Last Updated August 2026

1. Introduction

At Infinigate, we are committed to protecting personal data and respecting the privacy of the individuals with whom we interact. This Privacy Notice (“Notice”) explains how Infinigate Holding AG, a company incorporated in Switzerland under company number CHE-380.527.066, with its registered office at Grundstrasse 14, CH-6343 Rotkreuz, Switzerland, together with its affiliated companies listed here (collectively, “Infinigate”, “we”, “us” or “our”), collects, uses, shares and safeguards personal data in the course of its business activities, including in connection with relationships with vendors, reseller partners and visitors to our websites.

We have prepared this Notice in clear and accessible language to help you understand who we are, what personal data we collect, how and why we process it, how long we retain it and the rights and choices available to you regarding your personal data.

For the purposes of applicable data protection laws, the relevant Infinigate legal entity with which you interact is generally the data controller responsible for the processing of your personal data as described in this Notice. In certain circumstances, Infinigate Holding AG may also act as a controller or joint controller in relation to such processing.

2. When does this Notice apply?

This Notice applies to individuals acting in a business or professional capacity, including professionals representing cybersecurity software/hardware vendors and IT resellers, managed service providers (MSPs), systems integrators and other Infinigate partners as well as website visitors interacting with Infinigate.

This Notice does not apply to Infinigate employees, job applicants or candidates. Information relating to the processing of personal data in those contexts is provided in separate privacy notices made available to those individuals, as required under applicable law.

For detailed information about the use of cookies and similar technologies on Infinigate websites, please refer to our separate Cookie Notice.

In the event of a conflict between this Notice and any applicable local laws and/or regulations, and only to the extent such local laws and/or regulations require a higher level of protection for your personal information, such applicable local laws and/or regulations shall prevail.

3. Who are, what personal data we may process about you and for what purposes?

Depending on your relationship with Infinigate and the way you interact with us, we may collect and process different categories of personal data. The types of personal data we process, the purposes for which we use it, and the legal bases on which we rely may vary depending on whether you are associated with one of our vendors, reseller partners, or are a visitor to our websites.

We may collect personal data directly from you when you do business with us, visit our websites or otherwise interact with us. This may include communication by email or telephone, meetings with our representatives, the execution of contracts, the submission of forms, event registrations, requests for information and interactions through our systems, tools, platforms, and websites. We may also obtain personal data indirectly from the organization with which you are associated or from other third parties where permitted by applicable law.

Please see further details in the table below.

Purpose of processingWhat Infinigate doesCategories of personal data processedGDPR lawful basis
Vendor/Reseller onboarding and relationship management, contract management and executionEstablishing and maintaining business relationships with vendor or re-sellers’ contacts, including managing communication and day-to-day business relationshipContact and identification data: name, business email address, telephone number, job title, company affiliation, company business address Professional and interaction data: records of communications, meeting notes, account/contact preferences, vendor relationship historyLegitimate interest
Vendor/Re-seller screening and due diligencePerforming compliance checks on vendor contacts and related individuals as part of onboarding and ongoing monitoringContact and identification data: name, businessemail address, telephone number, job title/role within the vendor organization, company affiliation Compliance data: due diligence screening results relating to identified individuals (e.g. sanctions and PEP checks) [AM1] [NG2] Legal obligation
Sales, orders and distribution  To processes quotes, orders, licensing and renewalsContact and identification data: business contact details of reseller representative(s)
Transaction data: quotes, orders, renewals and related records, including names and contact details of individuals involved (e.g. requester or approver)
Communication data: correspondence related to orders and commercial activities
Legitimate interest
Compliance and record-keepingMaintaining legally required records relating to identified vendor contacts and their interactionsCompliance and record-keeping data: name, business contact details, billing and invoice contact information, correspondence records, and audit-related documentation involving identified vendor representative(s)Legal obligation
General business interaction and voluntary disclosuresProcessing additional information voluntarily shared during interactions and business communicationsVoluntarily provided information: feedback, opinions, reviews, uploaded files or documents, interests, preferred communication channels and any other information voluntarily shared with InfinigateLegitimate interest
Partner enablement (training and portals)Providing training, certifications, and access to internal systems and, where applicable, third‑party partner or vendor platformsContact and identification data: name, business email, employer (reseller company)
Account data: usernames, authentication data (e.g. hashed passwords), access logs
Training data: course participation, completion status, certifications
Legitimate interest
Management of essential website cookies    Ensuring the proper functioning, security and usability of our websites by enabling core features such as page navigation, session management and access to secure areas      Cookie identifiers: (e.g., session ID) and other technical information required to deliver site functionalityLegitimate interest
Management of non-essential cookies (preferences, statistics/analytics, marketing, and unclassified cookies) and other tracking technologiesTo remember your preferences, understand how visitors interact with our websites, improve website functionality and performance and, where applicable, deliver relevant advertising and improve user experienceCookie identifiers, preference settings, website usage and interaction data, and advertising-related signalsConsent

We may rely on one or more of the following legal bases for processing your personal data:

  • your consent, where required by law or otherwise permitted under applicable law;
  • the performance of a contract with you, or taking steps at your request prior to entering into a contract;
  • compliance with our legal obligations;
  • our legitimate interests, provided that such interests are not overridden by your interests or fundamental rights and freedoms. These interests may include fraud prevention, ensuring the security of our networks and information systems, internal administration and business cooperation and direct marketing (subject to applicable legal requirements – for further information please see section 5 below);
  • the protection of your vital interests, or
  • any other legal basis permitted under applicable law in the jurisdictions in which Infinigate operates.

5. Marketing

We may use your business contact details to carry out business-to-business marketing and related activities, including sharing information about our products and services, events, webinars, industry insights and relevant partner offerings through email, telephone and other communication channels. Where permitted under applicable law, we generally rely on our legitimate interests to undertake such activities.

The rules governing direct marketing, including email marketing and telemarketing, vary by country and by communication channel. Where required by applicable law, we will obtain your prior consent before sending you marketing communications. In certain jurisdictions, where permitted by law, we may rely on a “soft opt-in” or similar exemption to send marketing communications about our own products and services where we have obtained your contact details in the context of an existing or previous business relationship and you have not objected to such communications.

Email marketing and telemarketing activities may be carried out by Infinigate and/or by service providers acting on our behalf and under our instructions. Where you express interest in a particular product, service or offering, we may share relevant lead information, including your business contact details and details of your expressed interests, with the relevant technology vendor and/or authorised reseller partner to enable them to follow up with you regarding that offering.

You have the right to object at any time to the processing of your personal data for direct marketing purposes, including telemarketing. Where we rely on your consent, you may also withdraw that consent at any time. You can opt out of receiving further marketing communications by using the unsubscribe link included in our emails, by informing us during a telephone call or by contacting us using the details provided in this Notice.

6. When do we share your personal data?

We may share your personal data with other companies within the Infinigate group and with trusted third parties where this is necessary for our business operations. This may include technology vendors, software publishers, channel partners, distributors, logistics and fulfilment providers, IT and hosting service providers, payment and financial service providers and professional advisers such as auditors and legal counsels.

We may also share personal data where required to comply with applicable laws and regulations, respond to lawful requests from public authorities, or to protect our rights, systems and business operations.

7. How do we transfer your personal data internationally?

As part of an international group, Infinigate works with affiliated companies, technology vendors, channel partners and service providers that may be located in different countries. As a result, your personal data may be transferred to, stored in or accessed from countries outside the country in which you are located, including through remote access.

Where personal data is transferred internationally, we take appropriate measures to ensure that it remains protected in accordance with applicable data protection laws. Where required, we rely on recognised transfer mechanisms, such as adequacy decisions issued by the relevant authorities or approved contractual safeguards, including standard contractual clauses.

You may contact us using the details provided in this Notice if you would like further information about the safeguards we apply to international transfers of personal data.

8. How long do we keep your personal data?

We retain personal data only for as long as necessary to fulfil the purposes outlined in section 3 above, and to comply with any applicable legal, regulatory or contractual obligations. Once the relevant retention period has ended, your data will be securely deleted, destroyed or irreversibly anonymized to prevent unauthorized access or use.

The specific duration for which your data is retained is determined by a combination of the following criteria:

  • legal and regulatory requirements: compliance with applicable laws, regulations, and government directives that mandate specific retention periods;
  • contractual obligations: commitments arising from agreements with business partners that require data to be retained for a defined period;
  • business and operational needs: requirements related to the continuity of services, customer support, dispute resolution, audits and internal reporting;
  • technical constraints and system capabilities: limitations or capabilities of the systems used to store and manage data, including backup and archival processes, and
  • establishing and/or defending legal claims: the length of time the personal data is necessary for Infinigate to establish or defend itself from legal claims.

When you visit our website, we may collect certain technical information such as your IP address and access time (timestamp); this website log data is stored for a maximum of 48 hours and then deleted, unless a longer retention period is required to investigate security incidents or to comply with applicable legal obligations.

9. How is your personal data secured?

We implement appropriate technical, physical and organisational measures to protect the confidentiality, integrity and availability of your personal data. These measures are designed to safeguard personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access and other forms of unlawful processing.

Where appropriate, we align our security practices with recognised industry standards and frameworks and maintain appropriate certifications and audit processes across relevant Infinigate entities.

At Infinigate, we also maintain procedures to detect, investigate and respond to personal data breaches. Where required by applicable law, we will notify the relevant supervisory authorities and affected individuals of a personal data breach within the regulatory timeframes.

10. Your rights

Individuals may have certain rights in relation to their personal data under applicable data protection laws. These rights may vary depending on the jurisdiction in which you are located and the legal basis for processing your personal data. In particular, and to the extent provided under applicable law, your rights may include:

  • the right to be informed about the processing of your personal information (e.g., purposes of processing, types of data involved, recipients to whom the data may be disclosed, storage periods, etc.);
  • the right to access the personal information we hold about you;
  • the right to request rectification of your personal information – for instance, if it is incomplete or incorrect;
  • the right to request erasure/deletion of your personal information;
  • the right to restrict the processing of your personal information by us (under certain circumstances and in accordance with the applicable law);
  • the right to data portability, namely, the right to receive a copy of your personal information (which you have provided to us) in a structured, commonly used and machine-readable format. You may also have the right to request that we transmit such personal information to another party (to the extent the processing is based on consent or a contract);
  • the right to object to our processing of your personal information (under certain circumstances and in accordance with the applicable law) (e.g., “opting-out” from receiving marketing communications by us at any time);
  • the right to challenge automated decisions including profiling, and
  • the right to withdraw your consent to a processing at any time and without detriment (e.g., unsubscribing from our newsletter and promotional communications easily and without charges).

11. How to exercise your rights?

You can exercise your rights by reaching out to [email protected].

Subject to legal and other permissible considerations, we will use reasonable efforts to honour your request promptly or inform you if we require further information in order to fulfil your request. We may not always be able to fully address your request, for example if it would impact the duty of confidentiality we owe to others, or if we are legally entitled to deal with the request in a different way. 

You have a right to lodge a complaint with your local data protection supervisory authority if you have concerns about how we are processing your personal information. We ask that you please attempt to resolve any issues with us first, although you have a right to contact your supervisory authority at any time. A listing of each EU country’s Supervisory Authority can be found in this link.  If you live in the UK, your local supervisory authority is the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. If you live in Switzerland, your local supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Berne.

12. Contact

The primary point of contact for all issues arising from this Privacy Notice is our Data Protection Officer. The Data Protection Officer can be contacted in the following ways:

By e-mail: [email protected]

By post: Infinigate Data Protection Officer

Vijzelstraat 68-78
1017 HL Amsterdam
The Netherlands

We may update this Privacy Notice from time to time to reflect changes in our processing activities, business operations, or legal obligations. The latest version will always be available on our website and will apply from the “Last updated” date stated at the top of this Notice.