We, the Codos Foundation, a non-profit foundation with its registered office at Bahnhofstrasse 20, 6300 Zug, Switzerland, entered in the Commercial Register of the Canton of Zug under number CHE-340.055.782. ("Codos", "we" or "us") take the protection of your Personal Data seriously and would like to inform you about data protection at Codos.
As part of our responsibility under data protection law, additional obligations have been imposed on us by the entry into force of the EU General Data Protection Regulation (Regulation (EU) 2016/679; hereinafter: "GDPR") in order to ensure the protection of Personal Data of the person affected by processing (we also refer to you as the data subject as "Commuter", "you", "you" or "Data Subject").
Insofar as we decide either alone or jointly with others on the purposes and means of data processing, this includes above all the obligation to inform you transparently about the type, scope, purpose, duration and legal basis of the processing (Art. 13 and Art. 14 GDPR). With this declaration (hereinafter: "Privacy Policy") we inform you about the way in which your Personal Data is processed by us.
B. General Information
1. Definitions
In accordance with Art. 4 GDPR, this Privacy Policy is based on the following definitions:
• "Personal Data" (Art. 4 No. 1 GDPR) means any information relating to an identified or identifiable natural person ("Data Subject"). A person is identifiable if they can be identified directly or indirectly, in particular by reference to an identifier such as a name, an identification number, an online identifier, location data or information relating to their physical, physiological, genetic, mental, economic, cultural or social identity. The identifiability can also be provided by linking such information or other additional knowledge. The origin, form or embodiment of the information is irrelevant (photos, video or audio recordings can also contain personal data).
• "Processing" (Art. 4 No. 2 GDPR) means any operation which is performed on Personal Data, whether or not by automated means (i.e. using technical specifications). This includes, in particular, the collection (i.e. acquisition), recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of Personal Data, or alteration of the purposes for which they were originally processed.
• "Controller" (Art. 4 No. 7 GDPR) means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
• "Processor" (Art. 4 No. 8 GDPR) is a natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller, in particular in accordance with the controller's instructions (e.g. IT service provider). In terms of data protection law, a Processor is in particular not a third party.
• "Third Party" (Art. 4 No. 10 GDPR) means any natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorized to process Personal Data.
• "Consent" (Art. 4 No. 11 GDPR) of the Data Subject means any freely given, specific, informed and unambiguous indication of the Data Subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.
2. Amendment of this Privacy Policy
(1) In recognition of the further development of data protection law and technological or organizational changes, this Privacy Policy is regularly reviewed to determine whether it needs to be adapted or supplemented. You will be informed of any changes without undue delay.
(2) This Privacy Policy is valid as of 1 April 2025.
3. Commuter’s Obligation to provide Personal Data
As stipulated in the T&Cs, we cannot offer our services without processing your Personal Data.
C. Processing of your Personal Data
1. Collection of your Personal Data
(1) When you use the Codos App, we collect your Personal Data. Such Personal Data is exclusively processed in the European Union and the Swiss Confederation.
(2) This Personal Data includes (but is not limited to), your name, your location data, your IP address, and e-mail address.
2. Legal Basis of Processing
(1) In principle, any Processing of Personal Data is prohibited by law and is only permitted if the Processing falls under one of the following justifications:
• Art. 6 para. 1 sentence 1 lit. a GDPR ("Consent"): Where the Data Subject has voluntarily, in an informed and unambiguous manner, indicated by a statement or other unambiguous affirmative act that he or she consents to the Processing of Personal Data relating to him or her for one or more specific purposes.
• Art. 6 para. 1 sentence 1 lit. b GDPR: If the Processing is necessary for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract.
• Art. 6 para. 1 sentence 1 lit. c GDPR: If Processing is necessary for compliance with a legal obligation to which the Controller is subject (e.g. a legal obligation to retain data).
• Art. 6 para. 1 sentence 1 lit. d GDPR: If Processing is necessary in order to protect the vital interests of the Data Subject or another individual.
• Art. 6 para. 1 sentence 1 lit. e GDPR: If the Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller. Or
• Art. 6 para. 1 sentence 1 lit. f GDPR ("Legitimate Interests"): If the Processing is necessary for the purposes of the legitimate (in particular legal or economic) interests pursued by the Controller or by a Third Party, except where such interests are overridden by the interests or rights of the Data Subject (in particular where the data subject is a minor).
(2) For the processing operations carried out by us, we indicate below the applicable legal basis in each case. Processing may also be based on more than one legal basis.
3. Data Processing during the Download of the Codos App
(1) When you download the Codos App, certain personal data required for this purpose will be transmitted to the relevant application download platform (e.g. Apple App Store, Google Play).
(2) In particular, the e-mail address, the username, the customer number of the downloading account, the individual device identification number, payment information and the time of the download are transmitted to the application download platform during the download.
(3) We have no influence on the collection and processing of this data; it is carried out exclusively by the application download platform you have selected. Accordingly, we are not responsible for this Processing; the responsibility for this lies solely with the application download platform.
4. Processing of Personal Data during the Use of the Codos App
(1) Inevitably, we can only provide you with the benefits of the Codos App if we collect certain personal data required for the operation of the Codos App when you use it.
(2) We only collect this Personal Data if this is necessary for the fulfillment of the contract between you and us (Art. 6 para. 1 lit. b GDPR). Furthermore, we collect this Personal Data if this is necessary for the functionality of the Codos App and your interest in the protection of your Personal Data does not outweigh this (Art. 6 para. 1 lit. f GDPR) or if you consent to the collection and processing (Art. 6 para. 1 lit. a GDPR).
(3) We process the following Personal Data from you:
• Device Information: This includes the IP address, device OS, device OS version, device type, device- specific settings and app settings as well as app properties, the date and time of the retrieval, time zone the amount of data transferred and the message as to whether the data exchange was complete, app crash. These data are processed to enable the technical operation of the Codos App.
• Personal Data that you make available to us: To use the Codos App, you need to create a Commuter Account, that contains personal data.
• Personal Data with your Consent: We process other Personal Data if you allow us to do so.
• Personal Data contained in contact forms: When contact forms are used, the Personal Data transmitted through them is processed (e.g. gender, surname and first name, address, company, e-mail address and the time of transmission).
5. Storage of Personal Data (Duration)
(1) We delete your Personal Data as soon as it is no longer required for the purposes for which we collected or used it (see C. 4., 5., 6.). As a rule, we store your Personal Data for the duration of the use of the Codos App or the contractual relationship between you and us. Your Personal Data will generally only be stored on our servers in Frankfurt a.M., Germany, subject to any disclosure in accordance with the provisions in F. 1., 2. and 3.
(2) However, Personal Data may be stored beyond the specified period in the event of an (impending) legal dispute with you or other legal proceedings.
(3) Third Parties engaged by us (see F. 1.) will store your data on their system for as long as is necessary for us in connection with the provision of the service in accordance with the respective order.
(4) Legal requirements for the storage and deletion of Personal Data remain unaffected by the above. If the storage period stipulated by the statutory provisions expires, the Personal Data will be blocked or deleted unless further storage by us is necessary and there is a legal basis for this.
6. Security of Personal Data
(1) We use suitable technical and organizational security measures to protect your Personal Data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by Third Parties, taking into account the state of the art, the implementation costs and the nature, scope, context and purpose of the processing as well as the existing risks of a data breach (including its probability and effects) for the Data Subject. Our security measures are continuously improved in line with technological developments.
(2) We will be happy to provide you with more detailed information on request. Please contact us at dpo@codos.network.
7. No Automated Decision-Making / Profiling
We do not intend to use Personal Data collected from you for automated decision-making (including profiling).
8. Change of Purpose
(1) Your Personal Data will only be processed for purposes other than those described if this is permitted by law or if you have consented to the changed purpose of the data processing.
(2) In the event of further Processing for purposes other than those for which the Personal Data was originally collected, we will inform you of these other purposes prior to further Processing and provide you with all other relevant information.
D. Responsibility for Personal Data
1. Controller and Contact Details
(1) We are the Controller responsible for the Processing of your Personal Data within the meaning of Art. 4 No. 7 GDPR
Codos Foundation, Bahnhofstrasse 20, 6300 Zug, Switzerland [link].
(2) Our Data Protection Officer is available to answer any questions you may have and to act as your contact person on the subject of data protection. The contact of the Data Protection Officer is dpo@codos.network.
(3) Please contact the Data Protection Officer in particular if you wish to assert the rights to which you are entitled, which are explained in Chapter G, against us.
(4) If you have any further questions or comments regarding the Processing of your Personal Data, please also contact the Data Protection Officer.
2. Data Processing when making Contact
(1) If you contact us by e-mail or via a contact form, we will store your e-mail address, your name and all other Personal Data that you have provided in the course of contacting us so that we can contact you to answer your question.
(2) We delete these Personal Data as soon as storage is no longer necessary. If there are statutory retention periods, the data will remain stored, but we will restrict the processing.
F. Data Processing by Third Parties
1. Data Processing
(1) We may use contracted service providers (Processors) for individual functions of the Codos App. These service providers only act in accordance with our instructions and are contractually obliged to comply with data protection regulations in accordance with Art. 28 GDPR.
(2) The following categories of recipients, which are usually Processors, may have access to your Personal Data:
• We use data processing service providers for the operation of the Codos App and the processing of data stored or transmitted by the systems (e.g. for data center services, payment processing, IT security). The legal basis for the transfer is then Art. 6 para. 1 sentence 1 lit. b or lit. f GDPR, insofar as these are not Processors;
• Government bodies/authorities, insofar as this is necessary to fulfill a legal obligation. The legal basis for the transfer is then Art. 6 para. 1 sentence 1 lit. c GDPR;
• Persons engaged to carry out our business operations (e.g. auditors, banks, insurance companies, legal advisors, supervisory authorities, parties involved in company acquisitions or the establishment of joint ventures). The legal basis for the disclosure is then Art. 6 para. 1 sentence 1 lit. b or lit. f GDPR.
• Participants of the MESTRAJETS study in Geneve, Switzerland. In particular, BMH Bureau Mobil’homme Sàrl, Avenue de Sévelin 28, 1004 Lausanne, Switzerland.
(3) Other than the cases named in sec. (2) above, we will only pass on your Personal Data to Third Parties if you have given your express consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR.
(4) If your personal data is passed on by us to our subsidiaries or is passed on to us by our subsidiaries (e.g. for advertising purposes), this is done on the basis of existing Processing Relationships.
2. Transfer of Personal Data outside the EEA
(1) As part of our business relationships, your Personal Data may be passed on or disclosed to third-party companies. These may also be located outside the European Economic Area (EEA), i.e. in third countries. Such Processing takes place exclusively to fulfill contractual and business obligations and to maintain your business relationship with us (legal basis is Art. 6 para. 1 lit. b or lit. f in each case in conjunction with Art. 44 ff. GDPR). We will inform you about the respective details of the transfer at the relevant points below.
(2) The European Commission certifies that some third countries have a level of data protection comparable to the EEA standard by means of so-called adequacy decisions (a list of these countries and a copy of the adequacy decisions can be found here: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en). However, in other third countries to which Personal Data may be transferred, there may not be a consistently high level of data protection due to a lack of legal provisions. If this is the case, we ensure that data protection is adequately guaranteed. This is possible via binding corporate rules, standard contractual clauses of the European Commission for the protection of personal data pursuant to Art. 46 para. 1, 2 lit. c GDPR (the standard contractual clauses of 2021 are available at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0915&locale-en), certificates or recognized codes of conduct. Please contact our data protection officer (see D. 1.) if you would like more information on this.
3. Legal Obligation for Transmitting Personal Data
We may be subject to a special legal or statutory obligation to provide the lawfully processed Personal Data to third parties, in particular public authorities (Art. 6 para. 1 sentence 1 lit. c GDPR).
G. Your Rights
1. Right to Information
(1) You have the right to obtain information from us about the Personal Data concerning you within the scope of Art. 15 GDPR.
(2) This requires an application from you, which must be sent either by e-mail or by post to the addresses given above (see D. 1.).
2. Right of Objection to Data Processing and Withdrawal of Consent
(1) In accordance with Art. 21 GDPR, you have the right to object at any time to the Processing of Personal Data concerning you. We will stop Processing your Personal Data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or if the processing serves the establishment, exercise or defense of legal claims.
(2) Pursuant to Art. 7 (3) GDPR, you have the right to withdraw your Consent once given (even before the GDPR came into force, i.e. before May 25, 2018) - i.e. your voluntary, informed and unequivocal declaration or other unambiguous confirmatory act that you consent to the Processing of the Personal Data concerned for one or more specific purposes - at any time, if you have given such Consent. The consequence of this is that we may no longer continue the Processing based on this Consent in the future.
(3) In this regard, please contact our Data Protection Officer (see D. 1.).
3. Right to Rectification and Erasure
(1) Insofar as Personal Data concerning you is incorrect, you have the right under Art. 16 GDPR to demand that we correct it immediately. If you wish to make such a request, please contact our Data Protection Officer (see D. 1.).
(2) Under the conditions set out in Art. 17 GDPR, you have the right to request the erasure of Personal Data concerning you. Please send your request to our Data Protection Officer (see D. 1.). In particular, you have the right to erasure if the data in question is no longer necessary for the purposes Processing, if the data retention period (see C. 7.) has expired, if there is an objection (see G. 2.), or if the processing is unlawful.
4. Right to Restriction of Processing
(1) In accordance with Art. 18 GDPR, you have the right to demand that we restrict the Processing of your Personal Data.
(2) Please send your application to our Data Protection Officer (see D. 1.).
(3) You have the right to restriction of Processing in particular if the accuracy of the Personal Data is disputed between you and us; in this case, you have this right for the period of time required to verify the accuracy. The same applies if the successful exercise of a right to object (see G. 2.) is still disputed between you and us. You also have this right in particular if you have a right to erasure (see G. 3.) and you request restricted processing instead of erasure.
5. Right to Data Portability
(1) In accordance with Art. 20 GDPR, you have the right to receive the Personal Data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format in accordance with Art. 20 GDPR.
(2) Please send your application to our Data Protection Officer (see D. 1.).
6. Right of Lodging a Complaint with the Supervisory Authority
(1) In accordance with Art. 77 GDPR, you have the right to complain to the competent supervisory authority about the Processing of your Personal Data.
(2) You can reach the competent supervisory authority using the following contact details: Bavarian Data Protection Authority (Bayrisches Landesamt für Datenschutzaufsicht).
7. Rights of Swiss Residents
(1) Under Articles 25 et seq. of the revFADP, Data Subjects (i.e., individuals whose Personal Data is processed) are entitled to exercise certain rights concerning their Personal Data. These rights may include:
a) Right of Access
Data Subjects have the right to request information as to whether and which Personal Data relating to them is being processed, and to obtain a copy of such data.
b) Right to Rectification
Data Subjects have the right to request the correction or completion of any Personal Data that is inaccurate or incomplete.
c) Right to Deletion (Erasure)
Data Subjects have the right to request the deletion or destruction of their Personal Data under certain conditions, for example where:
• The data is no longer needed for the purposes for which it was collected;
• The data was processed unlawfully;
• The Data Subject has withdrawn consent (if consent was the legal basis for processing), and there is no other lawful basis for continued processing.
d) Right to Restrict Processing
Where provided by law, Data Subjects may request the restriction of processing rather than the deletion of their Personal Data (e.g., if the accuracy of the data is contested and requires verification).
e) Right to Data Portability
To the extent required by the revFADP, where the processing is based on the Data Subject’s consent or is necessary for the performance of a contract, and is carried out by automated means, the Data Subject may request to receive the Personal Data he or she provided in a structured, commonly used, and machine-readable format or have it transferred to another data controller, where technically feasible.
(2) How to Exercise those Rights
If you wish to exercise any of the above rights or have any questions regarding the processing of your Personal Data, please contact us at: dpo@codos.network
(3) Exceptions and Limitations
Please note that the above rights are subject to limitations and exceptions provided by the revFADP and other applicable laws. In certain cases, we may be entitled to refuse or limit the exercise of these rights, for example, if fulfilling a request would infringe upon the rights of other individuals or if legal obligations require ongoing retention of certain data.
Copyright 2025 © All rights Reserved.