# Wix Privacy Policy Switzerland

> Wix and Swiss data protection: Wix's role, data flows, what your privacy policy must state, apps, cookies and consent.

- Source: https://www.sidd.swiss/en/insights/wix-privacy-policy-switzerland/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Wix.com Ltd. is an Israeli website platform with more than 200 million users worldwide. In Switzerland, Wix is particularly common among micro and small businesses, freelancers, associations and creatives. From a data-protection standpoint, Wix is a special case: its headquarters are in Tel Aviv, processing runs across data centres in the US, Europe and Israel, and Israel has held an EU Commission adequacy decision since 2011, Switzerland has likewise recognised Israel as adequate (Annex 1 of the Data Protection Ordinance).

This article shows:

- which role Wix plays as data processor and partly as independent controller;
- which data flows actually arise on a Wix website from a data-protection perspective;
- which mandatory information your Swiss privacy policy must contain;
- which adjustments to the Wix default package are needed for DSG compliance;
- how to vet apps from the Wix App Market before installing them;
- and how cookies, tracking and consent management work in Wix.

Legal anchors: Federal Act on Data Protection (DSG, Art. 6, 8, 9, 16, 19, 22), GDPR (Art. 6, 13, 28, 44 et seq.), Israeli Privacy Protection Law 5741-1981, 2011 EU adequacy decision for Israel, FDPIC cookie guidance (2023), ePrivacy Directive.

## Wix as data processor

When you run a Wix website, Wix.com Ltd. (40 Tuval St., Ramat Gan 5252247, Israel) becomes the **data processor** for the personal data of your visitors. The contractual basis is the *Wix Terms of Use* plus the *Wix Data Processing Addendum*, automatically incorporated into the contract. The DPA includes the EU SCCs (Module 2) and the Swiss Addendum.

Key data flows:

- **Israel:** primary processing for the platform (Wix backend, editor, account management) happens in Israeli data centres. Israel benefits from EU Commission adequacy and is also recognised as adequate by Switzerland.
- **US:** hosting of website content runs partly via AWS and Google Cloud data centres in the US. For these transfers, Wix relies on the EU-US Data Privacy Framework (self-certified) and on supplementary SCCs.
- **EU:** for European customers, Wix is increasingly offering EU-based hosting, particularly for Wix Studio Enterprise.

Wix is also **independent controller** in two roles: for platform telemetry (performance, fraud) and for its own marketing communications towards you as customer. These secondary processings do not directly concern you in your privacy policy towards site visitors.

## Data flows on a Wix website

Every visit to your Wix website generates the following data categories:

- **Server log files:** IP address, browser, operating system, referrer, access timestamp. These logs are kept by Wix for security and performance purposes.
- **Wix Analytics:** active by default; measures visits, devices, geography. Sets its own cookies, which under the 2023 FDPIC guidance require at least a cookie notice.
- **Contact forms:** content is stored in *Wix Contacts* and forwarded to the site owner's registered email.
- **Wix Bookings / Wix Stores:** booking and order data including payment flow via Wix Payments (sub-processors Stripe, PayPal etc.).
- **Wix CRM and email marketing:** when enabled, member lists, newsletter recipients and marketing automation reside in the Wix cloud.
- **Third-party tracking:** if you embed Google Analytics, Meta Pixel, LinkedIn Insight, Hotjar or similar, additional data flows go to the respective providers.

Most of these flows are controllable and switchable from the Wix dashboard. An inventory at the start of a data-protection project (which Wix features are active, which are actually used) often substantially reduces what you need to describe in your privacy policy.

## Mandatory information in the privacy policy

A complete Swiss privacy policy for a Wix site must contain at least the following (Art. 19 DSG / Art. 13 GDPR):

1. **Controller:** company, Swiss address, UID, contact person for data-protection matters.
2. **Platform notice:** "This website is operated via the Wix.com Ltd. platform (40 Tuval St., Ramat Gan 5252247, Israel)."
3. **Processing purposes:** provision of the website, contact enquiries, newsletter, bookings, webshop, analytics.
4. **Data categories:** server logs, form content, booking/order data, newsletter data, cookies and tracking.
5. **Legal bases:** contract performance, legitimate interest, consent.
6. **Recipients:** Wix.com Ltd. (processor), sub-processors (AWS, Google Cloud), payment service providers (Stripe, PayPal), marketing/analytics providers (if active).
7. **Cross-border transfers:** Israel (adequacy), US (Swiss-US DPF, EU-US DPF, SCCs).
8. **Retention period:** concrete periods per data category, not "as long as necessary".
9. **Data-subject rights:** access, rectification, deletion, data hand-over, objection; right to lodge a complaint with the FDPIC.
10. **Cookies and tracking:** separate cookie notice or cookie table with provider, purpose and retention.

In the Wix editor, the privacy policy is set up as a dedicated page (typically */privacy*) and linked in the footer. Wix does not offer an automatic generator; it only integrates third-party templates such as Termly or iubenda as apps.

## Apps from the Wix App Market

Wix runs an App Market with thousands of extensions, from live chat to CRM and loyalty programmes. Every installed app is another disclosure under data-protection law. We recommend:

**Before installation:**

- Identify the app vendor (often a third party, not Wix itself).
- Read the vendor's privacy policy and DPA.
- Question the requested permissions critically (access to contacts, payments, site data).
- Verify the vendor's country of registration, a US vendor without DPF certification is hard to justify today.

**After installation:**

- Name the app in your privacy policy.
- Add the app to your record of processing activities.
- Periodically (at least annually) check whether the app is still in use and whether the DPA is still up to date.

Typical risk candidates in the Wix App Market are live chats (Tidio, Tawk.to, Crisp), heat-map tools (Hotjar), marketing apps with pixel functionality (Wix Ads itself, OneSignal Push, Facebook integrations) and loyalty apps. For these, a small DPIA is often worth doing.

## Cookies and consent in Wix

Wix offers a built-in **cookie consent banner** in the site settings. It distinguishes "strictly necessary", "functional", "analytics" and "advertising" categories. Configuration recommendations:

- **Opt-in mode for EU:** if you target EU visitors, non-essential cookies may only be set after active consent. Wix has supported this mode since 2022.
- **Categorise Wix Analytics:** by default Wix Analytics falls under "analytics", only fire after consent.
- **Couple third-party pixels to consent:** Facebook Pixel, Google Analytics, LinkedIn Insight, none may fire until consent. Wix allows this in the tracking settings.
- **Maintain a cookie table:** on a subpage */cookies* or directly in the privacy policy, with provider, purpose and retention.
- **Reject button at parity:** the Wix banner must display "accept" and "reject" with equal prominence, otherwise you breach EDPB Guidelines 03/2022.

If your requirements go beyond the Wix standard banner (granular categories, IAB TCF, multi-language, audit log), use an external Consent Management Platform such as Cookiebot, Usercentrics or CCM19 and integrate it via custom code.

## Swiss specifics and EU representation

Wix is globally positioned; many Swiss Wix sites de facto also address EU residents. Three additional duties follow:

1. **EU representative (Art. 27 GDPR):** if you have no EU establishment but offer goods or services to EU residents or monitor their behaviour, you need an EU representative.
2. **UK representative (UK GDPR Art. 27):** equivalent obligation if you actively target UK customers.
3. **Imprint:** Swiss obligation under Art. 3 UWG: company, address, email, commercial register and UID where applicable. Implement in the Wix editor as a dedicated page linked in the footer.

A frequent mistake: Swiss Wix users copy a German privacy-policy generator text without adding DSG-specific elements. The result is a policy that contains many GDPR building blocks but does not reflect the DSG (Art. 19 DSG, FDPIC complaint route, Art. 28 DSG data hand-over) at all. In an access request or supervisory case, this is an avoidable deficiency.

If you use Wix for a law firm, medical practice or fiduciary presence, Art. 321 of the Swiss Criminal Code additionally comes into play, you may not receive mandate details via contact forms unless the correspondence is end-to-end secured. A Wix site is suitable as a digital business card, not as a client portal.

## How SIDD supports you

SIDD regularly audits Wix sites for Swiss SMEs, associations and solo professionals. We deliver:

- audit of your existing Wix site (privacy policy, imprint, cookie banner, app inventory);
- drafting of a robust Swiss privacy policy including DSG components;
- configuration review of your Wix tenant and cookie banner;
- mandates as external [data-protection advisor](https://www.sidd.swiss/en/services/data-protection-advisor-switzerland);
- GDPR DPO mandates for organisations with EU exposure ([GDPR DPO mandates](https://www.sidd.swiss/en/services/data-protection-officer-eu));
- EU representation under Art. 27 GDPR ([EU representative](https://www.sidd.swiss/en/services/eu-representative)) and [UK representation](https://www.sidd.swiss/en/services/uk-representative);
- workshops on cookies, tracking and marketing compliance ([privacy workshop](https://www.sidd.swiss/en/services/data-protection-workshop-sme)).

Write to us via the [contact form](https://www.sidd.swiss/en/contact) or request a quote via the [quote form](https://www.sidd.swiss/en/quote). We deliver a Wix quick-audit within two working days.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
