Controller

The controller responsible for the processing of personal data in connection with this website is:

Faserplast Composites AG

Industrie Sonnmatt 6–8

CH-9532 Rickenbach TG

Switzerland

For questions about data protection or to exercise your rights, you can contact us at any time using the contact details provided above.

General Information on Data Processing

Faserplast Composites AG, domiciled in Switzerland (hereinafter “we” or “us”), processes personal data in accordance with the revised Swiss Federal Act on Data Protection (FADP) and, where applicable, the General Data Protection Regulation of the European Union (GDPR).

This privacy policy explains which personal data we process in connection with this website, for which purposes, on which basis the processing takes place, and which rights data subjects have.

The GDPR may apply in particular where our services are specifically directed at persons in the European Union or where personal data of persons in the EU is processed and the requirements for the territorial scope of the GDPR are met.

Categories of Data Processed

Depending on how you use this website and our services, the following categories of personal data may be processed in particular:

  • Usage and technical data: IP address, date and time of access, browser type and version, operating system, referrer URL, pages visited, and technical information about the use of the website.
  • Communication data: name, email address, telephone number, and the content of messages you send us via contact or inquiry forms.
  • Contract and business data: information required in connection with an inquiry, a contract, an order, or another business relationship.
  • Applicant data: information and documents you submit to us as part of a job application, in particular CV, references, qualifications, and contact details.
  • Consent and preference data: information about consents granted or withdrawn as well as settings relating to cookies and similar technologies.

We only process personal data that is necessary for the respective purposes.

Purposes of Processing

We process personal data in particular for the following purposes:

  • to ensure the technical operation and security of our website;
  • to handle and respond to inquiries;
  • to communicate with prospects and customers;
  • to prepare, perform, and administer contracts;
  • to conduct application procedures;
  • to comply with legal and regulatory obligations;
  • to prevent and detect misuse, spam, and attacks;
  • to improve and further develop our website and services;
  • where permitted, to safeguard our legitimate interests.

Legal Bases

Where the GDPR applies, personal data is processed in particular on the following legal bases:

  • Art. 6(1)(a) GDPR: processing based on consent you have given;
  • Art. 6(1)(b) GDPR: processing necessary for the performance of a contract or for pre-contractual measures;
  • Art. 6(1)(c) GDPR: processing necessary for compliance with a legal obligation;
  • Art. 6(1)(f) GDPR: processing necessary to safeguard our legitimate interests, unless overridden by the interests or fundamental rights and freedoms of the data subject.

Where the Swiss Federal Act on Data Protection applies, personal data is processed in accordance with the requirements and principles of the FADP.

Recipients of the Data

Personal data is generally only disclosed to third parties where this is necessary for the purposes described above, where a legal obligation exists, or where consent has been given.

Possible recipients include in particular IT, hosting, security, communication, and other technical service providers that may process personal data on our behalf.

Where such service providers act as processors within the meaning of the FADP or the GDPR, appropriate contractual and organizational measures are taken to ensure adequate protection of personal data.

Recipients may also include affiliated companies of our corporate group, in particular Faser-Plast Poland Sp. z o.o. (Słupsk, Poland) and Faserplast Composites US Inc. (Centerville, Utah, USA). Data is shared within the corporate group where this is necessary for handling an inquiry (for example, where a specific location is responsible for your request), for conducting an application procedure, for preparing or performing a contract, or for internal administrative purposes.

Where the GDPR applies, intra-group sharing is based in particular on Art. 6(1)(b) GDPR or on our legitimate interest in efficient internal organization and communication within the corporate group (Art. 6(1)(f) GDPR). Where data is shared with Faserplast Composites US Inc. in the USA, we observe the requirements for data transfers to third countries (see section “Transfer of Data to Third Countries”).

Transfer of Data to Third Countries

Personal data may be transferred to or processed by recipients in countries outside Switzerland or the European Economic Area. This applies in particular to the USA, for example where data is shared with our group company Faserplast Composites US Inc. or with service providers based in the USA.

Where the GDPR applies, transfers to third countries are carried out in accordance with the requirements of Art. 44 et seq. GDPR. Depending on the recipient and the destination country, a transfer may be based in particular on an adequacy decision of the European Commission, on appropriate safeguards pursuant to Art. 46 GDPR (e.g., standard contractual clauses), or on a statutory exception.

Where the Swiss Federal Act on Data Protection applies, we observe the requirements for cross-border data transfers pursuant to Art. 16 FADP.

For transfers to countries without an adequate level of data protection, an increased risk may exist, in particular with regard to access by authorities of the respective country.

Retention Period

Personal data is only stored for as long as necessary to fulfill the respective purposes.

In addition, personal data may be stored where statutory retention or documentation obligations exist or where the data is required for the establishment, exercise, or defense of legal claims.

Once the respective purpose no longer applies and no statutory or other legitimate grounds for further storage exist, the data is deleted or anonymized.

Rights of Data Subjects

Under the applicable data protection law, data subjects have in particular the following rights:

  • the right to information about the personal data processed;
  • the right to rectification of inaccurate or completion of incomplete personal data;
  • the right to erasure of personal data, where the legal requirements are met;
  • the right to restriction of processing, where the legal requirements are met;
  • the right to data portability, where the legal requirements are met;
  • the right to object to certain processing operations, in particular processing based on legitimate interests;
  • the right to withdraw consent at any time with effect for the future.

The lawfulness of processing carried out on the basis of consent before its withdrawal remains unaffected.

To exercise your rights, you can contact us at any time using the contact details provided above.

Right to Lodge a Complaint

Where the GDPR applies, you have the right to lodge a complaint about the processing of personal data with a data protection supervisory authority in the EU, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement.

In Switzerland, the supervisory authority for data protection is the Federal Data Protection and Information Commissioner (FDPIC); data subjects may contact the FDPIC with data protection concerns.

www.edoeb.admin.ch

Obligation to Provide Personal Data

There is generally no statutory obligation to provide personal data, unless a specific legal obligation exists in an individual case.

However, certain personal data may be required for us to handle an inquiry, prepare or perform a contract, or provide certain functions of our website.

If required data is not provided, it may not be possible to use certain functions or to handle an inquiry.

Cookies and Similar Technologies

Our website uses cookies and similar technologies. These are small files or technical information that can be stored on or read from your device.

We generally distinguish between technically necessary technologies and optional technologies.

Technically necessary cookies and technologies are used where they are required for the operation, security, and basic functions of the website.

Optional cookies and technologies are only used, where legally required, after you have given your consent.

You can adjust your cookie settings at any time via the consent management tool Borlabs Cookie used by us (see section “Borlabs Cookie”) or withdraw consent you have already given with effect for the future.

In addition, you can delete or block cookies via your browser settings. Disabling certain cookies may mean that individual functions of the website are not available or only available to a limited extent.

Borlabs Cookie

Our website uses the consent management tool Borlabs Cookie, a WordPress plugin that supports us in complying with the applicable data protection provisions (FADP, GDPR, and the relevant rules on the use of cookies). Borlabs Cookie enables us to obtain and manage our visitors’ consent to the use of cookies.

Borlabs Cookie displays a cookie box that allows you to individually adjust your preferences for different cookie categories (e.g., necessary cookies, marketing cookies, analytics cookies). The corresponding cookies are only activated and the associated scripts only loaded after your express consent.

What data does Borlabs Cookie process?

  • No personal data is transmitted to the provider Borlabs.
  • The “borlabs-cookie” cookie stores technical information such as duration, version, domain, path, and your consent preferences, as well as a randomly generated user ID (UID).
  • This data is used exclusively to manage your cookie settings on this website and is not passed on to third parties.

The use of Borlabs Cookie is technically necessary in order to obtain, manage, and document your consents. Where the GDPR applies, the processing is based on Art. 6(1)(c) and (f) GDPR (compliance with legal obligations regarding consent management and our legitimate interest in operating the website in a legally compliant manner). Where cookies are set for analytics or marketing purposes, this is done on the basis of your consent pursuant to Art. 6(1)(a) GDPR.

Further information is available on the website of the provider Borlabs GmbH:
https://borlabs.io/privacy-policy/

Contact & Inquiry Forms

If you contact us via a form on this website, we process the data you enter, in particular your name, email address, telephone number, and the content of your message.

The processing is carried out for the purpose of handling and responding to your inquiry and, where applicable, for pre-contractual measures or the preparation of a contract.

If your inquiry concerns a specific location of our corporate group, it may be forwarded for handling to the group company responsible (see section “Recipients of the Data”).

Where the GDPR applies, the processing is based, depending on the specific context, on Art. 6(1)(b) or (f) GDPR. Our legitimate interest lies in particular in handling inquiries, communicating with prospects and customers, and managing our business relationships.

Where consent is required, the processing is based on Art. 6(1)(a) GDPR.

The data transmitted is only stored for as long as necessary to handle the inquiry or as required by statutory retention obligations.

Job Applications

If you apply to us, for example by email or via the contact options listed on our career pages, we process the applicant data you submit, in particular your CV, references, proof of qualifications, contact details, and the content of your application letter.

The processing is carried out for the purpose of conducting the application procedure and deciding on the establishment of an employment relationship.

If your application relates to a position at one of our group companies, Faser-Plast Poland Sp. z o.o. (Słupsk, Poland) or Faserplast Composites US Inc. (Centerville, Utah, USA), we forward your application to the relevant company. That company conducts the local application procedure and is responsible for the further processing of your applicant data.

Where the GDPR applies, the processing is based on Art. 6(1)(b) GDPR (pre-contractual measures with a view to establishing an employment relationship) and, where applicable, on national provisions on employee data protection. If we wish to retain your applicant data beyond the specific application procedure (e.g., for future vacancies), this is done only on the basis of your consent pursuant to Art. 6(1)(a) GDPR.

Applicant data is generally deleted within six months of the conclusion of the application procedure, unless you have consented to longer storage, statutory retention obligations exist, or the data is required for the establishment, exercise, or defense of legal claims. If an employment relationship is established, the necessary data is transferred to the personnel file.

WordPress

Our website uses the content management system WordPress.

As part of the technical operation, personal data may be processed, in particular technical access data and data you submit via forms or other functions of the website.

The specific processing depends on the WordPress functions, plugins, and technical components used on this website.

Web Hosting and Own Infrastructure

Our website is operated on the infrastructure of visions.ch gmbh, which acts as a technical service provider and processor for us.

No additional external hosting provider is used for the actual operation of the website. The technical access data and server log data generated during operation are processed on this infrastructure.

The processing serves in particular the technical provision, stability, and security of the website as well as the detection and prevention of attacks and misuse.

Server Log Files

Each time our website is accessed, technical access data may be automatically collected and stored in server log files.

This may include in particular the IP address, date and time of access, requested file, browser type and version, operating system, referrer URL, and other technical information.

The processing serves in particular the technical provision and security of our website as well as the detection and prevention of attacks and misuse.

Where the GDPR applies, the processing is generally based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable, and functional operation of our website.

Content Delivery Network (CDN)

For the faster and more secure delivery of our website content, such as images, fonts, scripts, and stylesheets, we use the content delivery network (CDN) of BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia (“bunny.net”).

A CDN is a network of regionally distributed servers that cache website content and deliver it to visitors from a geographically suitable region. This can reduce loading times and improve the availability and resilience of the website.

When content is accessed via the CDN, technical access data, in particular the IP address, date and time of access, requested file, browser type, operating system, and referrer URL, may be transmitted to and processed on bunny.net servers.

The processing serves in particular the technical delivery of website content, operational security, and the detection and prevention of attacks.

Where the GDPR applies, the processing is generally based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the fast, reliable, and secure provision of our website.

Cloudflare Turnstile

This website uses Cloudflare Turnstile, a service provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (“Cloudflare”).

Cloudflare Turnstile is used to detect and prevent automated misuse, spam, and so-called bots. For this purpose, the service may analyze various technical information about the device and browser used.

Depending on the device and technical configuration, the IP address, browser and device information, and other technical information may be processed.

On devices running current Apple operating systems, verification may take place via so-called Private Access Tokens. On other devices, personal data may be transmitted to Cloudflare and processed in the USA.

Where the GDPR applies, the processing is generally based on Art. 6(1)(f) GDPR. Our legitimate interest lies in detecting and preventing misuse, spam, and automated attacks and in the secure operation of our website.

Processors and Service Providers

Where external service providers process personal data on our behalf, we select them carefully and, where legally required, take appropriate contractual and organizational measures to protect personal data.

The respective service providers generally only have access to the data required to perform the respective service.

Data Security

We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration, or disclosure.

The security measures are regularly reviewed and, where necessary, adapted, taking into account the current state of the art, the nature of the data processed, and the associated risks.

Changes to This Privacy Policy

We may amend this privacy policy at any time, in particular if our data processing operations, the technologies used, or the legal requirements change.

The version published on this website applies. The date of the last update is indicated at the end of this privacy policy.

Last Updated

Last updated: August 2026