Privacy Policy
1. General
This privacy policy provides information on how we process personal data. The term ‘personal data’ refers to any information relating to an identified or identifiable natural or legal person. ‘Processing’ refers to any handling of personal data, regardless of the means and methods used, in particular the collection, storage, use, alteration, disclosure, archiving, erasure or destruction of personal data.
Further provisions apply to certain data processing activities, e.g. in the context of concluding contracts. These are set out in the relevant contracts.
2. Data security
We are committed to protecting personal data and privacy in accordance with applicable laws, in particular the rules of professional conduct and data protection legislation. To this end, we implement various technical and organisational security measures (e.g. access restrictions, firewalls, personalised passwords, encryption and authentication technologies, staff training, etc.).
3. Categories of personal data
We process the following categories of personal data. We always process as little personal data as possible.
Customer data, such as:
-
Master and record data (e.g. name, address, nationality, date of birth, information relating to accounts, custody accounts, completed transactions and contracts, information about third parties affected by data processing, such as spouses, authorised representatives and advisers).
-
Transaction, order and risk management data (e.g. details of the beneficiaries of transfers, the beneficiary’s bank, the amount of transfers, risk and investment profile, details of investment products).
-
Technical data (e.g. transaction numbers, IP addresses, internal and external identifiers, access logs).
-
Marketing data (e.g. preferences, needs).
Data relating to visitors and interested parties (e.g. our visitors or visitors to our website), such as:
-
Master and customer data (e.g. name, address, date of birth).
-
Technical data (e.g. IP addresses, internal and external identifiers, access logs).
-
Marketing data (e.g. preferences, needs).
Supplier details, such as:
-
Master data and inventory data (e.g. name, address, date of birth, information on completed transactions and contracts).
-
Technical data (e.g. IP addresses, internal and external identifiers, access logs).
4. Source of personal data
In order to fulfil the purposes set out in clause 5, we may collect personal data from the following sources:
- Personal data provided to us, for example when establishing business relationships, in the course of fulfilling contracts, or when using products and services.
- Personal data generated in the course of using products or services and transmitted to us via the technical infrastructure or through collaborative processes.
- Personal data from third-party sources, e.g. from public authorities or UN and EU sanctions lists.
5. Purposes of processing
We may process personal data for the purpose of providing our own services, as well as for our own purposes or those required by law. In particular, this includes the following:
- Concluding and fulfilling contracts; implementing, processing and managing products and services (e.g. invoices, investments).
- Monitoring and managing risks (e.g. investment profiles, anti-money laundering, limits, leverage ratios, market risks).
- Planning and business decisions (e.g. developing new or evaluating existing services and products).
- Marketing, communication, providing information about the range of services and reviewing it (e.g. advertising in print and online media, events for customers, prospective customers or other parties, identifying future customer needs).
- Compliance with statutory or regulatory obligations to provide information or make disclosures to courts and authorities, and compliance with official orders (e.g. reporting obligations to FINMA and foreign supervisory authorities, orders from public prosecutors’ offices in connection with money laundering and terrorist financing).
- Safeguarding our interests and securing our claims, e.g. in the event of claims made against us or claims we make against third parties.
6. Disclosure to third parties, categories of recipients
We disclose customer data to the following third parties in the following circumstances:
• To other service providers for outsourcing purposes in accordance with clause 7 and for the purpose of providing comprehensive customer support.
• For the fulfilment of orders, i.e. when products or services are used.
• On the basis of legal obligations, legal grounds for disclosure or official orders, e.g. to courts, supervisory authorities, tax authorities or other third parties.
• To the extent necessary to safeguard our legitimate interests, e.g. in the event of legal action threatened or initiated against us by customers, in the case of public statements, to secure our claims against customers or third parties, in the collection of debts, etc.
• To other third parties with the consent of the data subjects.
In particular, when using certain products or services, personal data may, under certain circumstances, also need to be disclosed to third parties in countries where there is no adequate level of data protection (e.g. the USA). If a transfer to such a country is necessary, we shall, where possible, take appropriate measures to ensure that personal data continues to be adequately protected.
7. Outsourcing of business areas or services
We outsource certain business areas and services, either in full or in part, to third parties (such as compliance; risk management; accounting; CRM systems; IT).
The service providers who process personal data on our behalf for this purpose (known as ‘data processors’) are carefully selected. Wherever possible, we use data processors based in Switzerland. Data processors may, under certain circumstances, be authorised to have certain services provided by third parties on their behalf.
Data processors may only process personal data received in the same way as we do, and are contractually obliged to ensure the confidentiality and security of the data.
8. Automated decision-making in individual cases, including profiling
We reserve the right to process customer data automatically in future, where appropriate, in particular to identify key personal characteristics of the customer, predict trends and create customer profiles. This serves, in particular, to review and further develop our offerings and to optimise the provision of our services.
In future, customer profiles may also lead to automated individual decisions (e.g. the automated acceptance and execution of customer orders in the CRM system).
We ensure that a contact person is available should a data subject wish to express their views on an automated individual decision, where the law provides for such an opportunity to do so.
9. Duration of storage
The period for which personal data is stored depends on the purpose of the data processing in question and/or statutory retention obligations, which may be five, ten or more years, depending on the applicable legal basis.
10. Rights of data subjects
Anyone may request information from us as to whether personal data relating to them is being processed. You have the right to object, to restrict processing and, where applicable, the right to data portability. Incorrect data may be rectified. Furthermore, the erasure of personal data may be requested, provided that this is not prevented by legal or regulatory requirements (e.g. statutory retention obligations for business-related data) or technical obstacles. The erasure of data may mean that we are no longer able to provide certain services. Furthermore, where applicable, there is a right to lodge a complaint with a competent authority. Where we process personal data on the basis of consent, this consent may be withdrawn at any time.
To help us respond to your enquiry, please provide us with a clear and detailed message. We will review your enquiry and reply within a reasonable timeframe.
11. Contact
We are responsible for processing your personal data. Please feel free to direct any enquiries to us.


