Privacy Policy
K27 AG
Bahnhofstrasse 4, 6340 Baar, Switzerland Commercial Register of the Canton of Zug: CHE-212.019.272
Last updated: 15.07.2026.
1. Introduction
K27 AG ("K27", "we", "us", or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you visit our website www.k27.ag (the "Website") or interact with us in the course of our strategic advisory services.
We process personal data in accordance with the Swiss Federal Act on Data Protection of 25 September 2020 (FADP / revDSG) and its implementing ordinance. Where applicable — for example, when we offer services to, or monitor the behaviour of, individuals located in the European Economic Area (EEA) — we also comply with the EU General Data Protection Regulation (GDPR).
2. Data Controller and Contact Details
The controller responsible for the processing of personal data described in this Privacy Policy is:
K27 AG
Bahnhofstrasse 4, 6340 Baar, Switzerland
Phone: +41 (0)41 511 54 21
E-mail: info@k27.ag
If you have any questions regarding this Privacy Policy or the processing of your personal data, please contact us at the address above.
3. Categories of Personal Data We Process
Depending on how you interact with us, we may process the following categories of personal data:
a) Data you provide to us directly
- Contact details: name, company, position, e-mail address, phone number;
- The content of your enquiries submitted by e-mail, by phone, or via LinkedIn;
- Information you provide in the course of a business relationship, including contractual and billing data.
b) Data collected automatically when you visit the Website
- IP address;
- Date and time of access;
- Pages visited and referring URL;
- Browser type and version, operating system, device type;
- Language settings.
This technical data is collected in server log files by our hosting provider and is required to deliver the Website, ensure its stability and security, and detect and prevent misuse.
c) Cookies and tracking
Our Website does not use any analytics, tracking, marketing, or third-party cookies. At most, the Website may set strictly necessary technical cookies that are required for its proper functioning (for example, to store your language preference). Such cookies do not require your consent under applicable law. Should we introduce any non-essential cookies or tracking tools in the future, we will update this Privacy Policy accordingly and obtain your consent where required.
We do not knowingly collect sensitive personal data (special categories of data) through the Website.
d) Data from publicly available sources and third parties
In addition to the data you provide to us directly, we may — where permitted and necessary for the purposes set out in Section 5 — obtain personal data from publicly available sources or receive it from third parties. This includes, in particular:
- information from public registers (e.g. the commercial register) as well as from the press, the internet and professional networks (e.g. LinkedIn);
- information provided to us by our clients and business partners, such as contact details of their employees, contact persons or representatives in connection with the preparation and performance of an engagement;
- information received from authorities, advisers or other third parties in connection with the establishment or performance of a business relationship.
We use such data in particular to verify and update contact details, to communicate with the relevant contact persons, and to prepare and perform contracts.
If you provide us with personal data relating to other individuals (e.g. colleagues or contact persons within your organisation), please ensure that you are authorised to do so, that the data is accurate, and that the individuals concerned are aware of this Privacy Policy.
4. Provision of Personal Data
You are generally under no legal obligation to provide us with personal data. However, without certain information we will usually not be able to respond to your enquiry or to enter into or perform a contract with you or with the organisation you represent. The use of our Website also requires the transmission of certain technical data (e.g. your IP address).
5. Purposes of Processing
We process personal data for the following purposes:
- Providing, operating, and securing the Website;
- Responding to enquiries and communicating with prospective and existing clients;
- Preparing, concluding, and performing contracts for our advisory services;
- Client relationship management and administration;
- Invoicing, accounting, and compliance with statutory retention obligations;
- Establishing, exercising, or defending legal claims;
- Complying with legal and regulatory obligations under Swiss law;
- Marketing and business development, where permitted by law (e.g. informing existing clients about our services).
6. Legal Bases for Processing
Under the FADP, the processing of personal data is generally permitted provided the data protection principles (lawfulness, good faith, proportionality, purpose limitation, transparency, data security) are respected.
Where the GDPR applies, we rely on the following legal bases:
- Art. 6(1)(b) GDPR — performance of a contract or pre-contractual measures (e.g. handling your enquiry, providing advisory services);
- Art. 6(1)(c) GDPR — compliance with legal obligations (e.g. accounting and retention duties);
- Art. 6(1)(f) GDPR — our legitimate interests, such as operating and securing the Website, communicating with business contacts, and developing our business, provided your interests and fundamental rights do not override those interests;
- Art. 6(1)(a) GDPR — your consent, where requested. You may withdraw your consent at any time with effect for the future.
7. Disclosure of Personal Data
We disclose personal data to third parties only where this is necessary for the purposes described above, in particular to:
- Service providers (processors) acting on our behalf, such as providers of IT, hosting, e-mail and website services, who are contractually bound to confidentiality and data protection. Our key service providers currently include, in particular, Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg ("AWS"), for the hosting of our Website, with the data being hosted in the AWS Europe (Zurich) Region in Switzerland, and Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland ("Google"), for e-mail and office communication services (Google Workspace);
- Professional advisers, such as lawyers, auditors and accountants, where necessary;
- Companies of the K27 Group, for internal administrative purposes, where permitted;
- Authorities or courts, where we are legally obliged to do so or where disclosure is necessary to protect our rights.
We do not sell personal data.
LinkedIn: Our Website contains a link to our LinkedIn profile. If you follow this link, LinkedIn Ireland Unlimited Company / LinkedIn Corporation processes your data as an independent controller. For details, please refer to LinkedIn's privacy policy.
8. Transfers of Personal Data Abroad
Our service providers may be located outside Switzerland. Personal data is currently transferred in particular to countries within the European Economic Area (EEA), notably Luxembourg and Ireland, and may in certain cases be transferred to the United States (in particular to Amazon Web Services, Inc. and Google LLC as U.S. affiliates of our service providers). The EEA is recognised by the Swiss Federal Council as providing an adequate level of data protection.
Where personal data is transferred to a country that does not provide an adequate level of data protection recognised by the Swiss Federal Council (and, where the GDPR applies, by the European Commission), we ensure appropriate safeguards, in particular by concluding the standard contractual clauses (SCCs) recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC), supplemented where necessary. For transfers to the United States, we additionally rely, where applicable, on the Swiss–U.S. Data Privacy Framework: Amazon Web Services, Inc. and Google LLC are each certified under the Swiss–U.S. Data Privacy Framework. Alternatively, we rely on statutory exceptions (e.g. your express consent or the necessity of the transfer for the performance of a contract with you).
For further information on the safeguards in place, please contact us.
9. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, in particular:
- Enquiry data: for the duration of the correspondence and a reasonable period thereafter;
- Contractual and billing data: for the duration of the business relationship and thereafter in accordance with statutory retention periods under Swiss law (as a rule, 10 years for business records under the Swiss Code of Obligations);
- Server log data: typically deleted or anonymised within a maximum of 30 days.
After expiry of the applicable retention periods, personal data is deleted or anonymised, unless longer retention is required for the establishment, exercise, or defence of legal claims.
10. Data Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration, in accordance with Art. 8 FADP and, where applicable, Art. 32 GDPR. These measures include, among others, encrypted data transmission (TLS/SSL), access restrictions, and the careful selection of service providers. Please note, however, that no transmission of data over the internet can be guaranteed to be completely secure.
11. Your Rights
Subject to the conditions and limitations of applicable law, you have the following rights with regard to your personal data:
- Right of access — to obtain confirmation as to whether we process personal data concerning you and to receive a copy of such data (Art. 25 FADP; Art. 15 GDPR);
- Right to rectification — to have inaccurate personal data corrected (Art. 32 FADP; Art. 16 GDPR);
- Right to erasure — to request the deletion of your personal data (Art. 32 FADP; Art. 17 GDPR);
- Right to restriction of processing (Art. 18 GDPR, where applicable);
- Right to data portability — to receive certain data in a commonly used, machine-readable format (Art. 28 FADP; Art. 20 GDPR);
- Right to object — to object to processing based on legitimate interests, including direct marketing (Art. 21 GDPR, where applicable);
- Right to withdraw consent — at any time, with effect for the future, where processing is based on consent.
To exercise your rights, please contact us at info@k27.ag or at the postal address above. We may request proof of identity before responding to your request. We will respond within the statutory time limits (as a rule, 30 days under the FADP).
Right to lodge a complaint: You may lodge a complaint with the competent supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland (www.edoeb.admin.ch). If you are located in the EEA, you may also contact the supervisory authority of your place of residence or work.
12. No Automated Decision-Making
We do not use automated individual decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
13. Third-Party Websites
Our Website may contain links to third-party websites (e.g. LinkedIn). We are not responsible for the content or data protection practices of such websites. Please review the privacy policies of any third-party websites you visit.
14. Changes to This Privacy Policy
We may amend this Privacy Policy from time to time, in particular to reflect changes in our processing activities or legal requirements. The version published on this Website is the current version. We recommend that you review this Privacy Policy periodically.
K27 AG, Bahnhofstrasse 4, 6340 Baar, Switzerland info@k27.ag | +41 (0)41 511 54 21