Version 1.0 — effective 20 August 2026
SimpleWealth AG ("SimpleWealth", "we", "us") is a Swiss company whose live service is fiat-to-crypto on- and off-ramping: converting traditional currency into digital assets and back again. Custody and crypto direct debit are in beta and are not generally available; where you take part in a beta programme, this policy covers that processing too, alongside any separate beta terms we give you. Running these services means handling information about the people who use them. This policy sets out what we hold, why we hold it, who else sees it, and what you can ask us to do about it.
"Personal data" here means any information relating to an identified or identifiable individual. Where this policy refers to "you", it means any individual whose data we process — a client, a prospective client, a beneficial owner or authorised signatory of a corporate client, a supplier contact, a job applicant, or a visitor to our website.
This policy is governed by the Swiss Federal Act on Data Protection (FADP) and its implementing Ordinance. SimpleWealth is a Swiss company operating under Swiss law and does not market its services abroad. Where someone resident elsewhere approaches us on their own initiative and we accept them as a client, the data protection law of their country may also apply to that relationship. We assess those cases individually rather than restating every jurisdiction's rules here, and nothing in this policy limits a right you hold under the law of your own country.
Some of our services carry their own, more specific notices — for example, terms of business, account-opening documentation, or notices given at the point we collect information. Where a specific notice covers a particular activity, it takes precedence over this general policy for that activity.
If you give us personal data about someone else — a co-signatory, a beneficial owner, a family member, a professional adviser — please make sure you are entitled to do so, that the information is accurate, and that the person concerned has seen this policy.
The controller for the processing described in this policy is:
SimpleWealth AGQuestions about this policy, or requests to exercise the rights described in section 10, should go to the address above.
SimpleWealth has not appointed a Data Protection Officer. The FADP leaves this voluntary for private controllers. Data protection queries go to the address above and are handled internally.
The information we hold falls into three groups, depending on where it comes from.
Under the FADP, a private company may process personal data unless doing so unlawfully breaches your personality rights. Where it would — because you have objected, because the data is sensitive, or because we pass it to a third party — we need a justification: your consent, a statutory basis, or an overriding private or public interest. The table below sets out what we do and the justification we rely on for each.
| Purpose | What this involves | Justification under the FADP |
|---|---|---|
| Opening accounts and delivering on- and off-ramping (and beta custody or direct debit, where you use it) | Onboarding, executing your conversion orders, moving fiat and digital assets, settling, reporting and servicing your account. | Necessary to perform our contract with you, or to take steps you have asked for before we enter into one. |
| Anti-money laundering, counter-terrorist financing, sanctions and tax compliance | Identity verification, beneficial ownership determination, ongoing screening and transaction monitoring, travel-rule messaging, record-keeping, and reporting to the Money Laundering Reporting Office where required. | Required by Swiss law, principally AMLA and its implementing rules. Where screening surfaces sensitive personal data — political exposure, or criminal proceedings and sanctions — that same statutory duty is what permits it. |
| Fraud prevention and information security | Authentication, anomaly detection, logging, penetration testing, incident response and access control. | Legal duty, together with our overriding interest in protecting client assets and the integrity of our systems. |
| Regulatory supervision, audit and internal control | Responding to supervisory requests, external and internal audit, risk management, and maintaining our control framework. | Legal and regulatory duty, together with our overriding interest in running a properly controlled business. |
| Establishing, exercising and defending legal claims | Preserving evidence, handling disputes, complaints and enforcement, and responding to court and administrative proceedings. | Our overriding interest in establishing, exercising and defending legal claims, including where the material is sensitive. |
| Service improvement and product development | Analysing how our services are used, testing changes, and building new functionality — using aggregated or pseudonymised data wherever it will do the job. | Our overriding interest in developing services our clients want. |
| Marketing and client communications | Sending service updates, market commentary, invitations and newsletters, and running events. | Your consent where the law requires it; otherwise our overriding interest in telling existing clients about comparable services. You can opt out at any time — see section 10. |
| Recruitment | Assessing applications, interviewing, and taking up references. | Steps taken at your request before entering an employment contract; our overriding interest in staffing the business. |
| Corporate transactions | Due diligence and integration in connection with a financing, acquisition, disposal or reorganisation. | Our overriding interest in managing the corporate structure of the business. |
Where we rely on consent — for a newsletter subscription, for optional cookies, or for anything else we ask you to agree to specifically — you can withdraw it at any time. Withdrawal takes effect going forward and does not make our earlier processing unlawful.
Where we rely on a legitimate interest, you have the right to object; section 10 explains how, and what happens next.
Visiting our website causes your browser to send us technical data — IP address, browser and operating system, the pages requested, and the time of the request. We log this to keep the site available and secure, to diagnose faults, and to understand traffic in aggregate. Server logs are kept for a short period and then deleted.
Cookies are small files stored on your device. Session cookies expire when you close your browser; persistent cookies remain until they lapse or you delete them. We use strictly necessary cookies to make the site and your account work — these cannot be switched off without breaking the service. Any cookie that is not strictly necessary, including analytics and marketing cookies, is set only where you have agreed to it, and you can change or withdraw that choice at any time through the cookie settings on our site or through your browser. Most browsers accept cookies by default and allow you to block or delete them; blocking strictly necessary cookies will stop parts of the site working.
Google Analytics. We use Google Analytics, provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), with Google LLC in the United States acting as its sub-processor. It tells us how the site is used in aggregate: which pages are viewed, the path visitors take through the site, time spent on a page, the page they leave from, approximate location at country or city level, device and browser characteristics, and whether a visitor is new or returning.
Google Analytics loads only after you accept analytics cookies. If you decline, or have not yet chosen, the tag does not fire and no analytics data about your visit is collected. You can change or withdraw that choice at any time through the cookie settings on our site.
We have configured the service to collect as little as it can: Google Analytics does not log or retain full IP addresses, deriving only coarse location before discarding the address, and we have switched off Google Signals and data sharing with other Google products. Google processes this data on our behalf under its data processing terms. Google may nonetheless be able to associate the data with a Google account you hold, in which case that processing is governed by Google's own privacy notice rather than this one. Transfers to the United States rely on Google LLC's certification under the Swiss–U.S. Data Privacy Framework, as described in section 6.
Google Analytics is the only third-party tool on our website. We run no advertising, retargeting or other tracking services, no tag manager, no support chat, and no media embedded from other platforms. If we add any of these, we will update this policy before doing so.
We disclose personal data only where there is a reason to, and only to the extent that reason requires. The recipients fall into these categories:
We do not sell personal data.
Some of our recipients are outside Switzerland, including in the European Union, the United Kingdom and the United States. Where a country appears on the Swiss Federal Council's list of states with adequate data protection, no further step is needed.
Where it does not, we put a safeguard in place first. We use the standard contractual clauses recognised by the Federal Data Protection and Information Commissioner for Swiss transfers, with the Swiss adaptations the Commissioner requires; the Swiss–U.S. Data Privacy Framework, in force since 15 September 2024, where the recipient holds a current certification under it; binding corporate rules approved by the competent authority; or, failing those, a statutory exception under the FADP — a transfer necessary to perform a contract with you, to establish or defend a legal claim, or one you have expressly consented to.
Where we rely on the Swiss–U.S. Data Privacy Framework — as we do for Google Analytics — we check that the recipient is listed with Swiss coverage specifically, and not only a European certification, because the two are recorded separately and a company can hold one without the other. We keep contractual safeguards in place behind that reliance where we can, since an adequacy framework can be challenged and withdrawn.
Copies of the safeguards we use are available on request, subject to redaction of commercially confidential terms.
We keep personal data for as long as the purpose it was collected for lasts, and then for as long as a legal obligation or a live legal risk requires. In practice:
When a retention period ends, we delete the data or anonymise it so that it can no longer be linked to you. Data held in backups is deleted on the backup cycle rather than immediately.
We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, role-based access control and least-privilege provisioning, multi-factor authentication, network segmentation and monitoring, key management and custody controls for digital assets, secure development practices, vendor security assessment, staff training and confidentiality undertakings, logging, and an incident response process.
No system is perfectly secure, and ordinary email in particular travels unencrypted and can be intercepted or altered. Please use our secure channels for anything sensitive, and never send us private keys, seed phrases or passwords — we will never ask for them.
If a breach occurs that is likely to result in a high risk to you, we will notify you and the Federal Data Protection and Information Commissioner, and any other authority we are required to inform, within the timeframes the law sets.
Parts of our compliance and risk processes run automatically. Sanctions and PEP screening, transaction monitoring and wallet risk scoring apply rules and models to your data and can generate an alert or, in defined cases, hold or refuse a transaction. We also build profiles for suitability assessment and, where permitted, to tailor the communications you receive.
Where an automated process could produce a decision with a legal or similarly significant effect on you — refusing to onboard you, or blocking a transaction — a member of staff reviews the case before the decision is final, except where the law requires us to act automatically or prohibits us from telling you (as it does for certain AML measures). Where a decision is taken solely by automated means and the FADP gives you rights in that situation, we will tell you, and you may ask for the decision to be reviewed by a person, state your position, and contest the outcome.
These rights come to you under the FADP. Subject to the conditions and limits it sets, you can ask us to:
To make a request, contact us using the details in section 1. We will normally need to verify your identity before we act, since releasing data to the wrong person is itself a breach.
Some requests we will have to decline in whole or in part — where a legal retention duty overrides erasure, where disclosure would reveal another person's data or a confidential internal assessment, where an AML measure is subject to a prohibition on tipping off, or where we need the data to defend a legal claim. We will tell you which ground applies unless we are prohibited from doing so.
Exercising some of these rights may affect what we can do for you. Deleting identification data, for example, would leave us unable to maintain your account, because we cannot hold a relationship we are not permitted to hold. Where a request would have that consequence, we will say so before acting on it.
If you are unhappy with how we have handled your data, please raise it with us first — we would rather fix it directly.
You can also report the matter to the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern (www.edoeb.admin.ch), which supervises private data processing in Switzerland, or bring a claim before the competent Swiss civil court. If you are resident outside Switzerland, you may also have a route to the data protection authority of your own country.
We may update this policy as our services, our systems or the law change. The version published at www.simplewealth.ch is the one that applies, and we date each version so you can see when it last changed.
Where a change materially affects how we handle your data, and where the policy forms part of an agreement with you, we will tell you by email or another appropriate route before it takes effect.
Questions about this document? Email info@simplewealth.ch.