1. Responsible Entity
Lilya GmbH
Badstrasse 29
5400 Baden, Switzerland
Email: info@lilya.ch
This privacy policy applies to the website www.lilya.ch, the associated Shopify online store, and our physical store in Baden.
2. Principles of Data Processing
We process personal data in accordance with the Swiss Data Protection Act (revDPA) and – where applicable – the EU General Data Protection Regulation (GDPR).
We collect and process personal data exclusively for the purposes described in this policy and only to the extent necessary.
3. Collection and Purpose of Data Processing
In particular, we process the following categories of data:
a) When visiting the website
-
Server log files (IP address, date/time, pages accessed, browser type, operating system, referrer URL, provider)
Purpose: Operation, security, optimization, and statistical analysis.
b) Cookies and similar technologies
We use technically necessary cookies for the operation of the shop (e.g., shopping cart, language, login).
In addition – with your consent – analytics or marketing cookies may be used (e.g., Google Analytics, Google Ads).
You can adjust your cookie preferences at any time via the cookie settings.
Note: Without essential cookies, the use of certain functions is restricted.
c) Order and Customer Account
When placing an order or opening an account, we collect:
-
Name, address, email address, phone number
-
Delivery and billing address
-
Order details, payment and shipping information
Purpose: Contract fulfillment, delivery, customer service, accounting, legal obligations (e.g., retention according to OR).
d) Payment
Payments in the online shop are processed via:
-
Stripe (Shopify Payments) – Stripe Payments Europe Ltd., Ireland / Stripe Inc., USA
-
TWINT AG, Zurich
-
Powerpay (MF Group AG), St. Gallen
These payment providers process your data as their own data controllers.
Your payment data (e.g., credit card number, bank details) are not stored on our servers.
The respective privacy policies of the providers apply:
e) Shipping
For delivery, we pass on your delivery address to Swiss Post.
They only receive the information necessary for delivery.
f) Contact and Support
If you contact us via the contact form or email (info@lilya.ch), we store your information for processing and clarifying follow-up questions.
g) Newsletter
If you subscribe to our newsletter, we collect your email address and your consent (double opt-in).
The newsletter is sent via Mailchimp (The Rocket Science Group LLC, USA).
Data transfers are made in accordance with the Standard Contractual Clauses and the Swiss-U.S. Data Privacy Framework (DPF).
You can unsubscribe from the newsletter at any time via the unsubscribe link or by contacting info@lilya.ch.
h) Web Analysis and Advertising
To analyze and optimize our online presence, we use:
-
Google Analytics (Google Ireland Ltd.)
-
Google Ads (advertisements/remarketing)
These services use cookies to analyze user behavior anonymously or pseudonymously.
IP anonymization is activated.
You can refuse the storage of cookies in your browser settings or in the cookie banner.
i) Social Media and Embedded Content
Our website may include content and functions from third-party providers (e.g., Instagram, Pinterest, YouTube, Google Maps).
These providers may collect your IP address and other data as soon as their content is loaded.
Please refer to the privacy policies of the respective providers.
4. Data Disclosure and International Transfer
We only disclose personal data to the extent necessary for the purposes mentioned above or if there is a legal obligation.
Data may be transferred to countries outside of Switzerland and the EEA (especially to the USA), e.g., to:
-
Shopify Inc., Canada/USA
-
Google LLC, USA
-
Mailchimp (Rocket Science Group LLC), USA
-
Stripe Inc., USA
We ensure an adequate level of data protection through appropriate guarantees (Standard Contractual Clauses, Swiss-U.S. Data Privacy Framework).
5. Retention Period
We store personal data only as long as it is necessary for the respective purposes or as legally required:
-
Order data & accounting records: 10 years (legal retention obligation)
-
Contact inquiries: 24 months
-
Newsletter data: until consent is revoked
-
Log files: 6 to 12 months
6. Data Security
We take appropriate technical and organizational security measures to protect personal data from loss, unauthorized access, misuse, or alteration.
This includes encrypted connections (SSL), access restrictions, and regular data backups.
7. Your Rights
According to the revDPA, you have the right to:
-
Information about the stored data
-
Rectification of inaccurate data
-
Erasure ("right to be forgotten")
-
Data portability or transfer
-
Objection to direct marketing
To exercise these rights or for questions about data protection, please contact us at:
info@lilya.ch
You can also contact the Federal Data Protection and Information Commissioner (FDPIC).
8. Changes to this Privacy Policy
We reserve the right to adapt this privacy policy at any time.
The current version published on our website is always authoritative.
Status: October 11, 2025
Lilya GmbH
Badstrasse 29, 5400 Baden, Switzerland
info@lilya.ch