- What is this Privacy Notice about?
This Privacy Notice explains how we process personal data, primarily in relation with our business, our website, and any other digital platforms we operate. If you would like more information about our data processing, please feel free to contact us (sec. 2).
“Personal data” means any information that can be related with a specific individual, and “processing” means any handling of personal data, such as collecting, using, and sharing it.
- Who is the controller for the data processing?
For each data processing activity, there is a party that is primarily responsible for ensuring compliance, the “controller”. For the processing described in this Privacy Notice, the controller (also referred to as “we”) is:
Artos FS AG (Clovepay) Freigutstrasse 6 8002 Zurich
If you have any questions regarding data protection, please feel free to contact us at the following address:
For any inquiries or concerns about your data, you can contact our compliance department at the above address.
You may provide us with data about other individuals (for example when you designate authorized representatives, beneficial owners or related persons). We assume this data is accurate and that you are authorised to share it with us. As we may not directly contact these individuals or inform them about our data processing, we ask you to do so (e.g., by referring them to this Privacy Notice).
- How do we process data in relation with our products and services?
When you use our products and services (collectively, “services”), we process data for onboarding, concluding service agreements, and their performance and management. Our services include opening and managing accounts, executing transactions, and providing financial and investment services.
We may advertise our services, such as newsletters. More details are set out in sec. 4.
If we are in contact with you in view of an agreement, we process data, for example if you submit an application or complete an onboarding form. This is mostly data you provide to us, including personal and identification details (name, date of birth, nationality, address, email, phone number, identification documents, tax ID, biometric data (where required for identity verification), and government-issued identification; financial data (payment details, payment instruments, credit history, income, origin of assets; professional information (job title, company affiliation, professional experience), communication data (emails, call recordings, messages exchanged with us, chat content, images, audio, documents and files you transmit), technical data (IP address, device type, unique device identifier, network information, browser type, operating system, time zone settings, cookies, and user activity on our website, including login details, page views, duration of access, and event logs); legal and compliance data (KYC and AML-related data as required by regulations), and service-related profile data (user ID, profile picture, gender, preferred language, personal description, and imported contacts).
In the context of our regulatory obligations, we carry out KYC (know-your-customer) and AML (anti-money laundering) checks and process the corresponding legal and compliance data. We may also obtain further data from public registers (e.g. the commercial register), regulatory authorities, financial institutions, the media and the internet. Financial institutions are required to assist in the fight against money laundering and the funding of terrorism by obtaining, verifying, and recording identifying information about all customers. We may therefore consult other sources to obtain information about you, any sender, and any recipient.
If we enter into an agreement with you, we process the data from the onboarding and information on the agreement (e.g. the date and the content of the agreement).
We process personal data during and after the agreement, including details on service purchases, transactions, payments, customer service interactions, claims, complaints, for online services access data and logins, agreement terminations, and any related disputes or proceedings. These data processing activities are necessary for agreement performance.
We also process the above data for statistical purposes. These statistics help improve and develop products and inform business strategy. We may also use this data on an identifiable basis for marketing; see sec. 4 for details.
Consent: Where required, we will ask you for explicit consent for specific processing activities, such as marketing communications or biometric data collection. We process such data for the purposes covered by the consent and typically for as long as consent is not withdrawn, or as otherwise indicated, for example in a consent form.
We collect personal data directly from you or from third-party sources such as public registers, regulatory authorities, and financial institutions. We may also verify the identity of directors, authorized persons, partners, persons with significant control, and beneficial owners by consulting credit reference agencies and other third-party sources. This verification is limited to identity confirmation and does not constitute a credit check.
For corporate partners, we process limited personal data, as data protection law applies only to individuals. However, we handle data of individuals we interact with, such as names, contact details, professional information, communication details, and information about management personnel, as part of the general data on companies we work with.
- How do we process data in relation with advertising?
We also process personal data in order to advertise our services:
Newsletter: We send out electronic information and newsletters, which may include advertising for our services. We will ask for your consent before sending out electronic marketing, except for certain offers to existing customers. Where we rely on an existing relationship, you may object to receiving further marketing communication at any time.
Market research: We process data to improve and develop new services, such as information on service usage, reactions to newsletters, customer surveys, polls, and public sources.
- Do we use AI and automated decision-making?
Yes, we may use automated systems to analyze transaction patterns, assess risks, and prevent fraud. These systems can use machine learning, a common form of artificial intelligence. However, we do not make decisions solely based on automated processing without human intervention.
- How do we disclose personal data?
We may disclose personal data to various bodies within the scope of our activities. These include the following categories of recipients:
persons associated with you, e.g. authorized representatives, beneficial owners, and relatives, and in the case of contact persons of companies, employees and the company itself;
credit agencies and providers of sanctions lists and other databases to which we may disclose the necessary information about you as part of an information request;
regulatory and public authorities, offices and courts within the scope of our legal obligations and in connection with proceedings in which we are a party or third party;
financial institutions for transaction processing;
third parties, e.g. in connection with the acquisition or sale of assets by us;
service providers, in particular for IT services, payment processing, analytics, compliance support, administration and consulting services. These service providers may process personal data to the extent necessary. Key providers include Sum & Substance Limited (SumSub), Comply Advantage Ltd, HubSpot Inc., Microsoft LLC, Amazon Web Services (AWS) Inc., Steven AB;
Banking and financial-services partners and payment networks: Visa, Mastercard, and our correspondent banking network;
For providers used for our website, see sec. 9.
- Can we disclose data abroad?
Not all data recipients are located in Switzerland. This includes certain service providers, particularly in IT. We may also share data with foreign authorities if legally required or in connection with asset sales or legal proceedings (see sec. 9). These recipients may be based in the EU or EEA, in the USA and in other countries, potentially worldwide. Not all these countries offer adequate data protection. To address this, we implement appropriate safeguards, particularly the EU standard contractual clauses adapted to Swiss law. In some cases, data may be shared abroad without such safeguards as allowed by applicable law – for instance, with your consent or if necessary to perform a contract, assert or defend legal claims, or serve overriding public interests.
- How do we process data in relation with our website?
The following applies to our website and, where applicable, to our app and other digital platforms.
For technical reasons, each time you use our website, certain data is temporarily stored in log files, including your device’s IP address, information about your internet service provider, operating system, browser, referring URL, date and time of access, and content accessed. We use this data to operate the website, ensure security and stability, optimize the site, and for statistical purposes.
Our website uses cookies – small files stored by your browser on your device. These allow us to distinguish individual visitors, usually without identifying them. Cookies may contain information about accessed content and visit duration. Some cookies (“session cookies”) are deleted when you close your browser, while others (“persistent cookies”) remain for a set period to recognize returning visitors.
You can adjust your browser settings to block certain cookies or delete cookies and other stored data. For more information, refer to your browser’s help pages (usually under “privacy”).
- Are there other processing purposes?
Yes. Typical (though not necessarily frequent) cases are as follows:
Communication: When we are in contact with you (e.g. by email, phone, or messaging), we process the content as well as information about the nature, time, and location of the communication. For your identification, we may also process information about proof of identity. Telephone conversations with us may be recorded; we will inform you of this at the beginning of each conversation. If you do not want us to record such conversations, you have the option at any time to terminate the conversation and contact us by other means (e.g. by email).
Compliance with legal requirements: We may disclose data to authorities as required by law or to meet internal regulations. This includes compliance with anti-money laundering (AML), fraud prevention, tax regulations, and financial supervisory requirements.
Prevention: Data is processed to prevent crime or misuse, such as fraud prevention or internal investigations.
Legal proceedings: If involved in legal proceedings (e.g., court or administrative), we process and disclose data about parties, witnesses, and others involved to courts, authorities, or other relevant entities, including abroad.
IT security: We process data to monitor, control, analyze, secure, and assess IT infrastructure and manage backups and archives.
Transactions: In asset, business unit, or company sales or acquisitions, we process data to prepare and execute transactions, including disclosing customer or employee data to potential buyers or sellers.
Other purposes: Data is processed for training, administration (e.g., contract management, accounting, claims management, process improvement), anonymous statistics, or securing other legitimate interests.
- How do we protect your data?
We implement appropriate technical and organizational measures to ensure the security of your personal data is commensurate with the respective risk. These include encryption, access controls, and regular security assessments. However, absolute data security cannot be guaranteed, and some residual risks may remain.
- How long do we process personal data?
We process your personal data as long as necessary for the relevant purpose (e.g., for contracts, typically the duration of the contractual relationship), as long as we have a legitimate interest in its retention (e.g., to enforce legal claims, for archiving, or IT security), or as required by statutory retention obligations. In particular:
Transaction records are retained for at least 10 years.
Marketing and communication data is retained until you withdraw consent.
Website usage data is retained according to our cookie policy.
Once these periods expire, we delete or anonymize your data. We may anonymize your personal data so that it can no longer be associated with you and use such anonymous data for legitimate business purposes.
- Anything else to consider?
Depending on the applicable law, data processing is permitted only if explicitly authorised. This restriction does not apply under the Swiss Data Protection Act but does apply under the European General Data Protection Regulation (GDPR), if applicable. In such cases, we rely on the following legal bases for processing your personal data:
Art. 6 para. 1 lit. b GDPR for processing necessary to perform a contract with the data subject or to take pre-contractual measures (see sec. 3).
Art. 6 para. 1 lit. f GDPR (and Art. 9 para. 2 lit. f GDPR for special-category data, if applicable) for processing necessary to protect our or third parties’ legitimate interests, unless overridden by the data subject’s fundamental rights and freedoms. This includes compliance with Swiss law, ensuring sustainable, user-friendly, secure, and reliable operations, and the purposes outlined in sec. 10.
Art. 6 para. 1 lit. c GDPR for processing necessary to comply with a legal obligation under the laws of an EEA Member State. The EEA includes EU member states, Iceland, Norway, and Liechtenstein.
Art. 6 para. 1 lit. a GDPR (and Art. 9 para. 2 lit. b GDPR for special-category data, if applicable) for processing based on your separate consent.
In general, you are not required to disclose data to us, except in specific cases (e.g., fulfilling contractual obligations that necessitate data disclosure). However, we may need to process data for legal or contractual purposes. The use of our website would also not be possible without some data processing (see sec. 9).
- What are your rights?
You have certain rights in relation with your personal data, subject to conditions and restrictions under applicable law:
Access: You can request a copy of your personal data and further information about our data processing.
Rectification: You can have incorrect or incomplete personal data corrected or completed or supplemented by a note of dispute.
Erasure: You can request deletion of your personal data when legally permissible.
Restriction of processing: You can request that we limit how we process your data.
Objection: You can object to our data processing, especially in relation with direct marketing.
Data portability: You have the right to receive the personal data that you have provided to us in a structured, common, and machine-readable format, insofar as the corresponding data processing is based on your consent or is necessary for the performance of the contract.
Withdrawal of consent: To the extent that we process data based on your consent, you can withdraw your consent at any time. The withdrawal is only valid for the future, and we reserve the right to continue to process data based on another basis in the event of a withdrawal.
If you wish to exercise such a right, please contact us at privacy@artosfs.com. We will usually need to verify your identity (e.g. by means of a copy of your ID card).
You are also free to file a complaint against our processing of your data with the competent supervisory authority, in Switzerland the Federal Data Protection and Information Commissioner (FDPIC; www.edoeb.admin.ch). If the GDPR applies, you also have the right to lodge a complaint with a competent European data protection supervisory authority.
Version dated 27 March 2026