PostFinance Ltd, which has registered offices at Mingerstrasse 20, CH-3030 Bern (hereafter referred to as “PostFinance” or “we”), processes personal data that relates to you or to individuals with whom we have no direct contact. We use the terms “data” and “personal data” synonymously throughout this Privacy Policy.
PostFinance Ltd General Privacy Policy
Your trust is important to us. PostFinance is fully committed to handling your personal data responsibly. Our Privacy Policy contains information about the personal data that we collect from our customers and other data subjects, what we do with this data and what your rights are in this respect.
In this Privacy Policy, we describe how we process your data when you use our products or services, stay in touch with as part of a contractual relationship or communicate or interact with us in other ways.
This Privacy Policy applies to the processing of data that we have already collected or which we will collect in future. We will inform you about certain types of data processing separately, e.g. in specific privacy policies, general terms and conditions, subscriber conditions for products and services, product and service descriptions, on our website and in declarations of consent, contracts, forms and notes. A separate privacy policy containing information concerning data processing in relation to our websites can be found at postfinance.ch/dpd-web.
When you share data with us about other individuals (e.g. authorized representatives, controlling persons or heirs), you confirm that you are authorized to do so and that the data you are providing is correct. Please ensure prior to this that all third parties have been informed that we will process their data and forward them a copy of either this Privacy Policy or the document entitled “Information on data protection”, which can be found at postfinance.ch/dps.
PostFinance Ltd is generally responsible for processing data within the scope of this Privacy Policy, which means that it bears primary responsibility for this data processing under data protection law, unless otherwise specified in individual cases.
Please contact us using the following details if you have any concerns about data protection or wish to assert your rights in accordance with the “Your rights” section:
PostFinance Ltd
Data Protection Officer,
Legal
Mingerstrasse 20,
CH-3030 Bern mydata@postfinance.ch
We process different data from a range of sources, depending on the situation and purpose. We generally collect this data from you directly, i.e. when you submit information to us, communicate with us or use our products and services. However, we can also collect it from other sources, such as public registers or other publicly accessible sources, as well as from authorities or other third parties.
We process data about you from different categories, the most important of which are the following:
Master data
We use the term “master data” to refer to any information that relates to your identity, personal characteristics and circumstances, including your name, address, date of birth and factual data (e.g. market value of your property). This data can also relate to third parties (e.g. authorized agents) and can include authorizations to sign, powers of attorney and declarations of consent.
Financial and risk data
This involves processing data that relates to your income and assets, your financial situation and financial behaviour, as well as other information that we use to combat fraud and misuse and comply with legislation on money laundering, consumer credit or other statutory provisions.
Order and transaction data
This refers to the data that accumulates prior to the conclusion of a contract or in relation to individual orders and transactions, such as incoming and outgoing payments (including card payments). This also includes data pertaining to brokered products and services.
Tax data
This includes information about compliance with fiscal regulatory requirements.
Additional data relating to the contractual relationship
If you have concluded a contract with us, we will process additional data, including information on the products and services you buy and use, how contracts are performed and executed and information on feedback about our services (e.g. information on satisfaction).
Behavioural and preference data
This is information that relates to particular actions and interactions with us. We can use this information, along with other types of data, to calculate the statistical probability of you being interested in certain products and services or to predict that you will behave in a certain way (preference data). We generate this type of data based on existing information, but can also combine it with other data to improve the quality of our analyses.
Visitor and communication data
This includes information that relates to how and when we communicate with you, whether in written form, by telephone or via electronic channels (such as e-finance, chat, e-mail, SMS, push notifications or the PostFinance App). It can also include data concerning our communications with third parties, authentication data (as well as biometric data where applicable) and video and audio recordings or data related to building access. We also collect data to help identify you (such as a copy of your passport) if we want to confirm your identity or are required to do so, e.g. as part of a request for information.
Technical data
Technical data refers to the information that we collect when you use e-finance, the PostFinance App, other digital services or take part in an online survey, for example. This includes your device’s IP address, as well as the log files that we use to record information on how our systems are used. To ensure that our services function correctly, we may also assign an individual code to you, your device or your system (in the form of cookies, for example; see the “Which online tracking and analysis techniques do we use?” section). It is not possible to identify you or deduce anything about your identity based solely on technical data. However, we can link this data, as well as information collected from user accounts, registrations or access controls (or even with information about the performance of a contract) to other information and consequently to you, given the right circumstances (see the “Which online tracking and analysis techniques do we use?” section).
This refers to the information that we collect when you use e-finance, the PostFinance App or other digital services offered by PostFinance or take part in an online survey, for example. This includes your device’s IP address, as well as the log files that we use to record information on how our systems are used. To ensure that our services function correctly, we may also assign an individual code to you, your device or your system (in the form of cookies, for example; see the “Which online tracking and analysis techniques do we use?” section). It is not possible to identify you or deduce anything about your identity based solely on technical data. However, we can link this data, as well as information collected from user accounts, registrations or access controls (or even with information about the performance of a contract) to other information and consequently to you, given the right circumstances (see the “Which online tracking and analysis techniques do we use?” section).
Registration data
This refers to the data that you submit when you create a user account or register in order to use or participate in certain offers and services (e.g. newsletters and competitions). This also includes the data that we collect when you use that offer or service. Registration data, including biometric data, may also be required for access control.
Other data
We collect other data about you in various contexts. This includes information that relates to official or legal proceedings (e.g. case files, evidence, etc.). We can also collect data to help with fraud prevention or for reasons associated with occupational health and safety, and may obtain or produce photographs, videos and sound recordings in which you may be identifiable (e.g. in video recordings). We may also collect data when you enter or exit our premises, as well as information regarding your access rights (including access controls etc.). Finally, we may also collect data in connection with events or promotions (e.g. competitions) and the use of our systems and infrastructure. Sometimes we also carry out user tests and surveys, which also involve collecting data.
We process your data for the purposes outlined below.
Establishing, registering, processing, managing and terminating business relationships
We process your data to establish, register, process, manage and terminate business relationships, or to process the contract that has been entered into with you (e.g. if you are our supplier). The data that we process to this end varies depending on the type and scope of the relationship and may include master, financial, risk-related, order, transaction, registration and communication data in particular.
Compliance with laws, directives and recommendations from public authorities and internal regulations
We also process data to comply with laws, directives and recommendations from public authorities and our own internal regulations (Compliance). The data that we process for this purpose includes your master, financial, risk-related, communication, order, transaction and behavioural data in particular.
Risk management, prevention of fraud and other illegal activities, and prudent corporate management
We also process data – in particular, master, order and transaction, financial, risk-related and behavioural data – for the purposes of risk management, to assist in preventing fraud and other illegal activities, and to ensure prudent corporate management, including business organization and corporate development.
Brokering of third-party products and services
We also process personal data – in particular master, order and transaction data – to broker third-party products and services, e.g. insurance, vested benefits accounts, retirement savings accounts, personal loans and mortgages.
Marketing and customer care purposes
We process data for marketing and customer care purposes to allow us to send you, for example, personalized information, recommendations and offers regarding the products and services provided by us and third parties (e.g. cooperation partners). This information may be sent in a letter, via e-finance or as part of a newsletter, for example, or it may also come in the form of a personal consultation over the phone. We may also process your personal data in order to tailor the marketing material on our PostFinance website, so that it corresponds more closely to your interests (see the “Which online tracking and analysis techniques do we use?” section). The data that we process for the purpose of marketing and customer care includes your master, financial, risk-related, order and transaction, and behavioural and preference data, as well as other information regarding the contractual relationship.
You can object to the analysis of certain personal aspects of yourself (profiling) for marketing purposes at any time.
Market research, optimization of services and operations as well as product development and development of self-learning programmes
We also process your data for the purpose of market research, to optimize our services and operations, for product development as well as for developing self-learning programmes. This involves processing your master, transaction, behavioural and preference data, as well as information from surveys and user tests.
Security and access control purposes
We may also process your data – in particular your master, technical, behavioural and other data – for security reasons and access control purposes.
Communication
We also process the data that we collect in connection with communications with you and third parties so that we can send you information or messages, respond to your enquiries and communicate with you. We use your master and communication data in particular for this. We normally store this data on our system in order to document our communication with you, perform quality assurance and refer to it in the event of future enquiries.
Other purposes
We may process your data for other purposes as well, e.g. to aid our internal processes and administration.
If we ask for your consent to process certain data, we will notify you separately about the reasons for doing so.
We may use an automated, i.e. computer-assisted, system when processing and analyzing (including what is known as profiling) your data (see the “What data do we process?” section) for the purposes outlined in the “Why do we process your data?” section in order to obtain preference data, detect misuse and security risks, perform statistical analyses or plan our future operations, for example. We may also create profiles for these same purposes. To achieve this, we combine behavioural and preference, master, order and transaction data, as well as, amongst other things, additional information about the contractual relationship and the technical data that is attributed to you, in a way that helps us develop a better understanding of you, your individual interests and your personality. This also allows us to learn more about you, the products and services you already use, as well as those that you may wish to use in future. You may object at any time to the creation and use of profiles by PostFinance for marketing purposes.
PostFinance may use automated decision-making processes for reasons of efficiency and uniformity. We will always contact you if any of these decisions have legal implications or significantly affect you in any other way, and will take any and all measures as required by law.
We are bound to confidentiality not only by data protection law, but also by bank client confidentiality and other regulations. More information on this topic can be found in our General Terms and Conditions, for example. Our products and services are often developed, prepared and handled by different teams, including in particular those within our Group. This means that your data is processed by various parties including PostFinance, as well as individuals to whom you transfer money, other banks, and contracted service providers, for example. There are a number of specific risks associated with bank transfers and payment transactions (default, fraud, money laundering, etc.), which need to be investigated by third parties, which necessitates disclosing data to them. In this context, data may be disclosed to third parties as part of processing a transaction, as well as to other entities such as agencies, public authorities, other official bodies and banks. Data may likewise be disclosed in the context of legal provisions, i.e. when we are subject to obligations to clarify, report or provide information. The entities involved in these instances are legally permitted to process your data, but may only do so within the scope of legal and/or contractual provisions.
This section explains the main instances in which data is disclosed in connection with our products, services, contracts, and statutory obligations, for the purposes described in the “Why do we process your data?” section and to safeguard other legitimate interests. Your data will be disclosed to the following types of recipients:
Service providers
We work with service providers in Switzerland and abroad (see the “Do we disclose personal data abroad?” section).
Contractual partners, customers and involved parties
if you work for one of our contractual partners (e.g. a customer or supplier), we may transfer data about you to them. We also disclose personal data to creditors or individuals acting on your behalf (e.g. authorized persons) or who are otherwise involved in the performance of a contract.
Mobile payment
When you use a mobile payment-enabled card, data about the customer, device and mobile payment service provider is exchanged between ourselves, providers and card networks to facilitate card management, perform identity checks, prevent misuse and fraud, comply with legal requirements and process and display transactions. Furthermore, the provider’s terms and conditions may stipulate that they can acquire, process and disclose your data for other purposes.
Partners
If the contractual relationship includes bonus programmes or other third-party services, we may exchange data with these partners, provided this is necessary and you have given your consent for us to do so. If we provide you with products and services, we may pass your data on to a cooperation partner (see the “Why do we process your data?” section).
Authorities and other official bodies
We may disclose personal data to agencies, courts and other public authorities or official bodies if we are legally obliged or entitled to do so or in order to protect our legitimate interests.
Other persons
Data may also be disclosed to other recipients.
We would also like to draw your attention to the fact that sending data via different networks involves multiple internet providers. It can therefore never be ruled out that third parties could gain access to data that is sent in this way and use it without permission. Sensitive data should consequently never be sent by e-mail, SMS or other unencrypted channels. Even when such information is transmitted via encrypted channels, data such as the sender and recipient names remain public, which means that, in some circumstances, third parties can still make deductions about existing or future business relationships.
As explained in the “Who do we disclose your data to?” section, your data is processed not only by ourselves, but also by other parties where necessary. These parties are not based exclusively in Switzerland. Your data may therefore be processed worldwide, including in countries outside of the EU or the European Economic Area (third countries). We oblige our contractual partners in particular to maintain confidentiality when processing data to which we are bound by bank client confidentiality. Recipients in countries with insufficient legislation on data protection are contractually obliged to comply with data protection regulations, which is usually accomplished by inserting recognized standard contractual clauses (these can be found at The link will open in a new window eur-lex.europa.eu/legal-content). We can choose to waive this requirement if the partner is already subject to regulations designed to ensure data protection and which are recognized in Europe, or if we can make use of an exemption clause. The latter option may particularly apply to legal proceedings outside of Switzerland, in cases of overriding public interest or where the disclosure of data in this way is required to perform the contract, if you have consented to us disclosing data or in instances involving publicly accessible data made available by you that you have not objected to being processed.
Please be aware that making transactions and performing services within Switzerland or internationally (e.g. payment transactions, trading and safekeeping of custody account assets, foreign exchange or precious metal transactions, or derivative/OTC transactions) requires data about you and third parties to be disclosed to recipients located abroad. Data may also be disclosed to correspondent banks, particularly when processing payment orders. These recipients and their sub-processors might be located in different countries anywhere in the world. Under certain circumstances, they may not be subject to a legal duty of confidentiality and might be located outside our area of influence. We cannot rule out the possibility that authorities or third parties might access transferred data.
Please also note that data exchanged via the Internet is often routed through third countries. As such, your data may be sent abroad even if the sender and recipient are located in the same country.
We store your data for as long as we are required to do so in accordance with the applicable legal provisions or to fulfil the purpose of its processing. We also take into account the need to protect our own interests (e.g. to enforce or defend against claims and to ensure IT security and for documentation and evidence purposes). We delete or anonymize your data as part of our normal processes once these purposes have been achieved and our obligation or right to retain it ceases to apply. This may take more than ten years.
We take appropriate technical, organizational and legal security measures to maintain the security of your personal data, safeguard it against unauthorized or unlawful processing and protect it against the risk of loss, accidental modification, unintentional disclosure or unauthorized access.
Cookies and other technologies
Whenever you access a server online (e.g. when you use an app or website), your behaviour may be recorded using cookies and other technologies (such as software development kits, or SDKs for short, and marketing automation tools). We use technologies of this kind on our website, in e-finance and in the PostFinance App. Information on cookies and other technologies, how these are used and additional data processing in public areas on our website can be found in the privacy policy notices relating to our website, which can be accessed at postfinance.ch/dps-web. The following information relates to e-finance and the PostFinance App.
Use of technology for essential functions
These technologies enable us to distinguish your visits (or visits made using your system) from those made by other users, which is necessary in order for some functions within e-finance and the PostFinance App to work.
Personal evaluations in relation to the use of e-finance and the PostFinance App
We can analyze customers’ behaviour on a personal level by linking the device used to log into e-finance or the PostFinance App with our encrypted customer number (user ID), and thus track the behaviour of specific, identifiable users in e-finance or the PostFinance App. As a rule, therefore, it is possible to draw personal, cross-device conclusions about your behaviour, including your behaviour in the publicly accessible section of our website, after you have logged in once. This also applies to each individual third party that you allow to use your device.
The technologies outlined above allow us to conduct personal evaluations for analytical and statistical purposes, as well as for guidance regarding which content to display. One measure we take for this purpose is to employ a service provider; details about them can be found below. We also use the corresponding analytical and statistical data for our marketing measures. The information stored in our log files is also used as part of our personal evaluations of user behaviour.
Disabling data collection
For e-finance, you can configure your browser in such a way that it blocks certain cookies and other technologies or deletes existing cookies. You can likewise use browser-based software that blocks tracking. You can also opt out of data collection in the personal settings in e-finance or the PostFinance App at any time. Deactivation applies to both e-finance and the PostFinance App and takes effect from the next login.
Instructions
PostFinance App: More → My profile → Data protection settings – Edit → right arrow (menu opens) → Data usage (settings can be chosen here for web tracking, app tracking and my analytics).
E-finance: Settings and profile → My data → Data protection settings – Edit → Data usage tab (settings can be chosen here for web tracking, app tracking and my analytics).
The use of information stored in our log files as part of our personal evaluations of user behaviour cannot be deactivated.
Google Analytics
The above-mentioned service provider for the purposes mentioned above is currently Google. We use Google Analytics to generate usage reports for e-finance and the PostFinance App, which we do by authorizing Google to track the behaviour (visit duration, frequency of pages accessed, geographical origin of access, etc.) of visitors to e-finance, the PostFinance App and the publicly accessible section of our website. To do this, Google utilizes cookies (for e-finance and the website) and the tracking functions in the Firebase SDK (for the PostFinance App). Google Analytics is provided by Google LLC, and Google Ireland Ltd is responsible for compliance with data protection law. We have configured Google Analytics so that the IP addresses of visitors to e-finance, the PostFinance App and our website are truncated by Google in Europe before being transferred to the United States, thus making them impossible to trace. Furthermore, we do not send any information to Google that it can link to our customers. Google provides us with reports and evaluations based on the collected user data, and is our order processor in this sense. Google also processes this data to optimize its products and services. Information on how Google Analytics protects your data can be found at The link will open in a new window support.google.com/analytics/answer/6004245. If you object to Google Analytics being used in e-finance or the PostFinance App, please see “Disabling data collection” below.
We use Google Analytics. We use Google Analytics to generate usage reports for e-finance and the PostFinance App, which we do by authorizing Google to track the behaviour (visit duration, frequency of pages accessed, geographical origin of access, etc.) of visitors to e-finance, the PostFinance App and the publicly accessible section of our website. To do this, Google utilizes cookies (for e-finance and the website) and the tracking functions in the Firebase SDK (for the PostFinance App). Google Analytics is provided by Google LLC, and Google Ireland Ltd is responsible for compliance with data protection law. We have configured Google Analytics so that the IP addresses of visitors to e-finance, the PostFinance App and our website are truncated by Google in Europe before being transferred to the United States, thus making them impossible to trace. Furthermore, we do not send any information to Google that it can link to our customers. Google provides us with reports and evaluations based on the collected user data, and is our order processor in this sense. Google also processes this data to optimize its products and services. Information on how Google Analytics protects your data can be found at support.google.com/analytics/answer/6004245.
Under specified preconditions, you have the right to information about your personal data and its processing by us, to rectify incorrect or incomplete data and to object to our processing of your data. In certain cases, you also have the right to receive certain data in a structured, established and machine-readable format. If the processing of personal data requires your consent, you may withdraw this consent at any time. Such a withdrawal applies only with regard to future processing.
If we make a decision that affects you by means of an automated process and this results in a legal impact on you or otherwise has a significant effect on you, you have the right to speak to a person responsible for these matters at our company and to request that they reconsider the decision. If such an event occurs, we will contact you separately.
Should you wish to exercise your rights concerning us, please send us a signed letter (see the “Who is responsible for processing your data?” section) and a clearly legible copy of your identity document to allow us to identify you and to prevent misuse. You can revoke consent by other means, provided we give them as an option (e.g. under “Settings and profile” in e-finance).
We reserve the right to amend this Privacy Policy at any time. The version published at postfinance.ch/dps is the currently valid version.
Last updated: August 2024