finra

Legal · Annex A to the GTC

Data processing agreement

Agreement on processing on behalf under Art. 9 of the revised Federal Act on Data Protection (revised FADP) between the customer and finra.

The German version of this document is authoritative. Translations serve comprehension only.

1. Subject matter and roles

This data processing agreement (hereinafter „DPA") forms Annex A to the General Terms and Conditions of finra.ch and comes into effect upon use of the portal. It governs the processing of personal data that the customer (broker or fiduciary) receives from its own end customers via finra.

  • The Customer is the controller with regard to this end-customer data; it determines the purpose and means of the processing.
  • finra (R. Selimi, 9470 Buchs SG) is the processor and processes this data exclusively on behalf of and in accordance with the instructions of the customer.

For the customer's own account and contract data as well as for the technical operation of the platform, finra is by contrast independently responsible; the Privacy policy applies to this.

2. Nature, purpose and duration of the processing

Nature of the processing: Storage, provision, display, organisation and status management of the documents and information uploaded by the end customers via the portal.

Purpose: Provision of the customer portal so that the customer can receive documents from its end customers, manage them and track their processing status.

Duration: The processing takes place for the duration of the usage relationship between the customer and finra. Upon its termination, clause 11 (return and deletion) applies.

3. Categories of data subjects and data

Data subjects: the customer's end customers as well as further persons invited into the portal by it.

Data categories: Contact and master data as well as tax-, insurance- and finance-related documents. These may contain sensitive personal data under Art. 5 let. c revised FADP (such as information on health, assets or social insurance). finra takes account of this heightened need for protection through the measures under clause 6.

4. Compliance with instructions and purpose limitation

finra processes the data entrusted to it on behalf exclusively for the purposes stated in clause 2 and only within the framework of the customer's instructions. Use of the platform constitutes a documented instruction; any instructions going beyond this are issued by the customer by e-mail to info@finra.ch.

finra does not sell this data, does not pass it on for its own purposes and does not use it in particular to train AI models or for advertising. If finra considers an instruction to be unlawful, finra informs the customer without delay.

5. Confidentiality

finra treats all data processed on behalf as confidential. Persons authorised to process this data are bound to confidentiality, unless they are already subject to a statutory duty of secrecy (Art. 9 para. 1 revised FADP).

6. Technical and organisational measures

finra ensures data security appropriate to the risk (Art. 8 revised FADP, Art. 1–6 DPO), in particular:

  • end-to-end TLS encryption of all connections,
  • role-based access control — documents are accessible only after personal login and only to authorised persons,
  • strict tenant separation (each customer with its own subdomain and separate data view),
  • logging of security-relevant operations (audit trail),
  • regular, secured data backups,
  • Storage exclusively in data centres in Switzerland.

7. Engagement of sub-processors

The customer approves the engagement of the following sub-processor for hosting, data storage and e-mail dispatch:

  • Infomaniak SA, Geneva, Switzerland — hosting, storage and e-mail. Data location exclusively Switzerland.

If finra intends to engage a further sub-processor or to replace one, finra informs the customer in advance and grants it the opportunity to object for important data protection reasons. finra obliges every sub-processor to an equivalent level of data protection (Art. 9 para. 3 revised FADP).

8. No disclosure abroad

All data processed on behalf remains in Switzerland. There is no disclosure abroad. Should a disclosure abroad become necessary in the future (for instance through a payment service provider), it shall take place only under the conditions of Art. 16 et seq. revised FADP and after prior information to the customer.

9. Support for the controller

finra supports the customer with appropriate technical and organisational measures in fulfilling its obligations as controller — in particular in responding to requests from data subjects (access, rectification, deletion, release/portability under Art. 25–28 revised FADP). If end customers contact finra directly, finra forwards their matters to the responsible customer and does not answer them independently.

10. Notification of data security breaches

If finra becomes aware of a breach of data security concerning data processed on behalf, finra reports this to the customer without delay with the available information. The notification to the Federal Data Protection and Information Commissioner (FDPIC) and, where applicable, to the data subjects is the responsibility of the customer as controller (Art. 24 revised FADP); finra supports it in this.

11. Return and deletion after the end of the contract

After termination of the usage relationship, finra makes the data processed on behalf available to the customer for export in a common format for 30 days. After this period expires, the data and any copies are deleted, provided no statutory retention obligation stands in the way. The deletion of finra's own business records (e. g. invoices) is governed by the statutory periods.

12. Evidence and audit

Upon reasoned request, finra makes available to the customer the information necessary to demonstrate compliance with this DPA. finra maintains a register of the processing carried out on behalf under Art. 12 revised FADP.

Annex A to the GTC · As at: 01.08.2026