Privacy Policy
1. What is this privacy policy about?
The purpose of this privacy policy is to explain to you how Finder Spot collects, processes, protects, and uses your personal data, particularly in connection with the information provided on our websites (including subdomains and mobile applications), and specifically on our comparison platform for health insurance in Switzerland. This is done in accordance with the revised Federal Act on Data Protection (nFADP).
Applicable Law:
- Federal Act on Data Protection (nFADP), in effect since September 1, 2023.
- Data Protection Ordinance (DPO).These regulate, among other things, information duties, data security, and data protection impact assessments.
2. Who is responsible for data processing?
Responsible for data processing (Data Controller):
Zhwa Zapata Morales
Müllerstrasse 31, 8004 Zurich, Switzerland
Email: privacy@finderspot.com
CHE-431.687.104
Website: zhwa.ch
3. For what purposes do we process your personal data?
We collect and process your data for the following purposes:
- Provision of services: To offer you insurance comparisons, we process your contact details and other information you provide. We may forward your requests to selected insurers or partners.
- Communication: To reply to you or contact you by email, telephone, or other channels.
- Contract administration: To fulfill our contractual obligations to our customers and other partners (e.g., insurance companies, intermediaries, IT service providers, project partners), process payments, provide support, and comply with legal requirements.
- Marketing and relationship management: We may use your contact details to send you personalized information or advertising, unless you object or withdraw your consent. We also process your personal data for relationship management and marketing purposes, especially for personalized advertising (e.g., on our website, by email, or through other channels) for our users, partners, and other interested parties.
- Research and improvement of our services: We analyze the use of our website and services to optimize them and develop new products.
- Operation of our digital services: To operate our digital services securely and reliably, we collect technical data such as IP addresses, operating system information, device settings, region, time, and type of use. We also use cookies and similar technologies.
- Risk management and corporate governance: We process data for internal planning, legal compliance, crime prevention, and strategic decisions.
- Other administrative purposes: For example, for accounting and regulatory requirements.
4. Do we perform profiling or automated decision-making?
We may perform automated analyses to identify patterns or preferences (profiling). In some cases, we also use automated decision-making. If this significantly affects you, we will inform you, and you will have the right to express your point of view.
5. What specific data do we process?
We collect and process, in particular, the following categories of personal data:
- First name, last name, address, date of birth, postal code, email address, existing health insurance, preferences for insurance selection.
- Credit data, financial information.
- Technical data such as IP address, browser type, device type, language settings, timestamps.
- Information on user behavior (e.g., pages visited, tariffs and providers viewed, use of comparison features).
- Content from web forms, registration data, and newsletter subscriptions.
Note: We do not process special categories of personal data (e.g., health data, political opinions). Such data is collected exclusively and directly by the chosen insurance company, where necessary.
6. To whom do we disclose your data?
In connection with the purposes mentioned in Section 3, we may disclose your personal data, in particular, to the following categories of recipients:
- Service providers: We work with service providers in Switzerland and abroad who process data on our behalf, under joint responsibility, or independently, e.g., IT providers, marketing service providers, banks, insurers, collection agencies, address verifiers, or consulting firms.
- Partners: Insurance companies, brokers, or other cooperation partners with whom a contractual relationship exists or whose services you actively request through our platform.
- Other third parties: This includes, for example, payment recipients designated by you, your legal representative, or authorities in the context of legal obligations or judicial proceedings. Data may also be transferred in the event of company sales or mergers.
7. Do we transfer data abroad?
In certain cases, your data may be transferred to recipients abroad. We ensure that an adequate level of data protection is guaranteed – in particular through Standard Contractual Clauses (SCCs) or other legally prescribed guarantees under the nFADP.
8. What are your rights?
Under data protection law, you have the following rights in particular:
- Right of access to your stored personal data.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"), provided there are no legal retention obligations.
- Right to restriction of processing.
- Right to object to data processing.
- Right to withdraw consent with future effect.
- Right to data portability in a common, machine-readable format.
9. Use of cookies and similar technologies
When you use our services, technical data is generated and stored in logs. We also use cookies and similar technologies (e.g., pixel tags or fingerprinting). These enable certain functions, help us evaluate user behavior, and recognize preferences. You can set your browser to block or delete cookies. For more information on cookies and managing your settings, please see our cookie notice.
10. Data processing on social networks
We maintain online presences on platforms such as Facebook, Instagram, YouTube, LinkedIn, X (formerly Twitter), and TikTok. We process data there when you interact with us (e.g., commenting, sending messages). The platform providers also conduct their own analyses and process data for their own purposes – see their privacy policies:
11. Web analysis and advertising services
- Google Tag Manager: A solution that allows us to manage so-called website tags via a single interface (and, for example, integrate Google Analytics and other Google marketing services into our online offering). The Tag Manager itself (which implements the tags) does not process any personal data of users. Regarding the processing of users' personal data, reference is made to the following information on Google services. Terms of use: https://www.google.com/intl/de/tagmanager/use-policy.html.
- Google Analytics: Based on our legitimate interests (i.e., interest in the analysis, optimization, and economic operation of our online offering), we use Google Analytics, a web analytics service provided by Google LLC ("Google"). Google uses cookies. The information generated by the cookie about the use of the online offering by users is usually transmitted to a Google server in the USA and stored there. Google is certified under the “Google claims compliance via SCCs or new DPF” agreement, thereby providing a guarantee of compliance with European data protection law. Google will use this information on our behalf to evaluate the use of our online offering by users, to compile reports on the activities within this online offering, and to provide us with other services related to the use of this online offering and the internet. Pseudonymous user profiles can be created from the processed data. We only use Google Analytics with IP anonymization activated. Users can prevent the storage of cookies by setting their browser software accordingly; they can also prevent the collection of data generated by the cookie and related to their use of the online offering by Google by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=en. Further information: https://policies.google.com/technologies/ads, https://adssettings.google.com/authenticated.
- Audience building with Google Analytics: We use Google Analytics to display advertisements within Google's advertising services only to users who have shown an interest in our online offering or who have certain characteristics (e.g., interests in certain topics) that we transmit to Google (so-called "Remarketing" or "Google Analytics Audiences").
- Google AdWords and Conversion Tracking: We use the online marketing method Google "AdWords" to place ads in the Google advertising network so that they are shown to users who are presumed to have an interest. Google uses cookies when you visit our site and collects technical and usage data (e.g., IP address, pages viewed). Further information: https://policies.google.com/technologies/ads, https://adssettings.google.com/authenticated.
- Facebook Pixel, Custom Audiences, and Facebook Conversion: Our website uses the "Facebook Pixel," a service from Meta Platforms, to analyze visitor behavior, display targeted advertising, and measure the effectiveness of our ads. Details can be found at: https://www.facebook.com/policy, https://www.facebook.com/business/help/651294705016616, https://www.facebook.com/settings?tab=ads, http://optout.networkadvertising.org/, http://www.aboutads.info/choices, http://www.youronlinechoices.com/uk/your-ad-choices/.
- Bing Ads: We use Bing Ads, an advertising program from Microsoft Corporation, to measure the performance of our online advertising. Cookies are used to track user behavior. No IP addresses are stored. Details: http://choice.microsoft.com/en-US/opt-out, https://privacy.microsoft.com/en-us/privacystatement.
- Visual Website Optimizer (VWO): We use VWO to conduct A/B tests, click analyses, and heatmaps to improve our website. Processing is pseudonymized. Further information: https://vwo.com/privacy-policy/.
12. How long do we retain your data?
We store and process your data for as long as is legally required or necessary for the respective purpose – particularly in relation to contractual obligations and the duration of the business relationship. Furthermore, your data may be processed beyond this period for legal reasons or legitimate business interests (e.g., for evidentiary purposes). Once your data is no longer needed, it will be deleted or anonymized, where possible.
13. Changes to this privacy policy
This privacy policy is not part of any contract. We reserve the right to adapt it at any time. The version published on our website is the one that applies.
Disclaimer: The valid privacy policy is the one written in the German language.