Privacy Policy for ViaVadis SA

1. Who we are

ViaVadis SA (“ViaVadis”, “we”, “us” or “our”) is a Swiss professional trustee and advisory firm based in the Canton of Vaud, Switzerland. ViaVadis SA is the controller responsible for the personal data described in this Privacy Policy, unless another entity is identified as the controller for a particular processing activity.

Registered office: Regus Nyon Business Park, Route de Crassier 7, 1262 Eysins, Vaud, Switzerland. Email: contact@viavadis.com. Website: https://www.viavadis.com.

This Privacy Policy explains how we collect, use, disclose, store and protect personal data in connection with our website, communications, business development activities and our trustee, fiduciary, administrative and advisory services.

We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and its implementing ordinance. Where the EU General Data Protection Regulation (GDPR) applies to a particular processing activity, we also process personal data in accordance with the GDPR.

2. Personal data we collect

Depending on your relationship with ViaVadis, we may collect and process the following categories of personal data:

● Identification and contact data, such as name, date of birth, nationality, address, telephone number, email address and identification documents.

● Professional and business information, such as employer, position, business contact details, professional background and relationship to a client, trust, company or other structure.

● Client due diligence and compliance information, including information required for identification, KYC/AML, sanctions, politically exposed person (PEP), conflict, reputation, source-of-wealth and source-of-funds checks.

● Family, beneficiary and relationship information relevant to a trust, estate, succession, governance or private-client mandate.

● Financial, tax, banking, payment and asset-related information where relevant to our services or legal and regulatory obligations.

● Mandate and correspondence information, including instructions, documents, meeting notes, emails and other information provided to us or generated in the course of providing services.

● Website and technical data, such as IP address, browser type, device information, date and time of access, pages viewed, referring website and cookie or analytics identifiers.

● Marketing and event information, including newsletter subscriptions, event registrations, preferences and communications with us.

● Recruitment information, if you apply for a role with ViaVadis.

Depending on the circumstances, some information we process may constitute sensitive personal data under applicable law, for example information concerning health, religious or political views, the intimate sphere, biometric or genetic data, or certain social-security, administrative or criminal proceedings. We process sensitive personal data only where it is relevant to our services or obligations and permitted by law.

3. How we collect personal data

We collect personal data directly from you when you contact us, subscribe to communications, attend an event, apply for a role, enter into or are connected with a client relationship, or otherwise communicate with ViaVadis.

We may also receive personal data from clients, settlors, beneficiaries, family members, advisers, banks, asset managers, professional intermediaries, service providers, public authorities, registers, sanctions and compliance databases, publicly available sources and other third parties where this is relevant to our work or legal obligations.

4. Why we process personal data

We may process personal data for the following purposes:

● providing trustee, fiduciary, administrative and advisory services;

● conducting client onboarding, identification, AML/KYC, sanctions, PEP, conflict and reputation checks;

● administering trusts, companies, foundations and other structures and carrying out associated governance, banking, investment oversight, reporting and record-keeping activities;

● communicating with clients, beneficiaries, advisers, counterparties and other relevant persons;

● performing contracts and taking steps at your request before entering into a contract;

● complying with legal, regulatory, supervisory, tax, accounting, record-keeping and reporting obligations;

● protecting ViaVadis, its clients and other persons against fraud, misuse, security threats and legal or regulatory risk;

● managing our business, professional relationships, invoicing, accounting and internal administration;

● responding to enquiries and managing business-development relationships;

● sending newsletters, invitations and other communications where permitted by law;

● operating, securing and improving our website and digital services; and

● establishing, exercising or defending legal claims.

Under the FADP, processing is carried out in accordance with the applicable data-protection principles and, where required, on a lawful basis. Where the GDPR applies, the relevant legal basis may include performance of a contract, compliance with a legal obligation, our legitimate interests, protection of vital interests or your consent, depending on the circumstances.

5. Client, trustee and fiduciary relationships

In connection with a client, trust or fiduciary relationship, we may process information not only about the person instructing us, but also about settlors, protectors, beneficiaries, family members, directors, shareholders, advisers, counterparties and other persons connected with the relevant structure or mandate.

Because professional trustees are subject to legal, regulatory and compliance obligations, we may be required to collect and retain information even where the relevant individual has not provided it directly to us. Where required and practicable, we provide the relevant information to affected persons in accordance with applicable data-protection law.

6. Website use, cookies and analytics

6.1 Server and technical data

When you visit our website, our hosting and technical service providers may automatically process technical information required to deliver the website, maintain security and diagnose errors. This can include IP address, date and time of access, requested pages or files, browser and device information, operating system, referring page and related log information.

6.2 Cookies

Our website may use cookies and similar technologies. Some cookies are necessary for the operation and security of the website. Other cookies, including analytics or marketing cookies, are used only where permitted by applicable law and, where required, with your consent. You can manage your choices through our cookie banner or your browser settings.

6.3 Google Analytics and Google Tag Manager

Where enabled, we use Google Analytics to understand how visitors use our website and Google Tag Manager to manage analytics and related tags. These services may process technical and usage information such as device data, pages viewed, approximate location, referral source and interaction data. Non-essential analytics are activated only where permitted by law and, where required, after consent. You may withdraw or change your cookie choices at any time through the available cookie settings.

7. Email, Microsoft 365 and online meetings

ViaVadis uses Microsoft 365 services, which may include Outlook, Exchange Online, SharePoint, OneDrive and Microsoft Teams, for email, document management, collaboration, communications and online meetings. In using these services, ViaVadis and Microsoft may process contact information, message and document content, meeting metadata, authentication information, technical logs and other information relevant to the service being used.

Microsoft may process certain data as a service provider to ViaVadis and certain limited data for its own purposes in accordance with its own privacy documentation. Depending on the service and configuration, data may be processed in Switzerland, the European Economic Area or other countries. Where required, ViaVadis relies on recognised transfer mechanisms and contractual safeguards.

If an online meeting is to be recorded, participants will be informed in advance and consent will be obtained where required.

8. Newsletters, events and business development

If you subscribe to a newsletter, register for an event or otherwise ask to receive information from us, we may process your name, contact information, organisation, preferences and related interaction data for those purposes. Where required, marketing communications are sent on the basis of your consent. You can unsubscribe at any time using the unsubscribe mechanism in the communication or by contacting us.

If the communications platform we use measures delivery, opens or link interactions, such information may be used to understand engagement and improve our communications, where permitted by law.

9. Recruitment

If you apply for a role with ViaVadis, we may process the information contained in your application and communications for the purpose of assessing your application, communicating with you and, where appropriate, taking steps toward an employment relationship. We may retain unsuccessful applications for a limited period where permitted by law or with your consent.

10. Disclosure of personal data

We treat personal data as confidential. We may disclose personal data where this is necessary for our services, our legal or regulatory obligations, or the operation of our business. Recipients may include:

● ViaVadis employees, directors and authorised contractors who require access for their role;

● professional advisers, lawyers, tax advisers, auditors, accountants and compliance specialists;

● banks, custodians, asset managers, investment advisers, insurers and other financial-service providers relevant to a mandate;

● corporate, trust, fiduciary, administrative, IT, cloud, hosting, document-management, communications and security service providers;

● public authorities, courts, regulators, supervisory bodies, tax authorities and law-enforcement bodies where disclosure is required or permitted by law;

● other parties to whom disclosure is necessary to perform a mandate, protect legal rights, manage risk or implement client instructions.

Service providers that process personal data on our behalf are required to handle it in accordance with applicable law and appropriate contractual and security requirements.

11. Transfers of personal data abroad

Because our clients, counterparties and service providers may be located internationally, personal data may be transferred to or accessed from countries outside Switzerland.

Where the recipient country is recognised by the Swiss Federal Council as providing an adequate level of data protection, personal data may be transferred in accordance with that adequacy decision. Where an adequate level of protection is not recognised, we use an appropriate safeguard or another lawful basis where required, such as recognised standard contractual clauses, contractual protections or an applicable legal exception.

For transfers from Switzerland to the United States, the Swiss-U.S. Data Privacy Framework may provide an adequacy basis where the recipient US organisation is certified under that framework. Other transfers to the United States are assessed under the applicable Swiss and, where relevant, EU cross-border transfer rules.

12. Retention of personal data

We retain personal data for as long as necessary for the purposes for which it was collected and to meet contractual, legal, regulatory, accounting, tax, compliance, evidentiary and record-keeping obligations.

Retention periods vary according to the nature of the information and the relevant relationship. Certain business, client and compliance records may need to be retained for 10 years or longer where required by applicable Swiss law, regulation, supervisory requirements or legitimate legal needs. When personal data is no longer required, it is deleted, anonymised or otherwise securely disposed of, subject to applicable retention obligations.

13. Data security

We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. These measures may include access controls, authentication, encryption, secure storage, confidentiality obligations, backups, monitoring and internal policies and procedures.

No method of transmission or storage can be guaranteed to be completely secure. In particular, ordinary email and internet communications may involve security risks. Please avoid sending highly sensitive information by unsecured email unless appropriate protective measures have been agreed.

14. Your rights

Subject to applicable law and any relevant exceptions, you may have rights in relation to your personal data, including the right to:

● ask whether we process personal data about you and obtain access to it;

● ask us to correct inaccurate or incomplete personal data;

● request deletion or restriction of processing in circumstances provided by law;

● object to particular processing, including direct marketing;

● withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal;

● receive or request transfer of certain personal data in a commonly used format where applicable; and

● raise a concern with the competent data-protection authority.

These rights are not absolute. In particular, ViaVadis may be required or permitted to retain or continue processing information because of trustee, fiduciary, AML, regulatory, contractual, evidentiary or other legal obligations.

In Switzerland, the competent federal authority is the Federal Data Protection and Information Commissioner (FDPIC).

15. Third-party websites and social media

Our website may contain links to third-party websites or social-media platforms, including LinkedIn. If you follow such a link, the third party will process personal data under its own terms and privacy policy. ViaVadis is not responsible for the privacy practices of third-party websites or platforms.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our activities, technology, service providers, legal obligations or regulatory requirements. The current version will be published on our website with the date of the latest update.

17. Contact

If you have questions about this Privacy Policy or wish to exercise a data-protection right, please contact:

ViaVadis SA

Regus Nyon Business Park

Route de Crassier 7

1262 Eysins

Vaud, Switzerland

Phone: +41 79 929 7289

Email: contact@viavadis.com

Website: http://www.viavadis.com

If, after contacting us, you believe your data-protection concern has not been adequately addressed, you may also raise it with the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland (www.edoeb.admin.ch).

Date: September 2026