
Aurum Helvetica
Kaufen Sie physisches Gold und Silber, sicher verwahrt, bei einem vertrauenswürdigen Partner.
Privacy Policy
Effective: June 01, 2026
Prepared by: Monika Holik-Yaxley, External Compliance Consultant, in consultation with the
Board of Directors
1. Purpose
This Privacy Policy explains how Aurum Helvetica GmbH collects, uses, stores, protects and shares personal information. The policy reflects the principles of the Swiss Federal Act on Data Protection (FADP). Aurum Helvetica GmbH is committed to processing personal information fairly, and transparently, and only where necessary for legitimate business purposes.
2. Scope
This Privacy Policy applies to all personal information processed by Aurum Helvetica GmbH in connection with its business activities, regardless of the format in which the information is held. This includes information collected electronically, in paper format, verbally, or through third-party service providers acting on behalf of the Company.
The Policy applies to personal information relating to prospective clients, existing clients, former clients, beneficial owners, authorized representatives, suppliers, service providers, business partners, website visitors, job applicants (where applicable), and any other individual whose personal information is collected or processed by Aurum Helvetica GmbH.
Personal information may be collected and processed throughout the course of a business relationship, including but not limited to:
-
responding to enquiries and requests for information;
-
client onboarding and account opening;
-
customer due diligence ("CDD"), Know Your Customer ("KYC") and Anti-Money Laundering ("AML") verification procedures;
-
precious metals purchases, sales and secure storage services;
-
payment processing and transaction administration;
-
ongoing monitoring of customer relationships to meet legal and regulatory obligations;
-
communications by email, telephone or other electronic means;
-
compliance with applicable legal, regulatory and contractual requirements;
-
administration of the Company's internal business operations
This Policy applies to all employees, directors, contractors and authorized representatives of Aurum Helvetica GmbH who process personal information on behalf of the Company. All such individuals are expected to comply with the requirements of this Policy and to ensure that personal information is handled in a lawful, secure and confidential manner at all times.
3. Information Collected
Aurum Helvetica GmbH collects and processes only the personal information that is reasonably necessary to establish and maintain a business relationship, provide its products and services, comply with applicable legal and regulatory obligations, and protect the legitimate interests of the Company and its clients.
Depending on the nature of the relationship, the Company may collect and process the following categories of personal information:
Identity Information
-
Full name
-
Date of birth
-
Nationality
-
Government-issued identification (such as a passport or national identity card)
Contact Information
-
Residential and mailing address
-
Email address
-
Telephone number
-
Proof of address documentation
Financial and Transaction Information
-
Banking and payment details
-
Purchase and sale transaction records
-
Secure storage records
-
Account history and related financial information
Compliance Information
-
Know Your Customer ("KYC") documentation
-
Customer Due Diligence ("CDD") information
-
Anti-Money Laundering ("AML") screening results
-
Sanctions, politically exposed person ("PEP"), and adverse media screening results, where applicable
-
Information required to satisfy legal, regulatory, and compliance obligations
Communication Information
-
Correspondence by email, telephone, or other electronic means
-
Records of enquiries, requests, and client communications
-
Information voluntarily provided through the Company's website contact form
Technical Information
-
Limited technical information relating to visits to the Company's website, including information collected through GoDaddy Analytics to help monitor website performance and improve user experience.
The Company adheres to the principle of data minimisation and will only collect personal information that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
Access to personal information is restricted to authorised personnel who require such information to perform their duties. Personal information is maintained within secure business systems and is protected through appropriate technical and organisational safeguards designed to preserve its confidentiality, integrity, and availability.
4. Purposes of Processing
Aurum Helvetica GmbH processes personal information only where there is a legitimate business, legal or regulatory purpose for doing so. Personal information is processed fairly, lawfully and transparently, and only for purposes that are compatible with those for which the information was originally collected.
The Company may process personal information for one or more of the following purposes:
-
establishing and maintaining client relationships;
-
responding to enquiries and requests for information;
-
conducting client onboarding and account opening procedures;
-
verifying the identity of clients and beneficial owners through Know Your Customer ("KYC") and Customer Due Diligence ("CDD") procedures;
-
complying with applicable Anti-Money Laundering ("AML"), Counter-Terrorist Financing ("CTF"), sanctions screening and other legal or regulatory obligations;
-
facilitating the purchase, sale and secure storage of precious metals;
-
processing payments, maintaining transaction records and administering client accounts;
-
communicating with clients regarding their accounts, transactions, storage holdings or service requests;
-
detecting, preventing and investigating fraud, financial crime and other unlawful activities;
-
maintaining accounting, financial and business records;
-
managing contractual relationships with suppliers and service providers;
-
improving the Company's services, internal processes and operational efficiency; and
-
protecting the Company's legal rights and interests, and complying with court orders, regulatory requests or other legal obligations.
Personal information will not be processed for purposes that are incompatible with the original purpose for which it was collected unless required or permitted by applicable law or with the individual's consent.
5. Legal Basis for Processing
Aurum Helvetica GmbH processes personal information only where there is a lawful basis for doing so and where such processing is necessary for the operation of its business and the fulfilment of its legal and regulatory obligations.
Depending on the circumstances, personal information may be processed for one or more of the following reasons:
-
to enter or perform a contract with a client, supplier or business partner;
-
to comply with applicable legal, regulatory and compliance obligations, including Anti-Money Laundering ("AML"), Counter-Terrorist Financing ("CTF"), sanctions and other financial crime prevention requirements;
-
to protect the legitimate business interests of Aurum Helvetica GmbH, provided such interests do not override the rights and freedoms of the individual;
-
where the individual has provided consent, including for the receipt of marketing communications or where consent is otherwise required by law; and
-
where processing is otherwise permitted or required under applicable Swiss law.
The Company processes personal information in accordance with the principles of lawfulness, fairness, transparency, proportionality and purpose limitation, and will only process personal information for purposes that are appropriate, relevant and necessary for the activities described in this Policy.
6. Third-Party Service Providers
Aurum Helvetica GmbH engages carefully selected third-party service providers to support its business operations and assist in the delivery of its products and services. Personal information is shared with third parties only where it is necessary for a legitimate business purpose, to fulfil contractual obligations, or to comply with applicable legal and regulatory requirements.
The Company may disclose personal information to service providers including, but not limited to:
-
Comply Advantage: for sanctions, politically exposed person ("PEP"), adverse media and Anti-Money Laundering ("AML") screening;
-
Monex Europe Limited: to facilitate payment processing and foreign exchange services, where applicable;
-
Bankwell: for banking and payment-related services;
-
Microsoft 365: for secure business communications, document management and productivity services;
-
Google Workspace: for email, collaboration and business administration; and
-
Mailchimp: for the distribution and management of marketing communications and newsletters.
The Company may also disclose personal information to professional advisers, auditors, legal counsel, regulatory authorities, law enforcement agencies or other third parties where disclosure is required or permitted by law or is necessary to protect the Company's legal rights and legitimate interests.
Aurum Helvetica GmbH takes reasonable steps to ensure that third-party service providers maintain appropriate technical and organisational measures to protect personal information against unauthorised access, disclosure, alteration or destruction. Where appropriate, the Company requires service providers to process personal information only in accordance with contractual obligations and applicable data protection laws.
The Company does not sell, rent or otherwise disclose personal information to third parties for their own independent marketing purposes.
7. International Transfers
Aurum Helvetica GmbH may engage third-party service providers that process or store personal information outside Switzerland. This may occur where the Company's service providers operate internationally or utilise data centres located in other jurisdictions.
Where personal information is transferred outside Switzerland, Aurum Helvetica GmbH will take reasonable steps to ensure that such transfers are carried out in accordance with applicable Swiss data protection laws and that appropriate safeguards are in place to protect personal information.
These safeguards may include, where appropriate:
-
transferring personal information only to jurisdictions recognised as providing an adequate level of data protection;
-
entering contractual arrangements with service providers that require the protection of personal information in accordance with applicable data protection legislation;
-
implementing appropriate technical and organisational security measures; and
-
taking reasonable steps to ensure that personal information is processed only for authorised business purposes.
The Company will make reasonable efforts to ensure that all third-party service providers handling personal information maintain appropriate standards of confidentiality, security and data protection consistent with the requirements of this Privacy Policy and applicable law.
8. Marketing
Aurum Helvetica GmbH may use personal information to communicate with clients and prospective clients regarding its products, services, industry updates, market insights, promotions and other information that may be of interest.
Where required by applicable law, marketing communications will only be sent where the individual has provided the necessary consent or where the Company is otherwise permitted to do so. Individuals may withdraw their consent or opt out of receiving marketing communications at any time.
All electronic marketing communications distributed by the Company will include a clear and accessible unsubscribe mechanism. Requests to unsubscribe or withdraw consent will be processed promptly, and individuals who opt out of marketing communications will continue to receive any communications that are necessary for the administration of their accounts, transactions or legal obligations.
The Company does not sell or disclose personal information to third parties for their independent marketing purposes.
9. Website
Aurum Helvetica GmbH collects limited personal information through its website to facilitate communication with prospective and existing clients and to improve the functionality and performance of the website.
The Company's website currently provides a contact form through which visitors may voluntarily submit personal information, including their name, email address, telephone number and the details of their enquiry. This information is used solely for the purpose of responding to enquiries, providing requested information and establishing potential business relationships.
The website also utilises GoDaddy Analytics to collect limited technical and usage information, such as general visitor statistics, page views and website performance metrics. This information is used to monitor the effectiveness of the website, improve the user experience and support the ongoing development of the Company's online services. Information collected through analytics is generally aggregated and is not intended to identify individual users.
At the date of this Policy, Aurum Helvetica GmbH does not utilise Google Analytics, LinkedIn tracking technologies or client login portals on its website. Should additional functionality or tracking technologies be introduced in the future, this Privacy Policy will be reviewed and updated accordingly.
Visitors are encouraged not to submit sensitive personal information, payment details or copies of identification documents through the website contact form unless specifically requested by Aurum Helvetica GmbH.
10. Information Security
Aurum Helvetica GmbH is committed to protecting personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access. The Company implements appropriate technical and organisational security measures designed to safeguard the confidentiality, integrity and availability of the personal information entrusted to it.
Depending on the nature of the information and the associated risks, these security measures may include:
-
encryption of data in transit and, where supported by service providers, at rest;
-
multi-factor authentication ("MFA") for systems supporting this functionality;
-
role-based access controls to ensure that personal information is accessible only to authorised personnel with a legitimate business need;
-
secure storage of electronic records using reputable technology and cloud service providers;
-
offline backup copies to support business continuity and disaster recovery;
-
regular review of user access permissions and system security settings;
-
password protection and authentication controls;
-
secure disposal of confidential information when it is no longer required; and
-
ongoing monitoring and review of security practices to address evolving threats and business requirements.
Access to personal information is granted strictly on a need-to-know basis and is limited to personnel who require such access to perform their duties. All personnel are expected to maintain the confidentiality of personal information and to comply with the Company's internal policies and procedures relating to information security and data protection. While Aurum Helvetica GmbH applies reasonable safeguards to protect personal information, no method of electronic transmission or storage can be guaranteed to be completely secure. The Company will continue to review and enhance its security measures to minimise risks and respond to changes in technology, business operations and applicable legal requirements
11. Data Retention
Aurum Helvetica GmbH retains personal information only for as long as necessary to fulfil the purposes for which it was collected, including the provision of products and services, the administration of client relationships, and compliance with applicable legal, regulatory and contractual obligations.
Unless a longer retention period is required or permitted by law, personal information relating to clients and business relationships will generally be retained for a period of ten (10) years following the termination of the business relationship or the completion of the relevant transaction.
At the expiry of the applicable retention period, personal information will be securely destroyed, deleted or anonymized in a manner that prevents unauthorised access, recovery or misuse, unless the information is required to be retained for ongoing legal proceedings, regulatory investigations or other legitimate business purposes.
The Company periodically reviews the personal information it holds to ensure that records are retained only for as long as necessary and in accordance with applicable legal and regulatory requirements.
12. Individual Rights
Subject to applicable Swiss data protection laws and any relevant legal or regulatory restrictions, individuals whose personal information is processed by Aurum Helvetica GmbH may exercise certain rights in relation to their personal information.
These rights may include the right to:
-
request confirmation as to whether the Company processes their personal information;
-
request access to the personal information held about them;
-
request the correction or updating of inaccurate, incomplete or outdated personal information;
-
request the deletion of personal information where the Company is no longer legally required or entitled to retain it;
-
object to, or request the restriction of, certain processing activities where permitted by law;
-
withdraw consent at any time where the processing of personal information is based on consent, including for marketing communications; and
-
submit a complaint regarding the Company's handling of personal information.
Requests relating to personal information should be submitted in writing using the contact details provided in this Privacy Policy. Aurum Helvetica GmbH will respond to such requests within a reasonable timeframe and in accordance with applicable legal and regulatory requirements.
In certain circumstances, the Company may be unable to comply with a request where it is required to retain personal information to meet legal, regulatory, contractual or legitimate business obligations. Where a request cannot be fulfilled, the individual will be informed of the reasons, unless prohibited by law.
13. Data Breaches and Security Incidents
Aurum Helvetica GmbH is committed to responding promptly and effectively to any actual or suspected data breach or information security incident involving personal information.
All employees, contractors and authorised representatives who become aware of a suspected or actual privacy breach, security incident or unauthorised disclosure of personal information are required to report the matter to management immediately upon becoming aware of the incident.
Upon notification, the Company will take reasonable steps to:
-
investigate the nature and scope of the incident;
-
contain and mitigate any actual or potential harm;
-
assess the risks to affected individuals and the Company;
-
document the incident and any corrective actions taken;
-
implement measures to prevent a recurrence; and
-
notify affected individuals, regulatory authorities or other relevant parties where required by applicable law.
The Company will maintain appropriate records of all reported privacy and information security incidents and will periodically review such incidents to identify opportunities to strengthen its security controls, policies and procedures.
14. Responsibilities
The Board of Directors of Aurum Helvetica GmbH has overall responsibility for approving this Privacy Policy, overseeing the Company's compliance with applicable data protection legislation and ensuring that appropriate governance, resources and controls are in place to protect personal information.
Management is responsible for implementing this Policy on a day-to-day basis, establishing appropriate procedures and controls, ensuring that personnel receive appropriate guidance and training, and monitoring compliance with the Company's privacy and information security requirements.
All employees, directors, contractors and authorised representatives who process personal information on behalf of the Company are responsible for protecting the confidentiality of personal information, complying with this Policy and promptly reporting any suspected privacy or information security incident to management.
Where Aurum Helvetica GmbH engages external legal, compliance or privacy advisers, including consultants acting in an advisory capacity, such advisers provide independent guidance and recommendations only. Responsibility for the implementation, administration, monitoring and enforcement of this Policy, and for compliance with applicable legal and regulatory obligations, remains solely with the Board of Directors and the management of Aurum Helvetica GmbH.
15. Contact
If you have any questions regarding this Privacy Policy or the way Aurum Helvetica GmbH collects, uses, stores or protects your personal information, or if you wish to exercise any of your rights under applicable data protection laws, please contact the Company using the details below.
Aurum Helvetica GmbH
Address:
Weissbadenstrasse 8B
9050 Appenzell
Switzerland
Telephone:
+41 76 720 1063
Email:
info@aurumhelvetica.com
Business Hours:
Monday to Friday
8:00 a.m. – 5:00 p.m. (Central European Time)
The Company is committed to responding to privacy-related enquiries and requests within a reasonable timeframe and in accordance with applicable legal and regulatory requirements.
16. Policy Review
This Privacy Policy shall be reviewed at least annually to ensure that it remains accurate, appropriate and compliant with applicable legal, regulatory and operational requirements. The Policy shall also be reviewed whenever there are material changes to the Company's business activities, services, information systems, data processing practices or applicable laws and regulations that may affect the processing of personal information.
The Board of Directors is responsible for approving this Policy and any subsequent amendments. The Board may seek advice from external legal, compliance or privacy professionals as appropriate; however, responsibility for the review, approval, implementation and ongoing oversight of this Policy remains solely with the Board of Directors of Aurum Helvetica GmbH.
The most current version of this Privacy Policy shall be maintained by the Company and made available to relevant personnel and, where appropriate, to clients and other interested parties.