Legal

Privacy Policy

How CryptoVault collects, stores, and safeguards investor data in compliance with Swiss and EU regulatory standards.

Last updated: July 2026

1. Data We Collect

Account Information

Full name, email address, password (hashed), and role assignment collected at registration.

KYC Documents

Government-issued identification, date of birth, country of residence, and verification selfies required for identity verification under AML regulations.

Transaction Data

Deposit and withdrawal records, wallet addresses, transaction hashes, payment proof uploads, and investment plan selections.

Communications

Live chat transcripts and support email correspondence, retained for dispute resolution and quality assurance.

Technical Data

IP address, browser type, device fingerprint, and session logs used for fraud detection and security monitoring.

2. How We Store & Protect Data

Encryption at Rest

All personal data and KYC documents are encrypted using AES-256-GCM. Encryption keys are rotated quarterly and stored in a hardware security module (HSM).

Encryption in Transit

All data transmitted between your device and our servers uses TLS 1.3 with perfect forward secrecy.

Access Controls

Data access is restricted on a need-to-know basis. Admin actions are logged and auditable. No employee can access your wallet private keys.

Data Retention

KYC documents are retained for 5 years after account closure per regulatory requirements. Transaction records are retained for 7 years.

3. How We Use Your Data

Service Delivery

To activate investments, process withdrawals, and maintain your portfolio dashboard.

Regulatory Compliance

To verify investor identity, monitor transactions for suspicious activity, and fulfil reporting obligations to Swiss financial authorities.

Security & Fraud Prevention

To detect unauthorised access, prevent money laundering, and protect the platform from malicious actors.

Communications

To send deposit/withdrawal confirmations, security alerts, and important platform notices. Marketing emails are opt-in only.

4. Data Sharing & Third Parties

Regulatory Authorities

We may share data with Swiss financial regulators and law enforcement when legally compelled or when reporting suspicious transactions under AML law.

KYC Verification Partners

Identity documents are processed through accredited third-party verification services. These partners are GDPR-compliant and bound by data processing agreements.

Custody Providers

Wallet infrastructure is managed by institutional custody partners who do not have access to your personal data — only transaction routing information.

No Data Sales

CryptoVault never sells, rents, or trades investor data to any third party for marketing or commercial purposes.

5. Your Rights

Access & Portability

You may request a complete copy of your personal data at any time. We provide it in a machine-readable format within 30 days.

Correction

You can update your account information through the dashboard. For KYC corrections, contact support with verification.

Erasure

You may request account closure. Note that KYC and transaction records are retained per regulatory retention requirements.

Consent Withdrawal

You may opt out of marketing communications at any time. Security and transactional emails cannot be disabled.

6. Contact & Compliance

Data Protection Officer

Our DPO oversees all data handling practices and can be reached through the support contact form for privacy-related enquiries.

Regulatory Framework

CryptoVault operates under Swiss financial regulation (FINMA) and complies with GDPR, the Swiss Data Protection Act, and applicable AML/KYC directives.

Breach Notification

In the event of a data breach, affected investors will be notified within 72 hours of confirmation, per GDPR Article 33.

Policy Updates

This policy may be updated to reflect regulatory changes. Material updates will be communicated to all investors via email.

Questions about your data? Contact our Data Protection Officer through the support contact form.

CryptoVault is registered in Switzerland and operates under FINMA oversight. This policy complies with GDPR (EU 2016/679) and the Swiss Data Protection Act (revFADP).