Fill the BIM cart from the product catalogue

GF Supplier and Service Provider privacy statement

1.    What this notice covers

This privacy notice outlines how we process your personal data as a GF Supplier or service provider for Payment Orders, KYC obligations and due diligence.

This privacy statement is designed to inform you on all relevant information regarding your personal data processing, including on what personal data is collected, our reasons and justifications for doing so, and what your rights regarding this personal data. 
.
2.     Who we are (Controller)

For processing activities under this privacy statement GF AG and its relevant subsidiaries act as the data controller as according to applicable data protection laws. Georg Fischer AG is part of the Georg Fischer group, located in Schaffhausen, Switzerland (hereafter GF)

You can contact our group data protection officer at dataprotection@georgfischer.com. 

In case you wish to make a request relating to your personal data, please use this Privacy Web Form or on local GF websites. This ensures that GF can answer your requests in a timely and efficient manner.

3.    Whose personal data does GF process?

GF processes data on representatives, employees, directors and officers of GF suppliers, subcontractors, vendors, service providers, partners, joint venture partners, consortium partners and research and development partners (“Supplier”). This may also include the listed parties before any official relationship is established (“Potential Supplier”).

4.    What Personal data does GF process?

GF may process the following information including: 
•    Basic contact information, such as: name, date of birth, e-mail address, telephone number, address, position;
•    Qualification data;
•    Personal identification number (if company business identification number is not available);
•    Information on Supplier projects;
•    Information on products and services ordered from the Suppliers and Potential Suppliers and information on products and services offered by the Suppliers and Potential Suppliers to GF;
•    Information on meetings and other activities with the Supplier and Potential Supplier;
•    Information regarding the contents and method of communications (e.g. email, SMS) with the Supplier and Potential Supplier;
•    Preferences of existing Suppliers in recreational activities for the purpose of upholding the relationship with the Suppliers; and
•    Preferences of Potential Suppliers in recreational activities for supplier marketing purposes.

5.     Purpose of Processing Personal Data 

GF will only process your personal data for specific purposes that are justified on a suitable legal basis.
The purposes for processing the personal data are communications to Suppliers and Potential Suppliers, management of GF’s relations with its Suppliers and Potential Suppliers, including the processing of personal data of Suppliers and Potential Suppliers. Such purposes include:
•    ensuring the performance of Suppliers’ and Potential Suppliers’ obligations towards GF and performing GF’s obligations towards Suppliers’ and Potential Suppliers’
•    handling, evaluating and enforcing Supplier’s, Potential Supplier’s or GF's obligations and/or liabilities;
•    exercising GF's rights;
•    upholding and developing the supplier relationships;
•    managing binding or non-binding documents such as quotations, including request for quotations;
•    establishing a supplier relationship between the Supplier or Potential Supplier, and GF Building Flow Solutions; 
•    supplier marketing and communication purposes, including conducting supplier marketing research, direct marketing, automated marketing, informing the Suppliers and Potential Suppliers of new features, new products or launches, and special promotions;
•    managing and handling any product liability matters; 
•    developing GF's services and products; and
•    statistical and analytical purposes, including website analytics.

6.    Legal basis for processing

Collection and processing of personal data may be based on processing being necessary to complete a contract between a supplier or potential supplier with GF. Additionally, the processing of personal data can be based on the legitimate interests of GF. These interests arise from the relationship from the relationship between the Supplier or Potential Supplier, and GF. 
Additionally, GF may send electronic direct marketing to Suppliers and Potential Suppliers based on their consent if such consent is required under the applicable legislation. Your consent is only used where said consent to use such personal data is separate to other consents, informed, and freely given. You may withdraw your consent at any time using the GF Privacy Forms.
 
7.    Sources of Personal Data

The personal data is primarily collected from each data subject themselves, by personnel or through website or applications. In addition to publicly available sources, personal data may in some situations, as allowed by applicable legislation, be collected from other sources than directly from the data subject, e.g. from GF subcontractors or service providers.

Should you subscribe to GF services or fill in a form subscribing to GF services, GF may also use technical means through “pixel” tracking tools to track certain log data on whether communications have been opened or sent. You are welcom to opt-out of this tracking at any time.

GF informs each data subject of the data processing, including of any third-party data sources and data collected from such sources, in accordance with applicable legislation.
The data is entered into secure personal data databases by GF personnel, GF subcontractors or service providers, or by yourselves when volunteering such information.

8.    Disclosure and Transfer of Personal Data Outside the EU/EEA Area 

GF may disclose and transfer personal data outside EU/EEA in accordance with and subject to the limitations imposed by applicable legislation as follows:
•    with a contract entered into between the relevant GF entities, incorporating the European Commission’s Standard Contractual Clauses or other appropriate safeguards for data transfers as listed in the EU General Data Protection Regulation (GDPR), which ensure that adequate data protection arrangements are in place;
•    to authorized third parties to the extent they participate in the processing of personal data for the purposes stated in this privacy statement. The personal data may be processed by such authorized third parties also outside EU or EEA in accordance with a contract entered into between GF Building Flow Solutions and such authorized third party, incorporating the European Commission’s Standard Contractual Clauses or other appropriate safeguards for data transfers as listed in the EU General Data Protection Regulation (2016/679) (GDPR), which ensure that adequate data protection arrangements are in place. GF Building Flow Solutions shall oblige such third parties to keep confidential and adequately secure any such transferred personal data; or
•    based on your consent; or
•    as otherwise permitted by applicable legislation.
For technical reasons and for reasons related to the use of data, your personal data may be stored on servers of external service providers who process the data on behalf of GF. 
Any transfer of personal data shall be made in accordance with the General Data Protection Regulation and any applicable mandatory legislation, as may be amended from time to time.

9.    Sharing and Disclosing of Personal Data

The personal data covered by this Privacy Statement is exclusively processed for the purposes referred to above and will only be shared or disclosed on a strict need-to-know basis with the following categories of recipients:
•    Other companies within the Georg Fischer group;
•    Authorized external service providers, external auditors and/or subcontractors of the Georg Fischer group;
•    A competent public authority, government, regulatory or fiscal agency where it is necessary to comply with a legal or regulatory obligation to which the relevant Georg Fischer group company is subject to or as permitted by applicable local law; or
•    As necessary or appropriate to enforce our terms and conditions, and to protect our rights, privacy, safety or property, and/or that of our affiliates, you or others

10.    Data security and storage principles --Technical and Organizational Controls

GF Building Flow Solutions shall ensure that sufficient technical and organizational personal data protection measures are implemented and maintained throughout its own organization. Further, GF Building Flow Solutions shall ensure that any transfer or disclosure of personal data described in this privacy statement to any third party is subject to GF Building Flow Solutions having ensured an adequate level of data protection by agreements or by other means required by law.

Technical controls: 

Physical material is stored in locked spaces with restricted access. Any IT systems are secured by means of the operating system’s protection software. Access to the systems requires entering a username and a password and data transfers happen via high encryption channels.

Organizational controls:

Within the organization of GF, the use of the personal data is instructed, and access to IT systems including personal data is limited to such persons who are entitled to access them on the basis of their work assignments or role and who are subject to confidentiality obligations regarding the personal data.

11.    How long is your data stored? (data retention)
The Supplier personal data may be stored as long as GF needs it for the above listed purposes, however typically not longer than ten years.
The Potential Supplier personal data may be stored as long as GF needs it for the above listed purposes, however typically not longer than two years.

12.    Rights of Data Subjects

Unless any limitations apply, each data subject has the following rights regarding the personal data processed that is covered by this privacy statement:

•    the right to access all personal data GF has on them;
•    the right to request that GF corrects, erases or stops using any erroneous, unnecessary, incomplete or obsolete personal data;
•    the right to withdraw any consent previously provided by them, including an objection to all direct marketing 
Any requests are most efficiently handled via the request form here: Privacy Web Form. If dissatisfied with the decisions or actions of GF, each data subject has the right to lodge a complaint with their country’s data protection authority.

13.    Changes to this Privacy Policy

Please be aware that GF may change this Privacy Policy from time to time. However, in the event of any material, adverse changes, GF will post a notice informing of such changes both at the beginning of this Privacy Policy and on the Site’s home page. GF advises you to visit this Privacy Policy from time to time to be aware of such changes.

Should you have any additional questions, please don’t hesitate to contact us through our customer service or by writing to us at dataprotection@georgfisher.com.

Last Updated 07/08/2025