Data Protection Information (Privacy Policy)
Last updated: August 9, 2025
1. Data Controller
Lucamex SA
Headquarters: Corso San Gottardo 54/A, 6830 Chiasso
Website: lucamexsa.com
Contacts: Website contact form
2. Scope of Application
This policy applies to the processing of personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR), where applicable.
3. Personal Data Collected
3.1 Browsing data (collected automatically)
While browsing this website, the following are automatically collected:
- IP address
- Browser type and version
- Operating system used
- Pages visited and time spent
- Date and time of access
- Country and language of origin
- Referrer (site you came from)
3.2 Data Provided Voluntarily
Through the contact forms or services on the site you may provide:
- Name and surname
- E-mail address
- Telephone number
- Company belonging
- Request message
- Other personal data you choose to share
4. Purpose and Legal Basis of the Processing
4.1 Technical Purposes
Legal basis (LPD): Legitimate interest of the Data Controller
Legal basis (GDPR): Art. 6(1)(f) – Legitimate interest
- Technical operation of the website
- Cybersecurity and fraud prevention
- Anonymous usage statistics
- Improving site performance
4.2 Communication Purposes
Legal basis (LPD/GDPR): Consent of the interested party
- Respond to your contact requests
- Provide information about our services
- Manage business relationships (only if authorized)
- Sending promotional communications (only with prior consent)
5. Recipients and Communication of Data
Your personal data may be shared with:
5.1 Technical Service Providers
- Hosting provider (servers located in Switzerland/EU)
- Email services
- Backup and security services
- Content Management Platforms (CMS)
5.2 Web Analytics Services
- Google Analytics (if used) – with IP anonymization
- Other anonymous statistical analysis tools
5.3 Competent Authorities
- Only when required by Swiss or European law
- To protect the rights of the Owner or third parties
6. International Data Transfers
6.1 Countries with an Adequate Level of Protection
Data may be transferred to countries recognized by Switzerland as providing adequate protection.
6.2 Other Transfers
For transfers to third countries, we use appropriate safeguards such as:
- Standard contractual clauses
- Adequacy decisions
- Explicit consent of the interested party
7. Storage Times
- Browsing data: 24 months from harvest
- Contact details: Until the cancellation request or for 5 years from the termination of the relationship
- Technical cookies: Session duration or maximum 24 months
- Marketing cookies: Only with consent, maximum 12 months
8. Your Rights
In accordance with the LPD and the GDPR, you have several fundamental rights regarding your personal data. You can request: log in to the data concerning you to know what information we have collected and how we use it. If you notice errors or outdated information, you have the right to to rectify this data to keep it accurate and up-to-date.
When you no longer wish for your data to be retained, you can exercise the right right to erasure (also called the “right to be forgotten”) to request its deletion from our systems. In some circumstances, you can also ask for the limitation of processing, meaning that your data is stored but not actively used.
The law also recognizes the right to portability, which allows you to receive your data in a structured and readable format, so you can easily transfer it to other services. If you do not agree with the processing methods, you can to oppose you for legitimate reasons relating to your particular situation.
Finally, for all treatments based on your consent, you can revoke authorization at any time, without compromising the lawfulness of the processing carried out up to that point.
9. How to Exercise Your Rights
To exercise the rights listed above, you can contact us via the website contact formWe undertake to respond within 30 days of your request.
10. Data Security
We adopt appropriate technical and organizational measures to protect your personal data from:
- Unauthorized access
- Undue alteration
- Disclosure prohibited
- Accidental loss
- Unlawful destruction
11. Automated Decisions and Profiling
This site does not use automated decision-making processes that produce significant legal effects on data subjects, nor does it perform high-risk profiling.
12. Data Breaches
In the event of a data security breach that results in a high risk to your rights and freedoms, we will notify you promptly and, if required by law, within 72 hours of becoming aware of the incident.
13. Complaints
If you believe that the processing of your personal data violates applicable law, you can lodge a complaint with:
Swiss:
Federal Data Protection and Information Commissioner (FDPIC)
www.edoeb.admin.ch
EU/EEA:
Competent supervisory authority of your country of residence
14. Changes to the Privacy Policy
We reserve the right to modify this policy. Any changes will be posted on this page with an updated date. We encourage you to check this page periodically.
15. Contacts
For any questions regarding the processing of your personal data, you can contact us via website contact form.
Regulatory References:
- Swiss Federal Act on Data Protection (FADP) of 25 September 2020
- Regulation (EU) 2016/679 (GDPR)
- Data Protection Ordinance (DPO)