
© 2026 Kraus Partner Investment Solutions Ltd. All rights reserved.
Kraus Partner Investment Solutions Ltd ("Kraus Partner", "we", "us") takes the protection of your personal data seriously. This Data Protection Declaration explains what personal data we process, for what purposes, and what rights you have.
It applies to:
Where the processing differs between these two services, this is set out in the service-specific parts below (part 2 and part 3).
This declaration is based on the Swiss Federal Act on Data Protection (FADP). Where the EU General Data Protection Regulation (GDPR) applies to a particular processing activity - for example because data subjects are located in the EU - it is observed in addition.
The controller responsible for the data processing described here is:
Kraus Partner Investment Solutions Ltd Baeckerstrasse 40 8004 Zurich Switzerland
For any questions regarding data protection, or to exercise your rights, please contact our data protection contact at clientrelations@krauspartner.com.
Personal data is any information relating to an identified or identifiable natural person. We process personal data only in accordance with applicable law and the principles set out below.
We process personal data lawfully, fairly and in a transparent manner. We limit the collection and processing of personal data to what is necessary for the purposes described, keep it accurate, and retain it only for as long as required for those purposes or by law.
We do not intentionally process particularly sensitive personal data within the meaning of Art. 5 lit. c FADP, unless this is necessary in a specific case or required by law.
Depending on the processing activity, we rely on one or more of the following legal bases:
You may withdraw any consent you have given at any time, with effect for the future.
Certain personal data is required in order to provide our services or conclude and perform contracts or to grant access to our applications. Without this data, we may not be able to provide certain services or functionalities.
We may disclose personal data to service providers ("processors") who process it on our behalf and on our instructions - for example hosting providers. These providers are bound by contract to process the data only as instructed and to protect it appropriately. We may also disclose personal data where required by law or to protect our legitimate interests. The specific providers relevant to each service are named in part 2 and part 3.
All employees who have access to personal data are bound to confidentiality.
We do not sell personal data to third parties.
If you transmit personal data of other persons (such as colleagues or employees) to us, we assume that you are authorised to do so. You are responsible for ensuring that those third parties are informed of this Data Protection Declaration.
Personal data is processed primarily in Switzerland and the European Union. Where personal data is transferred to countries that do not provide an adequate level of data protection, including the United States, we ensure appropriate safeguards in accordance with applicable data protection law - in particular by entering into standard contractual clauses approved by the European Commission and recognised by the Swiss authorities, unless a statutory exception applies. Where applicable, service providers may also be certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework. Specific transfers are indicated in the relevant sections.
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access and disclosure - including encrypted transport (TLS), access controls, and restrictive firewall and authentication settings.
We process and store personal data for as long as is necessary to fulfil our contractual and legal obligations and the other purposes described in this declaration - typically for the duration of the entire business relationship (from initiation, through processing, to the end of the contract) - and beyond to the extent required by statutory retention and documentation obligations.
We may also retain personal data for the period during which legal claims may be asserted against us (in particular during the statutory limitation period) and where our legitimate interests so require (for example for evidence and documentation purposes).
As soon as personal data is no longer required for the purposes described, we delete or anonymise it. Where specific retention periods apply to a particular processing activity, these are stated in the relevant section of this declaration.
We do not make decisions affecting you that are based solely on automated processing, nor do we engage in profiling within the meaning of Art. 21 FADP or Art. 22 GDPR. If we introduce such processing in the future, we will inform you separately where required by law.
Within the limits of applicable law, you have the right to obtain information about whether and which of your personal data we process, to request the rectification of inaccurate data, to request the erasure of your data, to request the restriction of processing, to object to processing based on our legitimate interests, to receive certain data in a portable format, and to withdraw consent you have given.
To exercise these rights, please contact us using the details in section 2 of part 1. We aim to respond to data protection requests within 30 days. There is no fee unless the request is manifestly unfounded or excessive. You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, CH-3003 Bern (www.edoeb.admin.ch), or, where the GDPR applies, with your local supervisory authority.
We may amend this Data Protection Declaration at any time. The version published at the time of your use applies.
This part applies to your visit to our corporate website at www.krauspartner.com (and krauspartner.ch, which redirects to it).
Our website is hosted by green.ch, Switzerland. The data is stored on servers in Switzerland.
When you visit the website, the hosting infrastructure automatically collects and stores information that your browser transmits in server log files - in particular your IP address, the date and time of access, the pages accessed, and your browser and operating system. This data is processed to operate the website securely and reliably, is not combined with other data sources, and is stored only for a limited period before being deleted.
This processing is based on our legitimate interest in ensuring the security, stability and integrity of our services.
Our website provides a button to compose an email to us. If you contact us by email, we process the data contained in your message (such as your name, email address, phone number and the content of your enquiry) for the purpose of handling and responding to your request. We retain this correspondence for as long as necessary to deal with your matter and in accordance with statutory retention obligations.
We welcome solicited and unsolicited job applications. If you send us an application, we process the personal data you provide (such as your contact details, CV, references and other information contained in your application) for the purpose of assessing your application and conducting the recruitment process.
If we are unable to offer you a position, we retain your application data only for as long as necessary in connection with the application process - in particular to deal with any follow-up questions and to defend against potential claims - and then delete it, unless you have consented to a longer retention period (for example, to be considered for future openings).
We send informational mailings about our services and activities. These mailings are managed using our customer relationship management system (cobra ADRESS PLUS), which we operate on our own systems in Switzerland; backups are stored with a backup service located in Switzerland.
Recipients of our mailings include our clients and other interested persons. To the extent permitted and where we consider it appropriate, we may also obtain contact data from publicly accessible sources, such as company websites, professional directories or commercial registers.
We process relevant contact data (such as name, email address or phone number) for the purpose of informing recipients about our services and activities. This processing is based on our legitimate interest in maintaining client and business relationships and communicating with interested persons. Where required by applicable law, we obtain your consent before sending marketing communications.
You can object to receiving our mailings at any time and free of charge. Every mailing contains information on how to unsubscribe; you can also unsubscribe at any time by emailing clientrelations@krauspartner.com.
Our website includes an embedded map from Google Maps, a service provided by Google LLC (USA). When a page containing the map is loaded, your browser connects directly to Google's servers in order to display the map. As a result, Google receives information including your IP address and technical data about your browser, and may set cookies. Data may also be transferred to the United States.
Google may process this data for its own purposes and acts in this respect as an independent controller. We have no influence over the data processing carried out by Google. Further information is available in Google's privacy policy.
Our website contains links to our profiles on third-party platforms (such as X/Twitter or LinkedIn). These are simple links - no data is transmitted to those platforms until you actively click a link and leave our website. Once you do, the data protection declaration of the respective platform applies.
Our website uses only cookies that are technically necessary to operate the site (set by the WordPress system on which the website is built). We do not currently use analytics, tracking or advertising cookies on the website.
This part applies to your use of the jaive web application provided at jaive.ch (and jaive.net as well as jaive.com, which redirect to it). The application is available to registered users only.
The jaive web application and its data are hosted on infrastructure provided by Amazon Web Services (AWS), in a data centre located in Frankfurt, Germany (European Union).
Access to the jaive web application requires a user account. Accounts are created and issued by us; there is no public self-registration.
We generally issue one account per client organisation, assigned to the organisation's designated main contact. The same account may also be used by other employees of that organisation. For each account we process the following data: username, password (stored in hashed form), email address, name and company. This personal data relates to the designated main contact.
We process this data to provide access to the application, to authenticate the account, and to administer it. The legal basis is the performance of our contract with the client organisation.
Because an account is typically shared within a client organisation, activity within the application generally cannot be attributed to a specific individual person. Client organisations are responsible for ensuring that access credentials are used only by authorised persons and are kept confidential.
When you log in, we set a single, strictly necessary cookie containing an authentication token. It allows the application to recognise you as logged in. The cookie has a maximum lifetime of 7 days and is configured restrictively (SameSite=Strict). No analytics or tracking cookies are used in the application.
Within the application, you can enter and store your individual strategic asset allocations (SAA) and related data/parameters necessary for the calculation. We process this data to provide the application's functionality - in particular to calculate the optimal deviation between your strategic and tactical allocations.
To generate a written interpretation of the calculation results, the application uses an AI service provided by Groq, Inc. (USA). We do not intentionally transmit identifying data such as names or contact details. The transmitted information is limited to calculation outputs and technical parameters which do not directly identify individuals from our perspective.
The servers operating the jaive web application automatically record technical log data (for example via the web server and the security components), including IP addresses, user names, timestamps and accessed resources. This data is processed to operate the application securely, to detect and prevent misuse, and to evaluate and improve the service.
Raw log data is retained for 90 days and then deleted. Aggregated or anonymised evaluations derived from log data - which no longer allow any individual to be identified - may be retained for a longer period.
We retain user account data and related client data for the duration of the business relationship. After it ends, we retain such data for the period required by statutory retention obligations applicable to us, after which it is deleted or anonymised.
Last updated: May 2026