Legal

Privacy Policy

Last updated: 06 June 2026

SwissBorg SA ("SwissBorg", "we", "our", or "us") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information about you when you use our services.

1. Data We Collect

We collect the following categories of personal data:

  • Identity data: name, date of birth, nationality, government-issued ID
  • Contact data: email address, phone number, postal address
  • Financial data: bank account details, transaction history, wallet addresses
  • Technical data: IP address, device type, browser, app usage data
  • KYC/AML data: identity verification documents as required by law

2. How We Use Your Data

We use your personal data to:

  • Provide, maintain, and improve our services
  • Process transactions and manage your account
  • Comply with legal and regulatory obligations (AML, KYC)
  • Prevent fraud, money laundering, and other illegal activities
  • Send you service updates and security notifications
  • Provide customer support
  • Send marketing communications (where you have opted in)

We process your data under the following legal bases (GDPR Article 6):

  • Contract performance — to provide the services you have requested
  • Legal obligation — to comply with AML, KYC, and tax laws
  • Legitimate interests — fraud prevention and service improvement
  • Consent — for marketing communications and optional cookies

4. Sharing Your Data

We may share your data with:

  • Service providers — KYC verification providers, payment processors, cloud hosting
  • Regulatory authorities — as required by law (AMF, FIU, tax authorities)
  • Group companies — other SwissBorg entities for the purposes described above
  • Business transfers — in connection with a merger or acquisition

We never sell your personal data to third parties.

5. Security

We implement technical and organisational measures to protect your data, including:

  • AES-256 encryption for data at rest
  • TLS 1.3 for all data in transit
  • Multi-Party Computation (MPC) for private key management
  • Regular third-party security audits and penetration testing
  • 24/7 security monitoring and anomaly detection

6. Cookies

We use cookies and similar technologies to operate our website. For full details, please see our Cookie Policy.

7. Your Rights

Under GDPR, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion ("right to be forgotten")
  • Portability — receive your data in a structured, machine-readable format
  • Object — object to processing based on legitimate interests
  • Withdraw consent — at any time, for consent-based processing

To exercise your rights, contact us at privacy@swissborg.com.

8. Data Retention

We retain personal data for as long as necessary to fulfil the purposes outlined in this policy, and as required by law. KYC and financial records are retained for a minimum of 5 years following the end of our business relationship, as required by AML regulations.

9. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact our Data Protection Officer:

You also have the right to lodge a complaint with your local data protection authority.