Data Protection Policy

Capital Trustees AG is committed to protecting your personal data and complying with applicable Swiss and international data protection regulations.

Capital Trustees AG Privacy Policy

In the context of its activity, Capital Trustees AG (hereinafter also referred to as "Capital") processes data related to individuals and/or legal entities as defined in Art. 5 DPA (hereinafter "personal data").

Such personal data include information on current and past clients, as well as potential clients, business partners, and any other person who interacts with Capital.

The data processing carried out by Capital respects the Federal Act on Data Protection (DPA) of 25th September 2020 as well as the Ordinance to the Federal Act on Data Protection (DPO) of 31st August 2022 (hereinafter also referred to as "applicable regulations").

With the below, we would like to provide you with an overview of how we will process your data and also summarize what your rights are according to data privacy laws. Please note that the methodologies employed to process personal data depend significantly on the services applied for or agreed upon.

Who is Responsible for Data Processing?

The responsible party is:

Capital Trustees AG
Bleicherweg 50
CH-8002 Zürich
Switzerland

Phone: +41 (0)44 5125004
Email: info@capitaltrustees.ch

Purpose of Data Processing and Legal Basis

We process personal data in accordance with the provisions of the applicable regulations for the following purposes:

  • To fulfil contractual obligations. In this case, data are processed to allow us to provide our services, in the context of carrying out our business with our clients and our suppliers or to take pre-contractual measures (e.g., to identify any conflicts of interest);
  • To comply with laws and regulatory requirements (e.g., Anti-Money Laundering Regulations, FINMA ordinances and circulars, tax laws etc.);
  • For the purposes of pursuing legitimate interests (e.g., asserting legal claims and defence in legal disputes);
  • For other legitimate purposes (e.g., to send general information on capital to interested parties, as well as send invitations to events organized by Capital, etc.).

Sources of Data

We process personal data obtained from our clients and from other counterparties in the context of our business relationships. We also process personal data obtained from publicly-accessible sources (e.g., debt registers, commercial and association registers, the press, internet) or data which are legitimately transferred to us by other companies or by other third parties.

Types of Data Processed

Usually, the data we process are personal information (e.g., name, address and other contact details such as e-mail address and telephone number, date and place of birth, nationality, etc.) and identification data (e.g., ID card or passport details).

Furthermore, we collect data which help us fulfil our legal and contractual obligations, such as information about our clients' personal and financial situation (e.g., financial background, information about our clients' assets and their origin, professional information such as job title and professional experience, family details such as name of partners or children, tax domicile and tax-relevant information and documents). This information may also be collected with respect to prospective clients.

We collect also information related to our clients' risk assessments under a risk-based approach, such as information on pending charges, potential insolvency and bankruptcy.

We can record phone calls and video-calls for security reasons and we may collect data during such calls (e.g., phone numbers, forwarding numbers, time and date of calls and messages, duration of the call, images, etc.).

Moreover, when you access our website (www.capitaltrustees.ch), we automatically collect and store through cookies information about your use of the website (e.g., data related to your activity during your visit, date and time of the access, information about your device and your web browser), together with information that you may have voluntarily provided.

More in general, the personal data we collect come from our interactions with our clients and with our website visitors.

Who Receives My Data?

Within Capital, every unit that requires your data to fulfill our contractual and legal obligations will have access to them.

We may pass on information about you to third parties only if demanded by legal provisions, if you have given your consent, if we have been authorized by a contract or if we must do so to protect a legitimate interest.

Third-party recipients of personal data could be, for example:

  • Other fiduciary or trustee institutions, advisors, lawyers, banks, other third parties to which we may transfer your personal data over the course of our business relationship (depending on the contract). Please note though that service providers and agents appointed can receive access to data for the agreed purposes only if they maintain an adequate degree of confidentiality;
  • Public entities and institutions (e.g., criminal prosecution authorities, federal tax administration etc.) in order to comply with our legal obligations.

Data Security

Capital takes all the appropriate technical (e.g., encryption, logging, access control, data backup, etc.) and organizational (e.g., instructions for our employees, confidentiality agreements, etc.) measures to ensure security of the data collected and processed and to protect them from unauthorized access, improper use, loss, falsification and destruction.

However, it is impossible to completely exclude security risks, as some of them are most often unavoidable. In particular, since perfect data security cannot be guaranteed for communications via e-mail, instant messaging or similar means of communication, we recommend that you always send confidential information in safe mode.

Data Transfers to Third Countries

Data transfers outside Switzerland could only take place to Countries that guarantee adequate levels of data protection on the basis of a decision of the Federal Council.

Outside such Countries, and in the absence of other protection requirements (with respect to in Article 16 DPA), the transmission of data abroad can take place as long as:

  • It is necessary for carrying out our business with you;
  • It is required by law (e.g., reporting obligations under fiscal law);
  • You have granted us your consent.

Obligation to Provide Personal Data

In the context of our business relationship, you must provide all personal data required to start and move forward our business relationship with you, as well as the data that we are legally obliged to collect. Without those, we would not be in a position to finalize or execute any contract with you.

In particular, Anti-Money Laundering regulations require us to identify you on the basis of your personal documents before establishing a business relationship and we also must keep all the collected data updated over the course of our relationship.

In order to allow us to comply with these statutory obligations, you must provide us with the necessary information and documents in accordance with the Anti-Money Laundering regulations, and you must immediately disclose any changes arising over the course of the business relationship.

Otherwise, we could not enter into or continue the business relationship you desire.

Data Storage Duration

Personal data will be stored to the extent they are necessary for the purposes mentioned above in compliance with all Capital's business, legal or regulatory requirements.

When contracts are in place, personal data are stored at least for the duration of the contractual relationship. We also keep personal data whenever we have a legitimate interest to do so. In particular, this may occur if we need personal data to assert claims or defend against claims, for archiving purposes, to ensure IT security or as long as the limitation period for contractual or non-contractual claims is still running.

Furthermore, we store your personal data for the retention period stipulated by the applicable law (e.g., in compliance with the retention periods under Swiss tax and/or commercial and/or Anti-Money Laundering legislation, which are of at least 10 years).

Personal data that are not necessary for the above-mentioned purposes and requirements will be promptly deleted or anonymized.

Your Data Privacy Rights

Every data subject has the following rights: right to access (according to Article 25 of the DPA), right to rectification, updating, limitation and/or objection to data processing and data cancellation if incomplete, incorrect or collected in violation of the law (according to Articles 6 and 30-32 of the DPA) and – if applicable – the right to data portability (according to Article 28 of the DPA).

Based on the applicable regulations, however, the above-mentioned rights are not absolute, as under certain circumstances they may be subject to exceptions.

Automated Decision-Making

We do not use any Automated Decision-Making process.

Profiling

We do not process data automatically and/or have any automated process for data profiling.