PRIVACY POLICY
Institut für seltene Erden und Metalle AG (ISE AG)
Last updated: 17 August 2026
Notice: This Privacy Policy explains how ISE processes personal data. Use of the website does not require consent to this Privacy Policy. Where consent is legally required for specific processing activities, such consent will be obtained separately.
1. Controller and Contact Details
The controller responsible for processing personal data within the meaning of the Swiss Federal Act on Data Protection (FADP) and, where applicable, the General Data Protection Regulation (GDPR) is:
Institut für
seltene Erden und Metalle AG
Furrengasse
21
6004 Lucerne
Switzerland
Telephone:
+41 (0) 41 5 11 11 20
Email: [email protected]
Website: www.ise-ag.com
Data protection enquiries and requests from data subjects may be addressed to [email protected] or sent by post to the address above.
2. Scope and Applicable Data Protection Law
This Privacy Policy applies to the ISE website and to the processing of personal data in connection with ISE services and business relationships, including in particular information and market data services, Metal Quotes and Real Time Quotes, certification, inspection, analysis and valuation services, Metal Audits, as well as storage and custody services.
ISE is a company domiciled in Switzerland. Swiss data protection law applies primarily, in particular the Swiss Federal Act on Data Protection (FADP) and the Data Protection Ordinance.
Where ISE processes personal data in circumstances in which the GDPR or other foreign data protection laws apply, ISE will additionally comply with the applicable requirements.
Mere use of the website does not require acceptance of this Privacy Policy. Where consent is legally required, for example for certain non-essential analytics or marketing technologies, consent will be obtained separately or the relevant technology will not be used.
3. Principles and Purposes of Data Processing
ISE processes personal data only to the extent necessary and proportionate for a specified and recognisable purpose.
Personal data may be processed in particular for the following purposes:
- providing, operating, securing and developing the website and IT systems;
- processing enquiries and communicating with prospective customers, customers, suppliers, business partners and public authorities;
- initiating, concluding, administering and performing contracts;
- registering and administering user accounts, subscriptions and access to information and market data services;
- providing Metal Quotes, Real Time Quotes, market information and other information services;
- carrying out and documenting certifications, inspections, sampling, analyses, valuations and Metal Audits;
- issuing and administering Inspection Reports, Sample Taking Reports, analysis reports, valuations, Safekeeping Receipts and similar documents;
- carrying out and administering storage, custody, handling, logistics and related services;
- invoicing, payment processing, accounting, debt collection and the establishment, exercise or defence of legal claims;
- complying with legal, regulatory, tax, commercial, customs and record-keeping obligations;
- fraud prevention, IT security, abuse prevention and risk management;
- sending newsletters and other information where permitted or consented to;
- analysing the use of our website and optimising our services where permitted by applicable law.
4. Categories of Personal Data Processed
Depending on the relationship with ISE, the following categories of personal data may in particular be processed:
- master data such as name, company, function, address, country and language;
- contact data such as email address, telephone number and communication details;
- contractual and order-related data, including booked services, subscriptions, contract periods and correspondence;
- user account and access data, as well as information regarding the use of restricted information services;
- invoice, payment and transaction data;
- technical data such as IP address, device and browser information, access times and log data;
- data relating to goods, ownership and disposal rights, deliveries, storage, transport, customs and logistics;
- information concerning beneficial owners (UBOs), powers of representation and signature, as well as identification and compliance information where required for the relevant business relationship;
- content and metadata relating to inspections, sampling, analyses, valuations, Metal Audits and safekeeping documentation, insofar as such information can be linked to an individual;
- marketing and consent data, including newsletter registration, opt-in/opt-out information and, where applicable, preferences.
5. Sources of Personal Data
We primarily obtain personal data directly from the individuals concerned or from companies and organisations for which they work.
Personal data may also be obtained from contractual partners, authorised representatives, beneficial owners, warehouse and logistics partners, laboratories, inspection partners, payment service providers, publicly accessible sources, public authorities or other third parties where necessary for the relevant service or a lawful purpose.
6. Visiting Our Website and Technical Log Data
When you visit our website for purely informational purposes, technically necessary data is processed in order to deliver the website and ensure its stability and security.
This may include in particular:
- IP address;
- date and time of access;
- page or file requested;
- referrer URL;
- browser type and browser version;
- operating system and device type;
- HTTP status code and amount of data transferred.
This data is processed in particular for technical delivery, error analysis, defence against attacks and ensuring IT and network security.
Where the GDPR applies, such processing is generally based on our legitimate interest in providing a secure and functional online service.
7. Cookies and Similar Technologies
Our website may use cookies and similar technologies. These are technologies that store or access information on a user's device and that may enable the technical operation or analysis of a website.
We distinguish in particular between:
- strictly necessary technologies required for operation, security, login, language settings or other expressly requested functions;
- functional technologies supporting convenience features;
- analytics and statistics technologies;
- marketing and remarketing technologies.
Strictly necessary technologies may be used without separate consent where permitted under the applicable law.
Non-essential analytics, tracking or marketing technologies are used only where there is an adequate legal basis and, where required, after prior consent has been given.
You may delete or block cookies through your browser settings. This may restrict certain website functions.
Where a cookie or consent management tool is provided on the website, consents given there may be changed or withdrawn at any time with effect for the future.
8. Registration, User Accounts, Subscriptions and Information Services
Certain services may require a user account or subscription.
For this purpose, we process in particular master and contact data, access credentials, contractual and subscription information, payment status and usage data insofar as required for the provision, security, billing and administration of the relevant service.
This applies in particular to access to Metal Quotes, Real Time Quotes and other information and market data services.
Use of such services may be linked to a user account and logged for security, licensing and billing purposes.
9. Contact and Electronic Communications
If you contact us by email, contact form, telephone or other communication channels, we process the information provided by you for the purpose of handling your enquiry and further communication.
This generally includes your name, contact details, the content of your message, attachments and technical and time-related metadata.
Where ISE offers WhatsApp or comparable messaging services for business communication and you voluntarily use such a channel, the relevant service provider may also process data.
In the case of WhatsApp, communication metadata in particular may be processed. The respective platform provider's own privacy policy additionally applies to its processing activities.
10. Newsletter and Email Marketing
If you subscribe to our newsletter, we process your email address and any additional information voluntarily provided for the purpose of sending the newsletter.
Where legally required, we use a double opt-in procedure to confirm and document the subscription.
You may unsubscribe from the newsletter at any time using the unsubscribe link contained in the relevant email or by contacting [email protected]. Withdrawal applies with effect for the future.
ISE may use a specialised newsletter service provider for distribution, currently including Mailchimp, a service of The Rocket Science Group LLC d/b/a Mailchimp, an Intuit company.
Recipient data may be processed in countries outside Switzerland. International data transfers are governed by Section 17 of this Privacy Policy.
Where open or click tracking is used in newsletters, this is done only in accordance with applicable law. Where consent is required, such consent will be obtained or the tracking will not be activated without consent.
11. Web Analytics, Advertising and Marketing Technologies
ISE may use services provided by external providers for reach measurement, analytics, optimisation and advertising of its online services.
These may include services provided by Google Ireland Limited and Meta Platforms Ireland Limited, for example web analytics, Google Ads, remarketing or Meta Pixel technologies.
When such services are used, technical data, IP addresses, cookie or device identifiers, interactions with the website and information regarding accessed content may in particular be processed and transferred to the relevant providers.
Depending on the configuration, providers may also process data for their own purposes.
Where consent is required under applicable law, such non-essential analytics and marketing technologies will only be activated after consent has been given.
Consent may be withdrawn at any time with effect for the future.
The specific analytics and marketing services used on the website may change. ISE will update this Privacy Policy or the cookie/technology information provided on the website if the services used change materially.
12. Hosting, Content Delivery and IT Security
ISE may use specialised IT service providers for hosting, content delivery, protection against attacks, performance and IT security.
These may include Cloudflare, Inc.
Such providers may process technical information, such as IP addresses, access data and security data, insofar as necessary to provide and secure the website.
Processing is carried out within the framework of the respective roles and contractual arrangements. Where data is processed in countries outside Switzerland, the international data transfer provisions in Section 17 apply.
13. Certifications, Inspections, Sampling, Analyses and Valuations
In connection with certification, inspection, sampling, analysis and valuation services, ISE processes personal data insofar as necessary for the performance, documentation and traceability of the engagement.
This may include data relating to customers, contact persons, owners, persons authorised to dispose of goods, representatives, beneficial owners and participating laboratory, transport and logistics partners.
Processed data may be included in Inspection Reports, Sample Taking Reports, analysis reports, valuations or other engagement-related documents.
ISE may engage specialised laboratories, experts, inspection partners or logistics partners for the performance of services and may provide them with the data necessary for this purpose.
14. Metal Audits
As part of Metal Audits, ISE inspects and evaluates complete lots of goods.
In addition to goods-related information, personal data relating to customers, owners, persons authorised to dispose of the goods, beneficial owners, warehouse operators, suppliers, carriers, contact persons and other persons or companies involved with the relevant lot may be processed.
The processing is carried out in particular for engagement identification, traceability of the chain of custody and documentation, inspection, sampling, analysis and valuation, as well as preparation of the audit report.
15. Safekeeping Receipts, Storage, Custody and Logistics
In connection with Safekeeping Receipts and storage, custody, handling and logistics services, ISE processes in particular contractual, contact, ownership, disposal, UBO, goods, storage, transport, customs and billing data where necessary for the relevant service.
ISE operates or uses warehouse and bonded warehouse structures including in Embrach, Kloten and Dubai.
For the performance of storage and logistics services, personal data may be disclosed to local warehouse operators, logistics companies, customs and transport providers and other partners required for contract performance.
Storage and custody services are governed by the respective separate storage agreements.
Where personal data is processed in connection with a storage agreement, such processing is carried out in particular for contract performance, access control, documentation, inventory administration, issuance of safekeeping documents, billing and compliance with legal and customs requirements.
16. Payments and Payment Service Providers
For paid services, we process the data required for invoicing, payment, accounting and receivables management.
Where payment service providers are used, they receive the data necessary to process the respective payment.
Depending on the available payment method, credit card providers, PayPal or other payment service providers may in particular be used.
The contractual and privacy terms of the respective payment service provider additionally apply to processing carried out by that provider.
Where payments are processed externally, ISE generally receives only the information required for payment confirmation, allocation and accounting.
17. Recipients of Personal Data and International Data Transfers
ISE discloses personal data only insofar as required for the purposes described in this Privacy Policy or otherwise permitted by law.
Recipients may include in particular:
- IT, hosting, cloud, security and telecommunications service providers;
- newsletter, analytics and marketing service providers;
- payment service providers, banks and billing service providers;
- laboratories, testing institutes, experts and inspection partners;
- warehouse operators, bonded warehouse, logistics, transport, customs and handling partners;
- lawyers, fiduciaries, tax advisers, auditors, insurers and debt collection providers;
- public authorities, courts and other public bodies where there is a legal obligation or entitlement;
- other contractual partners where disclosure is necessary for the performance of an engagement or contract.
Recipients may be located in Switzerland, the European Economic Area, the United Kingdom, the United States, the United Arab Emirates or other countries where necessary for the relevant service or provider used.
Personal data is transferred to a country without a level of data protection recognised as adequate by the Swiss Federal Council only where appropriate safeguards are in place or a statutory exception applies.
Appropriate safeguards may include recognised standard contractual clauses and, where required, supplementary protective measures.
In the case of services provided by US companies, a transfer may also be based on an applicable and recognised data protection framework where the relevant recipient is appropriately certified.
Where the GDPR applies, transfers to third countries are carried out in accordance with Articles 44 et seq. GDPR, in particular on the basis of an adequacy decision, appropriate safeguards or a statutory derogation.
18. Retention Period
ISE stores personal data only for as long as required for the relevant processing purpose or for as long as statutory, contractual, tax, accounting, commercial, customs, evidentiary or documentation obligations apply.
The specific retention period depends on the category of data and the relevant business relationship.
Contractual, invoicing, audit, certification, analysis, storage and business documentation may be retained beyond the end of the active business relationship where necessary to comply with legal obligations or to establish, exercise or defend legal claims.
Newsletter data is generally used until consent is withdrawn or the individual unsubscribes. Evidence of consent or withdrawal may be retained for longer where required.
19. Data Security
ISE implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, disclosure or destruction.
Protective measures are determined taking into account the state of the art, the nature and scope of processing and the relevant risks, and are adapted where necessary.
However, completely risk-free transmission of data over the internet cannot be guaranteed. Particularly sensitive or confidential information should therefore be transmitted only via appropriate communication channels.
20. Legal Bases Where the GDPR Applies
Where the GDPR applies to a specific processing activity, ISE relies in particular on one or more of the following legal bases:
- Article 6(1)(b) GDPR for entering into or performing a contract;
- Article 6(1)(c) GDPR for compliance with legal obligations;
- Article 6(1)(f) GDPR for the legitimate interests of ISE or third parties, in particular secure operations, communication, fraud prevention, legal enforcement and appropriate business development;
- Article 6(1)(a) GDPR where consent has been obtained.
Consent may be withdrawn at any time with effect for the future. The lawfulness of processing carried out prior to withdrawal remains unaffected.
21. Rights of Data Subjects
Subject to applicable data protection law, individuals may in particular have the right to:
- request information as to whether and which personal data ISE processes about them;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data or cessation of certain processing activities where no statutory or overriding grounds prevent this;
- object to data processing where provided for by applicable law;
- withdraw consent at any time with effect for the future;
- where the statutory requirements are met, request the release or transfer of certain personal data in a commonly used electronic format;
- exercise additional rights under the GDPR where it applies to the relevant processing activity.
To exercise your rights, please contact [email protected].
To prevent unauthorised disclosure of personal data, ISE may request reasonable proof of identity.
In Switzerland, you may also contact the Federal Data Protection and Information Commissioner (FDPIC).
Where the GDPR applies, you also have the right to lodge a complaint with the competent data protection supervisory authority.
22. Automated Individual Decision-Making and Profiling
In the ordinary course of business, ISE does not make decisions based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect that individual without informing the person concerned accordingly.
Where profiling or automated decision-making with particular legal consequences is used in an individual case, ISE will provide information in accordance with applicable law.
23. Minors
ISE's business services are generally directed at adults and companies.
ISE does not intend to deliberately collect personal data from children without an appropriate legal basis.
If such data becomes known to ISE, it will be reviewed and deleted or processed further only where a lawful basis exists.
24. External Links and Third-Party Services
Our website may contain links to websites or services operated by third parties.
The relevant third-party provider is generally responsible for processing carried out through such external services. When external services are accessed, their own privacy policies apply.
25. Amendments to this Privacy Policy
ISE may amend this Privacy Policy at any time, in particular in the event of changes to legal requirements, technologies used or services offered.
The version currently published on our website applies.
In the event of material amendments, ISE may provide an appropriate notice regarding the updated Privacy Policy.
Institut für
seltene Erden und Metalle AG
Furrengasse
21
6004 Lucerne
Switzerland
[email protected]
www.ise-ag.com