Legal

Privacy policy

How CoinExForensics collects, uses, shares and protects personal data under the Swiss Federal Act on Data Protection (FADP/DSG, revised version in force since 1 September 2023) and, where applicable, the EU GDPR.

Last updated: 31 July 2026

1. Controller and data protection contact

CoinexForensics GmbH, Bahnhofstrasse 65, 8001 Zürich, Switzerland, is the controller responsible for the processing described in this policy.

Data protection enquiries and data subject requests: support@coinexforensics.com, telephone +41 41 677 15 30. Please write "DATA PROTECTION" in the subject line so your request reaches the right team.

2. Scope

This policy covers www.coinexforensics.com, the client portal, our recovery mandates and the concierge settlement desk, and all email and telephone contact with our team. It does not cover third-party websites, exchanges or wallets you reach through links or through your own accounts; those operators publish their own policies.

3. Categories of personal data we process

  • Account data: first and last name, email address, country of residence, password hash, language and theme preferences, notification settings.
  • Identity and verification data: identity document or passport images (front and back), a selfie holding the document, date of birth, nationality and residential address, verification status and reviewer notes.
  • Case data: incident descriptions, dates and amounts, transaction hashes, wallet and exchange addresses, counterparty details, correspondence and uploaded evidence files.
  • Transaction data: buy, sell and withdrawal instructions, amounts, assets, networks, quoted rates, fees, balances and full status history.
  • Communication data: emails, portal messages, notes from telephone calls with the desk, and support tickets.
  • Technical data: IP address, device and browser characteristics, timestamps, page and action logs, and security events such as sign-ins and password changes.

Identity documents and case evidence may contain data qualifying as sensitive personal data under Art. 5 lit. c FADP. We process such data only where it is necessary for identification, financial crime prevention or the mandate itself.

4. Where the data comes from

Most data comes directly from you: when you register, complete verification, open a mandate, place an instruction or contact the desk. Some data is generated automatically when you use the platform (technical and log data). Where a case requires it, we may also receive data from public blockchain records, sanctions and PEP screening sources, exchanges, banks, instructed counsel or authorities.

5. Purposes and legal bases

  • Performing the contract with you: account operation, mandate execution, settlement, support (Art. 31 para. 2 lit. a FADP / Art. 6(1)(b) GDPR).
  • Complying with legal obligations: anti-money-laundering identification, record keeping, sanctions and PEP screening, reporting and responses to lawful orders (Art. 31 para. 1 FADP / Art. 6(1)(c) GDPR).
  • Legitimate interests: fraud and abuse prevention, platform and account security, service improvement, statistical analysis in aggregated form, and establishing or defending legal claims (Art. 31 para. 1 FADP / Art. 6(1)(f) GDPR).
  • Consent: optional communications and any processing that goes beyond the above — withdrawable at any time with effect for the future (Art. 6 para. 6 FADP / Art. 6(1)(a) GDPR).

6. Is providing data mandatory?

Account, verification and mandate data is required: without it we cannot open an account, meet our due diligence duties or execute an instruction, and we will have to decline the relationship. Optional fields are marked as such, and refusing them has no consequence beyond the loss of the related convenience.

7. Recipients and processors

  • Infrastructure processors: cloud hosting, managed database, file storage and email delivery providers.
  • Compliance tooling: identity verification, sanctions, PEP and blockchain analytics services.
  • Counterparties in a mandate: exchanges, custodians, banks and payment providers, strictly limited to what a freeze, trace or settlement request requires.
  • Advisers and authorities: instructed legal counsel, auditors, law enforcement, and Swiss or foreign supervisory bodies where we are legally required or entitled to respond.

We disclose personal data only where it is necessary, and never for sale or advertising. Recipients fall into these groups:

8. International transfers

Some processors and counterparties operate outside Switzerland and the EEA. We transfer data to such countries only where the Swiss Federal Council recognises adequate protection, or on the basis of EU Standard Contractual Clauses together with the Swiss addendum recognised by the FDPIC, or where a statutory exception under Art. 17 FADP applies (for example, the transfer is necessary to perform the contract or to establish a legal claim). A copy of the safeguards used can be requested at the contact address above.

9. Retention

  • Identity, verification and transaction records: ten years after the end of the business relationship or the individual transaction, as required by Swiss anti-money-laundering law.
  • Case files: for the duration of the mandate plus ten years where the file supports a financial or compliance record.
  • Communication data: three years, or longer where it forms part of a case file.
  • Technical and security logs: typically twelve months.
  • Job applicant data: twelve months, unless you ask us to keep it on file for longer.

Once no retention obligation and no legal claim applies, data is deleted or irreversibly anonymised.

10. Security

Data is encrypted in transit and at rest. Identity documents and case evidence are held in private storage and are reachable only by authorised compliance staff through short-lived signed links. Access to production data is role-based, logged and reviewed, database access is governed by row-level security so clients can only reach their own records, and administrative actions are recorded in an audit trail. No system can be guaranteed absolutely secure; we work to a risk-appropriate standard and review our controls regularly.

11. Automated decision-making and profiling

We do not take decisions with legal or similarly significant effect about you on a purely automated basis. Screening and risk tooling may flag a case or an instruction, but a human analyst always makes the final decision to accept, hold or decline it.

12. Minors

Our services are intended for persons aged 18 and over. We do not knowingly process data about children. If we learn that we hold such data without a legal basis, we delete it.

13. Your rights

  • Information and access: obtain confirmation of processing and a copy of the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure or destruction, where no retention obligation or legal claim prevents it.
  • Restriction of, or objection to, processing based on legitimate interests.
  • Data portability: receive data you provided in a common electronic format, or have it transferred where technically feasible.
  • Withdrawal of consent at any time, with effect for the future.
  • Objection to disclosure to third parties, within the limits of our legal duties.

Send requests to support@coinexforensics.com. Exercising these rights is free of charge. We respond within 30 days and may ask you to verify your identity first; we may decline or restrict a request where the law requires it, for example where anti-money-laundering records must be preserved or where a disclosure would compromise an ongoing investigation.

You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, or, if the GDPR applies to you, with your local supervisory authority.

14. Cookies and local storage

We use strictly necessary storage only: an authentication session token, your language preference and your theme preference. We do not run advertising, profiling or cross-site tracking cookies, and we do not embed third-party analytics that identify you. Blocking this storage in your browser will prevent you from staying signed in.

15. Data breaches

If a breach of data security is likely to result in a high risk to your rights, we notify the FDPIC and, where required, you as promptly as possible, describing what happened, what data is affected and what you can do.

16. Changes to this policy

We update this policy as our processing, tooling or legal duties change. The date above reflects the current version; material changes are announced in the client portal before they take effect.

Questions about this policy? Write to support@coinexforensics.com or call +41 41 677 15 30. CoinexForensics GmbH, Bahnhofstrasse 65, 8001 Zürich, Switzerland.

Provider

CoinexForensics GmbH
Bahnhofstrasse 65
8001 Zürich, Switzerland
support@coinexforensics.com
+41 41 677 15 30