bau-referenzen.ch

Legal

Privacy Policy

Information on how your personal data is handled when you visit our website.

Controller

This page explains how your personal data is handled when you visit our website. In order to provide the functions and services of our website, we need to process personal data about you. Below we explain which data we process, why this is necessary, and what rights you have regarding your data.

The controller for the processing of personal data on this website is (see also the imprint): Losys GmbH, Europastrasse 30, CH – 8152 Glattbrugg, Switzerland. Telephone +41 44 503 93 30, e-mail info@losys.ch.

Contact for data protection matters: you can reach us at any time with any question about data protection at info@losys.ch.

Applicable law

We are based in Switzerland. Your data is therefore processed primarily under the Swiss Federal Act on Data Protection (revDSG) and its ordinance (DSV). Under Swiss law, the processing of personal data by private persons is permitted in principle, but it must observe the principles of Art. 6 revDSG — lawfulness, good faith, proportionality, purpose limitation, accuracy and transparency. A specific justification within the meaning of Art. 31 revDSG is only required where processing would infringe the personality of the data subject.

Our offering is also addressed to users in the European Union. Where the European General Data Protection Regulation (GDPR) applies to a processing operation (Art. 3(2) GDPR), we additionally state the legal basis required there. The GDPR references therefore sit alongside Swiss law rather than replacing it; where both regimes apply, we meet the stricter requirement.

We have not designated a representative in the European Union pursuant to Art. 27 GDPR. For matters from the EU, please contact us directly using the contact details above.

Informational Use

If you use this website without otherwise transmitting data to us (for example via the contact form, an enquiry to a company, or the registration of a company profile), we only process technically necessary data that your browser transmits automatically to our server: IP address, date and time of the request, the address requested, browser type, operating system and the referring page. This information is technically required in order to display our website to you, and it also appears in the operational logs we keep for troubleshooting and to defend against attacks and abusive use.

A network service provider acts as the entry point in front of our servers (content delivery network). It receives your request, encrypts the connection and protects the portal against automated attacks; in doing so it processes your IP address and sets one technically necessary cookie. Details can be found in the sections “Cookies and local storage” and “Recipients and processors”.

We process this data to operate, secure and stabilise our offering. This is proportionate processing within the meaning of Art. 6 revDSG; where the GDPR applies, we base it on our legitimate interest under Art. 6(1)(f) GDPR.

Cookies and local storage

Cookies are small text files that a website can store on your device via your browser. Our portal largely does without them: there are no user accounts and no login for visitors, and our own reach measurement deliberately works without cookies.

Without your consent, only the following technically necessary cookies are set:

Your decision regarding the advertising services that require consent is deliberately not stored in a cookie, but in your browser’s local storage (“localStorage”, entry “portal-consent”). This information does not leave your device and is not transmitted to us. You can change or withdraw your decision at any time via the “Cookie settings” link in the footer.

Beyond those listed above, cookies are set exclusively by the services named in the section “Advertising reach measurement” — and only if you have consented beforehand.

  • “bau-referenzen-session” (lifetime 2 hours). Session cookie of our application. It holds the state of your visit together — for us essentially your language choice and the protection of the forms. Your language choice is held in this session; there is no additional cookie for it.
  • “XSRF-TOKEN” (lifetime 2 hours). Protects the forms of the portal against abusive submission from third-party websites (cross-site request forgery).
  • “__cf_bm” (lifetime 30 minutes). Set by our network service provider Cloudflare in order to distinguish automated access (bots) from human visitors. The cookie serves this security function only, contains no identifier of your person and is not used for advertising or profiling. Further information: Cloudflare on “__cf_bm”.

These cookies are necessary for the operation and security of the website; no consent is required for them.

In one place we additionally use your browser’s local storage: after an order for image usage rights has been submitted, your device remembers the contact and billing details entered so that you do not have to type them in again for a further order. The details do not leave your device; you will find the specifics, and the way to delete them again, in the section “Ordering image usage rights”.

Irrespective of this, you can delete stored cookies at any time via your browser settings, or prevent them from being stored at all. In that case some functions of our website may not be available.

Contact Form

You can reach us directly via our contact form. If you use it, we process and store the details you enter: name, company, e-mail address, telephone number, subject and your message. In addition, we store the IP address from which the submission is made and the time of submission — this serves to prevent abusive and automated submissions. We use this data exclusively to handle and answer your enquiry; we do not pass it on to third parties in doing so.

Your enquiry is delivered to us by e-mail, involving the service providers for e-mail delivery and e-mail mailboxes named in the section “Recipients and processors”. We need the details marked as mandatory in order to handle and answer your enquiry; without them, submission is not possible. All other details are voluntary.

The processing is necessary to answer your enquiry and is therefore covered by Art. 6 revDSG. Where the GDPR applies, the legal basis is your consent under Art. 6(1)(a) GDPR; if your enquiry serves to prepare the conclusion of a contract, Art. 6(1)(b) GDPR is an additional legal basis.

This is to be distinguished from an enquiry to an individual company — in that case your details are deliberately forwarded. Details in the following section.

Enquiries to companies

Reference projects of construction companies are published on our portal. You can contact each of these companies directly via the “Enquiry” button. Unlike the general contact form, this is expressly a disclosure to a third party: we forward your enquiry by e-mail to the company you have selected — that is the purpose of this function.

The details you enter are transmitted — name, e-mail address, optionally your company, your request and your message — together with the information which reference project your enquiry relates to.

We additionally store the same details with us, together with the IP address from which the submission is made and the time of submission. We do this in order to be able to trace and evidence the delivery and to prevent abusive or automated submissions.

The receiving company decides independently on any further processing of your data and is solely responsible for it; its own privacy policy applies in that respect. We have no influence on how it handles your data.

The basis is your consent, which you give expressly before sending (Art. 6(6) and Art. 31(1) revDSG; Art. 6(1)(a) GDPR). If your enquiry serves to initiate a contract, Art. 6(1)(b) GDPR is an additional legal basis. Without the forwarding, the enquiry cannot fulfil its purpose.

Registering a company profile

Construction companies can register their own company profile on the portal. This form is addressed exclusively to companies. There is no user account for visitors on the portal, and no login is required in order to use it.

When you register, we process and store: company name, postcode, town and country, the name and role of the contact person, e-mail address, telephone number and the company logo you upload. In addition, we store the time at which the general terms and conditions were accepted, the IP address from which the registration is made and the time of your confirmation. We need this evidence in order to be able to document the registration and to detect registrations made in the name of other companies.

After submission you receive an e-mail containing a confirmation link; the registration only counts as received once you have confirmed it (double opt-in). To verify the details, we retrieve the publicly available entry in the Swiss commercial register for the company name and town provided, and store the result together with the registration; the query is made via Zefix, the Swiss federal Central Business Name Index.

The processing serves to review and handle your registration and therefore the initiation and performance of a contractual relationship (Art. 6 revDSG; Art. 6(1)(b) GDPR where applicable).

Ordering image usage rights

For individual reference projects you can acquire usage rights to the images shown there. If you place an order, we process and store the details you enter: salutation, first name and surname, company, street, postcode, town and country, e-mail address and telephone number. In addition, we store the IDs of the images ordered, the calculated amount, the address of the portal page from which you ordered, your IP address and the time at which you agreed to the price, the general terms and conditions and this privacy policy. IP address and time also serve to prevent abusive and automated orders.

After submitting, you receive an e-mail with a confirmation link; the order only becomes binding once you confirm it (double opt-in). If the confirmation does not arrive, we remind you once by e-mail. The providers for e-mail dispatch and e-mail mailbox named in the section “Recipients and processors” are involved in sending it. We use the details to check your order, issue the usage rights to the company named, provide you with the images and invoice the amount. We do not pass them on to third parties in doing so.

So that you do not have to type in your address again for a further order, your browser stores the contact and billing details you entered in the local storage of your device after an order has been submitted (“localStorage”, entry “portal-image-license-contact”). These details remain on your device and are only transmitted to us again with your next order; your consents to the price, the terms and conditions and data protection are never remembered. In the order form you can overwrite the suggested values at any time and remove them again via “Delete stored details”.

The processing is necessary for initiating and handling the purchase (Art. 6 revFADP; Art. 6(1)(b) GDPR, where applicable). We need the details marked as mandatory in order to issue and invoice the usage rights; without them an order is not possible.

Content published on the portal

The portal displays reference projects and company profiles. The details used for this — project descriptions, images, company information — come from two sources. On the one hand, the companies presented maintain their details themselves in our reference management system and decide there what is published; the respective company is responsible for the accuracy, currency and lawfulness of this content. On the other hand, Losys GmbH researches and photographs reference projects itself; we are responsible for these presentations created by us. Our own photographs are general exterior shots of the buildings and do not show any persons.

Where we research projects ourselves, we obtain the details from generally accessible sources. The legal basis is our overriding interest in a directory of construction references that is as complete and up to date as possible. A company presented may at any time take over a presentation created by us and adapt it in its own version, or object to its publication (section “Your rights”).

This content may contain personal data. In particular, companies may present contact persons in their profile — with name, role and portrait photograph — and persons may be named or depicted in project descriptions or in project images posted by companies. The presentations created by us ourselves may contain details of the companies and persons involved; our own photographs do not show any persons.

If you are affected by a publication, the route depends on the source. If a company has posted the details itself, please contact that company; it decides on the content and publication of its presentation. If your matter concerns a presentation created by Losys GmbH itself, contact us — info@losys.ch; you can request its removal. In any case, you can contact us directly. We review every report, inform the company concerned where applicable, and remove any detail from the portal that is unlawful or whose deletion you are entitled to request.

To prepare this content we use technical services from providers: machine translation so that the texts appear in all four portal languages, automated analysis of submitted images and documents in order to take over the project details, and a map service that converts addresses into coordinates for the map display. These services receive the submitted content, but no data about your visit to this website. The section below states which providers these are.

Recipients and processors

We pass on your personal data only to the extent described in this policy. For technical operation we use service providers that process data exclusively on our instructions (processors, Art. 9 revDSG; Art. 28 GDPR):

In addition, the advertising platforms named in the section “Advertising reach measurement” receive data — exclusively after your consent.

  • Website hosting. This website is operated on the Laravel Cloud platform (Laravel Holdings, Inc., USA). The underlying compute and storage infrastructure is provided by Amazon Web Services in the Frankfurt am Main (EU) data centre region, where the data is stored.
  • Network entry point and attack mitigation. Cloudflare (Cloudflare, Inc., USA, together with Cloudflare Germany GmbH) receives requests to the portal as a content delivery network, encrypts the connection and filters automated attacks. In doing so your IP address is processed and the cookie “__cf_bm” is set.
  • Central data management. The details submitted via the contact form, company enquiries and the registration of a company profile are processed and stored in our own backend system, which likewise runs on Amazon Web Services infrastructure in the Frankfurt am Main region. Delivery takes place via the Amazon Web Services content delivery network (CloudFront).
  • E-mail delivery. Our e-mails — for instance the forwarding of your company enquiry or the confirmation e-mail for a registration — are delivered by Twilio SendGrid (Twilio Inc., USA).
  • E-mail mailboxes and appointment booking. We operate our e-mail mailboxes with Microsoft 365 (Microsoft Ireland Operations Limited); enquiries addressed to us are therefore held in that environment. If you book a consultation appointment via the portal, the link leads to Microsoft Bookings — the details entered there are likewise processed in our Microsoft 365 environment.
  • Technical logs. We process operational and error logs with self-hosted logging software on Amazon Web Services infrastructure in the Frankfurt am Main region.
  • Commercial register query. When a company profile is registered, we query the company name and town against the Central Business Name Index Zefix (operated by the Swiss Federal Office of Justice).
  • Preparation of published content. For the machine translation of project and company texts and for the automated analysis of submitted images and documents we use Anthropic (Anthropic PBC, USA); for converting addresses into map coordinates we use the Google Maps Platform (Google Ireland Limited). These services receive the submitted content, but no data about your visit to this website.
  • Reach measurement. Our reach measurement with Matomo runs on our own infrastructure; details in the corresponding section below.

Beyond this, data is only received by: the company you have contacted (see the section “Enquiries to companies”) and the providers of the map display, whose servers your browser calls directly when a map is loaded (see the section “Map display”).

Some of these service providers are based in the United States or can access data from there. For disclosure abroad we rely on the Swiss Federal Council’s list of countries (Art. 16(1) revDSG in conjunction with Annex 1 DSV) and, where no adequate protection is established there, on standard contractual clauses with additional safeguards (Art. 16(2)(d) revDSG; Art. 46 GDPR). For transfers to the United States to companies certified under the Swiss-U.S. or the EU-U.S. Data Privacy Framework, we rely on that certification; you can check whether a company is certified in the Data Privacy Framework list.

Nevertheless, a level of protection fully equivalent to Swiss and European standards cannot be guaranteed in every case for transfers to the United States; in particular, access by US authorities cannot be ruled out.

Retention Period

We process and store your data only for as long as this is necessary for the processing or in order to comply with statutory obligations. Once the purpose of processing no longer applies, your data is blocked or deleted. Where statutory retention obligations exist beyond that, we block or delete your data upon expiry of the statutory retention periods.

Data security

We take appropriate technical and organisational measures to protect your data against unauthorised access, loss and manipulation (Art. 8 revDSG and Art. 3 DSV; Art. 32 GDPR). These include in particular end-to-end encryption of transmission (TLS/HTTPS), encrypted storage of session data, granting access rights only where necessary, and rate limiting to prevent automated mass access.

Please note that despite these measures data transmission over the internet may have security gaps; absolute protection is not possible.

Map display (swisstopo / OpenFreeMap)

On individual pages we display interactive maps. We serve the map library used for this, MapLibre GL JS, from our own server; the map tiles, by contrast, are loaded by your browser directly from the respective provider: from swisstopo (Federal Office of Topography, geo.admin.ch) for Switzerland and from OpenFreeMap (map data © OpenStreetMap contributors) for locations outside Switzerland. When a map is loaded, your IP address is necessarily transmitted to the respective provider so that the tiles can be delivered.

The sole purpose is the map display. According to our own technical review (as of July 2026), neither service sets cookies when the map tiles are retrieved — neither for advertising nor for reach measurement. As these are third-party servers, we cannot guarantee this behaviour permanently; we review it again whenever there are changes.

Both providers in turn use service providers for delivery: swisstopo delivers its tiles via the Amazon Web Services content delivery network, OpenFreeMap via Cloudflare. The responses from OpenFreeMap also contain an error-reporting instruction (“Network Error Logging”) on the basis of which your browser may send reports about failed connections — including your IP address — to Cloudflare.

The processing serves to display locations and is covered as proportionate processing by Art. 6 revDSG; where the GDPR applies, we base it on our legitimate interest in an appealing display of locations (Art. 6(1)(f) GDPR).

Further information: swisstopo / geo.admin.ch, OpenFreeMap, the privacy policy of the OpenStreetMap Foundation and the privacy policy of Cloudflare.

Reach measurement (Matomo)

For the statistical evaluation of usage we use Matomo, an open-source web analytics software. We operate Matomo ourselves; the access data collected is stored on our own infrastructure in the European Union (Frankfurt am Main data centre region) and is not passed on to third parties. The measurement requests are received by the Amazon Web Services content delivery network (CloudFront), whose locations are in Europe, the USA, Canada and Israel; the data itself is stored exclusively in Frankfurt am Main.

The measurement is deliberately configured to minimise data:

  • No cookies. No cookies are set and no comparable identifiers are stored on your device. No consent is required for this.
  • No storage of your IP address. Your IP address is evaluated at the moment of the page view in order to determine an approximate location (country, region, city), and is then truncated by its last two blocks. Only this truncated form is stored. The location is determined using a locally held database (DB-IP); no query is made to third parties.
  • “Do Not Track” is respected. If you send this setting in your browser, no measurement takes place at all — in that case no transmission is even triggered. This is also the way to object to the measurement.
  • No directly identifying personal data. Neither name nor e-mail address nor any other contact details are transmitted to Matomo.

The following technical usage data is recorded: the page requested including the identifiers contained in its address (for example project or company numbers), the referring page, the time and duration of access, the approximate location and browser, device and language settings.

The analysis serves to improve our offering and is covered as proportionate processing by Art. 6 revDSG. Where the General Data Protection Regulation additionally applies — for instance to users from the European Union — we base the processing on our overriding legitimate interest under Art. 6(1)(f) GDPR. Further information about the software used: matomo.org.

Advertising reach measurement — only with your consent

In addition to our own anonymous reach measurement, we use measurement technologies from advertising platforms in order to assess the success of our advertisements. In legal terms these differ fundamentally from our own measurement: they transmit data to companies outside our sphere of influence, they set cookies and they serve advertising purposes.

The following therefore applies without exception to all the services named below: they are only loaded and executed after you have expressly consented. As long as you have not consented, no connection to these providers is established — so it is not merely that “no cookie is set”, but that no data transmission takes place at all.

You make your decision in the notice banner on your first visit. You can change or fully withdraw it at any time via the “Cookie settings” link in the footer; withdrawal takes effect for the future and does not affect the lawfulness of processing carried out up to that point. If you withdraw, we delete the cookies of these services that are accessible to us and reload the page so that scripts already loaded demonstrably do not continue to run.

The basis is exclusively your consent (Art. 6(6) and Art. 31(1) revDSG; Art. 6(1)(a) GDPR).

Meta Pixel (Facebook and Instagram)

The provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (“Meta”). After your consent, your browser loads the file “fbevents.js” from connect.facebook.net and reports the visit to our pages to Meta.

The purpose is to measure and optimise our advertising campaigns on Facebook and Instagram: we learn whether people who have seen or clicked one of our advertisements subsequently visited our website, and we can build audiences for further advertisements at Meta on the basis of these visits.

We ourselves receive only aggregated, statistical evaluations from Meta and cannot identify individual persons from them. The building of audiences, by contrast, takes place at Meta and is personal there: Meta assigns the reported visits to its own user data.

The data processed includes in particular your IP address, information about your browser and device, the page requested and the time of access. The pixel sets the cookies “_fbp” and “_fbc”. If you have an account with Facebook or Instagram and are logged in there, Meta can assign the data collected to your user account.

We are joint controllers with Meta for the collection and the transmission of your data to Meta (Art. 26 GDPR; cf. the judgment of the European Court of Justice of 29 July 2019, C-40/17 “Fashion ID”). The details are governed by Meta’s controller addendum. Meta is solely responsible for the subsequent further processing of the data; we have no influence on it.

Meta also processes data in the United States. Meta Platforms, Inc. is certified under both the EU-U.S. and the Swiss-U.S. Data Privacy Framework; for transfers from Switzerland we rely on the recognition under Art. 16(1) revDSG in conjunction with Annex 1 DSV, and for transfers from the EU on the European Commission’s adequacy decision of 10 July 2023, supplemented by standard contractual clauses. Nevertheless, a level of protection fully equivalent to Swiss and European standards cannot be guaranteed in every case for transfers to the United States; in particular, access by US authorities cannot be ruled out.

Further information on data processing by Meta: Meta’s privacy policy. You can adjust your advertising settings at Meta there at any time.

LinkedIn Insight Tag

The provider is LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland (“LinkedIn”, a company of the Microsoft group). After your consent, your browser loads the file “insight.min.js” from snap.licdn.com and reports the visit to our pages to LinkedIn.

The purpose is to measure and optimise our advertising campaigns on LinkedIn: we learn whether people who have seen or clicked one of our advertisements subsequently visited our website, and we can build audiences for further advertisements at LinkedIn on the basis of these visits.

We ourselves receive only aggregated, statistical evaluations from LinkedIn and cannot identify individual persons from them. The building of audiences, by contrast, takes place at LinkedIn and is personal there: LinkedIn assigns the reported visits to its own user data.

The data processed includes in particular your IP address, information about your browser and device, the page requested and the time of access. The cookie “li_fat_id” may be set on our website; further cookies are added via the linkedin.com domain, including “bcookie”, “lidc”, “li_gc” and “UserMatchHistory”. If you have a LinkedIn account and are logged in there, LinkedIn can assign the data collected to your user account.

We are joint controllers with LinkedIn for the collection and the transmission of your data to LinkedIn (Art. 26 GDPR; cf. the judgment of the European Court of Justice of 29 July 2019, C-40/17 “Fashion ID”). The details are governed by LinkedIn’s joint controller addendum. LinkedIn is solely responsible for the subsequent further processing of the data; we have no influence on it.

LinkedIn also processes data in the United States. LinkedIn Corporation is certified under both the EU-U.S. and the Swiss-U.S. Data Privacy Framework; for transfers from Switzerland we rely on the recognition under Art. 16(1) revDSG in conjunction with Annex 1 DSV, and for transfers from the EU on the European Commission’s adequacy decision of 10 July 2023, supplemented by standard contractual clauses. Nevertheless, a level of protection fully equivalent to Swiss and European standards cannot be guaranteed in every case for transfers to the United States; in particular, access by US authorities cannot be ruled out.

Further information on data processing by LinkedIn: LinkedIn’s privacy policy. You can object to the use of your data for advertising purposes in your LinkedIn account settings.

No automated decision-making in individual cases

We do not take any decisions that entail legal consequences for you or significantly affect you and are taken exclusively on an automated basis (Art. 21 revDSG; Art. 22 GDPR). We do not operate any assessment or scoring procedure concerning visitors.

If you have consented to advertising reach measurement, the platforms named there build advertising audiences on their own systems. That analysis takes place at the platforms and is described in the respective section; you can influence your advertising settings there directly.

Links to other websites

Our website contains links to third-party websites — in particular to the websites of the companies presented, to our profiles on social networks and to appointment booking. These links are simple hyperlinks: no content of these providers is embedded in our pages, and no data is transmitted to them before you click. If you follow a link, the privacy policy of the respective website applies; we have no influence on its content or data processing.

Your rights

You have the following rights regarding your personal data (Art. 25 et seq. revDSG; Art. 15–21 GDPR, where the GDPR applies):

The easiest way to withdraw your consent to advertising reach measurement is via the “Cookie settings” link in the footer.

  • Access. You can request information as to whether and which personal data we process about you.
  • Rectification. You can request the rectification of inaccurate data.
  • Erasure. You can request the erasure of your data, provided that no statutory retention obligations prevent this.
  • Restriction of processing. You can request that the processing of your data be restricted.
  • Data portability. You can request that we release data you have provided to us in a common electronic format.
  • Objection. You can object to processing that we base on a legitimate interest on grounds arising from your particular situation. You can object to processing for direct marketing purposes at any time and without giving reasons (Art. 21(2) GDPR).
  • Withdrawal of consent. You can withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out up to the withdrawal remains unaffected.

An informal message to info@losys.ch is sufficient to exercise these rights. We may request proof of your identity in order to process the request.

In addition, you have the right to lodge a complaint with a supervisory authority: in Switzerland with the Federal Data Protection and Information Commissioner (FDPIC); within the scope of the GDPR, with the data protection supervisory authority of your habitual residence, your place of work or the place of the alleged infringement.

Changes to this privacy policy

We adapt this privacy policy when our offering, the services used or the legal requirements change. The version published on this page applies in each case; its date can be found at the end of the page. In the event of material changes we will point this out clearly visibly at this place.

Glattbrugg, July 2026. The German version of this privacy policy is legally authoritative; the French, Italian and English versions are translations.