
Policy
Data Protection Policy
FORFIRM applies Data Protection principles to protect Personal Data, Confidential Information and Client Data throughout their lifecycle.
Purpose
The purpose of this Data Protection Policy is to establish the core principles, operational requirements, and organizational safeguards governing the collection, processing, storage, and transfer of personal data within the Company. This policy ensures that all Personally Identifiable Information (PII) belonging to employees, clients, prospects, and third parties is handled with the highest standard of confidentiality and integrity, aligning corporate operations with international privacy frameworks and the ISO/IEC 27001:2022 standard.
Applicability
This policy applies to all operations involving the processing of personal data (whether automated or manual) conducted by the Company. It encompasses all data repositories, internal HR systems, customer relationship management (CRM) platforms, and cloud environments, and is binding for all employees, contractors, external consultants, and board members.
Data Protection Commitment
The Company recognizes privacy as a fundamental individual right and a cornerstone of corporate governance. The Company commits to adopting a proactive "Privacy by Design" and "Privacy by Default" methodology in all technological architectures and corporate workflows, ensuring that data protection principles are structurally integrated into every system lifecycle.
Compliance Obligations
The Company guarantees strict adherence to all applicable data protection regulations. This includes absolute alignment with the Swiss Federal Act on Data Protection (nLPD), the Ordinance on Data Protection (DPO) and specific international data transfer treaties governing transborder data flows.
Continual Improvement
The Company is committed to the continuous improvement of its privacy frameworks. Data processing registers, privacy notices, consent mechanisms, and cryptographic access protocols are systematically audited and updated to withstand evolving technological capabilities, regulatory amendments, and cyber threat landscapes.
Data Protection Principles and Performance Management
The Company enforces compliance through six fundamental data processing principles: • Lawfulness, Fairness, and Transparency: Personal data must be processed lawfully and fairly. Clear, intelligible, and accessible Privacy Notices must be provided to data subjects at the time of data collection, explicitly detailing the purposes of the processing • Purpose Limitation: Personal data must be collected for specified, explicit, and legitimate business purposes and must not be further processed in a manner incompatible with those initial purposes • Data Minimization: The collection of personal data must be strictly limited to what is necessary in relation to the purposes for which they are processed • Retaining unnecessary, excessive, or obsolete personal data sets is prohibited • Accuracy and Up-to-date Standards: Reasonable operational steps must be taken to ensure that personal data is accurate and, where necessary, kept up to date. Inaccurate data must be erased or rectified without delay upon identification or request • Storage Limitation and Retention: Personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed, or as mandated by statutory Swiss financial/contractual archival laws • Integrity and Confidentiality: Personal data must be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using robust encryption (AES-256), strong access controls (MFA), and data anonymization/pseudonymization where applicable
Roles and Responsibilities
• Executive Management carries ultimate legal responsibility for data protection governance, appoints the internal Data Protection Officer (DPO), and allocates the required compliance budget • The Data Protection Officer (DPO) / Privacy Committee is responsible for maintaining the Register of Processing Activities (RoPA), conducting Data Protection Impact Assessments (DPIAs) for high-risk processing, handling Data Subject Access Requests (DSARs), and acting as the main contact point for the Federal Data Protection and Information Commissioner (FDPIC) • All Personnel are responsible for executing daily tasks in strict compliance with this policy, ensuring data fields are not shared unsafely, and instantly escalating any suspected data leakage or privacy anomaly to the DPO
Awareness, Training and Culture
The Company maintains a continuous privacy training program. All employees receive mandatory privacy onboarding and periodic refresher courses focusing on the practical application of the nLPD, safe data dissemination habits, clean screen principles, and the legal implications of non-compliance.
Communication and Stakeholder Engagement
The Company's external Privacy Notices are published transparently on the corporate website. All contracts executed with third-party suppliers, processors, or SaaS vendors must include formalized Data Processing Agreements (DPAs) and standard contractual clauses guaranteeing that the third party enforces security controls equivalent to this policy.
Monitoring, Review and Continuous Alignment
The Company systematically audits internal user permissions, transborder data flows, and cookie consent configurations. This policy is formally reviewed at least annually by the DPO and Executive Management or upon major legislative shifts to preserve absolute structural alignment with international data protection benchmarks.
