Privacy Policy
Version 4.2 · 21 August 2026
1. General Information
NRG Solutions AG takes the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
This privacy policy fulfils the information obligations under the revised Swiss Federal Act on Data Protection (revFADP) and, where applicable, the General Data Protection Regulation (GDPR).
The use of our website is generally possible without providing personal data. Insofar as personal data (such as name, address, or email addresses) is collected on our pages, this is always done on a voluntary basis where possible.
2. Responsible Party
NRG Solutions AGPlatz 4
6039 Root D4
Switzerland
Email: contact@nrg-solutions.ch
Contact for Data Protection Matters
NRG Solutions AG, Data ProtectionEmail: contact@nrg-solutions.ch
3. Categories of Data Subjects and Types of Data
Website Visitors
When visiting our website, the following data is automatically processed:
- IP address
- Device and browser information (type, version, operating system)
- Pages accessed
- Referrer URL (the previously visited page)
- Date and time of access
Getting in Touch
When you contact us by email or telephone, or book an appointment through our scheduling tool, we process:
- Name (first and last name)
- Email address
- Telephone number, if you provide it
- Company, if you provide it
- The content of your enquiry
Contact Persons at Companies We Approach
Where we approach a company on our own initiative, we process business contact details obtained from publicly available sources such as company websites, the commercial register, industry and membership directories or professional networks:
- Name (first and last name)
- Role within the company
- Business email address and telephone number
- Company and business address
- Notes on the course of our contact
This information does not come from you directly. We inform you about it no later than one month after obtaining it, as a rule already with our first approach (Art. 19(3) and (5) revFADP). You may object to the processing at any time, see section 11.
4. Purposes and Legal Bases of Processing
We process your data for the following purposes and on the following legal bases:
5. Data Collection and Processing
Each time you access our website, the following data is automatically collected and stored in server log files:
- Browser type and version
- Operating system used
- Referrer URL (the previously visited page)
- IP address of the accessing computer
- Time of the server request
This data cannot be attributed to specific individuals. This data is not merged with other data sources.
6. Getting in Touch and Booking Appointments
This website does not contain a contact form. You can reach us by email or telephone using the details given in the legal notice and on the contact page. We store the information you provide in such an enquiry in order to handle it and in case of follow-up questions, among other places in a CRM system.
For scheduling appointments we use the online booking tool zcal, operated by zcal, Inc. based in the USA. On most pages of this website the tool is not active straight away: you first see a notice with a button, and the tool is only loaded once you click it. On the contact page and on the consultation page, where arranging an appointment is the purpose of the page, it is loaded as soon as the page opens. Once the tool is loaded, your IP address, browser and device information and the page you accessed are transmitted to that provider. If you book an appointment, the details you enter in the booking window, in particular your name and email address, are additionally processed by the provider. Further information on this transfer can be found in section 7.
The basis for this processing is the performance of pre-contractual measures and our legitimate interest in straightforward appointment scheduling.
6.1 Access to the Investor Presentation
The investor presentation at /invest/ is not publicly accessible. Access requires a code that we issue individually. Before the document is displayed, we record your first name, last name and email address, plus your company if you provide it, together with the time of access, and store this information in our CRM system. The purpose is to control access to confidential documents and to contact you about this presentation. The recipients are listed in section 7; retention is governed by section 9.
Before access is granted, you confirm with a single tick box that you will treat the document as confidential and that we may store your details and contact you about it, including by email. The legal basis is your consent under Art. 6(6) revFADP and Art. 6(1)(a) GDPR. You may withdraw it at any time, via the unsubscribe link in every email or at contact@nrg-solutions.ch. Every page of the document carries your name and, where provided, your company. If you respond at the end, we record whether you are interested.
The basis for this processing is the performance of pre-contractual measures and our legitimate interest in protecting confidential documents. Two technically necessary cookies are set for access: one for signing in, one for marking the document with your name. Both apply to this area only and expire after 30 days.
7. Recipients and Data Sharing
To provide our services, we use trusted service providers. The following categories of recipients may have access to your data:
AI-Assisted Features in the CRM System
In our CRM system (Attio Limited, United Kingdom) we use AI-assisted features, for example to summarise, structure and retrieve information. Under its data processing agreement, the provider engages language model providers as sub-processors, including OpenAI and Anthropic. Contact details and content from correspondence may thereby reach those systems, in part outside Switzerland, the EEA and the United Kingdom; for such transfers the provider's agreement provides for standard data protection clauses.
These features support our work. Decisions on offers, terms or the business relationship are made exclusively by our staff; no automated individual decision-making takes place. If you do not wish your details to be processed in this way, please let us know.
Fonts
Our website uses locally hosted fonts. No fonts are loaded from external services (e.g. Google Fonts). When visiting our website, no data is transmitted to external font services.
Third-Country Transfers
Some of our service providers are located outside Switzerland and the EEA, particularly in the USA. We ensure an adequate level of data protection, in particular through:
- a determination by the Swiss Federal Council pursuant to Art. 16(1) revFADP in conjunction with Annex 1 of the Data Protection Ordinance, insofar as the recipient is covered by that determination and certified thereunder;
- otherwise standard data protection clauses pursuant to Art. 16(2)(d) revFADP that have been approved, issued or recognised by the FDPIC.
Please note that authorities in the recipient country may be able to access data under certain circumstances and that such access is beyond our control.
8. Cookies and Local Storage Entries
No cookies are set on the publicly accessible pages of this website. There is no web analytics, no advertising or tracking services are used and no profiling takes place. That is also why there is no consent banner here: there is no processing for which consent would have to be obtained.
The only thing stored on your device is a technical entry in your browser's local storage (localStorage) recording your choice of language. In accordance with Art. 45c let. b of the Swiss Telecommunications Act (Fernmeldegesetz, FMG) we hereby inform you of this and point out that you may refuse this processing: you can configure your browser to block local storage entries and cookies, or to delete them automatically when the browser is closed. The website remains usable; it simply no longer preselects your language.
8.1 Storage Entries Used
Our internal systems and the access-protected area described in section 6.1 additionally set technically necessary cookies. They serve solely for logging in and for marking the document with your name, are limited to the respective area, expire after 30 days at the latest and do not occur on the public pages. Further details are set out in section 14.
8.2 Embedded Appointment Booking
The only third-party embed on this website is the appointment booking tool. On most pages it is loaded only once you click the corresponding button; before that click there is no connection to the provider. Which data is transmitted, and on which pages the tool is already loaded when the page opens, is set out in section 6.
8.3 No Web Analytics
Until 3 August 2026 a web analytics service was embedded on this website, loaded only after explicit consent. That service has been removed entirely. No usage statistics are collected any more and the associated cookies are no longer set. A consent entry previously stored in your browser is deleted automatically on your next visit.
9. Retention Periods
We store your personal data only for as long as is necessary for the respective processing purposes or as required by statutory retention obligations:
After the respective period expires, data is routinely deleted unless it is still required for the fulfilment of a contract or statutory obligations.
10. Data Security
We use technical and organisational security measures to protect your data made available to us against accidental or intentional manipulation, loss, destruction, or access by unauthorised persons.
Our security measures include, among others:
- Transport encryption: TLS 1.3 for all data transmissions
- Access controls: Role-based with multi-factor authentication
Our security measures are continuously improved in line with technological developments.
11. Your Rights
Under the revFADP and the GDPR, you are entitled to the following rights:
- Right of access: You have the right to know whether and which personal data we process about you.
- Right to rectification: You may request the correction of inaccurate or incomplete data.
- Right to erasure: You may request the deletion of your data, provided no statutory retention obligations apply.
- Restriction of processing: You may request the restriction of the processing of your data.
- Data portability: You have the right to receive your data in a structured, commonly used and machine-readable format.
- Right to object: You may object to the processing of your data at any time, provided the processing is based on legitimate interest.
- Withdrawal of consent: You may withdraw any consent given at any time with effect for the future.
To exercise your rights, please contact us at: contact@nrg-solutions.ch
Right to Lodge a Complaint
You have the right to lodge a complaint with the competent supervisory authority:
Federal Data Protection and Information Commissioner (FDPIC)Feldeggweg 1
3003 Bern
Switzerland
www.edoeb.admin.ch
For persons from the EEA, the competent data protection authority of the respective member state is also available as a complaints body.
12. Profiling and Automated Decisions
We do not carry out profiling or automated individual decisions with legal or similarly significant effects. Our CRM system uses AI-assisted features, for example to summarise and retrieve information. They support our work; decisions are made exclusively by our staff. Further details in section 7.
13. Changes
We reserve the right to occasionally adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy.
14. Internal Systems
For handling customer projects, for customer relationship management and for internal project and task planning we operate our own systems. They are available exclusively to employees of NRG Solutions AG; there is no self-registration. Customers receive individually issued, protected links to the documents prepared for them. In addition to the preceding sections, the following provisions apply to the personal data processed in this context.
14.1 Data Processed
14.2 Origin of the Data and Responsibility
Details about employees originate from NRG Solutions AG itself. Details about customers originate from the business relationship or, where we made the approach, from publicly available sources as described in section 3. No data is purchased. The controller within the meaning of Art. 5(j) revFADP is NRG Solutions AG.
14.3 Recipients and Processors
14.4 Disclosure of Data Abroad
The data is stored in Switzerland. The applications are operated in Germany, the customer relationship management system in the United Kingdom with data held in Ireland. All of these states are listed in Annex 1 of the Data Protection Ordinance as states with an adequate level of data protection; the disclosure is therefore based on Art. 16(1) revFADP and requires no additional safeguard. In so far as a processor itself engages sub-processors outside these states, that transfer is based on standard data protection clauses pursuant to Art. 16(2)(d) revFADP.
14.5 Retention Periods
14.6 Security, Cookies and Your Rights
Access is limited to authorised persons and is enforced at database level, not merely in the user interface. All connections are encrypted (TLS). Document links provided are additionally protected and expire after a set period. Only technically necessary cookies are used, for logging in and for display; no tracking and no web analytics take place.
All assessments and decisions are made by employees of NRG Solutions AG. No profiling within the meaning of Art. 5(f) revFADP takes place, and no automated individual decisions within the meaning of Art. 21 revFADP are made. You may also exercise your rights under section 11 in respect of these systems, at datenschutz@nrg-solutions.ch.
Version 4.2 · 21 August 2026