Switzerland Privacy Notice

Last Updated: 27/08/2026

 

1. Purpose

Davies Group Limited with its registered office at 5th Floor, 20 Gracechurch Street, London, EC3V 0BG, United Kingdom, and its entities and subsidiaries (hereinafter referred to as ‘Davies Group’) is committed to being transparent about how it processes your personal data.

The purpose of this Privacy Notice is to outlines how Davies Group will collect, hold, process, and share your personal data, to assist you in making informed decisions when using our website and/or accessing our products and services.

The objective of this Privacy Notice is to ensure transparency in the handling of personal data and to support compliance with applicable Swiss data protection requirements, including the Swiss Federal Act on Data Protection, as amended, and its implementing ordinances, including the Data Protection Ordinance, where applicable.

 

2. Scope

This Privacy Notice applies to all Davies entities, including all regulated entities, in the following territories:

Jurisdiction
Switzerland

 

In this Privacy Notice, the terms ‘we’, ‘our’ or ‘us’ are used to refer to Davies Group, who are the controller or processor responsible for processing your personal data.

 

3. Definitions

The following key terms and definitions are used in this Privacy Notice and should be interpreted in accordance with applicable privacy and data protection laws.

Personal Data Data relating to an identified natural person or a natural person who can be identified directly or indirectly, including by reference to identifiers such as name, voice, image, identification number, electronic identifier, geographical location, or one or more physical, physiological, economic, cultural or social characteristics. Personal data includes Sensitive Personal data and Biometric Data.
Sensitive Personal Data Sensitive personal data means personal data relating to a natural person’s religious, philosophical, political or trade union-related views or activities; data relating to health, the private sphere, or affiliation to a race or ethnicity; genetic data; biometric data that uniquely identifies a natural person; data relating to administrative or criminal proceedings or sanctions; and data relating to social assistance measures.
Data Controller / Controller Entity responsible for determining how personal data is processed.
Data Processor / Processor Individual or entity processing personal data on behalf of the Controller.
Data Retention The practice of keeping data for a specified period, defined by legal and business requirements, after which it is securely deleted.
Data Subject Rights Data Subject Rights means the rights available to individuals under applicable Swiss data protection law, including the right to request information about the processing of personal data (right of access), request rectification or deletion of personal data, request restriction or objection to processing in certain circumstances, request data disclosure or transfer where applicable, and to seek legal remedies or submit complaints to the competent supervisory authority.
International Transfers / Cross-Border Transfers Movement of personal data outside the Switzerland under strict security controls to ensure compliance with data protection standards.

 

4. The types of personal data we collect

We collect and process the following types of personal data:

• When you browse our website, we use cookies to collect usage data, which may include, but is not limited to, your IP address, browser type/version, browsing behaviour on our site (including the pages that you visit, the time spent on those pages and the date and time of your visit) and your geolocation data. More information about the types of cookies we use and our reasons for using them can be in our Cookie Policy.
• Personal identifiers, contact details, and characteristics, such as your name, country of residence, address, phone number and email address.
• Transaction Data includes details about payments to and from you and other details of forensic accounting services which you have instructed us to provide.
• Due Diligence and Anti-Money Laundering (AML) Data, including documentation and information required for client onboarding, identity verification, and screening checks (e.g. passport details, national identification numbers, or information about political exposure or criminal convictions, where legally required).
• Legal and Contractual Information, including copies of correspondence, signed contracts, declarations, or dispute resolution materials containing personal identifiers, where necessary for fulfilling legal obligations or maintaining business records.
• Sensitive Categories of personal data including health and/or medical diagnosis information, which may be held, used, and processed for the purpose of providing the services offered by Davies Group.
• We may collect personal data relating to children, but only if consent has been obtained (where required) from a parent or guardian, and the information is relevant to the products and services we provide.
• Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.

 

5. Where we obtain your personal data from

The personal data we process may be collected from a variety of sources including, but not limited to:

• Experts.
• Fraud prevention agencies and organisations.
• Industry regulators, government authorities, supervisory bodies, and ombudsman services, including (where applicable) data protection authorities, financial regulators, and dispute‑resolution bodies that oversee our industry or operations.
• Insurance companies.
• Insurance industry databases.
• Intermediaries, such as claims management companies.
• Law enforcement agencies.
• Loss adjusters and claims investigators.
• Other third parties.
• Our clients.
• Our website cookies.
• Social media.
• Public sources.
• Third party data providers/search systems.
• Your Insurer/Underwriter.
• Send information to us as a part of our investigations into an investigation you have asked us to perform or an insurance claim you have made.
• Complete any form or create an account on our website i.e. direct interactions.
• Subscribe to our publications.
• When you subscribe to our publications, request to receive marketing materials, or provide feedback such as comments on our website blogs or articles.

During the course of providing our services, we may also collect personal data from you directly, for example when the information is needed to progress your claim.

 

6. How we use your personal data

The purpose for which we will use personal data will depend on your relationship with our organization.

We may use personal data for the following purposes:

• To provide and manage our services, including claims handling, insurance support, and consulting services etc.
• To manage our relationship with clients and business partners.
• To comply with legal and regulatory obligations.
• To protect our business, systems, and data (including fraud prevention, security monitoring, complaint handling, maintaining or servicing accounts, operating user accounts for security purposes, providing customer service, processing or verifying customer information, processing payments, providing analytics services, providing storage, or providing similar services;) and to improve our services, systems, and customer experience.
• To manage recruitment and employment processes.
• To send marketing communications (where permitted by law).

We process personal data based on the lawful bases set out under applicable data protection laws.

 

7. Our grounds for processing your personal data

We may collect, use, disclose, store, transfer or otherwise process your personal data in accordance with applicable Swiss data protection law, including the Swiss Federal Act on Data Protection, where the processing complies with data protection principles and, where required, is justified by your consent, an overriding private interest, an overriding public interest, or by law. We may process your personal data in the following circumstances:

  • Consent – you have given clear consent for us to process your personal data for a specific purpose. Please note – for any processing we undertake which relies on your consent, you are able to remove your consent at any time by contacting our Data Protection Officer at DPO@davies-group.com.
  • Contract – where processing is directly connected with entering into, managing, or performing a contract with you, or taking steps at your request before entering into a contract.
  • Compliance with law – where processing is necessary for us to comply with applicable legal, regulatory, tax, accounting, employment, social security, social protection, or other legal obligations.
  • Overriding private interests – where processing is necessary for our legitimate and overriding private interests, provided that such interests are not outweighed by your personality rights or fundamental rights. This may include managing our business operations, providing and improving services, maintaining security, preventing fraud, managing client relationships, establishing, exercising or defending legal claims, and protecting our rights and interests.
  • Overriding public interests – where processing is necessary for an overriding public interest, including regulatory, legal, security, public protection, or similar purposes.
  • Research, planning and statistics – where processing is carried out for purposes not related to specific individuals, including research, planning or statistical purposes, and where appropriate safeguards are applied, such as anonymising the data as soon as the purpose permits and publishing results only in a manner that does not identify individuals.
  • Publicly available data – where the personal data has been made generally accessible by you and you have not explicitly prohibited processing, subject always to applicable Swiss data protection principles.

 

8. Change of purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another purpose and that further processing is compatible with the original purpose.

If you would like an explanation of how the processing for the new purpose is compatible with the original purpose, you may contact us.

If we need to use your personal data for a purpose that is not compatible with the original purpose, we will inform you where required under applicable Swiss data protection law and explain the legal ground or justification that allows us to do so.

Please note that we may process your personal data without further notice or consent where this is required or permitted by applicable law, or where an exception to the duty to provide information applies. This may include, for example, processing necessary for fraud prevention, compliance with legal obligations, investigations, or the establishment, exercise or defence of legal claims.

 

9. Automated decision-making and profiling

In some circumstances, we may use automation technologies, AI systems and, where relevant, profiling tools to support the processing of personal data, improve operational efficiency, and enhance user experience. These technologies are used to assist internal workflows, customer interactions and data analysis, and are not currently used to make decisions about you without human involvement. Our current use of automation technologies includes:

• Robotic Process Automation (RPA) – Where virtual workers automate the copying and pasting of information from one system into another.
• Self-Service Platforms – Allows humans to directly interact with an RPA process, enabling human-in-the-loop processing of information.
• Artificial Intelligence (AI) and Machine Learning – To enable virtual workers to learn and understand the data presented and improve effectiveness.
• Intelligent Automation Digital Assistant – An AI supervisor that automatically manages, tracks, and orchestrates virtual worker schedules and activities.
• Computer Vision/Optical Character Recognition – Offers pattern matching within images and can be used to interpret complicated language-based text recognition.
• Natural Language Processing – Translates/extracts human language into computer readable information (think “Hey Siri”) for the purpose of classifying information.
• Conversational AI – Uses AI and Natural Language Processing to enable real-time conversations with customers via the use of chatbots.
• API End-points – Uses virtual workers to bridge the gap between old systems and new ones by copying and pasting information across.

We do not anticipate that any of the automation technologies described above will produce legal or similarly significant effects on you, however if this was to change in the future, we would only do so where it is:

• Necessary for the entry into or performance of a contract; and
• Required under applicable Swiss data protection law.
• Based on your explicit consent.

 

10. Who we share your personal data with

Within Davies Group, your personal data will be shared with those team members who need to access it for the processing purposes outlined in this Privacy Notice.
We will only share your personal data with other parties where it is reasonable and necessary to accomplish the processing purposes outlined in this Privacy Notice. This may include (but is not limited to) where we:

• Are required to share information with law enforcement bodies and/or fraud prevention agencies for the purpose of preventing or detecting fraud or criminal activities; or
• Rely on the services of third-party service providers and hosting providers to carry out activities, provide services, or undertake business operations on our behalf. For example, we may use Hotjar in order to better understand our users’ needs and to optimise their service and experience when using our websites. Hotjar uses cookies and other technologies to collect data on our users’ behaviour and their devices, then stores this information on our behalf in a pseudonymised user profile. For further details, please see the ‘about Hotjar’ section of Hotjar’s support site.

In any such cases, the data we share will be limited to that which is strictly necessary and will be subject to appropriate contractual and confidentiality arrangements being in place.

Additionally, all of our third-party service providers are required to take appropriate security measures to protect your personal data, in line with Davies Group policies, and we do not allow them to use your personal data for their own purposes under any circumstances.

 

11. International transfers

Davies Group operates internationally and personal data may be transferred to, accessed from, or processed in countries other than the country in which it was collected, including by Davies Group entities, our Global Capability Centre in India, and authorised third-party service providers.

Where we transfer, disclose, store, or otherwise make personal data available outside the country in which it was collected, we will take appropriate steps to protect that data in accordance with applicable data protection laws. These steps may include:

• conducting due diligence on overseas recipients and service providers;
• relying on adequacy decisions, recognised comparable protection mechanisms, or equivalent legal safeguards where available;
• entering into appropriate contractual arrangements, such as standard contractual clauses, model contract clauses, intra-group transfer arrangements, data processing agreements, or other equivalent contractual protections;
• carrying out transfer risk assessments where required or appropriate;
• implementing supplementary technical and organisational measures;
• ensuring overseas recipients are required to protect personal data to a standard that is comparable or equivalent to the protection required under applicable data protection laws;
• limiting overseas transfers to what is necessary for the relevant purpose.

If you would like to understand more about this, please send an email outlining your query to DPO@davies-group.com.

For a list of Davies Group subsidiaries and legal entities, please refer to our Global Privacy Notice.

 

12. How long we keep your personal data for

We will keep your personal data for as long as necessary to fulfil the purposes that we describe in this Privacy Notice, including to satisfy any applicable legal, tax-related, forensic, and other legitimate business requirements.

To determine the appropriate retention period, we also consider a number of additional factors, such as the:

• Nature and sensitivity of the personal data.
• Potential risk of harm from unauthorised use or disclosure of the personal data.
• Requirements of the relevant controller, where we are acting in the capacity of processor.

 

13. How we keep your data secure

Davies Group has implemented an Information Security Management System (ISMS), which is globally certified to the International Organization for Standardization (ISO) 27001 standard for Information Security. This demonstrates our commitment to managing risks related to the security of the personal data we own and handle. We implement a range of technical, organisational, and physical security measures aligned with industry standards to protect your personal data from loss, misuse, unauthorised access, disclosure, alteration, or destruction. Our robust controls, policies, and procedures ensure that only authorised personnel have access to your information, maintaining its security throughout its lifecycle. These measures are further supported by an internal audit function and annual external certification.

 

14. Your rights

Davies Group is committed to processing your personal data in compliance with applicable data protection laws, including the Swiss Federal Act on Data Protection, where applicable.

You have certain rights in relation to your personal data; however, the exercise of these rights is subject to applicable legal conditions, exemptions, and limitations:

Right to Information: You have the right to receive transparent information about how your personal data is collected, and to request confirmation of whether we process personal data about you. Where applicable, you may also request access to your personal data and related information, including the purposes of processing, retention period or criteria, source of the data, recipients or categories of recipients, and details of automated individual decisions.
Right to Give and Withdraw Consent: Where we rely on your consent to process your personal data, you may withdraw your consent at any time by contacting us. Withdrawal of consent does not affect processing carried out before the withdrawal.
Right to Data Portability: You may request that we provide the personal data you have disclosed to us in a commonly used electronic format. You may also request that we transfer that personal data to another controller where the legal conditions are met, and no disproportionate effort is required. This right applies where the processing is automated and is based on your consent or is directly connected with the conclusion or performance of a contract with you.
Right to Correction, Deletion or Destruction: You may request that incorrect personal data be corrected, unless a statutory provision prohibits correction or the personal data is processed for archiving purposes in the public interest. Where personal data is processed unlawfully, you may also request deletion or destruction of personal data, or request that specific processing or disclosure to third parties be prohibited.
Right to Restriction of Processing / Right to Object: You may object to certain processing of your personal data or ask us to limit or stop processing in certain circumstances. We will assess your request in accordance with applicable Swiss data protection law, including whether continued processing is permitted or justified.
Rights Related to Automated Individual Decisions and Profiling: Where we make a decision about you based exclusively on automated processing and that decision has a legal consequence or considerable adverse effect on you, we will inform you in accordance with applicable Swiss data protection law. Where applicable, you may express your point of view and request that the decision be reviewed by a natural person.
Right to be Notified of a Data Breach: You have the right to be informed if your personal data is involved in a data breach that is likely to result in significant harm to you. We are legally required to notify you in such cases, so that you can take the necessary precautions.
Right to Complain to the Swiss Supervisory Authority: If you believe that your personal data has been processed in breach of Swiss data protection law, you may contact us or submit a report or complaint to the Swiss Federal Data Protection and Information Commissioner.

To exercise any of the rights outlined above, please contact us at SAR@davies-group.com. We may request specific information from you to confirm your identity. In some circumstances we, and where permitted by applicable Swiss data protection law, may charge a fee if responding to your request would involve disproportionate effort.

We may refuse, restrict or delay a request where permitted by applicable Swiss data protection law, including where a formal law provides for this, where it is necessary to protect overriding third-party interests, where the request is unjustified, or where our own overriding interests require this and we do not intend to disclose the personal data to third parties. Where we refuse, restrict or delay access, we will indicate the reason where required.

 

15. How to complain

We aim to meet the highest standards to safeguard your privacy. However, if you have any concerns about Davies Group use of your personal data, you can make a complaint to our Data Protection Officer by emailing DPO@davies-group.com, or by writing to:

Data Protection Officer
Davies Group
3rd, and 4th Floors
No.2 Smithfields
Stoke-on-Trent, ST1 3DH
United Kingdom

We encourage you to contact us first so that we can review and respond to your concern.

If you believe that your personal data has been processed in breach of applicable Swiss data protection law, you may also submit a report or complaint to the Swiss data protection supervisory authority, the Federal Data Protection and Information Commissioner (FDPIC).

The FDPIC may investigate a matter where there are sufficient indications that data processing may violate Swiss data protection regulations. The FDPIC may also decide not to open an investigation where the alleged violation is of minor importance. If you submit a report as a data subject, the FDPIC will inform you about the steps taken in response and the result of any investigation.

You can contact the FDPIC through its official contact page: https://www.edoeb.admin.ch/en/contact-2

 

16. Contact us

Our Group Data Protection Officer is Adam B Smith.

If you have any questions that could not be answered by this Privacy Notice or if you wish to receive more in-depth information about any of the content within it, please contact us at:

Post: Data Protection Officer, Davies Group, 3rd, and 4th Floors, No.2 Smithfields, Stoke-on-Trent, ST1 3DH, United Kingdom

Email: DPO@davies-group.com

 

17. Changes to this privacy notice

We reserve the right to update this Privacy Notice at any time, and we will provide you with a copy of the updated Privacy Notice (displayed electronically) when we make any substantial changes. We may also notify you in other ways from time to time about changes to the processing of your personal data.

    Keep up to date with Davies

    DISCOVER MORE