Privacy policy
Privacy Policy
This policy explains what personal data DTD Systems GmbH collects when you visit dtdsystems.ch or buy from us, why we collect it, who else sees it, and what you can do about it. Last updated 8 August 2026.
The short version
- We collect what we need to sell you a device, deliver it, invoice it and, where the law requires it, obtain export clearance for it.
- We run Meta advertising tools on this site. They send Meta a set of your details in hashed form. We explain exactly which ones below.
- If you are in the EU or the EEA, we ask before marketing and analytics cookies are set. If you are in Switzerland, we tell you instead of asking, and you may refuse.
- You have a right to object to advertising and marketing. It is absolute, you do not have to justify it, and we set it out in its own section below.
- We do not sell your personal data.
- Anything you want to ask, change, stop or delete: info@dtdsystems.ch.
Contents
- Who we are
- The law that applies
- What we collect
- What you have to give us, and what is optional
- Why we process it, and on what legal basis
- Cookies and tracking
- The Meta Pixel and the Conversions API
- Judge.me
- Automated decisions and profiling
- Who we share it with
- Sending data abroad
- How long we keep it
- If we ever want to use your data for a new purpose
- Your right to object
- Your other rights
- Additional rights if you are in Switzerland
- How to exercise your rights
- Complaints
- Changes to this policy
- Contact
Who we are
The controller of your personal data is:
- DTD Systems GmbH
- Company number CHE-445.864.884
- Schulhausstrasse 2, 5612 Villmergen AG, Switzerland
- Email: info@dtdsystems.ch
- Telephone: +41 76 225 50 04
We are a Swiss company. We sell to customers in Switzerland, Liechtenstein and the EU and Schengen area. Our online store runs on the Shopify platform.
We have not designated a representative in the European Union. Every request, objection and complaint therefore goes to the addresses above, and we answer it ourselves. If that changes we will name the representative here.
We have not appointed a Data Protection Officer. Data protection questions are handled by the management at info@dtdsystems.ch.
The law that applies
We process personal data under the Swiss Federal Act on Data Protection (revDSG, SR 235.1) and its implementing Ordinance. If you are in the EU or the EEA, Regulation (EU) 2016/679 (the GDPR) also applies to our processing of your data.
The two regimes are built differently, and we would rather show you the difference than blur it. The GDPR requires us to name a legal basis for every purpose, so we do that below. Swiss law does not work through a catalogue of legal bases: a private company may process personal data provided it does so lawfully, in good faith and proportionately, and provided it respects your objection unless an overriding interest applies. Where the Swiss and the EU answer genuinely differ, this policy gives both answers rather than one merged answer.
What we collect
Data you give us
- Order and delivery data: name, delivery and billing address, email address, telephone number, order contents and order history.
- Account data, if you create a customer account: your login details and the addresses saved to it.
- Payment data: the confirmation and reference data needed to match a payment to an order. We do not see or store full card numbers.
- Export documentation, for orders shipped outside Switzerland and Liechtenstein: the signed End User Certificate, which identifies you and the intended civilian use of the device, together with the supporting details we need for the licence application.
- Correspondence: what you write to us by email, by telephone or through our contact form, and our replies.
Data collected automatically
- Technical and usage data: IP address, browser and device information, the pages you view, the products you look at, what you add to the cart, and how you arrived at the site.
- Cookies and similar technologies set by our platform and by the tracking tools described under Cookies and tracking.
What you have to give us, and what is optional
Some data you have to provide, some you do not, and the difference has consequences worth knowing before you start.
- Required to place an order: the details the checkout marks as required, which include your name, delivery address, billing address, email address and the payment details for the method you choose. This is a contractual requirement. Without them we cannot conclude or perform a sale, so we cannot accept the order.
- Required by law for any order shipped outside Switzerland and Liechtenstein: a signed End User Certificate and the supporting details for the export licence application. This is a statutory requirement under the goods control regime described below. Without it we cannot ship, and if you have already paid we refund you in full.
- Optional: signing up for marketing messages. If you do not sign up, the order still goes through and you hear from us about your order only.
- Your telephone number, where we hold one, is used so that we or the carrier can reach you about delivery or customs clearance. Without it, both can be slower, because the carrier then has no way to reach you directly.
Why we process it, and on what legal basis
The legal bases named here are the GDPR bases that apply if you are in the EU or the EEA. If you are in Switzerland, the lawfulness of the same processing follows from the revDSG as explained above, and your right to object is set out in its own section.
To sell you something and deliver it
We use your order, delivery, account and payment data to take payment, arrange carriage, keep you informed about your order, handle returns and honour the two year guarantee. Legal basis: performance of a contract with you, Art. 6(1)(b) GDPR.
To meet Swiss accounting obligations
Orders, invoices and payment records are business records we are required by law to keep. Legal basis: compliance with a legal obligation, Art. 6(1)(c) GDPR.
To obtain export clearance for controlled goods
Night vision and thermal devices are dual use goods under the Swiss Goods Control Ordinance (Gueterkontrollverordnung, GKV, SR 946.202.1). For any order shipped outside Switzerland and Liechtenstein, we must collect a signed End User Certificate from you and apply to the State Secretariat for Economic Affairs (SECO) for an export licence. This means your identity and end user details are transmitted to a Swiss federal authority. We cannot ship without it, and if clearance is refused we refund you in full. Legal basis: compliance with a legal obligation, Art. 6(1)(c) GDPR.
To answer you
We use your correspondence to deal with your question, quotation request or complaint. Legal basis: performance of a contract or steps taken before entering into one, Art. 6(1)(b) GDPR. Where no contract is in view, our legitimate interest in answering people who contact us, Art. 6(1)(f) GDPR.
To keep the store working and secure
We and our platform provider process technical data to keep the site available, to prevent fraud and abuse, and to fix faults. Legal basis: our legitimate interest in operating a functioning and secure shop, Art. 6(1)(f) GDPR.
For advertising, measurement and marketing
We measure how our site is used, and we advertise on Facebook and Instagram, including showing ads to people who have already visited our site. If you are in the EU or the EEA, the legal basis is your consent, Art. 6(1)(a) GDPR, given through the cookie banner. If you are in Switzerland, we do not ask for prior consent; we tell you what happens, here and on the site, and you may refuse it and object at any time. If you have given us your details for marketing messages, you can tell us to stop at any time and we will. Read this together with the section below headed What consent does and does not switch off.
To send your order and account details to Meta for measurement
This is a separate purpose from cookies, and it deserves its own line because it is a separate kind of data. When you buy, the advertising tools described below transmit a set of your order and account details to Meta in hashed form, so that Meta can match a sale to an advertisement. That is customer data, not browsing data. If you are in the EU or the EEA, the legal basis is your consent, Art. 6(1)(a) GDPR, given through the cookie banner. If you are in Switzerland, no prior consent is sought and you may refuse and object at any time, as described below. In both cases we set out in the next section exactly which fields are involved, and what our consent banner does and does not control.
Cookies and tracking
What happens, and what you control
Cookies that are strictly necessary to run the shop, such as keeping your cart and your session, are always set. They cannot be switched off without breaking the store.
Marketing and analytics cookies are handled differently depending on where you are:
- If you are in the EU or the EEA, we ask you before marketing and analytics cookies are set. Our consent banner, provided by the Shopify platform, records your choice. You can withdraw your consent at any time by writing to info@dtdsystems.ch, and withdrawing it does not make the processing carried out before you withdrew it unlawful.
- If you are in Switzerland, we do not ask for prior consent. Swiss law permits the storing and reading of data on your device without prior consent provided we tell you what is happening and why, and tell you that you may refuse it. That duty comes from Art. 45c lit. b of the Telecommunications Act (Fernmeldegesetz, FMG, SR 784.10). So, plainly: you may refuse this. Write to info@dtdsystems.ch and we will act on it, and you can also block or delete cookies in your browser settings at any time.
Browsing our site is not consent. We do not treat your continued use of the site as agreement to anything.
What consent does and does not switch off
The banner controls the marketing and analytics tools that run in your browser on this site. Some of the same events are also sent to Meta from the server rather than from your browser, as described in the next section. We do not want to give you a guarantee about the server side that we have not verified end to end, so we will say it straight: if you want to be certain that nothing further is transmitted about you, write to info@dtdsystems.ch, tell us to stop, and we will confirm the position for your data and act on it.
The Meta Pixel and the Conversions API
We run the Meta Pixel and Meta's Conversions API through the official Facebook and Instagram app for Shopify, at the maximum data sharing setting, with advanced matching switched on. Our Meta dataset id is 1038989035164123.
The pixel records events on our site, such as page views, product views, add to cart, checkout started and purchase. The Conversions API sends the same events from the server. Advanced matching means that, where we hold them, the following fields are transmitted to Meta in hashed form: email address, telephone number, first and last name, gender, city, state or region, postal code, country, date of birth, and an internal customer identifier. Hashing converts the value into a fixed string before it leaves us, so Meta receives it in that form rather than as readable text. It is not anonymisation: the point of the exercise is that Meta can match the string to a person it already knows.
Meta and DTD as joint controllers
For the stage at which this data is collected on our site and transmitted to Meta, DTD Systems GmbH and Meta Platforms Ireland Limited are joint controllers within the meaning of Art. 26 GDPR. In plain terms: we decide what is collected on our website and we send it, and Meta then processes it for its own purposes afterwards. Here is the essence of the arrangement between us, so you can see who answers for what.
- What governs it are Meta's own published terms for its business tools, which apply because we installed the Facebook and Instagram app on this store. We did not negotiate a bespoke agreement with Meta, and no arrangement between us can reduce the rights the law gives you.
- DTD Systems GmbH discharges the duty to inform you about this processing. That is what this section is. Meta does not send you a separate notice for it.
- Meta processes the data afterwards for measuring and attributing advertising, for building and matching advertising audiences, and for its own product and advertising purposes, under its own terms. Meta publishes its own privacy policy, and it, not this document, describes that stage.
- Your contact point at DTD is info@dtdsystems.ch. You may exercise your rights against either of us, and if you start with us we will deal with what is ours and tell you plainly what only Meta can do.
Judge.me
Judge.me is a product review application installed on our store. Its review widget is switched off and does not display on our pages, but the app still registers a tracking pixel that loads when you visit the site. The app remains installed. We are disclosing it because it runs, not because we currently use it.
We will not overstate what we know about its legal role. We have not established whether Judge.me processes what that pixel collects only on our instructions, which would make it our processor, or also for its own purposes, which on the same reasoning we apply to Meta would make it a joint controller with us for the collection and transmission stage. Until we have established it, we treat the pixel as a marketing and analytics tool: in the EU and the EEA it falls under the consent you give in the banner, and in Switzerland you may refuse it and object as described above. Either way, start with us at info@dtdsystems.ch, and we will answer for the collection on our site.
Automated decisions and profiling
We do not take decisions about you that produce legal effects for you, or similarly significantly affect you, by automated means alone. Two things come close enough that we would rather describe them than leave you to guess.
- Order review. If we hold, cancel or refuse an order, a person at DTD takes that decision. You can ask us why, tell us your side of it, and ask for the decision to be looked at again.
- Export screening. Whether an order can lawfully be shipped is decided by a person at DTD against the destination, the device and the licence position, and by SECO on the licence application itself. It is not an automated decision.
Advertising profiling is different in kind and we treat it separately: it is covered by the Meta section above and by your absolute right to object below.
Who we share it with
- Shopify, our e-commerce platform and host. Shopify acts as our processor, on our instructions. It handles the storefront, checkout, orders, customer accounts, hosting and the consent banner.
- Meta Platforms Ireland Limited, as described above. Joint controller with us for the collection and transmission of pixel and Conversions API data, and controller in its own right for what it does with that data afterwards.
- Judge.me, whose pixel loads on our pages as described above.
- Payment providers and banks. Our checkout offers card payment, TWINT and bank deposit, and Apple Pay is available as a wallet. Card data is processed by the payment provider, not by us. We do not see or store full card numbers.
- SECO, the Swiss State Secretariat for Economic Affairs, for export licence applications on orders leaving Switzerland and Liechtenstein, as described above. This is a legal obligation, not a commercial choice.
- The carrier that transports your order. We arrange carriage ourselves and one carrier handles each order. It receives the name, address and contact details needed to deliver the parcel and to clear it through customs.
Beyond these, we disclose personal data only where the law requires us to. We do not sell your personal data.
Sending data abroad
All three providers described above sit outside Switzerland, and the data they handle for us may leave Switzerland and the EEA. We have negotiated and signed no transfer clauses of our own, and hold no certification and no Data Privacy Framework registration. One set does bind us, through terms we accepted rather than anything we drafted, and is named under Judge.me below.
Shopify
- Entity: Shopify International Limited, incorporated in Ireland, registration number 560279. Parent Shopify Inc., registered in Canada.
- Mechanism: its Data Processing Addendum states that transfers out of the EEA or Switzerland to another Shopify company are made under Shopify's Binding Corporate Rules, lead supervisory authority the Irish Data Protection Commission, published in full as a public PDF.
- Not established: the addendum names entities and mechanisms, not destination countries, so beyond Ireland, Canada and Singapore, which it names expressly, they sit in Shopify's subprocessor list. Its Swiss reference is to the pre 2023 act, never the revDSG.
- Read it: shopify.com/legal/dpa; cdn.shopify.com/static/Shopify-Processor-Policy.pdf; help.shopify.com/en/manual/your-account/privacy/subprocessors
Meta
- Entity: Meta Platforms Ireland Limited, Dublin, transferring onward to Meta Platforms, Inc. in the United States.
- The limit, and it matters most: Meta publishes no merchant facing transfer instrument for the joint controller stage the Pixel and the Conversions API sit in. Its European Data Transfer Addendum covers the processor stage only; the Controller Addendum governing that stage carries no transfer clause.
- United States leg: Meta's own published Data Privacy Framework certification statement. We have not independently confirmed it, and the position here changes if that certification lapses.
- Read it: facebook.com/legal/EU_data_transfer_addendum; facebook.com/legal/controller_addendum; facebook.com/privacy/policies/data_privacy_framework/
Judge.me
- Entity: Judge.me Ltd, a single United Kingdom company that contracts with every merchant.
- Destination: Annex A of its Data Processing Addendum gives the processing location as the United Kingdom and the EEA, main servers in Dublin.
- Mechanism: its published Data Processing Addendum binds us to the standard contractual clauses at its Annex C, with the United Kingdom addendum at Annex D. This is the one place such clauses reach us: we did not draft or negotiate them, they bind through accepted terms, and we hold no signed copy.
- Not established: what it publishes about onward transfers out of the United Kingdom, and whether it is our processor or a joint controller for its pixel, as its part of this policy records.
- Read it: judge.me/privacy/data-processing-addendum
The Swiss answer
Art. 19(4) with Art. 16 revDSG requires us to name the State and, where it lacks adequate protection, the guarantee. Art. 16(1) requires none for States the Federal Council has found adequate, in Annex 1 of the Data Protection Ordinance (DSV, SR 235.11).
- Ireland is on that list, so our disclosures to Shopify International Limited and to Meta Platforms Ireland Limited need no Art. 16(2) guarantee.
- Canada is on it for the private sector, conditional on the Canadian federal act on personal information in the course of commercial activities applying. Shopify Inc. processing our customers' data commercially meets that condition, so that leg needs no guarantee.
- The United Kingdom is on it, so our own disclosure to Judge.me Ltd goes to an adequate State. That entry carries a footnote qualifying the scope of the assessment, so we do not state it as unconditional.
- The United States is on it only for organisations certified under the Swiss US Data Privacy Framework. We disclose to Meta Ireland; the onward step is Meta's, on its own published certification, with the qualification above.
- Singapore is not on it; there Shopify publishes its Binding Corporate Rules. Art. 16(2)(e) revDSG accepts binding internal data protection rules approved in advance by the EDOEB or by a data protection authority of an adequate State, and Shopify's were approved with the Irish Data Protection Commission as lead. That reading is ours, from two published facts; Shopify asserts no Swiss approval of them.
The EU answer
Switzerland holds European Commission adequacy, most recently confirmed on 15 January 2024, so your data reaching us needs no additional safeguard. For the onward legs, and to meet Art. 13(1)(f) GDPR:
- Shopify and Meta contract with us from Ireland, Judge.me from the United Kingdom, whose EU adequacy decision was renewed in December 2025, so those disclosures need no further safeguard.
- Shopify's transfers beyond that, Singapore included: the Binding Corporate Rules above, an appropriate safeguard of the kind contemplated by Art. 46(2)(b) GDPR.
- Meta's United States transfers: published reliance on the EU US Data Privacy Framework, expressed for the processor stage only, with no transfer clause for the joint controller stage.
- Judge.me: the clauses at its Annex C are the European Commission's, an appropriate safeguard under Art. 46(2)(c) GDPR, binding on us through its published Data Processing Addendum.
Every safeguard above is published by the provider at the addresses given, and we will send a copy on request to info@dtdsystems.ch. We will not promise a document we do not hold, and the only transfer clauses reaching us are in Judge.me's published terms.
How long we keep it
Where the law sets a period, we follow it. Otherwise we apply the criteria below rather than a fixed number, so you can work out for yourself how long your data will exist.
- Orders, invoices and accounting records: ten years. Swiss law requires business records to be kept for ten years (Art. 958f of the Swiss Code of Obligations).
- Export control records, including End User Certificates and licence correspondence: kept for as long as the Swiss goods control regime requires them to be available for inspection.
- Customer account data: kept while your account exists. Close the account and we remove it, apart from what the accounting rule above obliges us to keep.
- Guarantee and claims data: kept while the two year guarantee runs, and for as long as a legal claim can still be brought or is still running.
- Marketing data: kept until you object or withdraw your consent. After that we stop, and keep only the minimum needed to remember not to contact you again.
- Correspondence: kept while it is still relevant to the relationship it belongs to, then deleted.
If we ever want to use your data for a new purpose
If we decide to use data we already hold for a purpose that is not described in this policy, we will tell you about that purpose first, together with the information you need to judge it, such as the legal basis, how long we would keep it and your rights. We will do that before the new processing starts, not afterwards.
Your right to object
We are setting this right out on its own, and drawing it to your attention explicitly, because it is the one that gives you the most control and because it is easy to miss in a list.
Direct marketing and advertising profiling: an absolute right
You may object to direct marketing, including advertising profiling, at any time and for any reason. This right is absolute. If you exercise it, we stop. There is nothing to weigh up and nothing for you to justify. One line to info@dtdsystems.ch is enough.
Other processing, if you are in the EU or the EEA
You may also object to processing we carry out on the basis of our legitimate interests, on grounds relating to your particular situation (Art. 21(1) GDPR). We then stop, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless we need the data for legal claims.
Other processing, if you are in Switzerland
Swiss law is not the same here, and it is more generous to you, so we state it separately. Under Art. 30(2)(b) revDSG you may declare expressly that you do not want a particular processing to take place, and you do not have to give any reason or point to your particular situation. Once you have declared it, processing against your declaration is a breach of your personality rights unless we can show a justification, and it is for us to establish an overriding private or public interest, or a legal duty, under Art. 31 revDSG. If we cannot, we stop. In practice: tell us what you want stopped, and the burden of arguing sits with us, not with you.
Your other rights
- Access. To be told whether we process data about you, and to receive a copy of it, along with the further information set out just below.
- Rectification. To have inaccurate data corrected and incomplete data completed.
- Erasure. To have your data deleted, unless we are legally required to keep it, for example accounting and export control records.
- Restriction of processing (GDPR Art. 18). To have us hold your data without using it while a question about it is resolved.
- Data portability. To receive the data you gave us in a common, machine readable format, and to have it sent to another provider where that is technically feasible.
- Withdrawal of consent. Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew it.
- Complaint. To lodge a complaint with a supervisory authority, as set out below.
- Objection. Set out in its own section above.
What an access request gets you
Swiss law fixes a minimum for what we have to tell you, and we would rather you knew the floor than assumed it was lower. Under Art. 25(2) revDSG an access response gives you:
- our identity and contact details;
- the personal data we process about you, as such;
- the purpose of the processing;
- how long we keep the data, or, if we cannot give a period, the criteria we use to decide;
- the information available to us about where the data came from, if we did not get it from you;
- whether an automated individual decision is taken, and if so the logic it rests on;
- the recipients or categories of recipients we disclose the data to, and, for disclosures abroad, the country and the guarantee relied on.
If you are in the EU or the EEA, Art. 15 GDPR gives you an equivalent set. We answer to whichever standard is higher for you.
Additional rights if you are in Switzerland
These are Swiss remedies under Art. 32 revDSG. They are not the same as the GDPR rights above and we do not merge them into it.
- Correction. You may demand that inaccurate personal data be corrected, unless a legal provision forbids it or we process the data only for archiving in the public interest.
- Prohibition of a specific processing (Art. 32(2)(a)). You may demand that a particular processing be prohibited. This is broader than the GDPR restriction right: it is directed at stopping a defined activity, not at freezing data during a dispute.
- Prohibition of disclosure to third parties (Art. 32(2)(b)). You may demand that we do not disclose your data to a particular third party. This is a real right here, not a theoretical one, given the disclosures to Meta and to the carrier described above. It cannot reach the disclosure to SECO, because that one is a legal duty we cannot set aside.
- Deletion or destruction (Art. 32(2)(c)). You may demand that your personal data be deleted or destroyed, subject to the retention duties described above.
- Marking as disputed (Art. 32(3), Bestreitungsvermerk). If neither the accuracy nor the inaccuracy of a piece of data can be established, you may demand that it be marked as disputed. The data stays, but it carries your dispute with it wherever it goes.
Art. 28 revDSG also gives you a Swiss right to the release and transfer of data. You may ask us to hand over the personal data you have disclosed to us, in a common electronic format, or to transfer it to another controller, where we process it automatically and process it either with your consent or in connection with a contract. This is a Swiss entitlement in its own right, not the EU portability right extended to you as a courtesy.
How to exercise your rights
Write to info@dtdsystems.ch, or to DTD Systems GmbH, Schulhausstrasse 2, 5612 Villmergen AG, Switzerland. Tell us what you want. You do not need any particular form of words.
We answer within 30 days. If a request is unusually complex and we need longer, we will tell you inside those 30 days, explain why, and give you a date. We may ask you for enough information to be sure we are dealing with the right person, so that we do not disclose your data to someone else.
Exercising these rights is free.
Complaints
If you think we have handled your data wrongly, please tell us first. We would rather fix it than argue about it.
You can also complain to a supervisory authority:
- In Switzerland: the Federal Data Protection and Information Commissioner (EDOEB), edoeb.admin.ch.
- In the EU or the EEA: the data protection authority of the country where you live, where you work, or where you believe the problem occurred.
Changes to this policy
We update this policy when what we do changes, for example when we add or remove a tool that processes your data. The date at the top shows when it was last changed. If a change materially affects how we use your data, we will say so plainly rather than quietly reissuing the page.
Contact
- DTD Systems GmbH, CHE-445.864.884
- Schulhausstrasse 2, 5612 Villmergen AG, Switzerland
- info@dtdsystems.ch
- +41 76 225 50 04