We use cookies to make its website more user-friendly, secure and effective. Cookies collect information about the use of websites. Further information: Information on data protection
This Privacy Policy provides you with an overview of the processing of your personal data and your rights under the Federal Act on Data Protection in connection with basic contracts of Baloise Bank Ltd (hereinafter also referred to as “bank” or “we”; see clause 2). We process your personal data (hereinafter referred to as “data”) or the data of other persons insofar as this is necessary for the conclusion, performance or termination of, or support related to, a basic contract.
Personal data is information that relates to an identified or identifiable natural person. Sensitive personal data is personal data that is specially protected by law due to its sensitivity (see clause 3.10). Processing means any form of handling of your data, in particular collection, storage, use, disclosure, archiving or erasure. We comply with the Federal Data Protection Act (FADP), the Data Protection Ordinance (DPO) and any other data protection laws applicable in individual cases (e.g. the European General Data Protection Regulation, GDPR).
In the following, we will show what data we collect, what we use it for and what your rights are in this regard. Independent privacy policies as well as further provisions (e.g. General Terms and Conditions, Terms of Use, declarations of consent or Product Information) apply to certain forms of data processing – for example for online applications (also referred to as “apps”) offered by the Bank, such as the TWINT app, mobile banking and e-banking, for loan and mortgage agreements, for financial and pension planning, etc. These are available on the corresponding web pages or in the corresponding apps.
We not only process data of our customers, but also data of third parties, in particular of the following persons:
When you transmit data to us via third parties, we assume that you are authorised to do so and that this data is correct. Therefore, please inform these third parties about the processing of their data by us and provide them with a copy of this Privacy Policy. If we refer you to a new version of these documents, please also hand over this new version in each case.
Our employees are regularly trained on data protection topics and are sworn to secrecy. In addition, our Data Protection Unit monitors compliance with data protection regulations.
The following company is responsible under data protection law for the data processing described here:
Baloise Bank Ltd
Amtshausplatz 4
4502 Solothurn, Switzerland
To raise your data protection concerns and exercise your rights under clause 13, you can contact our Data Protection Unit as follows:
Baloise Bank Ltd
Data protection unit
Amtshausplatz 4
4502 Solothurn, Switzerland
E-mail address: datenschutz-bank@baloise.ch
Depending on the products selected and services provided by the bank, we may process the categories of data described below, although the list provided in this document is not exhaustive.
In the event of changes to data over time (e.g. due to a change of address, a change in civil status or another modification), we will modify the data accordingly. The previous data will be stored if necessary in the context of the statutory retention periods and will then be erased.
Master data includes, in particular, contact information (e.g. name, address, telephone number and email address), personal details (e.g. date of birth, age, gender, nationality, residence permit status, data from identification documents, family details, occupation, education and training, employer), other identification data (e.g. AHV number, customer number, tax identification number), information from databases (e.g. World-Check) or information about your relationship with us (e.g. partner/customer status, customer history). Account details are also collected, including bank account details (e.g. account numbers) or credit card details.
Information on the persons affected by the data processing is also part of the master data (e.g. information on housing situation, information on relationships with third parties affected by the data processing, contact details of additional cardholders, partner’s income, etc.).
We obtain master data from you directly or from third parties, such as Group companies, custodian banks and credit reference agencies, as well as from public registers (e.g. the land register). We also receive data in connection with address changes, as we are involved in an address update network which sends us and the other companies involved in the network updated address data (e.g. the new address after a move).
Contract and product data is data that is generated in connection with the conclusion of a contract or the processing or termination of a contract. Contract data includes data from applications, contracts and information from pre-contractual relationships, for example information from consultation sessions, information about the products and services you use, information about card limits and card use, information about additional cardholders or account holders, authorised representatives and agents, credit data, as well as information about your account, securities account or contracts concluded.
Contract data also includes financial data, i.e. information on assets and their origins as well as budget details (e.g. own funds, savings, pension assets, liabilities and expenditure), information on earned income, pension income and income from investments, your creditworthiness (e.g. scoring, rating and creditworthiness data in the context of lending) and your payment history (i.e. information regarding payment demands and debt collection), as well as data regarding your securities and other financial instruments, your knowledge and your experience in investment matters, as well as investment products, risk and investment profile, investment objectives, ESG sustainability criteria or information as required in foreign jurisdictions.
Depending on the product, we also collect sensitive personal data, for example information on retirement savings accounts and planned retirement age, insofar as we need this information to process the contract.
We generally collect contract data directly from you and from third parties involved in the processing of the contract (e.g. it may be collected via other Group companies which then forward the information to us), as well as from publicly accessible registers (e.g. Land Register).
Transaction data includes payment transaction data, payment order data, data on the payer, data on the payment recipient or on the beneficiary and on the reason for payment; ATM deposit and withdrawal data, credit card numbers, as well as expiry date and card verification data; data on acceptance points (e.g. merchant name or company name); payment and transaction data, including cash withdrawal data (e.g. transaction amount, date and time of transactions, currency, etc.); transaction type data or data on incorrect PIN entries; data on investigations at acceptance points in connection with a complaint or possible card misuse; information on use of the card for online payments, for example about the IP address of the device used or information related to additional authentication; information about your use of electronic communications (e.g. opening an email or clicking on a link).
This includes data required for compliance with legal obligations incumbent on us and the related clarification and reporting in the context of combating fraud, money laundering and terrorism. We obtain such data from publicly available sources and registers (e.g. sanctions lists) or from public authorities (e.g. information on US citizens/double citizens, economic background, beneficial owners, on the origins and beneficial ownership of assets, on controllers, politically exposed persons or for matching with sanctions lists).
When you contact us via the contact form, our Customer Service or by email, telephone, e-banking messenger or chat, by letter or via other means of communication (e.g. customer portal), we collect the data exchanged between you and us (text messages as well as audio and/or video data), including your contact details and metadata relating to the communication.
We will specifically point out to you if we record communication (e.g. telephone calls, video, chats), for example for evidence or training purposes. If you do not wish to be recorded, please let us know or end your call.
If you wish to communicate via Microsoft Teams, separate Terms of Use apply. We enlist the help of the Microsoft Group for the technical provision of Microsoft Teams. This may also involve your data being transferred to countries outside of Switzerland, in particular to France, the Netherlands and the US. Microsoft undertakes to ensure appropriate data protection by means of standard contractual clauses and supplementary contractual, technical and organisational measures. Microsoft can also use the data to optimise or improve its own services (e.g. for the technical optimisation of the conference system) and to fight cybercrime and attacks. Microsoft’s Privacy Policy can be found at privacy.microsoft.com/en/privacystatement.
In addition, when communicating with you (for example when you submit a request for information), we sometimes also collect data to establish your identity (e.g. information from official identification documents, replies to security questions) in order to prevent us providing information to unauthorised third parties.
In order to provide you with the best possible service and advice on our products and services, we would like to find out your preferences and determine your requirements. To do this, we collect and use data about your interactions with us and about the preferences you tell us or that we identify.
Behavioural data is comprised of details of certain actions, such as the use of electronic means of communication (e.g. whether and when you opened an email), your use of our web pages or customer portals, the way in which you obtain products and services, your interaction with our social media profiles and your participation in prize draws, competitions and events. Preference data tells us about your requirements and which products or services might be of interest to you. We obtain this information from the analysis of existing data, such as behavioural data, so that we can tailor our consultation and our offers more precisely to you.
Technical data includes information collected when you access our websites, apps and social media channels, i.e. data transmitted to us by your browser or end device (smartphone) and automatically collected by our server. This includes IP addresses, MAC addresses of electronic devices, information about these devices (e.g. brand, type, screen, memory) and their settings (e.g. language, keyboard), cookies, functions used, date, time and duration of access, name of the files accessed and content visited, web browser, domain requested, orders placed or attempted, referring web pages and location information, client ID and version of the app installed.
We may also collect data from you in other situations. In connection with official or judicial proceedings, for instance, data accumulates (e.g. files or evidence) that may also relate to you.
We may receive or produce photographs, videos and audio recordings in which you may be identifiable (e.g. at events, by security cameras, etc.). You will either be asked for your consent or informed accordingly in advance (e.g. when opening a digital account). For security purposes, we may also collect data on who enters certain buildings at what point in time, or who has corresponding access rights (e.g. in the case of access controls or based on registration data or visitor lists, etc.), or who participates in events or campaigns (e.g. competitions) or uses our infrastructure and systems and at what point in time.
Details on video surveillance can be found in the separate Privacy Policy on video surveillance.
We obtain the data mentioned here primarily from you, but also from third parties (e.g. authorities) and in some cases also from the Group companies.
In some cases, we may collect sensitive personal data. Sensitive personal data, as defined by law, includes data on religious, ideological, political or trade union-related views or activities; data on health, private life or ethnicity; genetic data; biometric data for the unambiguous identification of a natural person; data on administrative and criminal proceedings or sanctions; and data on social security measures.
Information concerning your health may be processed for financial and tax planning, administrative and criminal convictions may be processed to clarify matters related to the Anti-Money Laundering Act, information about your religious beliefs may be processed in tax-related matters, or information about social security measures may be processed to enforce contractual obligations.
Details on financial and pension planning can be found in the separate Privacy Policy.
In some cases, we collect data directly from you, for example when you provide it to us (e.g. opening or terminating a business relationship, conclusion of a contract, consultation sessions or use of digital services).
This is data that is disclosed to us by third parties (e.g. the debt collection register, the Swiss Consumer Credit Information Office (IKO), from the Swiss Central Credit Information Bureau (ZEK), from credit bureaus, credit agencies, third-party banks, fraud prevention agencies (e.g. World-Check), pension funds or pension foundations) for the purpose of executing orders or reviewing and processing contracts or with your consent, as well as data from our contractual partners, intermediaries, Group companies or from domestic and foreign authorities, offices or courts.
This data becomes known to us as a result of your use of products or services or is transmitted via the technical infrastructure, e.g. when you visit our web pages, access our apps or through processes requiring the division of labour (e.g. in payment transactions, securities trading or cooperation with other financial or IT service providers, marketplaces or exchanges).
We also receive data in connection with address changes, as we are involved in an address update network which sends us and the other companies involved in the network updated address data (e.g. the new address after a move).
Your data will only be processed by us for the purposes we have indicated to you when collecting your data, or for which we are legally obliged or entitled to process it. For further details on the basis of our processing, please refer to clause 6.
Prior to the conclusion of a contract, we process your data in order to offer you the desired consultation and suitable products as well as to contact you in this regard.
Data is processed to provide banking and financial services. The purposes of data processing depend primarily on the specific product (e.g. account, loan, securities, deposits, payments or brokerage) and may include, but are not limited to, needs analysis, consultation, asset management and support, securities account analysis and transaction execution. Further details on the data processing purposes may also be set out in the relevant contract and product information that we will provide to you before a contract is concluded in each case.
In the course of initiating business, personal data – in particular master data, contract data and communication data – of potential customers and other contracting parties is collected or is generated in relation to communication. We also process data in connection with the conclusion of contracts in order to comply with legal requirements.
If the contractual relationship is established, we process your data to implement the contractual relationship, in particular to provide and claim contractual benefits, to manage the customer relationship, to prepare loan interest and capital certificates, as well as to communicate with you. This also includes consultation and customer support, the enforcement of legal claims arising from contracts (debt collection, court proceedings, etc.) as well as accounting or termination of contracts. In this context, we process primarily master data, contract data and communication data.
In the case of collaboration with other companies, for example within the framework of corporate partnerships or in the context of our business relationship with intermediaries (see clause 9.3), we also process master and contract data in particular for the purpose of initiating and processing contracts.
In order to comply with laws, regulatory clarification, disclosure, information, reporting and other obligations (e.g. Banking Act, Financial Services Act, Collective Investment Schemes Act, guidelines of the Swiss Bankers Association, Anti-Money Laundering Act, sanctions law, automatic exchange of information and other banking supervisory decrees and requirements), as well as court or official orders (e.g. issued by public prosecutor’s offices), we must subject your data to more detailed investigations (e.g. with regard to identity, beneficial owners of funds or shareholdings in companies) as well as an automated comparison with external watch lists. In certain cases, we may be required to report to authorities or disclose documents due to statutory requirements or court or official orders. Personal data about you may be processed in the course of internal or external investigations, for example by law enforcement or supervisory authorities or an appointed private body.
These legal obligations may arise from Swiss law, but also from foreign regulations to which we are subject. For these purposes, we process in particular your master data, contract data, claims data and communication data, but also behavioural data under certain circumstances (see clause 3.7).
Data that we require for statistical evaluations and data analyses is anonymised and aggregated and no longer allow any conclusions to be drawn about your person. The aggregated data is required for the creation of statistics (e.g. for the development of new, and adjustments to existing, products) or for topic-specific evaluations and data analyses, as well as for sales reporting. We also use data concerning all existing contracts – likewise without the possibility of drawing conclusions about you personally – to analyse the entire customer base and for the fulfilment of our contractual obligations, for example for general consultation regarding a contract adjustment or contract amendment or for the provision of comprehensive information, i.e. we perform anonymised evaluation which makes use in the individual contractual relationship possible.
We may use your data to send you advertising for our products and services as well as for our group companies and business partners, for example in the form of newsletters or other regular contacts (by email or messenger, by post, by telephone or as part of other marketing campaigns such as competitions or events). In particular, we use your communication data for this purpose.
In order to make our offers more relevant to your requirements and interests, we personalise some of our communications to allow for an individual approach. The individual approach can be made in writing or by telephone. To do this, we link data concerning you that we process – in particular master data, contract data, behavioural data, transaction data and communication data – and determine preference data as a further basis for personalisation. We can also create interest profiles about you and divide you into advertising groups (without including sensitive personal data).
In order to provide you with comprehensive advice on insurance, assets, pension and financial matters (e.g. financing, fund and other financial investments) and to make you offers for further products and services or to advertise them to you, we may process your master and contract data as well as the information disclosed on the occasion of the consultation conducted with your customer adviser.
To manage our relationships with customers and third parties, we may also invite you to our customer events and inform you about our products and services before, during or after the event.
Data can be processed for the purposes of market segment analysis. The main purpose of market segmentation is to identify differences between customers and to use this information to draw conclusions for segment-specific marketing programmes (customer structure analysis). This information is used, in particular to:
You can inform us at any time if you do not wish your data to be processed for the above purposes or if you wish to withdraw your consent in this regard (see contact address in clause 10). Likewise, you can unsubscribe from newsletters and prize draws at any time using the unsubscribe button in the message concerned.
We are committed to continuously developing our products and services to meet your needs. Therefore, we also sometimes contact you for market research purposes and use the results in anonymised form for addressing various questions within the company. To determine customer satisfaction, we can ask you about your experience with us. We also use your responses to contact you personally, to actively address your concerns and to improve our internal processes. We also collect, store and process your data for the evaluation, improvement and redevelopment of our products and services. In doing so, we analyse which products are used by which groups of people and which adjustments would be necessary in the future. The results of these analyses are – as far as possible – listed in pseudonymised or anonymised form (in accordance with privacy by design principles, we use anonymisation wherever possible in principle). For this purpose, we process the previously described master data, behavioural data, preference data and transaction data as well as communication data.
We may also process your data for other purposes, for instance, as part of our internal processes and administration. This includes training, educational and administrative purposes (such as the management of master data, accounting, data archiving and the management and ongoing improvement of the IT infrastructure), the protection of our rights (e.g. to enforce claims in and out of court and before authorities in Switzerland and abroad, or to defend ourselves against claims, such as by preserving evidence, legal clarifications and participation in judicial or official proceedings), security purposes (e.g. access controls, monitoring of buildings), statistical purposes as well as the evaluation and improvement of internal processes. In the course of preparing, carrying out or finalising mergers, acquisitions, demergers, transfers of assets or similar transactions, we may also sell businesses, parts of operations or companies to other companies, or acquire them from such companies, which may also result in the exchange and processing of data.
Where we ask for your consent for certain forms of processing, we will inform you separately about the corresponding purposes of the processing.
Where we ask for your consent for certain forms of processing, we will inform you separately, and as part of the consent process, about the relevant purposes of the processing. You can withdraw your consent at any time with effect for the future by pressing the unsubscribe button and using the contact details provided in clause 2. Once we have received notification of the withdrawal of your consent, we will no longer process your data for the purposes to which you originally consented. If consent is withdrawn, this will not affect the lawfulness of the processing carried out based on the consent previously given, up until the date of its withdrawal.
Unless we ask you for your consent to processing, we base the processing of your personal data on the fact that this is necessary for the fulfilment of our contractual obligations (e.g. to carry out pre-contractual measures for the provision of financial services), is a statutory or regulatory requirement (see clause 5.2) or is necessary in the context of weighing up interests (e.g. to ensure IT security and IT operations, or as part of business and risk management measures). Our legitimate interests also include the marketing of our products and services.
If you have signed a pension agreement with the above-mentioned foundations, Baloise Bank Ltd will process your data on behalf of the two foundations.
Data processing, inspection of files, duty of confidentiality and disclosure of data are governed by Article 85a et seqq. of the Federal Law on Occupational Retirement, Survivors’ and Disability Pension Plans (OPA). The provisions set out in the Data Protection Act (FADP) also apply. The disclosure of your data to third parties and the transmission of your data to third parties are governed by the data protection provisions set out in the OPA.
Details on this can be found in the separate Privacy Policy of the Vested Benefits Foundation and the Invest Savings 3 Pension Foundation.
For the purposes mentioned in clause 5, we may also process and evaluate your data automatically, i.e. electronically, in order to assess certain personal characteristics or behaviour (so-called profiling). This includes automated data processing, for example for combating money laundering and terrorist financing, for combating insurance fraud, for credit checks or individual risk evaluation and assessment as a necessary calculation basis for the insurance policy, as well as for identifying different interests and personal requirements for marketing purposes, product and service offers and services.
In the event that we base our decisions when concluding a contract or handling a claim exclusively on automated data processing (so-called automated individual decisions) and if such decisions cause legal effects or significant disadvantages for you (e.g. termination, risk exclusions, premium amount, denial of benefits) or if they affect you significantly in a similar way, we will inform you of this in an appropriate manner and separately inform you that you can have the relevant decision reviewed by a member of our staff if necessary. Such fully automated decisions are always based on rules we have established in advance for weighting the information.
Opening a business relationship using auto or video identification from the comfort of your own home is an alternative to visiting one of our branches. You can identify yourself online and sign the account opening documents electronically.
Video identification and electronic signature services are provided by our partners:
For regulatory and legal reasons, we are obliged to verify your identity when opening a business relationship and store certain personal data for this purpose.
The basis for this is provided by the Federal Act on the Electronic Signature (ESA) Electronic signature.
The camera on your end device will be used to take photos of your identification document and your face, and sound will be recorded via the microphone. These will be used for evidence and verification purposes by employees of Baloise Bank or Intrum. Your mobile phone number will be verified by means of an SMS sent to your mobile phone with a validation code. Your contract documents will then be transmitted by Intrum to Swisscom and digitally signed online with a legally valid electronic signature (in accordance with the Federal Law on Electronic Signatures, ESA).
As soon as identification is complete, Intrum will transmit all data to us and erase it from its servers within 90 days at most.
In the case of qualified electronic signatures, Swisscom is legally obliged (if necessary with the help of a registration authority) to retain various data on the identification process, the digital certificate and the signature process for 11 years from the last signature process.
Processing and transmission of your data: In the context of providing the possibility of instant payment, we process your transaction data in real time. This includes the following data:
This data is processed in order to forward your payments directly and securely to the recipient bank and to enable immediate crediting. The data is transmitted to partner banks or payment service providers that participate in the instant payment network.
Purposes of data processing: Your data for instant payment is processed in order to fulfil the payment service contract concluded with you in accordance with the provisions of the Data Protection Act (FADP). The transfer to external payment service providers is necessary to ensure the fast processing of the payment and is an essential part of the instant payment service.
Data transmission and security: Transaction data is transmitted via secure networks and is subject to the highest security standards to ensure the confidentiality and integrity of your data. When doing so, we ensure compliance with the legal requirements of the Swiss Data Protection Act and the Data Protection Ordinance (DPO).
Storage period: your transaction data will be stored in accordance with the statutory retention obligations and then erased, unless there are other legal requirements for longer storage.
Your rights regarding automated individual decisions: When you use instant payment, automated decisions may be made to check whether a payment is authorised or declined. These decisions are based on automated checks that take into account factors such as account coverage, fraud prevention and regulatory requirements.
In accordance with Article 21 FADP, you have the right not to be subject exclusively to an automated decision that has legal effects on you or significantly affects you. If you do not agree with a decision, you have the right to have it reviewed by one of our employees. If a payment is declined and you wish to have it reviewed by one of our employees, please contact us via the general contact channels. We will then subject the automated decision to a human review and inform you of the result.
Certain products and services are provided in processes requiring the division of labour. In certain scenarios, divisions and services are outsourced to Group companies or third parties (e.g. service providers, business partners). Risk management requires clarifications with third parties and the transmission of corresponding data. Your data may also be disclosed in the context of statutory requirements. The data recipients are bound by statutory and contractual requirements when processing your personal data. In connection with the purposes set out in clause 5 above, we may also disclose your personal data to third parties, in particular to the recipients categorised below:
For the conclusion or processing of the contract, sharing of data may also be necessary with other Group companies. If your contract was concluded by employees of other group companies, the data will be disclosed in particular for the purpose of allocating commission.
In order to provide comprehensive and efficient customer support and advisory services, and to contact you regarding the Group’s products and services, we may share your master data and contract data, as well as other information provided in the course of our customer relationship, within the Group. This includes, in particular, master data, financial data, transaction data, communication data and information on usage and payment behaviour.
Your data may also be automatically evaluated and analysed within the Group. The aim of such analyses may be to identify customer preferences, behavioural patterns or future needs, on the basis of which personalised customer profiles may be created. These profiles are used, amongst other things, to optimise customer relations, provide individual advice and furnish information tailored to individual needs, and also to enable the bank or other Group companies to develop, optimise and present bespoke offers.
Such processing may also be carried out automatically or using artificial intelligence (see clause 8).
We may make data available to the Group in anonymised and aggregated form for the purpose of preparing Group-wide statistical evaluations and data analyses (see clause 5.3).
For the purposes of comparing customer bases, customer master data may be compared for statistical purposes within the Group. The comparison analyses how many joint customers there are, how this proportion develops over time and how the joint customers are distributed geographically.
We may also share data within the Group in accordance with statutory, regulatory or internal compliance requirements (e.g. anti-money laundering checks), for the purposes of risk management and internal control, and for the purposes of carrying out statistical analyses, marketing activities as well as analyses of market segments and customer structures.
To conduct joint campaigns and for market segment analyses, customer structure analyses, market research and for product optimisation purposes (see clauses 5.4 and 5.5), we may disclose data to Group companies in order to improve our product and service offering in the process, manage the use of and desired access to the applications, products and information, maintain the business relationship with customers and monitor the performance of the offerings.
In order to achieve the Group-wide purposes mentioned in this clause, your data may also be processed in the future by the parent company in an automated manner or using artificial intelligence with the aim of evaluating certain personal aspects (see clause 8).
To ensure consistent and tailored support, the list of active bank customers is cross-referenced with the insurance company’s customer database once per day. This involves the use of identification data and contact details, as well as information regarding the customer relationship, in order to ensure that customers can be correctly identified and supported.
Additional information relevant to customer support may only be made available to the insurance unit that originally referred the customer in question to the bank. These notifications consist of selected event information, such as the occurrence of a significant cash transfer or the repayment in full of a mortgage. In the case of hybrid customers, the insurance company’s designated customer advisers may, where necessary for the performance of a specific service task, access further data relating to banking activities, in particular account information such as account balances, account movements, transaction data including payments, payees and transaction descriptions, and custody account information such as portfolio holdings and valuations. This information is used exclusively for the purposes set out in clause 17 of the General Terms and Conditions, in particular to provide personalised advice, tailored support, prepare for consultations, and also develop and present suitable offers within the Group.
Access to personal data is strictly governed by the need-to-know principle: Your data is only accessible to those departments that actually need it to perform their respective duties. Access is technically role-based and restricted to customers assigned to the relevant account manager. Each access is logged and regularly checked. Employees of the Group companies are obliged to treat your data as confidential and receive training in data protection and banking secrecy.
You can inform us at any time if you do not wish your data to be shared for the above purposes or if you wish to withdraw your consent in this regard (see contact address in clause 11).
You can request a list of the Group companies via the postal address or email address stated under clause 10 below.
We may also share your data with official bodies, courts and other government authorities and supervisory authorities (e.g. child and adult protection authorities) in Switzerland and abroad if we are legally obliged or entitled to do so or if this appears necessary to protect our interests. This includes, in particular, compliance with statutory notification obligations, the exercise of rights, the defence against claims and compliance with legal requirements, for example within the framework of official, judicial and pre- or extra-judicial proceedings as well as within the framework of statutory duties to inform and cooperate.
Within the context of our legal and regulatory obligations and based on your consent, your data will be disclosed to the Swiss Consumer Credit Information Office (IKO) or to the Swiss Central Credit Information Bureau (ZEK). Both can transmit the data to their members.
Data is also disclosed if we obtain information from public bodies, for example when checking an address.
Some of our services and business functions (e.g. in connection with the purchase of IT services) are provided on our behalf by legally independent companies in Switzerland and, in rare cases, abroad (see clause 10). They may process data about you if this is necessary for the performance of the contract. These service providers and vicarious agents work on our behalf in particular in the areas of information technology systems and software, customer service, marketing, advertising, newsletter, distribution, printing and real estate services, securities management, payment transactions, telecommunications, fraud prevention, information security, logistics, consultation, debt collection and credit risk management. They are involved in accordance with the provisions of banking and data protection law. Service providers are, for example, obliged to protect banking secrecy and to comply with our defined data processing purposes and the applicable data protection legislation. The bank verifies that data security is guaranteed by the service providers throughout the entire processing period by performing regular checks and audits. To the extent provided for by contract or law, such service providers may, in turn, engage third parties under the same terms and conditions with the prior approval of, and subject to a prior review by, the bank.
When checking your creditworthiness via credit agencies and when commissioning debt collection companies (e.g. to collect outstanding payments), we may share your data (concerning changes in payment behaviour occurring before and during the term of the contract) with the relevant companies. These companies store your personal data and may disclose it to other contracting parties as part of their activities, provided such contracting parties have presented a credible legitimate interest in individual cases for having the data transferred to them.
Your data may also be shared for the aforementioned purposes with other recipients (e.g. parties to judicial proceedings, purchasers of assets or divisions of the bank, auditing firms, Land Registry Offices and other public registers, notaries, pension funds, independent property appraisers and banks). Other persons to whom your data may be disclosed include, in particular, recipients of a payment, authorised representatives, correspondent banks, other financial institutions and other bodies involved in a legal transaction.
As part of the processing of your personal data, your data may also be transmitted abroad (e.g. in cases involving payment or securities orders), insofar as this is necessary to fulfil the business relationship, is provided for by law or you have given us your consent.
In the event that personal data is transferred abroad, we take contractual precautions, following a risk assessment, to contractually compensate for the weaker statutory protection in countries outside of Switzerland, as well as further measures (e.g. pseudonymisation) to reduce the risk of government access abroad authorised under the foreign legislation. We rely on the guarantees required by law, insofar as the recipient is not already subject to a legally recognised set of rules to ensure data protection and we cannot rely on an exceptional provision. An exception may apply in particular in the case of legal proceedings abroad, but also in cases of overriding public interest, if the fulfilment of the business relationship requires such disclosure (e.g. in cases involving payment or securities orders), if it is required by law (e.g. in cases involving reporting obligations under tax law), if you have given your consent (e.g. by using the digital account opening service) or if it is a matter of data that you have made generally accessible and you have not objected to its processing.
In accordance with the applicable data protection law and under certain conditions, you have the following rights:
You may request information as to whether we process your data and, if so, what data is being processed, and receive a copy of this personal data.
You can request that we correct incorrect data or complete incomplete data.
You can request the erasure of your data unless we are obliged or authorised to retain your data under applicable laws and regulations.
You have the right to object to the processing of your personal data at any time with future effect, provided that the processing is not strictly necessary for the performance of a contract and/or that we are not obliged or authorised to process the data under applicable laws and regulations.
Where applicable, you have the right to object to the processing of your data, in particular for the purposes of direct marketing, profiling conducted for direct marketing and other legitimate interests in the processing.
In cases where data processing is based on your consent, you have the right to withdraw this consent at any time. If you withdraw your consent this does not affect the lawfulness of the data processing undertaken on the basis of your consent up until the revocation.
You may request that the data provided by you be released or transmitted in a commonly used electronic form to another controller, provided that the processing is carried out by means of automated processing or you have consented to the processing.
You have the right to express your point of view in the case of exclusively automated individual decisions and to request that the decision be reviewed by a natural person.
You also have the right to lodge a complaint with our Data Protection Unit or the competent data protection supervisory authority if you do not agree with our handling of your rights.
Please note that these rights are subject to legal requirements and that exceptions and restrictions apply. In particular, we may need to further process and store your data in order to safeguard our own legitimate interests, such as the establishment, exercise or defence of legal claims, or to comply with legal obligations. To the extent legally permissible, in particular to protect the rights and freedoms of other data subjects and to safeguard legitimate interests, we must therefore also partially or wholly reject a data subject’s request (e.g. by redacting certain content that concerns third parties or our trade secrets). In order for us to be able to rule out fraudulent use, we must verify your identity (e.g. with a copy of your identity card, if identification is not possible in any other way). We generally retain information in connection with the processing of data subject requests for three years.
For queries and to exercise your rights, you can contact any of the companies listed below in writing or by email:
Baloise Bank Ltd
Data protection unit
Amtshausplatz 4
4502 Solothurn, Switzerland
Email: datenschutz-bank@baloise.ch
Your data will only be stored by us for as long as is required for reaching the aforementioned purposes and for as long as we are legally or contractually obligated to store it.
In individual cases, it is possible to retain personal data for longer, for example if claims are asserted against us (during the statutory limitation period) or if we are otherwise contractually, legally or officially obliged to do so, if you consent to this or if legitimate (business) interests, documentation and evidence purposes require this. As soon as your data is no longer required for the above purposes, it will be erased or anonymised as part of our standard deletion processes.
When processing personal data, we take appropriate technical and organisational measures to prevent unauthorised access and other instances of unauthorised processing. These measures are based on international standards and are regularly reviewed and adjusted if necessary.
We would like to remind you that the Internet is an open, global network that is accessible to everyone. Communication via email is not usually encrypted and takes place only during regular office hours. It is possible that data may be lost or intercepted and/or manipulated by third parties, for example, to make it appear authentic. We take technical and organisational security measures to prevent the risk within our systems. Nevertheless, the confidentiality of data transmitted by email cannot be guaranteed. This applies, in particular, to the transmission of sensitive personal data (such as health data). Emails may be delayed, deleted, misrouted or shortened during transmission due to transmission errors, technical defects or other malfunctions. External access devices (PC, smartphone, etc. of end users) and parts of the infrastructure involved in the transmission between the sender and us are located outside the security area under our control. It is the responsibility of each Internet user to find out about the necessary security precautions and to take appropriate measures (e.g. up-to-date anti-virus software, etc.). We are not liable for any damage or consequences arising from the electronic exchange of information, particularly from the misuse of the email system, for which we were not at fault. We reserve the right to seek redress from the data subject for any intentional damage it suffers as a result of business transactions with the data subject via the electronic exchange of information. We reserve the right in individual cases not to reply by email or to additionally require a different form (e.g. a form with a signature) for the order or information received by email.