How CryptoVault collects, stores, and safeguards investor data in compliance with Swiss and EU regulatory standards.
Last updated: July 2026
Full name, email address, password (hashed), and role assignment collected at registration.
Government-issued identification, date of birth, country of residence, and verification selfies required for identity verification under AML regulations.
Deposit and withdrawal records, wallet addresses, transaction hashes, payment proof uploads, and investment plan selections.
Live chat transcripts and support email correspondence, retained for dispute resolution and quality assurance.
IP address, browser type, device fingerprint, and session logs used for fraud detection and security monitoring.
All personal data and KYC documents are encrypted using AES-256-GCM. Encryption keys are rotated quarterly and stored in a hardware security module (HSM).
All data transmitted between your device and our servers uses TLS 1.3 with perfect forward secrecy.
Data access is restricted on a need-to-know basis. Admin actions are logged and auditable. No employee can access your wallet private keys.
KYC documents are retained for 5 years after account closure per regulatory requirements. Transaction records are retained for 7 years.
To activate investments, process withdrawals, and maintain your portfolio dashboard.
To verify investor identity, monitor transactions for suspicious activity, and fulfil reporting obligations to Swiss financial authorities.
To detect unauthorised access, prevent money laundering, and protect the platform from malicious actors.
To send deposit/withdrawal confirmations, security alerts, and important platform notices. Marketing emails are opt-in only.
We may share data with Swiss financial regulators and law enforcement when legally compelled or when reporting suspicious transactions under AML law.
Identity documents are processed through accredited third-party verification services. These partners are GDPR-compliant and bound by data processing agreements.
Wallet infrastructure is managed by institutional custody partners who do not have access to your personal data — only transaction routing information.
CryptoVault never sells, rents, or trades investor data to any third party for marketing or commercial purposes.
You may request a complete copy of your personal data at any time. We provide it in a machine-readable format within 30 days.
You can update your account information through the dashboard. For KYC corrections, contact support with verification.
You may request account closure. Note that KYC and transaction records are retained per regulatory retention requirements.
You may opt out of marketing communications at any time. Security and transactional emails cannot be disabled.
Our DPO oversees all data handling practices and can be reached through the support contact form for privacy-related enquiries.
CryptoVault operates under Swiss financial regulation (FINMA) and complies with GDPR, the Swiss Data Protection Act, and applicable AML/KYC directives.
In the event of a data breach, affected investors will be notified within 72 hours of confirmation, per GDPR Article 33.
This policy may be updated to reflect regulatory changes. Material updates will be communicated to all investors via email.
Questions about your data? Contact our Data Protection Officer through the support contact form.
CryptoVault is registered in Switzerland and operates under FINMA oversight. This policy complies with GDPR (EU 2016/679) and the Swiss Data Protection Act (revFADP).