24crypto
Legal

Privacy Policy

How 24crypto GmbH collects, uses, stores and protects personal data — and your rights as a data subject.

1. Contact addresses

1.1 Data protection officer or data protection consultant

24crypto GmbH / Chief Executive OfficerRiehentorstrasse 33
4058 Basel
Switzerland

Email: support@24crypto.ch

1.2 Data protection representation in the European Economic Area (EEA)

VGS Datenschutzpartner GmbHAm Kaiserkai 69
20457 Hamburg
Germany

Email: info@datenschutzpartner.eu

2. Terms and legal basis

2.1 Terms

Terms used in this privacy policy (such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “consent”, etc.) follow the definitions of the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

2.2 Legal basis

We process personal data on one of the following legal bases: (a) the data subject has given consent; (b) processing is necessary for the performance of a contract with the data subject or to take pre-contractual steps at their request; (c) processing is necessary to comply with a legal obligation we are subject to (in particular Swiss AML and KYC obligations); or (d) processing is necessary for the purposes of legitimate interests pursued by us or a third party, except where overridden by the rights of the data subject.

3. Type, scope, and purpose

We process personal data necessary to provide our services in a sustained, user-friendly, secure and reliable manner. Such data includes account data, identity and verification data, transaction data, technical data, and communications.

We process personal data for the duration required by the relevant purpose or statutory retention obligations and only to a reasonable extent.

4. Communication

When you contact us — via email, the contact form, support channels or otherwise — we process the personal data you provide (e.g. name, email address, content of the request) for the purpose of handling and responding to your enquiry.

5. Data security

We take appropriate technical and organisational measures to ensure data security in accordance with the state of the art, in particular to protect personal data against risks of loss, accidental alteration, unintentional disclosure or unauthorised access.

6. Personal data abroad

We disclose personal data abroad only where the recipient guarantees an adequate level of data protection — by means of a country assessment, contractual safeguards (standard contractual clauses), binding corporate rules or another lawful transfer mechanism — or where the data subject has expressly consented.

7. Rights of data subjects

7.1 Data protection claims

You have the following rights regarding your personal data:

  • Right of access (information about which data we process about you);
  • Right to rectification of inaccurate or incomplete data;
  • Right to erasure of your personal data, subject to statutory retention;
  • Right to restriction of processing;
  • Right to data portability;
  • Right to object to processing based on legitimate interests;
  • Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

7.2 Legal protection

You have the right to lodge a complaint with the competent supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), and in the EEA the data protection authority of your country of residence.

8. Use of the website

8.1 Cookies

Cookies — small text files stored by your browser — can be used to recognise visitors, store preferences and analyse usage. You can configure your browser to block cookies or notify you when one is set; some functions of the website may not be fully usable without cookies.

8.2 Logging

Our hosting provider records data about each access to the website (server log files). This includes the IP address, the request, the time of access, the data transferred and information about the requesting browser and operating system. The logs are used to detect and remedy disruptions, to assure security and to optimise the service.

8.3 Tracking pixels

We may use tracking pixels — small graphics embedded in pages or emails — to measure whether and how visitors interact with our content. The data collected includes IP address, browser type and the time of access.

9. Notifications and messages

9.1 Success and reach measurement

Notifications and messages we send (e.g. email) may contain web links and tracking pixels that record whether the message was opened and which links were clicked. The results help us optimise our communication.

9.2 Consent and objection

Notifications and messages requiring consent are sent only with your prior, explicit and revocable consent. You may opt out of any non-essential message at any time, for example by using the unsubscribe link inside the message.

10. Social media

We may operate official channels on social-media platforms. When you interact with our channels, the platform operator processes your personal data on its own responsibility in accordance with its own privacy policy.

11. Third party services

11.1 Digital infrastructure

We use third-party providers for hosting, content delivery, email delivery, analytics and security. These providers act as our processors and are bound by data-processing agreements.

11.2 Automation and integration of apps and services

We use third-party automation and integration services to connect our internal tools and to streamline customer support and operations.

11.3 Audio and video conferencing

For meetings, calls and webinars we may use third-party conferencing services. The operator processes the connection data and any media streams on its own responsibility in accordance with its privacy policy.

11.4 Payments

Payments and payouts are processed by regulated payment-service providers and banks. These providers receive the data strictly necessary to execute the payment.

11.5 Identity verification

For account onboarding and KYC checks we use specialised verification providers (e.g. KYC Spider AG). The data collected during the verification process is shared with the provider strictly for the purpose of verifying your identity and complying with applicable AML obligations.

12. Measuring success and reach

We measure the success and reach of our website and communications through aggregated analytics. Where required by law, this measurement is only carried out with your consent.

13. Final provisions

We may update this privacy policy at any time to reflect changes in the law or in our services. The current version published on this page applies. For any questions about this policy or your data, please contact support@24crypto.ch.