Kapitalden
Legal

Privacy Policy

Version 5.0 – Last updated: June 15, 2026

Article 1: Identification of the Controller

This privacy policy describes the strict data processing protocols of Kapitalden ("the Platform", "we", "us", or "our"), headquartered at Bahnhofstrasse 100, 8001 Zurich, Switzerland. We act as the controller within the meaning of the Swiss Federal Act on Data Protection (FADP) and – for users residing in the EEA – the EU General Data Protection Regulation (GDPR). To ensure absolute data integrity, we have appointed a Data Protection Officer (DPO) who can be reached directly at [email protected].

Article 2: Categories of Personal Data Collected

In accordance with the principle of data minimization, we collect:

Identity characteristics: Full legal name, date of birth, nationality, and government-issued identification for mandatory KYC (Know Your Customer) and AML (Anti-Money Laundering) verification.

Financial telemetry: Source of funds, bank details, digital wallet addresses (public keys), and comprehensive transaction histories.

Digital footprint: IP addresses, hardware specifications of devices, browser types, and detailed interaction logs with our AI-powered analytics interfaces.

Article 3: Legal Basis and Purpose of Processing

Our collection and use of information are based on the following pillars:

Contractual necessity: Essential for opening, managing, and providing your account as well as our digital analytics services.

Legal obligations: Compliance with Swiss Anti-Money Laundering Act (AMLA) and financial market regulatory retention requirements.

Legitimate business interests: Proactive fraud prevention, system security analysis, and protection of our digital network infrastructure against cyber risks.

Explicit consent: For personalized market insights, optional system notifications, and non-essential analytics cookies (revocable at any time).

Article 4: Advanced Security and Data Sovereignty

Encryption: All stored data (Data at Rest) is secured using AES-256 cryptographic protocols.

Transmission: Data transmission (Data in Transit) is carried out via seamless TLS 1.3 end-to-end encryption.

Hosting: Data hosting is performed on highly secure, redundant server structures in Switzerland or the European Economic Area (EEA), ensuring full compliance with strict data protection and sovereignty standards.

Article 5: Retention and Your Statutory Rights

We retain identity and transaction records for a period of at least ten (10) years after the termination of the business relationship to comply with the legal obligations of the Swiss Code of Obligations (CO) and the AMLA. Under Swiss DPA, you have the right to access, rectify, block, or delete your data, as well as data portability. Inquiries should be sent in writing to [email protected]. Furthermore, you have the right to contact the Federal Data Protection and Information Commissioner (FDPIC).

EN