Privacy Policy

for Clients

Privacy Policy
for Clients

I. Name and address of the controller

Thalmann & Verling Trust reg. is responsible for processing your personal data. The company's contact details are as follows:

Thalmann & Verling Trust reg.
Landstrasse 310
9495 Triesen
Principality of Liechtenstein

Contact details of the Data Protection Officer:

Gian-Luca Thalmann
Thalmann & Verling Trust reg.
Landstrasse 310
9495 Triesen
Principality of Liechtenstein

II. General Information on Data Processing

1. Scope of processing of personal data

Our processing of our users' personal data is limited to those data required to provide a functional website as well as our content and services. The processing of our users' personal data only takes place for the purposes agreed with them or if another legal basis (within the meaning of the GDPR) exists. Only such personal data is collected that is actually required for the implementation and processing of our tasks and services or that you have voluntarily provided to us.

2. Your rights (data subject rights)

You have the right to request information about your personal data processed by us. In particular, you can request information about the processing purposes, the categories of personal data, the categories of recipients to whom your data was or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, data portability*, the origin of your data, provided that these were not collected by us, as well as the existence of automated decision-making including profiling. You also have the right to withdraw any consent you may have given for the use of your personal data at any time. If you believe that the processing of your personal data by us contradicts the applicable data protection regulations, you have the option of lodging a complaint with the data protection office.

*provided that in the case of data portability, a disproportionate effort is not caused.

III. Description and Scope of Data Processing

1. Purposes of data processing

We process personal data of our clients for the following purposes:

  • Activities according to Art. 3 Wealth Management Act, in particular:

  • Investment services and investment activities:

    • Portfolio management;

    • Transmission of orders concerning one or more financial instruments;

    • Execution of orders on behalf of the client

  • Ancillary services:

    • Investment and financial analysis or other forms of general recommendations directly related to client service;

  • Audit office function (auditing review, review)

  • Compliance with statutory bookkeeping obligations

  • Correspondence

  • Compliance with legal obligations, in particular:

    • Wealth Management Act, Due Diligence Act

2. Data categories

In our data registers, the following data categories according to Art. 4 No. 1 GDPR are processed for the performance of our activities within the scope of the purposes listed under point 1:

  1. Client and address data — name, company, date of birth, residential and/or business address, nationality, occupation, telephone number, email address (data recipient: Thalmann & Verling Trust reg., Triesen)

  2. Legitimation data — identification documents, including copies of passports or ID cards, tax numbers, tax certificates, authentication data, including signature samples (data recipient: Thalmann & Verling Trust reg., Triesen)

  3. Due diligence documents — including contracting parties, identification of beneficial owners, profile of the business relationship with information on professional and personal background, e.g. profession and hobbies, World-Check data, clarifications under the Due Diligence Act (SPG) (data recipient: Thalmann & Verling Trust reg., Triesen)

  4. Mandate information — including company documents, bank documents, correspondence, due diligence (SPG) documents (data recipient: Thalmann & Verling Trust reg., Triesen)

  5. Accounting data — transaction and booking information (data recipient: Thalmann & Verling Trust reg., Triesen)

  6. Correspondence — client orders, general matters (data recipient: Thalmann & Verling Trust reg., Triesen)

3.  Legal basis

The data referred to under point 2 are processed

  • on the basis of the contractual relationship with our clients (Art. 6 (1) lit. b GDPR),

  • for compliance with a legal obligation (Art. 6 (1) lit. c GDPR),

  • in the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (Art. 6 (1) lit. e GDPR),

  • or for the purposes of the legitimate interests pursued by the controller or by a third party (Art. 6 (1) lit. f GDPR).

Processing activities based on our legitimate interest may include:

  • Processing for internal administrative purposes

  • Evaluations

  • Marketing

  • Direct marketing

  • Defense of unjustified claims

4.  Recipients of personal data

Personal data of clients are processed by us exclusively for the fulfillment of our contractual, statutory and regulatory obligations for the purposes set out under point 1.

For this purpose, the following entities may receive personal data:

  • external service providers and bodies:

    • Banks

    • Insurance companies

    • Lawyers

    • Auditors

    • other cooperation partners

    • Associations

If statutory or regulatory obligations are to be fulfilled by us, the following bodies in particular may receive personal data:

  • Offices and public bodies (e.g. supervisory authorities, courts)

  • Authorities of third countries or international organizations

5.  Transfer to third countries or international organizations

We do not transfer your data to other countries.

6.  Origin of the data

The data are collected directly (for example during meetings or in the context of correspondence with clients; internal background and due diligence clarifications) and partly by third-party service providers.

Third-party service providers can be:

  • Banks

  • Trustees

  • Auditors

7.  Retention period

The personal data are processed and stored for the duration of the ongoing business relationship within the framework of statutory provisions. After termination of the business relationship, this data is retained for 10 years on the basis of statutory provisions (PGR, SPG, ABGB). Longer retention of the data takes place exclusively on the basis of statutory or contractual retention obligations or for evidence purposes within the limitation periods.

8.  Automated decision-making (Art. 22 GDPR)

There is no automated decision-making using the personal data of clients. Should such procedures be used in individual cases, we will inform the clients to the extent provided by law.

9.  Necessity of data (Art. 13 (2) lit. e GDPR)

In order to be able to offer clients our services to the extent requested by them and in compliance with legal obligations, we absolutely require the data listed under point 2. Failure to provide this data will result, in addition to any statutory reporting requirements to the competent supervisory authorities, in the non-establishment or termination of the business relationship.

IV. Data Security

We use the popular SSL method within the website visit in conjunction with the highest level of encryption supported by your browser. You can tell whether an individual page of our website is transmitted in encrypted form by the closed representation of the key or lock symbol in the address bar of your browser.

In addition, we apply other appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or against unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.