Privacy and Cookie Policy
1. About this Policy
This Privacy and Cookie Policy (hereinafter referred to as the “Policy”) are developed to explain how we use the personal data collected from you when you use our services and website. We are EXOLOTL GmbH (hereinafter referred to as “we”, “us” or the “Company”), a limited liability company incorporated under the laws of Switzerland and duly registered in the commercial register of the Canton of Zug under the following company registration number: CHE-386.691.497 and having its registered address at Baarerstrasse 12, 6300, Zug, Switzerland.
The Company is a service provider in the field of digital assets, i.e. the exchange and brokerage between fiat money and crypto assets (on- and off-ramp services), supervised by the VQF (Verein zur Qualitätssicherung von Finanzdienstleistungen), a Swiss self-regulatory organization recognized and supervised by the Swiss Financial Market Authority FINMA.
This Policy applies when the Personal Data related to you is collected or processed by the Company with respect to:
- Your access to or use of content on the websites located at https://exolotl.ch/ or any other websites, applications, pages, features, or content owned or operated by us (collectively, the “Sites”); and/or
- Your use of our services (collectively, the “Services”).
Additionally, any information provided by you to the Company in reply to a written request received from us or to any other contact from us, or while using any of our Services, will also be managed in accordance with this Policy.
The Company is committed to processing your Personal Data responsibly and in compliance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the General Data Protection Regulation (GDPR).
2. Data we collect
When you use our Sites we may collect the following Data:
Browsing data, i.e. scope of information on how you access and use our Sites, which is collected for security and statistical purposes.
IT and security data, such as IP address, device identifier, browser, login details, and access logs, which are collected to ensure the security and correct operation of our Sites.
Cookies and tracking technologies, web beacons, and other analogous tools and technologies may be used to recall your preferences, analyze traffic for optimization purposes, detect potential fraud as well as enhance overall user experience.
Cookies & Tracking
Cookies are small text files placed on your computer or smartphone to collect standard Internet log and visitor behavior information. When you visit our Sites, we may collect information from you automatically through cookies or similar technology. This helps us to differentiate you from other users, which enhances your experience using our Sites. Cookies can be either first-party cookies built by our website or third-party cookies (e.g., Google Analytics).
Cookies may be classified as:
- Essential and functional Cookies, which are required to keep the basic functions of the Sites operating properly (cannot be disabled).
- Non-Essential Cookies, e.g. targeted Cookies, which are used for analytics, preferences, or marketing purposes.
We may use the following types of Cookies:
Functional cookies: we use them to recognize you and remember your previously selected preferences. These could include selected language and location you are in. A mix of first-party and third-party cookies are used, e.g. Cookies for Cross-Site Request Forgery (CSRF) protection against code injection, referrer Cookies to transfer data about the user’s referrer when going to the website used as part of determining the source of the attracted client, language Cookies to transfer data about the selected localized version of the Sites and session Cookies used to enhance the quality of services provided to the user.
Third-Party Cookies & Analytics: we use third-party analytics, tag management, and user-behavior tools to understand how visitors interact with our Sites and to optimize performance. These tools may collect technical information as well as interaction data. Such technologies are used for statistical analysis, service improvement, performance monitoring, and website optimization, and are activated only in accordance with your consent where required.
Consent Requirement
We will request your consent prior to placing any non-essential cookies on your device. You can provide, withdraw, or modify your consent at any time.
How to Control Cookies
You can manage or disable cookies through the cookie settings on our Sites. You can also modify your browser settings to reject cookies. Note that some features of the Sites may not function properly as a result.
If you are willing to delete the Cookies, to change the settings related to Cookies or to figure out which Cookies are stored, you must check your browser settings.
- Chrome: Activate, delete, and manage cookies in Chrome;
- Safari: Manage cookies and website data with Safari;
- Internet Explorer: Delete and manage cookies;
- Firefox: Delete cookies to remove data that websites have stored on your device.
It is possible to set up a notification and approval each time if you do want to store your data through Cookies. Furthermore, you are free to disable or delete cookies that are already stored on your device at any time. The process varies for each browser.
When you apply for or use our services, we may collect the following Personal Data crucial to enter into business relationship with you and to comply with regulatory requirements and fulfill the KYC/AML obligations:
- Identification and contact information: Full name, date of birth, nationality, copies of your identity documents, tax identification number, residential address, phone number, email address;
- Professional information: Occupation, employer details, CV or LinkedIn Profile, beneficial ownership information, and corporate or business information related to contractual relationships, where applicable;
- Financial and blockchain-related data: Source and proof of funds, banking information, wallet addresses, transaction hashes, blockchain activity data, and information collected for forensic and AML screening and ongoing monitoring.
We may also collect additional information from trusted third-party sources, such as identity verification providers, blockchain analytics providers, or AML and sanctions screening databases, where required under Swiss law. Where Personal Data is required to comply with legal obligations (including AML regulations), failure to provide such data may prevent us from entering into or maintaining a business relationship.
3. How and why your data is collected
You directly provide us with most of the data we require and collect. We collect and process data when you:
- Contact us using available means of communication;
- Submit application to us along with the requested Know-Your-Customer (KYC) documentation and information;
- Use our services;
- Voluntarily complete a customer survey or provide your feedback via e-mail.
We also process data we receive from third parties and other sources (business partners, clients, technical, payment and delivery service providers, advertising networks, tracking and analytics providers, data aggregators, lead generation agencies, public sources etc.).
Your Personal Data is collected and processed for legitimate purposes only. The main bases are as follows:
- Establishing business relationships with you and provision of our services to you;
- Information Security, which includes protection of accounts, Sites, and services from unauthorized access or cyberattacks;
- Quality management and development, which includes improvement and customization of our services and adding new features;
- General Customer Support, which includes answering your inquiries, resolving issues and disputes;
- Compliance reasons: we must comply with applicable Swiss legislations and regulatory obligations, including identification, KYC/AML/CFT, sanctions screening, suspicious activity monitoring, Travel Rule requirements, and reporting obligations;
- Internal Risk Management, which includes internal and external audit, compliance monitoring, internal control procedures, and supervisory examinations.
Please be informed that when we process your data, we may send it to, and use the resulting information from, compliance service providers to prevent fraud or money laundering.
Our Company may also share your personal data with other relevant third parties, primarily in case we are requested to do so to comply with a court order or law enforcement request, or if we deem it necessary, as determined at our sole discretion, to investigate, prevent or take action against illegal activities.
4. Data sharing
We do not sell or rent your Personal Data. Your Personal Data may be shared only in case it is necessary to provide our Services, comply with legal obligations and regulation, or ensure the security and integrity of our Sites and systems.
In general, access to your Personal Data is limited to our employees who need this access to perform their professional duties. Sensitive information, including KYC/AML, or transaction data, is subject to reinforced access controls and handled strictly on a need-to-know basis.
Personal Data collected to provide our Services may be shared with specialized third-party providers, such as identity verification, AML and sanction screening providers, IT infrastructure, cloud hosting, email, and communication service providers necessary for the operation of our Sites and Services.
These specialized third-party providers may process information such as identity documents, biometric data derived from identity verification processes, screening results, exclusively for the purposes of providing the services and complying with applicable legislation and regulatory requirements.
Personal Data may be shared with regulated financial and payment institutions strictly to the extent required for the performance of the requested services or to comply with applicable legislation and regulatory obligations. We do not consistently transfer client KYC documentation to our banking partners unless required for the provision of a specific service or by law.
5. Data storage and deletion
We will keep your data for as long as it is necessary to fulfil the purposes for which it has been collected or to comply with legal requirements under applicable law. Once the storage of your data is no longer required, your Personal Data will be deleted or anonymized in a secure manner.
KYC/AML Data: may be kept for up to ten years after the end of a business relationship unless a longer period is set by law, supervisory authority, or for compliance purposes.
Other Personal Data: shall be retained for as long as necessary to ensure the operation of Sites, provision of services, maintaining records, or complying with legal requirements.
The Company implements adequate technical and operational measures to protect Personal Data. Access to Personal Data is strictly limited to authorized personnel on a need-to-know basis and is protected by appropriate technical and organizational measures, including access controls, safe storage of identification documents, encryption, monitoring, and secure storage protocols.
Sensitive Personal Data processed for AML purposes is subject to enhanced protection measures, including access restrictions and role-based access.
Personal Data is primarily stored in Switzerland or in jurisdictions recognized as providing an adequate level of data protection under Swiss law. Where Personal Data is processed outside Switzerland, we ensure that appropriate protection measures are implemented in accordance with the FADP and, where applicable, the GDPR.
You have the right to access, correct, delete, restrict, object to the processing of your Personal Data, and to receive your Personal Data in a structured, commonly used, and machine-readable format, as permitted by law. Requests should be addressed to the email indicated at our website, namely hello@exolotl.ch.
Please be informed that certain rights may be restricted where processing is necessary to comply with legal obligations under KYC/AML regulations and laws or financial supervisory requirements.
We may transfer your personal data to recipients in countries outside of Switzerland or the EU (worldwide). Where Personal Data is transferred to jurisdictions that do not provide an adequate level of data protection under Swiss law, we implement appropriate safeguards in accordance with the Federal Act of Data Protection (FADP) and GDPR.
If you think your data protection rights have been violated, you can file a complaint with the relevant authority:
Switzerland (FADP): Federal Data Protection and Information Commissioner (FDPIC)
Website: www.edoeb.admin.ch
Address: Feldeggweg 1, 3003 Bern, Switzerland
European Union (GDPR): Your local national Data Protection Authority (DPA). Full list: edpb.europa.eu
6. Responsibility
The Company is responsible for the processing of data as described herein.
If you have any questions regarding your Personal Data we collect and keep, about this Policy, or you would like to exercise one of your data protection rights, please do not hesitate to contact us.
Our Data Protection Officer can be reached through the following e-mail address: hello@exolotl.ch or at the following address: Baarerstrasse 12, 6300, Zug, Switzerland.
7. Jurisdiction and governing law
This Policy and any questions relating thereto shall be governed by the laws of Switzerland, to the exclusion of any rules of conflict resulting from private international law.
Any dispute relating to this Policy must be brought before the ordinary courts of Zug, Switzerland.
8. Changes to the Policy
We reserve the right to update this Policy at any time without prior notice. Changes will be effective upon posting to the Sites. The current version published on our website shall apply.