Privacy Policy
Last updated: 2026-07-06
FX Fair Values – B2B research platform
- Controller
- QIO – Quantitative Investment Office AG
- Address
- Boendlerstrasse 63, 8802 Kilchberg ZH, Switzerland
- Contact
- contact@qio.finance
- Website
- https://fx.fair-value.investments
- Primary law
- Swiss Federal Act on Data Protection (FADP); GDPR where applicable
- Version
- Version 1.1 | 6 July 2026
1. Purpose and scope
This Data Protection Declaration explains how QIO processes personal data in connection with the FX Fair Values website and related B2B research and analytics services.
The Service is directed at business, professional and institutional users. Most personal data processed in this context relates to business contacts, authorised users, administrators, billing contacts, support contacts and other representatives of client organisations.
This declaration applies to the website, authenticated user area, subscriptions, support communications, service administration, newsletters relating to the Service and related contractual relationships.
This declaration is scoped to the FX Fair Values B2B platform only and is separate from any declaration covering goal-based.investments or other consumer-facing services operated by QIO or affiliated entities.
2. Controller
The controller responsible for processing personal data is QIO – Quantitative Investment Office AG, Boendlerstrasse 63, 8802 Kilchberg ZH, Switzerland.
For data protection questions or requests, please contact: contact@qio.finance.
If the Platform is directed at users in the EU/EEA and QIO has no establishment there, QIO should confirm with legal counsel whether an EU representative under Art. 27 GDPR is required and, if applicable, publish the representative’s contact details here.
3. Categories of personal data processed
QIO may process the following categories of personal data, depending on how the Service is used:
Business contact and identity data: name, title, role, employer, business email address, business telephone number, business address, country, language preference and communication history.
Account and authentication data: username, user ID, authentication tokens/confirmations received from the supported third-party identity provider used for sign-in (Google or LinkedIn – see Section 4), access rights, account status, organisation affiliation, acceptance logs and administrator assignments. QIO does not store an independent password for the Service: authentication is performed by the identity provider, and QIO relies on that provider’s confirmation together with the basic profile data (e.g. name, business email address and, where made available, employer or professional role) it releases at login.
Contract and billing data: subscription package, order forms, invoices, payment status, VAT or tax information, billing contacts and correspondence concerning fees or service administration.
Usage and technical data: IP address, device and browser information, log files, login events, session data, security events, pages viewed, features used, API calls, timestamps, session-recording/interaction data collected via UX-analytics tools (see Section 7) and diagnostic information. Server log data is used to ensure stable and secure operation of the Platform and is generally retained for 30 days if applicable, unless longer retention is required for security investigation, troubleshooting, abuse prevention or legal reasons.
Support and communication data: enquiries, support tickets, email correspondence, meeting notes, feedback, requests and related attachments submitted by users.
Marketing and preference data: newsletter subscriptions, event registrations, communication preferences and consent records where applicable.
QIO does not require users to provide sensitive personal data for ordinary use of the Service and asks users not to submit such data unless specifically requested and necessary.
4. Sources of personal data
QIO receives personal data directly from users, client organisations, administrators, contract signatories, support interactions, website usage, authentication systems and technical logs. Where a user signs in via a supported third-party identity provider, QIO receives an authentication confirmation and basic profile data (e.g. name, business email address and, where made available, employer or professional role) from that provider: currently Google (Google LLC) and LinkedIn (LinkedIn Corporation, a Microsoft company). The scope of data released depends on the permissions the user has granted to that provider and on the provider’s own platform settings.
QIO may also receive business contact data from publicly available professional sources, referrals, business partners, events, LinkedIn or other professional networks, where permitted by applicable law.
5. Purposes of processing
QIO processes personal data for the following purposes:
- Providing, operating, authenticating and securing access to the Service.
- Creating and managing user accounts, access rights, subscriptions, order forms, licences and contractual relationships.
- Providing support, maintenance, user communication, service notifications and technical troubleshooting.
- Billing, accounting, tax, audit, payment administration and debt collection.
- Monitoring usage, preventing misuse, enforcing contractual restrictions and protecting QIO, users and third parties against fraud, security threats and unlawful activity.
- Improving, testing and developing the Service, including technical performance, user experience and model or data-delivery workflows.
- Complying with legal, regulatory, accounting, tax, recordkeeping and dispute-resolution obligations.
- Sending B2B product updates, research notices, invitations or similar communications where permitted by law and subject to opt-out rights.
6. Legal bases
Where Swiss data protection law applies, QIO processes personal data in accordance with the principles of lawfulness, good faith, proportionality, purpose limitation, transparency and data security.
Where the EU or UK GDPR applies, QIO relies, depending on the context, on one or more of the following legal bases: performance of a contract or pre-contractual measures; legitimate interests in operating, securing, improving and marketing a B2B research service; compliance with legal obligations; and consent where required, for example for sign-in via a third-party identity provider, for non-essential cookies and session-monitoring tools (obtained at registration/login as described in Section 7) or direct marketing communications.
Users may withdraw consent at any time where processing is based on consent. Withdrawal does not affect processing carried out before withdrawal.
7. Cookies and similar technologies
The website and authenticated Service may use cookies, local storage, session identifiers, pixels or similar technologies.
Technically necessary cookies and similar technologies may be used without separate consent where they are required for login, authentication, security, fraud prevention, session management, load balancing, consent management or core website functionality.
Optional analytics, preference, embedded-content or marketing cookies are used only where implemented and where the required consent or other legal basis exists. The Platform does not display a separate cookie-consent banner. Instead, cookies and similar technologies are grouped into: (i) strictly necessary/functional cookies (login, session, security, load balancing); (ii) analytics/product-usage cookies; and (iii) session-monitoring/UX-analytics tools, such as Microsoft Clarity, which may record clicks, scrolling and page interaction for product-improvement purposes. Because the Service requires an account, consent to all cookies and monitoring tools described in this Section is obtained at the point of registration and/or first login (via Google or LinkedIn sign-in – see Section 4). Users who do not consent should not create an account.
Disabling necessary cookies may prevent the Service from functioning properly.
8. Disclosure to recipients and processors
QIO may disclose personal data to the following recipients where necessary for the purposes described above:
- IT hosting, cloud infrastructure, database, security, identity/authentication providers used for sign-in (Google, LinkedIn), authentication, monitoring, analytics and session-monitoring/UX-analytics providers (e.g. Microsoft, as provider of Clarity) and software providers. The concrete providers used for hosting, cloud infrastructure, authentication, analytics and communication tools should be inserted before publication where required.
- Email, communication, CRM, support, billing, accounting, payment, audit, legal, tax and compliance service providers.
- Professional advisers, auditors, insurers, banks, authorities, courts, regulators or other parties where required by law, contract enforcement or protection of rights.
- Client organisation administrators, where they manage access rights, subscriptions, usage or billing for their organisation.
QIO requires processors to process personal data only on documented instructions, to apply appropriate security measures and to maintain confidentiality, subject to the terms agreed with such processors.
9. International transfers
QIO is based in Switzerland. Personal data may be processed in Switzerland, the European Economic Area, the United Kingdom or other countries where QIO or its service providers operate.
Where personal data is transferred to countries without an adequate level of data protection, QIO applies appropriate safeguards where required, such as EU Standard Contractual Clauses, Swiss data-transfer clauses or addenda, transfer impact assessments, technical and organisational measures, adequacy decisions/frameworks, or relies on statutory exceptions where applicable. This includes transfers to the US-based identity and analytics providers referenced in Sections 4, 7 and 8 (e.g. Google, Microsoft/LinkedIn), for which appropriate transfer safeguards should be confirmed and documented before publication.
10. Data retention
QIO retains personal data only as long as necessary for the purposes for which it was collected, including service provision, security, contractual administration, accounting, tax, audit, legal defence and compliance obligations.
Account, contract, billing and business correspondence data may be retained for the applicable statutory limitation and recordkeeping periods. Technical logs are generally retained for shorter periods unless longer retention is required for security, troubleshooting, abuse prevention or legal reasons.
When personal data is no longer required, QIO deletes, anonymises or archives it in accordance with applicable law and internal retention practices.
11. Data security
QIO applies appropriate technical and organisational measures intended to protect personal data against unauthorised access, loss, misuse, alteration and disclosure. Such measures may include access controls, authentication, encryption in transit, role-based permissions, logging, backups, monitoring, secure development practices and confidentiality obligations.
No electronic communication or internet-based service can be guaranteed to be completely secure. Users are responsible for protecting their credentials, devices and internal access controls.
12. Data subject rights
Depending on the applicable law and circumstances, individuals may have rights to request information, access, rectification, deletion, restriction, objection, data portability or withdrawal of consent.
Requests may be submitted to the contact address stated above. QIO may need to verify the identity and authority of the requesting person and may reject or limit requests where permitted by law, for example to protect confidentiality, trade secrets, security, legal claims or rights of third parties.
Individuals may also have the right to lodge a complaint with the competent data protection authority. In Switzerland, the competent federal authority is the Federal Data Protection and Information Commissioner (FDPIC), subject to its statutory competence. Where the GDPR applies, individuals may also contact the supervisory authority of their habitual residence, place of work or place of the alleged infringement in the EU/EEA.
13. Automated decision-making and profiling
QIO does not use personal data from the ordinary operation of the Service to make decisions about individuals that produce legal effects or similarly significant effects within the meaning of applicable data protection law.
The Service itself provides financial-market research outputs and model-based FX analytics. These outputs concern currencies, markets and economic variables, not automated decisions about individual users.
14. B2B marketing communications
QIO may send existing or prospective business contacts information about the Service, research updates, events or related B2B offerings where permitted by applicable law. Recipients may opt out of such communications at any time by using the unsubscribe mechanism or contacting QIO.
Operational and contractual communications, such as security notices, service changes, billing reminders or legal updates, may still be sent where necessary.
15. Links to third-party websites
The Service may link to third-party websites or content. QIO is not responsible for the data protection practices, content or security of third-party websites. Users should review the privacy notices of those third parties.
16. Changes to this declaration
QIO may amend this Data Protection Declaration from time to time. The current version will be published on the website or otherwise made available. Material changes may be communicated by appropriate means where required.
QIO – Quantitative Investment Office AG | 6 July 2026