Privacy Policy (Plutoos.ch)
Last updated: 13 November 2025
1. Controller and how to contact us
1.1 Controller: Plutoos – New Neptune GmbH, Ringstrasse 1, 8603 Schwerzenbach, Switzerland.
1.2 Email: info@plutoos.ch.
1.3 On-site reception: none (customer support by email only).
1.4 Laws: We process data primarily under the Swiss Federal Act on Data Protection (FADP). Where applicable (e.g., EEA/Liechtenstein), we also apply the GDPR.
2. Scope and relation to other documents
2.1 This policy covers personal data when you browse Plutoos.ch, place orders, contact support, or use our services.
2.2 Cookie Policy: Cookies/tags (incl. analytics and reCAPTCHA) are described in our separate Cookie Policy; you can manage them via the Cookie settings link on our site.
2.3 Terms & Conditions: Commercial terms (returns/refunds etc.) are in our T&Cs; we reference them here only to explain related data processing.
3. Data we collect
3.1 Order & fulfilment data: name, billing/shipping address, ordered products, order number, tracking details, returns/warranty cases.
3.2 Communication data: your email/phone (if provided) and the content of emails/support tickets.
3.3 Account data (optional): login identifier, preferences, order history.
3.4 Payment: we do not store card/bank details. Payments are processed by PostFinance (and supported methods such as TWINT, cards, invoice, PayPal). We receive only minimal payment status info.
3.5 Returns & warranty evidence: information needed to verify eligibility (order number, product condition, photos if you provide them) and to issue refunds via the original payment method.
3.6 Technical logs & security: IP address, timestamps, requested URLs, browser/device info, error logs—used to run, secure, and debug the site.
3.7 Cookies & analytics: see the Cookie Policy (e.g., consent cookie, session/cart, Google Tag Manager, reCAPTCHA v3 as security, optional GA4 with ads features disabled).
4. Purposes and legal bases
4.1 Contract / pre-contract: order intake, payment confirmation, shipping, returns, refunds, warranty (FADP; GDPR Art. 6(1)(b), where applicable).
4.2 Legal obligations: accounting, tax, warranty documentation and retention (FADP; GDPR Art. 6(1)(c)).
4.3 Legitimate interests: IT security and fraud prevention; operating, maintaining and improving our site and core services; efficient customer service (FADP; GDPR Art. 6(1)(f)).
4.4 Consent: where required (e.g., certain analytics/marketing cookies). You can withdraw consent via Cookie settings or by contacting us.
5. What we do not do
5.1 No marketing use of your email or phone (no newsletters, no marketing calls/SMS) and no sharing with ad networks.
5.2 No sale of personal data.
5.3 No Facebook Social Plugins (if this changes, we will update the policy before activation).
5.4 No automated decision-making producing legal or similarly significant effects (no marketing profiling).
6. Who receives your data
6.1 Logistics: Swiss Post and other shipping partners (only data necessary for delivery/returns).
6.2 Payments: PostFinance and supported payment providers (e.g., TWINT, card acquirer, PayPal, invoice service) to process payments/refunds.
6.3 IT/hosting & support tools: reputable providers in Switzerland and the EU/EEA (bound by confidentiality and data processing agreements).
6.4 Analytics & security: Google Tag Manager (loader), Google reCAPTCHA v3 (security), optional Google Analytics 4 (configured without Google Signals/ads features).
6.5 Manufacturers (upon request): We are not the manufacturer. On request, we can provide manufacturer contact details so you can contact them directly for product/manufacturing claims. With your consent, we can share relevant information with the manufacturer to support such claims.
6.6 Authorities: where required by law (e.g., tax or legal requests).
7. International data transfers
7.1 Primary locations: We host and process data in Switzerland and in the EU/EEA.
7.2 Third-country transfers: Some providers (e.g., Google LLC in the U.S.) may process limited data outside Switzerland/EEA. We use recognised safeguards (e.g., Swiss-U.S. Data Privacy Framework and/or Standard Contractual Clauses) and minimise the data transferred.
8. Retention periods
8.1 Orders, invoices, refunds: typically 10 years (Swiss accounting/commerce laws).
8.2 Customer service emails/tickets: typically 24 months after last interaction, unless legal claims require longer.
8.3 Warranty/returns documentation: typically 24 months from case closure, unless statutory periods require longer.
8.4 Technical logs: typically 12 months (security/diagnostics), unless incident investigation requires longer.
8.5 Consent records (cookies): typically 6–12 months.
8.6 Analytics (if enabled): see Cookie Policy (typically 2–14 months at provider level).
9. Security measures
9.1 TLS (“https”) on all connections.
9.2 Role-based, least-privilege access; multi-factor where appropriate.
9.3 Reputable hosting in Switzerland and the EU/EEA; encrypted backups and separation of environments.
9.4 Periodic security reviews, monitoring and incident response procedures.
9.5 We do not store card data; payments are handled by certified providers (e.g., PostFinance).
10. Returns and refunds (data we use)
10.1 Return windows: 60 days for unopened products in original condition; 14 days for opened items (a fee may apply). Return shipping costs are borne by the customer. See our T&Cs.
10.2 Refund method: after inspection/acceptance, refunds are issued via the same payment method used for the order.
10.3 Data used: order identifiers, contact/address data, product/return details, refund status and—if needed—evidence you provide (e.g., photos).
11. Your rights
11.1 Under FADP: right to information/access; rectification; deletion (where no legal duty prevents it); objection in specific cases; portability where applicable.
11.2 Under GDPR (EEA/Liechtenstein): rights of access, rectification, erasure, restriction, portability, objection; withdraw consent; lodge a complaint with a supervisory authority.
11.3 How to exercise: email info@plutoos.ch with subject “Data Request”, and include your order number and the email you used. We reply without undue delay (usually within 30 days).
12. Legal bases summary
Contract; Legal obligation; Legitimate interests (security, service operation/improvement, efficient support); Consent (where required).
13. Children’s privacy
13.1 Services are for general consumers. We do not knowingly collect data from children below the minimum age defined by applicable law. If you believe a child provided data, contact info@plutoos.ch.
14. Third-party websites & external links
14.1 Our website may include links to third-party sites (e.g., manufacturer pages). When you follow such a link, you leave Plutoos.ch. The third party’s privacy policy and terms apply.
14.2 We provide these links for convenience only and are not responsible for their content or practices. We encourage you to review their privacy policies.
14.3 External links may open in a new tab/window. We may label them as external where technically supported.
15. EU/EEA representative and DPO
15.1 We are based in Switzerland. If an EU/EEA representative (GDPR Art. 27) becomes required, we will appoint one and update this policy.
15.2 A Data Protection Officer is not required for our activities at this time. We will update this policy if that changes.
16. Changes to this policy
16.1 We may update this policy. The latest version and date appear at the top. Material changes will be communicated when appropriate.
17. Contact
17.1 Plutoos – New Neptune GmbH, Ringstrasse 1, 8603 Schwerzenbach, Switzerland (no reception on site).
17.2 Email: info@plutoos.ch.