Legal

Privacy policy

How CoinExForensics collects, uses and protects personal data under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR.

Last updated: 31 July 2026

1. Controller

CoinexForensics GmbH, Bahnhofstrasse 65, 8001 Zürich, Switzerland, is the controller for the processing described here. Data protection enquiries: support@coinexforensics.com.

2. Data we process

  • Account data: name, email address, country, password hash, language and theme preferences.
  • Verification data: identity document images (front and back), a selfie holding the document, date of birth and address.
  • Case data: incident descriptions, transaction hashes, wallet addresses, chat and email correspondence, uploaded evidence.
  • Transaction data: buy, sell and withdrawal instructions, amounts, assets, networks, fees and status history.
  • Technical data: IP address, device and browser information, timestamps, and security event logs.

3. Purposes and legal bases

  • Performing the contract with you: account operation, mandate execution, settlement (Art. 31 FADP / Art. 6(1)(b) GDPR).
  • Legal obligation: AML/KYC identification, record keeping, sanctions screening and reporting (Art. 6(1)(c) GDPR).
  • Legitimate interests: fraud prevention, platform security, service improvement and enforcing our rights (Art. 6(1)(f) GDPR).
  • Consent: optional communications, where requested — withdrawable at any time.

4. Recipients and processors

We share data only where necessary: cloud hosting and database infrastructure providers, identity verification and screening tooling, email delivery, and — where a case requires it — exchanges, banks, law enforcement and instructed legal counsel. Processors act on our instructions under written data processing agreements. We do not sell personal data.

5. International transfers

Some processors operate outside Switzerland and the EEA. Such transfers are covered by adequacy decisions or EU Standard Contractual Clauses with the Swiss addendum.

6. Retention

  • Verification and transaction records: retained for the statutory AML period of ten years after the relationship ends.
  • Case files: retained for the duration of the mandate plus ten years where the file supports a financial record.
  • Technical and security logs: typically twelve months.
  • Applicant data: twelve months unless you ask us to keep it on file.
  • Account data is deleted or anonymised once no retention obligation applies.

7. Security

Data is encrypted in transit and at rest. Identity documents are stored in a private bucket and are accessible only to authorised compliance staff through short-lived signed links. Access to production data is role-based, logged and reviewed. Our controls are covered by our SOC 2 and ISO 27001 programmes.

8. Your rights

  • Access a copy of the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure, where no retention obligation prevents it.
  • Restriction of, or objection to, processing based on legitimate interests.
  • Data portability for data you provided under a contract.
  • Withdrawal of consent at any time, with effect for the future.

Send requests to support@coinexforensics.com. We respond within 30 days and may ask you to verify your identity first. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local EU supervisory authority.

9. Cookies and local storage

We use strictly necessary storage only: an authentication session token, your language preference and your theme preference. We do not run advertising or cross-site tracking cookies.

10. Changes

We update this policy as our processing changes. The date above reflects the current version.

Provider

CoinexForensics GmbH
Bahnhofstrasse 65
8001 Zürich, Switzerland
support@coinexforensics.com