• Pricing
  • About
Terms of servicePrivacy PolicyAML & KYC PolicySecurity
Risk Disclosure StatementPricingLicense and Registration

© 2026 ETI Tech AG. All rights reserved.

www.eti-tech.ch — Version 1.4 — July 2026

Privacy Policy

The website www.eti-tech.ch is produced and published by Eti-Tech AG, Müligässli 1, 8598 Bottighofen, Switzerland (“Eti-Tech”, “we”, “us”), registered in the Commercial Register of the Canton of Thurgau. As a Virtual Asset Service Provider (VASP) and member of the VQF Self-Regulatory Organisation (SRO) since November 2023, Eti-Tech AG is subject to Swiss financial market regulation and takes its data protection obligations with the utmost seriousness.

We are responsible for the collection, processing and use of your personal data in accordance with applicable law, including the Swiss Federal Act on Data Protection (revDSG/nDSG) and, where applicable, the EU General Data Protection Regulation (GDPR). We are committed to protecting your personal data and your privacy.

This Privacy Policy explains how Eti-Tech AG collects, uses, and discloses your personal data. Please read it carefully. Where the processing of your personal data requires your consent (for example, for marketing communications or non-essential cookies), we will request this separately and explicitly. Your access to or use of the website does not in itself constitute consent to any processing of personal data.

1. Controller / Responsible Person

The data controller responsible for the processing of your personal data is:

Eti-Tech AG

Müligässli 1, 8598 Bottighofen, Switzerland

Email: compliance@eti-tech.ch

Website: www.eti-tech.ch

For data protection enquiries, including in your capacity as a data subject, please contact us at compliance@eti-tech.ch. This address also serves as the contact point for our Data Protection Officer (DPO) function, which is reachable independently of Eti-Tech’s general management and can be contacted directly by data subjects and supervisory authorities. Eti-Tech has designated or engaged a qualified DPO given its large-scale systematic monitoring activities and biometric data processing. The name of the DPO or the external Dest.

2. What Personal Data We Collect

2.1 Data Collected During Website Use

When you visit our website for informational purposes only, our systems automatically collect the following technical data:

  • IP address
  • Date, time and time zone of your request
  • Pages accessed and content requested
  • HTTP status code and data volume transferred
  • Referring website
  • Browser type, version, language and operating system

2.2 Data Collected During Registration and Onboarding

As a regulated VASP and VQF SRO member, Eti-Tech AG is legally required to verify the identity of its customers (KYC – Know Your Customer) before providing services. When you register or place an order, we collect the following data depending on your account type:

Individual Accounts:

  • Full legal name, date and place of birth, nationality
  • Residential address and proof of address
  • Phone number and email address
  • Profession, employer, place(s) of business activity
  • Financial background: declaration of estimated income and assets, source(s) of income (employment, savings, inheritance, investment, own business, other)
  • Government-issued photo ID (passport, national ID or driver’s licence)
  • Biometric verification data (facial photograph and liveness check via our identity verification provider, Sumsub) — this data constitutes special category / sensitive personal data under GDPR Art. 9 and revDSG Art. 5(c), processed for identity verification under GDPR Art. 9(2)(g) (substantial public interest — AML/CTF obligations under AMLA and FINMA Circular 2016/7), subject to enhanced safeguards including strict access controls and data minimisation
  • Responses to AML/compliance questionnaire
  • Intended use and planned transaction volumes

Corporate / Business Accounts (in addition to the above):

  • Company name, legal form and registered address
  • Certificate of Incorporation and Articles of Association
  • Shareholder structure and beneficial owner information
  • Names and IDs of authorised signatories and their positions
  • Business purpose, turnover, profit and expected transaction profile

2.3 Data Collected During Transactions

When you use our exchange, conversion or custody services, we collect:

  • Transaction details (amounts, currencies, timestamps, order IDs, exchange rates)
  • Wallet addresses and blockchain transaction data (public keys, transaction hashes, chain/network information)
  • Results of blockchain analytics and wallet screening (risk scores assigned by our screening tool — see Section 6.3 below)
  • Payment method information (bank transfer reference, IBAN for verification purposes; no card data is stored on our servers)
  • Order history and account activity

Note on wallet addresses and blockchain data: Public wallet addresses and transaction hashes, when held by Eti-Tech in combination with your KYC identity information, constitute personal data and are treated as such throughout this Privacy Policy. Blockchain transactions are recorded on public, immutable ledgers beyond our control. The right to erasure applies to data held in Eti-Tech’s systems but cannot extend to public blockchain records, which we have no technical ability to modify or delete.

2.4 Communication Data

If you contact us by email, chat or other channels, we retain the content of your messages together with your contact details in order to respond to your enquiry and maintain our compliance records.

3. How We Use Your Personal Data

We use your personal data for the following purposes:

  • To provide and operate our cryptocurrency exchange, conversion, and custody services
  • To fulfil our legal obligations as a VASP and VQF SRO member, including AML/KYC compliance, transaction monitoring and suspicious activity reporting
  • To verify your identity and assess your risk profile in accordance with the Swiss Anti-Money Laundering Act (AMLA) and FINMA guidance
  • To assign and maintain your AML risk category (Low, Medium, or High) as required by our AML/CTF Policy and Appendix B of that policy, and to apply corresponding monitoring and due diligence measures
  • To conduct wallet screening and blockchain analytics on virtual asset addresses associated with your account, in accordance with the Travel Rule and our AML/CTF Policy (Section 5.8.2)
  • To process your orders, transactions and payments
  • To manage your user account
  • To communicate with you about your account, orders, and important service updates
  • To improve and develop our platform, products and services
  • To send you newsletters or marketing communications, where you have consented
  • To comply with applicable Swiss and international legal and regulatory obligations, including mandatory reporting to MROS, SECO and VQF
  • To detect, prevent and investigate fraud, money laundering and other illegal activities

4. Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contract performance (Art. 6(1)(b) GDPR / revDSG): Processing necessary to provide our services and fulfil our contractual obligations to you.
  • Legal obligation (Art. 6(1)(c) GDPR / revDSG): Processing required to comply with Swiss AML/KYC law (AMLA, AMLO, AMLO-FINMA), FINMA guidance and circulars, VQF SRO rules, and applicable sanctions regulations.
  • Legitimate interests (Art. 6(1)(f) GDPR / revDSG Art. 31): Processing necessary for our legitimate business interests, including fraud prevention, platform security, blockchain analytics (where not mandated by law), and service improvement, where our interests are not overridden by your fundamental rights. Note: AML risk scoring and mandatory transaction monitoring are processed primarily on the basis of legal obligation (see above), not legitimate interests. We have conducted balancing assessments for each legitimate-interests processing activity.
  • Consent (Art. 6(1)(a) GDPR / revDSG): Where you have provided specific consent, for example for marketing communications or optional features. You may withdraw consent at any time without affecting the lawfulness of prior processing.

5. Data Retention

We retain your personal data only for as long as necessary for the purposes for which it was collected, and in strict accordance with our legal obligations under Swiss AML law (Art. 7 AMLA, Art. 64 VQF-Regulation, Art. 958 CO):

Customer identification and KYC records:

Retained for a minimum of 10 years following the termination of the business relationship, as required by Art. 7 para. 3 AMLA and Art. 64 VQF-Regulation.

Transaction records and documentation:

Retained for a minimum of 10 years after the end of the financial year in which the relevant transaction was executed or the report was made, in accordance with Art. 958 CO and Art. 7 para. 3 AMLA. This may therefore extend beyond 10 years from the end of the business relationship depending on when transactions occurred.

Other records:

  • Account data: retained for the duration of your account and thereafter for the applicable legal retention period
  • Communication records: retained for as long as necessary to respond to your enquiry and satisfy applicable record-keeping requirements
  • Website technical data (logs): retained for a maximum of 6 months unless required longer for security or legal purposes

After the applicable retention period, data is securely deleted or anonymised. Withdrawn or previous versions of internal policies are retained for 10 years in accordance with the AML/CTF Policy.

6. Data Sharing and Disclosure

We do not sell, rent or trade your personal data to third parties. We may share your data in the following limited circumstances:

6.1 Service Providers and Processors

We engage carefully selected third-party providers to assist with identity verification (Sumsub), blockchain analytics and wallet screening, IT infrastructure, and compliance tooling. These providers act as data processors under contractual data protection agreements and are subject to confidentiality obligations.

6.2 Regulatory and Law Enforcement Authorities

We are required by Swiss law to disclose data to our supervisory authority, the VQF Self-Regulatory Organisation, and to the Money Laundering Reporting Office Switzerland (MROS), upon lawful request or where we have a legal obligation to report. This includes mandatory reporting under Art. 9 AMLA and sanctions reporting to SECO. FINMA, as the authority recognising VQF, may receive information indirectly through VQF’s supervisory process, or directly where required by law.

International Tax Reporting (AEOI/CRS): Switzerland participates in the OECD Automatic Exchange of Information (AEOI) framework (Common Reporting Standard / CRS) via the AEOI Act (AEIA). Depending on your country of residence, Eti-Tech may be required to report your account information to the Swiss Federal Tax Administration (FTA), which may onward-transmit this to the competent tax authority in your country of residence. The legal basis is legal obligation (GDPR Art. 6(1)(c) / revDSG).

FINMA International Supervisory Cooperation: FINMA, as the authority recognising VQF and overseeing the Swiss financial market, has the power under AMLA Art. 29 to share supervisory information with foreign financial market authorities. Where information originates from Eti-Tech, it flows to FINMA via VQF’s supervisory process; Eti-Tech has no control over such onward sharing by regulatory bodies once transmitted.

Note: Swiss banking secrecy does not apply to Eti-Tech AG, which is a non-bank VASP regulated under the AMLA framework.

Important limitation on your rights: In cases where we have filed or are required to file a report with MROS (or SECO) under Art. 9 AMLA or Art. 305ter para. 2 of the Swiss Criminal Code, we are legally prohibited from informing you of that report (Art. 10a AMLA — the “tipping-off” prohibition). During any such period, your rights of access, rectification, and information under data protection law are suspended to the extent required by Swiss AML law. This limitation applies for as long as the legal obligation subsists. See Section 9 for how this affects your data subject rights generally.

6.3 Blockchain Analytics and Wallet Screening

When you provide a virtual asset wallet address or initiate a crypto transaction, we conduct blockchain analytics and wallet screening using one or more specialist blockchain analytics and wallet-screening providers. This process analyses the risk profile of the wallet address against known risk indicators (e.g. exposure to sanctioned addresses, darknet markets, or mixing services) and assigns a risk score. The identity of our current screening provider(s) is available on request. The results are reviewed by our AML Special Unit and inform our decision to proceed with, restrict, or terminate a business relationship or transaction. Wallets approved after screening are added to our whitelist; transactions from non-whitelisted wallets trigger an alert for review.

6.4 Travel Rule: Inter-VASP Data Transfers

As required by the Crypto Travel Rule (Art. 14 VQF-Regulation and FATF Recommendation 16), when you send or receive virtual assets to or from an external wallet held at another regulated VASP, we are required to transmit the following information to the receiving or sending VASP via a secure communication protocol:

  • Your full name
  • Your public wallet address
  • Your residential address
  • The name and public address of the beneficiary

This data transfer is a legal obligation and constitutes a disclosure to a third party (the counterpart VASP) that we are required to make regardless of your consent. We only accept crypto transactions that comply with the same Travel Rule obligations on the sending side. The safeguards applicable to this transfer — including the legal basis under Swiss and EU data protection law where the receiving VASP is located outside Switzerland or an adequate jurisdiction — are set out in Section 6.7 below.

6.5 Banking and Payment Partners

Limited transaction data is shared with our banking and payment partners (including details required under Art. 10 AMLO-FINMA for fiat transfers: customer name, account number, address or date of birth) as required to process your transactions. The identity of our current banking and payment partners is available on request.

6.6 Legal Proceedings

Where necessary to establish, exercise or defend legal claims.

6.7 International Data Transfers

Certain processing activities require the transfer of personal data outside Switzerland. The following summarises the transfer categories and applicable safeguard mechanisms:

  • (a) Travel Rule transfers to foreign VASPs: mandatory legal obligation under FATF R16 / Art. 14 VQF-Regulation. Transfer basis: Art. 17(2)(c) revDSG / GDPR Art. 49(1)(c) (important public interest — AML/CTF compliance).
  • (b) Identity verification (Sumsub): where Sumsub processes data outside Switzerland or the EEA, transfers are conducted under Standard Contractual Clauses (SCCs) and a Data Processing Agreement imposing GDPR/revDSG-equivalent obligations.
  • (c) Analytics (Google Analytics / Google LLC, USA): EU-US Data Privacy Framework (DPF) for GDPR purposes; SCCs for revDSG purposes. See Section 8.1.
  • (d) Regulatory and law enforcement disclosures: transfers to foreign authorities pursuant to AMLA Art. 29, AEOI/CRS, or other mandatory legal obligations are conducted on the basis of legal obligation (GDPR Art. 6(1)(c) / revDSG).

Data storage location: In accordance with Art. 63 VQF-Regulation, all customer records, AMLA files, and transaction documentation are stored exclusively on servers located in Switzerland. Data is not stored on servers located outside Switzerland.

7. Automated Decision-Making and Risk Profiling

As part of our AML/CTF compliance obligations, we use automated tools (including screening software and blockchain wallet analytics) to support the assignment of a risk category (Low, Medium, or High) to each customer, based on criteria defined in our AML/CTF Policy (Appendix B). These tools flag relevant factors, but the resulting risk classification — and any decision to accept, restrict, continue, or terminate your business relationship — is always made or approved by a trained member of our First Line of Defence, our AML Special Unit, or Management, in accordance with our internal AML/CTF Policy, and never by an automated system acting alone. Consequently, this processing does not constitute a decision “based solely on automated processing” within the meaning of GDPR Art. 22 / revDSG Art. 21. This risk scoring affects:

  • The level of due diligence applied to your account
  • The transaction monitoring thresholds applied to your transactions
  • The frequency of periodic reviews of your AMLA file (Low risk: every 6 years; Medium risk: every 4 years; High risk: annually)
  • The management approval level required to accept or continue your business relationship

Risk categorisation is a legal requirement under Swiss AML law. Because it is not a solely automated decision, it is not, strictly speaking, subject to a right to object under Art. 21 GDPR; however, if you believe your risk category has been incorrectly assigned, you may always contact us at compliance@eti-tech.ch to request a review.

Your rights regarding risk decisions (offered as a transparency measure, consistent with the spirit of GDPR Art. 22 / revDSG Art. 21):

Right to information about the logic: The main factors used in risk scoring include (without limitation): country of residence and nationality; source of funds and wealth risk profile; planned transaction volumes and patterns; PEP status; sanctions screening results (UN, EU, SECO, OFAC, UK OFSI); wallet screening and blockchain analytics results; and business nature and purpose (for corporate accounts).

Significance and consequences: Low risk = standard due diligence and monitoring. Medium risk = enhanced monitoring and more frequent periodic review. High risk = Senior Management approval required for account acceptance or continuation, enhanced due diligence, and annual review.

Right to a further human review: Even though a human is always involved in the original decision, you may request that it be reviewed again by a different, more senior qualified member of our AML Special Unit or Management. Contact compliance@eti-tech.ch with your account details and the decision to be reviewed. We will acknowledge within 2 business days and complete the review within 10 business days. You may submit additional information in support of your request.

Limitations: AML risk categorisation is a legal obligation under AMLA and cannot be waived. Where an MROS reporting procedure is active, rights under this section may be suspended under Art. 10a AMLA.

Cookies, analytics, and other automated data collection on our website (see Section 8 below) rest on a separate legal basis (consent under applicable cookie/ePrivacy rules) and do not, on their own, result in any decision with a legal or similarly significant effect on you.

8. Cookies and Tracking

8.1 Cookies

Our website uses cookies – small text files stored on your device – to improve your experience. We use:

  • Session cookies: to maintain your session and carry information across pages without you having to re-enter data.
  • Persistent cookies: to recognise returning visitors and measure website usage patterns.
  • Analytics cookies: we use Google Analytics (Google LLC, USA) to analyse website usage. Google Analytics involves the transfer of personal data to Google’s servers in the United States. The US is not on the FDPIC’s adequate-country list. For GDPR purposes, this transfer relies on Google LLC’s EU-US Data Privacy Framework (DPF) certification. For Swiss law (revDSG) purposes, this transfer is conducted under Standard Contractual Clauses (SCCs) supplemented by IP anonymisation. Analytics cookies are non-essential and are only set after you provide explicit consent via our cookie consent banner. You may withdraw consent at any time or opt out at https://tools.google.com/dlpage/gaoptout.

8.2 Managing Cookies

You may configure your browser to refuse or delete cookies. Please note that disabling cookies may affect the functionality of our website. We implement cookie banners to obtain your consent for non-essential cookies in accordance with applicable law.

9. Your Rights

Subject to applicable law (revDSG / GDPR), you have the following rights regarding your personal data:

  • Right of access: to obtain confirmation of whether we process your data and receive a copy
  • Right to rectification: to request correction of inaccurate or incomplete data
  • Right to erasure: to request deletion of your data, subject to our legal retention obligations
  • Right to restriction: to request that we restrict processing of your data in certain circumstances
  • Right to data portability: to receive personal data you provided to us and that we process by automated means on the basis of consent or a contract, in a structured, machine-readable format (CSV or JSON). In scope: account profile data, transaction history, and order history. Not in scope: data processed solely on the basis of legal obligation (including AML/KYC records subject to mandatory retention)
  • Right to object: to object to processing based on legitimate interests
  • Right to withdraw consent: at any time, where processing is based on consent

Important limitations:

The exercise of certain rights is limited or overridden by our legal obligations as a regulated entity:

  • Mandatory AML/KYC record retention (minimum 10 years) limits the right to erasure.
  • AML risk categorisation is a legal requirement and is not subject to the right to object.
  • Where a report has been filed or is being considered, your rights of access and information are further limited by the tipping-off prohibition described in Section 6.2 above. We are not permitted to confirm or deny the existence of any such report.

To exercise any of the above rights, or to raise a data protection concern, please contact us at: compliance@eti-tech.ch

Response timeframes:

We will respond to data subject rights requests within 30 calendar days. Where a request is complex, we may extend by up to a further 60 days, notifying you within the initial 30-day period with reasons for the extension.

Identity verification:

To protect your data, we will verify your identity before processing any rights request. We may ask you to confirm information on file (registered email, account number, or other identifying details).

How to submit: Data protection, compliance, and AML requests should all be directed to compliance@eti-tech.ch. Please specify the right you are exercising and include your account details.

You have the right to lodge a complaint with a data protection supervisory authority. If you are resident in Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch. If you are resident in an EU/EEA member state, you may instead or additionally lodge a complaint with the data protection supervisory authority of your country of residence; a list of EU/EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

10. Data Security

Eti-Tech AG implements appropriate technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, loss or destruction. These measures include:

  • SSL/TLS encryption for all data transmitted to and from our website
  • Two-factor authentication (2FA) for user accounts
  • Access controls limiting data access to authorised personnel on a strict need-to-know basis
  • Secure, encrypted data storage on servers located exclusively in Switzerland
  • Regular security reviews and vulnerability assessments
  • Confidentiality classification of all AMLA files as “Confidential”

Despite our best efforts, no system can guarantee complete security against all threats. In the event of a personal data breach posing risk to individuals: (a) we will notify the FDPIC (and the relevant EU supervisory authority for GDPR purposes) within 72 hours of becoming aware; (b) where the breach poses high risk to your rights and freedoms, we will also notify you directly without undue delay, describing the breach, its likely consequences, and remedial measures taken; (c) we maintain an internal data breach register; (d) where a breach occurs at a third-party processor, our data processing agreements require them to notify us without undue delay.

11. Children

Our services are not directed at persons under the age of 18. This reflects both our own policy and the age of legal capacity to enter into binding contracts under Art. 14 of the Swiss Code of Obligations (CO/OR), which our KYC and account-opening processes require. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us immediately at compliance@eti-tech.ch and we will take steps to delete it.

12. Newsletter and Marketing Communications

If you subscribe to our newsletter or opt in to marketing communications, we will use your name and email address to send you updates about our products, services and the crypto ecosystem. Your consent forms the legal basis for this processing.

You may unsubscribe at any time by clicking the unsubscribe link in any communication or by contacting us at compliance@eti-tech.ch. Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. A material change includes: introduction of a new data category, new processing purpose, new recipient category, or change to retention periods. We will provide at least 30 days’ advance notice of material changes by email and via a prominent notice on the Platform. Continued use after the effective date constitutes acceptance. If you do not accept the changes, you may close your account before the effective date. Minor updates (formatting, clarifications, contact details) may take effect immediately. All previous versions are archived at www.eti-tech.ch/privacy/archive.

14. Contact Us

For any questions, requests or concerns regarding this Privacy Policy or the processing of your personal data, please contact us:

Eti-Tech AG

Müligässli 1, 8598 Bottighofen, Switzerland

Email: compliance@eti-tech.ch (also the contact point for our Data Protection Officer function)

Website: www.eti-tech.ch

Eti-Tech AG is a member of the VQF Self-Regulatory Organisation (SRO) and a regulated Virtual Asset Service Provider (VASP) under Swiss law. | Version 1.4 — July 2026 | Supersedes Version 1.3