Privacy Policy

Baited SA domiciliated c/o AMZ Fiduciaria Sagl, Via Merlina 15, 6962, Viganello, Switzerland (hereinafter the Company, we, us, our) collects personal data (as described below) in compliance with applicable laws and regulations, in particular the Swiss Federal Data Protection Act 2020, as of 1 September 2023 (FDPA).

The Company owns the intellectual property rights to its website and its content, namely currently: https://baited.io/ (hereinafter the Website).

The Website, its contents, texts, documents, trademarks, logos, names, images, graphics, arrangement and adaptations are protected by the Federal Act on Copyright and Related Rights (Copyright Act, CopA) (Bundesgesetz über das Urheberrecht und verwandte Schutzrechte, URG) of 9 October 1992 and subsequent amendments. Intellectual property may also be protected by other applicable laws.

Within this Website there are also images, documents, logos, names and trademarks of parties who have expressly authorized their publication on the Website. Third party material is also protected by the aforementioned law and is covered by copyright. The use of our Website and its contents is exclusively visual, and no copy, reproductions or storage is permitted. It is forbidden to copy, archive, alter, distribute, publish or use the contents of the Website without the express authorization of the Company.

1. Definitions

Pursuant to the FDPA, the terms indicated below have different meanings:

  • Personal Data any information relating to an identified or identifiable natural person.
  • Sensitive personal data personal data worthy of special protection: (i) data concerning religious, philosophical, political or trade union matters, (ii) data concerning health, intimate sphere or race or ethnicity, (iii) genetic data, (iv) biometric data that uniquely identifies a natural person, (v) data relating to administrative and criminal proceedings and sanctions, (vi) data relating to social assistance measures.
  • Processing any operation or set of operations, carried out with or without the aid of automated means, which apply to (groups of) personal data, including the collection, recording, organisation, structuring, storage, adaptation or modification, extraction, consultation, use, dissemination, communication by transmission, dissemination or any other form of disclosure, alignment or interconnection, limitation, erasure or destruction.
  • Data controller means a private person who or federal body which, alone or jointly with others, determines the purpose and the means of processing personal data.
  • Data subject: means a natural person whose personal data is processed.

For the purpose of this Privacy Notice, you are the data subject, while the Data controller under this privacy notice is Baited SA domiciliated c/o AMZ Fiduciaria Sagl, Via Merlina 15, 6962, Viganello, Switzerland.

2. Type of personal data acquired, purpose, legal basis and data storage

The Company uses specific software to conduct cybersecurity tests and campaigns (the Service), for its clients which are typically legal entities (the Customers).

The Company uses the Website to describe its Services and collect potential enquiries from the Customers. For this purpose, the Company process the following data:

Personal dataData acquisition methodPurpose of the processingLegal basis of the processingData retention time
Name of the prospect (individual) e-mail and name of the CompanyThrough a specific web-form on the WebsiteImplementation of pre-contractual measures and address queries of the CustomersPerformance of a contract (prior to entering into a contract)10 years from the end of the contract with the Company
Name of the prospect (individual) e-mail and name of the CompanyThrough a specific web-form on the WebsiteAdministration of the contractual relationship and address queries of the CustomersPerformance of a contract10 years from the end of the contract with the Company

3. To whom will the collected data be communicated?

We will only disclose your personal data if we are obliged to do so to comply with our legal or regulatory obligations, for business, administrative or contractual reasons or because you have instructed us to do so. This also includes disclosure:

  • within the Company;
  • to third parties who process personal data on our behalf (i.e. IT system providers, consultants, professionals and other service providers); and
  • to any government, authority, regulatory agency, supervisory or exchange body or court requiring it under applicable law or regulations.

4. The Website

Our Website may, from time to time, contain links to and from the websites of third-parties such as partners, affiliates etc. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

5. Can the Company transfer data to a third country and/or international organizations?

The data collected by the Company is stored in Switzerland. However, the Company may engage one or more third-party providers that transfer data outside the European Economic Area (EEA). In this case, the Company must make sure that all necessary and appropriate measures are taken. Such measures include official Standard Contractual Clauses (SCCs), Binding Contract Rules (BCR) or any other instrument to safeguard the data protection of the Data Subjects outside the EEA. Where applicable, the Company will ensure that third-party providers will rely on the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).

6. Children personal data

We do not address our Services to children under the age of 16. We do not intend to, or knowingly, collect or solicit personal information from children under the age of 16. Should a Target, a Customer or a prospect are under the age of 16, such individual shall not use the Service or the Website, otherwise provide us with any personal data either directly or by other means.

Should a minor has provided personal data to us, the Company encourages the child`'`s parent or the legal representative of such child to contact us and request the deletion of the personal data from our systems.

Should we learn that any personal data we collect has been provided by a child under the age of 16, we will promptly delete that personal information.

7. Disclaimer

The Company reserves the right to change or update the information on the Website at any time without notice. The Company is not responsible for internet malfunctions, damage caused by third parties, data imports of any kind including but not limited to viruses, worms, Trojan horses nor for links from or other websites on the Internet. The Company has no control over the content and form of external websites. The Company cannot guarantee the flawless operation of hardware and software. In no event shall the Company be liable to you or any third party for any direct, indirect, special, or consequential damages of any kind whatsoever resulting from the use of the Website or another website linked to it.

Any liability for loss of income, business interruption, loss of programs or other data the computer systems of the user is also excluded. The transmission of communications, documents and other information by e-mail is considered less reliable, secure and confidential than by letter or fax. Against viruses and spam the Company employ modern identification technologies. However, the Company recommends that the user also employs a virus scanner, and we disclaim any liability for any damage resulting from e-mails or loss thereof. We reserve the right to reject e-mails with potentially dangerous attachments. If you complete the web- form on the Website we may ask you for further information. For our part, we are committed to protecting the confidentiality of your personal data.

8. Not automated individual decision making, including profiling

While using the Website the Company does not take any decision based solely on automated processing and that has a legal consequence for or a considerable adverse effect on you, including profiling which produces legal effects on you as data subject. Therefore, you are not subject to any automated individual decision- making, including profiling under article 21 of FDPA.

9. How we protect your personal data

The security of your personal data is important to us and to protect it we use various technical and organizational measures. We are committed to safeguarding and protecting personal data by taking appropriate measures against accidental or unlawful destruction, loss, alteration or unauthorized disclosure.

10. Rights of interested parties

Under data protection law, you have a number of rights in relation to your personal data. You have the right to request access, rectification or deletion of such information, the right to limit or object to processing and, in certain circumstances, the right to data portability.

If your consent is necessary, you can revoke it at any time. If you wish to exercise the above rights, you can send a communication to:

Baited SA, c/o AMZ Fiduciaria Sagl, Via Merlina 15, 6962, Viganello, Switzerland
e-mail: [email protected]

We will try to answer them within one month maximum, provided by the law, although we reserve the right to extend this period for more complex requests. We reserve also the right to debit an expense administrative reasonable for any requests manifestly unfounded or excessive access to data personal and for any copies additional of the data personal requests.

You may also contact the Swiss Privacy Authority if our response does not satisfy you: www.edoeb.admin.ch
tel. +41 58 464 94 10, [email protected].

Contact information

This website is owned and operated by Baited SA.

You may contact us regarding this Privacy Policy by writing or emailing us at:

[email protected]

c/o AMZ Fiduciaria Sagl

Via Merlina 15

6962 Viganello

Switzerland

Email: [email protected]