For what purposes and on what legal bases do we process your personal data?
We process personal data in accordance with the Federal Act on Data Protection (ADP), and, to the extent applicable, with the European General Data Protection Regulation (GDPR). Personal data that we process may also be subject to banking secrecy or other contractual or professional confidentiality obligations applicable to us. We process personal data for the following purposes (hereinafter the “Purposes”) and legal bases:
(a) for the performance of contractual obligations
We collect and process personal data as necessary for the performance of a contract to which you or a related person is a party, or to carry out pre-contractual measures that occur as part of a request, which includes in particular the following processing operations: (i) opening and management of an account and business relationship with us, (ii) the execution of transactions, (iii) the provision of investment advice as well as (iv) asset and portfolio management and the distribution of financial products.
(b) for compliance with a legal obligation or in the public interest
As a bank, we are subject to various legal obligations which require us to process and collect personal data, including in relation to accounting requirements, the provision of information about products and services, the prevention of money laundering activities, bribery, corruption, tax frauds as well as other frauds and crimes, the recording of phone conversations, the satisfaction of any requirements of cooperation with, or reporting to, any competent public prosecution, supervisory, administrative or tax authority or court, as well as the assessment and management of risks.
(c) for the purposes of safeguarding legitimate interests
When necessary, we process your personal data for the purpose of the legitimate interests pursued by us or a third party, if such processing does not unduly affect your interest or fundamental rights and freedoms. Examples include (a) the development of our business relationship with you (b) measures for the security of our properties and systems (c) the recording of phone conversations to verify instructions, improve the quality of our services or to safeguard our rights (d) the exercise or defense of actual or potential legal claims, or the conduct of investigations or similar proceedings (e) review and improvement of our internal processes and organization, including for the purpose of risk management (f) the evaluation of certain characteristics of data subject on the basis of automatic processing of personal data (profiling).
(d) on the basis of your consent
To the extent that the processing of your personal data requires that you give your prior consent thereto, we will ask for your consent in due time. Any consent granted may be revoked at any time. Please be advised that the revocation of your consent shall only have effect for the future. Any processing that was carried out prior to the revocation shall not be affected thereby.
The provision of personal data may be mandatory, for instance in connection with compliance with applicable laws and regulations. If the required data are not provided, this may preclude us from establishing or pursuing a business relationship or from rendering services to you.
How long will your data be stored?
As a matter of principle, we process and store your personal data as long as it is necessary in order to achieve the Purposes. We will delete or anonymise your personal data regularly once they are no longer necessary in order to achieve the Purposes, unless a further processing of your personal data is necessary for the following purposes: (i) compliance with longer records retention periods under applicable law or regulations and (ii) preservation of all forms of relevant information to exercise or defend
Do we rely upon profiling or automated decision making?
In some cases, we process your personal data automatically with the aim of evaluating certain personal aspects (profiling), in particular to provide you with targeted information and advice on our products or services or those of our business partners. We may also use technologies that allow us to identify the level of risks linked to a data subject or to the activity on an account. Furthermore, as a rule, we do not make decisions based solely on automated processing in order to perform our services. Should we do so, we shall comply with applicable legal and regulatory requirementss.