Haelixa
  • About
  • Product
  • Team
  • News
  • Contact Us

Privacy Policy

Last updated: January 15, 2025

Haelixa AG ("Haelixa," "we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, store, and share personal data when you visit our website at haelisa.com, use our molecular traceability platform, or otherwise interact with us as a business or individual.

This policy is written in accordance with the EU General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (FADP / nFADP effective September 1, 2023), and other applicable data protection laws.

1. Data Controller

The data controller responsible for your personal data is:

Haelixa AG
Technoparkstrasse 1
8005 Zurich, Switzerland
Email: privacy@haelisa.com
Phone: +41 44 500 1234

For all data protection enquiries and requests to exercise your rights, please contact us at privacy@haelisa.com.

2. What Personal Data We Collect

2.1 Information You Provide Directly

When you contact us, request a demonstration, or engage with our services, we may collect:

  • Full name and job title
  • Business email address and phone number
  • Company name and industry sector
  • Physical business address
  • Content of messages and enquiries you send to us
  • Information provided in connection with a contract or service agreement
  • Payment information (processed through secure third-party payment processors — we do not store full card data)

2.2 Information Collected Automatically

When you visit haelisa.com, we automatically collect certain technical and usage information, including:

  • IP address and approximate geographic location (country/region)
  • Browser type, version, and operating system
  • Pages visited, time spent on pages, and navigation paths
  • Referring URLs and exit pages
  • Device type (desktop, mobile, tablet)
  • Date and time of access
  • Cookie and local storage identifiers (see our Cookie Policy)

2.3 Information from Business Partners and Enterprise Clients

When your organization engages Haelixa under a service agreement, we may receive:

  • Contact details of authorized users and administrators
  • Supply chain data containing material batch information and authentication event records
  • Laboratory sample metadata submitted through our TraceCloud platform

Such enterprise data is processed under the terms of our Data Processing Agreement (DPA) entered into with each enterprise client.

3. How We Use Your Personal Data

3.1 Providing Our Services

We use your data to deliver, manage, and support the Haelixa molecular traceability platform and related laboratory services. This includes account creation and management, responding to technical support requests, processing service orders, and issuing invoices.

3.2 Business Communications

We use contact information to respond to your enquiries, provide quotations, deliver requested product demonstrations, and communicate about ongoing service relationships. We will not send marketing communications without a lawful basis for doing so.

3.3 Website Analytics and Improvement

We analyze website usage data to understand how visitors interact with our site, identify technical issues, and improve the quality of our content and user experience. This processing is based on our legitimate interest in maintaining an effective digital presence.

3.4 Legal Compliance and Security

We process personal data as necessary to comply with applicable laws, regulations, and legal proceedings; to enforce our contractual rights; to prevent fraud and abuse; and to ensure the security and integrity of our information systems.

3.5 Scientific and Regulatory Reporting

For clients using our platform in regulated industries (pharmaceuticals, medical devices, food safety), we may process technical data to support regulatory audit trails and compliance documentation as required by applicable regulations including GMP, GLP, FDA 21 CFR Part 11, and EU Annex 11.

4. Legal Basis for Processing

Under the GDPR and Swiss FADP, we process personal data on one or more of the following legal bases:

Processing Purpose Legal Basis
Fulfilling a service contract or pre-contractual steps Contract performance (Art. 6(1)(b) GDPR)
Compliance with legal obligations Legal obligation (Art. 6(1)(c) GDPR)
Website analytics, security, legitimate business interests Legitimate interests (Art. 6(1)(f) GDPR)
Optional marketing communications Consent (Art. 6(1)(a) GDPR)
Defending or pursuing legal claims Legitimate interests / Legal obligation

5. Data Sharing and Disclosure

5.1 Service Providers and Processors

We share personal data with carefully vetted third-party service providers who assist in operating our business, including:

  • Cloud infrastructure providers (data hosting and storage)
  • IT security and monitoring services
  • CRM and customer communication tools
  • Professional service providers (legal, accounting, auditing)
  • Payment processing services
  • Courier and laboratory logistics services

All service providers are subject to Data Processing Agreements ensuring they process data only on our instructions and in compliance with applicable data protection law.

5.2 Professional Advisers

We may share data with legal counsel, insurers, and financial advisors as necessary to protect our legitimate business interests, including pursuing or defending legal claims.

5.3 Regulatory Authorities

Where required by law or lawful request from a competent authority, we will disclose personal data to regulatory bodies, law enforcement, or courts.

5.4 Business Transactions

In the event of a merger, acquisition, or sale of all or a portion of our assets, personal data held by us may be transferred to the acquirer, subject to appropriate confidentiality protections.

5.5 No Sale of Personal Data

Haelixa does not sell, rent, or trade personal data to third parties for their own marketing purposes under any circumstances.

6. International Data Transfers

Haelixa is headquartered in Switzerland. Some of our service providers operate from countries outside the European Economic Area (EEA) or Switzerland. When personal data is transferred to countries without an adequate level of data protection as determined by the European Commission or Swiss Federal Council, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules where applicable
  • Transfers to countries benefiting from an EU or Swiss adequacy decision

Switzerland has been recognized by the EU as providing an adequate level of data protection. For further information about international transfers, please contact privacy@haelisa.com.

7. Data Retention

We retain personal data for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our general retention periods are:

Data Category Retention Period
Customer and prospect contact data Duration of relationship + 3 years
Contract and transaction records 10 years (Swiss statute of limitations)
Website analytics data 26 months (anonymized after 12 months)
Authentication event logs (enterprise) As agreed in enterprise DPA (typically 7 years)
Correspondence and support records 5 years from last interaction

8. Your Data Protection Rights

Under the GDPR and Swiss FADP, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your data, subject to legal retention obligations.
  • Right to restriction of processing: Request that we limit how we use your data in certain circumstances.
  • Right to data portability: Receive your data in a structured, machine-readable format where technically feasible.
  • Right to object: Object to processing based on legitimate interests, including direct marketing.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint: You have the right to complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local supervisory authority.

To exercise any of these rights, please contact us at privacy@haelisa.com. We will respond to all legitimate requests within 30 days. In complex cases we may extend this by a further 60 days, notifying you of the extension within the first 30 days.

9. Data Security

Haelixa implements technical and organizational security measures appropriate to the risk of processing, including:

  • End-to-end encryption for data in transit (TLS 1.3) and at rest (AES-256)
  • Role-based access control with principle of least privilege
  • Multi-factor authentication for all platform access
  • Regular security assessments and penetration testing
  • ISO 27001-aligned information security management practices
  • Employee training on data protection and information security
  • Incident response procedures with 72-hour breach notification capabilities

Despite these measures, no internet transmission or storage system is completely secure. If you have reason to believe your interaction with us is no longer secure, please notify us immediately at security@haelisa.com.

10. Cookies and Tracking Technologies

Our website uses cookies and similar local storage technologies to enhance your browsing experience and analyze website usage. We do not use advertising or cross-site tracking cookies. For detailed information, please see our Cookie Policy.

11. Children's Privacy

Our services are directed exclusively at business professionals and are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it promptly.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify existing clients of material changes by email and will post the updated policy on this page with a revised "Last updated" date. We encourage you to review this policy periodically.

13. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:

Data Protection Officer
Haelixa AG
Technoparkstrasse 1, 8005 Zurich, Switzerland
Email: privacy@haelisa.com
Phone: +41 44 500 1234

You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch, or with the supervisory authority of your EU member state.

Haelixa

DNA-based molecular tagging solutions for material traceability and life sciences research.

Company

  • About Us
  • Our Product
  • Team
  • News
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2025 Haelixa. All rights reserved.

We use cookies to improve your experience. Learn more