Privacy Policy of Office Group Zug GmbH

  1. What is this privacy policy about?

Office Group Zug GmbH, CHE-274.729.193, ("OGZ", hereinafter also "we", "us") is a company based in Zug. As part of our business activities, we collect and process personal data, in particular personal data about our clients, associated persons, companies, authorities and courts, professional and other associations, visitors to our website, event participants, newsletter recipients, and other entities, or their respective contact persons and employees (hereinafter also "you"). 

As the protection of your personal data is very important to us, we provide information about these data processing activities in this privacy policy. Where appropriate, we will provide you with additional privacy notices to supplement these explanations. Such additional privacy notices supplement this privacy policy and must be read in conjunction with it.

If you provide us with data about other persons (e.g., family members, representatives, counterparties, or other associated persons), we assume that you are authorized to do so, that this data is correct, and that you have ensured that these persons are informed about this disclosure, insofar as a legal duty to inform applies (e.g., by bringing this privacy policy to their attention in advance).

  1. Who is responsible for processing your data?

The party responsible under data protection law for the processing described in this privacy policy is:

Office Group Zug GmbH, CHE-274.729.193
Untere Roostmatt 8, 6300 Zug
[hello@myoffices.ch]

For questions regarding anti-money laundering, AMLA onboarding, and compliance documentation, you can also contact us at [compliance@myoffices.ch].

Wikidata: https://www.wikidata.org/wiki/Q138506694

  1. For what purposes do we process which of your data?

When you use our services, visit our website (www.myoffices.ch) (hereinafter "website"), or otherwise interact with us, we collect and process various categories of your personal data. In general, we may collect and otherwise process this data for the following purposes in particular:

  • Communication: We process personal data so that we can communicate with you and with third parties, such as authorities, banks, law firms, and consulting companies, via email, telephone, mail, or otherwise (e.g., to answer inquiries, in the context of consulting, our mandate, and, if applicable, contract execution). This also includes the ability to send our clients, contractual partners, and other interested persons information about events, changes in the law, news about us, or similar matters. This can take place, for example, in the form of newsletters and other regular contact (electronically, by post, by telephone). You can decline such communication at any time or refuse or revoke consent to such communication. For this purpose, we process in particular the content of the communication, your contact details, and the metadata of the communication, as well as image and audio recordings of (video) calls (if available). In the case of an audio or video recording, we will inform you separately, and you are free to inform us if you do not wish to be recorded or to end the communication. If we need or wish to verify your identity, we will collect additional data (e.g., a copy of an ID).
  • Initiation and conclusion of contracts: With a view to concluding a contract, in particular a contract establishing a client relationship, with you or your client or employer, which also includes any preliminary clarifications, we may collect and otherwise process your name, contact details, powers of attorney, declarations of consent, information about third parties (e.g., contact persons, family details), contract contents, date of conclusion, creditworthiness data, as well as any other data that you provide to us or that we collect from public sources or third parties (e.g., commercial registers, credit agencies, sanctions lists, media, legal expenses insurance, or the internet).
  • Administration and execution of contracts: We collect and process personal data to fulfill our contractual obligations to our clients and other contractual partners (e.g., suppliers, service providers, project partners) and, in particular, to provide and claim contractual services. This also includes data processing for the purpose of fulfilling orders (e.g., consulting and representation before authorities and correspondence), bookkeeping, and public communication (where permitted). For this purpose, we process in particular the data that we have received or collected during the initiation, conclusion, and execution of the contract, as well as data that we create in the course of our contractual services or that we collect from public sources or other third parties (e.g., authorities, courts, credit agencies, media, or the internet). This data may include, in particular, meeting and consultation minutes, notes, internal and external correspondence, contract documents, documents that we create and receive during proceedings before authorities (e.g., certificates), background information about you or other persons, as well as other file-related information, performance records, invoices, and financial and payment information. 
  • Operation of our website: To operate our website securely and stably, we collect technical data such as your IP address, information about your device's operating system and settings, the region, and the time and type of usage. We also use cookies and similar technologies. For further information, please see section 8.
  • Improvement of our electronic offerings: To continuously improve our website and other electronic offerings, we collect data about your behavior and preferences by, for example, analyzing how you navigate our website and how you interact with our social media profiles, blog posts, and Google Ads.
  • Registration: To use certain offers and services (e.g., Wi-Fi in our offices, newsletters), you must register (directly with us or via our external login service providers). For this purpose, we process the data provided during the respective registration. Furthermore, we may also collect personal data about you while you are using the offer or service; if necessary, we will provide you with further information regarding the processing of this data.
  • Security purposes and access controls: We collect and process personal data to ensure and continuously improve the appropriate security of our IT and other infrastructure (e.g., office premises, buildings). This includes, for example, monitoring and controlling electronic access to our IT systems as well as physical access to our premises, analyzing and testing our IT infrastructure, system and error checks, and creating backups. For documentation and security purposes (preventive and for investigating incidents), we also maintain access logs and visitor lists for our premises. We will notify you of surveillance systems at the relevant locations via appropriate signage.
  • Compliance with laws, directives, and recommendations from authorities and internal regulations ("Compliance"): We collect and process personal data to comply with applicable laws (e.g., anti-money laundering regulations, tax obligations, or our professional duties), self-regulations, certifications, industry standards, our corporate governance, as well as for internal and external investigations in which we are a party (e.g., by a law enforcement or supervisory authority or an appointed private body). 
  • Anti-money laundering and AMLA onboarding: OGZ acts as a consultant within the scope of its legally mandated activities as defined in Art. 2 para. 3ter of the Anti-Money Laundering Act (AMLA). To fulfill the resulting due diligence, identification, documentation, and clarification obligations, we process the following data in particular:
    – Information regarding the company and the involved contractual partners;
    – First and last name of the beneficial owners;
    – Date of birth and address of the beneficial owners;
    – Extent of participation or beneficial ownership;
    – Function within the company;
    – Information regarding status as a politically exposed person (PEP);
    – Copy of an identity document or identification report.

    We process this data primarily to identify the client and the beneficial owners, to carry out AMLA onboarding, to clarify PEP and sanctions list matches, to fulfill legal obligations, and to document our findings.

    The relevant data and documents will be retained for 10 years after the end of the business relationship, insofar as this is required under the AMLA or other legal provisions.
  1. Where does the data come from?
  • From you: The majority of the data we process is provided by you (or your device) directly (e.g., in connection with our services, the use of our website, interaction with our social media publications, or communication with us). With the exception of certain individual cases (e.g., legal obligations), you are not required to disclose your data. However, if you wish to enter into contracts with us or use our services, you must provide us with certain data. Furthermore, the use of our website is not possible without data processing.
  • From third parties: We may also collect data from publicly accessible sources (e.g., debt collection registers, land registries, commercial registers, media, or the internet, including social media) or receive it from (i) authorities, (ii) your client, who has a business relationship with us or is otherwise involved with us, as well as from (iii) other third parties (e.g., customers, credit agencies, address brokers, associations, contractual partners, internet analysis services). This includes, in particular, data that we process in the context of initiating, concluding, and executing contracts, as well as data from correspondence and meetings with third parties, and all other categories of data according to section 3. 
  • Risk management and corporate governance: We collect and process personal data as part of our risk management (e.g., to protect against criminal activities) and corporate governance. This includes, among other things, our operational organization (e.g., resource planning) and corporate development (e.g., the purchase and sale of business units or companies).
  • Job applications: If you apply for a position with us, we collect and process the relevant data for the purpose of reviewing your application, conducting the application process, and, in the case of successful applications, preparing and concluding a corresponding contract. In addition to your contact details and information from relevant communications, we process the data contained in your application documents as well as data we may obtain about you from other sources, such as professional social networks, the internet, media, and references, provided you consent to us obtaining references. Data processing in connection with the employment relationship is subject to a separate privacy policy.
  • Other purposes: Other purposes include, for example, training and educational purposes as well as administrative tasks (e.g., accounting). We may monitor or record telephone or video conferences for training, evidentiary, and quality assurance purposes. In such cases, we will notify you separately (e.g., via an on-screen notification during the video conference), and you are free to inform us if you do not wish to be recorded or to end the communication (if you simply do not wish for your image to be recorded, please turn off your camera). Furthermore, we may process personal data for the organization, execution, and follow-up of events, such as participant lists and the content of presentations and discussions, as well as image and audio recordings created during these events. Protecting other legitimate interests also falls under these additional purposes, which cannot be exhaustively listed.
  1. To whom do we disclose your data?

In connection with the purposes listed in section 3, we disclose your personal data primarily to the categories of recipients listed below. Where necessary, we will obtain your consent or seek a release from our professional confidentiality obligations from our supervisory authority. 

  • Service providers: Service providers: We work with service providers in Switzerland and abroad who process data that they receive from us or have collected for us (i) on our behalf, (ii) in joint responsibility with us, or (iii) under their own responsibility. These service providers include, in particular, IT providers, hosting providers, online identification providers, debt collection agencies, credit bureaus, providers of sanctions list and PEP checks, banks, insurance companies, address verifiers, law firms, notaries, and consulting firms.
    The service providers and recipients we use include, in particular:

    - Intrum AG for online identification as well as for receivables management, debt collection, and credit checks;
    - A provider used by OGZ for sanctions lists, PEP, and other compliance checks. The specific provider is selected and engaged as soon as this is necessary for the respective service;
    - Infomaniak as a Swiss hosting and infrastructure provider.

    To the extent that these service providers process personal data on our behalf, this is done as commissioned processing to the necessary extent. If a recipient processes data for their own purposes and under their own responsibility, this is disclosed in the relevant section of this privacy policy.
  • Transmission to Intrum AG: Based on the General Terms and Conditions, particularly the provisions on receivables management and credit checks, we may transmit identification, contact, contract, and payment data to Intrum AG. Transmission may occur, in particular, for the purpose of conducting online identification, credit checks, assessing creditworthiness, preventing abuse, and processing and enforcing claims.

    Intrum AG may process this data as a recipient under its own responsibility, particularly in its credit rating database. The data protection information of Intrum AG applies to the corresponding data processing.

All these categories of recipients may in turn involve third parties, meaning your data may also become accessible to them. We can restrict processing by certain third parties (e.g., IT providers), but not by others (e.g., authorities, banks, etc.).

We also allow certain third parties to collect personal data from you on our website and at our events under their own responsibility (e.g., media photographers, providers of tools we have integrated into our website, etc.). To the extent that we are not decisively involved in these data collections, these third parties are solely responsible for them. For inquiries and to exercise your data protection rights, please contact these third parties directly. We have listed your rights in Section 7. Information regarding activities on our website can be found in Section 8. 

  1. Is your personal data also transferred abroad?
  • Customers and other contractual partners: This primarily refers to our customers and other contractual partners where the transmission of your data arises from the contract (e.g., because you work for a contractual partner or they provide services for you). This category of recipients also includes entities with whom we cooperate, such as consulting firms, banks, notaries, or law firms. These recipients generally process the data under their own responsibility.
  • Authorities and courts: We may disclose personal data to offices, courts, and other authorities in Switzerland and abroad if this is necessary for the fulfillment of our contractual obligations and, in particular, for mandate management, or if we are legally obliged or entitled to do so, or if it appears necessary to protect our interests. These recipients process the data under their own responsibility.
  • Involved persons: Where necessary for the fulfillment of our contractual obligations, particularly for mandate management, we also disclose your personal data to other involved persons (e.g., guarantors, financiers, affiliated companies, consulting firms, banks, notaries, law firms, information providers, or experts, etc.).
  • Other persons: This refers to other cases where the involvement of third parties arises from the purposes set out in Section 3. This concerns, for example, delivery recipients or payment recipients specified by you, third parties within the scope of representation relationships (e.g., your lawyer or bank), or persons involved in administrative or judicial proceedings. If we work with media and provide them with material (e.g., photos), you may also be affected. As part of corporate development, we may sell or acquire businesses, parts of businesses, assets, or companies, or enter into partnerships, which may also result in the disclosure of data (including yours, e.g., as a customer or supplier or as their representative) to the persons involved in these transactions. Communication with our competitors, industry organizations, associations, and other bodies may also lead to the exchange of data concerning you.

Compliance data and the associated identification, AMLA, and audit documentation are stored exclusively in Switzerland.

Depending on the file and the services used, other personal data may also be processed in Switzerland, the European Economic Area (EEA), or other countries. In the course of our work for clients, personal data may also be transferred to other countries if necessary for the respective service.

If a recipient is located in a country without adequate data protection, we contractually obligate the recipient to maintain an appropriate level of data protection. To this end, we use the European Commission's revised standard contractual clauses, including the necessary supplements for Switzerland, where required. Data may also be disclosed to a country without adequate data protection if this is based on a legal exception, such as for legal proceedings abroad, due to an overriding public interest, for the performance of a contract in your interest, based on your consent, or to protect vital interests.

The exclusive storage in Switzerland applies to compliance data and the associated documentation. It does not automatically apply to other categories of data processed via external website, analytics, communication, or social media services.

  1. What are your rights?

You have certain rights in connection with our data processing. Under applicable law, you may, in particular, request information about the processing of your personal data, have incorrect personal data corrected, request the deletion of personal data, object to data processing, or request the release of certain personal data in a common electronic format or its transfer to another controller. 

If you wish to exercise the aforementioned rights, please contact us; our contact details can be found in Section 2. To prevent misuse, we must verify your identity (e.g., by requesting a copy of your ID, if necessary). 

Please note that these rights are subject to conditions, exceptions, or restrictions (e.g., for the protection of third parties, trade secrets, or due to professional confidentiality). We reserve the right to redact copies or provide them only in part for reasons of data protection or confidentiality.

  1. How are cookies, similar technologies, and social media plug-ins used on our website and other digital services?

When you use our website (including our newsletter and blog), data is generated and stored in logs (particularly technical data). We may also use cookies and similar technologies (e.g., pixel tags or fingerprints) to recognize website visitors, analyze their behavior, and identify preferences. A cookie is a small file transmitted between the server and your system that enables the recognition of a specific device or browser. 

You can configure your browser to automatically reject, accept, or delete cookies. You can also disable or delete cookies on a case-by-case basis. You can find out how to manage cookies in your browser via your browser's help menu.

As a rule, both the technical data we collect and cookies do not contain personal data. However, personal data that we or third-party providers commissioned by us store about you (e.g., if you have a user account with these providers) may be linked to the technical data or the information stored in and obtained from cookies, and thus potentially linked to your person.

We also use social media plug-ins, which are small software components that create a connection between your visit to our website and a third-party provider. The social media plug-in informs the third-party provider that you have visited our website and may transmit cookies that the provider previously placed on your web browser. For more information on how these third-party providers use the personal data collected via their social media plug-ins, please refer to their respective privacy policies.

In addition, we use our own tools as well as third-party services (which may also use cookies) on our website, particularly to improve the functionality or content of our website (e.g., integrating videos or maps), to generate statistics, and to display advertisements.

We may use services from the following providers and advertising partners, whose contact details and further information regarding their specific data processing activities can be found in their respective privacy policies:

  • Google Analytics
    Information for Google accounts: https://policies.google.com/technologies/partner-sites?hl=en
    Provider: Google Ireland
    Privacy Policy: https://support.google.com/analytics/answer/6004245Anbieter: Google Irland
    Datenschutzhinweise: https://support.google.com/analytics/answer/6004245
  • Google Ads
    Provider: Google Ireland
    Privacy Policy: https://policies.google.com/technologies/partner-sites?hl=en We use Google Ads to display and evaluate advertisements. Google may use cookies to measure the effectiveness of ads and show you more relevant advertising.
  • Google Ads
    Anbieter: Google Ireland
    Datenschutzhinweise: https://policies.google.com/technologies/partner-sites?hl=de Wir nutzen Google Ads zur Schaltung und Auswertung von Werbeanzeigen. Google kann dabei Cookies einsetzen, um die Wirksamkeit von Anzeigen zu messen und Ihnen relevantere Werbung anzuzeigen.
  • Cookie-Consent-Tool
    Anbieter: cookiebot.com Usercentrics A/S (Dänemark)
    Datenschutzhinweise: https://www.cookiebot.com/en/privacy-policy/ Wir verwenden ein Cookie-Consent-Tool, um Ihre Cookie-Einstellungen zu speichern und die Einwilligung in nicht notwendige Cookies zu verwalten.
  • Elfsight WhatsApp Chat Bot
    Provider: Paddle.com Market Ltd (United Kingdom)
    Privacy Policy: https://elfsight.com/privacy-policy/ 
  • Cookie Consent Tool
    Provider: cookiebot.com Usercentrics A/S (Denmark)
    Privacy Policy: https://www.cookiebot.com/en/privacy-policy/ We use a cookie consent tool to save your cookie settings and manage consent for non-essential cookies.

Some of the third-party providers we use may be located outside of Switzerland. Information regarding the transfer of data abroad can be found in Section 6. From a data protection perspective, they act in some cases as our data processors and in others as independent controllers. Further details on this can be found in their privacy policies.

  1. How do we process personal data on our social media pages?

We maintain pages and other online presences on social networks and other third-party platforms and process data about you in this context. In doing so, we receive data from you (e.g., when you communicate with us or comment on our content) and from the platforms (e.g., statistics). The platform providers may analyze your usage and process this data in conjunction with other information they hold about you. They also process this data for their own purposes (e.g., marketing and market research, and for managing their platforms) and act as independent controllers for these purposes. For further information on processing by platform operators, please refer to the privacy policies of the respective platforms. 

We currently use the following platforms, with the identity and contact details of each platform operator available in their respective privacy policies:

We are entitled, but not obligated, to review third-party content before or after its publication on our online platforms, to delete content without notice, and, if necessary, to report it to the provider of the platform in question.

Some of the platform operators may be located outside of Switzerland. Information on data transfers abroad can be found in section 6.

  1. What else should be noted?

As our scope of activity is limited to Switzerland, we do not assume that the EU General Data Protection Regulation ("GDPR") is applicable in our case. However, should this exceptionally be the case for certain data processing activities, this section 10 shall apply additionally, exclusively for the purposes of the GDPR and the data processing subject to it.

We base the processing of your personal data in particular on the fact that

  • it is necessary for the initiation and conclusion of contracts and their administration and enforcement as described in section 3 (Art. 6(1)(b) GDPR); 
  • it is necessary for the protection of our legitimate interests or those of third parties as described in section 3, namely for communication with you or third parties, to operate our website, to improve our electronic offerings and register for specific offers and services, for security purposes, for compliance with Swiss law and internal regulations for our risk management and corporate governance, and for other purposes such as training and education, administration, evidence and quality assurance, organization, execution and follow-up of events, and for the protection of other legitimate interests (see section 3) (Art. 6(1)(f) GDPR);
  • it is required or permitted by law due to our mandate or our position under the law of the EEA or a member state (Art. 6(1)(c) GDPR), or is necessary to protect your vital interests or those of other natural persons (Art. 6(1)(d) GDPR); 
  • you have separately consented to the processing, for example, via a corresponding declaration on our website (Art. 6(1)(a) and Art. 9(2)(a) GDPR). 

Please note that we generally process your data for as long as our processing purposes, legal retention and documentation obligations, and our legitimate interests—particularly for documentation and evidentiary purposes—require. For compliance data and the associated identification and verification documents, a retention period of 10 years after the end of the business relationship applies, as required by the AMLA. If there are no legal or contractual obligations or technical reasons to the contrary, we generally delete or anonymize your data after the storage or processing period has expired, in accordance with our standard procedures and our retention policy.

If you do not provide certain personal data, it may result in us being unable to provide the related services or enter into a contract. We generally indicate where the personal data we request is mandatory.

The right to object to the processing of your data, as set out in section 7, applies in particular to data processing for direct marketing purposes.

If you do not agree with how we handle your rights or data protection, please let us know (see contact details in section 2). If you are located in the EEA, you also have the right to lodge a complaint with the data protection supervisory authority in your country. A list of authorities in the EEA can be found here: https://edpb.europa.eu/about-edpb/board/members_de.

  1. Can this privacy policy be changed?

This privacy policy is not part of any contract with you. We may update this privacy policy at any time. The version published on this website is the current version. 

Office Group Zug GmbH

Zug, 15.09.2026