This Privacy Policy has been translated and is believed to be accurate. However, the interpretation of the privacy policy is subject to the German version. The German version shall prevail if there are any discrepancies between the English and German translations.

Privacy Policy

Last updated: 6 December 2025


Responsible for Data Protection

3forONE AG
Obere Paulistrasse 13
8834 Feusisberg – Switzerland
E-mail: support@3forone.com
Phone: +41 52 544 88 88
Commercial Register No.: CH-280.3.014.107-9

 


What Data Do We Collect?

We process personal data that arises when visiting or using our platform. This may include technical connection data, usage data and communication data.


What Do We Use the Data For?

To provide, manage, optimise and further develop our platform, to conduct auctions, to communicate with users and to meet legal obligations.


Your Rights

You have the right to access, rectify, delete, restrict processing, request data portability, object to processing and lodge a complaint with a data protection authority.


1. Introduction

This Privacy Policy explains how personal data is processed within the context of online and hybrid auctions and outlines your rights.


2. Controller

3forONE AG
Obere Paulistrasse 13
8834 Feusisberg – Switzerland
E-mail: support@3forone.com
Phone: +41 52 544 88 88


3. Hosting

Our website is hosted by a professional hosting provider within the EU. A data processing agreement pursuant to Art. 28 GDPR is in place.


4. Cookies and Consent Management

We use technically necessary cookies to enable core functions such as login and language settings. Optional cookies (e.g., for statistics or analytics) are only activated with your consent. Your selection is stored and can be changed at any time.


5. Google Analytics

We use Google Analytics (Google Ireland Ltd.) with IP anonymisation enabled. The processing is based solely on your consent (Art. 6(1)(a) GDPR) and serves statistical purposes. You may withdraw your consent at any time via the consent tool.


6. Newsletter

Newsletters are sent only after a double opt-in procedure. The time, IP address and content of your consent are recorded. You may unsubscribe at any time via the link included in each newsletter or by email.


7. Contacting Us

When you contact us, we process the data you provide to handle your request.
Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR.


8. Participation and System-Related Processes

Registration is required to participate in auctions. We process contact and login data as well as necessary usage information to ensure system functionality. During use of the platform, data regarding interactions and usage is processed where required for operating the platform, conducting auctions, personalising content and optimising our services.

This also includes technical usage data and logs necessary for traceability of auction processes and for maintaining system integrity.

Processing is based on your consent (Art. 6(1)(a) GDPR), and where necessary, on Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in a secure and user-friendly platform).
Data is not shared with third parties for advertising purposes.


8a. Quality Assurance, Usage Analysis and System-Related Logging

During operation of our platform, we automatically process certain usage and system data. This includes technical events, interactions within the platform and process-related logs required for the stability, security and proper execution of online and hybrid auctions.

This data is used to:

  • ensure the functionality and technical quality of the platform,

  • enable and document the execution of auctions,

  • detect misuse or unauthorised activities,

  • continuously improve user experience and platform performance,

  • carry out internal analyses for the further development of our services.

Processing is based on Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(f) GDPR (legitimate interest in a stable, secure and optimised platform) and, where required, Art. 6(1)(a) GDPR (consent).

Auction-related logs may be used for internal evaluation, quality assurance, technical analysis or to fulfil legal requirements. Data is not shared with external third parties for advertising purposes.


9. Responsibilities in the Context of bbag.auction

For the execution of auctions on bbag.auction, 3forONE AG remains the sole controller in accordance with Art. 4(7) GDPR.

Baden-Badener Auktionsgesellschaft e.V. (BBAG) uses the platform solely within its operational activities (e.g., catalogue creation, awarding bids, invoicing) and is responsible for its own content.

No joint controllership pursuant to Art. 26 GDPR exists.


10. Disclosure of Data

Data is only disclosed where necessary for auction or contract processing (e.g., to BBAG or sellers). Data is not disclosed for advertising purposes.

Internal evaluations for quality assurance, technical analysis or corporate management may be carried out based on data collected through the platform.


11. Security and Encryption

The platform is secured via SSL/TLS. Passwords are hashed (e.g., bcrypt/argon2). System access is role-based and protected by multi-factor authentication. Regular security updates and encrypted backups ensure data protection.

 


12. Data Transfers to Third Countries

Where data is transferred outside Switzerland or the EU/EEA (e.g., to Google), such transfer is based on Standard Contractual Clauses (SCCs) and additional safeguards.


13. Storage Period

Data is stored as long as necessary for the purposes mentioned or as required by law.

Auction and system logs are retained for a period necessary for technical, legal or operational traceability.


14. Minors

The platform is not intended for children under 16 years of age. Registration is permitted only from the legally allowed minimum age or with the consent of a legal guardian.


15. Your Rights under the GDPR

You have the right to access, rectify, delete, restrict processing, request data portability and object to processing.
Requests may be submitted to support@3forone.com. We respond within one month; in complex cases, the period may be extended by up to two additional months.


16. Right to Object (Art. 21 GDPR)

You may object to processing for reasons relating to your particular situation at any time. You may object to direct marketing at any time without giving reasons.


17. Right to Lodge a Complaint

You may lodge a complaint with any competent data protection authority. In Switzerland, the competent authority is the Federal Data Protection and Information Commissioner (FDPIC).


18. Notification of Data Breaches

In the event of a personal data breach, we notify the competent authority within 72 hours (Art. 33 GDPR) and inform affected individuals pursuant to Art. 34 GDPR where a risk exists.


19. Changes to This Privacy Policy

This Privacy Policy may be updated in response to legal or technical changes. The version valid at the time of your visit applies.