Privacy policy

FIDEXAUDIT SA

FIDEXAUDIT RÉVISION SA

PRIVACY POLICY

Last updated: October 2025

This privacy policy (hereinafter: the “Policy“) aims to inform you about how Fidexaudit SA, a Swiss public limited company, registered under number CHE-107.516.529, with its registered office at Chemin de Mornex 2, 1003 Lausanne, and its branches, Fidexaudit SA, CHE-202.823.077, located at Rue des Vignerons 1B, 1110 Morges, and Fidexaudit SA, CHE-209.138.775, located at Rue des Deux-Marchés 23, 1800 Vevey, as well as Fidexaudit révision SA, a Swiss public limited company, registered under number CHE-102.868.553, with its registered office at Chemin de Mornex 2, 1003 Lausanne (hereinafter: the “Companies“, the “Company“, “we“, “us”, “our“), Process your Personal Data and the rights to which you are entitled in accordance with the Swiss Federal Act on Data Protection (hereinafter: the “FADP”) and, where applicable, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: “GDPR“).

This Policy provides general information applicable in most situations and may be supplemented by more specific policies or regulations, where applicable. The purpose of this Policy is to clarify the procedures applicable to the Processing of your Personal Data that we use to provide and improve our Site and Services. It explains what Personal Data we Collect and Process, how we use it, and for what purposes.

We recognise that the Processing of your Personal Data requires a high level of trust on your part. We take this trust very seriously and make it our priority to ensure the utmost confidentiality and security of your Personal Data.

1. DÉFINITIONS

Client

Any individual or legal entity using the Services offered by the Companies, whether for audit mandates with Fidexaudit révision SA or for all other Services with Fidexaudit SA.

Communication

The act of making Personal Data accessible, for example by authorising its consultation, transmitting it to a third party or authority, or disseminating it via the Website

Consent

An active, free, specific, informed and unambiguous expression of will by which a Data Subject gives their consent to the Processing of Personal Data concerning them.

Cookies

Cookies are data that are automatically placed on the Visitor’s terminal by the Visitor’s web browser when they access the Website. Cookies can be recalled by a web server in the domain that placed the Cookie. Cookies identify the Visitor’s browser to the web server. Cookies also enable information to be stored on the web server (e.g. language preferences, technical information, click or access path information, etc.) in order to improve the Website experience and to analyse the Website and evaluate its performance.

Personal Data

Any information relating to an identified or identifiable person. This includes identifiers such as names, audiovisual media, identification numbers, location data or online identifiers; it may also include specific elements relating to the physical, physiological, genetic, psychological, economic, cultural or social identity of the data subject. Sensitive personal data includes data on religious opinions or activities, health data, data on private life or racial or ethnic origin, genetic data, biometric data uniquely identifying a natural person, data on criminal and administrative proceedings and sanctions, and data on social assistance measures.

Data Subject

The natural person whose Personal Data is being Processed.

Services

means the Services provided by the Companies to Customers.

Data Controller

The person who determines the purposes and means of the Processing of Personal Data. Within the framework of this Policy, the Data Controllers are the Companies, namely Fidexaudit SA with its Branches, and Fidexaudit révision SA. Within the framework of this Policy, the Data Controllers are jointly referred to as the Company.

Service(s)

means the fiduciary, audit, taxation and advisory services provided to Clients by the Companies.

Website

means the Companies’ Internet Site available at the URL address https://www.fidexaudit.ch/.

Company(ies)

means Fidexaudit SA, CHE-107.516.529, and Fidexaudit révision SA, CHE-102.969.553, with registered offices at Chemin de Mornex 2, 1003 Lausanne. The two companies are related companies.

Branches

refers to the two branches of Fidexaudit SA, registered under numbers CHE-209.138.775 and 202.823.077, located in Vevey (Rue des DeuxMarchés 23, 1800 Vevey) and Morges (Rue des Vignerons 18, 1110 Morges).

Processing (or Process)

Any operation relating to Personal Data – regardless of the means and processes used – including the collection, storage, exploitation, modification, backup, use, communication, archiving, storage or destruction of data. Please note that the verb “process” refers to any of the above operations and is used in this Policy in a generic sense.

Visitor

Any natural person browsing the Site made available by the Companies.

2. DATA CONTROLLER AND CONTACT

Fidexaudit SA, its branches and Fidexaudit révision SA are affiliated companies.

For audit and review mandates, Fidexaudit révision SA is the Data Controller for the personal data of the Data Subjects.

For all other mandates, Fidexaudit SA is the Data Controller for the personal data of the data subjects.

In the absence of specific details, the Data Controller for Personal Data is Fidexaudit SA.

Requests and the exercise of rights relating to the protection of a data subject’s personal data may be sent to us by post or email, accompanied by a copy of the identity card or passport enabling the data subject to be identified.

Although Fidexaudit SA generally acts as the Data Controller, depending on the nature of the processing, the purpose pursued and the degree of autonomy it has in determining the purposes and means of Personal Data Processing, it may act as a data processor on behalf of its Clients.

This is particularly the case when it manages and administers the salaries of its clients’ employees or when it provides services related to its clients’ ordinary taxation. In these situations, it processes personal data exclusively on the instructions of its clients and strictly within the scope of the purposes related to the service to be provided. In this respect, it acts as a processor for the processing of this personal data. Where applicable, such Processing is governed by the mandate agreement concluded between the parties.

3. PRINCIPLES OF PERSONAL DATA PROCESSING

When Processing Personal Data, the Company undertakes to comply with the general principles of Personal Data protection, in particular the following principles:

a. Fairness and lawfulness

When Processing Personal Data, the individual rights of Data Subjects will be protected by the Company. Personal Data will be collected and Processed lawfully, fairly, in good faith and in a manner proportionate to the purpose pursued.

b. Limitation to a specific purpose

Personal Data processed by the Company must be adequate and relevant to the purpose for which it is processed. This means ensuring that the Personal Data collected is not excessive in relation to the purpose for which it is collected. Subsequent changes to the purpose of the processing are only possible to a limited extent and must be justified.

c. Transparency

The Data Subject is informed of how their Personal Data is Processed by the Company. When Personal Data is collected, the Data Subject must be informed

  • of the existence of this Policy;
  • the identity of the Data Controller(s);
  • the purpose of the collection and Processing of Personal Data;
  • how the Personal Data is processed, where it is processed and who processes it; and
  • the third parties to whom the Personal Data may be disclosed.

d. Accuracy

Personal Data processed must be accurate and, where necessary, kept up to date. Inaccurate or incomplete Personal Data must not be kept and must be deleted.

e. Data minimisation

Personal Data Processed shall be adequate, relevant, and necessary in relation to the purposes for which it is collected and Processed.

f. Storage limitation

Personal Data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the Personal Data are processed.

4. COLLECTION AND PROCESSING OF PERSONAL DATA

We Process various types of Personal Data, including:

  • Personal Data of Customers to whom we provide or have provided Services;
  • Personal Data that we have received indirectly from our Customers in the course of providing Services;
  • Personal data collected when visiting our Website;
  • Personal data collected when using our newsletter;
  • Personal data collected when participating in one of our events:
  • Personal data collected in the context of the relationship with the Customer, in particular in the event of communication and/or face-to-face meetings;
  • Personal data collected in other contractual relationships, e.g. as a supplier, service provider or consultant;
  • Personal data received in the context of recruiting our teams;
  • Personal data collected for legal or regulatory reasons;
  • Personal data collected when we exercise our duty of care or defend other legitimate interests, e.g. to avoid conflicts of interest, prevent money laundering or other risks, ensure data accuracy, verify creditworthiness, ensure security or assert our rights.

You will find more detailed information in the description of the relevant processing category in section 5 of this Policy.

5. CATEGORIES OF PERSONAL DATA

The Personal Data we Process depends on the nature of your interaction with us and the purpose of Processing such Personal Data.

In addition to your contact details, we may also process other Personal Data belonging to you or to persons related to you. Depending on the circumstances, this may include sensitive Personal Data.

We collect the following categories of Personal Data depending on the purpose for which it will be Processed by us:

  • Contact details (e.g. surname, first name, address, telephone number, email address);
  • Customer information (e.g. date of birth, nationality, marital status, occupation, title, job description, passport or identity card number, social security number)
  • Risk management data (e.g. creditworthiness information, commercial register data);
  • Financial information (e.g. bank details);
  • Mandate data, depending on the mandate (e.g. tax information, articles of association, minutes, contracts, employee data (e.g. salary, social insurance), accounting data, beneficial owner, ownership reports);
  • Website data (e.g. device information (UDI), browser information, website usage (analysis and use of plugins, etc.)
  • Application data (e.g. CV, employment certificates);
  • Marketing information (e.g. newsletter subscription);
  • Security and network data (e.g. visitor lists, access controls, network and email scanners, telephone call lists).

Where permitted, we also collect certain personal data from publicly available sources (e.g. debt collection registers, land registers, press, internet) or receive it from our clients and their employees, authorities, (arbitration) courts and other third parties.

In addition to the Personal Data you provide to us directly, the categories of Personal Data we receive from third parties about you include, but are not limited to:

  • Personal Data from public records;
  • Personal Data that we become aware of in the course of administrative and judicial proceedings;
  • Personal Data related to your professional duties and activities (so that, with your help, we can, for example, conclude and process business with your employer);
  • Personal Data about you in correspondence and discussions with third parties;
  • creditworthiness information;
  • information about you provided to us by people in your circle (family, advisor, legal representative, etc.) so that we can conclude or process contracts with you or through you (e.g. references, your delivery address, powers of attorney);
  • Personal Data relating to compliance with legal requirements such as anti-money laundering and export restrictions, data from banks, insurance companies, distribution partners and other contractual partners of our organisation for the purpose of using or providing services on your behalf (e.g. payments made, purchases made);
  • Personal Data about you from the media and the internet (if specified in a specific case, e.g. in connection with an application, etc.);
  • your addresses and, where applicable, interests and other socio-demographic data (for marketing purposes);
  • data relating to the use of the Website (e.g. MAC address of your smartphone or computer, data about your device and settings, cookies, date and time of your visit to the Website, pages and content viewed, functions used, referring websites, location data).

6. PURPOSES OF PERSONAL DATA PROCESSING AND LEGAL BASIS

6.1. PROVISION OF SERVICES

We primarily process personal data that we receive from our clients and other business partners in the context of our contractual relationships with them and other persons involved.

Our clients’ personal data includes the following:

  • Contact details of the Client and/or its bodies and/or employees in contact with us (e.g. surname, first name, address, telephone number, e-mail address, other contact details);
  • Personal information of data subjects (e.g. date of birth, nationality, marital status, profession, title, job description, passport or identity card number, social security number, family situation, etc.);
  • Risk management data (e.g. information relating to creditworthiness, commercial register data, sanctions lists, specialised databases, data from the internet);
  • Financial information (e.g. bank details, investments or shareholdings);
  • Mandate data, depending on the mandate, e.g. tax information, articles of association, minutes, employee data (e.g. salary, social insurance), accounting data, etc.;
  • Sensitive personal data when we provide services in the areas of payroll processing or accounting.

We process this personal data for the purposes described, based on the following legal grounds:

  • According to our Clients’ instructions, as a processor of Personal Data and in order to perform the Services described in the mandate agreement;
  • Conclusion or performance of a contract with or for the benefit of the data subject, including the preparation of the contract and its possible execution (e.g. consulting, fiduciary);
  • Compliance with a legal obligation (e.g. when we fulfil our obligations as an auditor or when we are required to publish information);
  • Preservation of legitimate interests (e.g. for administrative purposes, to improve our quality, ensure security, carry out risk management, assert our rights, defend ourselves against claims or examine potential conflicts of interest);
  • Consent (e.g. to process sensitive Personal Data, to send you marketing information).

6.2. INDIRECT PROCESSING OF PERSONAL DATA ARISING FROM THE PROVISION OF SERVICES

When we provide Services to our Clients, we may also Process Personal Data of third parties or Personal Data that we have not collected directly from the Data Subjects. These third parties may be contact persons, family members of Clients or persons who are related to Clients or Data Subjects for other reasons. We need this Personal Data in order to perform contracts with our Clients.

This Personal Data is provided to us by our Clients or by third parties they have appointed. Our Clients are responsible for informing Data Subjects whose Personal Data is Processed by us that they are sharing their Personal Data with us and for obtaining their explicit Consent for the Processing of sensitive Personal Data. To this end, our Clients may refer to this Policy.

As Data Controller, we remain responsible for informing Data Subjects of the categories of Personal Data processed, within one month of collection and before any communication to a third party, subject to any restrictions related to professional secrecy. In the event of a mandate entrusted to us by a legal entity or a natural person (e.g. for the processing of its employees’ salaries), we act jointly with the Client to inform the Data Subjects of the Processing, in accordance with the terms of the mandate contract. In this case too, the explicit Consent of the employees for the Processing of their sensitive Personal Data is obtained by the Client.

When we act as a processor for our Clients, the latter remain responsible for informing the Data Subjects of our processing of their Personal Data and remain responsible for the processing and the obligations associated with this processing as Data Controllers.

With regard to the personal data of data subjects in relation to our customers, this includes the following information in particular:

  • Contact details (e.g. surname, first name, address, telephone number, e-mail address, other contact details, marketing data);
  • Personal information (e.g. date of birth, nationality, marital status, profession, title, job description, passport or identity card number, social security number, family situation, etc.);
  • Financial information (e.g. bank details, investments or shareholdings);
  • Mandate data, depending on the mandate, e.g. tax information, articles of association, minutes, employee data (e.g. salary, social insurance), accounting data;
  • Particularly sensitive personal data: such as personal data relating to health, documents that may reveal religious opinions or information concerning social measures, in particular when we provide services in the areas of payroll processing or accounting.

We process this personal data for the purposes described, based on the following legal grounds:

  • In accordance with our clients’ instructions, as a processor of personal data and in order to perform the services described in the contract of mandate;
  • Conclusion or performance of a contract with or in favour of the data subject (e.g. when we fulfil our contractual obligations);
  • Compliance with a legal obligation (e.g. when we fulfil our obligations as an auditor or when we are required to disclose information);
  • Safeguarding of legitimate interests, in particular our interest in providing optimal service to our clients;
  • Consent of the Data Subject in the case of Processing of sensitive Personal Data.

When providing a Service, you may provide us with sensitive Personal Data about yourself or other Data Subjects (e.g. health-related data, extracts from the debt collection register, data relating to social measures, biometric data). As a data subject, you explicitly consent to our processing of this sensitive personal data in order to provide you with the desired services. As a third party, you confirm that you have obtained the explicit consent of the data subject so that we may process their sensitive personal data.

6.3. USE OF OUR WEBSITE

When you visit our Website, the server automatically collects a range of information through cookies (performance cookies, functional cookies, technical cookies, navigation cookies, etc.) and web beacons.

This information is also collected and analysed by third-party applications and tools, such as Google Analytics.

This includes the following Personal Data:

  • device type, browser, OS, operating system version, peripheral device;
  • entry page, date and time of connection to the Website, browsing time, location from which the Website is viewed, time spent on the Website, page viewed, number of clicks on the page, opening of the newsletter, clicks on links, settings and language preferences.

When you voluntarily contact us via the contact page of the Website or when you ask us to provide you with an offer, the following Personal Data is collected:

  • Contact details (surname, first name, address, e-mail address, telephone number);
  • The content of the message you send us;
  • Other information you provide to us via the Website.

We process this Personal Data for the purposes described, based on the following legal grounds:

  • Preservation of legitimate interests (e.g. for administrative purposes, to improve our quality, to analyse data or to promote our services);
  • Consent (in the use of Cookies and when you contact us).

You consent to this Personal Data being processed by the Company for the purposes of (i) optimising your visitor experience when you use the Website, (ii) monitoring and analysing Website traffic for statistical purposes in order to improve its functionality and usability, and (iii) ensuring the security of the Website.

You consent to this Personal Data being processed by the Company for the purpose of responding to your request and/or your call for tenders in connection with the Services.

6.4. USE OF THE NEWSLETTER

If you subscribe to our newsletter, we will use your email address and other contact details to send you the newsletter. You can subscribe to our newsletter with your consent.

To send the newsletter, the Personal Data to be submitted is your full name and your email address, which we record after you register. The legal basis for the Processing of your data in connection with our newsletter is your consent to receive the newsletter. You may revoke your consent at any time and unsubscribe from the newsletter.

By ticking the box “I subscribe to the newsletter”, you expressly consent to us processing your personal data to send you newsletters and/or marketing communications until you unsubscribe.

6.5. PARTICIPATION IN EVENTS

When you participate in one of our events, we collect Personal Data for the purpose of organising an conducting the event and, where applicable, sending you additional information at a later date. We also use your information to inform you about other events. Subject to your consent, we may take photos of you or film you during these events and publish these images internally or externally.

This includes the following information in particular:

  • Contact details (e.g. surname, first name, address, telephone number, e-mail address);
  • Personal information (e.g. profession, position, title, employer’s company, dietary habits);
  • Photos or videos;
  • Payment information (e.g. bank details).

We process this personal data for the purposes described, based on the following legal grounds:

  • Fulfilment of a contractual obligation with or for the data subject, including the preparation of the contract and its possible execution (enabling participation in an event);
  • Preservation of legitimate interests (e.g. holding events, disseminating information about our events, providing services, efficient organisation);
  • Consent (e.g. to send you marketing information or to create visual material).

By ticking the boxes “I agree to receive marketing information” and/or “I agree to be photographed and/or filmed during the event”, you expressly consent to us processing your personal data to send you marketing communications until you unsubscribe and/or to us taking photos and/or videos of you during the event and publishing these images internally or externally for marketing purposes.

6.6. DIRECT COMMUNICATION AND VISITS

When you contact us (e.g. by telephone, e-mail, SMS, chat or other instant messaging) or if we contact you, we Process the Personal Data necessary for this contact. We also Process this Personal Data when you visit us. In this case, you may be required to provide your contact details before your visit or leave them at reception. We will store this information for a certain period of time in order to protect our infrastructure and information.

We use the “Microsoft Teams” service to organise conference calls, online meetings, video conferences and/or webinars (“Online Meetings”). The “Zoom”, “Google Meet” and “3 CX” services may also be used where appropriate.

For this purpose, we process the following personal data in particular:

  • Contact details (e.g. surname, first name, address, telephone number, email address);
  • Secondary communication data (e.g. duration of communication, communication channel);
  • Records of conversations, e.g. during video conferences;
  • Other information that the user uploads while using the videoconferencing service, provides or creates, as well as metadata used for the maintenance of the service provided. Additional information on the processing of personal data by Microsoft Teams, Zoom, 3 CX and Google Meet can be found in the data protection statements of these services;
  • Personal data relating to the professional role of the data subject (e.g. profession, position, title, employer’s company);
  • Time and reason for the visit.

We process this personal data for the purposes described, based on the following legal grounds:

  • Fulfilment of a contractual obligation with or in favour of the data subject, including the preparation of the contract and its possible execution (provision of a service);
  • Preservation of legitimate interests (e.g. security, traceability and processing and management of customer relations);
  • Express consent when processing sensitive Personal Data.

6.7. JOB APPLICATIONS

You can send us your application for a position by post or via the email address indicated on our Website. The application file and all Personal Data communicated to us in this way are processed in a strictly confidential manner, are not passed on to third parties and are only processed by us for the purpose of processing your application for a job with us.

Unless you agree otherwise, after the application process has been completed, your application file will be returned to you or deleted/destroyed, unless it is subject to a legal obligation to retain it. The legal basis for the processing of your data is your consent, the performance of the contract with you and our legitimate interests.

For this purpose, we process the following information in particular:

  • Contact details (e.g. surname, first name, address, telephone number, email address);
  • Personal information (e.g. occupation, position, title, employer’s company);
  • Application documents (e.g. cover letter, certificates, diplomas, curriculum vitae);
  • Assessment information (e.g. recruiter’s assessment, reference information, assessments);
  • Any other information submitted in the application file;
  • Any information about you published on the internet (e.g. social media, articles);
  • Any information published in publicly accessible registers.

We process this personal data for the purposes described, based on the following legal grounds:

  • Preservation of legitimate interests (e.g. hiring new employees);
  • Consent.

By sending us your application by post or email, you expressly consent to our processing of your personal data, including any sensitive personal data, for the purpose of reviewing your application for potential employment.

6.8. SUPPLIERS, SERVICE PROVIDERS, OTHER CONTRACTUAL PARTNERS

When we enter into a contract with you for the purpose of providing us with a service, we process Personal Data about you or your employees. We need this data to communicate with you and to use your services. We also process this personal data to check for any conflicts of interest in connection with our activity as an auditor and to ensure that our collaboration does not expose us to any unintended risks, e.g. in relation to money laundering or sanctions.

To this end, we process the following information in particular:

  • Contact details (e.g. surname, first name, address, telephone number, e-mail address);
  • Personal information (e.g. occupation, position, title, employer’s company);
  • Financial information (e.g. bank details).

We process this personal data for the purposes described, based on the following legal grounds:

  • Conclusion or performance of a contract with or for the data subject, including the preparation of the contract and its possible execution
  • Preservation of legitimate interests (e.g. prevention of conflicts of interest, protection of the company, exercise of legitimate rights).

7. ANALYSIS AND TRACKING TECHNOLOGY

We use cookies on our website. These are small files that your browser automatically creates and that are stored on your device (laptop, tablet, smartphone, etc.) when you visit our website.

Information is stored in the cookie in relation to the specific device used. However, this does not mean that we immediately know your identity. Cookies are used to make our offering more user-friendly for you. For example, we use session cookies to see that you have already visited various pages on our website. These cookies are automatically deleted when you leave our website.

We also use temporary cookies to optimise user-friendliness. These files are stored on your device for a defined period of time. If you visit our Website again to use our Services, it automatically recognises that you have already visited our Website and what entries and settings you have made. This means you do not have to re-enter them.

We also use cookies to statistically record the use of our website and evaluate it for the purpose of optimising our offering for you. After a defined period of time, these files are automatically deleted.

The data processed by cookies is necessary for the purposes mentioned above. Most browsers automatically accept cookies. However, you can configure your browser so that no cookies are stored on your computer or so that a message is always displayed before a new cookie is created. However, completely deactivating cookies may mean that you will no longer be able to use all the features of our Website.

8. INTERNET ANALYSIS, NEWSLETTER ANALYSIS

In order to obtain details about the use of our website, improve our offering and be able to reach you with advertisements on third-party websites or social media, we use the following web analysis tools
and retargeting technologies: Google Analytics 4 and the Mailchimp platform.

These tools are provided by third-party providers. In general, information collected about the use of a Site through cookies or similar technologies is transmitted to the third-party provider’s server. Depending on the third-party provider, these servers may be located abroad.

8.1. GOOGLE ANALYTICS 4

The Website may use Google Analytics 4, a Website analysis service provided by Google Inc. (“Google”). Google Analytics 4 uses cookies, which are text files placed on your computer to help analyse how Users use the Website.

The data generated by Cookies concerning your use of the Website will be communicated to and stored by Google on servers located in the United States of America. Google will use this information to evaluate your use of the Website, compile reports on Website activity for its publisher and provide other services related to Website activity and Internet usage.

Google may disclose this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf, including, in particular, the publisher of this site. Google will not associate your information with any other data held by Google.

You may disable the use of Google cookies by selecting the appropriate settings in your browser. However, such deactivation may prevent the use of certain features of the Website. By using the Website, you specifically consent to the processing of your personal data by Google under the terms and for the purposes described above.

To learn more about how to prevent Google Analytics from tracking you on the websites you visit, go to tools.google.com/dlpage/gaoptout.

8.2. LINKS

If certain pages of the Site contain links to sites or pages belonging to third parties, these sites or pages do not apply the same Privacy Policy.

If you choose to visit any of these third-party sites or pages, you will be redirected to those third-party sites or pages. We have no control over third-party sites or pages and therefore recommend that you refer to the privacy statements of those sites or pages to learn about their procedures for collecting, using and transmitting Personal Data.

9. NEWSLETTER TRACKING

We send our newsletters using the Mailchimp platform. This software enables us to send and analyse newsletters. To carry out this analysis, we collect data about devices and access. In addition, the newsletter or websites accessible from this newsletter are tracked using cookies. A pixel is an image file saved on the recipient’s device.

Thanks to these technologies, we know whether the newsletter has arrived, whether it has been opened and which content the recipient has clicked on. We use this information to improve our newsletters and our offers.

It is possible to prevent pixels from being saved by disabling HTML in your email programme (this varies depending on the email programme).

10. COMMUNICATION AND PROCESSING OF PERSONAL DATA

We only share your Personal Data with third parties if this is necessary to provide our Services to the extent that these third parties can provide us with a service. We may also disclose your Personal Data to third parties if we are required to do so by law or by the authorities, or if we have an overriding interest in disclosing your Personal Data.

We also disclose your Personal Data to third parties, such as tax authorities, if you have given us your consent or if you have instructed us to do so. Sensitive Personal Data is transmitted in encrypted form by default. Unless otherwise expressly agreed with the Customer, other non-sensitive Personal Data, i.e. accounting, tax, legal, payroll administration data, pay slips and salary certificates, is transmitted in unencrypted form (e-mail).

The categories of recipients who may receive Personal Data from us are as follows:

  • The Companies, namely Fidexaudit SA or Fidexaudit révision SA, depending on the Personal Data Controller;
  • Branches;
  • Subsidiaries, in particular Société fiduciaire générale SFG SA, CHE-343.051.817, located at Chemin de Mornex 2, 1003 Lausanne;
  • Service providers (e.g. IT service providers, hosting providers, suppliers, consultants, lawyers, insurance companies, auditors); and
  •  Third parties in connection with our legal or contractual obligations, authorities, public bodies, courts.

We enter into contracts with service providers who process Personal Data on our behalf. By signing these contracts, they undertake to guarantee the protection of the Personal Data processed, in accordance with this Policy. Our service providers are located in Switzerland.

Certain Personal Data may be transferred to the United States (e.g. Google Analytics 4 data).

If Personal Data is to be transferred to countries whose level of Personal Data protection is not adequate, according to the list established by the Federal Council (Art. 16 FADP; Annex 1 OPDo), the Company will only disclose Personal Data after ensuring that an appropriate level of protection is guaranteed, for example on the basis of the EU standard contractual clauses (e.g. in the case of Google) or other appropriate instruments.

11. HOSTING YOUR PERSONAL DATA

Your Personal Data is hosted on the servers of Fidexaudit SA, in Switzerland.

12. RETENTION PERIOD FOR PERSONAL DATA

We process and store your Personal Data for as long as necessary to fulfil our contractual and legal obligations or to achieve the purposes pursued by the processing of Personal Data, i.e. for example, for the duration of the commercial relationship as a whole (from the initiation, execution and until the end of a contract) and beyond, in accordance with legal retention and documentation obligations. In doing so, it is possible that Personal Data may be retained for the period during which rights may be exercised against our company (i.e. in particular during the statutory limitation period) and to the extent that we are required to do so by law or if legitimate commercial interests require it (e.g. for evidence and documentation purposes). As soon as your Personal Data is no longer required for the above-mentioned purposes, it will, in principle and as far as possible, be deleted or anonymised.

13. DATA SECURITY

We take appropriate technical and organisational security measures to protect your Personal Data against unauthorised access, disclosure, alteration or destruction, such as:

  • issuing guidelines and training the Company’s employees;
  • IT and network security solutions;
  • access controls and restrictions;
  • where possible, encryption of data media and transmissions of Personal Data, pseudonymisation and controls.

However, you acknowledge that the use of the internet is by definition not secure and that it carries risks for your Personal Data. The Company makes every effort to protect your Personal Data, but cannot guarantee or ensure that the Personal Data you provide to is safe and protected from breaches, theft and unauthorised access by third parties, for which we accept no liability, within the limits of applicable law.

It is your responsibility to ensure that the device you are using is properly secured and protected against malware such as Trojan horses, computer viruses and worms. You are aware that without adequate security measures (including secure web browser configuration and up-to-date anti-virus software), there is a risk that the Personal Data and passwords you use to protect access to your Personal Data could be disclosed to unauthorised third parties.

14. PROTECTION OF YOUR PERSONAL DATA BY DESIGN AND BY DEFAULT

The Company will implement, both when determining the means of Processing and at the time of the Processing itself, appropriate technical and organisational measures, such as the encryption of sensitive Personal Data, and will comply with data protection principles, in particular minimisation, in an effective manner and will integrate the necessary safeguards into the Processing of your Personal Data in order to protect your rights.

The Company will implement the necessary technical and organisational measures to ensure that, by default, only Personal Data necessary for the fulfilment of the intended Processing is Processed. This obligation applies to the volume of Personal Data we Process, the extent of the Processing, the retention period and access to it. These measures ensure that, by default, your Personal Data is not made accessible to an indeterminate number of third parties without your intervention.

15. YOUR RIGHTS

In connection with our processing of your Personal Data, you have the following rights:

  • The right to access your Personal Data stored by us, as well as the right to be informed about the purpose of the Processing, the origin and the recipients or categories of recipients to whom the Personal Data will be transmitted;
  • Right to rectification if your Personal Data is incorrect or incomplete;
  • Right to restrict the processing of your Personal Data;
  • Right to request the deletion of Processed Personal Data;
  • Right to the portability of Personal Data and to transfer your Personal Data to a third party; and
  • Right to object to the Processing of Personal Data or to revoke Consent to the Processing of Personal Data at any time and without justification.

To exercise these rights, please contact the Data Controller with whom you interact, using the contact details provided in section 1, and provide official identification.

Please note, however, that we reserve the right to enforce the restrictions provided for by law, for example when we are required to retain or process certain Personal Data and we have an overriding interest in doing so (to the extent that we can invoke it), or if it would significantly affect the rights and freedoms of third parties.

The exercise of these rights is free of charge, unless your request is unfounded or excessive, in particular if you have already exercised this right several times in the last twelve months or if your request generates a significant amount of work for the Company. In such cases, the Company reserves the right to charge you an administrative fee.

If you believe that your Personal Data has been unlawfully processed or that the Company has not met your expectations in this regard, you may lodge a complaint with the competent authority, the Federal Data Protection and Information Commissioner (FDPIC). We encourage you to contact the Company with any complaints or concerns, but you are entitled to address your grievances directly to the competent authority.

16. APPLICABLE LAW AND JURISDICTION

The Policy, as well as all matters arising from or related to it (including non-contractual disputes or claims and their interpretation) shall be governed by Swiss law, excluding conflict of law rules.

All disputes, claims or disagreements between a Customer, Visitor or Data Subject and the Company relating to any matter arising from this Policy shall be submitted exclusively to the competent courts of Lausanne, subject to appeal to the Swiss Federal Court.

17. MODIFICATION OF THE DATA PROTECTION STATEMENT

We expressly reserve the right to amend this Policy at any time.

Last modified: October 2025