Markut Executive Search GmbH handles confidential executive search, leadership advisory, client and candidate information. This policy explains how we collect, use, share and protect personal data under Swiss data protection law — and, where applicable, the EU GDPR.
Introduction
Protecting confidential information is central to how Markut Executive Search GmbH (“Markut”, “MES”, “we”) works. Based on Article 13 of the Swiss Federal Constitution and the revised Federal Act on Data Protection (revFADP), every person is entitled to protection of their privacy and against the misuse of their personal data. We observe these provisions: personal data is treated in strict confidence and is neither sold nor passed to third parties, except as described in this policy. In close cooperation with our hosting providers, we take appropriate steps to protect our systems against unauthorised access, loss, misuse and alteration.
Controller
The controller responsible for the processing described here is:
- Markut Executive Search GmbH
- Bahnhofstrasse 61a, CH-6312 Steinhausen (Zug), Switzerland
- Phone: +41 76 450 4615
- Email: info@norbertmarkut.ch
- Registered seat: CH-6312 Steinhausen
- Commercial register: Canton of Zug
- UID: CHE-324.188.309 · VAT (MWST): CHE-324.188.309 MWST
For any data-protection question, contact us at info@norbertmarkut.ch or by phone.
Scope of this policy
This policy applies to personal data we process about:
- Visitors to this website
- Boards, CEOs, investors and company contacts discussing leadership mandates
- Senior executives introduced to us or who introduce themselves
- CV, profile and LinkedIn submissions
- People we contact in the course of a search assignment
- Anyone who emails or otherwise contacts us directly
Website log files
When you access our website, the following data is stored in log files: IP address, date, time, the browser request, and general information on the operating system and browser. This usage data forms the basis for statistical, anonymous evaluations that help us recognise trends and improve our services. It is not used to identify individual visitors.
Data from the mandate enquiry form
When you submit a leadership-mandate enquiry, we may collect:
- Full name
- Business email
- Company
- Role
- Leadership requirement
- Sector
- Geography
- Timing
- Confidentiality level
- Context notes
- Your consent confirmation
Data from the executive introduction form
When a senior leader is introduced or introduces themselves, we may collect:
- Name
- Current role
- LinkedIn profile
- An optional CV or profile document
- An optional short note
- Consent confirmation
The sensitive nature of executive search data
Executive-search information can be highly sensitive. It may reveal career intentions, leadership changes, succession planning, investor activity, board decisions and confidential company strategy. We treat it with corresponding discretion and restrict access to those who need it for a specific, legitimate purpose.
Why we process personal data
We process personal data to:
- Review and respond to mandate enquiries
- Assess fit for a search assignment
- Contact potential clients and candidates
- Review CVs, profiles and professional backgrounds
- Maintain confidential candidate and client records
- Manage and deliver search assignments
- Communicate with boards, CEOs, investors and senior leaders
- Meet our legal and administrative obligations
Legal grounds
Under Swiss law we process personal data where this is justified — in particular to prepare or perform a mandate, on the basis of your consent, to comply with a legal obligation, or in our overriding legitimate interest in operating a discreet, relationship-led search practice. Where the EU GDPR applies (see section 15), we rely on the corresponding grounds in Art. 6 GDPR (consent, contract, legal obligation, legitimate interests).
CVs and executive profiles
CVs, LinkedIn links and executive profiles are stored securely, reviewed only by those involved in a relevant assignment, and shared with a client only where there is an appropriate basis to do so (see section 11). We retain them in line with section 14 and delete them on request, unless we are legally required to keep them.
Sharing of personal data
We may share personal data, on a need-to-know and controlled basis, with:
- Clients, boards, investors and portfolio companies in connection with a relevant mandate
- Hosting, CRM and email providers acting on our instructions
- Legal and accounting advisors
- Assessment or reference providers, where such services are used
We do not sell personal data.
Google Analytics
This website uses Google Analytics, a web-analytics service provided by Google. Google Analytics uses cookies — text files stored on your device — to help analyse how visitors use the site. The information generated (including your IP address) may be transmitted to and stored by Google, including on servers in the USA, and used to evaluate website usage, compile reports and provide related services. You can prevent cookies through your browser settings and can opt out of Google Analytics. We use this service to understand and improve our website; where required it is activated only with your consent, and we recommend IP anonymisation.
International transfers
Personal data may be processed outside Switzerland — for example by providers such as Google. Where we transfer data to a country without adequate protection, we apply appropriate safeguards such as the Swiss / EU Standard Contractual Clauses.
How long we keep data
We keep personal data only as long as necessary for the purpose, or as required by law. Indicative periods:
- Website log data — up to 6 months, then deleted or anonymised
- Mandate enquiries — the duration of our discussions and up to 24 months thereafter
- Candidate profiles & relationship records — up to 24 months from our last meaningful contact, then reviewed and deleted or refreshed with your consent
- CVs — the duration of the relevant search; thereafter only within the relationship database above, where there is a basis to do so
- Accounting records — as required by statutory retention periods (Swiss law: 10 years)
- General correspondence — up to 24 months
Your rights
Under the revFADP you may request information about (access to), correction, deletion or restriction of your data, object to processing, and receive certain data in a portable format. Where the EU GDPR applies to the data of individuals in the EU/EEA, the corresponding GDPR rights also apply. You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), or with an EU supervisory authority where the GDPR applies.
To exercise your rights, contact info@norbertmarkut.ch.
Security
We use appropriate technical and organisational measures — in close cooperation with our hosting providers — to protect personal data against loss, misuse and unauthorised access, with particular care given the confidential nature of executive-search information.
Automated decision-making
We do not use solely automated decision-making, including profiling with legal or similarly significant effects, for candidate selection, search assessment or mandate evaluation. Decisions involve human judgement.
Contact and changes
For any privacy matter, contact info@norbertmarkut.ch or write to the registered seat in section 2. We may update this policy; the version published here, with the date above, applies.