Legal

Privacy Notice

Last Updated: August 2026

Applicable Frameworks: Swiss Federal Act on Data Protection (revFADP / revDSG), EU General Data Protection Regulation (EU GDPR), and UK GDPR.

1.

Scope and Distinction (Client Data vs. Corporate Data)

This Privacy Notice outlines how QUADRUM SA (“Company”, “we”, “us”, or “our”) collects, uses, stores, and protects Personal Data in connection with our website, software licensing, client onboarding, technical support, and business operations.

On-Premise Software Deployment Notice

When our RegTech software application is licensed as a client-hosted / on-premise installation, our client acts as the exclusive Data Controller for all regulatory, financial, or personal data processed within the application. In this deployment model, we possess no remote access, backdoors, or hosting visibility into the live environment and process zero end-customer data.

This Privacy Notice applies strictly to Personal Data where we act as a Data Controller (e.g., website visitors, business contact details, license verification logs, and support interactions).

2.

Definitions & Related Persons

Personal Data
Any information relating to an identified or identifiable natural person.
Processing
Any operation performed on Personal Data (e.g., collection, storage, adaptation, transmission, or deletion).
Related Persons
Individuals associated with our corporate clients, partners, or vendors whose details are provided to us in the context of a business relationship (e.g., directors, compliance officers, authorized signatories, legal representatives, or IT administrators).

We kindly request that you share this Privacy Notice with any Related Persons whose data you provide to us.

3.

Data Controller & Contact Information

The entity responsible for processing your Personal Data is:

Legal Entity
QUADRUM SA
Address
Chemin de Mornex 30, CH-1003 Lausanne, Switzerland
Commercial Register UID
CHE-375.480.418 HR/MWST
Data Protection Office
privacy@quadrum-solutions.ch | Phone: +41 (0) 21 311 59 67
4.

Categories of Personal Data We Collect

Depending on how you interact with us, we collect and process the following categories of Personal Data:

  1. B2B Account & Onboarding Data: Names, business email addresses, telephone numbers, job titles, employer details, digital signatures, and identity verification details for contract management.
  2. Technical & Telemetry Data: IP addresses, operating system specifications, browser types, license key activation logs, hardware identifiers, and session timestamps collected when accessing our portal or licensing servers.
  3. Communication & Service Desk Data: Form submissions, email exchanges, support ticket logs, phone call logs, and feedback collected during technical assistance.
  4. Commercial & Transactional Data: Invoicing records, payment histories, audit trails, and banking details required for billing.
5.

Purposes and Legal Bases for Processing

We process your Personal Data based on the following legal grounds under Swiss revFADP and GDPR.

Processing PurposeCategory of DataLegal Basis (FADP / GDPR)
Contract Execution & OnboardingB2B Account & Transactional DataNecessary for performance of a contract or pre-contractual measures.
System Security & Licensing AssuranceTechnical & Telemetry DataLegitimate interest to verify licensing, protect IT infrastructure, and prevent fraud.
Legal & Regulatory ComplianceCommercial & Transactional DataCompliance with legal obligations (e.g., 10-year Swiss Code of Obligations tax retention).
Direct B2B Communication & MarketingCommunication DataLegitimate interest in managing B2B relationships or prior explicit consent (opt-in).
6.

Disclosure of Personal Data to Third Parties

We do not sell, rent, or trade your Personal Data. We may disclose Personal Data to selected third-party service providers acting strictly as Processors on our behalf, including:

  • IT hosting providers and cloud infrastructure tools located in Switzerland or the EU/EEA.
  • Professional advisors (external financial auditors, tax advisors, legal counsel).
  • Public, administrative, or judicial authorities where required by statutory law or court orders.

All Processors are bound by strict Data Processing Agreements (DPAs) requiring equivalent security standards and limiting processing strictly to our documented instructions.

7.

International Data Transfers

Personal Data is primarily processed and stored within Switzerland and the European Economic Area (EEA).

Switzerland is officially recognized as offering an adequate level of data protection by both the European Commission and the UK Government. If Personal Data must be transferred outside CH/EEA/UK to a third country without an adequacy decision, we guarantee protection by implementing:

  • Standard Contractual Clauses (SCCs) issued by the European Commission;
  • The Swiss Addendum required by the Federal Data Protection and Information Commissioner (FDPIC);
  • The UK International Data Transfer Addendum (IDTA).
8.

Retention Period

We store Personal Data only for as long as necessary to fulfill the purposes for which it was collected:

  • Contractual Records: Retained for 10 years following contract termination, pursuant to Article 957 of the Swiss Code of Obligations (CO).
  • Technical Logs & Web Analytics: Automatically deleted or permanently anonymized after 12 months.
  • Marketing Contacts: Retained until you withdraw consent or object to B2B communications.
9.

Your Statutory Data Protection Rights

Subject to statutory conditions and legal limits, you possess the following rights regarding your Personal Data:

  • Right of Access: Request confirmation of processing and obtain a copy of your Personal Data.
  • Right to Rectification: Request the immediate correction of inaccurate or incomplete data.
  • Right to Erasure (“To Be Forgotten”): Request deletion of data no longer required by law or contract.
  • Right to Restrict & Object: Object to processing based on legitimate interest or direct marketing.
  • Right to Data Portability: Request transfer of your data in a structured, machine-readable format.

To exercise these rights, submit a written request to our DPO at privacy@quadrum-solutions.ch.

Requests are handled free of charge within 30 calendar days.

10.

Technical Security Measures (TOMs)

In close cooperation with our hosting infrastructure providers, we enforce stringent technical and organizational measures to safeguard databases against unauthorized access, loss, misuse, or falsification. Controls include TLS 1.3 transit encryption, AES-256 storage encryption, role-based access control (RBAC), and continuous vulnerability monitoring.

11.

Amendments to This Privacy Notice

We reserve the right to amend this Privacy Notice to reflect changes in legal mandates, regulatory guidance, or operational workflows. The current version published on our website is always binding.