EN

Privacy policy

Personal Data and legal basis

The Group Eric Sturdza S.A. and its affiliates, Banque Eric Sturdza SA, Coges Corraterie Gestion SA and Eric Sturdza Asset Management SA (hereinafter:  the “Group” or “GES”), collect, process and protect Personal Data concerning its “Contracting Parties” and /or “Related Person(s)” (together the “Data Subjects”) in the context of existing and/or potential relationships or in the context of the use of our websites and applications.

A “Business Relationship” is any type of legal relationship between an external party and the Group or any of its affiliate.

A “Contracting Party” is, but not limited to, a business or employment relationship, including, an account holder, Group employee, and supplier.

Personal Data” is any personal information as further detailed in section 3 below of this Privacy Statement.

A “Related Person” means an individual or entity whose personal data is known to us in connection with a Business Relationship. Related Persons may include, but is not limited to: director, officer, signing officer or employee of a company, a trustee, settlor or protector of a trust, an economic beneficiary of a Contracting Party’s assets, a controlling interest, representative or agent of a Contracting Party, family member(s) and/or any other individual or entity that has a relationship with a Contracting Party that is relevant to a Business Relationship.

When a Contracting Party entrust GES with Personal Data, GES is responsible, upon direct request from the Contracting Party or indirect through one of its Related Persons, to inform the Contracting Party or the Related Persons by providing them with a copy of this Privacy Statement.

The Group processes Personal Data in accordance with the Swiss Federal Act on Data Protection (FADP). Personal Data may also be subject to banking secrecy or other contractual, regulatory or professional confidentiality obligations applicable to it.

Collection and processing of Personal Data

The Group collects and processes Personal Data for the following non exhaustive purposes:

  • Pre-contractual checks before entering into a Business Relationship (AML for example);
  • Opening and management of a Business Relationship with the Group, including all related operations for Data Subject identification;
  • Providing financial services related to a Business Relationship, including, amongst others, execution and payments services and financial services expressly requested by the Data Subject;
  • Employment contracts;
  • Management, administration and distribution of investment funds, including any ancillary services related to these activities, or the processing of subscription, conversion and redemption requests in investment funds, as well as for maintaining the ongoing relationship with respect to holdings in such investment funds;
  • Managing requests for proposals and/or due diligence and related communication with the Data Subjects.

i. Based on the Group’s legal and regulatory obligations, for instance:

  • Providing information on the Group’s products and services to the Data Subject;
  • Monitoring compliance with legal obligations in the area of financial market regulation, including tax and regulatory reporting;
  • Conducting audits and/or regular reviews;
  • Carrying out any form of cooperation with, or reporting to, competent authorities, in particular supervisory authorities, authorities responsible for combating money laundering and terrorist financing, authorities involved in the automatic exchange of information in tax matters (including the OECD Common Reporting Standard and the US Foreign Account Tax Compliance Act (FATCA)) and data protection authorities;
  • Any measure to comply with international sanctions in accordance with the procedures established by the Group, including the processing of Personal Data for screening purposes;
  • Any risk management measures, including market, credit, operational, liquidity, legal and reputation risks;
  • Recording telephone conversations and electronic communications with Data Subjects where relevant for risk management purposes (e.g. to combat fraud and other criminal offences).

ii. In connection with legitimate interests of the Group, including:

  • Any processing aimed at developing a Business Relationship;
  • Any processing necessary to enable the Group to establish, enforce or oppose actual or potential legal claims, or to enable the Group to handle internal investigations;
  • Recording images (e.g. video surveillance) for ensuring the security of individuals, assets, property, buildings, as well as critical infrastructure and IT systems;
  • Sharing Personal Data within the Group for internal administrative purposes, consolidated compliance and risk management purposes.

Where legally required, the Group will ask Data Subject for their consent in due time before processing their Personal Data.

Processing of Personal Data by the Group does not include automated decision-making.

Nature of information on Data Subjects

Personal Data include any information relating to an identified or identifiable natural person or as defined in the Federal Act on Data Protection of September, 25th 2020 or General Data Protection Regulation (hereinafter the “Applicable Law”). The Group processes the following categories of Personal Data regarding Data Subjects:

  1. Identification data (name, address, telephone number, e-mail address, business contact information, video and audio recordings, etc.).
  2. Personal information including Data Subject’s relatives as the case may be (date of birth, country of birth, nationality, passport or identity card, TIN, social security number, professional activity, professional experience, professional skills, power of representation, possible sentences or pending proceedings, reputation checks and background checks; due diligence information e.g. results of anti-money-laundering checks, credit checks).
  3. Financial information (personal and family financial situation, credit history, bank details, tax information, account history information).
  4. Payment, transaction and investment data (originators, beneficiaries, correspondent bank, payment instructions past and current investments, investment profile, investment objectives, investment preferences, amounts invested, number and value of financial instruments held, role played in a transaction (seller / buyer), details of a transaction, investment instructions, suitability test, asset allocation).
  5. Any records of telephone calls with the Group or other information related to interactions with Data Subjects (visits, contact forms, connections to Group applications).
  6. Based on prior consent, certain web browsing information, e.g. cookies and similar technologies on websites (see our Cookies policy).
  7. Additional data with regards to employees of the Group, staff and job candidates (e.g. CV, job references, education, trainings, absence due to illness, holidays, business trips) including interviews on or off premises.

Source of Information on Data Subjects collected

The Group collects and receives Personal Data either directly from each Data Subject and/or indirectly from external sources, including any publicly available sources (trade register, land register, sanctions lists, press, media, internet), information available through subscription services or through third parties (e.g. a business introducer or external asset manager, head hunters). Personal Data are also collected through the Group’s website.

Transfer of Personal Data to third parties

The Group may be required to disclose or make accessible Personal Data to the following recipients, provided this is legally or otherwise authorized or required:

  1. To stock exchanges, trading platforms, brokers, exchange or central repositories, banking correspondents (including custodian, sub-custodians, clearing or settlement houses), payment companies or institutions such as Swift, credit card issuers;
  2. To courts, judicial authorities, market supervisory authorities such as FINMA, self-regulatory organizations, tax authorities, government agencies, public registers, notaries, experts, auditors or legal advisors, trustees, heirs and will executors;
  3. Service providers including IT, back office, hosting, storage, printing, communication, document destruction support, software and application service providers, market data service providers, business intelligence, accountants & payroll specialists, HR agencies;
  4. Insurance companies.

Transfer abroad

The Group processes and stores Personal Data in connection, directly or indirectly, with the conclusion or performance of a  Business Relationship in data centres located in Switzerland.

In certain circumstances the Group may disclose, transfer and/or store Personal Data abroad (a “International Transfer”).

International Transfers may include the transfer to jurisdictions that: (i) ensure an adequate level of data protection for the rights and freedoms of Data Subjects; (ii) benefit from adequacy decisions as regards their level of data protection (e.g. adequacy decisions from the Swiss Federal Data Protection and Information Commissioner); or (iii) do not benefit from such adequacy decisions and do not offer an adequate level of data protection. In the latter case, the Group will ensure on best effort basis that appropriate safeguards are provided, e.g. by using standard contractual data protection clauses recognized by the Federal Data Protection and Information Commissioner (FDPIC).

Length of time for which Personal Data is stored and recorded

Personal Data will be kept for as long as necessary in order to fulfil the Group’s contractual and legal obligations regarding the relevant Business Relationship.

Personal Data will be kept for a period of ten (10) years after the end of a Business Relationship. After this retention period, the Group safely destroys Personal Data.

Rights under data protection legislation

Each Data Subject has the following rights with regard to his or her Personal Data:

  1. Right to access and obtain information concerning their Personal Data;
  2. Right to have their Personal Data rectified if it is inaccurate, incomplete or obsolete;
  3. Right to oppose the processing of their Personal Data;
  4. Right to withdraw consent at any time when Personal Data Processing is based on consent;
  5. Right to delivery or transmission of Personal Data;
  6. Right to request a limit on the processing of their Personal Data;
  7. Right to obtain a copy of, or access to, the appropriate or suitable safeguards which the Group may have implemented in case of transferring the Personal Data abroad; and;
  8. Right to request the deletion of their Personal Data when it is no longer necessary for the purposes for which it was collected or processed or when the Data Subject has withdrawn his/her consent (in cases where the processing of the Personal Data in question is based on the consent of the Data Subject).

All Data Subjects may, at any time and without justification, object to the use of their Personal Data for marketing purposes, including profiling if it serves this purpose, by the Group or by third parties. Revocation of consent shall only have effect for the future. Any processing that was carried out prior to the revocation shall not be affected thereby.

Failing to provide certain Personal Data or revoking consent may preclude the Group from establishing or pursuing a Business Relationship including maintaining the Contracting Party’s account with the Group.

The aforementioned rights are limited by the Group’s legal obligations, by the requirements of the Business Relationship or by a legitimate interest of the Group, in particular the defence, exercise or establishment of legal claims.

Security

The Group is subject to a regulatory and contractual obligation of confidentiality. In addition, the Group implements internal technical and organizational measures to secure the Personal Data of Data Subjects, which may include access limitation and physical security measures. The Group requires its employees and associated third parties, who perform tasks in its name or on its behalf, to comply with appropriate standards, including the obligation to protect all information and to take adequate measures for the use and transfer of Personal Data.

The Group regularly reviews its security policies and procedures to ensure systems are secure and protected and to ensure compliance with all applicable data protection and security laws.

Responsibility for data processing

The Group is the entity responsible for the processing of Data Subjects’ Personal Data. For any question in connection with the processing of Personal Data, a Data Subject can contact the Group at the following address:

Eric Sturdza Group S.A.

112, rue du Rhône

PC 3024

CH – 1211 Geneva 3

dataprotection@groupe-es.ch

 

If a Data Subject is not satisfied with the answer provided by the Group, he has the right to contact the Federal Data Protection and Information Commissioner (FDPIC).

The Group reserves the right to amend this Privacy Statement at any time.

May 2026