Privacy policy
Translation of the German version (version 1.2 of 2 October 2026). The German version is authoritative. Deutsch
Privacy notice pursuant to Art. 13/14 GDPR and Art. 19 to 21 of the Swiss revFADP
1. Controller
The controller responsible for processing your personal data within the meaning of Art. 4(7) GDPR and Art. 5(j) revFADP is:
| Company | Rheinvalor Advisory GmbH |
|---|---|
| Address | CH-8600 Dübendorf, Switzerland |
| daniel.meran@rheinvalor.com | |
| Data protection contact | Daniel Meran, Managing Partner |
Rheinvalor has not formally appointed a data protection officer, as the statutory thresholds (Art. 37 GDPR, Art. 10 revFADP) are not met. Data protection is the responsibility of management, held by the Managing Partner and supported by external legal advisers where necessary.
2. Scope
This privacy notice applies to all processing of personal data by Rheinvalor in connection with the websites rheinvalor.com, procurevalor.com (including all sub-pages), spendvalor.com and marginvalor.com, the initiation and performance of consulting mandates, business correspondence, marketing and outreach activities, internal operating processes and the operation of the software products of the ProcureValor suite (software as a service).
3. Categories of personal data processed
- Master data (name, title, role, company, business contact details)
- Communication data (e-mails, LinkedIn messages, meeting notes)
- Contract and billing data (orders, invoices, payment data)
- Project-related data provided to us in the course of a mandate (e.g. supplier information, the client's procurement data)
- Website and log data (IP address, user agent, time stamp, only as far as technically necessary)
4. Purposes and legal bases
| Purpose | Legal basis GDPR | Legal basis revFADP |
|---|---|---|
| Initiation and performance of consulting mandates | Art. 6(1)(b) | Art. 31(2)(a) |
| Business development / outreach / direct approach | Art. 6(1)(f) (legitimate interest) | Art. 31(1) in conjunction with Art. 6 (proportionality) |
| Invoicing, accounting, audit | Art. 6(1)(c) (legal obligation) | Art. 31(1) in conjunction with Art. 958f CO (10 years) |
| Communication and correspondence | Art. 6(1)(b) / (f) | Art. 31(1) |
| Marketing / newsletter (where applicable) | Art. 6(1)(a) (consent) | Art. 31(1) in conjunction with Art. 3(1)(o) UCA |
| IT security, log analysis | Art. 6(1)(f) | Art. 31(1) in conjunction with Art. 8 (data security) |
5. Recipients and processors
Rheinvalor only discloses personal data where this is necessary to provide its services or required by law. Typical categories of recipients:
- IT service providers and SaaS providers (e-mail, storage, video conferencing, AI tools), on the basis of data processing agreements pursuant to Art. 28 GDPR / Art. 9 revFADP
- Tax advisers, auditors, legal advisers, where required by law or contract
- Banks and payment service providers, for invoicing
- Authorities, only where legally required
An up-to-date list of sub-processors is provided to clients on request and forms part of the data processing agreements.
Software products (ProcureValor suite): within the products, Rheinvalor processes customer data as a processor on the customer's instructions. Operation and data storage take place in data centres in Switzerland (Infomaniak). For AI functions, only providers processing data in Switzerland are used (Infomaniak AI Services; Safe Swiss Cloud as a fallback), contractually without training on customer data and without permanent storage of inputs (Rheinvalor AI policy v1.1, section 13).
6. Transfers to third countries
Switzerland benefits from an adequacy decision of the European Commission; transfers from Rheinvalor to the EEA and vice versa are therefore permitted. For transfers to third countries without an adequate level of data protection (in particular the USA), we rely on the EU standard contractual clauses (Implementing Decision 2021/914), including the Swiss addendum of the FDPIC, supported by technical and organisational measures (encryption, access control, pseudonymisation).
For every regular data transfer to third countries, Rheinvalor carries out a documented TIA and reviews it at least once a year.
7. Retention periods
- Contract data: duration of the business relationship plus 10 years (Art. 958f CO / HGB)
- Invoicing and accounting data: 10 years
- Prospect and outreach data: no more than 24 months without interaction
- Log data: 90 days, then deletion or anonymisation
- Applications: 6 months after the end of the process
8. Your rights as a data subject
Regardless of the applicable law, you have the right to:
- access (Art. 15 GDPR / Art. 25 revFADP)
- rectification (Art. 16 GDPR / Art. 32 revFADP)
- erasure (Art. 17 GDPR / Art. 32 revFADP)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR / Art. 28 revFADP)
- object to processing (Art. 21 GDPR / Art. 30 revFADP)
- withdraw consent at any time with effect for the future
Please send requests to daniel.meran@rheinvalor.com. We respond within 30 days (extendable once by a further 60 days for complex requests, Art. 12(3) GDPR).
9. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular:
- Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern
- The EU supervisory authority responsible for your place of residence or work
10. Automated decisions and AI
Rheinvalor does not take decisions based solely on automated processing within the meaning of Art. 22 GDPR / Art. 21 revFADP. AI-supported tools are used only to support work; all results with an effect on clients are reviewed and approved by a person (see Rheinvalor AI policy). In the software products, AI extracts content from business documents (e.g. contracts and invoices); amounts are calculated by program code, and results are confirmed by a person before they are used.
11. Changes to this notice
Rheinvalor reviews this privacy notice at least once a year and updates it where necessary. The current version is available at rheinvalor.com.
This version 1.2 came into force on 2 October 2026 (version 1.1: 1 October 2026, software products, sections 2, 5 and 10; version 1.0: 23 April 2026; change in 1.2: section 2, all websites). Previous versions are archived in the internal policy repository.