for booking by phone | European Union |
Beyond that, disclosure to authorities may take place in so far as we are legally obliged to make it.
In the course of a collaboration, personal data may be passed to people we call in to perform the engagement. They are contractually bound to confidentiality.
11Transfer of data abroad
Our servers are located in Germany. The website, the audience measurement and the booking application process personal data exclusively there. Booking by phone is the exception; it is described below as the fourth place.
A transfer outside the European Economic Area takes place in four places. The first: booked appointments are entered in a business calendar with Google Ireland Limited. The contracting party is the Irish company; access by the US parent company cannot be entirely ruled out under US law. The transfer rests on the European Commission's standard contractual clauses and on the EU-US Data Privacy Framework, which Google has joined. Only the name, email address and subject of booked appointments are affected.
The second takes place when you use the SEO Health Check: the website address you have given is transferred to Google's PageSpeed Insights interface. Your personal details — name, email address, telephone number — are not transferred in the process.
The third concerns the same operation: to assess a website's inbound links we retrieve a public metric from DomCop OÜ (Open PageRank, USA). Only the domain name of the website you have given is transferred. Your personal details are not transferred in the process.
The fourth: when you call our telephone number, you speak to an AI assistant. So that it can understand you, what is spoken is transmitted to Deepgram in the United States and converted into text there. This concerns your telephone number, your name, your email address if you give it, and your enquiry — everything you say during the call. No audio recording is made at any point; only the text is stored. The transfer is based on a data processing agreement with recognised safeguards for data protection.
If you do not call, do not book an appointment and do not use the SEO Health Check, no transfer to a third country takes place.
12Retention periods for personal data
We process and store your personal data for as long as is necessary to fulfil our contractual and legal obligations or otherwise to serve the purposes pursued by the processing — that is, for example, for the duration of the entire business relationship (from initiation and performance through to the termination of a contract) and beyond that in accordance with statutory retention and documentation obligations. Personal data may accordingly be retained for the period during which claims can be brought against our company, and in so far as we are otherwise legally obliged to do so or legitimate business interests require it (for example for evidential and documentation purposes). As soon as your personal data is no longer required for the purposes named above, it is as a rule and as far as possible deleted or anonymised. Markedly shorter periods apply to operational data such as system logs; they are listed individually in the following paragraph.
Analysis data from the audience measurement is deleted after 24 months. Server logs are deleted after 14 days at the latest. We keep enquiries submitted through the contact form for as long as handling them and any follow-up question requires, for no longer than 24 months. Booking data for cancelled or expired appointments is deleted after 12 months. Conversation text from booking by phone is deleted after 30 days. If a collaboration arises from an enquiry, the statutory retention periods apply.
In our processing database we delete details from the SEO Health Check after 24 months, and the hash value of the IP address used for abuse prevention after 30 days. Contact details taken from these into our customer management system are kept beyond that for as long as a business interest exists — where a collaboration has arisen, in accordance with the statutory retention periods, otherwise until you object. You may object to further retention at any time, without formality; we then delete the details.
Processing logs that record the technical course of a transmission are deleted automatically after 14 days.
13Data security
We take appropriate technical and organisational security measures to protect your personal data against unauthorised access and misuse. We take the protection of personal data into account already when developing or selecting hardware, software or procedures, through corresponding technical and organisational measures. We further ensure privacy-friendly default settings.
14Obligation to provide personal data
Within our business relationship you must provide the personal data that is necessary to enter into and conduct a business relationship and to perform the associated contractual obligations (as a rule you are under no legal obligation to provide us with data). Without this data we will as a rule not be in a position to conclude a contract with you (or with the body or person you represent) or to perform it. Nor can the website be used if certain details required to ensure data transmission (such as the IP address) are not disclosed.
15Profiling and automated decision-making
We carry out no profiling. We do not analyse your behaviour in order to assess or predict interests, preferences or economic circumstances.
The audience measurement described in section 04 works without cookies and without any personal reference; it permits no attribution to a particular person.
There is no automated decision-making that produces legal effects concerning you or similarly significantly affects you. This also applies to booking by phone: the AI assistant takes requests and records them; a person decides on your enquiry.
16Rights of the data subject
Within the data protection law applicable to you, and in so far as it so provides (as in the case of the GDPR), you have the following rights:
- the right to ask us whether, and which, data concerning you we process;
- the right to have us correct data if it is inaccurate;
- the right to request the erasure of data;
- the right to request that we release certain personal data in a common electronic format or transmit it to another controller;
- the right to withdraw consent, in so far as our processing rests on your consent;
- the right to receive, on request, further information necessary for exercising these rights;
- the right, in the case of automated individual decisions (section 15), to express your point of view and to request that the decision be reviewed by a natural person;
- the right to object at any time to the processing of your personal data where we base it on a legitimate interest.
Please note, however, that we reserve the right to invoke the restrictions provided for by law — for instance where we are obliged to retain or process certain data, have an overriding interest in doing so (in so far as we may rely on it), or need the data to pursue claims. Should any costs arise for you, we will inform you in advance. We have already given information on the possibility of withdrawing your consent in section 03. Please note that exercising these rights may conflict with contractual arrangements and may have consequences such as early termination of the contract or cost implications. In that case we will inform you beforehand, where this is not already governed by contract. Exercising such rights generally requires you to prove your identity unambiguously (for example by a copy of an identity document, where your identity is not otherwise clear or verifiable). To assert your rights you may contact us at the address given in section 01. Every data subject additionally has the right to enforce their claims in court or to lodge a complaint with the competent data protection authority. The competent data protection authority in Switzerland is the Federal Data Protection and Information Commissioner (http://www.edoeb.admin.ch).
In so far as processing rests on your consent — in the case of the single follow-up enquiry after the SEO Health Check, see section 08 — you may withdraw it at any time with effect for the future. An informal message is enough.
You have the right to lodge a complaint with a supervisory authority. In Switzerland this is the Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (Federal Data Protection and Information Commissioner, EDÖB), Feldeggweg 1, 3003 Bern. If you reside in a member state of the European Union, you may additionally approach the data protection supervisory authority there.
17Changes
We may amend this privacy policy at any time without prior notice. The version currently published on our website applies. In so far as the privacy policy forms part of an agreement with you, we will inform you of any update by email or by other suitable means.
18Booking by phone, with AI support
When you call +41 58 689 68 99, you will speak to an AI assistant. It takes appointment requests, answers questions about our services and, if you prefer, notes a callback. The assistant states at the beginning of the call that it is a machine.
In doing so we process your telephone number, your name, your email address if you give it, and your appointment request or enquiry. Your telephone number reaches us from the telephone network; you give the remaining details during the call.
The call is not recorded. To understand it, what is spoken is converted into text; we store that text so the conversation can be traced and errors found. Deepgram (speech recognition, United States), Mistral AI (response generation, France) and Google (speech output, Europe) are involved. We have data processing agreements with all three; the transfer to the United States takes place on the basis of recognised safeguards.
Appointments are stored in our booking system and your contact details in our customer system. We run both on our own servers in Germany. We delete the conversation text after thirty days.
You may at any time request information about the data stored about you, and ask for it to be corrected or deleted. Please contact info@om3.ch.