Who is responsible for your data
This notice describes how MOM Storen GmbH processes personal data through this website. The Swiss Federal Act on Data Protection (FADP) applies. For privacy enquiries, please contact:
MOM Storen GmbHGrundstrasse 6
6343 Rotkreuz, Switzerland
info@mom-storen.ch
+41 79 455 22 31
Contact, quotations and callbacks
We process information you provide: your name, contact details, optional company information, canton, preferred solution, message and, where relevant, callback time. Depending on the form, we need an email address or telephone number. We also record the language, originating page, submission time and handling status.
We use this information to respond, prepare a quotation, arrange requested callbacks and clarify and handle your project. The forms do not place an order, take payment or subscribe you to a newsletter. Without the required contact details, we cannot process your enquiry through that form.
Photographs, attachments and the 3D configurator
Photographs attached to a form are stored with the enquiry. They are not part of the public gallery; access requires authorised administration. Please only send project-related images and avoid unnecessary information about other people.
A background photograph selected in the 3D configurator is initially processed only in your browser. Selecting it does not upload it. When you submit the design enquiry form, the selected dimensions and options and an available preview image are sent. That preview includes your background photograph if visible in the design. Downloading an image alone keeps it on your device.
The configurator produces an illustrative design. It does not make automated decisions about a contract or about you. Your enquiry is reviewed personally.
Browser storage and cookies
This website does not embed advertising trackers, marketing analytics, external fonts or automatically loaded social media plugins. No customer account is needed to use the public website.
The 3D configurator stores selected dimensions and options locally in your browser so you can continue on the same device. The background photograph is not saved in that persistent browser storage. “Start a new design” resets the options; you can remove all stored website data in your browser settings.
In the administration area we process the name, sign-in email address and a salted password hash. Passwords are not stored in plain text. For password recovery, we send a time-limited link to the email address stored in the admin account. When Google Authenticator is enabled, an app or recovery code is also required; otherwise, we send a separate email code. For Authenticator we store an encrypted secret, time-limited enrolment data, the last accepted time step and hashes of remaining recovery codes. The QR code is generated locally in the browser. Enrolment data expires after ten minutes and is replaced or removed on confirmation, cancellation or a new enrolment. We store only the corresponding hashes, expiry times and limited attempt counters. Reset links expire after 15 minutes and codes after at most 10 minutes. Expired recovery records are removed during later recovery requests; successful recovery deletes the previous reset and session records. A necessary session cookie enables sign-in for up to twelve hours; expired session records are removed during a later sign-in. Another cookie remembers the sidebar state. The sidebar cookie expires after seven days. You can delete or block cookies in your browser, which may restrict administration features.
Operation, security and recipients
The website, its database and uploaded files are hosted by Hostinger on a server in Germany. DNS is managed through Cloudflare, Inc., based in the United States. Cloudflare processes technical name-resolution data on its global network. When the Cloudflare proxy is enabled, it also processes connection and request data to deliver and protect the website; this may take place outside Switzerland and the European Economic Area.
Further information about processing and the transfer safeguards described by the providers: Hostinger · Cloudflare · Cloudflare DPA.
When serving requests, the server processes connection and request data, including the network address, requested path and browser information transmitted. The application protects forms with a counter based on a hashed network identifier. This identifier is pseudonymous, not anonymous. Counters are valid for 15 minutes; expired entries are removed on the next form request.
People authorised to handle enquiries at MOM Storen can access stored enquiries and attachments. Public images and product content can be accessed without signing in. Project information is intended to be shared with involved specialists or suppliers only to the extent necessary for the specific assessment or delivery.
We use Resend (Plus Five Five, Inc., USA) for form notifications and account-security emails. It processes the recipient address, subject and message contents, including contact and project details in enquiries. Sending is configured for the Ireland region (eu-west-1). This does not mean exclusive EU storage: Resend’s data processing agreement also describes processing in the United States and standard contractual clauses for international transfers. Open and click tracking are disabled for our sending domain. Attachments remain in the protected administration area.
Resend privacy · Resend data processing and transfer safeguards
WhatsApp, email and external links
WhatsApp is provided as an external link. You access the service only when you open it. If you send a message there, your phone number, profile and message information are processed by WhatsApp and by us for communication. WhatsApp’s privacy terms also apply; processing may take place outside Switzerland. This website does not automatically send the contents of its enquiry forms to WhatsApp.
You can use the contact form or telephone instead. An email link opens your own email application; your email provider’s terms also apply when sending. Sites opened through external links are governed by their respective operators’ notices.
How long we retain data
Enquiries and images are retained to handle the matter and the resulting business relationship. Once that purpose no longer applies, they are to be deleted or anonymised unless statutory retention duties or necessary evidence for legal claims require retention. The current administration does not automatically delete closed enquiries; “Closed” is not deletion.
Accounting books and records subject to statutory retention generally have to be retained for ten years from the end of the financial year (Article 958f of the Swiss Code of Obligations). This does not apply indiscriminately to every photograph or non-binding enquiry.
Your rights and contact
You can request information about the processing of your personal data and correction of inaccurate data. You can also request deletion, object to processing or withdraw consent for the future. Data delivery or transfer rights apply to the extent provided by law. Statutory duties and overriding legitimate interests can limit individual rights.
Send your request to info@mom-storen.ch. Please identify the enquiry concerned. We may request proportionate verification of identity to avoid unauthorised disclosure.
For privacy concerns you can contact the Federal Data Protection and Information Commissioner (FDPIC). EDÖB / FDPIC
Scope and updates
This notice covers the website as described here. Changes to hosting, forms, analytics or external services require a corresponding update. You can request information about the service providers and the safeguards applicable to your data using the contact details above.
