Legal

Privacy policy.

How SWIIX AG processes personal data in connection with this website and its onboarding process, under the Swiss Federal Act on Data Protection (FADP).

Controller & contact

This policy explains how SWIIX AG (“SWIIX”, “we”) processes personal data in connection with this website and its onboarding process, in accordance with the Swiss Federal Act on Data Protection (FADP). The controller responsible for the processing is:

SWIIX AG, Zugerstrasse 32, 6340 Baar, Switzerland. Data-protection contact: privacy@swiix.com.

Personal data we process
  • Identification and contact data of client representatives, beneficial owners and controlling persons (e.g. name, role, company, email, telephone, address).
  • Identity-document data collected during identity verification.
  • Sanctions, politically-exposed-person (PEP) and adverse-media screening data.
  • Transaction and payment data.
  • Website technical and log data (e.g. IP address, browser type, pages viewed) and cookies — see our Cookie Policy.
Purposes & legal bases
  • Contract — to assess, enter into and administer a business relationship, and to take steps at your request before doing so.
  • Legal obligations — AMLA customer due-diligence and identification, sanctions screening, and record-keeping.
  • Legitimate interests — security, fraud and abuse prevention, and the basic operation of this website.

SWIIX’s intended services will commence only upon affiliation to a self-regulatory organisation. Until then we process only the limited data needed to respond to enquiries and to prepare for onboarding.

Recipients & international transfers

We disclose personal data only where necessary, to the following categories of recipient: identity-verification and screening providers; payment and banking partners; crypto custody and blockchain-analytics providers; IT, hosting and communication providers; and Swiss authorities where legally required.

Some of these providers are located outside Switzerland, including in the EU/EEA and other countries. Where a destination country does not ensure an adequate level of protection, transfers are safeguarded by appropriate measures, such as an adequacy decision or the standard contractual clauses recognised by the Swiss authorities.

Retention

Personal data relating to a business relationship or a transaction is retained for ten years after the end of the relationship or the completion of the transaction, as required by Article 7 AMLA. Website and log data is retained in accordance with our internal data-retention policy, otherwise for a standard period of up to twelve months, unless a longer period is required for security or legal reasons.

Your rights & complaints

Subject to legal limits, you may request access to, rectification or erasure of, and the portability of, your personal data, object to processing, and withdraw any consent you have given. AMLA record-keeping obligations may prevent us from erasing certain data.

You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC). We do not take automated decisions producing legal effects without human involvement; all onboarding decisions are subject to human compliance review.

Last updated: 13 July 2026