Privacy Policy
Compass Asset Management
Compass Asset Management SA (hereinafter the “Controller” or the “Company”) is a company with many years of experience in the field of international finance (asset management, investment funds, bond trading and brokerage, wealth and estate planning, and risk management).
The processing of the personal data of Users who browse and/or interact with the web services accessible electronically through the website www.compass-am.com (hereinafter the “Website” or the “Platform”) is carried out by the Company in compliance with Article 19 of the Swiss Federal Act on Data Protection (hereinafter also referred to as the “FADP”) and Article 13 of the Data Protection Ordinance (hereinafter also referred to as the “DPO”), while also taking into account the principles of fairness, lawfulness and transparency, as well as all limitations relating to data retention, data minimisation and data accuracy, thereby ensuring the protection of personal integrity and the confidentiality of all information relating to an individual.
This Privacy Policy applies exclusively to this Website and not to any other websites that may be accessed by the User through links. It is addressed solely to the Users of this Website.
The Website may contain links to websites, services and other Internet resources operated by third parties. In such cases, the Controller shall not be responsible in any way for the content, security or availability of such websites and resources. In particular, the Controller does not verify the privacy policies adopted by such third parties and provides no warranties regarding the protection of privacy and personal data by those parties.
Table of Contents
1. Who is the Data Controller?
2. What are personal data and what is meant by processing?
2.1 What personal data are processed?
3. What are the purposes of the processing?
4. What is the legal basis for processing the User’s data?
5. How are the User’s data processed?
6. To whom may the User’s data be disclosed?
7. Where are the data stored? Are they transferred outside Switzerland?
8. How long are the User’s data retained?
9. What are the User’s rights?
10. Is automated decision-making used?
11. How can I contact the Privacy Officer?
12. Additional Information – Use of Social Networks
13. Amendments
1. Who is the Data Controller?
The Data Controller is:
Compass Asset Management SA
Via Massimiliano Magatti 6
6900 Lugano, Switzerland
E-mail: compliance@compass-am.com
Telephone: +41 (0)91 923 26 22
The Company is represented by the persons vested with signatory authority in accordance with the entries recorded in the Cantonal Commercial Register (CHE-100.956.614).
The list of Data Processors and any authorised persons is kept at the registered office of the Controller and is made available upon request by the data subject.
2. What are personal data and what is meant by processing?
Personal data are any information relating to an identified or identifiable natural person and may provide information concerning that person’s characteristics, habits, personal relationships, and other aspects.
Examples of personal data include, but are not limited to, first name, surname, address or other contact details, an identification number or an online identifier.
Processing means any operation performed on personal data, whether or not by automated means.
Examples of processing include, but are not limited to, the collection, recording, organisation, storage, modification, consultation, deletion or destruction of personal data.
2.1. What personal data are processed?
Users may browse the Website without providing personal data, except for browsing data, as specified below.
Each User of the Website may choose to provide the Controller with limited personal data in order to obtain information regarding the Controller’s services.
Once collected and recorded, the User’s personal data shall be used exclusively for the purposes set out in this Privacy Policy.
The Website may therefore collect, for the purposes described in this Privacy Policy, the following categories of personal data:
Browsing data
The IT systems and software procedures used to operate the Website acquire, during their normal operation, certain personal data whose transmission is inherent in the use of Internet communication protocols.
These data are not collected in order to be associated with identified data subjects; however, by their very nature, they could allow Users to be identified through processing and association with data held by third parties.
Such data include, by way of example:
- IP addresses or domain names of the computers used by Users connecting to the Website;
- URI (Uniform Resource Identifier) addresses of the requested resources;
- the time of the request;
- other parameters relating to the User’s operating system and IT environment.
Further information regarding cookies is available in the Cookie Policy available at:
www.compass-am.com/cookie-policy-en/
Data voluntarily provided by the User
The User’s personal data are collected by the Controller following the User’s submission of a contact e-mail and/or request for information, containing any personal data or contact details (such as, by way of example, first name, surname and e-mail address), as well as any additional information (including information contained in any curriculum vitae submitted) that the User voluntarily includes in the text of the message to be sent, or following telephone contact.
The Company does not intentionally collect, through the Website, personal data deserving special protection and therefore requests that Users refrain from transmitting such categories of data through the tools made available on the Website.
Users are advised that the use of e-mail does not ensure the confidentiality and integrity of data in transit, as many e-mail service providers are located in, or store their data in, countries that do not guarantee an adequate level of protection of personal data. The use of such e-mail services therefore entails the transfer and storage of data in a country that may not ensure an adequate level of protection.
The User releases the Controller from any liability in the event of unauthorised access by third parties to documents and/or personal and/or confidential information transmitted to or received from the Controller by e-mail.
3. What Are the Purposes of the Processing?
The User’s personal data shall be processed for the following purposes:
Browsing the Website, and in particular:
- ensuring the operation of the Website;
- obtaining anonymous statistical information regarding the use of the Website;
- monitoring its proper functioning and identifying anomalies and/or misuse.
Contacting the User following a request submitted by e-mail or telephone, and in particular in order to:
- manage or respond to a question or request;
- send information material or other communications;
- inform the User of changes to the Website or updates to the services;
- provide the best possible service and improve the User’s experience;
- enable the User to exercise his or her rights.
Managing job applications received through the e-mail address published on the Website, and in particular in order to:
- receive curriculum vitae;
- carry out recruitment, assessment, evaluation and personnel selection activities;
- retain CVs for future recruitment requirements.
Legal, administrative and audit purposes, and in particular in order to:
- comply with obligations imposed by applicable laws and regulations;
- carry out legal and regulatory compliance checks;
- satisfy requests received from the competent authorities.
Furthermore, personal data may be processed:
- to enable the Controller to establish, exercise or defend a right before judicial, extrajudicial or administrative authorities;
- to ascertain any liability in the event of alleged cybercrimes committed against the Website or third parties.
4. What Is the Legal Basis for Processing the User’s Data?
Pursuant to Article 6 of the FADP, the Controller shall process the User’s personal data within the applicable legal framework. The applicable legislation is the Swiss Federal Act on Data Protection (FADP).
Where required, and depending on the purpose of the processing activity, the processing of the User’s personal data may be based on one of the following legal grounds or justifications:
- for contacting the User following a submitted request and for managing job applications: the Controller’s overriding interest, consisting in the implementation of pre-contractual and contractual measures (Articles 6 para. 7 and 31 para. 1 FADP);
- with regard to data processed for enabling browsing of the Website, establishing liability in the event of alleged cybercrimes against the Website, administrative or audit purposes, or establishing, exercising or defending legal rights before judicial, extrajudicial or administrative authorities: the Controller’s overriding interest (legitimate interest) pursuant to Article 31 paragraph 2 FADP;
- for processing carried out to comply with legal obligations: compliance with a legal obligation (Article 31 paragraph 1 FADP);
- in certain cases, where necessary, for the performance of a task carried out in the public interest.
Where processing is necessary for the performance of contractual or pre-contractual measures, the provision of personal data is voluntary; however, failure to provide such data shall make it impossible to conclude the contract and to provide the requested service.
Where processing is necessary to comply with a legal obligation, the provision of personal data is mandatory; failure to provide such data shall make it impossible to conclude the contract and to provide the requested service.
Where processing is necessary for the purposes of the Controller’s legitimate interest, such processing shall be carried out only insofar as it does not unduly prejudice the User’s interests, rights and fundamental freedoms and only where the personal data are necessary to achieve the intended purpose. In such cases, the provision of personal data is voluntary.
5. How Are the User’s Data Processed?
In relation to the purposes described above, personal data are processed by means of manual, IT-based and electronic tools, in any event in such a manner as to ensure the security and confidentiality of the data.
The following processing operations may be carried out: collection, recording, storage, organisation, processing, selection, extraction, comparison, interconnection, disclosure, blocking, deletion and destruction.
With regard to data security, specific technical and organisational security measures are implemented to protect personal data and to prevent their loss and/or destruction, improper and/or unauthorised use, access, disclosure and modification, as well as, more generally, any unlawful processing.
6. To Whom May the User’s Data Be Disclosed?
Within the scope of the Controller’s activities and for the purposes described above, the User’s personal data may be shared with:
- Data Processors, duly appointed, providing specific processing or ancillary services on behalf of the Controller. The User may request the updated list of Data Processors at any time;
- Independent Data Controllers to whom personal data may be disclosed pursuant to legal provisions or orders issued by competent Authorities;
- Persons authorised by the Controller to process personal data necessary for carrying out activities strictly related to the provision of the services and who are bound by appropriate legal and contractual confidentiality obligations (for example, employees and/or collaborators of the Controller);
- Competent Authorities, where required for compliance with legal obligations and/or pursuant to requests issued by public authorities.
Third-party service providers are required to comply with a series of technical and organisational security measures, irrespective of their geographical location, including measures relating to:
- information security management;
- information security risk assessment;
- information security safeguards, including, by way of example:
- physical access controls;
- logical access controls;
- protection against malware and hacking;
- data encryption measures;
- backup management and disaster recovery measures.
The above-mentioned third parties shall process the personal data shared pursuant to this provision exclusively for the purposes for which such data were originally collected and, in any event, in accordance with a level of protection at least equivalent to that applicable under Swiss law.
The Controller does not intend to sell or otherwise disclose the User’s personal data to third parties.
7. Where Are the Data Stored? Are They Transferred Outside Switzerland?
All personal data are stored electronically on servers located in Switzerland and shall not be transferred to third countries that do not provide the same level of data protection as the country in which the information was originally collected, unless the conditions set out in Articles 16 and 17 of the FADP are fulfilled.
For the sake of completeness, it should be noted that, pursuant to Articles 16 and 17 of the FADP, personal data may be transferred abroad only where the Federal Council has determined that the legislation of the recipient State or the international organisation ensures an adequate level of data protection, or where one of the following conditions applies:
- the data subject has given his or her consent;
- the disclosure is directly connected with the conclusion or performance of a contract;
- the disclosure is necessary to safeguard an overriding public interest or to establish, exercise or enforce a right before a court or another competent foreign authority;
- the disclosure is necessary in order to protect the life or physical integrity of the data subject or of a third party;
- the data subject has made the personal data generally accessible;
- the data originate from a register provided for by law that is accessible to the public or to persons having a legitimate interest worthy of protection.
As the Controller uses the Google Maps service on its Website, the User’s personal data may be transferred to the United States of America.
More specifically, the transfer of Users’ personal data to the United States is considered adequate under the Swiss Data Protection Ordinance (DPO) of 31 August 2022, Annex 1, provided that the transfer is made to an organisation certified under the Swiss–U.S. Data Privacy Framework.
With regard to the use of the Google Maps service, Users are informed that this functionality is provided by third-party service providers.
As a general rule, the information collected through the use of such services regarding the use of a website is transmitted to the third-party provider’s servers by means of cookies or similar technologies.
Normally, data are transmitted using shortened IP addresses, thereby preventing the identification of individual devices.
To enable Google Maps, the data subject must expressly consent to the loading of third-party scripts on the Website.
8. How Long Are the User’s Data Retained?
In accordance with Article 6 para. 4 of the FADP, the Controller shall retain the User’s personal data in compliance with the principle of necessity of processing and only for the period required to fulfil the purposes described above.
In particular:
- Browsing data: for the duration of the browsing session. Such data shall be deleted immediately after processing.
- Identification and contact data provided when submitting a contact request: for the period necessary to process the request and, in any event, for no longer than six (6) months from the date of the request. Once the User’s request has been processed, the User’s personal data shall be processed in accordance with the Customer Privacy Notice published on the Website.
- Curricula vitae submitted by the User as part of a job application shall be retained for a maximum period of two (2) years from the date of submission.
In any event, the Controller reserves the right to retain the User’s personal data for the period permitted under Swiss law where necessary to protect its legitimate interests.
Where personal data are processed in connection with actual or potential legal proceedings, such data shall be retained for the entire duration of any judicial or extrajudicial proceedings and until the expiry of the applicable limitation periods and any available rights of appeal.
The Controller periodically reviews the data retained in relation to the purposes for which they were collected. Upon expiry of the applicable retention periods, the data shall be deleted or anonymised.
Accordingly, once the applicable retention period has expired, the rights of access, erasure, rectification and data portability may no longer be exercised.
9. What Are the User’s Rights?
Pursuant to the FADP, the Controller recognises the following rights of the User (non-exhaustive list):
- to be subject to transparent processing;
- to obtain confirmation as to whether personal data relating to him or her are being processed;
- to request access to personal data in order to obtain information regarding the purposes of the processing, the recipients to whom the data may be disclosed, the duration of the processing (where possible), and any consequences of processing based on profiling;
- to request the rectification of inaccurate or incomplete personal data;
- to request the erasure of personal data where they are no longer necessary for the purposes for which they were processed;
- to request the restriction of processing in the cases provided for by law;
- to request the transfer of personal data to another controller in a commonly used and machine-readable format, in the cases provided for by law;
- to object to the processing of personal data and, in particular, to object to decisions concerning him or her that are based solely on automated processing, including profiling;
- to lodge a complaint with the competent supervisory authority (in Switzerland, the Federal Data Protection and Information Commissioner – FDPIC);
- to request a declaration that the processing of personal data is unlawful;
- to request that a notation be added to the data indicating that their accuracy is contested.
The User may exercise the above rights by requesting a copy of the personal data processed by the Controller through one of the following channels:
By e-mail:
compliance@compass-am.com
By ordinary mail:
Compass Asset Management SA
Via Massimiliano Magatti 6
6900 Lugano
Switzerland
The Controller shall comply with such requests, withdrawals or objections in accordance with the applicable data protection legislation, unless it is required to retain or process certain personal data due to an overriding interest or for the establishment, exercise or defence of legal claims.
10. Is Automated Decision-Making Used?
The Controller does not subject Users to decisions based wholly or partly on automated processing.
11. How Can I Contact the Privacy Officer?
The Controller has appointed a Privacy Contact Person, who may be contacted at the Controller’s address indicated above or by e-mail at:
The Controller has also appointed a Data Protection Officer, pursuant to Article 10 of the FADP, and has entrusted this role to iuXta SA. The contact details enabling data subjects to contact the Controller quickly and communicate directly and effectively with it are as follows:
12. Additional Information – Use of Social Networks
The Controller, as identified above, manages its corporate accounts on social networks operated by various social media providers and hereby provides the following information regarding LinkedIn.
The Controller uses its LinkedIn account to provide information regarding the Company, its products, services and offerings, as well as current developments, and to communicate with Users.
Users may send messages through the LinkedIn account and may also share or “like” the Controller’s posts.
The Controller processes Users’ profile data (in particular the User’s name) and the related interactions (including the content of messages or comments) for the purpose of handling Users’ enquiries and responding to their requests.
Such processing is carried out within the applicable legal framework pursuant to Article 6 of the FADP and, where required, may be based on the Controller’s overriding interest, consisting in the performance of contractual obligations (Article 31 para. 2 FADP).
Each time a User visits the Controller’s social media account, the relevant social network provider may process personal data.
The social network provider may also place cookies (small files downloaded onto Users’ devices).
The Controller neither controls nor is able to control such processing activities.
Further information regarding the purposes and methods of processing carried out by the relevant social network provider, together with information concerning Users’ rights and the available options for protecting their privacy, may be found in the privacy policies published by the respective social network providers.
13. Amendments
The Controller reserves the right to amend this Privacy Policy at its sole discretion and at any time.
Users will not receive proactive notifications regarding such amendments.
An updated version of this Privacy Policy shall become effective immediately upon publication on the Website, unless otherwise specified.
The User’s continued use of the Website following the effective date of the updated Privacy Policy shall constitute acceptance of such amendments.
However, without the User’s consent, the Controller shall not use the User’s personal information in a manner that is materially different from that stated at the time the personal information was collected.
Effective Date: 5 June 2026
This document also exists in an official Italian version. In the event of any discrepancy or inconsistency between the Italian version and this English translation, the Italian version shall prevail and shall be considered the sole official and legally binding text.
