Privacy Policy
Last updated: 1 July 2026
1. Controller
The controller responsible for the processing of personal data in connection with this website is:
GFM-Stiftung
Fuchsiastrasse 19
8048 Zurich
Switzerland
UID: CHE-324.235.133
Commercial Register No.: CH-020.7.002.449-4
Email: info@gfmtrust.net
2. Scope
This Privacy Policy applies to the I tesori della Russia website, to enquiries by email or contact form, to the technical use of the website and to embedded or linked collection content to the extent that we are responsible for the relevant processing. External platforms and services may also be subject to their own privacy notices.
3. Applicable data-protection law
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and the Swiss Data Protection Ordinance. Where visitors from the European Economic Area, the United Kingdom or other jurisdictions are concerned, we also observe applicable requirements of the GDPR or comparable data-protection laws.
4. Categories of personal data
Depending on how you use the website, we may process in particular the following data:
- technical access data such as IP address, date and time of access, browser type, operating system, device, referrer URL, pages viewed and server log data;
- communication data if you contact us, such as name, email address, organisation, content of the enquiry and attached information;
- preference and consent data, including language settings, cookie choices and consent logs;
- usage and analytics data where analytics functions are enabled and the required consent has been obtained;
- data connected with embedded third-party content, in particular when content from , interne Sammlungsdatenbank or other external services is loaded.
5. Purposes of processing
We process personal data for the following purposes:
- provision, stability, security and technical administration of the website;
- presentation of the collection, artist and artwork data and related editorial content;
- handling enquiries, scholarly comments, rights enquiries and provenance information;
- compliance with legal obligations, documentation and protection of legitimate interests;
- improvement of usability, accessibility, performance and quality of the website;
- management of consents and cookie preferences.
6. Legal bases
Under Swiss law, our processing is governed in particular by lawfulness, transparency, purpose limitation, proportionality and data security. Where the GDPR applies, processing is based, depending on the context, on Art. 6(1)(f) GDPR (legitimate interests in secure and user-friendly website operation, collection documentation and communication), Art. 6(1)(a) GDPR (consent, in particular for non-essential cookies and comparable technologies), Art. 6(1)(b) GDPR (pre-contractual or contractual communication) or Art. 6(1)(c) GDPR (legal obligations).
7. Hosting, platform services and processors
The website may be operated or technically supported through . Technical access data, communication data, security data and cookie/consent data may therefore be processed by and affiliated entities. Where the collection is embedded or linked through interne Sammlungsdatenbank, additional data may be transmitted to interne Sammlungsdatenbank when external content is loaded. We select service providers with care and use appropriate contractual and technical safeguards where required.
8. Third-party content and embedded collection data
The website may include embedded content, database views, images, videos, maps, fonts or other third-party content. When such content is accessed, technical data may be transmitted to the respective provider. Non-essential third-party content should be loaded only after the relevant consent has been obtained or where a data-protection-compliant integration is ensured. For integrations that are particularly relevant for tracking or privacy, a two-click or consent-based solution is used where possible.
9. Cookies and similar technologies
We use cookies and similar technologies to provide the website, store language preferences, ensure security, understand performance and, where applicable, enable embedded content. Non-essential cookies, in particular analytics, marketing or external media cookies, are set for visitors from jurisdictions requiring consent only after approval. Further details are provided in our Cookie Notice.
10. International disclosures
Personal data may be processed in Switzerland, the European Economic Area, the United Kingdom, Israel, the United States or other countries, in particular where international platform or hosting services are used. Where data is transferred to countries without an adequate level of data protection, we use appropriate safeguards, including contractual clauses, technical safeguards or recognised certification or adequacy mechanisms, where available and applicable.
11. Retention
We retain personal data only for as long as required for the relevant purposes, statutory retention obligations or legitimate documentation, security or evidentiary interests. Server and security logs are deleted or anonymised regularly unless a security investigation is required. Contact enquiries are retained for as long as necessary to handle and document the enquiry.
12. Data security
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration or disclosure. These include access restrictions, encrypted transmission, secure platform configuration, regular review of third-party integrations and a data-minimising website design.
13. Your rights
Data subjects may, subject to applicable law, request access, rectification, erasure, restriction, data disclosure or data portability, object to processing and withdraw consent with effect for the future. To exercise your rights, please contact us at info@gfmtrust.net. We may request reasonable identity verification to prevent misuse.
14. Right to complain
In Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC). Where the GDPR applies, you may also contact a competent data-protection supervisory authority in the EEA.
15. No automated individual decision-making
We do not use personal data for automated decisions producing legal effects or similarly significant impacts. We do not sell personal data.
16. Updates to this Privacy Policy
This Privacy Policy may be amended if the website, services used, legal requirements or internal processes change. The current version is available on this website.