1. General
PQ Technologies AG attaches great importance to data protection and therefore observes the legal provisions of the Federal Data Protection Act (FADP) and the Data Protection Ordinance (DPO). This data protection declaration contains details of how PQ Technologies AG collects and processes personal data and informs the persons concerned of their rights under the data protection regulations.
This declaration covers personal data processing in connection with both the website www.pqt.ch and the operation of our software product Nucleus, the Compliance & Risk Intelligence Engine of PQ Technologies AG. Specific provisions regarding Nucleus are set out in Section 13.
“Personal data” means all information that relates to an identified or identifiable natural person;
“Processing” means: any handling of personal data, regardless of the means and procedures used, in particular the acquisition, storage, use, modification, disclosure, archiving, deletion or destruction of personal data.
With these instructions, PQ Technologies AG fulfils its duty to provide information in the context of the collection and processing of personal data from data subjects.
2. Origin of Personal Data
2.1 General
PQ Technologies AG processes the personal data that PQ Technologies AG receives from the data subjects. It also obtains data from service providers (e.g. public registers) which the company requires for the provision of the service and/or for legal or regulatory reasons.
2.2 Contact Form
Via the contact form, the data fields specified there (name, company, telephone number, e-mail, message) as well as information on the time of use are collected and processed for processing and response. The data is transmitted to PQ Technologies AG, which is named and identified in the respective contact form.
The processing of the data is necessary to establish contact.
2.3 Nucleus
Within the Nucleus software, personal data is processed on behalf of and on the documented instructions of the respective client (e.g. a financial institution). The categories of data, the legal roles of the parties involved, the deployment model and the retention rules are described in Section 13.
3. Scope of the Personal Data Processed
PQ Technologies AG processes as little personal data as necessary. These are mainly related to the services you have requested or agreed with us.
The categories of personal data processed by PQ Technologies AG include data in connection with business relationships with customers or potential customers, employee data, supplier data, data when using the website, and — where PQ Technologies AG provides support, maintenance or related services for Nucleus — data within client deployments of Nucleus (see Section 13).
4. Purpose of the Processing
PQ Technologies AG only processes data that is necessary to achieve a specific purpose. Personal data is processed for the following purposes:
- In connection with the provision of the customer business or the products and services offered, including the operation, maintenance and support of Nucleus on behalf of clients
- In connection with the processing and administration of contractual relationships with customers, employees, suppliers, etc.
- To maintain contacts and communication
- In connection with the provision of services
- To fulfil legal or regulatory obligations
- Marketing activities (e.g. sending specialist information, event invitations, etc.)
5. Data Protection Principles
5.1 Principles
PQ Technologies AG processes:
- Personal data in compliance with the Swiss Federal Data Protection Act (FADP) and the Ordinance on Data Protection (DPO);
- Data lawfully, in good faith and proportionately.
In addition, PQ Technologies AG ensures that the data is correct and complete. The data is only processed for the identifiable purpose.
5.2 Data Security
PQ Technologies AG attaches great importance to data security. In addition to complying with legal requirements, PQ Technologies AG takes precautions to protect your privacy (e.g. implementation of technical and organisational security measures).
With the technical and organisational measures PQ Technologies AG (or the commissioned service providers) ensures that personal data:
- Are only accessible to authorised persons
- Are available when they are needed
- Are not changed unauthorised or unintentionally
- Are processed in a comprehensible manner
6. Basics for Data Processing
Data processing depends on the services and products that PQ Technologies AG may provide to you, or the purpose for which the personal data is processed, and is based on the following:
6.1 Business Performance
To enter into, conclude or perform a contract or business relationship with you or to fulfil PQ Technologies AG’s obligations under such contract or business relationship.
If applicable:
- To safeguard the legitimate interests of PQ Technologies AG (such as statistics, planning or product development, business decisions, monitoring and controlling risks, ensuring IT security, IT operations and buildings as well as plant security, business auditing, marketing, comprehensive support, advice and information on the range of services, preparation and provision of tailor-made services — insofar as no objection has been made)
- Safeguarding the interests and securing the claims of PQ Technologies AG, clients and employees
6.2 Legally
To fulfil legal or regulatory obligations of PQ Technologies AG or the performance of tasks in the public interest.
6.3 Consent
If the processing of personal data requires consent by law, PQ Technologies AG obtains this consent from the person concerned. The consent given can be revoked at any time. Such a revocation is only effective upon receipt by PQ Technologies AG and does not affect the lawfulness of the processing of personal data until the revocation. There may be reasons (e.g. due to a law) which make it necessary to process the personal data despite the revocation. A revocation may lead to the restriction of certain services or the termination of the business relationship.
7. Duration of the Storage of Personal Data
The duration of the storage of personal data is determined by legal retention obligations or the purpose of the respective data processing. In principle, PQ Technologies AG stores personal data for the duration of the business relationship or contract period and subsequently for at least a further ten years. This corresponds to the period of time within which legal claims can be asserted against PQ Technologies AG. Ongoing or anticipated legal, tax or supervisory proceedings may result in storage beyond this period.
For personal data processed within Nucleus on behalf of clients, retention is determined by the respective client as controller. See Section 13.6.
8. Profiling and Automated Individual Decision-Making
PQ Technologies AG does not perform profiling on its own behalf and does not make automated individual decisions that produce legal effects concerning data subjects or similarly significantly affect them.
Nucleus, the software provided by PQ Technologies AG to its clients, performs automated analyses (in particular rule-based and AI-supported risk scoring, alerting and classification of documents and transactions) on data the client provides, in order to assist the client’s compliance review. PQ Technologies AG acts here as a processor on behalf of the client (the controller). All such outputs are intended for review by qualified personnel of the client; no final decision producing legal effects on a data subject is taken by Nucleus without human involvement. Further details on Nucleus are set out in Section 13.
9. Intended Recipients of Personal Data
At PQ Technologies AG, only those persons process personal data who require it to fulfil contractual or legal obligations.
PQ Technologies AG only discloses customer data to service providers and third parties in the following cases (depending on the type of products and services purchased):
- For the execution of orders, use of products or services
- Due to legal obligations, legal justification or official orders
Service providers and third parties as recipients of personal data may be, for example:
- Order processors and other service providers who process personal data on behalf of and for the purposes of PQ Technologies AG
- Public bodies (e.g. authorities), insofar as this is provided for by a legal or official obligation
Personal data processed within Nucleus is not disclosed by PQ Technologies AG to third parties; the recipient framework for such data is set out in Section 13.5.
10. Data Transmission Abroad
As a matter of principle, data is not transferred abroad. Should personal data have to be transferred abroad, this will take place in compliance with the legally prescribed provisions and where this is necessary for the fulfilment of the contract.
Nucleus is deployed within the client’s own infrastructure. Personal data processed in Nucleus therefore generally does not leave that infrastructure, and PQ Technologies AG does not transfer such data abroad.
11. Your Rights
Provided there is no legal obligation to the contrary, you have the right to request information, correction, transfer, prohibition of certain personal data processing, restriction, deletion, prohibition of disclosure to third parties, revocation of consent and objection to your personal data.
Requests for information should be sent together with a legible copy of a valid official form of identification (e.g. passport, identity card) to the address given under point 15.
The rights of deletion and objection are not unrestricted rights. Overriding interests may make further processing necessary. PQ Technologies AG will examine each individual case and inform you of the result.
If the provision of information, the issuing or transfer of data involves disproportionate effort, PQ Technologies AG may insist on a contribution to costs up to a maximum of CHF 300.
For personal data processed within Nucleus on behalf of a client, the respective client is the controller and the primary point of contact for the exercise of data subject rights. PQ Technologies AG supports the client in handling such requests in accordance with the applicable data processing agreement.
12. Data Relating to the Internet Presence
12.1 General Information
The following information explains how the Company processes data on the occasion of its Internet presence.
12.2 Cookies
The internet pages of PQ Technologies AG do not use any cookies.
12.3 Collection of General Data and Information in Connection with the Internet Presence
The website of PQ Technologies AG collects general data and information whenever a data subject or automated system calls up the website. This general data and information is stored in the log files of the server. The following can be recorded:
- Browser types and versions used
- The operating system used by the accessing system
- The website from which an accessing system accesses our website (so-called referrer)
- The sub-websites which are accessed via an accessing system on our website
- Date and time of access to the website
- Internet protocol address (IP address)
- Internet service provider of the accessing system
- Other similar data and information that serve to avert danger in the event of attacks on the information technology systems of PQ Technologies AG
When using these general data and information, PQ Technologies AG does not draw any conclusions about the data subject. Rather, this information is needed to:
- Deliver the contents of the PQ Technologies AG website correctly
- Optimise advertising
- Ensure the long-term functionality of the information technology systems and technology of the PQ Technologies AG website
- In the event of a cyber-attack, to provide law enforcement authorities with the information necessary for prosecution
PQ Technologies AG analyzes these anonymously collected data and information statistically, with the aim of increasing the data protection and data security of PQ Technologies AG, and ultimately ensuring an optimal level of protection for the personal data we process. The anonymous data of the server log files are stored separately from any personal data provided by a data subject.
13. Data Relating to Nucleus
13.1 Overview
Nucleus is the Compliance & Risk Intelligence Engine of PQ Technologies AG. It supports clients — typically financial institutions and other regulated entities — in fulfilling their compliance and risk obligations by validating compliance profiles, transactions, documents and complex structures against client-specific standards.
13.2 Roles of the Parties
Nucleus is operated by the client within the client’s own infrastructure. With respect to personal data processed inside a Nucleus deployment, the client (e.g. the financial institution) is the controller and determines the purposes and means of the processing.
PQ Technologies AG does not access personal data within a client’s Nucleus deployment in the ordinary course of business. Where PQ Technologies AG is expressly engaged by the client to provide support, maintenance, troubleshooting or similar services that involve access to personal data, PQ Technologies AG acts as a processor on behalf of the client and exclusively on the client’s documented instructions, under a separate data processing agreement.
For the relationship between the client and the underlying data subjects (e.g. customers of a financial institution), the client’s own privacy notice and contractual arrangements apply.
13.3 Deployment and Data Location
Nucleus is deployed on-premise within the client’s own IT infrastructure. Personal data processed in Nucleus is stored and processed within that infrastructure. PQ Technologies AG does not host, mirror or replicate this data on its own systems.
13.4 Categories of Personal Data Processed in Nucleus
Depending on the modules activated by the client, Nucleus may process the following categories of personal data:
- Data concerning persons covered by compliance profiles (e.g. customers, counterparties, beneficial owners of the client): identification data, contact data, nationality and residence information, document data (e.g. identification documents), beneficial ownership and ownership-structure information, transaction data, risk-relevant attributes and any further information made available by the client for compliance and risk assessment purposes.
- Data concerning operator users (employees of the client who use Nucleus): identifiers provided through the client’s single sign-on (SSO) system (e.g. e-mail address, employee identifier, name), role and permission information, and audit-log entries recording actions performed by the user in the system.
The actual scope of personal data processed in any given deployment is determined by the client.
13.5 Automated Analyses and AI Components
Nucleus uses a combination of rule-based logic and AI-supported analytics — such as risk scoring, anomaly detection, document classification and information extraction — to assist the client’s compliance review.
All AI components used for the processing of personal data within Nucleus are operated within the client’s deployment. No personal data processed in Nucleus is transmitted to third-party AI providers or other external services by PQ Technologies AG.
All outputs of these automated analyses are intended for review by qualified personnel of the client. No final decision producing legal effects on a data subject or similarly significantly affecting a data subject is taken by Nucleus without human involvement on the client’s side.
13.6 Retention and Deletion
Retention periods for personal data processed in Nucleus are determined by the client in accordance with its own legal, regulatory and contractual obligations. Personal data is deleted in accordance with the client’s instructions and retention policies and, at the latest, in accordance with the deletion and handover procedures agreed for the end of the contractual relationship between the client and PQ Technologies AG.
13.7 Recipients
Personal data processed in Nucleus is not disclosed by PQ Technologies AG to third parties. Disclosure of such data to third parties (e.g. authorities, auditors, group entities) is determined by the client as controller.
13.8 Data Subjects’ Rights
For personal data processed in Nucleus, the client (e.g. the financial institution) is the responsible controller and primary point of contact for the exercise of data subject rights (information, correction, deletion, restriction, objection, data portability, revocation of consent). Data subjects are kindly requested to address such requests to the respective client. PQ Technologies AG supports the client in handling such requests as required under the applicable data processing agreement.
Operator users (employees of the client) may, in addition, contact PQ Technologies AG at the address given under Section 15 for any concerns specifically relating to the operation of Nucleus by PQ Technologies AG.
14. Subject to Change
This data protection declaration was last updated in May 2026 and generally covers the processing of personal data by PQ Technologies AG.
PQ Technologies AG reserves the right to adapt the data protection declaration at any time in compliance with the requirements of data protection law. The current version of this data protection declaration is available on the PQ Technologies AG website.
15. Contact Details
The office responsible for data protection issues is:
PQ Technologies AG
Contact point for data protection
Konradstrasse 12
8005 Zurich
Switzerland
+41 44 253 67 67
info@pqt.ch
Website: www.pqt.ch
Data protection concerns can be addressed in writing to the above contact address.
If you are not satisfied with the response from PQ Technologies AG, you have the right to lodge a complaint with the Swiss data protection authority: https://www.edoeb.admin.ch/edoeb/de/home/meldeportale.html