bootstrap/wernersphon CONTACT US
bootstrap/wernersthumb SWISS QUALITY SINCE 1983.
bootstrap/wernermail [email protected]
bootstrap/wernersphon +41 (52) 368 30 10

Privacy policy

1. Data Controller

The data controller responsible for data processing on this website and all associated websites and shops is:

Hemag Nova AG

Mr. Mario Picardi
Steigstrasse 2
8355 Aadorf, Switzerland

Tel: +41 52 366 31 31
Email: [email protected]

For questions regarding data protection or to exercise your rights under this privacy policy, our data protection advisor is available.


2. General Statement

We respect your privacy and the protection of your personal information in accordance with the legal requirements of the Federal Act on Data Protection (FADP) and the corresponding ordinances. The protection and security of your personal data is our highest priority. The processing of your data takes place in accordance with the applicable data protection regulations and guidelines.

We implement extensive technical and organisational measures (TOMs) to protect your data against unauthorised access, loss, misuse or manipulation. Nevertheless, we point out that the transmission of information over the internet (e.g. by email) may entail security risks.


3. Processing of Personal Data

3.1 Definitions

Personal data is any information that relates to an identified or identifiable person. A data subject is someone whose personal data is being processed. By "processing" we mean all actions in connection with personal data, regardless of the means and procedures used, such as storing, disclosing, obtaining, deleting, retaining, modifying, destroying and using personal data.

3.2 Purposes of Processing

The processing of personal data is carried out for the following purposes:

  • With the consent of the data subject: e.g. for marketing purposes.
  • For the fulfilment of a contract: e.g. for processing orders.
  • For the fulfilment of legal obligations: e.g. tax law requirements and age verification under the TabPA.
  • For the protection of legitimate interests: e.g. to ensure IT security, enforce legal claims or improve customer experience.

3.3 Retention Period

Personal data is stored for as long as is necessary for the respective purpose. After the retention period expires or the processing purpose ceases to apply, the data is deleted, unless legal retention obligations (up to 10 years) exist.


4. Legal Bases for Data Processing

The processing of your personal data is carried out on the basis of the following legal grounds:

  • Consent: If you have given us your consent to process your data for specific purposes.
  • Contract performance: If processing is necessary for the performance of a contract.
  • Legal obligation: If we are legally obliged to process your data.
  • Legitimate interests: If we have a legitimate interest in the processing, e.g. for the optimisation of our website or to ensure IT security.

5. Data Processing in Switzerland

Hemag Nova AG processes and stores your personal data exclusively in Switzerland. We currently do not ship abroad and generally do not transmit your data to recipients in third countries. Should this change in the future, we will inform you of corresponding adjustments to this privacy policy and ensure that an adequate level of data protection is guaranteed.


6. Processing of Electronic Payments

For the processing of electronic payments, personal data such as name, address, payment information and the IP address of the device used are transmitted to a Swiss payment processing service provider. This data is used exclusively for processing the payment and stored securely. It is ensured that this service provider meets the legal data protection requirements and handles the data in accordance with the applicable data protection regulations.


7. Age Verification

For the sale of age-restricted products (tobacco and nicotine products), we are legally obliged to verify the age of our customers. This obligation arises from the revised Federal Act on Tobacco Products and Electronic Cigarettes (TabPA).

7.1 When does age verification take place?

Age verification is only triggered when age-restricted products are in your cart. When purchasing exclusively non-restricted items (e.g. charcoal, shishas, accessories), no age verification takes place.

7.2 Service Provider Used

To carry out the age verification, we work with PXL Vision AG, Förrlibuckstrasse 30, 8005 Zurich, Switzerland. PXL Vision is a Swiss provider for digital identity verification and processes the data in Switzerland. The solution is KJM-certified and complies with the requirements of the Swiss Federal Act on Data Protection (FADP).

7.3 Data Processed

As part of the age verification, the following data is processed by PXL Vision AG:

  • Image of the identification document (passport, ID card or driving licence)
  • Technical connection data (IP address, browser information)

7.4 Data Transmission to Us

We ourselves receive from PXL Vision only a simple yes/no result regarding whether the verified person is of legal age (18 years or older). We do not receive any images or identification data. This confirmation is linked to your customer account so that re-verification for subsequent orders is not necessary.

7.5 Storage and Deletion

The data transmitted to PXL Vision as part of the verification (ID image) is automatically deleted by PXL Vision after completion of the verification. On our side, only the status of the successful verification is stored, linked to your customer account.

7.6 Legal Basis

The processing of your data for the purpose of age verification takes place to fulfil a legal obligation (Art. 31 para. 2 lit. e FADP in conjunction with the TabPA) and to protect our legitimate interests in protecting minors and complying with legal requirements.

7.7 Further Information

Detailed information on data protection at PXL Vision can be found in their privacy policy at: https://pxl-vision.com/de/datenschutz/


8. Customer Reviews

Customers have the opportunity to rate products directly in our online shop. Every review is checked before publication to ensure it complies with our guidelines. We reserve the right not to publish reviews that are offensive, inappropriate or otherwise unsuitable. The data provided by customers is not modified and is published together with the review.


9. Newsletter

We send newsletters to inform you about news, offers and relevant content. For this purpose, your data is transmitted to an external email marketing service provider and processed there. You can unsubscribe from the newsletter at any time by using the unsubscribe link in the newsletter or by contacting us directly.

It is ensured that the data (names and email addresses) transmitted are protected and cannot be misused. No data processing takes place on the part of this service provider that is not carried out by Hemag Nova AG.


10. Opening a Customer Account

When opening a customer account in our online shop, the following personal data is collected and stored:

  • Salutation
  • Surname
  • First name
  • Billing and delivery address
  • Email address
  • Date of birth
  • Company, company address and UID number (for business customers)
  • Phone number
  • Order history and data on purchased products
  • Status of age verification (if age-restricted products have been purchased)

This data is required to offer you a personalised shopping experience, to process orders efficiently and to provide you with relevant information and offers.


11. Cookie Policy

This website uses cookies. These small text files allow specific user-related information to be stored on the end device while the website is being used. Among other things, cookies enable the recording of usage frequency and the number of users, the analysis of user behaviour on the site and the improvement of the user experience.

The visitor can prevent the storage of cookies by making appropriate settings in their browser. However, it should be noted that in this case it may not be possible to use all functions of the website to their full extent. Cookies remain stored even after the browser is closed (not if the user uses the incognito/private mode of the relevant browser) and can be retrieved when the website is visited again.


12. Tracking on the Website

For the purpose of needs-based design and continuous optimisation of our website, we use tracking technologies. In this context, we create pseudonymised usage profiles and use cookies (see also the "Cookie Policy" section). The information generated by the cookie about your use of this website is stored and processed together with the log file data on our servers.

We collect the following information, among other things:

  • The navigation path a visitor takes on the website (including content viewed and products selected or purchased).
  • The time spent on the website or certain subpages.
  • The subpage on which the website is left.
  • The country, region or city from which access takes place.
  • Information on the end device (type, version, width and height of the browser window).
  • Whether the visitor is a returning or new user.

We use this information to evaluate the use of the website, to compile reports on website activities and to provide further services related to website use for the purposes of market research and needs-based design of our pages.

The data is not passed on to third parties.


13. Use of Hemag Nova AG's Guest Wi-Fi at the Company Headquarters in Aadorf

At the headquarters of Hemag Nova AG in Aadorf, we provide our customers with a guest Wi-Fi. When using the guest Wi-Fi, data such as the MAC address, manufacturer and type of device used and the duration of use is stored. This data is used exclusively to ensure IT security. No further use or transmission of this data takes place.


14. LiveChat Functions and Contact

Our website offers a LiveChat function as well as a contact form that allows you to communicate directly with our customer service. The data provided as part of the use of LiveChat or the contact form (e.g. name, email address, chat content) is stored and used exclusively for processing your enquiries. This data may be analysed to improve our services, but is not passed on to third parties.

The same applies to contact via email. Data you provide will be used and stored to process your request. The data may be analysed to improve our services, but is not passed on to third parties.

Telephone conversations are not recorded. The data you provide during the conversation is used by our employee to resolve your request. This data may be stored in the form of conversation notes by our employees. The storage helps us to resolve your request. The conversation notes may be analysed to improve our services, but are not passed on to third parties.


15. Privacy-Friendly Default Settings (Privacy by Default)

Our systems and services are set up by default in such a way that only the data necessary for the respective purpose is processed. This "Privacy by Default" setting ensures that data protection is integrated from the outset and the privacy of users is protected in the best possible way.


16. No Liability for External Links

Our website may contain links to external websites operated by third parties. We have no influence on the content and data protection practices of these external sites and accept no liability for their content or the protection of your data. We recommend reading the privacy policies of the linked sites before entering any personal data.


17. Data Processing in Connection with Prize Draws

In the context of prize draws, competitions or similar promotions that we offer, personal data such as name, address and contact information is processed. This data is used exclusively for the implementation of the prize draw and, if applicable, for notifying the winners. After the prize draw is completed, the data is deleted, unless other consents have been given.


18. Rights of Data Subjects

You have the following rights with regard to your personal data:

  • Right of access: You have the right to obtain free information about the personal data we have stored.
  • Right to rectification: You can request the correction of incorrect or incomplete data.
  • Right to erasure: You can request the deletion of your data, provided that it is no longer necessary for the original purpose and there are no legal retention obligations.
  • Right to restriction of processing: Under certain conditions, you can request the restriction of the processing of your data.
  • Right to data portability: You have the right to receive your personal data in a structured, common and machine-readable format and to transmit this data to another controller.
  • Right to withdraw consent: If you have given us consent to process your data, you can withdraw this at any time with effect for the future.

To exercise these rights, you can contact our data protection officer at any time (contact details see above).


19. Credit Check / Debt Collection

Before offering the payment method "invoice", we reserve the right to carry out a credit check. For this purpose, we work with an external service provider who processes personal data for this purpose. This check serves to protect our legitimate interests in minimising the risk of payment defaults. The data is transmitted in compliance with the Swiss Federal Act on Data Protection to a credit check and debt collection service provider based in Switzerland.

To check creditworthiness, the data you provided at order completion will be transmitted. This transmission may contain the following data: surname, first name, address, email address as well as date of birth and order information (order amount).

In the event of a payment default, further data is transmitted to this debt collection company, namely outstanding invoice and reminder amounts as well as the billing data provided by you (names, address, email address). After this transmission, further processing of the data takes place by the debt collection company. Data protection is also ensured during this processing.


20. Order Processing and Disclosure to Third Parties

In certain cases, we commission third parties with the storage and processing of your personal data on our behalf. These third parties act exclusively as processors and may not use the data for their own purposes. It is ensured in any case that the third parties are FADP-compliant and your data is protected in accordance with the Swiss Federal Act on Data Protection.


21. Video Surveillance

Our business premises are under video surveillance to prevent and clarify criminal offences and to protect our legitimate interests and those of our employees and customers. The recordings are deleted after 90 days, unless they are required as evidence for incidents.


22. Changes to the Privacy Policy

We reserve the right to change this privacy policy at any time. Changes will be published on our website and apply from the time of publication.

Loading...