Privacy and
Data Protection Notice

Version of 18/09/2026

 

MV Invest AG (hereinafter referred to as the "Company") attaches the highest importance to the confidentiality and protection of the personal data of its clients and prospects.

This Privacy and Data Protection Notice (hereinafter referred to as the "Notice") is intended to explainhow the personal data of clients and prospects (collectively referred to as "Data Subjects") is processed bythe Company. It also outlines the rights of Data Subjects with respect to their personal data.

1.        Definitions

1.1.        Personal Data: any information relating to an identified or identifiable natural person (Article 5 lit. a of the Federal Acton Data Protection ("FADP")). A person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (such as an IP address), or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity;

1.2.        Sensitive Personal Data: Personal Data relating to religious, philosophical, political or tradeunion-related views or activities, to health, the private sphere or affiliation to a race or ethnicity, genetic data, biometric data that uniquely identifies a natural person, data relating to administrative and criminal proceedings or sanctions, as well as those relating to social assistance measures (Article 5lit. c FADP);

1.3.        Processing: Any handling of Personal Data, irrespective of the means and procedures used, in particular the collection, storage, keeping, use, modification, disclosure, archiving, deletion or destruction of data (Article 5 lit. d FADP);

1.4.        Controller: A private person who or federal body which, alone or jointly with others, determines the purpose and the means of processing Personal Data (Article 5 lit. j FADP);

1.5.        Processor: Aprivate person or federal body that processes Personal Data on behalf of the Controller (Article 5 lit. k FADP);

1.6.        Breach of Data Security: A breach of security that leads to the accidental or unlawful loss, deletion, destruction or modification or unauthorized disclosure or access to Personal Data (Article 5 lit. h FADP).

2.        Personal Data processed by the Company

2.1      Type of Personal Data

2.1.1. Personal Data of Data Subjects may include, without being limited to, the name, surname, personal address, email address, phone number, civil status, social security number, passport or identity card number, residence permit, financial information (including bank details, payment and transaction statements), information relating to investments and the relevant real estate assets, tax information, risk profile, information obtained in the course of complying with legal due diligence obligations, internally assigned identifiers such as client or investment numbers, the AVS number, as well as any professional information (such as the Data Subjects’ job title and remuneration). 

2.1.2. The Company may process Sensitive Personal Data, including data concerning legal proceedings or criminal and administrative sanctions, as well as data relating to political views or activities, and the private sphere. Sensitive Personal Data will only be processed by the Company for the purposes outlined in Section 4.1, below.

3.        Identity of the Data Controller

The Company, having its registered office at Mainaustrasse 34, 8008 Zurich, acts as Controller.

4.        Purpose of Processing

4.1.  The Company processes Personal Data in order to provide and implement wealth management and advisory services, as well as to address related inquiries and comply with its legal and regulatory obligations (hereinafter referred to as the "Services" and "Purpose of Processing").

4.2. The Company, or any duly authorized person within the Company, shall process Personal Data only in strict accordance with the Purpose of Processing.

5.        Automated Individual Decision-Making

Personal Data is not subject to automated individual decision-making and the Company does not engage in any profiling activities.

6.        Grounds for Justification for the Processing of Personal Data

The processing of Personal Data is based on the contractual relationship between the Company and Data Subjects, on the Company's overriding interest in processing the Personal Data and/or on legal requirements.

7.        Source of Collection

Personal Data is processed by the Company based on information provided directly by the Data Subjects or, when necessary, by an authorized third party; this may include, without being limited to, the Data Subjects' legal representatives, tax advisor or any other authorized agent, notaries, financial intermediaries, subscription agents, or regulatory compliance service providers (in particular in relation to identity verification or due diligence processes), as well as certain public or specialized databases.

8.        Disclosure and Subprocessing of Personal Data

8.1      Disclosure to third parties

  8.1.1   To the extent required by the Purpose of Processing or for the fulfillment of its contractual, legal or regulatory obligations, the Company may be required to disclose Personal Data, including Sensitive Personal Data, to third parties.

  8.1.2   This may include, in particular, custodian banks, competent regulatory or judicial authorities, notaries, as well as any agents of the Data Subjects, in particular their legal or tax advisors, it being specified that this latter category acts only at the request of, or with the consent of, the Data Subjects.

  8.1.3   The disclosure of Personal Data, asoutlined above, is carried out in strict compliance with the provisions of the FADP.

8.2      Subprocessing  

  8.2.1   The Company may also provide certain contractual partners, acting as Processors, access to Personal Data, including Sensitive Personal Data. These Processors contribute to the proper functioning of the Services.

  8.2.2   Disclosure of Personal Data, including Sensitive Personal Data, to Processors is carried out in full compliance with the FADP and under the conditions that (i) the processing be based on a legal basis or contract, (ii) the Company be authorized to process the Personal Data itself, and (iii) that there be no legal or contractual obligation to maintain confidentiality that prohibits the disclosure.

  8.2.3   The Company may, in particular, grant access to Personal Data to Processors providing compliance services, risk management services, IT services as well as administrative services.

  8.2.4   These Processors are based in Switzerland.

  8.2.5   Processors process Personal Data onbehalf of the Company and solely in accordance with the Company's instructions. They are contractually bound to protect the processed Personal Data in a manner consistent with the Company's own procedures and the provisions set forth in this Notice, and must provide adequate assurances to that effect.

9.        Retention of Personal Data

9.1 The Company retains Personal Data for as long as such data is necessary to fulfill the Purposes of Processing or as required by applicable law and in line with the Company's Human resources data retention policy.

9.2 The Company hosts Personal Data in Switzerland.

10.      Management of Personal Data and Notification of a Breach of Data Security

10.1 The Company implements appropriate organizational and technical measures to ensure an adequate level of security for Personal Data and to prevent any unauthorized exposure or disclosure of such data.

10.2 Any Breach of Data Security or suspected Breach of Data Security will be managed in accordance with legal requirements.

10.3 In the event of Breach of Data Security, the Company will:

(i) promptly inform the Data Subjects, to the extent necessary and technically feasible;

(ii) to the extent required by applicable law, notify the competent authorities in accordance with applicable law; and

(iii) cooperate, as necessary, with individuals and/or authorities that may need to be involved in the investigation or resolution of the Breach of Data Security, including providing reasonable assistance if such individuals and/or authorities need to notify any third party. Upon reasonable requests from these individuals, and within the limits of applicable law, the Company will promptly provide access to information related to the Breach of Data Security. Such information shall remain confidential and proprietary.

11.      Rights of Data Subjects

11.1 Subject to applicable law, the Data Subjects have the following rights:

·        Right of access to their Personal Data;

·        Right to object to the communication of their Personal Data, if they can demonstrate a legitimate and compelling reason for protection;

·        Right for the Company to refrain from processing their Personal Data unlawfully;

·        Right for the Company to erase the effects of unlawful processing of their Personal Data;

·        Right for the Company to acknowledge the unlawful nature of the processing of their Personal Data;

·        Right for the Company to remedy the consequences of unlawful processing of their Personal Data;

·        Right to update (rectify) their Personal Data, with the additional right to have the rectification published or communicated to third parties;

·        Right to the destruction of their Personal Data;

·        Right to withdraw consent, where applicable, within the limits of applicable law, provided that such withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal based on consent.

11.2 Any Data Subject may exercise their rights by contacting the Company, bymail at the following postal address: MV Invest AG, Mainaustrasse 34, 8008 Zurich, Switzerland, or at the following email address:  info@mvinvest.ch

11.3 The Company may request Data Subjects to verify their identity before responding to any request based on the rights outlined above or otherwise related to their Personal Data.

11.4 Data Subjects also retain the right to lodge a complaint with any competent authority if they believe their Personal Data is not being processed in accordance with the FADP and/or any other applicable law.

12.      Changes to the Pricacy and Data Protection Notice

The Company reserves the right to amend this Notice at any time by publishing are vised version through appropriate channels. The current version of the Notice can be accessed at the following location:

13.      Questions

Any questions relating to this Notice may be addressed to the Company, by mail at the following address: MV Invest AG, Mainaustrasse 34, 8008 Zurich, Switzerland, or at the following email address:  info@mvinvest.ch.