Privacy policy

This policy was last updated at 10th of March 2020

Scope

This privacy policy stipulates how abstract ltd, Bruderholzstrasse 32, 4053 Basel, Switzerland (hereinafter "abstract" or "we") processes personal data of its webusers and customers ("you") who provide personal data on its website and/or mobile applications (“website”), whether these personal data are provided by the data subject or by a third party, and whether personal data are transmitted to abstract via the website or via other means.

Contact

You can contact us as follows: 

abstract ltd, Bruderholzstrasse 32, 4053 Basel

E-mail: info@abstract.build

You can contact our data privacy officer as follows:

E-mail: privacy@abstract.build

General 

abstract‘s business scope is the provision of software as a service platform for building professionals of the worldwide AEC industry for cost, energy and functional simulations. On our website we offer information about our business, our products and services, an online shop as well as feedback, forum and blogging opportunities.

We adhere to data protection law. All personal data collected during registration on, or during use of, our website, which are protected either by the Swiss Federal Act on Data Protection (hereinafter "FADP") or the European General Data Protection Regulation (hereinafter "GDPR"), will be used exclusively for fulfilling our services to you; unless, in particular pursuant to this privacy policy, you have consented to further use of your personal data or the applicable law permits such further use. Our employees are obliged to treat personal data confidentiality.

As we process most personal data electronically, we have taken appropriate IT organisational and technical measures (e.g., IT security) to ensure that your personal data is protected. We also regularly educate our employees in data protection and information security.

What Personal Data is Collected for What Purpose

We may collect your master data (name, address, e-mail, etc.), personal data about the services obtained, payment transaction data, online preferences, and your feedback. 

We use your personal data to communicate with you and third parties; for evaluating, concluding and performing our transactions with you; for billing purposes; or for market research and marketing, such as contacting the customer by postal mail or e-mail. We might also add industry information and interests to your master data in our database.

Input fields on the website that are absolutely necessary for the provision of our services are marked accordingly during registration. The disclosure of personal data in non-marked input fields on the website is voluntary. You can inform us at any time that you no longer wish us to process your personal data you provided voluntarily (cf. section 12, Your Rights). 

We may collect personal data about your financial standing in order to protect ourselves against payment defaults.

Furthermore, we collect your surfing and usage data when you access our website. This data includes, for example, information about which browser and browser version you are using, when you accessed our website, which operating system you use, from which website (link) you accessed our website, which elements of the website you use, and how you use these elements. These personal data are stored together with the IP address of the device you are using to access our website. They serve to correctly display and optimise our website, to protect it against attacks or other infringements, and to personalise your user experience. We do not draw any conclusions about the data subject from these surfing and usage data. We only evaluate personal data anonymously, unless they are required to clarify infringements.

Retention Period

We only process personal data until the purpose, for which it was collected, is fulfilled, or as required by law.

If you have opened an account with us, we will store the master data you provided for an unlimited period of time. However, you can request the deletion of your account at any time (cf. section 12, Your Rights). We will delete your master data, unless we are required otherwise by applicable law.

If you placed an order without opening an account, your master data will be deleted after the expiry of the services or warranty period (as applicable), unless we are required otherwise by applicable law. This deletion can take place immediately or in the context of periodically executed deletion runs.

To refuse further business contact with a data subject due to misuse, payment default, or other legitimate reasons, we may store personal data for five years, or ten years in case of recurrence. 

Processing by Third Parties and Abroad 

Within the purpose agreed herein, we may have personal data processed by our group entities or third parties. Such third parties are marketing and market research companies, companies that operate our information technology (outsourcing partners), financial service providers, debt collection companies, or attorneys and government bodies. If we commission group companies or third parties with the processing of personal data, the third party will be carefully selected and must take appropriate security measures to guarantee the confidentiality and security of your personal data.  

We or the third parties may process personal data abroad, i.e. in European or non-European countries. We represent that the third parties will only use personal data according to the law and exclusively in the interest of abstract. These necessary contractual guarantees provided by the third parties are based on the standards of the European Commission (also recognised in Switzerland). You have the right to inspect the guarantees in these contracts (or parts thereof).

We have engaged the following third parties as sub-processors:

  • Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA;
  • YouTube LLC, 901 Cherry Avenue, San Bruno, CA 94066, USA;
  • HubSpot, Inc., 25 First Street, 2nd Floor, Cambridge, MA 02141 USA;
  • Adobe Systems Incorporated, 345 Park Avenue, San Jose, CA 95110-2704, USA;
  • Amazon Web Services (AWS), Amazon Web Services, Inc., 410 Terry Avenue North, Seattle WA 98109, USA;
  • DocuSign UK Limited, 9 Appold St, London EC2A 2AP, UK;
  • Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Irland;
  • Squarespace, Inc.225 Varick Street, 12th Floor,New York, NY 10014, USA;
  • The Rocket Science Group, LLC 675 Ponce de Leon Ave NE Suite 5000. Atlanta, GA 30308 USA
  • Softr Platforms GmbH, Lohmühlenstrasse 65, 12435 Berlin Germany
  • MailerLite Limited, Ground Floor, 71 Lower Baggot Street, Dublin 2, D02 P593, Ireland
  • NetHunt Inc., 651 N Broad St, Suite 206 Middletown, DE 19709, USA
  • Formagrid Inc, San Fransisco, 799 Market Street, 8th Floor, San Fransico, CA 94103

Analytical services

We use third-party services to analyse surfing behaviour. We also integrate content of third party websites. 

We measure and evaluate the use of the website with analytical tools. 

Personal data processed by analytical services are transmitted anonymously to servers of the commissioned third parties abroad, including the USA.  

Inclusion of Third Party Elements on Our Web Site

Our website includes content from various third party providers, such as, for instance, videos from video platforms, such as, YouTube, or social media button from platforms such as Facebook or Twitter. This content enables our visitors to enjoy content from those platforms on our website or simply to share our content on the relevant social media networks. 

When you browse our website, if such content is displayed as part of the website, a connection to the servers of the third party provider is automatically established. Personal data about your visit to our website, in particular your IP address, will be transmitted to this third party provider. Therefore, if you have signed in to that third party’s account at the time you visit of your website (for example, with a Facebook or Google account), that third party may detect that you visited our website. You authorise us to share this information with the third party provider that hosts your account.

Please note that the information regarding the purpose and scope of data processing by such third parties, as well as your rights and setting options, is provided by such third parties.

Cookies and Pixel Tags

We use cookies and tracking pixel on our website. 

Cookies are data packets sent from the webserver of our website to your browser. They are stored on your computer and can be retrieved by the webserver at a later visit. Cookies store information about the online preferences of visitors to the website and enable us to improve the visitor experience. 

Session cookies are used to uniquely assign to you or your Internet browser information stored on the webserver that are necessary when accessing the website (e.g., the online shop) during a web session (e.g., so that the contents of the shopping basket are not lost). Session cookies are deleted after closing your Internet browser. 

Permanent cookies are used to save your preferences (e.g., preferred language) over several independent accesses to our website, i.e. even after closing your Internet browser or to enable automatic login. Permanent cookies are deleted according to the settings of your Internet browser (e.g., one month after your last visit). By using our website and the corresponding functions (e.g., language selection or auto login) you agree to the use of permanent cookies.

You can delete current session or existing cookies in your Internet browser at any time, and deactivate the setting of additional cookies in your browser settings. However, deactivation may affect the functionality you enjoy on our website.

Pixel tags (e.g., tracking pixel, web beacons, clear GIFS, or canvas) are small graphics that are loaded into your Internet browser when you open our website or HTML emails. Our webserver (the webserver of our hoster respectively) logs information (e.g., date and time of your web visit or your opening of the HTML e-mail) about your web access each time your Internet browser or e-mail program loads a tracking pixel. The tracking pixel also enables the transmission of browser data, such as information about the device you are using to access the website (e.g., screen resolution or IP address). 

Legal Bases of Processing

The legal justification, upon which we base our processing of personal data, is stipulated in article 13(2)(a) FADP (processing directly related to the conclusion, or the settlement, of a contract; corresponding to article 6(1)(b) GDPR; and article 13(1) FADP (consent of the data subject or obligation to process by law) corresponding to article 6(1)(a) GDPR.

We reserve the right to store the first name and surname, postal address, and e-mail address of a data subject pursuant to article 13(1) FADP (corresponding to article 6(1)(f) GDPR) if, based on misuse, non-payment or similar legitimate reasons, we refuse to conclude any future contracts with data subjects.

Furthermore, group entities may also process personal date pursuant to article 13(1) FADP (corresponding to article 6(1)(f) GDPR).

Your Rights

Upon request, we will inform the data subject about and - if so - which personal data we process about him or her (right of confirmation, right of access). 

At your request:

  • we will cease processing personal data, in part or in full (right to withdraw your consent to the processing of personal data for one or more specific purposes; right to erasure (right “to be forgotten”)). Your request to be forgotten will also be communicated to third parties to whom we have previously forwarded your personal data.
  • we will correct the relevant personal data (right to rectification);
  • we will restrict the processing of the relevant personal data (right to restriction of processing; in this case we will only store or use your personal data to protect our own legal claims or the third party rights;
  • you will receive the relevant personal data in a structured, commonly used and machine-readable format (right to data portability).

To request any of the rights described in this section, for example if you no longer wish to receive our e-mail newsletters or if you wish to delete your account, please use the appropriate function on our website, or contact our data protection officer or an employee as described in section 2 (Contact). 

If we do not comply with your request, we will inform you of the reasons for our non-compliance. For example, we may legally refuse to delete your personal data if we still need it to fulfil the purpose, for which it was originally provided (for example if we continue providing our services to you), if the processing is based on mandatory law (for example mandatory accounting regulations), or if we have a predominant interest of our own (for example in the case of a lawsuit against the data subject). 

If we assert a predominant interest in the processing of personal data, you have nevertheless the right to object to the processing; provided, however, that your individual situation compares differently to that of other data subjects (right to object). This could be the case, for example, if you are a person of public interest, or if processing increases the risk of you being harmed by third parties. 

If you disagree with our response to your request, you have the right to file a complaint with a competent supervisory authority, for example, in your country of residence or at the registered seat of abstract (right to appeal).

Severability and Changes

If any provision of this Agreement is held to be invalid, illegal or unenforceable, the validity, legality and enforceability of the remaining provisions will in no way be affected or impaired as long as the intent of the Parties can be preserved. 

Due to the further development of our website and offers or due to changed legal or official requirements, it may become necessary to change this data protection declaration. You will be informed about the changes.

Applicable Law and Place of Jurisdiction

This privacy policy and any agreements concluded based on, or in connection with, this privacy policy, as the case may be, are governed by Swiss law, unless the applicable law of another country is applies mandatorily. The place of jurisdiction is the registered seat of abstract, unless a different place of jurisdiction applies mandatorily.