Privacy policy
PRIVACY AND COOKIE POLICY
Last updated: 25 August 2026
1. Scope and legal frameworks considered
This Privacy and Cookie Policy explains how VYN Global Distribution GmbH processes personal data when you visit www.vyn.one, place an order, use an account or licence, communicate with us, participate in VYN programmes, apply for a role, act as a sales or business partner, receive marketing, or otherwise interact with VYN and our digital services.
Where applicable, this Policy takes account in particular of the Swiss Federal Act on Data Protection (FADP/DSG), the Data Protection Ordinance (DPO/DSV), the Telecommunications Act (TCA/FMG), including rules relevant to cookies and comparable technologies, and the Federal Act against Unfair Competition (UCA/UWG); Regulation (EU) 2016/679 (GDPR), Directive 2002/58/EC on privacy and electronic communications and its national implementing laws, and Regulation (EU) 2024/1689 on artificial intelligence (AI Act), as amended from time to time, including the amendments made by Regulation (EU) 2026/1744; and, in the United Kingdom, the UK GDPR, Data Protection Act 2018, Data (Use and Access) Act 2025, and Privacy and Electronic Communications Regulations 2003 (PECR), as amended.
Where mandatory local law in another country imposes additional or different requirements, that law applies in addition. This Policy is a transparency notice. Contract-specific, consent-specific, or situation-specific notices may also apply.
2. Controller
VYN Global Distribution GmbH
Oetlingerstrasse 74
4057 Basel
Switzerland
Website: www.vyn.one
Email: hello@vyn.one
Commercial Register: Canton of Basel-Stadt, Switzerland
Commercial Register Number: CH-270.4.010.312-1
UID / VAT No.: CHE-211.980.020 VAT
Authorised representative: Catherine Meuter
VYN Global Distribution GmbH forms part of the VYN corporate structure. Where another VYN entity determines its own purposes and means for a particular processing activity, that entity may act as a separate or joint controller for that activity. Where required, this will be identified separately.
3. Privacy contact and complaints
For privacy requests, data subject rights, complaints, and cookie questions, contact hello@vyn.one. We may request reasonable information to verify your identity before disclosing personal data or acting on a rights request.
4. EU / EEA representative
Where a representative is required under Article 27 GDPR, the EU / EEA representative is:
Gerd Flach
Bornberg 19
99869 Tröchtelborn
Germany
Email: Gerd.Flach@vbflach.eu
5. UK representative
Where a representative is required under the UK GDPR, the UK representative is:
VYN SWITZERLAND LTD
Flat 21, 261 Green Lanes
London, England, N4 2UX
United Kingdom
Company number: 13951401
Director: Stefan Reto Mathys
6. People and activities covered by this Policy
This Policy applies in particular to customers, website visitors, prospects, newsletter recipients, business contacts, B2B prospects, applicants, independent sales and business partners, hosts and referrers, licence and account users, supplier contacts, and people whose professional or business information is processed from permitted indirect or public sources.
7. Categories of personal data
- Identity and contact data, such as name, address, email address, telephone number, language, country, and communication preferences.
- Account, licence, and permission data, such as user account, roles, tenant, licence status, device assignments, login, and security information.
- Order, contract, product, delivery, return, warranty, service, and transaction data.
- Payment and risk information made available to us by payment or fraud prevention providers. Full payment card data is generally processed directly by payment service providers.
- Communication data from emails, forms, chats, messages, calls, appointments, support cases, and other correspondence.
- Marketing, preference, campaign, consent, and interaction data, such as newsletter status, opens, clicks, campaign responses, product interests, and opt-out information.
- Technical and usage data, such as IP address, device, browser, operating system, timestamps, logs, session data, error, and security events.
- Cookie, consent, and similar online identifier data.
- B2B and acquisition data, such as company, role, professional contact details, publicly visible business profiles, source, topic relevance, business interests, publicly expressed need or purchase signals, and derived relevance or prioritisation indicators.
- Application, recruitment, and partner onboarding data, such as CV, qualifications, professional experience, languages, references, application communications, interview notes, and status in a selection or onboarding process.
- Partner, affiliate, referral, and sales data, such as partner number, attribution, commission or settlement information, activity, and training status and related business transactions.
- Content and metadata processed by authorised users in connected digital accounts, communication channels, or business systems.
8. Sensitive and special category personal data
We seek not to use sensitive or special category personal data for ordinary marketing, acquisition, lead scoring, or profiling. Such data is processed only where necessary for a specific permitted purpose, an appropriate legal basis exists, and additional safeguards are applied. Public sources are not intentionally searched for health data, political or religious beliefs, racial or ethnic origin, genetic or biometric data, sexual orientation, or comparable sensitive information in order to evaluate people for sales or marketing.
9. How we collect data directly
We obtain data directly from you when you place an order, create an account, use a licence, contact us, subscribe to a newsletter, book an appointment, complete a form, register a return, apply for a role, participate in a VYN programme, register as a partner, configure connected accounts, set consent or cookie preferences, or otherwise provide information to us.
10. Indirect, public, and licensed sources
We may obtain personal data from permitted indirect sources, including service providers, business partners, referrers, publicly accessible corporate websites, professional directories, publicly accessible professional social media profiles and posts, press and event sources, trade and corporate information, and licensed or authorised data sources.
We do not use a source merely because information is technically accessible. Before systematic use, we consider in particular data protection law, competition and communications law, platform terms, access restrictions, purpose limitation, data minimisation, freshness, and the reasonable expectations of the people concerned. We do not intend to circumvent technical access restrictions or use unlawful data extraction.
11. Notice where data is not obtained directly
Where we obtain personal data other than directly from you, we provide information in accordance with the applicable legal rules, including Article 14 GDPR, corresponding Swiss transparency duties, and UK data protection rules. Where an individual notice is required, it is generally provided within the legally required period and at the latest at the first communication or disclosure, unless a statutory exemption applies. A reference to this Policy may form part of that notice.
12. Digital sales, marketing, acquisition, analytics, communication, and assistance systems
VYN may use digital sales, marketing, acquisition, analytics, communication, and assistance systems. These systems may structure, search, classify, summarise, prioritise, translate, segment, and analyse information, prepare content, coordinate communications, support appointments and tasks, manage leads or opportunities, assess campaigns, and recommend next work steps.
These systems may use rule-based automation, statistical methods, and artificial intelligence. The processing involved depends on the function, user role, connected accounts, approved data sources, and the relevant business activity. Permissions, roles, logging, approvals, and technical safeguards are designed to limit access to what is required.
13. Purposes and lawful bases
We process personal data only where a lawful basis is available. Depending on the jurisdiction and activity, these bases may include performance of a contract or steps before entering into a contract, legal obligations, consent, legitimate interests, and, in the United Kingdom, recognised legitimate interests where applicable under UK legislation. When relying on a balancing test, we consider the type, source, context, expectations, effects, and safeguards involved.
14. Orders, contracts, accounts, and services
We process identity, contact, order, delivery, payment, account, and communication data to enter into and perform contracts, manage orders, payments, deliveries, returns, refunds, warranties, customer accounts, licences, appointments, services, and voluntary VYN programmes.
15. Payment security, fraud prevention, IT, and network security
We process transaction, device, log, security, and risk data for secure payment processing, fraud and abuse prevention, authentication, access control, attack detection, troubleshooting, protection of our systems, and compliance with applicable security obligations. Automated risk signals may trigger human review.
16. Customer service, logistics, returns, and legal obligations
We process the data required for customer communications, delivery, customs, returns, complaints, defects, accounting, tax, product safety, legal defence, regulatory requests, and other legal obligations.
17. Direct marketing, sales, and acquisition
We may use contact and business-related information for sales, direct marketing, B2B acquisition, customer relationship management, invitations, newsletters, product information, back-in-stock information, events, and similar commercial communications where legally permitted.
A legitimate interest in business development and direct marketing may support the selection and management of business contacts. That interest does not override channel-specific consent, opt-in, opt-out, or suppression-list rules. For email, SMS, messaging services, telephone, social-media direct messages, and comparable channels, we also comply with the applicable electronic communications and competition rules, including nationally implemented ePrivacy rules in EU / EEA countries, PECR in the United Kingdom, and the relevant Swiss UCA and TCA requirements.
Where consent is required, we use the relevant channel for marketing only after valid consent. Where a statutory customer or soft opt-in rule is available, we rely on it only within its conditions. Marketing communications include an easy means to object or unsubscribe where required. We may retain suppression information as necessary to ensure that an objection or opt-out continues to be respected.
18. Public business signals, lead discovery, scoring, and prioritisation
Permitted public or indirect business information may be used to assess business relevance, topic fit, possible needs, purchase or cooperation signals, freshness, or the suitability of a next business step. A public signal is not automatically treated as a full customer or lead record. We may initially maintain a limited signal or intent record containing source, context, timestamp, topic category, relevance, and a permitted next step.
Scoring, ranking, or prioritisation is used for work organisation and to identify potential business opportunities. It does not guarantee interest, purchase intent, or lawful contactability. Before outreach, applicable data protection, competition, communications, and platform rules are considered. Where this activity constitutes profiling under applicable data protection law, the corresponding transparency, objection, and safeguard rights apply.
19. Recruitment, applications, and selection of sales or business partners
When handling applications and selecting employees, independent sales partners, or business partners, we may process application documents, professional information, evidence of qualifications, interview content, references, and publicly available professional information. Automated tools may structure information, check completeness, prioritise, or prepare decision support.
Material decisions about hiring, rejection, termination, remuneration, or similarly significant effects are not intended to be based solely on an automated output. Where an AI or automated system is used in a legally regulated recruitment or employment context, we apply any additional requirements that apply to VYN, including high-risk AI requirements under the EU AI Act where relevant.
20. Artificial intelligence and human oversight
Our digital systems may use generative AI, classification, prioritisation, recommendation, prediction, speech and text processing, translation, summarisation, embeddings, content generation, and similar methods. Inputs, selected business data, and generated outputs may be transmitted to contractually engaged technology providers where necessary for the relevant function.
We seek to minimise personal data, use business or API data controls where available, and do not intend to make personal data relating to customers, prospects, applicants, or partners available for unrestricted public model training. Outputs from automated or AI-assisted systems can be inaccurate or incomplete and are subject to appropriate review for material business or people-related decisions.
Where the EU AI Act requires transparency information for direct interaction with an AI system or for certain synthetic content, appropriate notices or labels are provided to the extent that the relevant obligation applies to VYN and the particular use.
21. Significant automated decisions
We do not intend to subject customers, prospects, applicants, or sales and business partners to a solely automated decision producing legal or similarly significant effects unless the legal conditions and required safeguards are met.
Where such a decision is lawfully used, we provide the information and safeguards required by the applicable jurisdiction. These may include human intervention or review, an opportunity to make representations, and an opportunity to contest the decision. For Switzerland, we take particular account of Article 21 FADP; for the EU, the relevant GDPR framework; and for the United Kingdom, the automated decision-making rules as amended by the Data (Use and Access) Act 2025.
22. Connected accounts, platforms, and communication channels
Where the relevant function is offered, authorised users may connect their own or business-authorised social media, advertising, email, calendar, website, commerce, CRM, communication, and similar accounts. Access tokens, account identifiers, technical metadata, content, and communications data necessary for the requested function may be processed.
Use of connected platforms is also subject to their terms and privacy notices. Users may connect only accounts and process only data for which they have the necessary rights and lawful bases. Secrets and credentials are stored using technical safeguards and are not disclosed for unrelated purposes.
23. Analytics and product and service improvement
We may analyse usage, quality, error, performance, and interaction data to improve our website, processes, campaigns, products, and digital services. Where possible, we use aggregated or anonymised information. Personal-data analytics is carried out on an appropriate lawful basis and subject to applicable consent and objection rights.
24. Recipients and processors
Where necessary and legally permitted, personal data may be disclosed in particular to the following categories of recipients:
- Shop, hosting, cloud, infrastructure, security, backup, and monitoring providers.
- Payment, fraud prevention, logistics, fulfilment, shipping, and customs providers.
- CRM, email, calendar, communication, customer service, and consent-management providers.
- Marketing, advertising, social media, analytics, affiliate, and campaign providers.
- AI, speech, search, translation, content, media, and other technology providers.
- Lawyers, tax advisers, auditors, insurers, and other professional advisers.
- VYN entities and authorised business partners where required for the relevant purpose.
- Authorities, courts, and supervisory bodies where a legal obligation or permitted legal ground applies.
Where recipients act as processors, they are subject to appropriate contractual and organisational requirements. Where a provider acts as an independent or joint controller, its privacy information also applies.
25. International transfers
Personal data may be processed in Switzerland, the EEA, the United Kingdom, the United States, and other countries in which authorised providers or recipients operate. Where required, we use adequacy decisions or recognitions, recognised standard contractual clauses, Swiss-recognised contractual safeguards, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another legally permitted transfer mechanism and supplementary safeguards.
26. Retention
We retain personal data only for as long as required for the relevant purpose, legal obligations, limitation periods, security, fraud prevention, or legal defence. Relevant criteria include the type of data, relationship, freshness, purpose, consent or objection, statutory retention duties, and risk.
- Accounting, invoice, and business records are generally retained for up to ten years where Swiss retention requirements apply.
- Account, licence, and partner data is retained for the duration of the relationship and afterwards where necessary for settlement, evidence, suppression, disputes, and legal duties.
- Application and selection records are retained for the duration of the process and for a limited period afterwards where necessary for evidence or legal claims. Longer talent-pool use requires an appropriate lawful basis.
- Prospect, lead, and public-signal information is reviewed for relevance and freshness and deleted or anonymised when no longer required for a permitted business purpose or where an effective objection prevents continued use.
- Marketing data is retained until consent is withdrawn, an objection is made, or the purpose ends; suppression information may be retained longer to respect the objection.
- Technical and security logs are retained only for the operationally or legally required period, and may be kept longer where an incident requires it.
27. Rights under Swiss data protection law
Where the Swiss FADP applies, you may in particular have rights to information and access, rectification, disclosure or portability in the cases provided by law, deletion or cessation of unlawful processing, and rights relating to automated individual decisions. Statutory limitations and exceptions remain reserved.
28. Rights under the GDPR
Where the GDPR applies, you may in particular have rights of access, rectification, erasure, restriction, data portability, objection, withdrawal of consent, and rights relating to automated decisions and profiling. In particular, you have the right to object to direct marketing at any time. You may also lodge a complaint with a competent data protection supervisory authority.
29. Rights in the United Kingdom
Where UK data protection law applies, you may in particular have rights of access, rectification, erasure, restriction, data portability, objection, withdrawal of consent, and safeguards relating to automated decisions. Under the Data (Use and Access) Act 2025 framework, significant automated decisions are subject to applicable information, representation, intervention, and contest safeguards where the statutory conditions are met. Complaints may be made to the Information Commissioner’s Office.
30. Exercising rights and privacy complaints
Send requests to hello@vyn.one. We process requests within the applicable statutory time limits and may reasonably verify identity. Where the UK rules on complaints to controllers apply, we facilitate submission of a privacy complaint, acknowledge it within the statutory period, and deal with it without undue delay. If we cannot fully comply with a request, we explain why where legally required.
31. Cookies and similar technologies
We use cookies and similar technologies, which may include pixels, tags, local storage, SDKs, device identifiers, and tracking links depending on configuration, to operate the shop and digital services, provide security, remember settings, measure use, and, where legally permitted, support marketing, personalisation, and connected content.
32. Cookie categories
- Strictly necessary technologies: cart, checkout, payment, login, security, fraud prevention, session management, load balancing, consent storage, and technical stability.
- Preference and functionality technologies: language, region, display, and functional preferences.
- Analytics and statistical technologies: use, errors, performance, navigation, campaign effectiveness, and service improvement.
- Marketing, advertising, retargeting, and profiling technologies: campaign measurement, audiences, frequency control, personalisation, and cross-platform advertising effectiveness.
- Social media and embedded-content technologies: embedded video, maps, reviews, social features, and comparable third-party content.
33. Cookie rules in Switzerland, the EU / EEA, and the United Kingdom
Switzerland: We provide information about cookies and comparable technologies and make available the control or refusal mechanisms required by applicable law. Where the related processing of personal data requires additional consent, we obtain it.
EU / EEA: Information is generally stored on or accessed from terminal equipment only with prior consent unless a statutory exemption applies, in particular for strictly necessary operations. Consent must meet the applicable GDPR standard.
United Kingdom: We apply PECR as amended by the Data (Use and Access) Act 2025. In addition to strictly necessary purposes, certain statutorily defined statistical or functionality purposes may be permitted without consent where the statutory conditions are met. Where no exemption applies, we obtain the required consent and provide the required information and controls.
34. Cookie consent and preferences
Through the cookie banner or consent-management tool, where offered and legally required, you can accept, reject, or later change categories. Consent-requiring non-essential categories are not preselected. Withdrawal operates for the future and is as easy as giving consent. Browser and device settings may provide additional controls.
35. Analytics, advertising, and retargeting technologies
Analytics and marketing technologies may process page views, clicks, campaign attribution, device, browser, approximate region, interactions, and comparable online signals. Marketing and retargeting technologies may link information across websites, platforms, devices, or sessions. We activate them only on a basis permitted under the applicable jurisdiction.
36. Third parties, embedded content, and current cookie list
Third parties may act as processors, joint controllers, or independent controllers depending on their role. The actual cookies, providers, purposes, categories, and retention periods may change with technical configuration. The current list is made available through the cookie banner, consent-management tool, or a cookie overview on the website.
37. Data security, data protection by design, and incidents
We use risk-based technical and organisational measures, including role and access controls, authentication, encryption or protected transmission, secret and token management, logging, backup and recovery procedures, patch and vulnerability management, controlled releases, tenant and permission separation, and security-incident response procedures.
Where a personal data breach occurs, we comply with applicable assessment, documentation, authority-notification, and data-subject-notification obligations.
38. Data protection impact assessments and elevated risk
Where processing is likely to result in a high risk to personality, fundamental rights, or freedoms, we carry out the risk review or data protection impact assessment required by applicable law. This may be relevant in particular to extensive profiling, sensitive data, certain recruitment or employment systems, or other intrusive automated processing.
39. Children
Our offerings are generally directed to adults and persons able to enter into business transactions. We do not knowingly collect children’s personal data for sales, marketing, acquisition, or profiling. If an online service is likely to be used by children, we take account of the additional requirements that apply, including under UK data protection law and other applicable child-protection and privacy rules.
40. Changes, supervisory authorities, and contact
We update this Policy where laws, business processes, digital functions, data sources, providers, international transfers, or cookie configurations materially change. The current version is published on www.vyn.one. Where required, we provide additional notice of material changes.
In Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC/EDÖB). In the EU / EEA, you may contact the competent data protection supervisory authority. In the United Kingdom, you may contact the Information Commissioner’s Office (ICO).
Privacy contact:
VYN Global Distribution GmbH
Oetlingerstrasse 74
4057 Basel
Switzerland
Email: hello@vyn.one
