GEMARA SA Privacy Policy

Data Protection Notice pursuant to the nFADP

Version
1.0
Effective Date
15 May 2026
Controller
GEMARA SA, Rue Du-Roveray 20, 1207 Geneva, Switzerland
Contact
contact@gemara.ch

1. Introduction

GEMARA SA (hereinafter “Gemara”, “the Company”, “we”, “us” or “our”) is a company incorporated under Swiss law, headquartered in Geneva, Switzerland, and operating in the financial technology sector. The Company is a member of the Self-Regulatory Organisation VQF (Verein zur Qualitätssicherung von Finanzdienstleistungen), SRO VQF, which is recognised by the Swiss Financial Market Supervisory Authority (FINMA) pursuant to the Anti-Money Laundering Act.

The Company provides, among other services: (i) the issuance of prepaid payment instruments and vouchers; (ii) the management of technical voucher accounts; and (iii) technical payment processing and acceptance services to merchants, enabling them to accept transactions made with the Company's payment instruments (collectively, the “Services”).

In the course of providing its Services, the Company collects, uses, stores, transfers and otherwise processes personal data relating to end users, account holders, merchants' end customers and business contacts. The Company is committed to protecting all personal data it processes and to complying fully with applicable Swiss data protection law.

This Privacy Policy describes the personal data we collect, the purposes and legal grounds for its processing, how we share it, how long we retain it, and the rights you may exercise. Please read it carefully. By using any of our Services, you acknowledge that you have read and understood this Privacy Policy.

2. Applicable Legal and Regulatory Framework

The processing of personal data by the Company is governed by the following Swiss legislation, regulations and supervisory instruments:

2.1. Data Protection Law

  • Federal Act on Data Protection of 25 September 2020 (nFADP / LPD / revDSG), SR 235.1 — the principal data protection statute, in force since 1 September 2023, governing all processing of personal data relating to natural persons in Switzerland.
  • Ordinance on Data Protection of 31 August 2022 (ODP / ODPr / VDSG), SR 235.11 — implementing regulation of the nFADP, in force since 1 September 2023, specifying inter alia data security requirements, profiling thresholds and cross-border transfer mechanisms.

2.2. Financial Market and Anti-Money Laundering Law

  • Federal Act on Combating Money Laundering and Terrorist Financing of 10 October 1997 (AMLA / LBA), SR 955.0 — imposes know-your-customer (KYC) and client identification obligations on financial intermediaries, including members of recognised SROs.
  • Ordinance on Combating Money Laundering and Terrorist Financing (AMLO / OBA), SR 955.01 — implementing regulation to the AMLA.
  • VQF Anti-Money Laundering Regulations (Reglement VQF) — the binding SRO rules issued by VQF, approved by FINMA, which the Company is required to observe as an affiliated member.
  • FINMA Circular 2016/7 — Video and Online Identification — governs remote KYC procedures for digital onboarding.
  • Federal Act on Financial Market Infrastructures and Market Conduct in Securities and Derivatives Trading (FMIA / LIMF), SR 958.1 — applicable to the extent the Company's payment instruments constitute a payment system.

2.3. Contract and Telecommunications Law

  • Swiss Code of Obligations of 30 March 1911 (CO), SR 220 — governs contractual obligations arising between the Company and its users, merchants and business partners.
  • Federal Act on Telecommunications of 30 April 1997 (TCA / LTC), SR 784.10 — applicable to the extent the Company's processing activities involve electronic communications services, including the use of cookies and similar tracking technologies.
  • Federal Act on Electronic Signatures (ESA / SCSE), SR 943.03 — applicable to the extent that electronic signature mechanisms are used in onboarding or contracting.

2.4. Cross-Border and International Considerations

The Company's Services are primarily directed at users located in Switzerland. Where the Company transfers personal data outside Switzerland, it does so in accordance with the requirements of Article 16 et seq. of the nFADP and the ODP, including but not limited to:

  • Adequacy decisions — transfers to countries or international organisations whose level of protection has been recognised as adequate by the Federal Council pursuant to Article 16(1) nFADP (see the FDPIC list of adequate countries).
  • Appropriate safeguards — where no adequacy decision exists, transfers are effected on the basis of Standard Contractual Clauses (SCCs) approved or recognised under Swiss law, binding corporate rules, or other mechanisms set out in Article 16(2) nFADP.

Although the Company's end users are principally located in Switzerland, and thus the EU General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) does not apply as a primary legal instrument, the Company takes note of applicable Swiss-EU adequacy arrangements and seeks to maintain data protection standards consistent with Swiss law, which is recognised by the European Commission as providing adequate protection.

3. Identity and Contact Details of the Controller

The controller responsible for the processing of your personal data within the meaning of Article 5(j) nFADP is:

GEMARA SA
Rue Du-Roveray 20
1207 Geneva, Switzerland
Commercial Register: CH-660.4.808.024-4
Data Protection Contact: contact@gemara.ch

If you have questions, requests or complaints regarding this Privacy Policy or the processing of your personal data, you may contact us at the address or email above. We will endeavour to respond within thirty (30) calendar days of receipt of your request.

4. Categories of Data Subjects

This Privacy Policy applies to all natural persons whose personal data the Company processes in connection with its Services, including:

  • End users who purchase, hold or use prepaid payment instruments or vouchers issued by the Company, whether or not they have registered an account (“Voucher Users”);
  • Account holders who have opened a technical voucher account with the Company and provided personal data during the registration process (“Account Holders”);
  • End customers of merchants who engage with the Company's payment infrastructure and whose data is transmitted to the Company by the merchant in the course of transaction processing (“Merchant Customers”);
  • Representatives, employees, beneficial owners and contact persons of merchants, business partners and service providers with whom the Company maintains contractual relationships (“Business Contacts”);
  • Visitors to the Company's website(s) and digital channels.

5. Personal Data We Collect

The categories of personal data we process depend on the nature of your relationship with the Company and the Services you use.

5.1. Prepaid Payment Instruments and Vouchers (Unregistered Use)

Even where you do not create an account, the Company may collect certain personal data in connection with the issuance, distribution, loading or redemption of a prepaid payment instrument or voucher, including:

  • Transaction data: voucher reference or serial number, transaction amount, date, time and location of redemption, merchant identifier;
  • Technical identifiers: device fingerprint, IP address, browser type and version, cookie identifiers, session tokens;
  • Contact data provided voluntarily: if you contact our customer support, the email address, name and content of the communication you submit;
  • Identity data collected at point-of-sale or online activation: where required by applicable AML/KYC thresholds under the AMLA and VQF regulations, first name, last name, date of birth and, where applicable, a copy of an identity document.

5.2. Technical Voucher Accounts (Registered Users)

When you open or operate a technical voucher account, we collect and process the following categories of data:

  • Identity data: first name, last name, date of birth, nationality;
  • Contact data: email address, postal address, telephone number;
  • Authentication data: username, hashed password, two-factor authentication credentials;
  • Identity verification data: scanned identity document (passport, identity card or equivalent), selfie or video for remote identification, verification results;
  • Financial data: balance information, transaction history, linked payment method details (where applicable);
  • Technical data: login timestamps, IP addresses, device identifiers, session logs;
  • Correspondence: records of all written communications with the Company.

5.3. Data Received from Merchants (Merchant Customers)

In the context of providing technical payment processing services to merchants, the Company may receive from the merchant personal data relating to the merchants' and the Company's end customers in connection with individual transactions completed with a Company-issued voucher (doing so, the end customer becomes a customer of the Company too). Such data typically includes, but is not limited to:

  • First name and last name;
  • Date of birth (where required for age verification or KYC purposes);
  • Email address;
  • Transaction reference, amount, currency, date and time;
  • Any other data transmitted by the merchant as part of a transaction payload in accordance with the relevant merchant services agreement.

The Company processes such data in parallel with the merchant, as the user of the voucher accepts the Company's Terms of Use when purchasing and redeeming the voucher and becomes an end customer of the Company too. As the Company independently determines the purposes and means of processing (e.g., for AML screening), it acts as a controller in its own right.

5.4. Merchant and Business Partner Contacts

In respect of merchants and other business partners, the Company processes:

  • Name, function and professional contact details (email, telephone, address) of representatives and signatories;
  • Identity and verification documents of beneficial owners, directors and authorised signatories as required under the AMLA and VQF regulations;
  • Contractual documentation and correspondence;
  • Financial information relevant to the business relationship (e.g., bank account details for settlement purposes).

5.5. Data Sources

We collect personal data directly from you when you use our Services. We also obtain personal data from third parties, including:

  • Merchants who submit transaction data to us;
  • KYC/identity verification providers;
  • Sanctions, PEP and adverse media screening providers;
  • Fraud monitoring and transaction monitoring tools;
  • Publicly accessible registers (e.g., commercial registers);
  • Authorities and supervisory bodies where legally required.

We process such data in accordance with Article 19(2)(b) nFADP.

6. Purposes of Processing and Legal Grounds

The Company processes personal data on the following legal bases under Article 6 nFADP, which provides that processing is lawful where it serves a purpose that is legitimate, proportionate and proportional to the legitimate interest pursued, or where the data subject has consented, or where processing is required to perform or prepare a contract, or where processing is required by law.

6.1. Performance of a Contract or Pre-Contractual Measures (Art. 6(2)(b) nFADP)

  • Issuing, managing, loading and processing prepaid payment instruments and vouchers;
  • Opening and maintaining technical voucher accounts;
  • Executing transactions and processing payments;
  • Providing customer support and handling complaints;
  • Onboarding merchants and providing technical payment acceptance services under merchant services agreements.

6.2. Compliance with Legal Obligations (Art. 6(2)(c) nFADP)

  • Performing customer due diligence (CDD) and enhanced due diligence (EDD) as required under the AMLA, AMLO and VQF regulations;
  • Identifying and verifying the identity of clients and beneficial owners (KYC);
  • Screening against sanctions lists, PEP lists and adverse media pursuant to AMLA obligations;
  • Detecting, investigating and reporting suspicious transactions to the Money Laundering Reporting Office Switzerland (MROS) in accordance with Articles 9 and 37 AMLA;
  • Complying with data retention obligations imposed by the AMLA (ten years), CO (ten years) and applicable cantonal law;
  • Responding to lawful requests from judicial or supervisory authorities (FINMA, VQF, cantonal authorities, MROS).

6.3. Legitimate Interest of the Company (Art. 6(2)(d) nFADP)

Where the Company relies on legitimate interest, it has carried out a balancing assessment and determined that its interests are not overridden by the interests or fundamental rights of the data subject. Processing on this basis includes:

  • Fraud prevention, detection and investigation, including transaction monitoring and anomaly detection;
  • Information security, including penetration testing, access controls, logging and audit trails;
  • Business continuity and disaster recovery management;
  • Improving, testing and developing our Services and internal systems;
  • Defending and asserting legal claims;
  • General corporate administration, internal reporting and governance.

6.4. Consent (Art. 6(2)(a) nFADP)

Where the Company relies on your consent, this will be obtained expressly and separately before processing commences. Processing on the basis of consent includes:

  • Sending promotional communications and marketing materials (including newsletters and product updates);
  • Placing non-essential cookies and similar technologies on your device (see Section 12 below);
  • Conducting surveys, market research or user experience studies.

You may withdraw your consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

7. Sensitive Personal Data

The nFADP designates certain categories of data as “sensitive personal data” (données sensibles), which includes data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health data, data concerning sex life and sexual orientation, biometric data used for identification purposes, and data on social welfare measures or administrative and criminal proceedings (Article 5(c) nFADP).

The Company does not intentionally collect sensitive personal data. However, in the context of identity verification processes required under the AMLA, the Company may necessarily process biometric data (facial images for matching) and information contained in identity documents that may incidentally reveal ethnicity or nationality. Such processing is strictly limited to what is required under applicable law and is protected by appropriate technical and organisational measures.

In the event that any sensitive data is transmitted to the Company by a merchant or data subject, the Company will treat it with heightened care and limit its processing to the extent strictly necessary and legally justified.

8. Recipients and Disclosure of Personal Data

The Company does not sell personal data to third parties. We may share personal data with the following categories of recipients:

8.1. Service Providers and Data Processors

The Company engages third-party service providers who process personal data on its behalf under binding data processing agreements compliant with Article 9 nFADP. These include:

  • Cloud infrastructure and hosting providers;
  • KYC and identity verification solution providers;
  • Payment processing and settlement partners;
  • Sanctions and PEP screening providers;
  • IT security, monitoring and audit service providers;
  • Legal, tax and financial advisors (subject to professional secrecy obligations);
  • Customer relationship management (CRM) and support platform providers.

8.2. Merchants

Where end-user data is transmitted to the Company by a merchant in the context of transaction processing, the Company may share transaction confirmation, status updates or error information with the relevant merchant in respect of that transaction. The merchant is independently responsible for its own data processing activities in relation to its customers.

8.3. Regulatory and Supervisory Authorities

The Company is required by law to disclose personal data to the following authorities:

  • Money Laundering Reporting Office Switzerland (MROS): where a suspicious activity report (SAR) is filed pursuant to Article 9 AMLA;
  • Swiss Financial Market Supervisory Authority (FINMA): in the context of regulatory inspections, licensing queries or enforcement proceedings;
  • VQF: in the context of SRO supervisory audits, reviews or disciplinary proceedings;
  • Swiss federal, cantonal or municipal judicial authorities: where disclosure is required by law or court order;
  • Foreign competent authorities: only where required under a binding legal obligation applicable to the Company and subject to any applicable Swiss blocking statutes.

8.4. Group Entities and Corporate Transfers

Where the Company belongs to a corporate group, it may share personal data with affiliated entities for internal administrative purposes, subject to appropriate intragroup data sharing arrangements and applicable data protection requirements.

In the event of a merger, acquisition, restructuring or sale of all or part of the Company's business, personal data may be disclosed to prospective acquirers or their advisors, subject to appropriate confidentiality undertakings, and transferred to successors following completion.

8.5. Outsourcing and Data Processing Agreements (Art. 9 nFADP)

Where the Company engages third-party service providers located in Switzerland or the European Union to process personal data on its behalf (including IT hosting, cloud services, and customer due diligence (CDD/KYC) providers), such providers act as data processors (Auftragsbearbeiter) within the meaning of Article 9 nFADP.

The Company ensures that all such processing is governed by a written Data Processing Agreement (DPA), which includes in particular:

  • Processing only on documented instructions from the Company;
  • Confidentiality obligations binding all authorised personnel;
  • Implementation of appropriate technical and organisational measures in accordance with Article 8 nFADP and the ODP;
  • Prior authorisation requirements for the engagement of sub-processors, including transparency and objection rights;
  • Assistance to the Company in fulfilling its data protection obligations, including responding to data subject requests;
  • Notification of personal data breaches without undue delay;
  • Audit and inspection rights in favour of the Company;
  • Obligation to delete or return personal data upon termination of services.

The Company remains responsible for ensuring that any processor provides sufficient guarantees of compliance with applicable data protection law.

8.6. Regulatory and AML-Specific Outsourcing Safeguards

In the context of outsourcing functions relevant to anti-money laundering compliance (including KYC/CDD and transaction monitoring), the Company implements additional safeguards to ensure compliance with the Swiss Anti-Money Laundering Act (AMLA) and applicable SRO regulations. These include:

  • Obligations on service providers to support the Company in fulfilling AMLA duties;
  • Cooperation with audits and regulatory requests from FINMA and the relevant SRO;
  • Prompt notification of legally binding requests from public authorities, unless prohibited by law;
  • Strict segregation of the Company's data from that of other clients;
  • Ensuring that sensitive identification and KYC data is processed only in jurisdictions with adequate protection.

9. International Transfers of Personal Data

The Company primarily processes personal data within Switzerland. Where processing activities involve the transfer of personal data to a country or international organisation outside Switzerland, the Company will only do so in compliance with Articles 16 and 17 nFADP and the ODP:

  • To countries whose level of data protection has been recognised as adequate by the Federal Council (see the FDPIC list of countries with adequate protection);
  • On the basis of standard contractual clauses (SCCs) recognised under Swiss law, which provide appropriate safeguards for the protection of transferred data;
  • On the basis of binding corporate rules approved under Swiss law;
  • Where another derogation listed in Article 17 nFADP applies, including where the data subject has expressly consented to the proposed transfer after being informed of the risks, or where the transfer is necessary for the performance or conclusion of a contract concluded in the interest of the data subject.

Upon request, the Company can provide information about the specific safeguards in place for any given transfer.

9.1. International Transfers — List of Countries

Where we transfer personal data abroad, such transfers may occur to the following countries:

  • European Union / EEA member states (adequate protection).

We will update this list if additional countries are added.

9.2. Transfers to the European Union (Adequacy)

Where personal data is transferred to service providers located in the European Union or European Economic Area, such transfers are based on the adequacy decision of the Swiss Federal Council recognising that these jurisdictions provide an adequate level of data protection. The Company ensures that:

  • Processing takes place within the EU/EEA unless otherwise authorised;
  • Any onward transfer by the processor to a third country is subject to prior written authorisation and appropriate safeguards under Swiss law;
  • Processors are contractually bound to comply with Swiss data protection requirements in addition to any applicable EU law.

10. Data Retention

The Company retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following general retention periods apply:

Category of DataRetention PeriodLegal Basis
KYC / identity verification records, incl. biometric data (facial image)10 years from end of business relationshipArt. 7 AMLA / VQF Regulations
Customer information (transmitted by merchant)10 years from end of business relationship / 10 years post transaction if no account openedArt. 7 AMLA / VQF Regulations
Transaction and payment records10 years from end of business relationshipArt. 7 AMLA; Art. 958f CO
Account data (registered users)10 years from account closureArt. 7 AMLA; Art. 958f CO
Merchant contract data10 years from end of contractArt. 958f CO
Suspicious activity reports (SAR)10 years from filing dateArt. 7 AMLA
Customer support communications5 years from closure of matterCO; legitimate interest
Marketing and consent records3 years from last interaction or withdrawalnFADP Art. 6
Website technical logs (unregistered)12 months from collectionLegitimate interest
Cookie / tracking data13 months maximum (session cookies: session end)TCA; nFADP Art. 6

At the end of the applicable retention period, personal data will be securely deleted or anonymised in accordance with the Company's data retention and destruction policy. Where legal proceedings or regulatory investigations are ongoing, data will be retained until those proceedings are finally concluded.

11. Data Security

The Company implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with Article 8 nFADP and the requirements of Annex 1 to the ODP. Such measures include, without limitation:

  • Encryption of personal data at rest and in transit using industry-standard protocols (TLS 1.2 or higher; AES-256 or equivalent);
  • Role-based access controls and the principle of least privilege;
  • Multi-factor authentication for access to systems processing personal data;
  • Regular penetration testing and vulnerability assessments;
  • Audit logging of access to sensitive data and systems;
  • Business continuity and disaster recovery procedures, including regular encrypted backups;
  • Employee training on data protection and information security;
  • Contractual security requirements imposed on all data processors.

Notwithstanding these measures, no transmission or storage system is completely secure. In the event of a personal data breach that poses a high risk to individuals, the Company will notify the FDPIC as required under Article 24 nFADP and will inform affected data subjects without undue delay where required by law.

12. Cookies and Similar Technologies

The Company's website(s) and digital platforms use cookies and similar technologies (collectively, “cookies”) in accordance with the TCA and the nFADP. Cookies are small text files stored on your device when you visit our digital channels.

12.1. Strictly Necessary Cookies

These cookies are essential for the operation of our website and Services (e.g., session management, security tokens, load balancing). They do not require your consent and cannot be disabled.

12.2. Analytical and Performance Cookies

These cookies collect information about how visitors use our website (e.g., pages visited, error messages, traffic sources). They help us improve our Services. They are only placed with your prior consent.

12.3. Functional Cookies

These cookies enable personalised features, such as remembering your language preference. They are placed with your prior consent.

12.4. Marketing Cookies

We do not currently use third-party advertising or marketing cookies. Should we introduce such cookies in the future, we will seek your prior consent in compliance with applicable law.

You may manage your cookie preferences via our cookie consent banner or your browser settings. Please note that disabling certain cookies may affect the functionality of our Services.

13. Your Data Protection Rights

Subject to applicable law and certain exceptions (including, in particular, the Company's obligations under the AMLA and VQF regulations, which may restrict or preclude the exercise of certain rights), you have the following rights under the nFADP:

  • Right of access (Art. 25 nFADP): You have the right to request a copy of the personal data held about you and information about how it is processed.
  • Right to rectification (Art. 32(1) nFADP): You have the right to request correction of inaccurate personal data or the completion of incomplete data.
  • Right to erasure (Art. 32(2)(a) nFADP): You have the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected and no overriding retention obligation applies.
  • Right to restriction of processing (Art. 32(2)(b) nFADP): You have the right to request that the processing of your data be restricted in certain circumstances, for example while the accuracy of the data is contested.
  • Right to data portability (Art. 28 nFADP): Where processing is based on your consent or a contract with you, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used and machine-readable format, and to have it transmitted directly to another controller where technically feasible.
  • Right to object (Art. 32(2)(c) nFADP): You have the right to object to processing based on the Company's legitimate interests. The Company will cease such processing unless it demonstrates compelling legitimate grounds that override your interests, or the processing is necessary for legal claims.
  • Right to withdraw consent (Art. 6 nFADP): Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of prior processing.
  • Right to lodge a complaint: You have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland (www.edoeb.admin.ch), if you believe that your data has been processed unlawfully.

Please note that, pursuant to Articles 9 and 37 AMLA, the Company is prohibited from informing any person who is the subject of, or connected to, a suspicious activity report that such a report has been or may be filed, or that a related investigation is underway. Accordingly, the Company may in certain circumstances be unable to fully respond to a request for access, rectification or erasure if doing so would violate this prohibition.

To exercise any of your rights, please submit a written request to the data protection contact address indicated in Section 3. The Company will respond within thirty (30) calendar days. In complex cases, the response period may be extended by a further sixty (60) days with prior notification.

14. Automated Decision-Making and Profiling

The Company may use automated processes to screen transactions for fraud, money laundering and sanctions exposure. These processes may produce automated flags or scores that have consequences for the processing of transactions or business relationships. Where such automated processing constitutes profiling with a significant effect on you within the meaning of Articles 21 and 22 nFADP, the Company will:

  • Inform you of the fact of such processing;
  • Provide you with the ability to state your position;
  • Ensure that the final decision is reviewed by a qualified member of staff where your interests are significantly affected.

AML screening and KYC checks are carried out as a matter of legal obligation and are not subject to opt-out.

15. Minors

The Company's Services are not directed at persons under the age of 18. The Company does not knowingly collect personal data from minors. If the Company becomes aware that it has inadvertently collected personal data from a minor, it will take prompt steps to delete such data. If you believe that a minor's data has been submitted to us, please contact us immediately at the address set out in Section 3.

Where applicable law requires that the consent of a legal representative be obtained in connection with the processing of a minor's data (e.g., in the context of emancipated minors who may lawfully use payment services), the Company will take appropriate steps to verify and document such consent.

16. Third-Party Websites and Links

Our website and communications may contain links to third-party websites or services. This Privacy Policy applies only to the Company's own processing activities. We are not responsible for the privacy practices of third parties and encourage you to review the privacy policies of any third-party website you visit.

17. Changes to This Privacy Policy

The Company reserves the right to amend this Privacy Policy at any time to reflect changes in applicable law, supervisory guidance, business practices or technological developments. The updated version will be published on our website with the new effective date prominently indicated. Where changes are material, the Company will provide notice by appropriate means (e.g., by email to registered account holders or by a prominent notice on our website) prior to the effective date.

Your continued use of our Services following publication of a revised Privacy Policy constitutes your acknowledgement of the updated version. We encourage you to review this Privacy Policy periodically.

18. Governing Law and Jurisdiction

This Privacy Policy is governed by Swiss law, in particular the nFADP and the ODP. Any dispute arising from or in connection with this Privacy Policy that is not resolved amicably shall be subject to the exclusive jurisdiction of the competent courts of the Canton of Geneva, Switzerland, subject to any mandatory provisions of applicable consumer protection law.

19. Language

This Privacy Policy may be translated into other languages for informational purposes. In the event of any inconsistency or discrepancy between the English version and any translation, the English version shall prevail, unless otherwise required by applicable mandatory law in the language concerned.

20. Annex — Glossary of Key Terms

TermDefinition
AMLA / LBAFederal Act on Combating Money Laundering and Terrorist Financing, SR 955.0
ControllerThe natural or legal person who determines the purposes and means of the processing of personal data (Art. 5(j) nFADP)
CDD / EDDCustomer Due Diligence / Enhanced Due Diligence — KYC procedures required under the AMLA
FDPICFederal Data Protection and Information Commissioner — the Swiss data protection supervisory authority
FINMASwiss Financial Market Supervisory Authority
KYCKnow Your Customer — identity verification and due diligence procedures
MROSMoney Laundering Reporting Office Switzerland — the Swiss financial intelligence unit
nFADP / LPDFederal Act on Data Protection of 25 September 2020 (new FADP), SR 235.1, in force since 1 September 2023
ODP / ODPrOrdinance on Data Protection of 31 August 2022, SR 235.11
Personal DataAny information relating to an identified or identifiable natural person (Art. 5(a) nFADP)
ProcessorAny natural or legal person who processes personal data on behalf of the controller (Art. 5(k) nFADP)
ProfilingAny form of automated processing of personal data to analyse or predict personal aspects (Art. 5(f) nFADP)
SARSuspicious Activity Report — filed with MROS pursuant to Art. 9 AMLA
SCCStandard Contractual Clauses — contractual safeguards for international data transfers
SRO VQFSelf-Regulatory Organisation VQF (Verein zur Qualitätssicherung von Finanzdienstleistungen), recognised by FINMA
TCA / LTCFederal Act on Telecommunications, SR 784.10