finra

Legal

Privacy policy

How finra.ch processes and protects personal data and uploaded documents under the revised Swiss Federal Act on Data Protection (revised FADP).

The German version of this document is authoritative. Translations serve comprehension only.

1. Controller and our dual role

This privacy policy explains how personal data is processed in connection with finra.ch. The revised Swiss Federal Act on Data Protection (revised FADP) together with its Data Protection Ordinance (DPO) is authoritative.

The provider responsible for the operation of finra.ch is:

finra — Sole proprietorship of R. Selimi
9470 Buchs SG, Switzerland
E-mail: info@finra.ch

finra processes personal data in two different roles. This determines whom you should contact with your matters:

  • As controller we act with regard to the account and contract data of the brokers and fiduciaries (our business customers) as well as for the technical operation, security and further development of the platform. For this processing we are your point of contact.
  • As processor we act with regard to the documents and information of their own end customers received by the brokers and fiduciaries via the portal. For this data, the respective broker or fiduciary is the controller; it determines the purpose and means of the processing. We process this data exclusively on instruction, on behalf and within the framework of a data processing agreement under Art. 9 revised FADP. If end customers wish to exercise rights in respect of these documents, they should contact their broker; we support the latter in this.

2. What data we process

  • Account and registration data (as controller): name, e-mail address, company, role, language and login data of the brokers, fiduciaries and the users created by them.
  • Contract and payment data (as controller): selected package, term, billing and payment details.
  • Uploaded documents (as processor): tax-, insurance- and finance-related documents that end customers submit via the portal. These may contain information on income, assets, health or insurance relationships and are deemed sensitive personal data under Art. 5 let. c revised FADP.
  • Usage and server log data (as controller): IP address, time of access, pages accessed, browser type — to ensure operation and security.
  • Information from the contact form (as controller): name, e-mail address, telephone number and message content.

3. Purposes of the processing

We process personal data to fulfil the usage contract (provision and operation of the customer portal), for invoicing and contract administration, to respond to contact enquiries, to ensure system security and prevent misuse, to further develop the offering and to fulfil statutory obligations. We use the end-customer documents processed on behalf of the brokers exclusively for the purpose specified by the respective broker (receipt, provision and status management of the documents) and not for our own purposes.

As a private undertaking we do not require a separate statutory basis for this processing under the revised FADP; we comply with the processing principles under Art. 6 revised FADP (good faith, proportionality, purpose limitation, accuracy). Where we rely on consent (for instance with the contact form), you may withdraw it at any time.

4. Hosting, processors and no disclosure abroad

  • Hosting and e-mail are provided by Infomaniak SA, Geneva, Switzerland. All data and uploaded documents remain in Switzerland.
  • There is no disclosure of personal data abroad.
  • Processors engaged by us are contractually bound to confidentiality, data security and compliance with Swiss data protection law (Art. 9 revised FADP); they process data only on our instructions.
  • Note for the future: As soon as we introduce payment processing via an external payment service provider, payment and contact data will be transmitted to it, which may result in a disclosure abroad. We will supplement this policy accordingly before going live and ensure the required safeguards under Art. 16 et seq. revised FADP.

5. Disclosure to third parties

As a matter of principle, we do not pass personal data on to third parties. Disclosure takes place exclusively to the processors named above within the framework of the processing on behalf, and where we are legally obliged to do so or an official or judicial order exists. There is no sale of data and no passing on for advertising purposes.

6. Data security

We take appropriate technical and organisational measures to protect your data (Art. 8 revised FADP, Art. 1–6 DPO), in particular:

  • end-to-end TLS encryption of all connections to finra.ch,
  • storage in Switzerland with access protection and a role-based authorisation concept — uploaded documents can be viewed only after login with a personal account,
  • separation of tenants (each broker with its own subdomain and separate visibility),
  • logging of access to sensitive operations (audit trail),
  • regular data backups.

If, despite all precautions, a breach of data security occurs that is likely to result in a high risk to the data subjects, we report it to the Federal Data Protection and Information Commissioner (FDPIC) and, where necessary, to the data subjects as quickly as possible (Art. 24 revised FADP). If the incident concerns end-customer documents processed on behalf, we notify the broker concerned as controller without delay.

7. Register of processing activities

As we process sensitive personal data, we maintain a register of processing activities under Art. 12 revised FADP. The exemption for smaller undertakings does not apply here.

8. Retention and deletion

We retain personal data only for as long as the respective purpose or a statutory obligation requires (Art. 6 para. 4 revised FADP):

  • Account and uploaded document data are deleted within a reasonable period after termination of the contractual relationship or after deletion of an account; a data export remains possible during this period. With regard to the end-customer documents, we act on the instructions of the respective broker.
  • Server log data is deleted automatically after a short time (as a rule a few months).
  • Contact form enquiries are deleted as soon as they have been dealt with and no further correspondence is to be expected.
  • We retain our own business and accounting records for the statutory period of ten years (art. 958f CO).

You may request early deletion at any time, provided no statutory retention obligation stands in the way.

9. Cookies · 10. No automated individual decisions

finra.ch uses exclusively technically necessary session cookies to ensure the login status and security during use. There is no tracking, no advertising cookies are set and no third-party analysis tools are integrated.

We take no automated individual decisions within the meaning of Art. 21 revised FADP that would have legal or significant effects for you, and we do not carry out profiling.

11. Your rights

Within the framework of the revised FADP, you have in particular the right to access (Art. 25), rectification (Art. 32), deletion as well as the right to object to processing or to have it restricted, and the right to the release or transfer of your data (data portability, Art. 28). We provide information free of charge and, as a rule, within 30 days.

  • If your matter concerns your account or our operation (controller role), an e-mail to info@finra.ch suffices.
  • If your matter concerns documents uploaded by a broker (processor role), please contact the broker or fiduciary concerned as the controller. We forward such requests to it and support it.

If you do not agree with our response, you may contact the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.

12. Amendments

We may amend this privacy policy in order to adapt it to changed legal or technical circumstances. The version published on finra.ch at any given time is authoritative.

As at: 01.08.2026