Information on Switzerland's New Data Protection Law

On September 1st, 2023, the new data protection regulation will come into effect.

This regulation contains provisions for the protection of natural persons in the processing of personal data and for the free movement of such data.

We provide you with important information regarding the use of Belbo software as well as information about the measures and adjustments we have implemented. Please note that you should also inform yourself comprehensively about the potential impact of the new General Data Protection Regulation on your business. Detailed information is available from the New Data Protection Act (revDSG).

Belbo Measures:

Processing Your Data by Belbo

Belbo Business Software GmbH processes customer data. These are users of the administration and cash register software. You will soon find the updated data processing agreement in your calendar account settings, which you can accept electronically.

Data Request by End Customers

  1. Each customer has the option to download all data stored about them using their email address or mobile number. This includes name and contact data as well as images, uploaded documents, and note fields. The form for downloading data will be accessible via the website https://belbo.com and in the online booking.
  2. If a customer makes a request for data disclosure, you will receive a notification at the location email address.
  3. If the customer has not provided an email address or mobile number and still wants to retrieve their data from you in person, you can add a mobile number or email address with the customer's consent. The customer can then perform a data request via the website. If the customer does not want to provide an email address or mobile number, you can also print the data in the Belbo calendar from the customer file and give it to the customer.
  4. The customer receives a ZIP file with all stored data. It is important that additionally created fields are also retrieved and the customer has access to all data that belongs to their customer profile.

    Exception: You can mark additional fields as "trade secret". This may only contain information that does not uniquely identify the customer and is performance-related. Examples include: color formulas (hairdresser), machine configurations (cosmetics), current strengths (EMS sports).
    In the export, these fields are mentioned, but their content is not displayed.

  5. If you wish, you can also disable direct data requests by your customers. In this case, customers can express their wish for a data request in the online booking via a form. However, you must fulfill this request yourself. Please note that you must comply with the legally prescribed processing period to avoid legal consequences.

Complete Deletion of Customer Data

  1. An important part of data protection regulations is the customer's ability to have their own data completely deleted. Any customer who has their own access can do this themselves in the online booking.
  2. Even if customers ask you as a service provider to delete customer data, you have the option to perform a data protection-compliant deletion in the respective customer file.
  3. If the cash register system is used, the data will continue to be stored in tax-relevant exports. However, additional, non-tax-relevant information such as date of birth and customer notes will be permanently removed.
  4. If you wish, you can also disable direct deletion by your customers. In this case, customers can express their wish for data deletion in the online booking via a form. However, you must fulfill this request yourself. Please note that you must comply with the legally prescribed processing period to avoid legal consequences.

Approval for Sending Marketing Messages

  1. As long as the customer has not consented to processing for marketing purposes, they will not receive marketing emails.
  2. SMS campaigns will no longer be legally possible in the future, as unsubscribing via link is not possible here.

Changes to Online Registration

Registration and appointment booking forms will be expanded with 2 fields:

  1. An expanded data protection field will be added and must be actively clicked as before during registration and appointment booking (without registration).
  2. Another field for receiving marketing messages will be established. You can generally disable this if you do not plan to send marketing messages.

Data Processing Information

  1. In your calendar account settings, you can enter supplementary information about your data strategy. For example, if you regularly import exports of your customer data into third-party software, you should inform your customers about this at this point.
  2. In the "Supplement to Data Protection Agreement" field, you can store your own supplementary information.

What happens to customers who object to data storage?

In this case, the data is deleted and is no longer accessible to you and is permanently deleted.

Exception for Belbo cash register system users: Since the customer leaves data that must be legally retained, the following data will not be deleted:

  1. Gender, name and first name of the customer, provided that an appointment took place or should take place.
  2. Complete appointment history and services performed as well as the performing employee.

However, the data mentioned under point (1) will no longer be findable for you, but only through:

  • explicitly clicking on a past appointment in the calendar
  • printing of the cash register statement or monthly statement

What happens if I unlawfully conduct marketing campaigns with old customers whose approval I do not have in writing?

With the new data protection law coming into force, legal violations will be penalized much more severely than before. Heavy fines are imposed for serious legal violations.

I am uncertain whether all marketing approvals I have collected so far comply with legal requirements. How can I ensure that all campaigns sent after 01.09.2023 are lawful?

In the GDPR Assistant, you have the option to contact all customers who already have marketing permission activated again. In the letter, your customers have the option to update their contact information or to prevent the sending of messages with advertising content. This ensures that all future campaigns are only sent to customers who have explicitly agreed to receive them.

I have a customer status "unreliable customer" and I store information about the customer's behavior in the note field to inform my colleagues about it. Can the customer see this data when requesting their information?

Your customers can now view all information you collect about them when requesting data. If you have previously stored data in your customer files that you believe should not be viewed by the customer, you must remove it. Please note that your customers already had the right to request their own data previously.

I want to ensure that my employees do not misuse customer data.

In the Belbo calendar, you have the option to grant or deny different rights to each login. If you deny the "Customer Database" permission, your employees can enter appointments and view the names of customers for the day, but cannot access the entire customer database.
More on the topic of rights management can be found here.

General Notes on Belbo Use by Your Employees:

Customer Data: In the Belbo calendar, you have the option to create your own customer fields. These then appear in every customer file and can be filled with the desired data. Typical examples of customer fields are birthday, address data, or industry-specific data such as color formulas (hairdresser), training progress (fitness studio), or product line used (cosmetics). Please consider the principles mentioned above when creating and populating these fields. This includes ensuring that this data does not belong to prohibited data. This includes information such as the customer's ethnic origin or sexual orientation.
Furthermore, you may only make such data mandatory fields if they are necessary for the provision of your service.

Learn more about customer fields and mandatory fields in the Belbo manual chapter.

Many different employees often work with the Belbo calendar in your business. Ensure that everyone in your business who has access to customer data is also familiar with the rules of the General Data Protection Regulation. To ensure that your employees process your customer data conscientiously, you can have them sign a confidentiality agreement.

Further Notes:

Create a directory of companies that further process your customer data. These must also work in compliance with data protection law. Such companies include, for example, digital contact directories and email service providers, as well as Belbo Business Software GmbH.

Ensure that you also use your employee data in accordance with regulations. This includes, for example, the use of employee photos on your website or in online booking, which may only be done with the consent of the affected employee. It is best to have a consent form signed for this.

Conclusion

We protect your data and your customer data carefully and in compliance with the law. We also support you with meaningful technical measures in implementing legal regulations. However, our measures and information can only take into account part of your business processes. Please inform yourself thoroughly about the new General Data Protection Regulation and ensure that your customer and employee data is processed correctly in your business.