Jimdo Privacy Policy Switzerland
Introduction
Jimdo is a German website platform headquartered in Hamburg, popular in Switzerland with small businesses, associations, freelancers and coaches. Jimdo provides hosting, the editor, templates, a shop mode (Jimdo Stores) and, particularly relevant for data protection, an automated privacy policy generator. It is precisely this generator that, in Swiss practice, often produces a false sense of security: it is calibrated for the German TTDSG and the GDPR but does not fully cover the Swiss Federal Act on Data Protection (DSG).
This article shows:
- which role Jimdo plays as data processor and controller;
- what the Jimdo generator delivers, and what it does not cover;
- which Swiss gaps you must close manually;
- which apps, integrations and tracking scripts Jimdo serves by default;
- how to configure the cookie banner behaviour in line with the FDPIC guidance and ePrivacy;
- and which duties you have as a website operator irrespective of the generator.
Legal anchors: DSG (Art. 6, 8, 9, 16, 19, 22, 24), GDPR (Art. 6, 13, 28, 44 et seq.), Swiss Telecommunications Act (TKG/FMG), ePrivacy Directive, FDPIC cookie guidance (2023), German Telecommunications and Telemedia Data Protection Act (TTDSG).
Jimdo as data processor
When you run a Jimdo website, Jimdo GmbH (Stresemannstr. 375, 22761 Hamburg, Germany) becomes the data processor for the personal data of your visitors. The contractual basis is the Jimdo terms of service plus the Jimdo Data Processing Agreement (DPA), which is automatically incorporated into the contract when you sign up as a Swiss or EU business customer.
Key points:
- Hosting region: Jimdo primarily uses EU data centres (including AWS Frankfurt). For Switzerland this means no cross-border transfer to the platform itself, the level of protection is considered adequate under the Data Protection Ordinance.
- Sub-processors: Jimdo uses sub-processors for email delivery (e.g. AWS SES), image processing and support tools. The current sub-processor list is available in the Jimdo Trust Center.
- Independent controller role: for platform telemetry, account management and marketing communications towards you as Jimdo customer, Jimdo acts as independent controller. You don't need to mention this in your privacy policy, it concerns the relationship Jimdo ↔ you, not the relationship you ↔ your visitors.
From a Swiss standpoint, Jimdo is therefore a comparatively clean provider, the critical points lie less in the platform contract and more in what you do as the website operator.
What the Jimdo generator delivers
Jimdo provides, under SEO & Statistics → Legal Texts in the dashboard, an automatic generator for the imprint, privacy policy and cookie notice. The generator was developed in cooperation with the Berlin law firm eRecht24 and fills in standard building blocks automatically:
- controller details from your account data;
- server log files, cookies, hosting;
- embedded third-party services (Google Analytics, Maps, YouTube, Facebook Pixel, Mailchimp etc.);
- data-subject rights under the GDPR;
- right to lodge a complaint with the competent supervisory authority.
The generator is solid and saves you a lot of work, provided you run a website based in Germany with German visitors. For Swiss SMEs, however, systematic gaps remain:
- No reference to the DSG, the generator only names the GDPR.
- No reference to the FDPIC (EDÖB) as supervisory authority; by default it points to the relevant German state authority.
- Swiss specifics (UID, VAT, Swiss address) are reflected only inadequately.
- The cookie banner logic is calibrated to the German TTDSG (strict opt-in); for Swiss visitors opt-out may be sufficient in some cases, a difference the generator does not handle.
- Cross-border transfers are simplified; Swiss-US DPF / EU-US DPF are not always correctly mentioned.
Closing the Swiss gaps manually
For a Swiss Jimdo website, we recommend adding the following building blocks manually after running the generator:
- Dual-regime mention: "This privacy policy applies to the processing of personal data under the Swiss Federal Act on Data Protection (DSG) and, where applicable, under the EU General Data Protection Regulation (GDPR)."
- FDPIC reference: "You have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC / EDÖB), Feldeggweg 1, 3003 Bern, Switzerland."
- Controller with Swiss data: company, Swiss address, UID (CHE-XXX.XXX.XXX), VAT number, email of a Swiss data-protection contact.
- Clarify GDPR scope: if you target EU visitors, you must additionally comply with Art. 13 GDPR and appoint an EU representative under Art. 27 GDPR (unless an exception applies).
- Professional secrecy clause: for lawyers, accountants, medical practitioners and other holders of professional secrecy, an explicit reference to Art. 321 of the Swiss Criminal Code.
- Right to data hand-over: mention the right to data hand-over under Art. 28 DSG (functionally similar to GDPR data portability but regulated independently in the DSG).
Keep these elements in a Switzerland annex to the generator-produced text, so that a generator update does not overwrite your additions.
Third-party services, apps and integrations
Jimdo offers numerous integrations, each of which constitutes a separate disclosure. Common examples:
- Google Analytics 4: data flow to Google LLC (US). Requirements: consent, Consent Mode v2, DPA with Google.
- Google Maps: every map load transmits IP, browser and geolocation. Consent recommended, especially on EU-facing pages.
- YouTube videos: recommendation: activate YouTube-nocookie mode and load the embed only after click.
- Facebook Pixel: only after explicit consent; list Meta Ireland Ltd. and Meta Platforms Inc. (US) as recipients in your privacy policy.
- Mailchimp / Brevo / CleverReach: newsletter delivery; double opt-in, confirmation trail, DPA in place.
- Jimdo Stores checkout: payment processing via Stripe (sub-processor). Stripe DPA and PCI-DSS in place.
- Live-chat tools (e.g. Tidio, Chatra): process chat content and IP, verify DPA and privacy notice.
Each of these integrations must appear cleanly in the privacy policy, the record of processing activities and the cookie banner. The Jimdo generator covers the most common ones, but for self-inserted custom HTML blocks or external embeds it sees nothing.
Cookie banner and ePrivacy
Jimdo offers a built-in cookie banner under Settings → Privacy. The banner distinguishes between strictly necessary cookies and tracking cookies and, depending on the plan, can display granular categories. Key points:
- For Swiss visitors, non-essential cookies are in principle permissible after a clear notice and an opt-out option. The 2023 FDPIC guidance, however, foresees consent for tracking that constitutes profiling.
- For EU visitors, the ePrivacy opt-in rule applies strictly: tracking cookies may only load after "accept" is clicked.
- The banner must contain an equally prominent "reject" option, "cookie walls" (accept or leave) are unlawful under EDPB Guidelines 03/2022.
- Marketing cookies may not be set before "accept" is clicked, not even in the denied mode of Consent Mode v2.
If you embed scripts outside the Jimdo standard integrations, you must couple them manually to the consent behaviour, Jimdo's standard offers only limited support for this; for more complex cookie governance, an external Consent Management Platform is worthwhile.
Duties independent of the generator
The privacy policy is only the public-facing element. As controller you have a number of internal duties under the DSG that the generator does not take off your hands:
- Record of processing activities (Art. 12 DSG): mandatory for companies with 250+ staff or when processing sensitive personal data. Rule of thumb: sensible in any event.
- Data protection impact assessment (Art. 22 DSG): before any high-risk processing, e.g. newsletter personalisation with profiling.
- Data breach notification (Art. 24 DSG): within 72 hours of becoming aware of a high-risk breach, to the FDPIC. You need an internal process that works on weekends too.
- Handling access requests (Art. 25 DSG): 30-day response window. Define a responsible person, a response template set and an escalation path.
- Data processing agreements (Art. 9 DSG): with every service provider that processes personal data on your behalf, hosting, mail, analytics, newsletter etc.
- EU representative (Art. 27 GDPR): if you actively target EU visitors and have no EU establishment.
Once you cover these six duties cleanly, you are well above the level the generator alone reaches.
How SIDD supports you
SIDD typically supports Swiss Jimdo users with three building blocks: a legally robust Swiss privacy policy (instead of, or in addition to, the generator), a record of processing activities and, for EU-facing sites, EU representation under Art. 27 GDPR.
Our services:
- audit of your existing Jimdo privacy policy, imprint and cookie banner;
- drafting of a tailor-made privacy policy;
- setup of a record of processing activities (Art. 12 DSG);
- mandates as external data-protection advisor;
- GDPR DPO function (GDPR DPO mandates);
- EU representation under Art. 27 GDPR (EU representative);
- privacy workshops for SMEs and associations (privacy workshop).
Write to us via the contact form or request a quote via the quote form. We deliver a Jimdo quick-audit within two working days.
