Privacy Notice
This website (including the online shop) is operated and Red Ink is provided by LawDigital Ltd., Stockerstrasse 47, CH-8002 Zürich, who also acts as the controller. It aims at offering Red Ink at corporate customers. While it makes available Red Ink also to private individuals, it does not aim to or actively offer products or services to individuals outside Switzerland.
With regard to the collection and other processing of personal data by LawDigital Ltd., in connection with Red Ink and otherwise, we refer to the privacy notice below:
Types of Personal Data
General Data
We process general personal data about you, such as your name and contact details.
[Note: concerns section 3: all data processing].
Financial Data
We process your financial data.
[Note: concerns section 3: communication, administration and processing of contracts].
Location Data
We process your location data.
[Note: concerns section 3: improvement of electronic offerings].
Sources of Personal Data
Provided Data
We process personal data that you provide to us.
[Note: concerns section 4, first bullet point].
Collected Data
We process personal data that we collect about you.
[Note: concerns section 4, second bullet point].
Received Data
We process personal data about you that we receive from third parties.
[Note: concerns section 4, second bullet point.]
Purpose of Processing
Product Development
We use your personal data for the development and improvement of products and services.
[Note: concerns section 3:
improvement of electronic offerings].
Other Purposes
We use your personal data for other purposes without direct connection with the core service.
[Note: concerns section 3: security, etc.]
Passing Onto Third Parties
Data Transfers
We transfer your personal data to other companies
that decide themselves how to use the data.
[Note: concerns section 5].
Place of Processing
Worldwide
We also process your personal data outside
of Switzerland and the EEA.
[Note: concerns section 6].
1. What is this privacy notice about?
LawDigital Ltd. is a limited liability company with its registered office in Zurich, Switzerland (hereinafter also “LawDigital“, “we”, “us”). In the course of our business activities, we collect and process personal data (hereinafter also “data”), in particular personal data about our customers and persons interested in our products, associated persons, employees of partner companies (e.g., other service providers) and other associations, visitors to our websites, participants in events, and other entities or, in each case, their contact persons and employees (hereinafter also “you”). In this Privacy Notice we inform you about the processing of these personal data. In addition to this Privacy Notice, we may provide you with additional information about the processing of your data (e.g., in consent forms or contract terms), additional Privacy Notices (e.g. on other websites or in apps from us), forms and notices.
If you disclose data to us about other persons (e.g., family members, representatives, counterparties, or other associated persons), we assume that you are authorized to do so, that such data is accurate, and that you have ensured that such persons are aware of such disclosure to the extent that an information obligation applies (e.g., by bringing this Privacy Notice to their attention in advance).
2. Who is the controller for processing your data?
For the processing activities described in this Privacy Notice, the following companies are each individually or jointly responsible:
LawDigital Ltd.
Stockerstrasse 47
8002 Zürich
Switzerland
The responsibility for the particular processing activity lies with the LawDigital Ltd. legal entity with which you communicate, with which you (or your principal or employer) intend to enter into or have entered into a contract, by which you (or your principal or employer) are advised or represented, which represents another party in a matter in which you (or your principal or employer) are involved, which takes up contact with you, to whom you are applying to or who you are visiting, unless otherwise stated or evident from the circumstances. To the extent we are representing clients, LawDigital is generally a data controller with respect to LawDigital’s related data processing activities, but may be so jointly with its respective clients. If you wish to contact us about the processing of your data, you can do so via info@lawdigitalag.ch
3. For what purposes do we process which of your data?
When you use our services or our website redink.ai and other websites and apps we may operate (hereinafter “Website” or “Websites“) or otherwise deal with us or when you register and maintain an account for entering into a license subscription agreement we obtain and process different categories of your personal data. Providing the data indicated as mandatory is required for doing so. In particular, we process the following personal data from you for the following purposes:
- Registration:We collect and process your personal data when you register and maintain an account for entering into a license subscription agreement. Providing the data indicated as mandatory is required for doing so. The license management for professional licenses requires that users are activated on our license management system (hosted on https://redink.ai) using a user ID; the users choose which user ID (e.g., e-mail address, other unique, non-identifying ID) they want to use; the add-ins will regularly contact the license management server to check whether the license is still valid (if the users work for you, please inform them of this privacy notice). Other offers and services (e.g., newsletter) may also require registration (directly with us or via our external login service providers). For this purpose, we process the data provided during the respective registration. Furthermore, we may also collect personal data about you during the use of the offer or service, e.g. data about how you use our services and products and preferences or communication data. If required, we will provide you with further information about the processing of this data.
- Communication:We process personal data so that we can communicate with you as well as with third parties, by e-mail, telephone, letter, or other means (e.g., to answer inquiries, in the context of legal advice and representation as well as pre-contractual measures or execution of contracts). For this purpose, we process in particular the content and metadata of the communication as well as your contact data, but also image and audio recordings of video or phone calls. In the event of an audio or video recording of the communication (e.g. in the course of a video conference), we will inform you separately, and you are free to inform us if you do not wish to be recorded or to terminate the communication. If we need or wish to confirm your identity, we may collect additional data (e.g., a copy of an ID). We may also send information about events, changes, news about our firm, or similar information. This may, e.g., take the form of newsletters and other regular communication (especially electronically, via mail, and via telephone). You have the option to refuse or withdraw your consent to communications for marketing purposes at any time (see our contact details in Section 2).
- Administration and performance of contracts: We process personal data in order to comply with our contractual obligations to our clients and other contractual partners (e.g., suppliers, service providers, project partners), to perform our contracts, and to ensure that our customers and other contract partners comply with their obligations. This includes the operation of a license management system that tracks our customers’ licenses including user activations, as described above. This involves us collecting related personal data, where users choose to identify them (e.g., by their e-mail address)
- Operation of our websites: In order to operate our websites in a secure and stable manner, we collect technical data, such as IP address, information about the operating system and settings of your end device, region, time and type of use. Additionally, we use cookies and similar technologies. More information about this can be found in Section 8.
- Improving our offerings: We may collect and process personal data about use in connection with us providing you support or solving problems or issues you may have with Red Ink (and related products and services) for such purposes. In order to continuously improve our websites, our services, products and other (electronic) offerings (e.g., other websites, apps, online tools), we may collect data about your use of them and preferences by analyzing, for example, how you navigate through our websites and how you interact with our social media profiles and our apps and online tools or how you use or like our services. For this purpose, we also process direct or indirect feedback from you regarding our website and our tools (e.g. comments, emails or other statements that are directly addressed to us or of which we become aware of otherwise) as well as other feedback regarding our services. With regard to the logging, data disclosure by using Red Ink and our data collection through Red Ink (if any), see the user’s manualfor more details (in particular the FAQ).
- Security purposes and access controls:We process personal data to ensure and continuously improve the appropriate security of our IT and other infrastructure (e.g., buildings). This includes, for example, monitoring and controlling electronic access to our IT systems as well as physical access to our premises, analyzing and testing our IT infrastructures, performing system and error checks, and creating backup copies. For documentation and security purposes (preventive measures and analysis of incidents), we also maintain access logs or visitor lists for our premises and use surveillance systems (e.g., security cameras). At the entrances to our buildings we may use video surveillance systems
- Compliance with laws, directives and recommendations of authorities as well as internal regulations (“Compliance”): We process personal data to comply with applicable law (e.g., anti-money laundering, tax law obligations), self-regulations, certifications, industry standards, our corporate governance and for internal and external investigations in which we are a party (e.g., by a law enforcement or supervisory authority or an appointed private body).For this purpose, we collect in particular master and behavioral data as well as financial data, but also all other data whose collection appears necessary or useful to us in order to fulfill our obligations with regard to our compliance.
- Risk management and corporate governance: We process personal data as part of our risk management (e.g., to protect against criminal activities) and corporate governance. This includes, among other things, our operational organization (e.g., resource planning) and corporate development (e.g., acquisition and sale of parts of businesses or companies). For this purpose, we process in particular master data, contract data, registration data and technical data, but also behavioral and communication data.
- Audit and surveillance: We may also process personal data about you in connection with audits we may perform in connection with verifying your compliance with the license of Red Ink.
Other purposes: Other purposes include, for example, fraud prevention, statistics, training and educational purposes and administrative purposes (e.g., accounting). We may listen to or record telephone or video conferences for purposes of training, evidence, and quality assurance. In such cases, we will notify you separately (e.g., by displaying a notice during the relevant video conference) and you are free to let us know if you do not wish to be recorded or to terminate the communication (if you do not wish your image recorded, please switch off your camera). In addition, we may process personal data for the organization, implementation, and follow-up of events, such as, in particular, lists of participants and the content of presentations and discussions, but also image and audio recordings made during these events. Protection of other legitimate interests is also one of the further purposes, which cannot be listed exhaustively.
4. Where does the data come from?
- From you:You provide us with much of the data we process (e.g., in the context of our attorney-client relationship or other services, your use of our websites, and your communication with us). You are not obliged or required to disclose your data, with certain exceptions (e.g., legal obligations). You must for example provide us with certain data to use our services or to enter into contracts with us. The use of our websites is also impossible without data processing. Also, obtaining, activating and using professional licenses requires you to provide us with the relevant data, including unique user IDs (which, however, can also be identifiers that are not identifiable to us). The same applies if you wish to obtain other services or products from us or ask us to provide you with support or other information.
- From third parties: We may collect data from public sources (e.g., the media, the Internet including social media, debt collection registers, commercial and other public registers) or receive such data from public authorities, your employer or principal who has a business relationship with us or otherwise deals with us, as well as from other third parties (e.g., clients, service providers that provide us leads, credit agencies, address brokers, associations, contractual partners, Internet analysis services). This includes, in particular, the data that we process in the course of initiating, concluding and performing contracts, as well as data from correspondence and other communication with third parties, but also all other categories of data pursuant to Section 3.
5. With whom do we share your data?
In connection with the provisions set forth in Section 3 we disclose your personal data in particular to the categories of recipients listed below. If necessary, we obtain your consent for this or will have the competent supervisory authorities release us from our professional obligation of confidentiality.
- Service Providers:We work with service providers in Switzerland and abroad who (i) process data on our behalf (e.g., IT providers, such as Hostpoint, Brevo, Microsoft), (ii) process data under joint responsibility with us or (iii) process data under their own responsibility that they have received from us or collected on our behalf. Service providers include e.g., IT providers, support- and training providers, payment service providers, banks, insurance companies, debt collection companies, credit agencies, list brokers, advertising companies, law firms or consulting companies. As a general rule, we conclude contracts with our processors regarding the processing and protection of personal data. Regarding the Red Ink license, we use a payment and invoicing service provider located in Switzerland, Payrexx AG (https://payrexx.com), to handle your purchases. When you purchase a subscription, we pass the relevant information to such provider, who will process the information and any personal data included in it as a sole controller under its own responsibility. We do not see your credit card details. See the provider’s data privacy notice for more details. Our website and license management system runs on servers operated by Hostpoint AG (https://www.hostpoint.ch) in Switzerland, using various WordPress applications. For newsletters and emailing, we work with Sendinblue GmbH/Sendinblue SAS (https://www.brevo.com) in Germany/France.
- Clients and other contractual partners: This mainly includes our clients and our other contractual partners for whom a transfer of your data arises from the contract (e.g., because you work for a contractual partner or they provide services for you). This category of recipients also includes entities with which we cooperate, such as IT, support and training providers in Switzerland and abroad. The recipients process the data under their own responsibility, partly as sole controllers, partly as joint controllers with us.
- Authorities and courts: We may disclose personal data to offices, courts, and other authorities in Switzerland and abroad if this is necessary for the fulfillment of our contractual obligations and, or if we are legally obliged or entitled to do so, or if this appears necessary to protect our interests. The recipients are themselves responsible for the processing of the data.
- Other persons:This refers to other cases where the inclusion of third parties results from the purposes according to Section 3. This includes, for example, delivery addressees or payment recipients specified by you, third parties in the context of agency relationships (e.g., your lawyer or your bank) or persons involved in official or legal proceedings. We may also disclose your personal data to our supervisory authority. You may also be affected if we cooperate with the media (including publishers of business directories) and transmit content to them (e.g., photos, contact details). We may also disclose personal data about you in the context of publications (e.g., in the form of citations and case reports). In the course of business development, we may sell or acquire businesses, parts of businesses, assets or companies, or enter into partnerships, which may also result in the disclosure of data (including data about you, e.g., as a client or supplier or as their representative) to the parties involved in these transactions. Communications with our competitors, industry organizations, associations, market observers and other bodies may also involve the exchange of your data.
All these categories of recipients may involve third parties, so that your data may also become accessible to them. We can restrict processing by certain third parties (e.g., IT providers), but not by others (e.g., authorities, banks, etc.).
We also allow certain third parties to collect personal data from you on our websites and at events organized by us, also under their own responsibility (e.g., media photographers, providers of tools that we have embedded on our websites or apps [if any], etc.). These third parties are solely responsible for the data processing insofar as we are not decisively involved in these data collections. If you have any concerns or wish to assert your data protection rights, please contact these third parties directly (see Section 8).
6. Is your personal data also disclosed abroad?
We process and store personal data mainly in Switzerland and the European Economic Area (EEA). However, depending on the circumstances personal data may potentially be processed in any country in the world, for instance through subcontractors of our service providers or in proceedings before foreign courts or authorities.
If a recipient is located in a country without adequate statutory data protection, we require the recipient to undertake to comply with data protection (for this purpose, we use the revised standard contractual clauses of the European Commission, which can be accessed via https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?, if necessary with the required adaptations for Switzerland), unless the recipient is subject to a legally accepted set of rules to ensure data protection. We may also disclose personal data to a country without adequate statutory data protection without entering into a separate contract for this purpose if we can rely on an exception clause. An exception may apply in particular in the case of legal proceedings abroad, but also in cases of overriding public interests or if the performance of a contract that is in your interest requires such disclosure (e.g., if we communicate with you through platforms such as GitHub), if you have consented, if it is not possible to obtain your consent within a reasonable period of time and the disclosure is necessary to protect your life or physical integrity or that of a third party, or if it concerns data made publicly available by you, the processing of which you have not objected to. We may also rely on the exception for data from a register provided for by law (e.g., commercial register) to which we have been legitimately granted access.
7. What are your rights?
You have certain rights in connection with our data processing. In accordance with applicable law, you may, in particular, request information about the processing of your personal data, have inaccurate personal data rectified, request the deletion of personal data, object to data processing, request the release of certain personal data in a standard electronic format or its transfer to other data controllers or revoke consent with effect for the future, insofar as our processing is based on your consent.
If you wish to exercise any of the above rights against us, please contact us. Our contact details can be found in Section 2. To prevent misuse, we must verify your identity (e.g., with a copy of your ID, if necessary).
Please note that conditions, exceptions, or limitations apply to these rights (e.g., to protect third parties or trade secrets or due to our professional obligation of confidentiality). We reserve the right to redact copies or to supply only excerpts for reasons of data protection or confidentiality.
8. How are cookies, similar technologies and social media plug-ins used on our websites?
We ourselves do not use any marketing cookies on this website. However, when using our websites (incl. newsletters), data is generated that is stored in logs (especially technical data). In addition, we may use cookies and similar technologies (e.g., pixel tags or fingerprints) to recognize website visitors, evaluate their behavior, recognize preferences, and for security purposes. A cookie is a small file that is transmitted between your system and the server and enables the recognition of a specific device or browser.
You can set your browser to automatically reject, accept or delete cookies. You can also disable or delete cookies on a case-by-case basis. You can find out how to manage cookies in your browser in the help menu of your browser.
Both the technical data we collect and cookies generally do not contain any personal data. However, personal data that we or third-party providers commissioned by us store about you (e.g., if you have a user account with us or these providers) may be linked to the technical data or to the information stored in and derived from cookies, and thus possibly to your identity.
9. What else should be considered?
We do not track the use of Red Ink when you install and operate it in your environment. Red Ink does connect to our servers to check for and obtain new versions, the two helper files and and help information (“Help me, Inky”). Since we log access to our servers, such connections appear in our logfiles (without names, of course). You can turn these connections off by using the corresponding configuration parameters (see the manual).
We do not presume that the EU General Data Protection Regulation (“GDPR”) is applicable to data processing by us. Nonetheless, if the GDPR should apply to certain data processing on an exceptional basis, this Section 10 shall apply exclusively for the purposes of the GDPR and the data processing subject to it.
In this case, we base the processing of your personal data in particular on the fact that
- as set out in Section 3 it is necessary for the initiation, conclusion and performance of contracts and their administration and enforcement (article 6 para. 1 lit. b GDPR);
- it is necessary for the protection of legitimate interests of us or of third parties as set out in Section 3, e.g., for communication with you or third parties, to operate our websites, to improve our electronic offers and registration for certain offers and services, for security purposes, for compliance with the law and internal regulations, for our risk management and corporate governance, and for other purposes such as training and education, administration, evidence and quality assurance, organization, implementation and follow-up of events and for the protection of other legitimate interests (article 6 para. 1 lit. f GDPR);
- it is required or permitted by law due to our mandate or position under the law of the EEA or a member state (article 6 para. 1 lit. c GDPR) or is necessary to protect your vital interests or those of other natural persons (article 6 para. 1 lit. d GDPR);
- you have separately consented to the processing, e.g., via a corresponding declaration on our websites (article 6 para. 1 lit. a and article 9 para. 2 lit. a GDPR).
We would like to point out that we process your data for as long as it is necessary for our processing purposes (cf. Section 3), the legal retention periods and our legitimate interests, in particular for documentation and evidence purposes, or storage is technically required (e.g. in the case of backups or document management systems). If there are no legal or contractual obligations or technical reasons to the contrary, we generally delete or anonymize your data after the storage or processing period has expired as part of our usual processes and in accordance with our retention policy.
If you do not disclose certain personal data to us, this may mean that it is not possible to provide the related services or conclude a contract. In principle, we indicate which personal data requested by us are mandatory.
The right to object to the processing of your data, described in Section 7, applies in particular to data processing for the purpose of direct marketing.
If you do not agree with our handling of your rights or data protection, please let us know (see contact details in Section 2). If you are in the EEA, you also have the right to complain to the data protection supervisory authority in your country. You can find a list of authorities in the EEA here: edpb.europa.eu/about-edpb/about-edpb/members_en.
10. Can this Privacy Notice be changed?
This Privacy Notice is not part of any contract with you. We may amend this Privacy Notice at any time. The version published on this website is the current version.
Subscribe to our mailing list
We allow anyone to subscribe to our news mailing list. You can at any time ask to be removed from it, either by mailing at info@redink.ai or through an unsubscribe link at the end of each mail. As a subscriber you will be automatically included in the mailing list, unless you opt-out, which you can do at any time. In any event, you will get notifications concerning your subscription, if you have one, including important product updates (e.g., in case of security issues).
If you have any questions, please contact us at info@redink.ai or info@lawdigitalag.ch.