Vektor Privacy Policy

Version 0.2 — 14 August 2026

1. Controller and product

Vektor AG, Rennweg 45, 8704 Herrliberg, Switzerland (“Vektor AG”), is responsible for the processing described here unless a specific agreement establishes a different allocation of roles. Vektor is the software product and customer portal operated by Vektor AG.

2. Terms and legal grounds

“Processing” means any handling of personal data, including collection, storage, use, disclosure, archiving, and deletion. Vektor AG processes data under the Swiss Federal Act on Data Protection, in particular to perform contracts, pursue legitimate interests, comply with legal duties, or based on consent.

3. Purposes

Vektor AG processes personal data to provide and secure Vektor, perform contracts, support customers, bill services, meet compliance obligations, improve services, and, where permitted, conduct marketing. If bLink is enabled, data is also processed to retrieve bank statements, create and substantiate accounting records, troubleshoot errors, and monitor security.

4. Data categories

Depending on use, processed data includes master, contact, contract, communication, usage, device, security, financial, banking, and accounting data. It may include IP addresses, browser details, access and feature logs, and third-party data supplied by the customer.

5. Bank data through SIX bLink

  1. The bLink connection is optional. Following explicit consent at the bank, Vektor uses only the read-only Account Information Service (AIS) to retrieve CAMT.053 bank statements. Vektor cannot use this connection to initiate payments or change data at the bank.
  2. Processed data includes the connected bank, account identifiers such as IBAN, account and balance details, transactions, booking text and other information in CAMT.053 statements, as well as technical status, error, and consent logs.
  3. The parties involved are Vektor AG as operator of Vektor and data controller; Atlanto AG, Engelgasse 2, 9000 St. Gallen, Switzerland, as Vektor AG's sister company and the bLink Service User registered with SIX; the connected bank as Service Provider; and SIX BBS AG as operator of bLink and CaaS. Under the CaaS model, SIX stores the bank access token; Vektor stores a permission identifier and the connection data required for operation and evidence.
  4. Vektor AG uses banking data to import statements, store them as source documents, generate or assign accounting data, secure the service, and investigate errors. Atlanto AG supports the bank connection in its registered role as bLink Service User.
  5. Disconnecting in Vektor stops future retrieval and Vektor attempts to revoke the CaaS permission. Automatic and immediate removal at every bank or Service Provider cannot be guaranteed. When ending the bank connection or the contractual relationship with Vektor AG, the customer must therefore also revoke bLink consent at the relevant bank or responsible Service Provider and verify its removal.
  6. Revocation does not automatically delete previously imported bank statements, source documents, or accounting records. They remain stored for as long as required for accounting, evidence, contract performance, or statutory retention duties.

6. Profiling and automated decisions

Vektor AG may analyze data to improve and personalize services and identify security risks. If a solely automated individual decision has significant legal effect, Vektor AG will inform the affected person as required by applicable law and provide the required review mechanism.

7. Recipients and service providers

Where necessary, Vektor AG may disclose data to Atlanto AG in its role as bLink Service User, other affiliated companies, fiduciary partners, IT, hosting, communications, support and security providers, banks, SIX BBS AG, authorities, and other contractually or legally designated recipients. Recipients process data according to their role and the applicable contracts and privacy rules.

8. International disclosures

If data is disclosed to a country without an adequate statutory level of protection, Vektor AG uses recognized safeguards, in particular suitable standard contractual clauses, or relies on a legal exception. Vektor's technical infrastructure and individual recipients may be located outside Switzerland.

9. Retention

Vektor AG retains personal data only for as long as required for its purpose, the establishment or defense of claims, contract performance, or legal duties. It is then deleted or anonymized unless an exception applies. Backups may persist until the end of their deletion cycle.

10. Security

Vektor AG applies appropriate technical and organizational measures against unauthorized or unlawful processing and loss. No electronic transmission or storage can be guaranteed to be entirely risk-free.

11. Rights of data subjects

Subject to applicable law, data subjects may request access, correction, deletion, restriction, objection, or data delivery and may withdraw consent for the future. Legal retention duties and third-party rights may restrict these requests.

12. Contact

Vektor AG
Vektor Data Protection
Rennweg 45
8704 Herrliberg, Switzerland
Email: datenschutz@vektor.ch

13. Amendments

Vektor AG may amend this Privacy Policy for the future. Material changes will be communicated appropriately. Earlier versions and their applicable periods remain documented.