Privacy policy
1. Preamble and Scope
SWIX MONACO S.A.M. (“SWIX MC”) attaches the utmost importance to the protection and security of the personal data entrusted to it. As a wealth management company established in the Principality of Monaco, it processes highly sensitive personal and financial information relating to its clients and persons connected with them, as well as data relating to its suppliers, business partners and employees.
This Policy explains, in clear terms, how SWIX MC collects, uses, retains and protects personal data, as well as the rights available to data subjects. It reflects the obligations applicable to SWIX MC under Law No. 1.565 of 3 December 2024 on the protection of personal data, Sovereign Ordinance No. 11.327 of 10 July 2025 implementing that Law, and the recommendations of the Autorité de Protection des Données Personnelles (APDP).
It applies to all personal data processed by SWIX MC, whether obtained directly from data subjects, through professional intermediaries or from third-party service providers, including data collected through the company’s website. It forms part of the company’s governance framework and is supplemented by detailed internal procedures.
2. Data Controller and Data Protection Contact
SWIX MONACO S.A.M., a Monaco public limited company with a share capital of EUR 450,000, whose registered office is located at Villa le Dôme, 4/6 rue des Lilas, 98000 Monaco, registered with the Monaco Trade and Industry Registry under number 26S10433, is the data controller for the processing activities described in this Policy.
A data protection contact (RPD) has been appointed. The contact may be reached at dataprotection-swixmonaco@swixfo.com or by post at the registered office, for the attention of the data protection contact.
3. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data, including its collection, recording, storage, consultation, disclosure, erasure or destruction.
- Data controller: the person who determines the purposes and means of the processing, in this case SWIX MC.
- Processor: a service provider that processes personal data on behalf of and on the instructions of the data controller.
- Sensitive data: data relating in particular to racial or ethnic origin, political, philosophical or religious opinions, trade union membership, health, sex life, as well as offences and criminal convictions.
4. Data Subjects and Sources of Data
This Policy applies to: clients and prospective clients; beneficial owners, authorised representatives and other persons connected with managed structures; suppliers, professional intermediaries and business partners; applicants and employees; and visitors to the website.
Data is collected:
- directly from the data subject;
- from the client, where the data relates to persons connected with that client;
- from professional intermediaries and advisers introducing the relationship;
- from custodian banks and brokers, in relation to account and transaction data;
- from compliance database providers, for sanctions screening, identification of politically exposed persons and adverse information searches;
- from public sources and official registers.
5. Purposes of Processing
SWIX MC processes personal data only for lawful and necessary purposes directly related to the services it provides. The purposes depend on the nature of the relationship and may include the following.
5.1 Clients and Prospective Clients
- Establishing and maintaining the client relationship, including onboarding, suitability assessment and portfolio management.
- Carrying out financial analyses, providing investment advice and wealth management services in accordance with the agreed mandates.
- Complying with legal and regulatory obligations, particularly in relation to anti-money laundering and counter-terrorist financing, sanctions screening and tax reporting.
- Communicating with clients regarding their portfolios, market developments, corporate actions and any other relevant matters.
5.2 Connected Persons and Beneficial Owners
- Identifying and verifying beneficial owners, authorised representatives and other connected persons in accordance with AML/CFT and tax obligations.
- Administering clients’ structures, such as trusts, foundations or holding companies.
5.3 Suppliers and Business Partners
- Managing contracts, payments and due diligence relating to third-party service providers and professional intermediaries.
- Maintaining a supplier register in accordance with regulatory expectations.
5.4 Employees and Applicants
- Managing the employment relationship, including payroll, employee benefits, training and performance appraisal.
- Processing applications from prospective employees and service providers.
5.5 General Business Operations
- Ensuring the security of IT and communication systems, including the use of the Infront portfolio management system.
- Conducting internal audits, risk management and compliance monitoring.
- Protecting the security and integrity of premises, systems and data.
- Responding to enquiries submitted through the website.
Personal data is not processed for purposes incompatible with those described above, except where required or permitted by law. Where consent is required, it is obtained in a clear and informed manner.
6. Legal Bases
SWIX MC processes personal data only where there is a valid legal basis for doing so. This section sets out the legal bases provided for under Article 5 of Law No. 1.565 on which the company may rely:
- performance of a contract: processing necessary for entering into, performing and managing contractual relationships with clients, suppliers and employees;
- compliance with legal obligations: in particular AML/CFT checks, tax reporting, including FATCA and the Common Reporting Standard, and retention obligations arising from Monaco regulations applicable to companies authorised under Law No. 1.338;
- SWIX MC’s legitimate interests, balanced against the rights and freedoms of data subjects: improvement of services, security of systems and networks, and business management;
- consent, where required by law, in particular for certain marketing communications and for the use of cookies that are not necessary for the operation of the website, such as audience measurement cookies, and for the processing of sensitive data where not otherwise authorised; consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before its withdrawal;
- protection of the vital interests of the data subject or another natural person; in the case of sensitive data, this legal basis additionally requires that the person be unable to validly give consent due to impairment of their faculties, physical or legal incapacity, or material impossibility.
7. Retention Periods
SWIX MC retains personal data only for as long as necessary for the purposes for which it was collected or in order to comply with applicable legal, regulatory and contractual obligations.
Retention periods are extended where a longer legal obligation, an ongoing administrative procedure or pending litigation requires it. At the end of the applicable retention periods, SWIX MC securely deletes electronic records from active systems and backups, destroys paper documents through a certified service provider, or irreversibly anonymises the data where appropriate.
The company periodically reviews the data it holds to ensure that it remains accurate, relevant and retained only for as long as necessary.
8. Rights of Data Subjects
Persons whose data is processed by SWIX MC have the following rights, subject to the conditions provided by law:
- right of access: to obtain confirmation as to whether personal data relating to them is being processed and, where applicable, to receive a copy of such data together with information concerning its use;
- right to rectification of inaccurate or incomplete data;
- right to erasure, where the data is no longer necessary, consent has been withdrawn and no other legal basis applies, or the processing is unlawful; SWIX MC may nevertheless be legally required to retain certain data, in particular for five years following the end of the business relationship pursuant to its AML/CFT obligations;
- right to restriction of processing while a dispute or verification is being examined;
- right to data portability;
- right to object on grounds relating to the data subject’s particular situation, including in relation to direct marketing;
- right to withdraw consent where processing is based on consent;
- right not to be subject to a decision producing legal effects concerning them or similarly significantly affecting them, based solely on automated processing, including profiling, subject to the circumstances in which such a decision is permitted by law;
- right to lodge a complaint with the competent data protection authority.
Profiling and Automated Decision-Making
As part of its due diligence obligations, SWIX MC classifies the risk associated with each business relationship and establishes a risk profile and investment objectives; these processing activities involve an element of profiling.
No decision producing legal effects or significantly affecting an individual is made solely on the basis of automated processing: any decision to establish a relationship, refuse a relationship, terminate a relationship or classify a relationship as high-risk is subject to human assessment.
If such a decision were nevertheless to be made exclusively by automated means in one of the circumstances permitted by law, the data subject would be informed accordingly, as well as of the reasoning underlying the processing, its significance and the expected consequences for them, and would be entitled to obtain human intervention, express their point of view and contest the decision.
9. Exercising Your Rights
Requests may be submitted by post, electronically or in person to the data protection contact using the contact details set out in Section 15.
SWIX MC verifies the identity of the applicant and may, where there are reasonable doubts, request additional supporting documents, including a copy of an identity document bearing the holder’s signature where required by the circumstances.
SWIX MC informs the data subject in writing of the action taken on their request within one month of receipt. In the case of a complex request or multiple requests, this period may be extended by two months, provided that the data subject is informed of the reasons for the extension within one month.
Where the company does not act on the request, it informs the data subject, within the same period at the latest, of the possibility of lodging a complaint with the APDP or bringing proceedings before the Court of First Instance.
Information is provided free of charge. Where a request is manifestly unfounded or abusive, particularly because of its repetitive nature, the company may charge a reasonable fee or refuse to act on the request, provided that it demonstrates the manifestly unfounded or excessive nature of the request.
10. Transfers of Data Outside Monaco
Given the international nature of SWIX MC’s client base and activities, personal data may be transferred, stored and processed outside the Principality. Such transfers take place only where necessary for the provision of services, compliance with legal obligations or the operation of the company’s systems.
10.1 Transfers to Switzerland
SWIX MC uses the Infront portfolio management system to manage its clients’ portfolios and associated information. Infront’s servers are located in Switzerland, as are the daily cloud backups.
The company’s website is hosted by WeDoIT Group Sagl, Via Gola di Lago, CH-6950 Tesserete, Switzerland. Service providers established in Switzerland are subject to the Swiss Federal Act on Data Protection, which imposes obligations relating to confidentiality, security and respect for the rights of data subjects.
A transfer outside the Principality may take place without prior formalities where the recipient country is included on the list of countries, territories and international organisations recognised as providing an adequate level of protection. This list is adopted by Ministerial Order, following consultation with the APDP, and published in the Journal de Monaco and on the Authority’s website.
10.2 Transfers to Other Jurisdictions
Data may also be transferred to other countries in which the company’s service providers, custodians, counterparties or professional advisers operate, including Italy, the United Kingdom and France.
10.3 Safeguards Applicable to Non-Adequate Jurisdictions
Where an adequate level of protection is not available, a transfer is carried out only where appropriate safeguards are in place, in the form of standard contractual clauses, binding corporate rules or another legally binding and enforceable instrument ensuring data protection and the right to an effective remedy.
10.4 Internal Governance
Any transfer outside the Principality is subject to the company’s internal transfer approval procedure, which verifies the legal basis for the transfer, the security measures applied and the recipient’s compliance.
10.5 Recipients and Processors
Data may be disclosed to custodian banks and brokers appointed by the client, regulators and supervisory authorities, advisers and auditors subject to confidentiality obligations, as well as to other processors, particularly in connection with IT services or control activities.
Each processor acts on SWIX MC’s written instructions pursuant to a data processing agreement complying with the requirements of Law No. 1.565 and is subject to a prior assessment of its level of data protection and information systems security.
11. Security Measures
SWIX MC implements a range of organisational, technical and physical measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure or unauthorised access.
- Organisational measures: clearly defined data protection roles and responsibilities, staff training, access restricted according to the need-to-know principle and periodically reviewed, and internal policies governing the use of email, mobile devices and remote working.
- Technical measures: secure hosting, encryption of data at rest and in transit, enhanced access authentication, monitoring of security events and keeping systems up to date.
- Physical measures: access-controlled premises, secure storage of paper documents and confidential destruction of documents.
Details of these measures, as well as descriptions of the technical safeguards implemented, are set out in the company’s internal security procedures and may be disclosed to the competent authorities and to clients upon request.
12. Data Breaches
SWIX MC has an incident response plan in place to investigate and address without delay any suspected data breach.
Any breach is notified to the APDP in accordance with the conditions and time limits laid down by Law No. 1.565 and communicated to the data subjects where it is likely to result in a high risk to their rights and freedoms.
13. Cookies and Trackers
A cookie is a file stored on the user’s device when visiting the website. Cookies that are strictly necessary for the operation and security of the website are placed without prior consent.
All other trackers, in particular those used for audience measurement, are placed only after consent has been obtained through the banner displayed on the first visit. Users may accept, reject or customise their preferences at any time.
Certain audience measurement tools involve the transfer of data to countries that do not provide an adequate level of protection; such trackers are activated only with explicit consent.
Consent may be withdrawn at any time via the “Manage my cookies” link in the website footer or through the browser settings. Consent records are retained for no longer than six (6) months.
14. Amendments to This Policy
SWIX MC may update this Policy to reflect changes in its practices, legal obligations or the technologies it uses. In the event of a significant change, the company:
- publishes the updated version on its website;
- indicates the date of the latest revision;
- where appropriate, informs clients by email, secure message or any other agreed communication channel.
The version currently in force is the version published on the website. This Policy is reviewed at least once a year and whenever there is a significant change in processing activities, service providers or the regulatory framework.
Last updated: 01.09.2026
15. Contact Details and Supervisory Authority
For any question, concern or request relating to this Policy:
By post:
SWIX MONACO S.A.M.
For the attention of the Data Protection Contact
Villa le Dôme
4/6 rue des Lilas
98000 Monaco
Principality of Monaco
By email:
dataprotection-swixmonaco@swixfo.com
By telephone:
+377 92 00 32 90
Supervisory Authority:
Autorité de Protection des Données Personnelles (APDP)
Le Concorde, 4th floor
11 rue du Gabian
98000 Monaco
www.apdp.mc
For clients established outside Monaco, the contact details of the competent supervisory authority in their jurisdiction may be provided upon request.