MySwissLab (SBR Group Sarl) is committed to protecting your personal information. This policy explains what we collect, how we use it, and your rights under GDPR and applicable Swiss data protection law (nDSG). We believe transparency builds trust, so we have included plain-language summaries alongside the formal legal text.
1. Information We Collect
Plain English: We collect basic info when you contact us or use our website — like your name, email, and how you browse our site. We only collect what we genuinely need.
We collect information that you voluntarily provide to us when you interact with our services, including but not limited to:
- Contact information: name, email address, phone number, company name, and job title when you submit enquiry forms, request quotes, or subscribe to our newsletter.
- Project information: details about your cosmetic product requirements, formulation briefs, brand specifications, and any documents you share with us during the quoting or onboarding process.
- Communication records: the content of emails, chat messages, and other correspondence exchanged between you and our team.
We also collect certain information automatically when you visit our website:
- Technical data: IP address, browser type and version, operating system, device type, screen resolution, and referring URL.
- Usage data: pages visited, time spent on each page, click patterns, scroll depth, timestamps, and error logs.
- Cookie data: information collected through cookies and similar technologies (see our Cookie Policy for full details).
We only collect data that is reasonably necessary to provide our services, improve your experience on our website, and comply with legal obligations. We do not collect sensitive personal data (such as health information, religious beliefs, or biometric data) unless explicitly required for a specific service engagement and with your express consent.
2. How We Use Your Information
Plain English: We use your data to respond to your enquiries, deliver our lab services, improve our website, and send you marketing emails only if you opt in. We never sell your data.
Your personal data is processed for the following purposes:
- Service delivery: to respond to your enquiries, prepare quotations, manage your projects, deliver laboratory results, and provide ongoing support.
- Communication: to send you transactional emails related to your projects, service updates, and important notices about changes to our terms or policies.
- Marketing: to send newsletters, industry insights, and promotional communications — only with your explicit consent. You can unsubscribe at any time using the link in every email.
- Website improvement: to analyse how visitors use our website, identify technical issues, optimise page performance, and develop new features.
- Legal compliance: to meet our obligations under Swiss law, EU regulations, and applicable industry standards, including record-keeping for ISO-certified processes.
- Analytics: usage data is processed via Google Analytics under an appropriate data processing agreement. We use anonymised IP addresses where possible.
We process your data under the following legal bases (GDPR Article 6):
- Consent (Art. 6(1)(a)) — for marketing communications and optional cookies.
- Contractual necessity (Art. 6(1)(b)) — for processing related to delivering our services.
- Legitimate interest (Art. 6(1)(f)) — for website analytics, security, and fraud prevention.
- Legal obligation (Art. 6(1)(c)) — for regulatory compliance and record-keeping.
3. Data Sharing and Third Parties
Plain English: We share your data only when necessary — with trusted service providers who help us run our business. We never sell your information to advertisers or data brokers.
We may share your personal data with the following categories of recipients, always under appropriate data protection safeguards:
- Group companies: parent and subsidiary companies within SBR Group Sarl for administrative and operational purposes.
- IT service providers: hosting providers, email platforms, CRM systems, and cloud storage providers that process data on our behalf under strict data processing agreements.
- Analytics providers: Google Analytics and similar tools, configured to minimise personal data collection.
- Payment processors: secure payment gateways that handle invoicing and transaction processing in compliance with PCI-DSS standards.
- Professional advisors: lawyers, auditors, and accountants when necessary for legal, regulatory, or financial purposes.
- Law enforcement: government authorities when we are legally compelled to disclose information, such as in response to a court order or regulatory request.
All third-party processors are contractually required to protect your data and may only process it for the specific purposes we instruct. We conduct due diligence on all data processors and require them to maintain appropriate security measures.
4. Data Storage and Security
Plain English: Your data is stored on encrypted servers in Switzerland. We keep it only as long as needed and apply industry-standard security measures to protect it.
All personal data is stored on encrypted, Switzerland-hosted systems in compliance with the Swiss Federal Act on Data Protection (nDSG) and the EU General Data Protection Regulation (GDPR). We implement commercially reasonable technical and organisational security measures including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Access controls with role-based permissions and multi-factor authentication for sensitive systems.
- Regular security audits and vulnerability assessments.
- Employee training on data protection and information security.
- Incident response procedures for prompt handling of potential data breaches.
Data is retained only for as long as necessary to fulfil the purposes outlined in this policy or as required by law. Typical retention periods include:
- Client project data: for the duration of the business relationship plus 10 years (Swiss commercial law requirement).
- Marketing consent records: for the duration of consent plus 3 years.
- Website analytics data: 26 months (Google Analytics default).
- Enquiry form submissions: 2 years from the last interaction.
No method of electronic transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of any account credentials or login information.
5. Your Rights (GDPR)
Plain English: You have the right to see, correct, or delete your data. You can also object to how we process it or ask us to transfer it elsewhere. Just email us and we will handle it.
Under the GDPR and Swiss data protection law, you have the following rights regarding your personal data:
- Right of access (Art. 15): you may request a copy of the personal data we hold about you and information about how it is processed.
- Right to rectification (Art. 16): you may request correction of inaccurate or incomplete personal data.
- Right to erasure (Art. 17): you may request deletion of your personal data where there is no compelling reason for continued processing.
- Right to restrict processing (Art. 18): you may request that we limit the processing of your data in certain circumstances.
- Right to data portability (Art. 20): you may request your data in a structured, commonly used, and machine-readable format.
- Right to object (Art. 21): you may object to processing based on legitimate interests, including direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact our Data Protection Officer (see Section 8 below). We will respond to your request within 30 days. If we are unable to comply, we will explain why and inform you of your right to lodge a complaint with a supervisory authority.
You have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you are in the EU, with your local Data Protection Authority.
6. Cookies and Tracking
Plain English: We use cookies to remember your preferences and understand how you use our website. You can manage your cookie settings at any time. See our separate Cookie Policy for the full details.
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse website traffic, and understand where our visitors are coming from. Cookies are small text files placed on your device when you visit our site.
We use the following categories of cookies:
- Essential cookies: required for the website to function properly (e.g., session management, cookie consent preferences). These cannot be disabled.
- Analytics cookies: help us understand how visitors interact with our site (e.g., Google Analytics). These are opt-in only.
- Marketing cookies: used to track visitors across websites for advertising purposes (e.g., Meta Pixel, LinkedIn Insight Tag). These are opt-in only.
You can manage your cookie preferences at any time through our cookie banner or browser settings. For comprehensive information about the specific cookies we use, their purposes, and durations, please refer to our Cookie Policy.
7. Children's Privacy
Plain English: Our services are for businesses, not children. We do not knowingly collect data from anyone under 16. If we discover we have, we will delete it immediately.
MySwissLab provides B2B laboratory services and does not target or knowingly collect personal data from children under the age of 16. If we become aware that we have inadvertently collected personal data from a child, we will take immediate steps to delete that information from our systems. If you believe a child has submitted personal information through our website, please contact us immediately at hello@myswisslab.ch.
8. Changes to This Policy
Plain English: We may update this policy from time to time. If we make significant changes, we will notify you by email or by posting a notice on our website.
We reserve the right to update this Privacy Policy at any time. Changes will be posted on this page with an updated "Last updated" date. For material changes that significantly affect how we process your personal data, we will provide additional notice — such as an email notification or a prominent banner on our website. Your continued use of our services after such changes constitutes acceptance of the updated policy.
9. Contact Us
Plain English: Have questions about your data? Email us at hello@myswisslab.ch and our Data Protection Officer will get back to you.
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact our Data Protection Officer:
S. Yavari — Data Protection Officer
MySwissLab — SBR Group Sarl
1B Route de l'Industrie
1072 Forel, Switzerland
Email: hello@myswisslab.ch
We aim to respond to all data protection enquiries within 30 days of receipt. This policy is governed by Swiss law and compliant with the EU General Data Protection Regulation (GDPR).