Privacy Policy
How Wake AG handles personal data, and what you can ask us to do about it.
About this policy
This policy explains how Wake AG handles personal data. It covers everyone whose data we process: visitors to our website, the people we deal with at our corporate clients and partners, and individuals whose data reaches us because they use a service we provide through one of our clients.
We are a Swiss financial intermediary. A large part of the data we hold, we hold because the law requires us to. Where that is the case we say so, because it affects what you can ask us to do with it.
Who is responsible
| Controller | Wake AG, Gubelstrasse 11, 6300 Zug, Switzerland. UID CHE-381.774.414. |
| Contact | privacy@wakepay.ch, which reaches the person responsible for data protection at Wake AG — or write to us at the address above. |
Wake AG is the controller for the personal data described in this policy, including data about our clients' own customers. We identify those customers ourselves, under our own anti-money-laundering obligations, and we decide why and how their data is processed. Where we provide a service to a client's customer, it is governed by an agreement to which the client, the customer and Wake AG are all party.
A client that receives transaction data from us — for example so that it can credit its customer's account — processes that data as a separate controller, under its own privacy notice.
Which law applies
We are established in Switzerland, so the Swiss Federal Act on Data Protection (FADP) applies to our processing. Where we offer services to individuals in the European Economic Area, or monitor their behaviour there, the General Data Protection Regulation (GDPR) applies in addition. Where both apply we follow the stricter requirement.
What we collect
| Category | Examples |
|---|---|
| Identification data | Name, date and place of birth, nationality, residential address, identity document details and images, photograph or video captured during identification. |
| Contact data | Email address, telephone number, postal address. |
| Corporate data | For corporate clients: company details, ownership and control structure, details of directors, signatories, controlling persons and beneficial owners. |
| Due diligence data | Source of funds and source of wealth information, purpose and intended nature of the relationship, sanctions and politically exposed person screening results, adverse media results, risk classification. |
| Transaction data | Amounts, currencies and assets, timestamps, blockchain addresses and transaction hashes, counterparty information, quotes, conversions and settlement references. |
| Account and technical data | Login identifiers, authentication tokens, device and browser information, IP address, access and audit logs. |
| Correspondence | Emails, support messages and notes of calls or meetings. |
We do not seek to collect special categories of personal data. Some may nonetheless reach us — for example where an identity document reveals place of birth, or where adverse media screening returns information about criminal proceedings. We process it only so far as anti-money-laundering law requires.
Where it comes from
- From you, when you contact us, apply to open a relationship, complete identification, or use our services.
- From our clients, where they introduce a customer to us — for example contact details and the reference they use for that customer. Identification itself we carry out directly with the customer.
- From public and commercial sources, including commercial registers, sanctions and politically exposed person lists, adverse media databases and blockchain analytics providers.
- From your use of our website and interfaces, automatically, as described in our Cookies Policy.
Why we process it
| Purpose | Basis |
|---|---|
| Providing the service — opening and operating relationships, generating deposit addresses, issuing quotes, executing conversions and settling proceeds | Performance of the contract with you or steps taken at your request (Art. 6(1)(b) GDPR). Under the FADP, processing necessary to perform a contract. |
| Meeting our anti-money-laundering obligations — identification and verification, establishing beneficial ownership, screening, transaction monitoring, clarifications, record keeping and reporting | Compliance with a legal obligation (Art. 6(1)(c) GDPR), in particular under the Swiss Anti-Money Laundering Act and its ordinances and the VQF SRO Regulations. |
| Preventing fraud and securing our systems and our clients' funds | Legitimate interests (Art. 6(1)(f) GDPR), and in part legal obligation. |
| Accounting, tax and corporate record keeping | Compliance with a legal obligation (Art. 6(1)(c) GDPR), in particular the Swiss Code of Obligations. |
| Establishing, exercising or defending legal claims | Legitimate interests (Art. 6(1)(f) GDPR), and legal obligation where applicable. |
| Any marketing communications we send you | Your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time. |
Under the FADP we do not need a legal basis in the way the GDPR requires one, but we must process data lawfully, in good faith and proportionately, for the purpose we told you about. The table above is how we meet both standards at once.
Who we share it with
We do not sell personal data and we do not share it for anyone else's marketing. We disclose it only as set out below.
| Recipient | Why |
|---|---|
| Service providers acting for us | Technology and operational services, wallet infrastructure, blockchain analytics and wallet screening, identity verification, travel rule messaging, compliance support, hosting, and communications. They act on our instructions under written contracts. |
| Banks and payment institutions | Where they are involved in settling funds to or from you. |
| Authorities and supervisory bodies | The Money Laundering Reporting Office Switzerland (MROS), VQF as our self-regulatory organisation, our external AML auditor, tax authorities, and courts and law enforcement — where the law requires or permits it. |
| Professional advisers | Auditors, lawyers and tax advisers, who are bound by professional secrecy. |
| Acquirers or successors | If our business or part of it is transferred, subject to appropriate safeguards. |
We may be unable to tell you about a report. If we file a report with MROS, Swiss anti-money-laundering law prohibits us from informing you or any third party that we have done so.
Transfers outside Switzerland
Some of our service providers are located outside Switzerland. Where we transfer personal data to a country that the Swiss Federal Council has not recognised as providing adequate protection, we rely on appropriate safeguards — normally the European Commission's Standard Contractual Clauses as recognised and amended for Swiss purposes by the Federal Data Protection and Information Commissioner, or, for recipients in the United States, certification under the Swiss–US Data Privacy Framework. You can ask us for a copy of the safeguards we rely on for a particular transfer.
Automated processing
We use automated tools to screen customers and transactions against sanctions and politically exposed person lists, to score blockchain addresses and counterparties for risk, and to flag unusual activity. These tools can result in a deposit being held, a transaction being refused, or a relationship being declined or ended.
A decision of that kind is always reviewed by a person before it becomes final, unless the law requires us to act immediately. Where an automated decision does produce legal effects for you, you may ask for human intervention, put your point of view, and contest the decision — except where telling you would breach the reporting rules described above.
How long we keep it
| Data | Retention period |
|---|---|
| Identification documents, due diligence files, transaction records and the documentation of clarifications | Ten years from the end of the business relationship or from the date of the transaction, as required by Art. 7(3) of the Swiss Anti-Money Laundering Act. |
| Accounting records and supporting vouchers | Ten years from the end of the financial year, under Art. 958f of the Swiss Code of Obligations. |
| Correspondence and support records | Three years from the end of the correspondence, unless it forms part of a due diligence file, in which case the ten-year period above applies. |
| Website and cookie data | As set out in the Cookies Policy. |
| Data processed with your consent | Until you withdraw consent. |
When a retention period ends we delete the data or anonymise it irreversibly. We may keep it longer where it is needed for a pending claim or where an authority has asked us to.
How we protect it
Access to personal data is restricted to the people who need it, controlled by role and recorded in an audit log. Traffic to and from our systems is encrypted in transit. Our primary systems are hosted in Switzerland or the European Union; where a provider elsewhere has access to personal data, the safeguards described under Transfers outside Switzerland apply. Our providers are assessed before engagement and reviewed periodically.
Your rights
Subject to the conditions in the FADP and, where it applies, the GDPR, you may:
- ask what personal data we hold about you and receive a copy;
- have inaccurate or incomplete data corrected;
- ask us to delete data, or to restrict how we use it;
- receive data you gave us in a machine-readable format, or have it sent to another controller;
- object to processing we carry out on the basis of our legitimate interests;
- withdraw consent at any time, where we rely on it.
These rights have limits. Where we hold data because anti-money-laundering or accounting law requires it, we cannot delete it on request, and we may have to withhold access where doing otherwise would defeat the purpose of an investigation or breach a duty of confidentiality.
To exercise a right, write to us at privacy@wakepay.ch. We will respond within 30 days, and will tell you if we need longer. We may ask you to confirm your identity first.
If you are not satisfied, you may complain to the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland. If the GDPR applies to the processing, you may also complain to the supervisory authority in your country of residence or place of work.
Cookies
Our corporate website sets no cookies of its own. The platform sets only those strictly necessary to keep you signed in and secure. The detail, and how you control them, is set out in our separate Cookies Policy.
Changes
We update this policy when our processing changes or the law does. The current version is always published at wakepay.ch/privacy. Where a change materially affects you we will tell you directly.
Wake AG is affiliated to VQF, a self-regulatory organisation recognised by FINMA, as member no. 101395. The affiliation concerns compliance with the Anti-Money Laundering Act; it is not a FINMA licence for other activities.