Last updated: 2026-09-08 · Swiss FADP + GDPR
N&T Swiss AG, Via Luigi Lavizzari 4, 6900 Lugano, Switzerland (UID CHE-332.913.550) is the controller for personal data processed in connection with this website and with inquiries received via natswiss.com.
Contact for data-protection matters: legal@natswiss.ch. No data protection officer has been appointed. N&T Swiss AG is not established in the EU and has not designated a representative under Art. 27 GDPR; requests from EU/EEA residents go to legal@natswiss.ch.
N&T collects personal data only where you submit it — via contact, RFP, sample, catalogue or documentation forms, or by direct e-mail — and where technical processing is necessary to run and secure the website.
When you submit a form, N&T processes the name, work e-mail, company, division, subject and message you provide, together with technical metadata captured at submission for spam triage and as an audit trail: IP address, browser user-agent, the page you came from, the language you were browsing in and the version of the consent wording shown to you. Notes added by N&T staff while handling the inquiry are stored with it. Submissions are stored in a database accessible only to authorised N&T staff.
Answering inquiries, preparing quotes and fulfilling B2B agreements: steps prior to entering into a contract and performance of a contract (Art. 6(1)(b) GDPR). Marketing e-mails and any optional tools: your consent (Art. 6(1)(a) GDPR; Art. 3(1)(o) Swiss Unfair Competition Act). Operating, securing and improving the website, preventing spam and documenting business correspondence: legitimate interests (Art. 6(1)(f) GDPR). Under the Swiss FADP, processing follows the principles of Art. 6 FADP; consent is obtained where the Act requires it.
Advertising e-mails — insights, catalogue updates, a short onboarding series (up to five e-mails in the first month), then no more than one note a month — are sent only to contacts who ticked the optional opt-in box on a form or used the subscribe form. Consent is recorded together with the submission and can be withdrawn at any time via the unsubscribe link in every such e-mail or by writing to unsubscribe@natswiss.ch. Withdrawing consent does not affect the answer to your inquiry. Mailing lists are managed in Resend (see processors). No advertising e-mail is sent without prior consent.
You can request access to the personal data N&T holds about you, its correction or deletion, restriction of processing, and a copy in a portable format. You can object to processing based on legitimate interests and withdraw consent at any time with effect for the future. Requests go to legal@natswiss.ch and are answered within 30 days (Art. 25 FADP; Art. 12 GDPR); N&T may ask you to verify your identity first.
N&T uses third-party processors for hosting, e-mail delivery, database and file storage. Each is bound by a data processing agreement (Art. 28 GDPR; Art. 9 FADP). Transfers to the USA rely on the EU-U.S. and Swiss-U.S. Data Privacy Framework where the processor is certified, and otherwise on the EU Standard Contractual Clauses (Decision (EU) 2021/914) with the Swiss addendum.
Personal data is processed over TLS in transit and encrypted at rest under provider-managed encryption (Supabase Postgres, Cloudflare R2). Access to the inquiry datastore is limited to authorised personnel through the authenticated admin interface. Server logs are kept by the hosting provider for a few days for security monitoring; backups follow provider defaults.
N&T applies access controls, password protection and firewalls in line with industry practice. A personal-data breach that is likely to result in a high risk to you is notified to the competent supervisory authority without undue delay — within 72 hours where the GDPR applies — and to affected individuals where required.
If you believe your data is processed unlawfully, you can lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, edoeb.admin.ch, or — if you are in the EU/EEA — with the supervisory authority of your member state (Art. 77 GDPR).
This policy is reviewed when processing changes. The date at the top shows the current version. In case of discrepancy between language versions, the English version prevails.