Data Protection Notice
Thank you for your interest in the products and services of Banca Popolare di Sondrio (SUISSE) – hereinafter referred to as BPS (SUISSE) or the “Bank”.
Please read this notice carefully before using the products and services of the Bank or supplying your personal data. Any supplementary terms and conditions that apply to the products and services of BPS (SUISSE) will be provided when you purchase these services.
By proceeding with the use of the Bank’s services or products or browsing on its website, you confirm your express consent to the Bank’s privacy policy, set out in this document. If you do not agree with its content, we would ask that you stop browsing the pages of the relevant website or using the product or service concerned.
The Bank reserves the right to amend its privacy policy at any time without notice.
1. Object and purpose of this data protection notice
The Bank places great importance on the protection of privacy and the processing of the personal data of users of BPS (SUISSE) services. BPS (SUISSE) is aware that personal data is entrusted to it and takes its obligation to protect and safeguard this data very seriously. Consequently, this document sets out the types of data collected when you use the Bank’s products and services, visit its websites, use its mobile applications (“apps”) or sign up for any services (generally referred to as “BPS (SUISSE) services”). It outlines the purpose for which it is collected, the manner in which it is processed, the entities to which it could be transmitted and the security measures adopted to protect it.
At the same time, we inform you of your rights under data protection legislation. Please be aware that the personal data actually processed and used in each case varies, largely depending on the products and services of our Bank that you sign up to and use.
The policy set out here applies to any data acquired by BPS (SUISSE) by means of your use of BPS (SUISSE) services. It does not apply to any product or service that is controlled by third parties not associated with the Bank and that you might access by following links from the BPS (SUISSE) websites.
2. Recipients of this data protection notice
The following information on data protection relates to the personal data of:
3. Data controller and contact details
The controller under the provisions relating to data protection is:
Banca Popolare di Sondrio (Suisse) SA
Via G. Luvini 2a
CH-6900 Lugano
www.bps-suisse.ch
If you have any questions about data protection at BPS (SUISSE), you can contact:
Banca Popolare di Sondrio (Suisse) SA
Data Protection
Via Maggio 1
CH-6900 Lugano
dataprotection@bps-suisse.ch
4. Sources of data
In the context of the business relationship with clients, the use of BPS (SUISSE) services, registration on a website or discussions with Bank employees, the Bank will receive your personal data.
In order to provide services, BPS (SUISSE) may also potentially obtain personal data from freely accessible public sources (e.g. land, commercial and association registers, the press, the Internet) or be given it by third parties (e.g. credit reporting agencies).
5. Types of data processed
The type of personal data processed depends mainly on the purpose of processing. BPS (SUISSE) will only ever collect and process the data that it needs for the purposes that it pursues.
Such data may include:
6. Purpose of data processing
Personal data will be used:
7. Recipients of personal data
Within the Bank, any unit that needs your data to comply with contractual and legal obligations or to safeguard its legitimate interests will have access to your data. In the context of compliance with contractual and legal obligations, your personal data will not be processed solely by us, but also by relevant third parties (e.g. service providers, implementing partners). In particular, the management of risks also requires clarifications with third parties and related transfers of data (e.g. to authorities, auditors and other banks). Data may also be communicated on the basis of legal requirements (e.g. when fulfilling relevant clarification, disclosure and information obligations). In processing your personal data, the data recipients are bound by legal and/or contractual provisions. For the purposes described above, we are authorised to send your personal data to the following categories of recipients in Switzerland and abroad:
Before transmitting your personal data, we perform a thorough examination of the respective recipient of the data and arrange to contractually commit them to ensuring adequate protection of the data and maintaining confidentiality vis-à-vis your data.
Please note that, when you download our apps from an app store and use them, the manufacturers of the devices concerned and/or of the operating system (e.g. Microsoft, Apple, Google) receive personal data or can analyse your usage patterns. This may enable the detection of a current, past or future client relationship between you and us, an eventuality over which we have no control and are unable to prevent.
Data on the use of the websites may be transferred to third parties where permitted by law, if BPS (SUISSE) is obliged to do so, or if it needs to transfer the data in order to exercise its rights, particularly in the event of any dispute regarding a contractual relationship. The Bank may also disclose data to service providers with the stipulation that it is used solely for the purposes for which it is provided. Any person or entity that receives data is required to comply with the applicable national and international data protection laws and with the BPS (SUISSE) data protection regulations.
The recipients of personal data may be located in Switzerland or abroad. Therefore, your personal data may be processed all over the world. Data may be transmitted abroad because this is necessary for the execution of orders (e.g. payment and/or securities orders), because this is prescribed by law (e.g. in the context of notification obligations under tax law, automatic exchange of information, etc.) or because you have given the Bank your consent to do this.
If a recipient is located in a country that does not guarantee an adequate level of data protection, the Bank shall make every effort to commit the recipient to ensuring adequate protection of the data by drafting recognised standard contractual clauses, or shall proceed only if the exceptions prescribed by law apply (e.g. your consent, the conclusion or management of a contract, the safeguarding of overriding public interests, the assertion of legal claims, or if you have made the data accessible to the general public and are not opposed to the processing thereof).
8. Security measures
BPS (SUISSE) has taken appropriate technical and organisational security measures to protect your personal data against unauthorised access, misuse, loss or destruction, taking into account the applicable legal and regulatory requirements.
9. Data retention
BPS (SUISSE) processes and stores your personal data for as long as necessary to comply with its contractual and legal obligations or for the purpose of the processing concerned. In this context, we take into account the purpose of processing and, in particular, the need to safeguard our personal interests (e.g. to assert and defend against claims and to ensure information security). In this regard, it must be borne in mind that the business relationship with the Bank constitutes a long-term obligation of a number of years’ duration.
Data that is no longer required in order to comply with contractual and legal obligations will be erased unless it needs to be processed further – for a limited time – for the following purposes:
10. Transfer of data via the Internet
In general, the Internet (including social media, see notice) is not considered a secure environment, and data transferred via this channel may be viewed by unauthorised third parties, which risks disclosures, changes to content and technical issues. Even if the sender and recipient are resident in the same country, any data transferred via the Internet could be transmitted outside national borders to countries with a lower level of data protection than that required in the country of residence.
Please be aware that BPS (SUISSE) accepts no responsibility for the security of your data whilst it is being transferred to the Bank via the Internet.
11. Cookies and other tracking and analytics technologies
For the purposes outlined above, on its websites and apps, BPS (SUISSE) uses so-called cookies, small text files that are stored in your browser, and/or other tracking and analytics technologies. These files are created automatically when you use the Bank’s websites and stored on your device if you do not prevent this by disabling them. Cookies serve various purposes, including to make your browsing session secure, to store temporary settings, to save your language settings during multiple browser sessions and to show you content on the website that matches your interests (you can find more details on this in the "Cookie settings" section). You can disable the use of cookies at any time in your browser settings and delete existing cookies or manage your settings by clicking here. Disabling cookies may mean that certain features can no longer be used or can only be used to a certain extent.
In its apps, the Bank may use other tracking and analytics technologies from third-party providers, e.g. software development kits (SDK), to record and analyse your usage patterns. This enables us to continuously optimise our apps and identify errors. In the settings of the relevant app, you can disable the recording of your usage data and its transmission to the supplier concerned at any time.
12. Web analytics
To analyse and optimise its offerings, BPS (SUISSE) collects anonymised information on the use of its websites and their features.
In the publicly accessible sections of its websites, the Bank uses “Google Analytics” (a website analytics service provided by Google) in order to gain a better understanding of the use of its websites and thus make continuous improvements to their content and features. The legal basis for using “Google Analytics” is BPS (SUISSE)’s legitimate interest. Since the Bank’s websites are an important tool for communicating with existing clients and acquiring new ones, having functioning, attractive and tailored websites at all times is essential.
“Google Analytics” uses cookies, which are stored on your computer; please read the platform’s terms of service for more information. Google may process and analyse information collected via cookies regarding how visitors use the website and, based on this information, may send statistical evaluations of web page usage activities to BPS (SUISSE).
13. Profiling and automated individual decisions
In principle, for the purposes of establishing or fostering the business relationship, the Bank does not apply any fully automated decision-making process with legal effect.
To a certain extent, the Bank processes personal data by automated means in order to analyse specific personal aspects (profiling). This processing is used in the manner described below, for instance:
14. Rights of the data subject
Every data subject has the right of access under Article 8 of the Swiss Federal Act on Data Protection (FADP), the right to rectification under Article 5 FADP, the right to erasure under Article 5 FADP, the right to restriction of processing under Articles 12, 13 and 15 FADP, the right to object, and, where applicable, the right to data portability. If, by way of an exception, the processing of your personal data is based on consent that you have given separately, you have the right to revoke this at any time with effect for the future. Where applicable, you will be entitled to lodge a complaint with a supervisory authority with responsibility for data protection.
Having given us your consent to process your personal data, you may withdraw it at any time. Once you withdraw your consent, your personal data will no longer be processed for the purpose concerned, unless overriding public or private interests or the law allow for further processing. The same applies if you refuse consent to data processing. Please bear in mind that, in this case, the Bank may be unable to provide its services. It may take up to five working days for withdrawal or objection to come into effect. Data for advertising campaigns or information of a generic nature is usually processed several weeks in advance. It is therefore possible that you will still receive advertising for a certain period of time after exercising your right of withdrawal and/or objection. You may exercise your rights by sending a signed letter to the address stated in section 3, together with a copy of your identity card or passport.
Please note that these rights are subject to legal requirements and restrictions (e.g. we cannot delete data if we are obliged to comply with related retention obligations). We will ensure that you are informed of any restrictions. You are also entitled to these rights in relation to other parties tasked with data processing who collaborate with us under their own responsibility. To exercise your rights regarding processing, we suggest that you contact the relevant parties directly.
15. Links to other websites
BPS (SUISSE) websites may host third-party content or links to third-party websites that it does not operate or monitor directly. Please note that these third-party sites are not covered by the privacy policy set out in this notice, and that the Bank is not responsible for their content or personal data processing principles. You are advised to consult and check the individual privacy policies or terms of use of third-party electronic services.
16. Amendments
The Bank may amend and supplement this information at any time. The latest version is always available electronically on the website: www.bps-suisse.ch/en/privacy.php.
You can contact our call centre between 8 a.m. and 5.30 p.m. Monday to Friday on 00800 800 767 76 (calls from Switzerland are free).
Alternatively, you can use our contact request forms.