Privacy Policy
Version 5.0 · 30 September 2026
1. General Information
This privacy policy describes how NRG Solutions AG processes personal data: when you visit this website, when you enter information in forms and access-protected areas, when you contact us or we contact you, and in our internal systems. It fulfils the information obligations under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
You can use this website without providing any information about yourself. Providing personal data is not required by law or by contract. Without the details marked as mandatory, however, we cannot process an enquiry, a registration or an access request.
We may amend this privacy policy. The version published on this website applies.
2. Controller
NRG Solutions AGPlatz 4
6039 Root D4
Switzerland
Email: contact@nrg-solutions.ch
Please also use this address for questions about data protection and requests concerning your rights.
3. Visiting this Website
Each time this website is accessed, the following data is processed and stored in the server's log files:
- IP address
- Browser, device and operating system information
- Page accessed and previously visited page
- Date and time of access
The purpose is to deliver the website, to keep it secure and to protect it against misuse. We do not combine this data with other data sources. The legal basis is our legitimate interest in a secure and functioning website (Art. 31(1) FADP, Art. 6(1)(f) GDPR).
4. Contact and Appointment Booking
When you contact us by email or telephone or book an appointment, we process the details you provide, in particular your name, email address, telephone number, company and the content of your request. We store them, among other places in our customer relationship management system, in order to handle your request and answer follow-up questions.
Appointments are booked through a service embedded from a third-party provider (section 8). The details you enter there, in particular your name and email address, are also processed by that provider.
The legal basis is the performance of pre-contractual measures and our legitimate interest in answering enquiries and in straightforward appointment scheduling (Art. 31(1) FADP, Art. 6(1)(b) and (f) GDPR).
5. Forms, Registrations and Access-Protected Areas
This section applies to all information you enter in a form on this website, for example when registering for an event or for access to a confidential document. It applies equally to contact details that we record at trade fairs and events on our devices or in conversation with you.
We process the details you provide, in particular first and last name, email address, telephone number, company, position or role within the company and industry, together with information about your request, such as selected topics, figures you enter into a calculator or your feedback on a document. We record the time and language of your entry and the member of our team responsible for you. Where we record your details in conversation, we also note its content.
The purpose is to carry out your registration, request or access, to hold events, to control access to confidential documents and to contact you about the matter for which you provided the details, including by email.
Depending on the form, your details are sent by email to the responsible members of our team or directly to our customer relationship management system; we use an email delivery service for sending. Where provided for, you receive a confirmation at the email address you gave, for example with a calendar file.
Where a form collects personal data, you confirm with a tick box before submitting that you have taken note of this privacy policy or that you consent to the processing described. Where we record your details in conversation, we obtain your consent verbally. You may withdraw consent at any time, via the unsubscribe link in the emails we send you on that basis or at contact@nrg-solutions.ch.
Access-protected areas are opened with an access code that we issue individually. Depending on the area, we record your contact details before granting access; the document then bears your name and, where provided, your company. Cookies are set for signing in (section 8).
We process registrations and requests in order to carry out your registration and pre-contractual measures (Art. 31(1) FADP, Art. 6(1)(b) GDPR). Access control is based on our legitimate interest in protecting confidential documents (Art. 31(1) FADP, Art. 6(1)(f) GDPR). Where we contact you on the basis of your consent, that consent is the legal basis (Art. 6(6) and Art. 31(1) FADP, Art. 6(1)(a) GDPR).
6. Approaching Companies Directly
Where we approach a company on our own initiative, we process business contact details from publicly available sources, such as company websites, the commercial register, industry and membership directories or professional networks. These are in particular name, position, business email address and telephone number, company and business address, and notes on the course of our contact. This information does not come from you. We inform you about it no later than one month after obtaining it, as a rule with our first contact (Art. 19(3) and (5) FADP, Art. 14 GDPR).
The purpose is to contact potential business partners and to maintain the related records. The legal basis is our legitimate interest in doing so (Art. 31(1) FADP, Art. 6(1)(f) GDPR). You may object to this processing at any time (section 13).
7. Internal Systems
We use our own systems for customer projects, customer relationship management and internal project and task planning. They are available exclusively to employees of NRG Solutions AG; there is no self-registration. Customers receive individually issued, protected links to the documents prepared for them. The links expire after a set period.
The following are processed in particular:
- about employees: name, business email address, role and account status, together with the details required for signing in and for keeping it traceable;
- about customer contact persons: name, position, business contact details and notes on the course of the matter;
- about customer companies: company details and technical information about the site, in so far as required to assess a project.
Details about employees originate from NRG Solutions AG itself; details about customers originate from the business relationship or, where we made the approach, from publicly available sources (section 6). We do not purchase data. The legal basis is the initiation and performance of contracts and our legitimate interest in the orderly handling of our projects (Art. 31(1) FADP, Art. 6(1)(b) and (f) GDPR).
8. Cookies, Storage Entries and Embedded Services
We do not set any cookies on the publicly accessible pages of this website. We do not carry out web analytics, use no advertising or tracking services and create no profiles.
We store entries on your device only for the following purposes:
None of these entries is used to analyse your behaviour or for advertising. In accordance with Art. 45c let. b of the Swiss Telecommunications Act (Fernmeldegesetz, FMG), we hereby inform you of this processing and its purpose and point out that you may refuse it: set your browser to block cookies and local storage entries or to delete them when it is closed. The website remains usable; it will then no longer preselect your language, and areas that require signing in will not be available.
Services of third-party providers, such as the appointment booking tool, are embedded in individual pages. They are only loaded once you activate them with a click; until then there is no connection to the provider. On pages dedicated to such a service, such as appointment booking, it is loaded as soon as the page opens. Once a service is loaded, the provider receives your IP address, browser and device information and the page accessed; it may also store its own entries on your device. The legal basis is our legitimate interest in these services, such as straightforward appointment scheduling (Art. 31(1) FADP, Art. 6(1)(f) GDPR). We deliver all other content of this website ourselves, including the fonts.
9. Recipients and Disclosure Abroad
We disclose personal data only to the following categories of recipients, in so far as required for the purposes described:
Some recipients process personal data outside Switzerland, in particular in EU states, the United Kingdom and the USA. For the EU and EEA states and for the United Kingdom, the Swiss Federal Council has determined that an adequate level of data protection exists; for the USA, this applies to recipients certified under that determination (Art. 16(1) FADP in conjunction with Annex 1 of the Data Protection Ordinance). In all other cases, including sub-processors of our providers, we rely on standard data protection clauses approved, issued or recognised by the FDPIC (Art. 16(2)(d) FADP); where the GDPR applies, the same applies to transfers to states without an adequacy decision of the European Commission (Art. 46 GDPR). You can obtain a copy of these clauses on request. Authorities in the recipient country may be able to access data under certain circumstances; such access is beyond our control.
10. Retention
We retain personal data for as long as the purpose for which we received it requires. We then delete or anonymise it, at the latest:
- three years after our last contact with you, for details from enquiries, registrations, access-protected areas and conversations;
- two years after the last contact attempt, for details from a direct approach that receives no response;
- 30 days after access, for server log files.
Statutory retention obligations take precedence. We retain project and customer data from our internal systems until the project is completed or cancelled and for ten years thereafter, and details of user accounts for the same period after their deactivation, in so far as they evidence business transactions (Art. 958f CO).
11. Data Security
We protect personal data with technical and organisational measures against loss, destruction, alteration and unauthorised access. These include in particular encrypted transmission, role-based access rights, multi-factor sign-in and time-limited, protected links to documents. We adapt these measures continuously.
12. AI-Assisted Features, Profiling and Automated Decisions
In our customer relationship management system we use AI-assisted features, for example to summarise, structure and retrieve information. The provider engages language model providers as sub-processors for this purpose. Contact details and content from correspondence may thereby reach these systems, including outside Switzerland, the EEA and the United Kingdom (section 9). If you do not wish your details to be processed in this way, please let us know.
These features support the processing. Assessments and decisions, for example on offers, terms or the business relationship, are made exclusively by our staff. We do not carry out profiling and do not make automated individual decisions (Art. 21 FADP, Art. 22 GDPR).
13. Your Rights
Under the FADP and, where applicable, the GDPR, you are entitled to:
- access to information on whether and which personal data we process about you;
- rectification of inaccurate or incomplete data;
- erasure, provided no statutory retention obligation applies;
- restriction of processing;
- release or transfer of your data in a common electronic format;
- withdrawal of consent at any time, with effect for the future.
To exercise your rights, including in respect of our internal systems, please contact contact@nrg-solutions.ch.
Right to Object
Where processing is based on our legitimate interest, you may object to it at any time. This applies in particular to direct approaches by us.
Right to Lodge a Complaint
You may lodge a complaint with the competent supervisory authority, in Switzerland with the Federal Data Protection and Information Commissioner:
Federal Data Protection and Information Commissioner (FDPIC)Feldeggweg 1
3003 Bern
Switzerland
www.edoeb.admin.ch
Persons in the EEA may also contact the data protection authority of their member state.
Version 5.0 · 30 September 2026