GDPR Compliance
Last updated · June 2026
P・M・Z Switzerland is established in Switzerland and primarily subject to the Swiss revised Federal Act on Data Protection (revFADP). Because we engage with sports organisations and individuals across the European Union and the EEA, we also align our practices with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") where it applies to our processing.
1. Our Role
In our capacity as a market opener and value-added partner promoting bespoke solutions to athletes and sports clubs, P・M・Z Switzerland acts as the data controller for the personal data collected through this website and our direct outreach. When we operate technology on behalf of a client club or federation, we act as a data processor under a written Data Processing Agreement (DPA).
2. Lawful Bases (Art. 6 GDPR)
- Consent — for sending the requested guide after email verification, and for any future marketing communications.
- Pre-contractual measures — to respond to executive briefing requests.
- Legitimate interests — for site security, fraud prevention, and limited B2B outreach to professional sports organisations, balanced against your rights.
- Legal obligation — to comply with applicable Swiss and EU regulations.
- Performance of a contract — where we are engaged directly to provide services.
3. Data Subject Rights
If you are located in the EU/EEA, you have the right to:
- Access your personal data (Art. 15).
- Request rectification of inaccurate data (Art. 16).
- Request erasure of your data ("right to be forgotten", Art. 17).
- Restrict processing (Art. 18) or object to processing (Art. 21).
- Receive your data in a portable format (Art. 20).
- Withdraw consent at any time, without affecting prior lawful processing.
- Lodge a complaint with your national supervisory authority.
Requests can be sent to performance@p-m-z.ch and will be answered within one month.
4. International Transfers
Transfers of personal data outside Switzerland or the EEA are protected by the EU Standard Contractual Clauses (2021/914) together with the Swiss FDPIC addendum, or another mechanism recognised under Art. 46 GDPR. We perform a transfer impact assessment where required.
5. Security
We implement appropriate technical and organisational measures: encryption in transit, restricted access to production systems, row-level security on our database, double opt-in for guide downloads, short-lived verification tokens, and audit logging of email delivery.
6. EU Representative
Given the limited scope of our processing of EU residents' data and the nature of our B2B outreach, we currently rely on the derogations of Art. 27(2) GDPR. If you believe an EU representative should be designated for a specific engagement, please contact us — we will appoint one where required.
7. Data Protection Contact
Privacy enquiries: performance@p-m-z.ch