Version retail-open-v2 · Ashenden Finance SA
This Privacy Policy applies to Ashenden Finance SA, with registered offices at Rue Sigismond-Thalberg 2, 1201 Genève, Switzerland ("Ashenden Finance", "we", "us", "our"). We are the data controller for personal data processed through the Platform. Ashenden Finance SA is affiliated to SO-FIT, a self-regulatory organisation recognised by FINMA, as a financial intermediary within the meaning of article 2 para. 3 of the Swiss Anti-Money Laundering Act (AMLA). Each member of our advisory team is registered in the Swiss Register of Client Advisers. We process personal data in accordance with the Swiss Federal Act on Data Protection (nDSG) and, where it applies, the EU General Data Protection Regulation (GDPR). For data protection enquiries, please contact us at: contact@research.ashfin.ch
We collect and process the following categories of personal data: Account & Identity Data: full name, email address, password (stored in hashed form using bcrypt), company name, and professional role. Usage & Analytics Data: pages visited, research articles viewed, search queries, session duration, and feature interactions within the platform. Communications Data: messages you send via our contact form or support channels. Technical Data: IP address, browser type and version, device identifiers, and cookies (see our Cookie Policy for details). We do not collect sensitive personal data (e.g. health data, political opinions, or biometric data).
We process your personal data for the following purposes: Service Delivery: to provide access to the Ashenden Finance platform, including research publications, bond and equity analytics, macro indicators, and advisory services you have subscribed to. Account Management: to create and manage your user account, process authentication, and maintain session security. Communications: to send you research updates, morning briefings, and service notifications you have opted into, as well as essential administrative communications. Security & Fraud Prevention: to detect and prevent unauthorized access, abuse, or fraudulent activity. Legal Compliance: to meet our obligations under applicable law, including anti-money laundering (AML) requirements and record-keeping duties. Product Improvement: to analyse aggregated, anonymised usage patterns and improve our platform.
We rely on the following legal bases: Contract Performance (Art. 6(1)(b) GDPR / nDSG Art. 31): processing necessary to deliver the services you have subscribed to. Legitimate Interests (Art. 6(1)(f) GDPR): security monitoring, fraud prevention, and platform analytics. Legal Obligation (Art. 6(1)(c) GDPR): compliance with legal duties to which we are subject, including accounting, tax and anti-money laundering obligations. Consent (Art. 6(1)(a) GDPR): marketing communications and non-essential cookies, where you have provided explicit consent.
We do not sell, rent, or trade your personal data. We may share data with: Service Providers: trusted third-party processors operating on our behalf (e.g. hosting infrastructure, email delivery) under strict data processing agreements. Competent Authorities: courts, regulators and public authorities, where disclosure is required by law. Professional Advisors: legal counsel, auditors, and insurers, bound by confidentiality obligations. Your data is processed within the EEA and in Switzerland. Switzerland benefits from an adequacy decision of the European Commission, so transfers between the two require no additional safeguard. Any transfer to a country without an adequacy decision is made under standard contractual clauses or an equivalent safeguard.
We retain your personal data for as long as your account is active, plus a further period as required by applicable law (typically 10 years for accounting and financial records under the law of Switzerland). Usage logs and analytics data are retained for up to 24 months in identifiable form, then anonymised or deleted. Upon account termination, we will delete or anonymise your personal data within 90 days, except where retention is required for legal or regulatory compliance.
Subject to applicable law, you have the right to: · Access the personal data we hold about you · Rectify inaccurate or incomplete data · Erase your data ("right to be forgotten") where legally permissible · Restrict or object to certain processing activities · Data portability (receive your data in a structured, machine-readable format) · Withdraw consent at any time, without affecting the lawfulness of prior processing To exercise any of these rights, please email us at contact@research.ashfin.ch. We will respond within 30 days. You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).
We implement industry-standard technical and organisational measures to protect your data, including encrypted data transmission (TLS), bcrypt password hashing (12 rounds), JWT-based session management with short expiry windows, and role-based access controls. No method of electronic transmission or storage is 100% secure. We will notify you and relevant authorities promptly in the event of a data breach affecting your rights, as required by law.
We may update this Privacy Policy to reflect changes in our practices or applicable law. Material changes will be notified via email or a prominent notice on the platform at least 30 days before taking effect. Your continued use of the platform after that date constitutes acceptance of the updated policy.
For any privacy-related enquiries, please contact: Ashenden Finance SA Rue Sigismond-Thalberg 2 — 1201 Genève, Switzerland T +41 91 220 20 70 contact@research.ashfin.ch