Privacy policy
1. what is this privacy statement about?
The protection of your personal data and fair and transparent data processing are important to us. Therefore, we would like to inform you about our data processing and provide you with the information you need to exercise your rights.
For further information, please refer to the applicable product- and service-specific terms and conditions, our website
2. who are we?
The following company is responsible for data processing in accordance with this privacy policy:
Best-Finance GmbH
Bahnhofstrasse 67
5001 Aarau
Switzerland
Our data protection officer will be happy to answer any questions or concerns you may have in connection with our data protection:
Best-Finance GmbH
Bahnhofstrasse 67
5001 Aarau
Switzerland
Mr Dino Ferraro
3. when, for whom and for what is this privacy statement intended?
This privacy policy applies to all processing of personal data in connection with all our business activities in all our business areas. It applies to the processing of both existing and future personal data held by us.
4. which personal data do we process for which purposes, from which sources and on which legal basis?
When you access this website, information of a general nature is automatically collected. This information is recorded in the server log file and includes the type of web browser, the operating system used, the domain name of your internet service provider, your IP address and the like.
Comments
When visitors post comments on the site, we collect the information displayed in the comment form, as well as the visitor's IP address and user agent string (which identifies the browser) to help detect spam.
An anonymous string of characters (also called a hash) can be created from your e-mail address and transferred to Best-Finance GmbH.
The personal data we process originates on the one hand from you as an existing or future customer and on the other hand from publicly accessible sources (e.g. the media or the Internet), from group companies of Best-Finance GmbH, from government agencies (e.g. from residents' registration authorities, the land registry office, the commercial registry office or debt collection offices) and from third parties (e.g. external credit checkers, the Central Office for Credit Information [ZEK] or the Consumer Credit Information Office [IKO]).
Depending on the occasion and purpose, we process different personal data, e.g. personal details (name, address and other contact details, date and place of birth and nationality), legitimation data (e.g. identification data) and authentication data (e.g. specimen signatures, behaviour and movement patterns). In addition, this may also include order, transaction and risk management data (e.g. payment transaction data, data from the consultation and data from the processing of contractual relationships), information about your financial situation (e.g. income and assets, creditworthiness, etc.), and data from the processing of orders. (e.g. information on income and assets, creditworthiness data, scoring/rating data (see note 4b), information on the origin of assets, current or concluded credit agreements), tax-relevant information (information on tax domicile and, if applicable, other tax-relevant documents and information) and contractual and documentation data (e.g. information on the account, custody account, concluded transactions or on third parties such as life partners or proxies, minutes of consultations and minutes of meetings).
Personal data requiring special protection is data that enjoys special protection (e.g. information on ethnic origin, political opinion, religious and ideological beliefs, genetic and biometric data, health data or information on criminal convictions). They are only processed with your consent or on a legal basis.
Please note that consent to the processing of personal data that does not require special protection - should it be requested - is usually given for other reasons, depending on the individual case, e.g. to comply with the provisions on banking secrecy. Such consents do not change the fact that we do not rely on consent when processing personal data that does not require special protection, but on the legal bases mentioned below.
Among other things, we process personal data in the following situations for the following purposes and on the following legal bases. Data processing may also be based on several legal bases.
a. For the conclusion, execution and enforcement of contracts
Personal data is processed for the provision of banking transactions and financial services in the context of the conclusion, execution and enforcement of our contracts with our customers or for the performance of pre-contractual measures that take place at your request. The purposes of data processing depend primarily on the specific product and may include, among other things, account opening, maintenance and balancing, needs analyses, advice and support, and the execution of transactions. Further details on the purpose of data processing can be found in the respective contract documents, terms and conditions and, if applicable, other documents made available to you.
b. Within the framework of a balancing of interests
In addition, we also process your data to protect our legitimate interests, insofar as your interests do not outweigh these. The following is a non-exhaustive list of processing purposes that constitute a legitimate interest:
- Analysis, monitoring and management of credit risk (scoring).
- Fraud Prevention.
- Advertising measures, market research, marketing evaluations, preparation and offering of tailor-made services (e.g. direct marketing, print and online advertising, customer, prospect or cultural events, sponsoring, competitions, determination of customer satisfaction, survey of future customer needs or behaviour or assessment of a customer, market or product potential) for our own offers as well as for offers of group companies of Best-Finance GmbH and cooperation partners and delivery of these offers to your postal, e-mail or telephone address (e.g. via SMS, Whatsapp). Best-Finance GmbH and cooperation partners as well as the delivery of these offers to your postal, e-mail or telephone address (e.g. via SMS, Whatsapp), in the eService or in a mobile app, insofar as you have not objected to the use of your data and make use of the corresponding services.
- Processing of data for loyalty and value-added programs of cooperation partners as well as the forwarding of selected data required for the operation and improvement of the loyalty and value-added programs. This may include customer, status, control and card data of customers as well as cumulative sales figures at individual or all merchants. Transaction details are not disclosed. Further information on the loyalty and value-added programmes can be found in the terms and conditions of the respective products. The cooperation partners use this data under their own responsibility and in accordance with their own data protection regulations.
- Visiting websites; using our eServices: When you visit our website or install and use a mobile app from us, depending on the offer and functionality, we process information such as log data, for websites, for example, information about the time of access to our website, the duration of the visit and the pages accessed. We use this data for reasons of IT security, but also to improve the user-friendliness of the website and its functions and to personalise the offer. For these purposes, we also use analysis services such as Google Analytics. This involves collecting detailed information about the use of the website in question. For these purposes, we may use technologies such as "cookies" and similar technologies. Cookies are small files that are stored on your terminal device when you visit our website. Further information can be found on our website and in the product-specific contract and, where applicable, data protection provisions.
- Safeguarding rights, e.g. to enforce claims in court, before or out of court and before authorities in Switzerland and abroad, or to defend ourselves against claims. In doing so, we may have the prospects of litigation clarified by third parties or submit documents to an authority. It may also be that authorities request us to disclose documents that contain personal data.
- Ensuring IT security and IT operations of Best-Finance GmbH.
- Prevention and detection of crime.
- Contact inquiries on your part with our customer service.
- Telephone calls can be recorded for quality control and training purposes, for example.
- Measures for building and facility security (e.g. access controls and video surveillance).
- Corporate Transactions: We may also process Personal Data to prepare and process corporate acquisitions and sales and purchases or sales of assets, such as accounts receivable or real estate and similar transactions
- Corporate Transactions: We may also process Personal Data to prepare and process corporate acquisitions and sales and purchases or sales of assets, such as accounts receivable or real estate and similar transactions
- Evaluation, planning, statistics, product development and business decisions (e.g. improvement and review of existing products, new products and services, processes, technologies, systems, returns, utilisation rates).
5. do you have a duty to provide personal data?
As a rule, you are not obliged to provide us with personal data. However, we will not be able to enter into a contract with you if you do not provide us with the personal data required for a business relationship and the fulfilment of contractual obligations or which we are required to collect by law (this applies, for example, to information required for identification purposes such as name, place of birth, date of birth, nationality, address and identification data).
6. to whom do we pass on your personal data?
Where we send your data
Visitor comments could be examined by an automated spam detection service.
Within Best-Finance GmbH, those departments, employees and other bodies that need to access your personal data in order to perform their duties will be given access to it. We may also outsource individual or entire business areas and services to group companies of Best-Finance GmbH and to third parties in Switzerland and abroad, assign claims and rights and enter into cooperation agreements with partners. In doing so, your personal data will be forwarded to these recipients - insofar as this is necessary. We ensure through the selection of the order processors and through suitable contractual agreements that data protection and banking secrecy are also maintained by third parties during the processing of personal data.
In particular, this involves services and cooperation in the following areas:
- IT services, e.g. services in the areas of data storage (hosting), cloud services, dispatch of advertising materials, data analysis, etc.
- Creditworthiness checks
- Fighting fraud
- Transaction Authorization
- Business information and debt collection, e.g. if due receivables are not paid
- consultancy services, e.g. services provided by tax advisers, lawyers, management consultants, recruitment and placement consultants
- Administration of contractual relationships including collection, e.g. application and contract processing, invoicing and processing of the direct debit procedure, collection of due receivables
- Document and map creation
- Compliance and data management
- Cooperation with partners
- Cooperation with insurance partners
- Cooperation with intermediaries
We may also disclose your personal data for business purposes (e.g. credit risk, anti-fraud and marketing purposes) to recipients within Best Finance Ltd for their own purposes. As a result, your personal data may also be processed and linked together with personal data originating from a group company of Best Finance GmbH for the respective purposes.
If you send us a request for a loan as part of our PostFinance personal loan offer (with or without credit insurance), we will collect data from you. This includes certain personal master data (title, surname, first name, date of birth) and contact details (e-mail address, address and mobile number) of you and possibly also of your spouse or registered partner ("partner") as well as other data relevant to the granting of credit (e.g. copy of ID, employer, contact person at the employer, monthly income, salary statements, bank statements, existing loans and debt collection, existence of a guardianship). We require this data in order to create your customer account, to contact you if necessary, to carry out the legally required credit check and to prepare the contract and process it properly.
If a credit agreement is concluded, we may send you invoices and payment reminders by SMS, e-mail or post.
The disclosure of personal data in other cases is possible. We may disclose your personal data to third parties if it is in our legitimate interest or if you have authorised us to do so, and we are even obliged to do so if this is required by law (usually to the authorities).
7. when do we pass on personal data abroad?
We may outsource our services abroad (see previous section). Personal data may also be transferred abroad when executing contracts or transactions, e.g. when executing payment orders or processing payments. The recipients of your personal data may also be located abroad - including outside the European Union (EU) or the European Economic Area (EEA, which includes, for example, the Principality of Liechtenstein). These countries may not have laws that protect your personal data to the same extent as in Switzerland or the EU or EEA. If we transfer your personal data to such a third country, we will ensure the protection of your personal data in an appropriate manner. One means of doing this is by entering into data transfer agreements with the recipients of your personal data in third countries that ensure the required level of data protection. These include contracts that have been approved, issued or recognised by the European Commission and the Federal Data Protection and Information Commissioner (FDPIC), so-called standard contractual clauses. Likewise, transfers to recipients who have joined the Swiss-U.S. Privacy Shield program, i.e., who have committed themselves to maintaining high data protection standards, are permitted.
Employer: Only in the event of justified doubts regarding the authenticity of submitted salary statements/receipts will we verify this information with the employer. Verification is carried out via the employer you have specified using the telephone number provided. The salary stated and the status of the employment relationship will be checked. The employer will not be informed about our benefits, their scope or any other information about you. The data from the verification is used directly in the credit check to decide whether we can offer you a loan.
Disclosure in connection with financial transactions: If we are involved in a business combination (merger), a joint venture, an acquisition or sale of company shares or assets, we may pass on your data to any transaction partner who also complies with the applicable legal bases, in particular with regard to your rights under data protection law.
8. does profiling take place and do we make automated decisions?
We may process your data to create profiles, e.g. for analysis, evaluation and decision-making. Such processing is used by us and our group companies in particular for fraud prevention and risk management purposes. We also use profiles so that we can provide you with individual advice and personalised offers. You can object to the processing of your data for advertising purposes at any time (see section 11).
If we make automated individual decisions, they are generally necessary for the conclusion or fulfilment of a contractual relationship or are based on your express, separate consent. We will inform you in each case about such decisions if this is required by law.
9. how do we protect your personal data?
We use appropriate technical and organisational security procedures to maintain the security of your personal data, for example to protect it against unauthorised or unlawful processing and against the risk of loss, and to prevent accidental alteration, disclosure or access.
10. how long do we store your personal data?
How long we store your data
When you post a comment, it is saved indefinitely, including metadata. This way, we can automatically detect and approve follow-up comments instead of holding them in a moderation queue.
For users who register on our website, we additionally store the personal information they provide in their user profiles. All users can view, change or delete their personal information at any time (the username cannot be changed). Administrators of the website can also view and change this information.
We store your personal data as long as it is necessary for the purpose for which we collected it. We also store your personal data for longer if we are subject to a statutory retention obligation. For example, a ten-year retention period applies to most documents. We also store personal data if we have a legitimate interest in storing it, e.g. if limitation periods are running, if we need personal data to enforce or defend claims, as well as for archiving purposes and to ensure IT security.
11. what rights do you have?
If you have an account on this website or have posted comments, you may request an export of your personal data from us, including any data you have provided to us. In addition, you can request the deletion of all personal data that we have stored about you. This does not include data that we are required to retain for administrative, legal or security needs.
Every data subject has certain rights under the data protection law applicable to them, in particular the following rights:
- the right to information
- the right of rectification
- the right to erasure
- the right to restrict processing
- the right to object to the further processing of their personal data and the right to the transfer of certain personal data.
In addition, there is a right of appeal to a competent data protection supervisory authority, in Switzerland to the Federal Data Protection and Information Commissioner (FDPIC).
You can revoke your consent to the processing of personal data at any time. Please note that a revocation is only effective for the future. Processing that took place before the revocation is not affected by this. Consent obtained for other reasons, e.g. on the basis of the provisions on bank client confidentiality in accordance with the Federal Law on Banks and Savings Banks (BankG), will not be affected by this.
Consents obtained for other reasons, e.g. on the basis of the provisions on bank client confidentiality pursuant to the Federal Law on Banks and Savings Banks (BankG), are not affected by this.
You can also object to the further processing of your personal data for the purposes of direct advertising at any time by notifying us.
13. direct advertising
If you give us your consent to do so, we will use your e-mail address and certain demographic data (age, gender, postcode, language) and your contract master data to send you attractive offers and relevant information about our products and/or (depending on the consent you have given) about the products of our cooperation partners.
12. changes to this privacy policy
We may amend this privacy policy at any time without prior notice. The current version published on our website applies.
In the event of any ambiguity, the German wording of this privacy policy shall prevail.
Status: October 2018