Privacy Policy

Switzerland

It is important that you know exactly what we do with the personal information you and others make available to us, why we collect it, and what it means for you. This document outlines the approach to Data Privacy SeifMoney is taking to fulfill its obligations under the the Swiss Federal Data Protection Act (FADP, revised as of 1 September 2023). Being transparent and providing accessible information to individuals about how we will use their personal data is a key element of our organization.

The collection and use of data from a variety of sources are essential to our ability to provide our payment Services in a safe manner and are helping us to reduce the risk of fraud and money laundering. If you disagree with the practices described in this privacy policy, you should take the necessary steps to remove cookies from your computer/device after leaving our website(s) and not continue to use our Services.

What Personal Data signifies?

“Personal Data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified directly or indirectly, by reference to an identifier such name, an identification number, location, data, or other information that help/lead to identify that natural person.

“Special categories of personal data” means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, health data, sexual orientation, trade union membership, genetic data and biometric data.

“Swiss Data Protection Law” means the Federal Act on Data Protection (FADP, Switzerland).

“Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

“Data Protection Impact Assessment” means the process meant to describe the processing, to evaluate the necessity of performing the processing and the proportionality of such processing and to contribute to the risk management regarding the rights and freedoms of data subjects, by evaluating them and establishing the risk mitigating measures.

“Personal Data Breach” means a breach of security leading to the accidental and unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Controller” means the natural or legal person, public authority, agency or other body which alone or jointly with others, determines the purposes and means of the processing of personal data.

“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

“Data Protection Officer or DPO” means the person designated by the Controller to overlook the Personal Data Processing, especially where the core activities of the controller or the person empowered by the Controller consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale or the core activities of the controller consist of processing on a large scale of special categories of data and personal data relating to criminal convictions and offences/felonies.

Who is the Data Controller?

For personal data processed under this privacy policy, the data controller is:

M WAY AG, Hinterbergstrasse 53, 6312 Steinhausen, Switzerland

The personal data we would like to collect from you is:

First Name and Surname (with title);

Date of birth;

Email;

Proof of address documents;

ID Documents;

Other personal information such as telephone recordings; security questions, user ID;

Address;

Gender;

Bank Account details;

Telephone number;

Transactional information; and

CCTV footage where you visit SeifMoney offices.

Our legal basis for processing the personal data:

receipt of your consent;

performance of a contract where you are a party;

legal obligations that SeifMoney is required to meet;

national law.

Any legitimate interests pursued by us, or third parties we use, are as follows:

the prevention of fraud, money laundering, counter-terrorist financing, or misuse of services.

Governing Law and Jurisdiction:

This privacy policy shall be governed by and interpreted in accordance with the laws of Switzerland. In case a dispute has arisen between you and us concerning this Privacy Policy and /or the Payment Services, the parties agree that the dispute, controversy or request arising as a result or in relation to this Privacy Policy will be conducted exclusively by the competent courts in Zurich, Switzerland.

Notice

We may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data: public interest; legal obligation (mandatory for compliance with a legal or regulatory obligation); performance of a contract to which you are a party or to take steps at your prior to entering a contract) and our legitimate interest.

Consent

By using our services, you are consenting to this privacy policy and you are giving us permission to process your personal data specifically for the purposes identified above. Consent is required for SeifMoney to process personal data, but it must be explicitly given. Where we are asking you for sensitive personal data, we will always tell you why and how the information will be used.

Consent for Underaged

SeifMoney services are not available for anyone under the age of 18 years. In any case, please be aware that children need specific protection about their personal data, as they may be less aware of the risks, consequences and safeguards concerned, and of their rights in relation to the processing of personal data for the purposes of using these services.

Withdrawal of Consent Conditions

You may withdraw consent from direct marketing at any time by contacting us via support@seifmoney.ch or sending a letter through the postal service to our office. Please note, where you have consented to your data being used for carrying out financial transactions, then the right to withdraw consent does not exist. As a payment services are being provided through us, SeifMoney is obliged to retain data concerning financial transactions for 10 years in accordance with the laws of Switzerland for the purpose of keeping financial records, and of preventing, detecting, and investigating, possible money laundering or terrorist financing. In any case, a withdrawal of consent for information processing required in the process of carrying out our services will cause immediate termination of service.

Cross-Border Data Transfers & Third-Party Disclosures

In limited situations where SeifMoney stores or transfers personal information outside Switzerland, robust procedures and safeguarding measures apply to secure, encrypt and maintain the integrity of the data. SeifMoney will complete continual reviews of any third parties with sufficient adequacy decisions, such as the GDPR (EU), FADP (Switzerland), UK GDPR, and provisions for binding corporate rules, standard data protection clauses, or approved codes of conduct.  SeifMoney will further perform due diligence checks with all recipients of personal data to assess and verify that they have appropriate safeguards in place to protect the information. The data subject has enforceable rights and effective legal remedies;

SeifMoney shall comply with its obligations under the data protection legislation by providing adequate protection to any personal data that is transferred (or, if it is not so bound, uses its best endeavors to assist the customer in meeting its obligations).

SeifMoney complies with any reasonable instructions notified to it in advance with respect to the processing of personal data; and

Upon written direction shall delete or return personal data (and any copies of it) unless SeifMoney is required by Law to retain the personal data.

Where SeifMoney is required to transfer personal data to the United States of America, SeifMoney shall only send such personal data to third-party sub-contractors that meet the minimum requirements contained under Swiss-U.S. Data Privacy Framework, or in the standard contractual clauses approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC).

These measures may include reviewing third parties’ privacy and security standards, verifying if they have certified their compliance with the Swiss-U.S. Data Privacy Framework.

Retention Period

Under the current Switzerland anti-money laundering regulatory framework, SeifMoney will process personal data for the duration of the contract for services and will store the personal data for ten (10) years. Such a period may be prolonged in accordance with Switzerland anti-money laundering obligations. When we no longer need to retain your personal data, it will be deleted or anonymized.

We will retain personal data for the period necessary to fulfill the purposes outlined in this privacy policy unless a longer retention period is required or permitted by law. Please note that we have a variety of obligations to retain the data that you provide to us, including to ensure that transactions can be appropriately processed, settled, refunded, or charged back, to help identify fraud, and to comply with anti-money laundering and other laws and rules that apply to us and to our financial service providers.

Your Rights as a Data Subject

At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights under FADP and GDPR:

  • Right to be informed
  • Right of access
  • Right to rectification
  • Right to erasure / right to be forgotten (subject to AML obligations)
  • Right to object to direct marketing, including profiling
  • Right to withdraw consent at any time for processing based on consent
  • Right to object to processing based on legitimate interests
  • Right not to be subject to a decision based solely on automated decision-making
  • Right to lodge a complaint with a supervisory authority (see below)
  • Right to data portability
  • Right to restriction

Changes to this privacy policy

We may amend this privacy policy from time to time. Any changes we may make to our privacy policy in the future will be posted on our website and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to our privacy policy.

Complaints

In the event that you wish to lodge a complaint with the respect to the mechanism for processing Personal Data by the Controller, when you consider your personal rights with the respect to Personal Data are infringed, you have the right to lodge a complaint directly to SeifMoney, by email. If you are not satisfied with your complaint handling by SeifMoney, the complaint shall be filled with the Swiss Federal Data Protection and Information Commissioner (FDPIC) by email at info@edoeb.admin.ch or by visiting https://www.edoeb.admin.ch.