Privacy Policy
Last updated: 29 September 2026 · WurthAG
1. Who We Are
WurthAG (“WurthAG”, “we”, “us”) operates this website and the services described in this policy and is the controller responsible for processing your personal data. Our company details are listed in our Legal notice.
This Privacy Policy explains how we collect, use, store, and share your personal data when you use our website, Savings Vaults, Current Account, WurthAG Card, and related financial services.
2. Data Protection Framework
We process personal data in line with the Swiss Federal Act on Data Protection (FADP) and, where they apply to our services, the EU General Data Protection Regulation (GDPR) for customers in the EU/EEA and the UK GDPR for customers in the United Kingdom.
You can reach our data protection contact at support@wurthag.com.
3. What Data We Collect
3.1 Data You Provide Directly
- Contact data: Full name, email address, phone number, country of residence
- Identity verification: Date of birth, nationality, gender, residential address and a copy of your government-issued ID document (passport, national ID card or driving licence)
- Account and transaction data: Vault balances and interest, card balance, top-ups and card transactions, transfer instructions (recipient name and IBAN, amount, reference) and your transaction history
- Messages and callback requests: Messages and callback requests you send us (support chat, email, or the callback forms on the sign-in and sign-up pages) and our phone calls with you
3.2 Data We Collect Automatically
- Security logs: IP address, browser type, the pages you request, sign-in times and failed sign-in attempts, kept to protect your account
- Cookies and similar technologies: See our Cookie Policy for details
3.3 Data from Introducers
- Introducers: If a partner introduced you to us, we receive from that partner your name, email address and phone number and, where provided, details of your request (such as the amount and term you are interested in, or a message)
4. Why We Process Your Data
| Purpose | Legal Basis |
|---|---|
| Providing and managing your Savings Vaults, Current Account, and WurthAG Card | Performance of contract (Art. 6(1)(b) GDPR) |
| Verifying your identity before we open your account | Performance of contract (Art. 6(1)(b) GDPR); legitimate interest in preventing fraud (Art. 6(1)(f) GDPR) |
| Calculating and crediting daily interest on your deposit at rates up to 4.4% p.a. | Performance of contract |
| Processing your transfers, the interest top-ups to your WurthAG Card and your card transactions | Performance of contract |
| Fraud prevention and the security of your account | Legitimate interest (Art. 6(1)(f) GDPR) |
| Compliance with applicable legal obligations | Legal obligation |
| Replying to messages and callback requests you send us (support chat, email, or the callback forms on the sign-in and sign-up pages), including our phone calls with you | Performance of contract / Legitimate interest |
| Following up on a request an introducer passed on to us, and telling the introducer its status | Legitimate interest (Art. 6(1)(f) GDPR) |
5. Data Sharing
We share personal data only where necessary and lawful:
- Hosting provider: To operate our website and services and to store your data on our behalf.
- Banks that execute your transfers: When you instruct a transfer, the details needed to carry it out (your name, the recipient’s name and IBAN, the amount and the reference).
- Payment processors: For WurthAG Card transactions (Visa/Mastercard network).
- Introducers: If a partner introduced you to us, the status of your request, including whether and when your account was opened and received its first deposit. We do not share your identity documents, balances or transactions with introducers.
- Public authorities: Only where we are legally required to disclose data.
We never sell your personal data. We do not share data with advertisers, data brokers, or any third party for their own marketing purposes.
6. International Data Transfers
Where personal data is transferred to a country outside Switzerland and the EU/EEA that does not offer an adequate level of data protection, we ensure appropriate safeguards through Standard Contractual Clauses (SCCs) or equivalent mechanisms.
7. Data Retention
- Account data: Retained for the duration of your account relationship plus 10 years (statutory record retention requirements).
- Identity documents: Retained for 10 years after account closure.
- Transaction records: 10 years (statutory record retention requirements).
- Security logs: Only as long as needed to protect your account.
8. Your Rights
Under applicable data protection law, you have the right to:
- Access: Request a copy of all personal data we hold about you.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Request deletion of your data (subject to legal retention obligations).
- Restriction: Limit how we process your data in certain circumstances.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interest.
To exercise any of these rights, contact us at support@wurthag.com. We respond within one month.
9. Security Measures
We protect your data with:
- Encrypted connections (TLS) for all data in transit
- Password-protected account access
- Automatic sign-out after 30 minutes of inactivity
- Employee access controls with least-privilege principle and audit logging
10. Children
WurthAG services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a person under 18, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or in legal requirements. We publish material changes on this page before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.
12. Contact and Complaints
Data protection contact: support@wurthag.com
Company details: See our Legal notice
Complaints: You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), with the data protection authority in your EU/EEA country of residence or, in the United Kingdom, with the Information Commissioner’s Office (ICO).