Privacy Statement SDX
This Privacy Statement explains how and why SDX Web3 AG, SIX Digital Exchange AG and SDX Trading AG (hereinafter collectively “SDX”) as subsidiaries of SIX Group, process personal data.
What is the purpose of this Privacy Statement?
This Privacy Statement explains how and why SDX processes personal data. It applies to all natural persons with whom we come into contact (referred to as “you” in this document). This includes employees, officers, directors, beneficial owners and other personnel of our customers as well as service providers, authorities, and other business counterparties.
SDX aims at strong protection of natural persons in regards to processing of their personal data. Our services are offered to institutional customers only, nonetheless the processing of transactions might include personal data where this is necessary to ascertain the business purpose. In addition, we process personal data in the context of business contact information.
Who is responsible?
The legal entities listed below are the controllers of your personal data. They are responsible for processing your data.
SDX Web3 AG
SIX Digital Exchange AG
Why do we process personal data?
We process personal data about you where e.g.:
- It is necessary to enter into a contract or carry out a contract with our customer
- It is necessary to comply with our legal obligations, or
- It is in our legitimate business interests, e.g. for security compliance if you visit our office, or to protect our IT infrastructure.
We process your personal data for the following reasons:
- To undertake corporate marketing
- To enter into contract
- To provide services and products to our customers including any communication required to render them
- To ensure fair and orderly markets
- To receive customer requests and improved services/products accordingly
- To receive, investigate and respond to customer complaints
- To inform customers, suppliers and authorities about incidents and their impacts and resolution
- To manage relationships with our business partners, customers and service providers
- To carry out analyses with the intention to strengthen our relationships and improve the quality of our services and products
- For testing and support purposes
- To operate and maintain our information technology
- To establish, exercise and/or defend legal claims and rights
- To protect, exercise and enforce our rights, property or safety, or to assist our customers or others to do so
- For other purpose
What categories of personal data do we have?
Personal data processed by SDX is limited to basic contact information for individuals. In general this includes name, job title, position, work address, telephone number, email address. Other categories depend on the respective business product or service, e.g. beneficial owner identifiers in transaction reports.
Where do we get personal data from?
We collect data from the following sources:
- Personal data obtained from customers when you
– Give us contact data for relationship management, sales or any other purpose
– Send us your data on forms, e-forms, e-mail or by post
– Send us information for client on-boarding or admission
– Provide us data to enter into a contract or service level agreement including billing
– Provide us with data during the performance of our services for issue management, collection of customer experience, service improvement and other legitimate reasons
- Personal data obtained from service providers required to
– Establish and maintain a contact
– Enter into and maintain contracts, service level agreements and other types of service descriptions
– Facilitate billing and payment
– Monitor and control service delivery to ensure and enhance quality
– Collaborate on solution design and delivery
- Personal data we receive from other sources
– Background information from third party providers
– Information from authorities
– Information from publicly available sources
To whom do we disclose your personal data?
Your personal data may be disclosed to and / or transferred to
- Our business partners (e.g. custodians, correspondent banks) if your data is included in business transactions which need to be processed by them
- Your own organization in connection with issue and problem resolution, contract management, service and billing requests, requests of your compliance office, client relationship management concerns
- The Swiss National Bank (SNB)
- Competent regulatory (e.g. FINMA), prosecuting or tax authorities
- Our auditors and legal advisors involved in or contemplating legal proceedings
- Our technology suppliers that provide support for incident handling
- Other persons where disclosure is required by law
Where do we transfer your personal data to?
We may transfer your personal data to SIX Group, other subsidiaries of SIX Group, regulatory, prosecuting, tax and governmental authorities, courts and other tribunals, service providers and other business counterparties located in countries inside or outside the European Economic Area (EEA), including countries which have different data protection standards to those which apply in the EEA. When we transfer your personal data to service providers or other business counterparties in these countries, we will ensure that they protect your personal data in accordance with EEA-approved standard data transfer agreements or other appropriate safeguards.
How long to we keep personal data?
As a general rule, we keep personal data as long as we have a client relationship. After a client relationship ends, we usually must keep it for a period of 10 years. In cases where the relevant client or counterparty informs us that employment of a certain persons has ceased, the retention period starts from that point in time.
What rights do you have in relation to personal data?
You can ask us to: (i) provide you with a copy of your personal data; (ii) correct your personal data; (iii) erase your personal data; or (iv) restrict our processing of your personal data. You can also opt out of the processing of your personal data for direct marketing purposes or object to our other processing of your personal data. These rights will be limited in some situations; for example, where we are required to process your personal data by law.
To exercise these rights or if you have questions about how we process your personal data, please contact us using the contact details on the last page. You can also complain to the relevant data protection authorities where you live or work or where the alleged infringement of data protection law occurred.
Updates to this Privacy Statement
This Privacy Statement was last updated on 4 April 2021. Future updates may be required in response to changing legal, technical or business developments.
How to contact us
If you want to request further information, please contact the Data Protection Officer of SIX Group by e-mail to firstname.lastname@example.org or writing to SIX, Compliance, Hardturmstrasse 201, CH-8005 Zurich, Switzerland.