This privacy policy has been translated and we assume that it is correct. However, the German version shall prevail for the interpretation of the Privacy Policy. In the event of any discrepancies between the English and German translations, the German version shall prevail.

Privacy Policy

Effective date: 10 November 2025


I. Summary

This summary provides a quick overview of what personal data we process, why we process it, and what rights you have.
The full policy below explains these aspects in more detail.


1. Data Controller

3forONE AG
Obere Paulistrasse 13
8834 Feusisberg – Switzerland
Email: support@3forone.com
Telephone: +41 52 544 88 88

3forONE operates the following platforms:

  • 3forone.com – community, profiles, courses, news, communication

  • 3forone.auction – online and hybrid auctions

  • bbag.auction – online auctions operated technically on behalf of Baden-Badener Auktionsgesellschaft e. V. (BBAG)


2. What data we process

We process personal data generated when you use our platforms, in particular:

  • information you provide during registration or profile creation,

  • communication and contractual data,

  • technical connection data,

  • usage information from platform activities.

We process only the data necessary to operate and improve our services.


3. Why we process your data

  • to operate, secure, and maintain our platforms,

  • to conduct auctions and related transactions,

  • to provide personalized content and recommendations,

  • to manage communication and user support,

  • to analyse and improve our services,

  • to send newsletters or information (only with your consent).

We do not sell or share your personal data with third parties for advertising purposes.


4. Cookies and tracking

  • Necessary cookies: enable login, language, security, and stability.

  • Optional cookies (e.g., Google Analytics): used only with consent.

  • Server-side analytics: essential for stability, security, and fraud prevention; processed internally only.


5. Your rights

You have the right to request access, rectification, deletion, restriction, data portability, objection, and to lodge a complaint (with the FDPIC in Switzerland or the competent EU authority).
Contact: support@3forone.com


II. Full Privacy Policy


1. Controller

3forONE AG
Obere Paulistrasse 13
8834 Feusisberg – Switzerland
Email: support@3forone.com
Telephone: +41 52 544 88 88


2. Hosting and infrastructure

Our platforms are hosted on servers within the European Union.
Technical maintenance is provided by authorized IT partners under data-processing agreements pursuant to Art. 28 GDPR.


3. Categories of personal data

We process personal data collected during registration, communication, and platform use, including:

  • identification data (name, email address, language),

  • contractual and communication data,

  • technical usage data (system logs, device details, timestamps).


4. Purposes and legal bases

Purpose

Description

Legal Basis

Platform operation

Provision, security, stability

Art. 6 (1)(b), (f) GDPR

Auctions and transactions

Registration, bidding, communication

Art. 6 (1)(b) GDPR

Personalization

Tailoring content and recommendations

Art. 6 (1)(b), (f) GDPR

Analysis & optimization

Technical improvement, quality assurance

Art. 6 (1)(f) GDPR

Newsletter

Only with explicit consent

Art. 6 (1)(a) GDPR

Legal obligations

Compliance, documentation

Art. 6 (1)(c) GDPR


5. Server-side logging

To ensure functionality, security, and traceability, our systems record certain technical events (such as logins and access activity).
This processing is technically necessary and cannot be disabled.
Evaluation takes place exclusively within 3forONE AG.


6. Cookies and consent management

Cookies are used to support navigation, security, and analytics.

  • Essential cookies: always active.

  • Optional cookies (e.g., analytics): activated only with your consent through our consent banner.

You may change or withdraw consent at any time.


7. Google Analytics

We use Google Analytics (Google Ireland Ltd., Dublin) for statistical analysis with IP anonymization enabled.
Processing occurs solely based on your consent (Art. 6 (1)(a) GDPR).
Data are retained for a maximum of 14 months.
You can withdraw consent at any time via the cookie settings or Google opt-out add-on.


8. Communication and newsletters

Contact requests are processed solely to handle your inquiry (Art. 6 (1)(b),(f) GDPR).
Newsletters are sent exclusively after double opt-in using Mailjet (EU-based).
You may unsubscribe at any time.


9. Auctions and responsibilities

For auctions hosted on 3forone.auction and bbag.auction:

  • 3forONE AG acts as data controller (Art. 4 (7) GDPR) for technical operation and data processing.

  • The respective auction organizer (e.g. BBAG e. V.) is responsible for its own content, sale procedures, and contractual performance.

  • No joint controllership exists under Art. 26 GDPR.

Personal data (e.g. contact or purchase details) are shared with the organizer only as necessary for auction or contract execution.


10. Data sharing

Data may be disclosed solely to:

  • IT and hosting providers,

  • payment or delivery service providers (where necessary),

  • auction organizers or sellers for contract execution.

We do not share data with third parties for advertising or profiling purposes.


11. Data security

All platforms use SSL/TLS encryption.
Passwords are securely hashed (bcrypt / argon2).
Role-based access control and multi-factor authentication are implemented.
Regular backups and updates ensure ongoing data protection.


12. Data transfers to third countries

If data are transferred outside Switzerland or the EU/EEA (e.g. to Google or Stripe), such transfers rely on EU Standard Contractual Clauses (SCCs) and additional technical safeguards.


13. Data retention

Personal data are stored only as long as necessary for the purposes described or as required by law.


14. Minors

Use of our platforms is permitted from the age of 16 or with parental consent.


15. Your rights

You have the right to access, rectify, erase, restrict processing, request data portability, and object to processing.
Requests can be sent to support@3forone.com.
Supervisory authority in Switzerland: Federal Data Protection and Information Commissioner (FDPIC).


16. Right to object

You may object at any time to processing based on Art. 6 (1)(e) or (f) GDPR.
In the case of direct marketing, you may object without providing reasons.


17. Data-breach notification

In the event of a personal-data breach, we will notify the competent authority within 72 hours (Art. 33 GDPR) and, if necessary, the affected individuals (Art. 34 GDPR).


18. Updates

This policy is reviewed and updated regularly.
The latest version is available at www.3forone.com.


19. External services and integrated content

Our platforms may include or connect to external services such as livestreams, payment systems, or social-sharing functions.
Limited data exchange may occur with:

  • Stripe (for secure payment processing),

  • Mailjet (for newsletters),

  • Zoom (for webinars and live seminars),

  • Meta / Facebook / Instagram, X (Twitter) and YouTube (for embedded or shareable content).

These integrations are configured to be as privacy-friendly as possible (e.g. consent-based activation, extended privacy mode).
Data are transmitted only if you actively use such functions or participate in related services.

Each provider’s own privacy policy applies in addition to this one.