Data Protection

Last updated: January 31, 2025

Introduction

At Karwita.ch, we attach paramount importance to the protection of your personal data. We take care to guarantee their security and confidentiality in complete transparency. This privacy policy explains what information we collect, how we use it and how we protect it. We process your data as part of our activities and services, in particular on our website karwita.ch. This policy also sets out your data protection rights and how you can exercise them. Depending on the services used, other legal documents may apply, such as our general conditions of sale (CGV), our conditions of use or our rules of participation. We comply with the Federal Data Protection Act (LPD) in Switzerland as well as applicable international regulations, including the General Data Protection Regulation (GDPR) of the European Union. The European Commission recognizes that Switzerland offers a level of data protection consistent with European standards.

Modalities and Legal Basis

Personal data corresponds to any information allowing the identification, directly or indirectly, of a natural person. The data subject is the person whose personal data is processed. The processing of personal data includes any action carried out on this information, regardless of the methods and tools used. This includes in particular the collection, recording, organization, conservation, modification, exploitation, communication, deletion or destruction of data. The European Economic Area (EEA) includes the countries of the European Union (EU) as well as Norway, Iceland and Liechtenstein. The General Data Protection Regulation (GDPR) defines the processing of personal data as any operation applied to this data, whatever the purpose.

Compliance with data protection regulations

We place great importance on the protection of personal data and ensure that it is processed in compliance with the laws in force in Switzerland, particularly the Federal Act on Data Protection (FADP) and its Implementing Ordinance (FODP). When the General Data Protection Regulation (GDPR) applies, the processing of information is based on specific legal grounds: Contract execution (Article 6(1)(b) GDPR): We process data when necessary to provide a service or fulfill a contractual obligation with the data subject, including pre-contractual measures. Legitimate interests (Article 6(1)(f) GDPR): Processing is carried out when essential for the proper functioning of our services, platform security, fraud prevention, or the protection of our rights, unless the interests or fundamental rights of the data subject take precedence. Compliance with a legal obligation (Article 6(1)(c) GDPR): When the law of a European Economic Area (EEA) member state requires us to collect or process certain information. Public interest (Article 6(1)(e) GDPR): When data processing is necessary for the performance of a task carried out in the public interest. Explicit consent (Article 6(1)(a) GDPR): When the data subject has expressly authorized us to use their data for a specific purpose. Vital interest protection (Article 6(1)(d) GDPR): If processing is essential to safeguard the life or physical integrity of a person.

Management and Protection of Personal Data

As part of our activity, we only collect and process personal data essential to the management and optimization of our services. This may include identification and contact information, device and browsing data, interactions with our platform, as well as transactional, contractual, location and usage details. Their retention is limited to the period necessary to achieve the objectives set or to meet legal obligations in force, after which they are either deleted or anonymized. In order to ensure efficient and secure processing, we may use external service providers or share certain data with partners when necessary. These third parties are carefully selected and required to comply with strict data protection standards.

Data Collected

We collect the following information:

  • Profile information: name, email address, phone number
  • Postal address for vehicle sales
  • Profile pictures and vehicle photos
  • Vehicle information (make, model, price, etc.)
  • Messages exchanged between sellers and buyers
  • Payment data (securely processed through Stripe)

Data Usage

Your data is used to:

  • Create and manage your user account
  • Publish your vehicle listings
  • Facilitate communication between buyers and sellers
  • Process payments and listing renewals
  • Ensure platform security
  • Improve our services

Data Protection

We protect your data through:

  • Secure storage with encryption
  • Secure HTTPS connections
  • Limited access to personal data
  • Trusted payment processing partners

Data Usage

Your data is used for the following purposes:

Essential Services

  • Managing your account and user profile
  • Publishing and managing your vehicle listings
  • Secure messaging system between buyers and sellers
  • Processing payments and listing renewals
  • Account authenticity verification

Security and Protection

  • Fraud prevention and detection
  • Moderation and reporting system
  • Sanction management (warnings, suspensions)
  • Protection against malicious activities

Service Improvement

  • Market trend analysis
  • User experience optimization
  • Personalized customer support
  • New feature development

Data Retention

We retain your data for the following periods:

  • Account data: as long as your account is active
  • Messages: 24 months after the last activity
  • Listings: 6 months after expiration
  • Payment data: 10 years (legal obligation)
  • Security logs: 12 months

Your Rights

In accordance with the FADP and GDPR, you have the following rights:

  • Access: obtain a copy of your personal data
  • Correction: rectify inaccurate information
  • Erasure: request the deletion of your data
  • Data portability: receive your data in a structured format
  • Objection: refuse the processing of your data
  • Restriction: limit the processing of your data
  • Withdrawal of consent: for processing based on consent

Contact

For any questions regarding your personal data or to exercise your rights:

  • Email: privacy@karwita.ch
  • Data Protection Officer: dpo@karwita.ch
  • Supervisory authority: Swiss Federal Data Protection and Information Commissioner (FDPIC)

Cookies and Similar Technologies

We use different types of cookies:

  • Essential cookies: authentication, security, user session
  • Functional cookies: language and display preferences
  • Analytical cookies: improving user experience
  • Performance cookies: optimizing the website

Data Sharing

We share your data only with:

  • Stripe: for secure payment processing
  • Competent authorities: in case of legal obligation
  • Moderators: for handling reports
  • No commercial sharing with third parties

International Data Transfers

Your data is primarily stored in Switzerland. Any transfer outside Switzerland or the EU is governed by appropriate safeguards (standard contractual clauses, adequacy decisions).

Protection of Minors

Our service is intended for adults only. We do not knowingly collect data from minors.

Policy Changes

We reserve the right to modify this policy. Significant changes will be notified to you via email or through our platform.