Privacy notice
1. Our privacy promise to you
Your privacy is important to Taurus (“Taurus”, “we”, “us” and “our”). We are committed to protecting your personal data and being transparent about the personal data we hold and use and, wherever possible, giving you control over how we use your personal data. Overall we uphold the following values to make your Taurus journey as safe and secure as possible:
- Transparency: We will always be clear about the data we collect, how we use it, and who we share it with.
- Security: We’re committed to keeping your personal data secure and will take necessary steps to protect it.
- Control: You have control over the personal data we hold about you.
- Legality: We will comply with the full extent of the law and regulations regarding your data.
- Accountability: We hold ourselves accountable for protecting your privacy, and welcome your questions or concerns.
2. Notice at collection
The following serves as our notice at collection of personal data in accordance with applicable law. Under no circumstances does Taurus sell personal data.
Category of personal data collected | Shared |
---|---|
Core identifying data, such as name, maiden name, date of birth, gender, nationality, place of residence, utility bills, picture, tax identification number, ID card/passport, ultimate beneficiary and beneficiary | Yes |
Other identifying data, including address, marital status, title, job title, shareholding details, employer, company/organization name signature, sanctions and whether you are a politically exposed person or a family member of a politically exposed person. | No |
Contact data, including email address, address,telephone number, mobile number, other information in an email signature. | No |
Financial data, including bank account details, distributed ledger/blockchain addresses, account user, account name, account number, unique identifier, reference data, sort code, account balance details, details relating to your financial position, assets, income, salary details, bank statements, source of wealth information. | No |
Commercial and transactional data, including payment transaction details including account name, account number, country of residence, ID contact details (e.g. email address), user name, payment amount, ultimate beneficiary and beneficiary, ultimate remitter and remitter, message identifiers and any information contained in a payment reference. | No |
Correspondence data, including information which you provide in, or we learn about you from, any correspondence or communications with us, including details of any enquiries or requests for technical support and any complaints. | Yes |
Internet activity data, including usage data, including device IP address, the pages of the Taurus websites that you visit and usage information for the Taurus websites. | Yes |
Security data, including username, password, security question and hint, first access PIN. | No |
Technical data, including type of device, unique device identifier, network information, the type of operating system and browser you use, time zone settings, current location and other device related information. | Yes |
Publicly available data, including details obtained from online searches or that is otherwise available in public records including identity, financial and economic data. | No |
Marketing and communications data, including your marketing preferences and communication preferences. For further information see the cookie policy outlined in section 12. | No |
Sensitive personal data, including race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data, criminal convictions and offences including terrorist offences and fraudulent activity. | No |
3. Purposes for which we collect and use your personal data
We use your personal data to:
- Operate our business, the Taurus websites and Taurus Products;
- Manage security, risk and crime prevention for us and our clients;
- Improve the Taurus Products, Taurus API, Taurus websites, client relationships and experiences, including through the use of data analytics;
- Perform any agreement we have entered into with a Related Entity (see details below) or a client or otherwise as necessary in the provision of the Taurus Products, including to process a transaction;
- Comply with any applicable law or regulation; and/or
- For the purposes of the legitimate interests pursued by us or a third party. These legitimate interests include the purposes identified in the table below at paragraph 5.7 but also include other commercial interests and our internal administrative purposes. Where we rely on legitimate interests as the lawful basis for processing your personal data, we will put in place appropriate safeguards to protect your data and to ensure that your interests or fundamental rights and freedoms are not overridden by those legitimate interests;
- Fulfil a purpose for which we have your consent which may be obtained directly or by a Related Entity;
- Establish, exercise, or defend legal claims. We retain each category of Personal Information that we collect for as long as necessary to fulfil the purposes described in our Privacy Policy, including to satisfy legal or reporting requirements. For further information about how we process personal data, please read the details of the Privacy Notice which follows.
1. Introduction
This notice applies to:
- Any individual associated with a client or prospective client of Taurus which includes directors, shareholders, members, UBOs and other beneficial owners, individuals identified in source of wealth documents, contractors, representatives, employees, and any other individuals identified in documents provided by a client or prospective client to us or identified in searches carried out by us as part of the client onboarding or acceptance process;
- Anyone whose personal data we process in connection with the provision, or possible provision, of products and services by us to our clients including as a result of communications and interactions with us, through the use of our products and services directly or indirectly and as necessary in order to enable us to comply with our legal and regulatory obligations (for example by carrying out verification, anti-money laundering, and sanctions checks);
- Anyone whose personal data we process in connection with the provisions, or possible provision, of products and services to us. Such individuals include employees, contractors and representatives of our suppliers, external advisers, financial service companies and intermediaries we work with. Please read this notice carefully. Among other things, it explains:
- What personal data we may collect about you in connection with: (i) our delivery of, and your use of our websites, software and systems together the “Taurus Products"; and (ii) any related interaction between you and us;
- How and why we process your personal data and the lawful basis or bases by which we process your personal data and other important information, such as how long we retain your personal data and who we share your personal data with; and
- Your rights in relation to the personal data we hold about you.
We may collect, use, disclose and store information about you when:
- You interact or use the Taurus websites at www.taurushq.com or www.t-dx.com (“Taurus websites”);
- You correspond with us;
- You register for, or use any of, the Taurus Products;
- A business that you are associated with, or with whom you are contracted to, registers for or uses any of the Taurus Products (a “Related Entity”);
- Your employer or a business that you are associated with, or with whom you are contracted to, provides services to us;
- We carry out ongoing diligence, monitoring and screening, or respond to an external inquiry, in respect of anti-money laundering, politically exposed persons, source of wealth, fraud, sanctions and other crimes;
- We process guarantee and indemnity claims;
- We enforce our rights;
- You report an error in, or request technical support for, our products and services or generally request any client care support or we otherwise investigate an incident;
- You make a complaint or a data request;
- You provide data for other legal and regulatory purposes or we otherwise process personal data to comply with our legal and regulatory obligations; and/or
- You, or your employer, provides products or services to us.
This notice is intended to be communicated to you in a concise, transparent, intelligible, and easily accessible manner, but we appreciate that you may have queries or want to seek clarification as to its terms. If so, please contact us (using the details set out at paragraph 2 below) and we will endeavour to respond to you as soon as possible.
We may make changes to this notice from time to time, including as may be necessary or prudent to reflect any changes in the ways in which we process personal data (including as a result of any new Taurus Products that we may introduce from time to time) or any changes in data protection laws. Any changes and updates to this notice will be posted on the Taurus websites. Please check this notice regularly so that you are aware of any changes.
2. Who we are and our contact details
For the purposes of data protection laws, Taurus SA, a company registered in Switzerland with company number CHE-337.375.281 whose registered headquarter is at Place Ruth-Bösiger 6, 1201 Geneva, Switzerland and which is authorised to operate as a securities house and is regulated by the Swiss Financial Supervisory Authority (FINMA). For some processing activities required in the provision of the Taurus Products, we may be a joint controller with our client which might be a Related Entity. In other activities, we may be a processor, acting on the specific instructions of a client or third party which might be a Related Entity.
For further information regarding when we process your personal data as a joint controller and with whom, or as a processor, please contact us. For information regarding how a Related Entity processes your personal data, please contact that relevant Related Entity.
If you have any queries regarding this notice or the way in which we process your personal data, please contact us at:
Email: [email protected]
Telephone: +41(0) 22 518 90 49
Address: Taurus SA Place Ruth-Bösiger 6 1201 Geneva Switzerland
3. Changes to your personal data
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes or if you become aware that any personal data that we hold is not accurate.
4. What personal data we collect and how we obtain your personal data
4.1 The type of personal data we process may include (as applicable) the following:
Categories of Data | Description of Data |
---|---|
Identity Data | Name, address, date of birth, age, ID card or passport, pictures and videos, tax number, residence permit, credit/debit card statement, document issued by a government authority or agency or other, job title, role, directorship, shareholding details, employer, company/organisation name and details in an email signature, Curriculum Vitae, education details, details regarding sanctions and whether you are a politically exposed person or close to a politically exposed person. |
Contact Data | Email address, address, telephone number, mobile number, other information in an email signature. |
Financial Data | Bank account details including account user, account name, account number, unique identifier, reference data, sort code, account balance details. Details relating to your financial position, assets, income, salary details, bank statements, source of wealth information. |
Transactional Data | Transaction details including blockchain address, account name, account number, country of residence, payment amount, beneficiary, message identifiers and any information contained in a payment reference or included in a free text field which may include sensitive personal data. |
Correspondence Data | Information which you provide in, or we learn about you from, any correspondence or communications with us, including details of any enquiries or requests for technical support and any complaints. |
Usage Data | Logs to our products and systems, device IP address, the pages of the Taurus websites that you visit, usage information for the Taurus websites and the Taurus Portal. |
Security Data | Username, password, first access PIN. |
Technical Data | Type of device, unique device identifier (e.g. an IMEI number, IP, or Mac address), network information, the type of operating system and browser you use, time zone settings and other device related information. |
Publicly Available Data | Details obtained from online searches or that are otherwise available in public records including identity data, financial and economic data, data obtained from online media. |
Marketing and Communications Data | Your marketing preferences and communication preferences. |
Information about why we process, and the lawful basis upon which we rely to process, the above personal data is set out in the table at paragraph 5 below.
4.2 We may process sensitive personal data including details about your race or ethnicity, political opinion or situation (PEP status), biometric data, sanctions and/or debts. This data may be transferred to us by you or may be obtained by us for the purposes of our money laundering and verification checks (for example, within data that reveals political opinions or situation).
4.3 We may process information about criminal convictions and actual or potential offences including terrorist offences and fraudulent activity. Such information is recorded by us and may be shared with financial crime prevention offices, law enforcement agencies, regulators, and other financial institutions.
4.4 We may collect personal data from you directly and we may also obtain personal data from third parties or public sources including the following:
4.4.1 A Related Entity or a client of ours;
4.4.2 Third parties engaged by a Related Entity or a client of ours;
4.4.3 Financial Institutions, payment service providers, payment system operators, intermediaries, other financial services companies (to (amongst other things) provide the Taurus Products, process a payment and prevent, detect and prosecute fraudulent and criminal activity) and external advisers;
4.4.4 Refinitiv World-Check (a third party company engaged by us to carry out money laundering, PEP and adverse news checks);
4.4.5 Onfido (a third party company engaged by us to carry out identification checks);
4.4.6 Criminal record;
4.4.7 Debt collection offices;
4.4.8 Regulatory and government bodies such as the FINMA, Money Laundering Reporting Office Switzerland (MROS), Prosecution authorities;
4.4.9 Public registers;
4.4.10 Third party websites; or
4.4.11 External legal counsel and other professional advisers.
5. The purposes for which we process your personal data
Following the principle of data minimization, we ensure that the personal data we collect and process is relevant, adequate, and limited to what is necessary in relation to the purpose for which it is processed. We are committed to upholding this principle and ensuring that unnecessary data collection is minimised while still fulfilling the stated purposes.
5.1 We use your personal data for a number of purposes but only where we are allowed to by the law.
5.2 We may process your personal data in any circumstances where such processing is necessary:
5.2.1 in order to perform any agreement we have entered into with a Related Entity or a client or otherwise as necessary in the provision of the Taurus Products;
5.2.2 in order to receive services that your employer, or a business that you are associated with or with whom you are contracted to, provides to us;
5.2.3 to comply with any applicable law or regulation; and/or
5.2.4 for the purposes of the legitimate interests pursued by us or a third party. These legitimate interests include the purposes identified in the table below at paragraph 5.7 but also include other commercial interests and our internal administrative purposes. Where we rely on legitimate interests as the lawful basis for processing your personal data, we will put in place appropriate safeguards to protect your data and to ensure that your interests or fundamental rights and freedoms are not overridden by those legitimate interests.
5.3 We may also process your personal data where we have your consent which may be obtained for us by a Related Entity. Where we rely on consent as the lawful basis for processing your personal data, you have the right to withdraw your consent at any time and if you wish to do so, you should contact our Data Protection Officer using the contact details set out in paragraph 2 above. The withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal or the lawfulness of processing based on other lawful grounds.
5.4 We may process sensitive personal data, in particular the ones relating to your political opinion or situation (PEP status), criminal convictions and actual or potential offences where:
5.4.1 we have your explicit consent; 5.4.2 the processing is necessary for reasons of substantial public interest because of the law; and/or 5.4.3 the processing is necessary for the establishment, exercise, or defence of legal claims.
5.5 We may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data.
5.6 We may process your personal data ourselves or in conjunction with our third-party service providers in accordance with paragraph 7.
5.7 Information about the purposes for which we use your personal data, the types of personal data we process to achieve these purposes, and the lawful basis by which we process it, is set out in the table below:
Purpose/Activity | Type of Personal Data Processed | Lawful Basis for Processing |
---|---|---|
Registration and Onboarding
|
|
|
Provision of Taurus Products
|
|
|
Verification, Fraud and Crime Prevention
|
|
|
Business Operation and Maintenance
|
|
|
Client Relationship Management
|
|
|
Business Development
|
|
|
Business Management
|
|
|
Marketing
|
|
|
5.8 We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose.
5.9 If we need to use your personal data for an unrelated purpose, we will notify you (which may be by way of update to this notice) and we will explain the legal basis which allows us to do so.
5.10 Please note that we may process your personal data without your knowledge or consent where this is required or permitted by law.
6. What if you refuse to provide us with any personal data?
Where we need to collect personal data by law, or under the terms of an agreement we have with you or a Related Entity, and you fail to provide that data when requested (or fail to consent to the processing of that data, if necessary), we may not be able to perform the agreement or arrangement we have or are trying to enter into with a Related Entity. If you withdraw your consent during the commercial relationship we have with you, we may have to terminate such relationship.
7. Sharing information with third parties
7.1 We will not share any of your personal data with third parties except as set out in this paragraph 7 or otherwise notified to you or agreed between you and us from time to time.
7.2 We may share personal data with our board members, executive team members, group companies (including our subsidiaries) and partnered companies for the purposes outlined in this notice. We may also share personal data with third party service providers who we engage to provide services which facilitate our business, and we may need to share personal data with other third parties in order to comply with our legal and regulatory obligations. In 7.3 below, is a list of specific third parties and categories of third parties with whom we may share your personal data. We may also share your personal data with third parties who provide similar services to those specified in 7.3 or third parties who provide replacement or substitute services for those listed.
7.3 Parties whom we may share your personal data with (A-Z)
- Any Related Entity;
- Banks, custodians, central security depositories, brokers dealers, digital assets counterparties (crypto-currency exchanges and OTC dealers), payment service providers, virtual assets services providers (VASP), trade repositories and trading venues, and other financial services companies, intermediaries and partners Taurus works with;
- Credit check agencies, debt collection agencies/offices;
- External legal counsel and other professional advisers;
- Social networks;
- Social security insurances and pension funds;
- Regulatory and government bodies (e.g. the Swiss Financial Market Regulation Authority (FINMA), tax authorities (SIF, IRS,…));
- Law enforcement and fraud prevention agencies (e.g. Money Laundering Reporting Office Switzerland (MROS));
- Accounting firms;
- Audit firms (e.g. KPMG, BDO);
- Amazon Web Services (AWS);
- Best Vision Solutions and Services SA and related entities;
- Cloudflare;
- DocuSign;
- Elca Informatique;
- Exoscale;
- GitHub;
- Google (Analytics, Ads, reCAPTCHA,…)
- HubSpot;
- Jira;
- Microsoft;
- Onfido;
- Refinitiv World Check;
- Salesforce;
- Slack;
- VSHN.
7.4 We ensure that any third party engaged by us who processes your personal data in connection with the purposes listed in paragraph 5 does so under an agreement with us and has policies and procedures in place to ensure compliance with data protection laws.
7.5 For any third parties that are based, or process data, outside of Switzerland, UK and the EEA, we engage such third parties in accordance with paragraph 8 below.
7.6 We will remain the controller responsible for the processing of your personal data notwithstanding that third parties may operate as a joint controller with us. For some processing activities we may act as a processor for a third party and, in such circumstances, the third party will be responsible for providing you with the processing information required under data protection laws.
7.7 We may share your personal information with third parties where we are required to do so by law or regulation (such as in connection with an investigation of fraud or other legal enquiry) or in connection with other legal proceedings (including where we believe that your actions violate applicable laws or any agreement with us).
7.8 In the event that our business or any part of it is sold or integrated with another business, your details may be disclosed to our advisers and those of any prospective purchaser and will be passed to the new owners of the business.
8. International transfers of personal data
8.1 From time to time, it may be necessary for us to transfer your information internationally including to fulfil your request, process a transaction, or otherwise as required in the provision of the Taurus Products and services. In particular, your information may be transferred to and/or stored on the servers of third parties identified in paragraph 7 which are based outside of Switzerland, UK and the EEA.
8.2 However, we will not transfer your personal data outside of Switzerland, UK and the EEA unless:
8.2.1 such transfer is to a country or jurisdiction which has been approved pursuant to data protection laws as having an adequate level of protection;
8.2.2 appropriate safeguards are in place in accordance with applicable data protection laws. These safeguards can include the use of encryption, standard contractual clauses or binding corporate rules;
8.2.3 any data importer provides us with relevant sources and information relating to the destination country or territory and the laws applicable to the transfer in that destination country in order to substantiate the matters set out in 8.2.1; or
8.2.4 the transfer is otherwise allowed under data protection laws (including where we have consent, the transfer is necessary for important reasons of public interest, is necessary for the establishment, exercise or defense of legal claims or is necessary for the performance of a contract with the data subject).
8.3 We will ensure that where your personal data is transferred outside of Switzerland, UK and the EEA, the data importer will be contractually obliged to:
(a) ensure your personal data is afforded the same level of protection as would be afforded to it within Switzerland, UK and the EEA; and (b) keep us informed of any development affecting or likely to affect the level of protection your personal data receives in the importer’s country.
9. Your rights as a data subject
9.1 Subject to any conditions and requirements set out in applicable laws, you may have some, or all, of the following rights in relation to the personal data we hold about you:
9.1.1 Right to be informed about the processing of your data; 9.1.2 the right to request a copy of your personal data held by us; 9.1.3 the right to correct any inaccurate or incomplete personal data held by us; 9.1.4 the right to request that we restrict the processing of your data; 9.1.5 the right to have your personal data transferred to another organisation; 9.1.6 the right to object to certain types of processing of your personal data by us; 9.1.7 the right to request the erasure of your personal data held by us; and
9.2 the right to complain (please see paragraph 13 of this notice). PLEASE NOTE that these rights are not absolute in all situations and may be subject to conditions and provisions set out in applicable laws. We cannot, therefore, guarantee that we will be able to honour any request from you in connection with the rights set out above. For example, even if you request that we delete your personal data, we may be required by law to retain some personal data for accounting and record keeping purposes or in order that we comply with our legal and regulatory obligations.
9.3 To protect your privacy, we may verify your identity by matching personal data that you submit with your requests with information that we maintain on our systems. Where applicable, we will use the requested information for verification purposes only. Please note that we may decline a request where we are unable to verify your identity.
9.4 If you exercise any of the foregoing rights, we will not discriminate against you, including by denying access to our products or services or restricting your access to products or services of a certain quality or price level. However we raise your attention to the fact that the exercise of certain rights may not be compatible with the continuation of the relationship and/or the provision of our products or services.
9.5 For further information, or to exercise any particular right, please contact us at [email protected].
10. Storage and retention of your personal data
10.1 As a minimum, we need to store your personal data for as long as is necessary to enable us to fulfil the purpose for which it is processed, including to fulfil our legal and regulatory obligations (e.g. relating to record keeping) and to exercise or defend any legal claims.
10.2 To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of personal data; the potential risk of harm from unauthorised use or disclosure of personal data; the purpose for which we use the personal data; whether we can achieve the purposes through other means; and the applicable legal requirements.
10.3 We maintain and implement a data retention policy and will delete personal data in accordance with this.
10.4 If we de-identify data, we will maintain and use the data in de-identified form and not attempt to re-identify the data except as required or permitted by law, and we will require any recipient of de-identified data to adhere to similar restrictions.
10.5 For as long as we do store your data, we follow generally accepted industry standards and maintain reasonable safeguards to attempt to ensure the security, integrity, and privacy of the information you have provided. All information you provide to us is stored on our secure servers. We have security controls based on ISO 27001:2022, ISAE3402, or similar best practices in place.
10.6 It is important that you keep secure and confidential any login credentials that you have for the Taurus websites and/or products and services. You are responsible for maintaining the security and confidentiality of such login credentials. You should notify us promptly if you become aware that the security or confidentiality of your login credentials is compromised.
10.7 We will notify you without undue delay in accordance with the requirements and limitations of data protection laws, if we have reason to believe that there has been a personal data breach by us which could adversely affect your rights and freedoms and/or if it is required for your protection, as long as we are required by law to notify you.
11. Links to third parties
11.1 The Taurus websites may link or redirect to other websites, social media accounts or other content which is not under our control. Such links or redirects are not endorsements of such websites or representation of our affiliation with them in any way and such third party websites are outside the scope of this notice.
11.2 If you access such third party websites, please ensure that you are satisfied with their respective privacy policies before you provide them with any personal data. We cannot be held responsible for the activities, privacy policies or levels of privacy compliance of any websites operated by any third party.
12. Cookies
The Taurus websites use some cookies as detailed in the Pivacy policy.
13. Questions and complaints
13.1 We take our data protection obligations seriously. If you have any questions or complaints about this notice or the way that we handle your personal data, we would appreciate the chance to deal with your concerns in the first instance before you approach the relevant authority. Please contact us using the details provided in paragraph 2 above.
13.2 You have the right to make a complaint at any time to any relevant authority for data protection issues.