Data Protection Notice
Thank you for your interest in the products and services of Banca Popolare di Sondrio (SUISSE) – hereinafter referred to as BPS (SUISSE) or the “Bank”.
Please read this notice carefully before using the products and services of the Bank or supplying your personal data. Any supplementary terms and conditions that apply to the products and services of BPS (SUISSE) will be provided when you purchase these services.
By proceeding with the use of the Bank’s services or products or browsing on its website, you confirm your express consent to the Bank’s privacy policy, set out in this document. If you do not agree with its content, we would ask that you stop browsing the pages of the relevant website or using the product or service concerned.
The Bank reserves the right to amend its privacy policy at any time without notice.
1. Object and purpose of this data protection notice
The Bank places great importance on the protection of privacy and the processing of the personal data of users of BPS (SUISSE) services. BPS (SUISSE) is aware that personal data is entrusted to it and takes its obligation to protect and safeguard this data very seriously. Consequently, this document sets out the types of data collected when you use the Bank’s products and services, visit its websites, use its mobile applications (“apps”) or sign up for any services (generally referred to as “BPS (SUISSE) services”). It outlines the purpose for which it is collected, the manner in which it is processed, the entities to which it could be transmitted and the security measures adopted to protect it.
At the same time, we inform you of your rights under data protection legislation. Please be aware that the personal data actually processed and used in each case varies, largely depending on the products and services of our Bank that you sign up to and use.
The policy set out here applies to any data acquired by BPS (SUISSE) by means of your use of BPS (SUISSE) services. It does not apply to any product or service that is controlled by third parties not associated with the Bank and that you might access by following links from the BPS (SUISSE) websites.
2. Recipients of this data protection notice
The following information on data protection relates to the personal data of:
3. Data controller and contact details
The controller under the provisions relating to data protection is:
Banca Popolare di Sondrio (Suisse) SA
Via G. Luvini 2a
CH-6900 Lugano
www.bps-suisse.ch
If you have any questions about data protection at BPS (SUISSE), you can contact:
Banca Popolare di Sondrio (Suisse) SA
Data Protection
Via Maggio 1
CH-6900 Lugano
dataprotection@bps-suisse.ch
4. Sources of data
In the context of the business relationship with clients, the use of BPS (SUISSE) services, registration on a website or discussions with Bank employees, the Bank will receive your personal data.
In order to provide services, BPS (SUISSE) may also potentially obtain personal data from freely accessible public sources (e.g. land, commercial and association registers, the press, the Internet) or be given it by third parties (e.g. credit reporting agencies).
5. Types of data processed
The type of personal data processed depends mainly on the purpose of processing. BPS (SUISSE) will only ever collect and process the data that it needs for the purposes that it pursues.
Such data may include:
6. Purpose of data processing
Personal data will be used:
7. Recipients of personal data
Within the Bank, any unit that needs your data to comply with contractual and legal obligations or to safeguard its legitimate interests will have access to your data. In the context of compliance with contractual and legal obligations, your personal data will not be processed solely by us, but also by relevant third parties (e.g. service providers, implementing partners). In particular, the management of risks also requires clarifications with third parties and related transfers of data (e.g. to authorities, auditors and other banks). Data may also be communicated on the basis of legal requirements (e.g. when fulfilling relevant clarification, disclosure and information obligations). In processing your personal data, the data recipients are bound by legal and/or contractual provisions. For the purposes described above, we are authorised to send your personal data to the following categories of recipients in Switzerland and abroad:
Before transmitting your personal data, we perform a thorough examination of the respective recipient of the data and arrange to contractually commit them to ensuring adequate protection of the data and maintaining confidentiality vis-à-vis your data.
Please note that, when you download our apps from an app store and use them, the manufacturers of the devices concerned and/or of the operating system (e.g. Microsoft, Apple, Google) receive personal data or can analyse your usage patterns. This may enable the detection of a current, past or future client relationship between you and us, an eventuality over which we have no control and are unable to prevent.
Data on the use of the websites may be transferred to third parties where permitted by law, if BPS (SUISSE) is obliged to do so, or if it needs to transfer the data in order to exercise its rights, particularly in the event of any dispute regarding a contractual relationship. The Bank may also disclose data to service providers with the stipulation that it is used solely for the purposes for which it is provided. Any person or entity that receives data is required to comply with the applicable national and international data protection laws and with the BPS (SUISSE) data protection regulations.
The recipients of personal data may be located in Switzerland or abroad. Therefore, your personal data may be processed all over the world. Data may be transmitted abroad because this is necessary for the execution of orders (e.g. payment and/or securities orders), because this is prescribed by law (e.g. in the context of notification obligations under tax law, automatic exchange of information, etc.) or because you have given the Bank your consent to do this.
If a recipient is located in a country that does not guarantee an adequate level of data protection, the Bank shall make every effort to commit the recipient to ensuring adequate protection of the data by drafting recognised standard contractual clauses, or shall proceed only if the exceptions prescribed by law apply (e.g. your consent, the conclusion or management of a contract, the safeguarding of overriding public interests, the assertion of legal claims, or if you have made the data accessible to the general public and are not opposed to the processing thereof).
8. Security measures
BPS (SUISSE) has taken appropriate technical and organisational security measures to protect your personal data against unauthorised access, misuse, loss or destruction, taking into account the applicable legal and regulatory requirements.
9. Data retention
BPS (SUISSE) processes and stores your personal data for as long as necessary to comply with its contractual and legal obligations or for the purpose of the processing concerned. In this context, we take into account the purpose of processing and, in particular, the need to safeguard our personal interests (e.g. to assert and defend against claims and to ensure information security). In this regard, it must be borne in mind that the business relationship with the Bank constitutes a long-term obligation of a number of years’ duration.
Data that is no longer required in order to comply with contractual and legal obligations will be erased unless it needs to be processed further – for a limited time – for the following purposes:
10. Transfer of data via the Internet
In general, the Internet (including social media, see notice) is not considered a secure environment, and data transferred via this channel may be viewed by unauthorised third parties, which risks disclosures, changes to content and technical issues. Even if the sender and recipient are resident in the same country, any data transferred via the Internet could be transmitted outside national borders to countries with a lower level of data protection than that required in the country of residence.
Please be aware that BPS (SUISSE) accepts no responsibility for the security of your data whilst it is being transferred to the Bank via the Internet.
11. Cookies and other tracking and analytics technologies
For the purposes outlined above, on its websites and apps, BPS (SUISSE) uses so-called cookies, small text files that are stored in your browser, and/or other tracking and analytics technologies. These files are created automatically when you use the Bank’s websites and stored on your device if you do not prevent this by disabling them. Cookies serve various purposes, including to make your browsing session secure, to store temporary settings, to save your language settings during multiple browser sessions and to show you content on the website that matches your interests (you can find more details on this in the "Cookie settings" section). You can disable the use of cookies at any time in your browser settings and delete existing cookies or manage your settings by clicking here. Disabling cookies may mean that certain features can no longer be used or can only be used to a certain extent.
In its apps, the Bank may use other tracking and analytics technologies from third-party providers, e.g. software development kits (SDK), to record and analyse your usage patterns. This enables us to continuously optimise our apps and identify errors. In the settings of the relevant app, you can disable the recording of your usage data and its transmission to the supplier concerned at any time.
12. Web analytics
To analyse and optimise its offerings, BPS (SUISSE) collects anonymised information on the use of its websites and their features.
In the publicly accessible sections of its websites, in order to gain a better understanding of the use of its websites and thus make continuous improvements to their content and features, the Bank currently uses tools from Google Ireland Limited (hereinafter "Google"):
For more information, please refer to Google's privacy policy. The legal basis for using the aforementioned tools is BPS (SUISSE)’s legitimate interest. Since the Bank’s websites are an important tool for communicating with existing clients and acquiring new ones, having functioning, attractive and tailored websites at all times is essential.
13. Online marketing activities
a. Social media and other information platforms
BPS (SUISSE) is present on various platforms such as LinkedIn, Facebook, Instagram and YouTube (see information) and publishes news about the Bank and the financial sector. Please refer to the different terms of service of the individual social networks for more details.
The Bank uses these social channels as well as other information platforms to promote its products and services. By participating in the Bank's social media profiles and interacting with BPS (SUISSE) campaigns on other online platforms, you consent to your contribution being used for statistical and marketing purposes (as described in point 6).
b. Google Ads
Google Ads is an advertising service provided by Google. BPS (SUISSE) uses it to promote its products and services, offers or promotions in Google search results, as well as on third-party websites. In providing these services, Google may collect and evaluate information from visitors to web pages under its own responsibility. The Bank has no influence on the scope and further processing and use of the data by Google. For further information, please refer to the privacy policies of Google.
14. Profiling and automated individual decisions
In principle, for the purposes of establishing or fostering the business relationship, the Bank does not apply any fully automated decision-making process with legal effect.
To a certain extent, the Bank processes personal data by automated means in order to analyse specific personal aspects (profiling). This processing is used in the manner described below, for instance:
15. Rights of the data subject
Every data subject has the right of access under Article 8 of the Swiss Federal Act on Data Protection (FADP), the right to rectification under Article 5 FADP, the right to erasure under Article 5 FADP, the right to restriction of processing under Articles 12, 13 and 15 FADP, the right to object, and, where applicable, the right to data portability. If, by way of an exception, the processing of your personal data is based on consent that you have given separately, you have the right to revoke this at any time with effect for the future. Where applicable, you will be entitled to lodge a complaint with a supervisory authority with responsibility for data protection.
Having given us your consent to process your personal data, you may withdraw it at any time. Once you withdraw your consent, your personal data will no longer be processed for the purpose concerned, unless overriding public or private interests or the law allow for further processing. The same applies if you refuse consent to data processing. Please bear in mind that, in this case, the Bank may be unable to provide its services. It may take up to five working days for withdrawal or objection to come into effect. Data for advertising campaigns or information of a generic nature is usually processed several weeks in advance. It is therefore possible that you will still receive advertising for a certain period of time after exercising your right of withdrawal and/or objection. You may exercise your rights by sending a signed letter to the address stated in section 3, together with a copy of your identity card or passport.
Please note that these rights are subject to legal requirements and restrictions (e.g. we cannot delete data if we are obliged to comply with related retention obligations). We will ensure that you are informed of any restrictions. You are also entitled to these rights in relation to other parties tasked with data processing who collaborate with us under their own responsibility. To exercise your rights regarding processing, we suggest that you contact the relevant parties directly.
16. Links to other websites
BPS (SUISSE) websites may host third-party content or links to third-party websites that it does not operate or monitor directly. Please note that these third-party sites are not covered by the privacy policy set out in this notice, and that the Bank is not responsible for their content or personal data processing principles. You are advised to consult and check the individual privacy policies or terms of use of third-party electronic services.
17. Amendments
The Bank may amend and supplement this information at any time. The latest version is always available electronically on the website: www.bps-suisse.ch/en/privacy.php.
18. Collection and processing of personal data in the BPS (SUISSE) application process
BPS (SUISSE) collects and processes applicants’ personal data in a number of ways. This takes place in particular when applicants complete a contact form on the BPS (SUISSE) website or when applicants send their CVs to BPS (SUISSE) speculatively by e-mail/post or in response to an advertisement published by BPS (SUISSE) on its website or a third-party site dedicated to job vacancies.
Usually, the data is provided directly by the applicant during the selection process, although in some cases it may be obtained from third parties or freely accessible public sources, following the applicant's agreement, in order to check the content of the application.
Only Human Resources has access to applicants’ personal data at the Bank. It is processed by BPS (SUISSE) to manage the application and staff selection process and to perform activities such as checking the suitability of the applicants’ experience and qualifications.
BPS (SUISSE) stores applicants’ personal data for the time required to achieve the processing purpose, unless the applicant withdraws their consent. Unless consent is withdrawn or the deadline set by the Bank expires, the data collected under the application procedure remains in the Bank's system in order to cover vacancies at a later date. In addition, it could serve to answer any question in respect of the application and possibly enable the Bank to fulfil its burden of proof under the terms of the Equality Act.
BPS (SUISSE) may use third-party IT services and/or specialist HR service providers (e.g. recruitment companies or specialist platforms). In principle, the data is processed in Switzerland. In the context of the administration, development and operation of the computer systems, it may be the case that this data is transferred outside Switzerland, to Europe or Third Countries. If this were to happen, BPS (SUISSE) would adopt safeguard measures to guarantee an adequate level of protection of the data.
Applicants have the right to access, rectify, erase, restrict the processing of, object to the processing of and request the transfer of their personal data. To exercise these rights, applicants may contact Human Resources, which will coordinate requests with the relevant departments.
You can contact our call centre between 8 a.m. and 5.30 p.m. Monday to Friday on 00800 800 767 76 (calls from Switzerland are free).
Alternatively, you can use our contact request forms.