Privacy Policy
Last updated: 25 May 2026
We are pleased that you are visiting our website and thank you for your interest in our photo booth solutions for business customers. The protection of your personal data is a central concern for us. In this Privacy Policy, we transparently inform you about which data we collect, the purposes for which we use it, and the rights to which you are entitled.
This Privacy Policy has been prepared in accordance with the revised Swiss Federal Act on Data Protection (revFADP). Where individuals from the EU/EEA visit our website, we additionally take into account the requirements of the EU General Data Protection Regulation (GDPR).
The controller responsible for data processing within the meaning of the revFADP is:
Pixora Marketing GmbH
Hagenholzstrasse 102
8050 Zurich, Switzerland
Telephone: +41 44 577 62 55
Email: info@pixora.ch
Website: pixora.ch
This Privacy Policy applies to the processing of personal data by Pixora Marketing GmbH on the website pixora.ch and on any subdomains associated with it.
The primary legal basis is the Swiss revFADP. As our website may also be accessed by individuals from the EU/EEA, we additionally take the GDPR into account. Where consent is required, we obtain it prior to processing. Otherwise, we base our processing on the following legal grounds:
- Art. 6(1)(a) GDPR (consent)
- Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures)
- Art. 6(1)(c) GDPR (legal obligation)
- Art. 6(1)(f) GDPR (legitimate interests)
- Art. 31 revFADP (overriding interests)
Personal data: Any information relating to an identified or identifiable natural person (under the GDPR: “personal data”).
Processing: Any operation involving personal data, in particular collecting, storing, using, transmitting and erasing.
Controller: The natural or legal person who determines the purposes and means of the processing.
Processor: A person or entity that processes personal data on behalf of the controller.
Cookies: Small text files stored in the user’s browser that enable recognition and analysis of user behaviour.
Each time our website is accessed, our hosting provider automatically collects information that your browser transmits to our server. These so-called server log files include:
- anonymised IP address of the accessing device
- date and time of access
- name and URL of the file retrieved
- amount of data transferred
- notification of successful retrieval
- browser type, browser version and operating system
- referrer URL (previously visited page)
These data are evaluated exclusively to ensure uninterrupted operation of the website and to improve our offering. Storage takes place for security reasons for a maximum of 14 days. The legal basis is our legitimate interest pursuant to Art. 6(1)(f) GDPR and Art. 31(2)(a) revFADP.
For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of the browser changes from “http://” to “https://” and by the padlock icon in your browser bar.
Our website is operated on servers provided by our hosting partner. As part of the hosting service, personal data (e.g. IP addresses, contact enquiries) is processed. We have concluded a data processing agreement with the provider in accordance with Art. 9 revFADP and Art. 28 GDPR.
In addition, content elements (e.g. emoji icons) are loaded from WordPress.com (Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA). Data may be transferred to the USA in the process. The transfer is based on the Swiss-US Data Privacy Framework and the EU Standard Contractual Clauses.
Our website uses cookies and comparable technologies (e.g. LocalStorage, web beacons, pixel tags). Cookies are small text files stored on your device and assigned to your browser.
We distinguish between:
- Necessary cookies: These are technically required to operate the website (e.g. language preference via WPML, session management, storage of your cookie selection).
- Statistics cookies: These collect anonymised data to analyse user behaviour.
- Marketing cookies: These are used to make content and advertising more relevant, as well as to integrate external content (e.g. social media feeds, embedded videos).
To manage your consent, we use the WordPress plugin Reply42 Cookie Consent, which we operate ourselves. The plugin was developed by our web agency Reply42 and runs exclusively on our own servers. The consent tool itself does not transfer your data to any third party (and in particular does not transfer data to third countries).
When you first access the website, a cookie banner is displayed in which you are informed about the cookie categories used and can grant or refuse your consent in a granular manner. The “Accept” and “Reject” buttons are designed with equal prominence (FDPIC-compliant, no so-called “dark patterns”). Your selection is stored in a technically necessary cookie named “r42cc_consent” on your device (storage period: 30 days).
To document consent pursuant to Art. 7(1) GDPR and Art. 6(6) revFADP, the plugin logs your selection in a database on our server. The following data is stored:
- a randomly generated consent ID (UUID)
- your IP address in hashed form (SHA-256 with a site-specific salt — the original IP address cannot be reconstructed from it)
- browser identifier (user agent)
- the selected cookie categories
- the language in which the banner was displayed
- the URL of the page on which consent was given
- type of action (accept, reject, individual selection, withdrawal)
- timestamp
As long as you have not yet made a selection, all non-essential cookies and third-party scripts (e.g. Google Analytics, embedded YouTube videos, embedded Google Maps via Snazzymaps, social media feeds from Facebook, Instagram, X/Twitter, TikTok, Google Reviews/Trustindex, and reCAPTCHA) are automatically blocked by the plugin. For Google services, we additionally implement Google Consent Mode v2, so that only those signals corresponding to your consent are transmitted to Google.
You can withdraw or adjust your consent at any time via the “Cookie settings” link in the footer of our website. The legal basis for processing the consent logs is Art. 6(1)(c) GDPR (legal obligation to demonstrate consent) and our legitimate interest in compliance documentation under Art. 6(1)(f) GDPR and Art. 31(2) revFADP.
8.1 Contact Form (Contact Form 7)
When you send us enquiries via the contact form on our website, your details from the enquiry form, including the contact data you provide there (name, company, email address, telephone number, message), are stored by us for the purpose of processing the enquiry and in case of follow-up questions.
We do not share this data without your consent. Processing is based on Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in responding to your enquiry). We use the WordPress plugin Contact Form 7 for data entry. The data is processed exclusively on our servers.
8.2 Email and Telephone Contact
If you contact us by email or telephone, your details will be stored for the purpose of processing the enquiry and in case of follow-up questions.
8.3 WhatsApp Business
We offer you the option to contact us via WhatsApp Business. The provider is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, a subsidiary of Meta Platforms, Inc. (1601 Willow Road, Menlo Park, California 94025, USA).
When you use WhatsApp, personal data (telephone number, profile picture, message content, timestamps) is transmitted to WhatsApp/Meta. Transfer to the USA may take place. This transfer is based on the EU-US Data Privacy Framework and the Swiss-US Data Privacy Framework.
Please note that we have no influence over data processing by WhatsApp/Meta. Further information can be found in WhatsApp’s Privacy Policy: www.whatsapp.com/legal/privacy-policy
On our website you have the option of signing up for our newsletter to receive regular information about new products, industry trends and reference projects.
Registration takes place via a simple form based on Contact Form 7 (see section 8.1 above). The data submitted is sent to our business email address info@pixora.ch and managed internally on our own systems. We do not currently use an external email marketing platform (e.g. Mailchimp, Brevo, MailPoet); your registration data is not transferred to any third party.
The following data is processed in connection with the newsletter:
- email address (mandatory)
- where applicable, name and company (voluntary)
- time of registration
By submitting the registration form, you give us your consent to use your contact details to send the newsletter. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and Art. 6(6) revFADP.
You can unsubscribe from the newsletter at any time by sending a short informal message to info@pixora.ch. After withdrawal, your data will be deleted unless further storage of the registration is required for evidentiary purposes.
10.1 Google Analytics (Universal Analytics – Legacy)
On our website, the measurement tag “Google Analytics” (Universal Analytics, property ID UA-122819504-1) of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, has historically been embedded. Universal Analytics was discontinued by Google on 1 July 2023 and has not collected any new data since that date. The tag will be removed from our website as part of ongoing modernisation, or replaced with an up-to-date, consent-based analytics solution (Google Analytics 4 with Consent Mode v2).
Until full replacement, the Universal Analytics tag is blocked by our consent tool as long as you have not consented to corresponding statistics cookies.
11.1 Google reCAPTCHA
To protect our forms against spam and automated abuse, we use Google reCAPTCHA v2 (Google Ireland Limited). reCAPTCHA checks various characteristics (e.g. IP address, mouse movements, time spent) to determine whether input is being made by a human or by an automated programme. Processing takes place on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR. Further information: policies.google.com/privacy
11.2 Facebook Feed (Smash Balloon)
On certain subpages, we display content from our Facebook page using the WordPress plugin “Smash Balloon Custom Facebook Feed”. The plugin provider itself (Smash Balloon LLC, USA) does not process data from our website visitors; the data is retrieved server-side by our WordPress installation from the Facebook API. However, when the embedded images and content are loaded, connections are established with servers of Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland) and Meta Platforms, Inc. (1601 Willow Road, Menlo Park, California, USA). The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. Further information: facebook.com/privacy/policy
11.3 Instagram Feed (Smash Balloon)
With the “Smash Balloon Instagram Feed” plugin, we embed content from our Instagram profile. Here too, connections are established with servers of Meta Platforms Ireland Limited and Meta Platforms, Inc. (USA) as soon as content (images, reels) is loaded. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. Further information: privacycenter.instagram.com/policy
11.4 X/Twitter Feed (Smash Balloon Custom Twitter Feeds)
With the “Custom Twitter Feeds” plugin, we embed content from our X/Twitter profile. When the content is loaded, connections are established with servers of X Corp. (1355 Market Street, San Francisco, CA 94103, USA; formerly Twitter International Unlimited Company, Ireland). The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. Further information: x.com/en/privacy
11.5 YouTube Feed (Smash Balloon Feeds for YouTube)
Videos from the YouTube platform (Google Ireland Limited) are embedded on our website. Where possible, we use the extended data protection mode (“youtube-nocookie.com”). When you access a page with an embedded video, a connection to YouTube servers is established and cookies may be set. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. Further information: policies.google.com/privacy
11.6 TikTok Feed (Smash Balloon Feeds for TikTok)
With the “Feeds for TikTok” plugin, we embed content from our TikTok profile. When the content is loaded, connections are established with servers of TikTok Technology Limited (10 Earlsfort Terrace, Dublin 2, Ireland) and ByteDance Ltd. (Beijing, China). This may result in personal data being transferred to the USA, the United Kingdom and China. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR and, for transfers to third countries without an adequacy decision, Art. 49(1)(a) GDPR. Further information: tiktok.com/legal/page/eea/privacy-policy/en
11.7 Google Reviews (Trustindex)
To display our Google reviews, we use the “Widgets for Google Reviews” / “Reviews Feed” widget by Trustindex.io Kft. (Andrássy út 60, 1062 Budapest, Hungary). The review data is retrieved via the Google API; when the reviews are displayed, connections are established with Trustindex servers (Hungary/EU) and, where applicable, with Google (see above). Personal data of our website visitors is only processed in the form of technical connection data (IP address, user agent). The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. Further information: trustindex.io/privacy-policy
11.8 Embedded Map (Snazzymaps / Google Maps)
On our contact page, we embed an interactive map showing our location. The integration is provided via the Snazzymaps service (Snazzy Maps, operated by Atomic Spin LLC, USA), which delivers styled map representations based on the Google Maps API (Google Ireland Limited / Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). When the map loads, connections are established to Snazzymaps servers and to Google servers, and personal data (in particular IP address, browser and device information, and where applicable your approximate location) may be transmitted to these providers. Transfer to the USA may take place. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR; transfers to the USA are based on the Swiss-US and EU-US Data Privacy Frameworks and on the EU Standard Contractual Clauses. Further information: snazzymaps.com/privacy-policy and policies.google.com/privacy
11.9 WhatsApp Link
On our website, we link to our WhatsApp Business number via a button (wa.me). This is purely a link; no data exchange with WhatsApp/Meta takes place until you actively click on the link and start a conversation in WhatsApp. See section 8.3 above.
11.10 WPML (Multilingual Plugin)
To provide multilingual content (German/English) we use the WordPress plugin WPML. A technically necessary cookie is set to store your language selection. No personal data is transferred to third parties.
11.11 Imagify
To optimise the loading speed of our website, we compress image files with the Imagify service (WP Media SAS, 331 rue Pierre Mauroy, 59000 Lille, France). The compression takes place server-side; image files are transmitted to an Imagify server for this purpose. No personal data of website visitors is transferred. Further information: imagify.io/privacy
11.12 Sucuri Security
To protect against cyber attacks and malware, we use the Sucuri security service (Sucuri Inc., 4035 Westshore Blvd, Tampa, Florida, USA) and the WordPress plugin “All-In-One Security (AIOS)”. IP addresses and access patterns may be processed to detect attacks. The legal basis is our legitimate interest in the security of our website pursuant to Art. 6(1)(f) GDPR. Further information: sucuri.net/privacy
11.13 Yoast SEO
For search engine optimisation, we use the WordPress plugin Yoast SEO. The plugin does not process any personal data of website visitors and does not embed any external resources.
In connection with the services mentioned above (in particular Google services / Google Maps, Snazzymaps, Meta/WhatsApp/Facebook/Instagram, X/Twitter, TikTok/ByteDance, WordPress.com, Sucuri), your personal data may be transferred to the USA, the United Kingdom, China or other third countries. We base these transfers on:
- Swiss-US Data Privacy Framework (recognised by the Federal Council since 15 September 2024)
- EU-US Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023)
- EU Standard Contractual Clauses (SCC) pursuant to Decision (EU) 2021/914
- your express consent pursuant to Art. 49(1)(a) GDPR and Art. 17 revFADP, in particular for transfers to third countries without an adequacy decision (e.g. China)
We only store personal data for as long as is necessary for the respective purposes or as required by statutory retention periods:
- Server log files: max. 14 days
- Contact enquiries: until final processing, max. 24 months
- Business correspondence and quotations (tax-relevant): 10 years (retention obligation under the Swiss Code of Obligations, Art. 958f CO)
- Newsletter registrations: until withdrawal of consent; after unsubscribing, the email address is removed from the distribution list and the registration record is retained for up to 3 years as proof of the consent given
- Consent cookie (r42cc_consent) on your device: 30 days
- Consent logs (consent log in our database, with hashed IP): 12 months
You have the following rights under the revFADP and the GDPR:
- Right of access (Art. 25 revFADP / Art. 15 GDPR): You can request information about which personal data we process about you.
- Right to rectification (Art. 32(1) revFADP / Art. 16 GDPR): You can request the correction of inaccurate data.
- Right to erasure (Art. 32(2)(c) revFADP / Art. 17 GDPR): You can request the deletion of your data.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 28 revFADP / Art. 20 GDPR).
- Right to object (Art. 30 revFADP / Art. 21 GDPR): You can object to the processing of your data.
- Withdrawal of consent: You can withdraw consent that has been granted at any time with effect for the future.
- Right to lodge a complaint with a supervisory authority: In Switzerland with the Federal Data Protection and Information Commissioner (FDPIC), in the EU with the respective competent national data protection authority.
To exercise your rights, please contact us informally at: info@pixora.ch. We will respond to your request as quickly as possible, and at the latest within 30 days.
For Switzerland:
Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
3003 Bern, Switzerland
www.edoeb.admin.ch
We take appropriate technical and organisational measures (TOMs) to protect your data against accidental or unlawful destruction, loss, alteration and unauthorised access. These include, among others:
- SSL/TLS encryption of data transmission
- access restrictions and role-based permissions
- regular backups (BackWPup, UpdraftPlus) and security updates
- web application firewall and malware scanner (Sucuri, All-In-One Security)
In the event of a data breach with a high risk to the data subjects concerned, we will inform the FDPIC and, where applicable, the affected individuals in accordance with Art. 24 revFADP.
We reserve the right to amend this Privacy Policy in order to keep it in line with current legal requirements at all times or to implement changes to our services, for example when introducing new offerings. The new Privacy Policy will then apply to your next visit.
Last updated: 25 May 2026 · Pixora Marketing GmbH, Zurich